Wpa_supplicant conf for NAP

Schneider, Craig-p98692 Craig.Schneider
Thu Nov 13 12:29:12 PST 2008


Can you confirm that my build config is ok when using hostapd as the
RADIUS client, and wpa_supplicant (on separate machines)? 

CONFIG_IEEE8021X_EAPOL=y
CONFIG_EAP_MD5=y
CONFIG_EAP_MSCHAPV2=y
CONFIG_EAP_TLS=y
CONFIG_EAP_PEAP=y
CONFIG_EAP_TTLS=y
CONFIG_EAP_GTC=y
CONFIG_EAP_OTP=y
CONFIG_EAP_SIM=y
CONFIG_EAP_AKA=y
CONFIG_EAP_PSK=y
CONFIG_EAP_SAKE=y
CONFIG_EAP_GPSK=y
CONFIG_EAP_PAX=y
CONFIG_EAP_LEAP=y
CONFIG_EAP_IKEV2=y

CONFIG_DRIVER_HOSTAP=y
CONFIG_DRIVER_TEST=y
CONFIG_DRIVER_WIRED=y

I am trying to determine why wpa_supplicant was authenticating, then
after a reboot of the all the boxes, authentication fails for
wpa_supplicant (still works with a Vista client).

Thanks,
Craig

On Thu, Nov 13, 2008 at 09:21:51AM -0700, Schneider, Craig-p98692 wrote:
> Can someone share their wpa_supplicant configuration that works with
> NAP?

I haven't tested this with Windows Server 2008, but anyway, to enable
NAP (SoH) you will need to include following in the network
configuration block to allow wpa_supplicant to use SoH:

    eap=PEAP
    phase2="auth=MSCHAPV2"
    phase1="peapver=0 tnc=soh crypto_binding=2"

-- 
Jouni Malinen                                            PGP id EFC895FA

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.shmoo.com/pipermail/hostap/attachments/20081113/e58b0f12/attachment-0001.htm 



More information about the Hostap mailing list