802.1X wired with MS IAS

Brian Bender d6p0d8f02
Mon Jan 12 14:16:42 PST 2009


On Mon, Jan 12, 2009 at 10:48 AM, Gerhard Schaden ges-at-liscon.com
|hostaplist/personal| <...> wrote:
> Does anybody use wpasupplicant on Ethernet with MS IAS Server. I tried to
> connect using MD5 and MSCHAPv2 but did not succeed.

FWIW, I recently ran into a problem talking to an MS IAS Server using
wpa_supplicant on a WPA2-PEAP WLAN. The server was complaining that
user "anonymous" didn't exist; I was completely confused at the time,
but in hindsight I think it must have gotten "anonymous" from the
outer identity in the PEAP exchange, rather than validating against
the tunneled inner identity. I haven't gotten back to testing with the
outer (anonymous_identity in .conf file) set to my user ID yet, but I
expect (hope!) that will fix my problem.

It might be possible to tell the IAS Server to validate the inner
rather than outer identity, but in this case the server is not in my
control.

Could this possibly be related to what you're seeing? Do you have
access to the event logs from the IAS server?

 - Brian



More information about the Hostap mailing list