From owner-freebsd-questions@FreeBSD.ORG Wed Feb 28 16:03:53 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id B139116A404 for ; Wed, 28 Feb 2007 16:03:53 +0000 (UTC) (envelope-from dan@dan.emsphone.com) Received: from dan.emsphone.com (dan.emsphone.com [199.67.51.101]) by mx1.freebsd.org (Postfix) with ESMTP id 6083B13C48D for ; Wed, 28 Feb 2007 16:03:43 +0000 (UTC) (envelope-from dan@dan.emsphone.com) Received: from dan.emsphone.com (dan@localhost [127.0.0.1]) by dan.emsphone.com (8.14.0/8.13.8) with ESMTP id l1SG3aHo005358 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Wed, 28 Feb 2007 10:03:36 -0600 (CST) (envelope-from dan@dan.emsphone.com) Received: (from dan@localhost) by dan.emsphone.com (8.14.0/8.14.0/Submit) id l1SG3amC005338; Wed, 28 Feb 2007 10:03:36 -0600 (CST) (envelope-from dan) Date: Wed, 28 Feb 2007 10:03:36 -0600 From: Dan Nelson To: Only OpenSource Message-ID: <20070228160336.GH71962@dan.emsphone.com> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-OS: FreeBSD 6.2-STABLE User-Agent: Mutt/1.5.13 (2006-08-11) Cc: freebsd-questions@freebsd.org Subject: Re: does FreeBSD support ms chapv2 ? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 Feb 2007 16:03:53 -0000 In the last episode (Feb 28), Only OpenSource said: > Does FreeBSD support ms chapv2 protocol ? > > I am trying to setup a FreeBSD server as a PPP server > that can authenticate a Windows client using MS CHAP v2. >From the ppp manpge: MSChapV2|chap81 Default: Disabled and Accepted. It is very similar to standard CHAP (type 0x05) except that it issues challenges of a fixed 16 bytes in length and uses a combination of MD4, SHA-1 and DES to encrypt the challenge rather than using the standard MD5 mecha- nism. So I would guess that it is supported. All you would have to do is add "enable mschapv2" to your ppp.conf file. -- Dan Nelson dnelson@allantgroup.com