Chapter 4

Pop quiz – authentication

  1. The use of PAP on its own can be a security risk, but when tunneled through TLS it is very secure.
  2. These users are probably authenticating with CHAP. CHAP requires that the passwords be stored in cleartext. Most RAS servers allow you to select the authentication protocols which it supports. Configure the RAS server to use only PAP.
  3. You can encrypt the passwords by using the smbencrypt program and use the value of NT hash for the NT-Password AVP.

Get FreeRADIUS Beginner's Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.