Community discussions

MikroTik App
 
evsio0n
just joined
Topic Author
Posts: 1
Joined: Thu Jan 06, 2022 3:47 pm

When dose routeros radius authentication using PAP

Thu Jan 06, 2022 4:06 pm

When or How to make radius is using PAP instead of MSCHAPv2 in Routeros Radius Client?
In https://wiki.mikrotik.com/wiki/Manual:RADIUS_Client Access-Request I didn't find when routeros is using MSCHAPV2 and when I set ppp profile encrypt set to no. My server still get MSCHAPv2 Challenge responses.
04CDD6F7-4380-4A08-BDB9-BB61B2CDD9DC.png
We are using a owned accouting system and we are using a own-built radius server so that our employee can using l2tp vpn.
In MSCHAPv2 password is stored as md4 in request and the only way seems to store a md4 hash of password then compare it with response,which is quite different from how our accouting system designed.
You do not have the required permissions to view the files attached to this post.
 
knigmaAK
just joined
Posts: 2
Joined: Fri Feb 24, 2023 8:23 am

Re: When dose routeros radius authentication using PAP

Sat Apr 15, 2023 3:55 am

I agree, PAP needs to be supported. I am not going to store my passwords in Radius (LDAP backend) in plain text. That would be a security risk.

Please Mikrotik support PAP for radius client mode. It looks like you do for Hotspot and other radius services.

Thanks

Who is online

Users browsing this forum: Amazon [Bot], Bing [Bot], infabo, thomassocz and 73 guests