📄 rlm_mschap.5
字号:
.TH rlm_mschap 5 "19 May 2006" "" "FreeRADIUS Module".SH NAMErlm_mschap \- FreeRADIUS Module.SH DESCRIPTIONThe \fIrlm_mschap\fP module provides MS-CHAP and MS-CHAPv2authentication support. .PPThis module validates a user with MS-CHAP or MS-CHAPv2 authentication.It should be listed in both the \fIauthorize\fP and \fIauthenticate\fPsections. In \fIauthorize\fP, it will look for MS-CHAPChallenge/Response attributes in the Acess-Request, and configureitself to be the module called for the \fIauthenticate\fP section..PPThe module can authenticate the MS-CHAP session via plain-textpasswords (User-Password attribute), or NT passwords (NT-Passwordattribute). The module can perform authentication against an NTdomain by using the \fIntlm_auth\fP program..SH SMB IntegrationThe module also enforces the SMB-Account-Ctrl attribute. See theSamba documentation for the meaning of SMB account control. Themodule does not read Samba password files. Instead, the\fIrlm_passwd\fP module should be used to read a Samba password file,and to supply an NT-Password attribute which this module can use. Seethe \fIetc_smbpasswd\fP module in \fIradiusd.conf\fP for more details..SH MODULE CONFIGURATIONThe main configuration items to be aware of are:.IP use_mppeUnless this is set to 'no', FreeRADIUS will add MS-CHAP-MPPE-Keys forMS-CHAPv1 and MS-MPPE-Recv-Key/MS-MPPE-Send-Key for MS-CHAPv2. Thedefault is 'yes'..IP require_encryptionIf MPPE is enabled, setting this attribute to 'yes' will cause theMS-MPPE-Encryption-Policy attribute to be set to require encryption.The default is 'no'..IP require_strongIf MPPE is enabled, setting this attribute to 'yes' will cause theMS-MPPE-Encryption-Types attribute to be set to require a 128 bit key.The default is 'no'..IP with_ntdomain_hackWindows clients send User-Name in the form of "DOMAIN\\User", but send thechallenge/response based only on the User portion. Setting this valueto yes, enables a work-around for this error. The default is 'no'..IP ntlm_authUse the \fIntlm_auth\fP program for authentication against Samba, or aWindows NT or Active Directory Domain Controller. For machineauthentication, the following configuration should be used:.DSntlm_auth = "/path/to/ntlm_auth --username=%{mschap:User-Name:-None} --challenge=%{mschap:Challenge:-00} --nt-response=%{mschap:NT-Response:-00} --domain=%{mschap:NT-Domain:-YOUR_DEFAULT_DOMAIN}.DEIf configured, \fIntlm_auth\fP will always be called, even if there isa clear-text or NT-Password available for the user. You can force\fIntlm_auth\fP to not be used by setting.DSMS-CHAP-Use-NTLM-Auth := No.DEin the \fIusers\fP file, or in a database such as SQL..PP.SH SECTIONS.BR authorization,.BR authentication.PP.SH FILES.I /etc/raddb/radiusd.conf.PP.SH "SEE ALSO".BR radiusd (8),.BR radiusd.conf (5).SH AUTHORChris Parker, cparker@segv.org
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -