<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=29&amp;t=1010" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2013-03-26T14:16:37+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=29&amp;t=1010</id>
<entry>
<author><name><![CDATA[samir]]></name></author>
<updated>2013-03-26T14:16:37+01:00</updated>
<published>2013-03-26T14:16:37+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3804#p3804</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3804#p3804"/>
<title type="html"><![CDATA[Re: [QUESTION] - MSCHAP not working with YubiRadius/2008r2 R]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3804#p3804"><![CDATA[
Hello,<br /><br />To configure the MSCHAPv2 with YubiRADIUS please refer the following link for your reference:<br /><!-- m --><a class="postlink" href="http://freeradius.org/">http://freeradius.org/</a><!-- m --> <br /><br />YubiRADIUS supports PAP and EAP-GTC. You can customize the YubiRADIUS with the help of above link as per your requirements.<br /><br />To understand what went wrong in your configuration please send us the screenshot of &quot;Global Configuration&quot; &gt;&gt; &quot;General&quot; of YubiRADIUS and following log files to &quot;support@yubico.com&quot;.<br /><br />1. Please configure the log files with the following settings from the webmin console:<br />1. Login to webmin<br />2. Go to &quot;System&quot; &gt;&gt; &quot;System Logs&quot;<br />3. Click on log file (ykropval.log ,etc. mentioned below)<br />4. Select &quot;all&quot; option in &quot;priorities&quot; field of &quot;Message types to log&quot; section<br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please repeat step 3, 4 and 5 for other log files mentioned below.<br />7. Please click on &quot;Apply Changes&quot; button on System Logs page<br />8. Go to &quot;Servers&quot; &gt;&gt; &quot;YubiRADIUS Virtual Appliance&quot;<br />9. Navigate 'Global Configuration' &gt;&gt; 'FreeRADIUS' menu, please enable FreeRADIUS Logging<br />10. Could you please ssh to the YRVA instance and restart the rsyslog process by executing the following command:<br />/etc/init.d/rsyslog restart<br />11. Please try to add the user and test the user with YubiKey credentials.<br /><br />Please send us the following log files:<br />/var/log/syslog<br />/var/log/messages<br />/var/log/ykval.log<br />/var/log/ykropval.log<br />/var/log/ykmap.log<br />/var/log/freeradius/radius.log<br />/var/log/postgresql/postgresql-8.4-main.log<br />/var/log/apache2/error.log<br />/var/log/apache2/access.log<br />/var/log/debug<br /><br />2. If you have already configure the webmin logs, please send &quot;webmin.debug&quot; file available at /var/webmin/webmin.debug<br /><br />If not please configure the log file with the following settings from the webmin console: <br />1. Login to webmin<br />2. Go to &quot;Webmin&quot; &gt;&gt; &quot;Webmin Configuration&quot;<br />3. Please Click on &quot;Debugging Log File&quot;<br />4. Please Click on &quot;yes&quot; option of &quot;Debug log enabled?&quot; <br />5. Please click on &quot;save&quot; button to save the changes.<br />6. Please once again Import Users.<br /><br />Please find the &quot;webmin.debug&quot; file at /var/webmin/webmin.debug<br /><br />3. Please brief on any other observations and please send the screen shots, error messages observed.<br /><br />Thanks and best regards,<br />Samir.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=1076">samir</a> — Tue Mar 26, 2013 2:16 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[abrazier]]></name></author>
<updated>2013-03-25T14:00:06+01:00</updated>
<published>2013-03-25T14:00:06+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3799#p3799</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3799#p3799"/>
<title type="html"><![CDATA[[QUESTION] - MSCHAP not working with YubiRadius/2008r2 RRAS]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1010&amp;p=3799#p3799"><![CDATA[
I have the YubiRadius 3.6.1 Appliance fully configured.  I also have a Server 2008 R2 setup with RRAS.  In the configuraion of RRAS I have it set to use MSCHAPv2 for the Authentication type and I have it pointing to the YubiRadius for RADIUS Authentication.  On a Windows 7 VPN login, with MSCHAPv2 and Required Encryption, it constantly denies credentials.  I have gradual deployment enabled and have single factor authentication turned on for all users imported from Active Directory.  I currently have no Yubikeys assigned and I am just testing the functionality of the Radius Authentication provided via YubiRadius.  In the FreeRadius log file I see where the Authentication is failing, yet I am unable to decipher what the log is having a problem with.  Can someone help me out?<br /><br /><span style="color: #FF4000">rlm_perl: Added pair MS-CHAP2-Response = 0x0000f460b5f590a1171149195ce6ed4dad2f0000000000000000f224aa1c8d21ea6afcc72c10d69f935078d076b9cb846e67<br />rlm_perl: Added pair NAS-Port = 257<br />rlm_perl: Added pair Auth-Type = MSCHAP<br />++[perl] returns ok<br />[files] users: Matched entry DEFAULT at line 147<br />++[files] returns ok<br />[pap] WARNING! No &quot;known good&quot; password found for the user.  Authentication may fail because of this.<br />++[pap] returns noop<br />Found Auth-Type = MSCHAP<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group MS-CHAP {...}<br />[mschap] Creating challenge hash with username: abrazier<br />[mschap] Told to do MS-CHAPv2 for abrazier with NT-Password<br />[mschap] expand: --username=%{mschap:User-Name:-None} -&gt; --username=abrazier<br />[mschap] expand: %{mschap:NT-Domain} -&gt; epc<br />[mschap] expand: --domain=%{%{mschap:NT-Domain}:-epc} -&gt; --domain=epc<br />[mschap]  mschap2: b1<br />[mschap] Creating challenge hash with username: abrazier<br />[mschap] expand: --challenge=%{mschap:Challenge:-00} -&gt; --challenge=98a9b3e2374fa6cf<br />[mschap] expand: --nt-response=%{mschap:NT-Response:-00} -&gt; --nt-response=f224aa1c8d21ea6afcc72c10d69f935078d076b9cb846e67<br />Exec-Program output: Invalid handle (0xc0000008) <br />Exec-Program-Wait: plaintext: Invalid handle (0xc0000008) <br />Exec-Program: returned: 1<br />[mschap] External script failed.<br />[mschap] FAILED: MS-CHAP2-Response is incorrect<br />++[mschap] returns reject<br />Failed to authenticate the user.<br />Using Post-Auth-Type Reject<br /># Executing group from file /etc/freeradius/sites-enabled/default<br />+- entering group REJECT {...}<br />[attr_filter.access_reject] expand: %{User-Name} -&gt; epc\abrazier<br /> attr_filter: Matched entry DEFAULT at line 11<br />++[attr_filter.access_reject] returns updated<br />Delaying reject of request 1 for 1 seconds<br />Going to the next request<br />Thread 3 waiting to be assigned a request</span><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2369">abrazier</a> — Mon Mar 25, 2013 2:00 pm</p><hr />
]]></content>
</entry>
</feed>