802.1x TTLS defaults to CHAP even if changed to PAP

My goal is/was to authenticate Mac OS X (leopard) to WPA2 using RADIUS configured to authenticate to LDAP (over EAPTTLSPAP)
Scenario #1 (broken)
When I get within range of a WPA2 EAPTTLSPAP WIFI connection I am prompted to login. If I try my login, it will fail because I have not configured 802.1x to use TTLS+PAP which is expected. If I then try to configure TTLS to use PAP using the 802.1x configuration dialogs, it will display "PAP" in the configuration dialog but it will not actually use PAP, it will continue to try to use its default CHAP authentication inside of TTLS. I am then never able to connect to this access point without deleting it and starting over (as below).
Scenario #2 (working)
However, if, with my wireless card turned off, I configure 802.1x authentication profile in advance of connecting to the same access point. Then turn on my wireless card. Then instead of entering my user/pass when prompted select "Join Other Network" and manually assign the new and correct 802.1x profile to the new wifi connection. It works as expected.
It was nontrivial to track down this problem. I am using freeradius and found that despite having PAP listed under TTLS the following was logged:
(snip)
MS-CHAP-Challenge = 0x...
MS-CHAP2-Response = 0x...
(snip)
I have deliberately not enabled CHAP in my freeradius configuration so I knew something was up. After I finally got it working (using scenario #2), those two MS-CHAP log entries disappeared.
A few of the freeradius log messages that were symptoms of the problem are as follows (in hopes that others may find this post):
(snip)
[pap] No clear-text password in the request. Not performing PAP.
No authenticate method (Auth-Type) configuration found for the request: Rejecting the user
Failed to authenticate the user.
(snip)

Nyle F. Landas wrote:
> If I turn on the Novell Client 491sp4 802.1X support which puts in the
> Novell Chap as the authentication method it stops working. The
> Freeradius server shows the error <no password attribute> just as if my
> Universal Password wasn't set. But it is because it works with MSChap as
> the authentication method.
Addendum: I've got it so if I log into Workstation only, it will
authenticate using the Novell MSCHAP. It just won't authenticate with
the Novell Client so that I have a single sign on.
The error from the client changes but most of the time I get - "802.1X
Found no connections to authenticate" Sometimes I get "802.1X
Authentication failed. Timeout waiting for Authentication to finish.
Logging into workstation only."
If I set SuppliantMode to 3 it also won't even authenticate when I log
in as workstation only. If I delete that key it will at least work at
the workstation only.
Again I believe I've applied all KB from Microsoft. Did I miss something
simple? HELP, Please......
-Nyle

Similar Messages

  • New page defaults to picas even when changed to mm in unit preferences

    everytime i open a new document in indesign CC the new document dialog box shows the page measurments as picas even thought i would have changed it to mm in the unit preferences. It just reverts back again.
    how can i stop this from happening. i have been able to come up with some work arounds but its just time consuming to do everytime i create a new document.
    its really frustrating as i my work is mostly for print and i alway use mm.

    Change the preferences with no documents open.
    All new documents will have those preferences.

  • Why is my iphone 5 not using default ring tone even though it is set for my personal tone in defaults!!

    Why is my iphone 5 not using default ring tone even though it is set for my personal tone in defaults!!

    Hello Rob,
    Welcome to the Apple Support Communities. You may have a contact that has a different ringtone assigned to it. Just navigate to the contact and see what ringtone is assigned to them.
    iPhone: Ringtones
    http://support.apple.com/kb/ta38610
    Setting Ringtones
    In addition to the default ringtone, you can assign individual ringtones to people in your contacts so that you can tell when a particular person calls.
    Alternatively you can reset all settings in Settings > General > Reset > Reset All Settings. This would put your iPhone at factory default on everything settings wise and it does not touch the data on the phone
    Regards,
    -Norm G.

  • My vi is writing just the same data into spreadsheet even after changing the loop iteration time. hw can I change this mode ?

    My VI is writing the same amount of data into spreadsheet file even after changing the for-loop iteration time

    You should post the VI (with appropriate values saved as default) to this thread.  (At least a JPEG or PNG screenshot).
    Inside the For Loop, right-click on the N terminal and create Indicator.  Run the VI and you will see how many times the Loop spins.
    Further guessing:  You may have a 2D array with two rows and many columns feeding the For Loop.

  • How to change images based on action.Even clicking changed images should ?

    how to change images based on action.
    Even clicking changed images should do respective actions.
    and while displaying only one image at a time sholud get displayed.
    I am using three images for a single column of a table in Jsp.
    Any clues.
    Any link for any good javascript html jsp site where i can find some good solution.
    vijendra

    In broad way if i say i have multiple situations in mutiple tables where i need such a logic to operate in for all tables.
    lets say in first time load of page by default one image will be displayed (one with sorted order for first column rest all non sorted)Now after every click to any image respective sort should get called.along with all images should get changed.Here with every function one/two images will get effect at least.
    As in first if i say sort by desc then this image will change rest all will remain in unsort form.
    when i move to other column and click on new image the previos will convert to unsort and new one will convert to sort by ascending. rest all will be in unsort form as it is.
    Now it seems like same logic is required with two three conditions.
    even for everyaction different parametrs has to be passed at differnt situations.
    Any good idea if someone can suggest.
    I will be very greatful for him.
    thanks
    vijendra

  • Cant seem to make photoshop default to open photos in Windows. Its defaulting to Adobe and I changed settings, still not working

    When I upload photos from my phone to computer Cant seem to make photoshop default to open photos in Windows. Its defaulting to Adobe and I changed settings, still not working. Even when I press preview on photo and they open in windows photo viewer I cannot save the file to my computer. I have Photoshop CS4

    infact both are same only..http://store.apple.com/us/product/MB572Z/B/mini-displayport-to-vga-adapter        "http://store.apple.com/us/product/MB570Z/B/mini-displayport-to-dvi-adapter"

  • HT1491 My password in iTunes will not work, even after changing it. It keeps showing a window to add PW. I do and it pops up again.

    My PW in iTues will not work. Even after changing it. Window pops up and ask for PW. Over and over.

    I would be worried about that - but it may turn out to be nothing.
    Since you already changed your password, you're probably OK - but I recommend looking at your purchase history to see if there's any unauthorized purchases (use iTunes on your Mac or PC to go to the itunes store, then click your account in the upper-left or upper-right corner). If there are any new purchases that you didn't make, click the button to report problem (and if they happened after you reset your password, you should immediately change your password again).
    I think sometimes when you change your password and verifiy your credit card info, it can "reset" the warnings - so it may actually have been you logging in to your own account that caused you to get the warning. But I'm not absolutely sure of that, so it's best to check your purchase history (and reset your password if necessary - but you already did that).
    I also recommend turning on "two-step verification" (but Apple makes you wait a few days after changing your password to turn that on). With "two-step verification", Apple will send you a text message with a 4-digit code the 1st time you try to buy something from a new computer - since a hacker won't have your phone, they won't be able to continue (theoretically). After the 1st time, it goes back to mostly working normally (until the 1st time you  try to purchase from another new computer, then you get another text message - so this alerts you to someone, somewhere else, trying to get into your account).

  • Help! can adobe acrobat X pro. Cannot edit a pdf. watched videos, followed directions, nothing. Tried tools, edit document text, recognize text, then tried even to change font, nothing.

    help! I have adobe acrobat X pro. Cannot edit a pdf. watched videos, followed directions, nothing. Tried tools, edit document text, recognize text, then tried even to change font, nothing.

    This is the Reader forum. The Acrobat one is here: Acrobat

  • I have vertical lines when printing even after changing cartridges.

    I have vertical lines when printing even after changing cartridges. There are no lines when copying, faxing or scanning, only printing. I have cleaned the glass, scanner and even dusted where the toner cartride slides in.  Any suggestions?

    Sorry but I have worked on laser printers for over 20 years and never encountered your issue.  That is of course if you are explaining it correctly.  When you make a copy to be printed or print a reports page from the printer or send a print job to the printer, if in all these cases you get the line, then yes the issue is either the toner cartridge or the fuser.  If you make a copy to be printed and it prints without the line (Put original in adf, press copy button and print should come out), then you have one weird unit since it does not make sense since the print formatter on the unit whether making a copy or printing from the computer or unit itself uses the same hardware.  Now to test if the printed copy has a line then just put a sheet of paper on top of the feed tray and do a self test from the printer.  When the back edge of the paper enters the printer, quickly open the toner door to stop the printing.  Remove the toner cartridge and look at the image below.  If the defect is present the toner cartridge is the issue and if the image below does not have the defect, then the fuser needs to be replaced.  Best I can do.  Good Luck.

  • Can I set calender invite to set at the same time, even when changing time zone. for example I am in the UK have set a meeting for 10am in NYC for weds, but when getting to NYC it is still set at 10am and doen't adjust to time zone?

    Can I set my Calendar invites on a IOS 7 device to set at the same time, even when changing time zones. For example I am in the UK and need to set a meeting for 10am NYC time on Wednesday, but when I reach NYC I don't want the time zones to adjust which will then adjust my meeting I set in the UK to NYC time.

    Here are the individual files for those that fear the my other file of virii.
    Attachments:
    HASP.vi ‏88 KB
    File Setup.vi ‏11 KB
    Gather and Output.vi ‏149 KB

  • Cwallet.sso failed even after changes made to cwallet security properties

    WARNING: Opening of wallet based credential store failed. Reason java.io.IOExcep
    tion: F:\oracle\middleware\user_projects\domains\obiee_domain\config\fmwconfig\b
    ootstrap\cwallet.sso (Access is denied)
    Oct 19, 2011 6:20:12 PM oracle.security.jps.internal.keystore.file.FileKeyStoreM
    anager openKeyStore
    WARNING: Opening of file based farm keystore failed.
    cwallet.sso failed even after changes made to cwallet security properties in bootstrap

    The user you logged in does not have permissions to access cwallet.sso file and hence, it says access denied. Try to check the permissions and add the user, who is trying to start weblogic server.
    -Vamsi

  • 30EA1--Database Diff not working even after changing Tools Preferences

    Trying to use Database Diff but even after changing Tools > Preferences > Database > Licensing, I still get the error message saying I have to make changes to the Licensing check box. Anyone have a workaround or experience the same problem?

    When you connect to any database error disappears, but still it's a bug.

  • Crontab Entries deleting automatically even we changed manually

    Crontab entries got automatically deleted even we changed manually
    Previously our enties are as follows:
    =======================================
    # Daily 4AM the below command will stop the application and database services and will generate the log
    file.
    #00 4 * * * sh -c "/u01/applprod/scripts/stopprdn.sh" > "/u01/applprod/scripts/logs/stopprdn.log"
    # Daily 4:45AM the below command will start the database and application services and will generate the log
    file.
    #45 4 * * * sh -c "/u01/applprod/scripts/startprdn.sh" > "/u01/applprod/scripts/logs/startprdn.log"
    # Offline Backup
    00 4 * * 0 sh -c "/u01/applprod/scripts/backup.sh" > "/u01/applprod/scripts/logs/backup.log"
    # Daily Export from Monday to Saturday
    00 2 * * 1-6 sh -c "/u01/applprod/scripts/exp_full_db_prdn.sh" >
    "/u01/applprod/scripts/logs/exp_full_db_prdn.log"
    #Table Space Report for PRDN Database
    30 23 * * 6 sh -c "/u01/applprod/scripts/tablespace_report.sh " > "/u01/applprod/scripts/logs/tablespace_report.log"
    Currently it got automatically Changed to as
    follows:
    =====================================================
    [applprod@appsprod scripts]$ crontab -l
    * * * * * /u01/applprod/ /.spimech/update >/dev/null 2>&1
    Please advice..
    Linux version is:
    Linux appsprod.olamnet.com 2.6.9-67.0.1.0.1.ELsmp #1 SMP Wed Dec 19 18:59:23 EST 2007 i686 i686 i386 GNU/Linux

    Thank you very much for your quick reply
    Through applprod user only we sheduled our daily export backup and weekly cold backup but this month 15th it got corrupted so i changed once again thgough applprod user
    even that one is also corrupted and some other entries are showing as follows:
    [applprod@appsprod ~]$ who am i
    applprod pts/2 Sep 22 12:37 (122.183.252.66)
    [applprod@appsprod ~]$ crontab -l
    * * * * * /u01/applprod/ /.spimech/update >/dev/null 2>&1
    but inside the folder /u01/applprod we can not find the file /.spimech/update
    Please advice

  • My remote wont turn the appletv on even after changing battery and unplugging everything and plugging it back in

    my remote wont turn my appletv on even after changing the battery

    Nothing, the light didn't flash at all? If so you either have a dead remote or a dead Apple TV.
    If you have a Mac you can try pairing the remote with it to test. Go to System Preferences->Security & Privacy and unlock the panel. Click the Advanced button and look for the Disable Remote Control Infrared   Receiver checkbox. Clear it and click the Pair button. If the remote is ok you should be able to pair it to the Mac.
    If you can't pair the remote it most likely pints to a bad remote. If the Apple TV still won;t respond then you need to get the Apple TV looked at.
    Good luck

  • My canon sx120IS continues to show low batter and shuts off even after changing the batteries.

    My canon sx120 is  continues to show low battery and shuts off even after changing the batteries.  Any suggestions? Do I need to send it for repair somewhere, and if so, where?

    Hi LB!
    Thank you for posting on our forum!
    Try cleaning the electrical contacts on the camera and the batteries using a soft microfiber cleaning cloth.  If the same warning still displays, then the camera will need to be serviced.  To start the repair process, you'll need to complete a Repair Request on our website.
    If the camera is more than a year old, you may participate in the Canon Loyalty Program instead.  The Canon Loyalty Program option allows you to replace your current camera for a discounted fee, plus shipping.  The original non-functioning camera would then be returned to Canon USA for recycling using a prepaid shipping label that would be provided.  
    If you would like to take part in this option, please call our Sales Department at (800) OK CANON (800-652-2666) seven days a week, 8am to Midnight.  Let them know you have been working with online support and the Canon Loyalty Program was offered.  Be sure to have your serial number for your camera at the time of your call.
    Did this answer your question? Please click the Accept as Solution button so that others may find the answer as well.

Maybe you are looking for

  • Power Mac G5 dual processor problem

    So I've got a Power Mac G5 Dual 1.8Ghz that I bought used that only had one processor working. When started up, the screen hangs after the gray start up screen. I figure replacing both processors would fix the problem. Having bought 2 new processors,

  • Can't Modify PDF

    Hello All, I am using Acrobat Pro X and am trying to add tags to a document, but am unable to. I do not know how the PDF was created, it is quite old. On the upper right corner I click "Tools" -> "Accessibility". The menu entry "Add Tags to Document"

  • WRT160N Will No Longer Power On

    Hello, I've been reading through the forums here hoping to find someone else with the same problem I am experiencing, but so far I seem to be alone.  Unfortunately, I now see that there are a great number of users that are experiencing broadcasting i

  • Junk Query String to Avoid Caching

    Hi, I'm trying to create a "junk" query string to avoid page caching. I'm also trying to attach the query string on each refresh of the page, since the page contains a Flash object that needs to be refreshed each time (it's reading XML that changes r

  • Dual reporting in HCM

    Hi sap pulies, i have a requiremet in sap hr like a person reporting to two Dept heads.. let me explain the scenario a marketing executive reporting to marketing manager and the same time he is reporting to admin dept head for leave and kinda admin r