Re: Merit RADIUS pppuser vs. SCP user.ppp

William Bulley (web@merit.edu)
Mon, 30 Oct 1995 09:51:44 -0500 (EST)

According to David Carmean:
>
> I'm looking into the Merit RADIUS system to replace my current Livingston
> version, as it seems more extensible. However, I'm having trouble
> understanding the above use of the above "canonical" user entries. I've
> looked at the files and manpages with the distribution.

The description is contained in comments near the bottom of the users
file in the Merit RADIUS distribution.

> Using Livingston Portmasters, would it be the case that the 'pppuser'
> and 'slipuser' would only come into play using PAP or CHAP (or another
> protocol) where the User-Service and Framed-Protocol were already
> established?

PAP and CHAP are part of the PPP standard, SLIP is separate and has no
such was to negotiate user credentials. The NAS is configured to prompt
for "host:" first, then "login:" and "password:" second and third. If
the user enters PPP (or SLIP) as pseudo-hosts, or starts directly sending
PPP packets to the PostMaster so it can auto-detect PPP, then the RADIUS
server will get a "hint" in the form of the Service-Type attribute. It
is the presence of this "hint" in the request AND the lack of any Service-
Type reply-item attributes above the DEFAULT entry in the users file which
lets the Merit solution work.

> I haven't been around Unix/Networking/Internet/Remote Access for very
> long, but it seems like chat scripts and software PPP/SLIP servers
> started by the user from the command line came before PAP/CHAP...is that
> not correct?

The correct way to do dialing scripts is to have them deal with just
the call setup issues like setting up the modem and dialing the number.
Anything after than may vary as the ISP vendor changes NAS hardware and
software. It is best to let a modern protocol like PPP handle all this
post-modem-train stuff in a standard manner.

> Anyway, thank you very much for the input you've provided the group
> so far....I think you have a great "product" that I just don't fully
> grok yet.

Thank you -- but it is not a product -- it is just a public service
we offer to folks for no cost and with no support (other than the spare
time I spend reading this list...) ;^)

Regards,

web...

-- 
William Bulley, N8NXN              Senior Systems Research Programmer
Merit Network Inc.                 Domain: web@merit.edu
4251 Plymouth Road                 MaBell: (313) 764-9993
Ann Arbor, Michigan  48105-2785    Fax:    (313) 747-3185