CHAP / NT / "Couldn't CHAP on port S7 - Not allowed" (fwd)

MegaZone (megazone@livingston.com)
Fri, 6 Sep 1996 17:52:43 -0700 (PDT)

Once upon a time Kevin Fink shaped the electrons to say...
>We have a dial-up customer who is running Windows NT 4.0 and trying to
>connect to our PM2E-30. The negotiation gets as far as opening the Link
>Control Protocol, but then immediately fails with a "Couldn't CHAP on port
>S7 - Now allowed" error. We don't have any other users using CHAP.

Is the NT box doing MS-CHAP? The MS CHAP is non-standard and doesn't work
with anyone doing standard CHAP (us). CHAP uses MD5, MS-CHAP uses MD-4 and
then passes it into DES. No real advantage at all, just marketing hype on
their part about how it is better. This was discussed on
comp.protocols.ppp recently.

>Is there anything extra I need to set up on the PM in order to allow CHAP?

The password must be stored in cleartext in the /etc/raddb/users file. CHAP
relies on cleartext passwords and cannot use UNIX passwords.

>something. Or is there something I can have the user change on the NT end
>to make it work? It doesn't seem like any communication at all is

See if they can use PAP instead.

>Sent to port S7: 26 bytes LCP Request-1
> Authentication-Protocol = PAP

We ask for PAP.

>Recvd from port S7: 11 bytes LCP Request-99
> Authentication-Protocol = CHAP 0x80

They ask for CHAP...

But this format is weird - where did we ACK it? Did we?

-MZ

--
Livingston Enterprises - Chair, Department of Interstitial Affairs
Phone: 800-458-9966 510-426-0770 FAX: 510-426-8951 megazone@livingston.com
For support requests: support@livingston.com  <http://www.livingston.com/> 
Snail mail: 6920 Koll Center Parkway  #220, Pleasanton, CA 94566
See me in person: Internet Expo, Boston, MA, October 16-17, Booth 422 ;-)