[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: RADIUS User-Name versus EAP Identity



Joseph Salowey (jsalowey) wrote:
> [Joe]This is strange, many EAP methods do not rely upon the
> EAP-Response/Identity.  What are the problems you are seeing?   

  The home RADIUS server is rejecting the request because
EAP-Response/Identity does not match the RADIUS User-Name.  This is
happening for most (if not all) RADIUS servers we've tested.

  The common interpretation is that if the fields disagree, then the NAS
is doing something strange.  One problem seen in the past is where the
User-Name in the first EAP packet is set from the EAP-Response/Identity,
but later User-Names are... something else.  This happens without
intermediate proxies, and is a function of a buggy NAS.

  Alan DeKok.

--
to unsubscribe send a message to radiusext-request@ops.ietf.org with
the word 'unsubscribe' in a single line as the message text body.
archive: <http://psg.com/lists/radiusext/>