Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    RADIUS authentication fails with ERROR: No NT-Password

    Scheduled Pinned Locked Moved General pfSense Questions
    16 Posts 4 Posters 5.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Sure, and I'd expect it to work, but it's definitely something unusual. I'd want to confirm it's not the cause before doing anything further.

      Steve

      1 Reply Last reply Reply Quote 0
      • A
        andersonshatch
        last edited by

        I encountered this error too on pfSense Community 2.6.0 trying to setup UniFi RADIUS login.
        An account with a password specified can login okay, but one setup to use OTP yields the below failure:

        Login incorrect (mschap: FAILED: No NT-Password.  Cannot perform authentication)
        
        1 Reply Last reply Reply Quote 0
        • M
          MacUsers
          last edited by

          okay, so looks like it's not an isolated case. I tried with one of my Linksys AP and got exactly the same error - that indicates the issue on the RADIUS side but cannot be very sure. Is there any one can help to debug this pls?

          -S

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            And that was also with OTP? Were you able to test anything without OTP to confirm?

            1 Reply Last reply Reply Quote 0
            • D
              dawsnet
              last edited by

              I seem to be getting the same issue's also.

              Pfsense : 2.6.0-RELEASE (amd64)
              Freeraduis: 3: 0.15.7_33
              Access points Unifi

              Auth: (11)   Login incorrect (mschap: FAILED: No NT-Password.  Cannot perform authentication): 
              
              Auth: (12) Login incorrect (eap_peap: The users session was previously rejected: returning reject (again.)):
              

              But if I untick the "Disables weak EAP types: MD5, and GTC" everything connects fine both MAC and Windows devices.

              When ticked the Mac device's prompt twice for login's and then connect but the windows device don't connect..

              Any help would be great.

              Thanks

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                So the clients is trying to use a weak EAP type and in OSX it is able to see that switch to another type but Windows doesn't. There's probably tweak for that in Windows.

                D 1 Reply Last reply Reply Quote 0
                • D
                  dawsnet @stephenw10
                  last edited by

                  @stephenw10 I am using this solution for a flex office so don't really wan't to go about tweaking the devices ;) but cheers for the advice.

                  do you think this issue can be fixed so we don't need to use weak EAP ?

                  Cheers

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Probably not if the clients are using one of those weaker options and do not try anything else.
                    For local wifi auth it's unlikely to be significant risk IMO.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • D
                      dawsnet
                      last edited by

                      Would this even be the case with a fresh install of Windows 10 fully up-to-date as I am getting the same errors 😳

                      Sorry just trying to understand it fully..

                      Cheers

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Not something I've ever looked into but if Windows is choosing to use that I'm not sure what you can do. Maybe radius can indicate why it fails prompting Windows to re-try or send a list of accepted ciphers. Also not something I've had to try.

                        1 Reply Last reply Reply Quote 1
                        • V vLANity referenced this topic on
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.