Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    freeradius3 - mschap: FAILED: No NT-Password

    Scheduled Pinned Locked Moved General pfSense Questions
    11 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vLANity
      last edited by

      Saw the link in the recent news letter to the article about setting up 2FA via freeradius... I get the following error when attempting to connect an actual wifi client (Unifi AP):

      Login incorrect (mschap: FAILED: No NT-Password. Cannot perform authentication): [iphone] (from client AP port 0 via TLS tunnel)
      

      My freeradius setup authenticates non-2FA users.

      • I can successfully authenticate using 2FA via the Diagnostic > Authentication only
      • I've read this thread, applied changes but no effect.
      • I tried re-installing the package, but the existing settings weren't purged as part of the operation - would appreciate help for how to be able to start from scratch.

      Pertinent:

      • freeradius3: 0.15.10
      • pfsense: 23.05.1-RELEASE (amd64)
      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Hmm, what exactly are you trying to log into there?

        It works as expected in the local auth test?

        V 1 Reply Last reply Reply Quote 0
        • V
          vLANity @stephenw10
          last edited by

          iphone > Unifi AP > pfense/freeradius

          stephenw10 said in freeradius3 - mschap: FAILED: No NT-Password:

          It works as expected in the local auth test?

          Yes, I believe that's what my first bullet states

          stephenw10S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator @vLANity
            last edited by

            @vLANity said in freeradius3 - mschap: FAILED: No NT-Password:

            Yes, I believe that's what my first bullet states

            Ah, so it does! 😉

            Ok, so you are using this for 802.1x auth to the access point rather than OpenVPN as shown in the article? Did you try using it for OpenVPN?

            Yeah reading through that other thread it sure seems the same. You are running a newer pfSense version. I wonder if the those older EAP types were deprecated.

            Do you see the same failure from any client type?

            V 1 Reply Last reply Reply Quote 0
            • V
              vLANity @stephenw10
              last edited by

              @stephenw10 said in freeradius3 - mschap: FAILED: No NT-Password:

              ...you are using this for 802.1x auth to the access point rather than OpenVPN as shown in the article? Did you try using it for OpenVPN?

              Correct; I have no need for OpenVPN at this time.

              Yeah reading through that other thread it sure seems the same. You are running a newer pfSense version. I wonder if the those older EAP types were deprecated.

              True; my concern is that my freeradius setup has seen so many alterations which may have rendered the fix in the reference thread useless. Hence why I was asking how to purge in order to setup from stock (as demonstrated in the original article)...

              Do you see the same failure from any client type?

              I tried various types, various combinations. I'm unclear on what you mean by "client", the terminology is overused so wanna make sure I know you're referring to the freeradius client vs iphone/etc. I haven't tested with tablet, but anticipate same as iphone.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Sorry I meant Windows, MacOS, Linux, iOS etc. The other user reported Windows failed entirely whereas MacOS eventually succeeded. Implying it tried more EAP types and eventually tried one that worked. Also that it started out with the least secure types....

                V 1 Reply Last reply Reply Quote 0
                • V
                  vLANity @stephenw10
                  last edited by

                  Only iOS clients to date, using what I understand to be the various insecure EAP types. Which again, I suspect there could be an issue with a legacy configuration change I've made that I'm unaware of that is impacting testing...

                  No plans for Win/Mac/Android.

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    It would be a good test though since we know it worked after some tries in MacOS in earlier versions.

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      vLANity @stephenw10
                      last edited by

                      Can not test what I do not have

                      NogBadTheBadN 1 Reply Last reply Reply Quote 0
                      • NogBadTheBadN
                        NogBadTheBad @vLANity
                        last edited by NogBadTheBad

                        @vLANity Here is what mine is set to no issues connecting IOS devices:-

                        Screenshot 2023-09-09 at 08.37.02.png

                        It also works fine with my Mac Pro, but that's at home so kinda pointless :)

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        V 1 Reply Last reply Reply Quote 0
                        • V
                          vLANity @NogBadTheBad
                          last edited by

                          @NogBadTheBad Thanks? I added IPsec as was previously not using...

                          Still - no change re: original issue:

                          • iOS device over wifi (Unifi AP) using 2FA: can NOT authenticate
                          • Diagnostic > Authentication: The same user authenticates using 2FA
                          • Log reports as listed in thread title
                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.