How does freeradius authentication working with Microsoft Active Directory?

Viewed 425

I recently built a lab environment which I want to test 802.1x features on our network facility, Freeradius as the alternative radius server in this lab, we don't use users file, we want FR to us MS AD 2016 as external user source, prefered PEAP+mschapv2.

In my test, I followed this site [http://deployingradius.com/documents/configuration/active_directory.html] and the following test is confirmed.

  1. Prefered authentication method, PEAP + mschapv2, config ntlm_auth module to get NTkey from MS AD for autheticcation, this working fine, In lab I installed FR in ubuntu, but I realize in our production environment, we use FreeRadius in pfsense OS, so it looks impossible because pfsense doesn't provide samba and krb packages.
  2. use LDAP bind against AD for authentication, this is tested both worked both in FR in ubuntu and pfsense, however again, this is limit to EAP-ttls + PAP authentication method, not preferred auth method.

so, my confusion, with requirement of PEAP,MSCHAP, is there a third way of getting Freeradius working with AD in pfsense OS without samba/krb support in pfsense? To be precise, I'm thinking that MS AD store NT-hashed pw instead of plain text pw, FR LDAP module cann't retrieve NT-Hash Password from AD for auth without samba support, am I right?

0 Answers
Related