I configured freeradius which use ldap as a backend database.(in ldap, i stored password in ssha) Because ldap does not support mschap, I Use eap-ttls with pap for authentication. In freeradius server, when I run freeradius in debug mode, I see username and password of client in cleartext.freeradius output
so, as I said before, because I use ldap as a backend database, I can't use mschap (which is the only secure way I know for client to send his password). I just want to know is there another way to send password that is not visible in output of freeradius?
I Found this options in windows, but I don't know if they are useful for my case or not. windows interface configuration
Thanks.