How does pptpd (poptop) or pppd work with eap-tls and mppe-128?
Posted
by Henk
on Server Fault
See other posts from Server Fault
or by Henk
Published on 2009-09-24T14:10:14Z
Indexed on
2010/03/09
11:21 UTC
Read the original article
Hit count: 260
To create a VPN I've installed pptpd on an Ubuntu domU (Debian domUs can also be created). MSCHAPv2 isn't a very strong authentication protocol so I'd like to use EAP-TLS. I've set up a FreeRADIUS server and certificates for EAP-TLS before (for use with WPA), and I've also set up a pptp server with mschap-v2 auth, but I can't figure out how to combine the two. Maybe pppd can use EAP-TLS on its own, but I can't find support for it in the Ubuntu package. If I need to patch the package, that's fine, I know how to patch Debian packages (provided the patch applies cleanly).
Also, can MPPE still be used when pppd is configured to use EAP? Because it says in the manual several times that MPPE requires MSCHAP. However, other docs like this one: http://www.nikhef.nl/~janjust/ppp/ seem to refute that.
The clients are running Mac OS X Leopard and GNU/Linux, there's no need to fix anything for Windows.
© Server Fault or respective owner