Two-Factor Authentication support in GNU RADIUS server

Rajeesh Ramanathan <[email protected]> Fri, 23 Oct 2015 19:20:25 +0530
Newsgroups gmane.comp.gnu.radius.bugs
Message-ID <CAHn7P3EWcuEyuk9LuFikA5FvEd4UaHPZOfZGj_+23SfRfA3i-Q@mail.gmail.com>
--===============0283481779034426941==
Content-Type: multipart/alternative; boundary=089e0112c50cc4eab00522c5e455

--089e0112c50cc4eab00522c5e455
Content-Type: text/plain; charset=UTF-8

Hi,

We are trying to test two-factor authentication using RADIUS server.

*Two-Factor Authentication:*
            * First level authentication using username/password
            * Second level authentication using the OTP

*RADIUS FLOW:*

*User*                                              *NAS*
         *RADIUS server*
Telnet/SSH to NAS
using Username &  -------->   ACCESS-REQUEST  -----------> Authenticates
Username & password
password

Prompt the user
for OTP input       <--------------------           <-----------------
ACCESS-CHALLENGE

User enters OTP   -------->   ACCESS-REQUEST       ----------->
Authenticates OTP via external OTP verification script

User logs in
successfully       <--------------------           <-----------------
ACCESS-ACCEPT

Could you please confirm whether this RADIUS flow (two-factor
authentication) is feasible using GNU RADIUS server for PAP & CHAP users.

-- 
Regards,
Rajeesh.R

--089e0112c50cc4eab00522c5e455
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Hi,<div><br></div><div>We are trying to test two-factor au=
thentication using RADIUS server.</div><div><br></div><div><b>Two-Factor Au=
thentication:</b></div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 * Fir=
st level authentication using username/password</div><div>=C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 * Second level=C2=A0authentication using the OTP</=
div><div><br></div><div><u><b>RADIUS FLOW:</b></u></div><div><br></div><div=
><u>User</u> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0<u>NAS</u> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<u>RADIUS server=
</u></div><div>Telnet/SSH to NAS=C2=A0</div><div>using Username &amp; =C2=
=A0--------&gt; =C2=A0 <span style=3D"background-color:rgb(255,255,0)">ACCE=
SS-REQUEST</span> =C2=A0-----------&gt; Authenticates Username &amp; passwo=
rd</div><div>password</div><div><br></div><div>Prompt the user=C2=A0</div><=
div>for OTP input =C2=A0 =C2=A0 =C2=A0 &lt;-------------------- =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 &lt;----------------- =C2=A0 =C2=A0<span style=3D"=
background-color:rgb(255,255,0)">ACCESS-CHALLENGE</span><br clear=3D"all"><=
div><br></div><div>User enters OTP =C2=A0 --------&gt; =C2=A0 <span style=
=3D"background-color:rgb(255,255,0)">ACCESS-REQUEST</span> =C2=A0 =C2=A0 =
=C2=A0 -----------&gt; Authenticates OTP via external OTP verification scri=
pt</div><div><br></div><div><div>User logs in =C2=A0</div><div>successfully=
 =C2=A0 =C2=A0 =C2=A0 &lt;-------------------- =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 &lt;----------------- =C2=A0 =C2=A0<span style=3D"background-color:r=
gb(255,255,0)">ACCESS-ACCEPT</span></div></div><div><br></div><div>Could yo=
u please confirm whether this RADIUS flow (two-factor authentication) is fe=
asible using GNU RADIUS server for PAP &amp; CHAP users.</div><div><br></di=
v>-- <br><div class=3D"gmail_signature">Regards,<div>Rajeesh.R</div></div>
</div></div>

--089e0112c50cc4eab00522c5e455--


--===============0283481779034426941==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Bug-gnu-radius mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/bug-gnu-radius

--===============0283481779034426941==--