Two-Factor Authentication support in GNU RADIUS server
Rajeesh Ramanathan <[email protected]> Fri, 23 Oct 2015 19:20:25 +0530
| Newsgroups | gmane.comp.gnu.radius.bugs |
|---|---|
| Message-ID | <CAHn7P3EWcuEyuk9LuFikA5FvEd4UaHPZOfZGj_+23SfRfA3i-Q@mail.gmail.com> |
--===============0283481779034426941==
Content-Type: multipart/alternative; boundary=089e0112c50cc4eab00522c5e455
--089e0112c50cc4eab00522c5e455
Content-Type: text/plain; charset=UTF-8
Hi,
We are trying to test two-factor authentication using RADIUS server.
*Two-Factor Authentication:*
* First level authentication using username/password
* Second level authentication using the OTP
*RADIUS FLOW:*
*User* *NAS*
*RADIUS server*
Telnet/SSH to NAS
using Username & --------> ACCESS-REQUEST -----------> Authenticates
Username & password
password
Prompt the user
for OTP input <-------------------- <-----------------
ACCESS-CHALLENGE
User enters OTP --------> ACCESS-REQUEST ----------->
Authenticates OTP via external OTP verification script
User logs in
successfully <-------------------- <-----------------
ACCESS-ACCEPT
Could you please confirm whether this RADIUS flow (two-factor
authentication) is feasible using GNU RADIUS server for PAP & CHAP users.
--
Regards,
Rajeesh.R
--089e0112c50cc4eab00522c5e455
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr">Hi,<div><br></div><div>We are trying to test two-factor au=
thentication using RADIUS server.</div><div><br></div><div><b>Two-Factor Au=
thentication:</b></div><div>=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 * Fir=
st level authentication using username/password</div><div>=C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 * Second level=C2=A0authentication using the OTP</=
div><div><br></div><div><u><b>RADIUS FLOW:</b></u></div><div><br></div><div=
><u>User</u> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0=
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0<u>NAS</u> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<u>RADIUS server=
</u></div><div>Telnet/SSH to NAS=C2=A0</div><div>using Username & =C2=
=A0--------> =C2=A0 <span style=3D"background-color:rgb(255,255,0)">ACCE=
SS-REQUEST</span> =C2=A0-----------> Authenticates Username & passwo=
rd</div><div>password</div><div><br></div><div>Prompt the user=C2=A0</div><=
div>for OTP input =C2=A0 =C2=A0 =C2=A0 <-------------------- =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 <----------------- =C2=A0 =C2=A0<span style=3D"=
background-color:rgb(255,255,0)">ACCESS-CHALLENGE</span><br clear=3D"all"><=
div><br></div><div>User enters OTP =C2=A0 --------> =C2=A0 <span style=
=3D"background-color:rgb(255,255,0)">ACCESS-REQUEST</span> =C2=A0 =C2=A0 =
=C2=A0 -----------> Authenticates OTP via external OTP verification scri=
pt</div><div><br></div><div><div>User logs in =C2=A0</div><div>successfully=
=C2=A0 =C2=A0 =C2=A0 <-------------------- =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 <----------------- =C2=A0 =C2=A0<span style=3D"background-color:r=
gb(255,255,0)">ACCESS-ACCEPT</span></div></div><div><br></div><div>Could yo=
u please confirm whether this RADIUS flow (two-factor authentication) is fe=
asible using GNU RADIUS server for PAP & CHAP users.</div><div><br></di=
v>-- <br><div class=3D"gmail_signature">Regards,<div>Rajeesh.R</div></div>
</div></div>
--089e0112c50cc4eab00522c5e455--
--===============0283481779034426941==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
Bug-gnu-radius mailing list
[email protected]
https://lists.gnu.org/mailman/listinfo/bug-gnu-radius
--===============0283481779034426941==--