Re: PEAP TLV TYpe 8 and Fast Reconnect



Wei Zheng,

I forgot to mention that I have two dll's - authorization dll that looks for
absence of ratClearTextPassword, queries SQL2K database, and adds it to the
outbound attributes. The authorization dll looks for
access-request->challenge-response->presence of ratEAPTLV with EAPTVLSTATUS
success, and deletes that attribute from the inbound, adds the new EAPTLVURI
and the EAPTLVSTATUS success back to the outbound attributes. My thinking
was that maybe the client side needed to find EAPTVLSTATUS as the last
EAPTLV. Looking at IASSAM, the total length of the EAP-Message attribute is
approx. 30 bytes greater than the length of EAPTLVURI and EAPTLVSTATUS. If
it will help, I can post the IASSAM but why does turning off Fast-Reconnect
make it work? A timing issue?

Many thanks for your help in getting this resolved.

Regards,

Bernard.


.


Loading