03-16-2017 09:58 AM
I have two services setup. One is in production using EAP-TLS and working fine. I created another service and cloned the Authentication source used in the production servcice...using EAP-PEAP. In the logs I can see that the EAP-PEAP session establishes. Then there is an eap-mschapv2 challenge issued. I then get the following errors:
|2017-03-16 09:08:16,784||[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - rlm_mschap: authenticating user xxx, domain xxxx|
|2017-03-16 09:08:16,817||[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - rlm_mschap: user xxx authentication failed|
|2017-03-16 09:08:16,817||[Th 21 Req 3234183 SessId R000781e9-01-58cab870] ERROR RadiusServer.Radius - rlm_mschap: AD status:No trusted SAM account (0xc000018b)|
|2017-03-16 09:08:16,818||[Th 21 Req 3234183 SessId R000781e9-01-58cab870] INFO RadiusServer.Radius - MS-Chap User Authentication time = 33 ms|
|2017-03-16 09:08:16,818||[Th 21 Req 3234183 SessId R000781e9-01-58cab870] ERROR RadiusServer.Radius - rlm_mschap: FAILED: MS-CHAP2-Response is incorrect|
Solved! Go to Solution.
03-16-2017 10:09 AM
Thanks for pointing that out. So, we have 3 CPPM servers. 1 of them is joined and the bind account appears to be working becuase I can browse AD. The other 2 aren't joined;howerver, I don't think they are clustered...or done correctly...so not sure if that matters.
But the original Service utilizing the same autentiation source (although different authentication methods) is working just fine.
03-16-2017 10:11 AM
03-16-2017 10:16 AM
Ah, I think I see.
So because the original service is using EAP-TLS, not all servers need to be joined to the domain to work; however, using PEAPv0/EAP-MSCHAPv2, all servers need to be joined for the protocol/authentication to work?
(I didn't set this up and got put on WiFi duty with little experience....so thanks for your patience and time)!
03-16-2017 10:30 AM
That’s why EAP-TLS is the recommended authentication method when possible.
03-16-2017 11:04 AM
Sorry Tim, one more question. The 2 other servers in the cluster I want to add to the domain. I'm dumb with this stuff and wanted to make sure there wouldn't be an outage with the services during this time? I'm assuming not, but wanted to make sure that I put in a change if there was a possibility of CPPM going offline or using a server that isn't fully connected/joined to the domain.
03-16-2017 11:07 AM
03-20-2017 10:53 AM
So after adding all 3 servers to the domain, I'm still getting the same error.
I saw some other posts out there suggesting to unjoin and then join the servers back to the domain. Does that make sense? Is that suggested in this case?