Wireless Access

last person joined: 31 minutes ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

This thread has been viewed 3 times
  • 1.  EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    Posted Nov 25, 2018 05:52 PM

    Hey All,

     

    Just general question. Testing some stuff around RADIUS. Using EAP-PEAP flavour, as the first step when you connect to the SSID, you get prompt to enter username/password:dd.JPG

     

     

    In monitor mode PCAP l see frames as EAP-Request/Response-Identity, but l cannot figure out how the password is delivered to the AP (l do not even see any hash or anything encrypted) and l can only see username:

    EAP.JPG

    Thanks,

    Myky



  • 2.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    EMPLOYEE
    Posted Nov 26, 2018 11:46 AM
    At the point of receiving the credential prompt, no credentials have been sent.


  • 3.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    Posted Nov 26, 2018 03:20 PM

    @cappalli that is totally true. Monitor mode PCAP was taken while l was entering the credentials and when the authentication failed. I do see my username was sent (smuser1) but there was no password in PCAP. That also makes sense because that is the job of NAS to deliver credentials via RADIUS protocol and encrypt the username password as we still can see username in the RADIUS Access-Request packet. 

    But it must be somehow delivered to the AP via air.



  • 4.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.
    Best Answer

    EMPLOYEE
    Posted Nov 26, 2018 03:34 PM
    That is the outer username. The inner username and credential are encapsulated and encrypted into an EAP exchange.


  • 5.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    Posted Nov 27, 2018 12:24 PM

    Found this:

    https://www.arubanetworks.com/techdocs/ClearPass/Aruba_DeployGd_HTML/Content/A%20802.1X%20EAP-PEAP%20Reference/EAP_PEAP_handshake.htm

    It looks like even client is prompt to enter username and password, only username is sent over the air. Then full EAP-PEAP process kicks in where the client sends its identity that includes a password. 

     

    Thanks,

    Myky



  • 6.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    EMPLOYEE
    Posted Nov 27, 2018 12:30 PM
    The outer username and the inner username are not always the same. The outer username should be anonymized.


  • 7.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    Posted Nov 27, 2018 12:33 PM

    Thanks Tim. Do you have any good KB that explains this? 



  • 8.  RE: EAP-Request/Response-Identity. Cannot figure out how password is delivered to AP.

    EMPLOYEE
    Posted Nov 27, 2018 12:50 PM
    None of this is Aruba-specific. It’s all standards.