Peap Mschapv2
Protected Extensible Authentication Protocol (PEAP) comes in a couple of variations. PEAP version 0 uses MS-CHAPv2 (Microsoft Challenge Handshake Authentication Protocol version 2). PEAP version 1 uses GTC (generic token card). However, PEAP using MS-CHAPv2 is far more widely deployed than PEAP using a generic token card.
Cisco Systems, Microsoft, and RSA Security collaborated on the development of PEAP with MS-CHAPv2. PEAP increases protection of authentication messages by creating a protected TLS tunnel. Then, within the protection of the TLS tunnel, an authentication protocol, such as MS-CHAPv2, can be used. Specifically, even though an authentication protocol might be susceptible to attacks (such as a dictionary attack) when used independently, even a "vulnerable" authentication protocol can be used. This is because those authentication messages are sent securely within a TLS tunnel.
Notice in Figure 6-18 that MS-CHAPv2 challenge and response messages are exchanged between the supplicant and the authentication server within the protection of a TLS tunnel. This approach allows the supplicant and authentication server to mutually authenticate, without requiring the supplicant to have a digital certification. This was a requirement for EAP-TLS.
Figure 6-18 EAP with MS-CHAPv2
(Supplicant) &
802.1x-Enabled Switch (Authenticator)
RADIUS Server (Authentication Server)
EAPOL Start Frame
EAP Identity Request
EAP Identity Response
EAP Request and TLS Start Frame
TLS Tunnel Formed
EAP Response/TLS Client Hello
Server Certificate and Certificate Request
Updated Cipher Suite
EAP Request and Cipher Suite Confirmation
EAP Identity Response
MS-CHAPv2 Challenge
MS-CHAPv2 Response
Success Notification
EAP Identity Response
EAP Request and TLS Start Frame
EAP Response/TLS Client Hello
Server Certificate and Certificate Request
Updated Cipher Suite
EAP Request and Cipher Suite Confirmation
EAP Identity Response
MS-CHAPv2 Challenge
MS-CHAPv2 Response
Success Notification
Continue reading here: Understanding the Types of Buffer Overflows
Was this article helpful?