Ms-chap authentication – H3C Technologies H3C SR8800 User Manual
Page 27

19
Two types of CHAP authentication exist: one-way CHAP authentication and two-way CHAP
authentication. By one-way CHAP authentication, one side of the link acts as the authenticator and the
other acts as the supplicant. By two-way authentication, each side serves as both the authenticator and
the supplicant. Normally, one-way CHAP authentication is used.
In one-way CHAP authentication, the authenticator may or may not be configured with a username. It is
recommended that you configure a username for the authenticator, which makes it easier to identify the
authenticator.
If the authenticator is configured with a username, CHAP authentication is performed as follows:
1.
The authenticator initiates an authentication by sending a randomly-generated packet (Challenge)
to the supplicant. The packet carries the local username with it in addition.
2.
When the supplicant receives the authentication request, it searches the local user list for the
password of the username carried in the received packet, encrypts the packet using the MD5
algorithm, with the packet ID and the password as the parameters, and then sends the encrypted
packet and the local username to the authenticator (Response).
3.
The authenticator encrypts the original randomly-generated packet using the MD5 algorithm, with
the password of the supplicant it maintains as the parameter, compares the encrypted packet with
the one received from the supplicant, and returns an Acknowledge or Not Acknowledge packet
depending on the comparison result.
If the authenticator is not configured with a username, the CHAP authentication is performed as follows:
4.
The authenticator initiates an authentication by sending a randomly-generated packet (Challenge)
to the supplicant.
5.
When the supplicant receives the authentication request, it encrypts the packet using the MD5
algorithm, with the packet ID and the default CHAP password as the parameters, and then sends
the encrypted packet and its own username to the authenticator (Response).
6.
The authenticator encrypts the original randomly-generated packet using the MD5 algorithm, with
the password of the supplicant it maintains as the parameter, compares the encrypted packet with
the one received from the supplicant, and returns an Acknowledge or Not Acknowledge packet
depending on the comparison result.
Figure 8 CHAP Authentication
MS-CHAP authentication
MS-CHAP is a three-way handshake authentication protocol using cipher text password.
- H3C SR6600-X H3C SR6600 H3C MSR 5600 H3C MSR 50 H3C MSR 3600 H3C MSR 30 H3C MSR 2600 H3C MSR 20-2X[40] H3C MSR 20-1X H3C MSR 930 H3C MSR 900 H3C WX6000 Series Access Controllers H3C WX5000 Series Access Controllers H3C WX3000 Series Unified Switches H3C LSWM1WCM10 Access Controller Module H3C LSWM1WCM20 Access Controller Module H3C LSQM1WCMB0 Access Controller Module H3C LSRM1WCM2A1 Access Controller Module H3C LSBM1WCM2A0 Access Controller Module