Protected Extensible Authentication Protocol

PEAP is also an acronym for Personal Egress Air Packs.

The Protected Extensible Authentication Protocol, also known as Protected EAP or simply PEAP, is a protocol that encapsulates the Extensible Authentication Protocol (EAP) within an encrypted and authenticated Transport Layer Security (TLS) tunnel.[1][2][3][4] The purpose was to correct deficiencies in EAP; EAP assumed a protected communication channel, such as that provided by physical security, so facilities for protection of the EAP conversation were not provided.[5]

PEAP was jointly developed by Cisco Systems, Microsoft, and RSA Security. PEAPv0 was the version included with Microsoft Windows XP and was nominally defined in draft-kamath-pppext-peapv0-00. PEAPv1 and PEAPv2 were defined in different versions of draft-josefsson-pppext-eap-tls-eap. PEAPv1 was defined in draft-josefsson-pppext-eap-tls-eap-00 through draft-josefsson-pppext-eap-tls-eap-05,[6] and PEAPv2 was defined in versions beginning with draft-josefsson-pppext-eap-tls-eap-06.[7]

The protocol only specifies chaining multiple EAP mechanisms and not any specific method.[3][8] However, use of the EAP-MSCHAPv2 and EAP-GTC methods are the most commonly supported.[citation needed]

Overview

PEAP is similar in design to EAP-TTLS, requiring only a server-side PKI certificate to create a secure TLS tunnel to protect user authentication, and uses server-side public key certificates to authenticate the server. It then creates an encrypted TLS tunnel between the client and the authentication server. In most configurations, the keys for this encryption are transported using the server's public key. The ensuing exchange of authentication information inside the tunnel to authenticate the client is then encrypted and user credentials are safe from eavesdropping.

As of May 2005, there were two PEAP sub-types certified for the updated WPA and WPA2 standard. They are:

  • PEAPv0/EAP-MSCHAPv2
  • PEAPv1/EAP-GTC

PEAPv0 and PEAPv1 both refer to the outer authentication method and are the mechanisms that create the secure TLS tunnel to protect subsequent authentication transactions. EAP-MSCHAPv2 and EAP-GTC refer to the inner authentication methods which provide user or device authentication. A third authentication method commonly used with PEAP is EAP-SIM.

Within Cisco products, PEAPv0 supports inner EAP methods EAP-MSCHAPv2 and EAP-SIM while PEAPv1 supports inner EAP methods EAP-GTC and EAP-SIM. Since Microsoft only supports PEAPv0 and doesn't support PEAPv1, Microsoft simply calls it "PEAP" without the v0 or v1 designator. Another difference between Microsoft and Cisco is that Microsoft only supports the EAP-MSCHAPv2 method and not the EAP-SIM method.

However, Microsoft supports another form of PEAPv0 (which Microsoft calls PEAP-EAP-TLS) that many Cisco and other third-party server and client software don't support. PEAP-EAP-TLS requires client installation of a client-side digital certificate or a more secure smartcard. PEAP-EAP-TLS is very similar in operation to the original EAP-TLS but provides slightly more protection because portions of the client certificate that are unencrypted in EAP-TLS are encrypted in PEAP-EAP-TLS. Ultimately, PEAPv0/EAP-MSCHAPv2 is by far the most prevalent implementation of PEAP, due to the integration of PEAPv0 into Microsoft Windows products. Cisco's CSSC client (discontinued in 2008 [9]) now supports PEAP-EAP-TLS.

PEAP has been so successful in the market place that even Funk Software (acquired by Juniper Networks in 2005), the inventor and backer of EAP-TTLS, added support for PEAP in their server and client software for wireless networks.

PEAPv0 with EAP-MSCHAPv2

MS-CHAPv2 is an old authentication protocol which Microsoft introduced with NT4.0 SP4 and Windows 98.

PEAPv0/EAP-MSCHAPv2 is the most common form of PEAP in use, and what is usually referred to as PEAP. The inner authentication protocol is Microsoft's Challenge Handshake Authentication Protocol, meaning it allows authentication to databases that support the MS-CHAPv2 format, including Microsoft NT and Microsoft Active Directory.

Behind EAP-TLS, PEAPv0/EAP-MSCHAPv2 is the second most widely supported EAP standard in the world. There are client and server implementations of it from various vendors, including support in all recent releases from Microsoft, Apple Computer and Cisco. Other implementations exist, such as the xsupplicant from the Open1x.org project, and wpa_supplicant.

As with other 802.1X and EAP types, dynamic encryption can be used with PEAP.

A CA certificate must be used at each client to authenticate the server to each client before the client submits authentication credentials. If the CA certificate is not validated, in general it is trivial to introduce a fake Wireless Access Point which then allows gathering of MS-CHAPv2 handshakes.[10]

Several weaknesses have been found in MS-CHAPv2, some of which severely reduce the complexity of brute-force attacks making them feasible with modern hardware.[11]

PEAPv1 with EAP-GTC

PEAPv1/EAP-GTC was created by Cisco to provide interoperability with existing token card and directory based authentication systems via a protected channel. Even though Microsoft co-invented the PEAP standard, Microsoft never added support for PEAPv1 in general, which means PEAPv1/EAP-GTC has no native Windows OS support. Since Cisco has typically recommended lightweight EAP protocols such as LEAP and EAP-FAST protocols instead of PEAP, the latter has not been as widely adopted as some had hoped.

With no interest from Microsoft to support PEAPv1 and no promotion from Cisco, PEAPv1 authentication is rarely used.[when?] Even in Windows 7, released in late 2009, Microsoft has not added support for any other authentication system other than MSCHAPv2.

Nokia E66 and later mobile phones ship with a version of Symbian which includes EAP-GTC support.

LDAP (Lightweight Directory Access Protocol) only supports EAP-GTC.[citation needed]

References

  1. ^ "Understanding the updated WPA and WPA2 standards". ZDNet. 2005-06-02. Retrieved 2012-07-17.
  2. ^ Microsoft's PEAP version 0, draft-kamath-pppext-peapv0-00, §1.1
  3. ^ a b Protected EAP Protocol (PEAP) Version 2, draft-josefsson-pppext-eap-tls-eap-10, abstract
  4. ^ Protected EAP Protocol (PEAP) Version 2, draft-josefsson-pppext-eap-tls-eap-10, §1
  5. ^ Protected EAP Protocol (PEAP) Version 2, draft-josefsson-pppext-eap-tls-eap-07, §1
  6. ^ Protected EAP Protocol (PEAP), draft-josefsson-pppext-eap-tls-eap-05, §2.3
  7. ^ Protected EAP Protocol (PEAP), draft-josefsson-pppext-eap-tls-eap-06, §2.3
  8. ^ Protected EAP Protocol (PEAP) Version 2, draft-josefsson-pppext-eap-tls-eap-10, §2
  9. ^ "End-of-Sale and End-of-Life Announcement for the Cisco Secure Services Client v4.0". Cisco. Retrieved 2021-05-04.
  10. ^ "Man-in-the-Middle in Tunneled Authentication Protocols" (PDF). Nokia Research Center. Retrieved 14 November 2013.
  11. ^ "Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate". 2016-03-16. Archived from the original on 2016-03-16. Retrieved 2022-10-19.

Read other articles:

Olsen Bersaudara (Brødrene Olsen)Noller (kiri) dan Jørgen Olsen (kanan)Informasi latar belakangAsalDenmarkTahun aktif1972–sekarangSitus webhttp://www.olsen-brothers.dk/AnggotaJørgen OlsenNiels Noller Olsen Olsen Bersaudara (bahasa Denmark: Brødrene Olsen) adalah sebuah duo musik rock/pop Denmark, yang dibentuk oleh kakak beradik Jørgen (kelahiran 15 Maret 1950) dan Noller (Niels, kelahiran 13 April 1954) Olsen yang memenangkan Kontes Lagu Eurovision 2000.[1] Mereka membentuk grup …

Markhor Status konservasi Hampir Terancam (IUCN 3.1) Klasifikasi ilmiah Kerajaan: Animalia Filum: Chordata Kelas: Mamalia Ordo: Artiodactyla Famili: Bovidae Subfamili: Caprinae Genus: Capra Spesies: C. falconeri Nama binomial Capra falconeri(Wagner, 1839) Markhor (Capra falconeri; bahasa Pashto: مرغومی marǧūmi; bahasa Persia / Urdu: مارخور) atau kambing tanduk-ulir adalah spesies kambing liar yang ditemukan di timur laut Afganistan, utara dan tengah Pakistan, negara bagia…

  لمعانٍ أخرى، طالع ماريا آنا من بافاريا (توضيح). ماري آن فيكتوار من بافاريا معلومات شخصية الميلاد 28 نوفمبر 1660(1660-11-28)ميونخ الوفاة 20 أبريل 1690 (29 سنة)فرساي مكان الدفن كاتدرائية سان دوني  الزوج لويس، دوفين الأكبر (7 مارس 1680–)  الأولاد فيليب الخامس ملك إسبانيالويس، دوق بو…

The Metropolitan Museum of ArtLokasi The Metropolitan Museum of Art di New York CityDidirikan1870[1][2]Lokasi5th Avenue dan 82nd Street, Manhattan, New YorkWisatawan5.2 million (2008)[1]4.9 million (2009)[3] Peringkat pertama nasioanl Peringkat ketiga global DirekturThomas P. CampbellAkses transportasi umum86th Street (IRT Lexington Avenue Line)Situs webhttp://www.metmuseum.org/ The Metropolitan Museum of Art (dijuluki The Met) adalah museum seni di ujung timur Ce…

Регионы Молдавского княжества:      — Цара-де-Жос;     — Цара-де-Сус;     — (Бессарабия). История Молдавии Доисторический период (1 млн. л. н. — IV в. до н. э) Культура Триполье-Кукутень (середина 5-го тысячелетия до н. э. — 2650-е годы до н. э.) Гето-…

Eparki Santo Vladimir-Le-Grand de ParisEparchia Sancti Vladimiri Magni in urbe Parisiensi pro Ucrainis ritus ByzantiniDiocèse de Saint-Vladimir-le-Grand de ParisGereja Katolik Yunani Ukraina Katedral St. VladimirLokasiNegara PrancisMetropolitSubyek langsung Tahta SuciStatistikPopulasi- Katolik(per 2013)25,400Paroki16InformasiDenominasiGereja Katolik Yunani UkrainaGereja sui iurisGereja Katolik Yunani UkrainaRitusRitus BizantiumPendirian22 Juli 1960KatedralKatedral St. Vladimir di…

Si ce bandeau n'est plus pertinent, retirez-le. Cliquez ici pour en savoir plus. Cet article ne cite pas suffisamment ses sources (janvier 2013). Si vous disposez d'ouvrages ou d'articles de référence ou si vous connaissez des sites web de qualité traitant du thème abordé ici, merci de compléter l'article en donnant les références utiles à sa vérifiabilité et en les liant à la section « Notes et références ». En pratique : Quelles sources sont attendues ? Comm…

وزارة عاطف عبيدمعلومات عامةالبلد مصر الاختصاص مصر التكوين 10 أكتوبر 1999 النهاية 15 يوليو 2004 المدة 4 سنواتٍ و9 أشهرٍ و5 أيامٍوزارة كمال الجنزوري الأولى وزارة أحمد نظيف الأولى تعديل - تعديل مصدري - تعديل ويكي بيانات وزارة عاطف عبيد هي الوزارة الثالثة عشر بعد المائة في تاريخ مصر. كُ…

This article is an orphan, as no other articles link to it. Please introduce links to this page from related articles; try the Find link tool for suggestions. (January 2022) Neighborhood in Montgomery, Ohio, United StatesGrantland GardensNeighborhoodAerial view of Old Lane Park in Grantland GardensCoordinates: 39°39′49.83″N 84°10′47.22″W / 39.6638417°N 84.1797833°W / 39.6638417; -84.1797833CountryUnited StatesStateOhioCountyMontgomeryTownshipWashingtonArea…

العلاقات الكويتية الإسواتينية الكويت إسواتيني   الكويت   إسواتيني تعديل مصدري - تعديل   العلاقات الكويتية الإسواتينية هي العلاقات الثنائية التي تجمع بين الكويت وإسواتيني.[1][2][3][4][5] مقارنة بين البلدين هذه مقارنة عامة ومرجعية للدولتين: وجه ال…

StadiaPeranti bergerak yang menjalankan Stadia dengan kontroller resmiPengembangGoogleSistem operasiPlatform silangSitus webstadia.com Stadia adalah sebuah layanan cloud game yang dioperasikan oleh Google. Layanan tersebut dikatakan dapat menyiarkan permainan video sampai 4K dalam 60 frame per detik dengan dukungan rangkaian dinamis tingkat tinggi, untuk para pemain melalui sejumlah pusat data perusahaan tersebut di seluruh dunia, yang menyediakannya memakai koneksi internet berkecepatan tinggi.…

Cet article est une ébauche concernant une entreprise chinoise et Hong Kong. Vous pouvez partager vos connaissances en l’améliorant (comment ?). Une page sur une entreprise étant sujette à controverse, n’oubliez pas d’indiquer dans l’article les critères qui le rendent admissible. Pour les articles homonymes, voir Watson. Groupe A.S. Watson Création 1828 Slogan « We Bring More to Life »(« Nous apportons plus à la vie ») Siège social Sha Tin Hong …

Pengguna ini sedang sibuk di dunia nyata dan mungkin tidak menanggapi pesan dengan cepat. Halo! Selamat datang di Wikipedia Bahasa Indonesia! Memulai Memulai Para pengguna baru dapat melihat halaman Pengantar Wikipedia terlebih dahulu. Anda bisa mengucapkan selamat datang kepada Wikipediawan lainnya di Halaman perkenalan. Untuk mencoba-coba menyunting, silakan gunakan bak pasir. Baca juga aturan yang disederhanakan sebelum melanjutkan. Ini adalah hal-hal mendasar yang perlu diketahui oleh semua …

B

  此條目介紹的是拉丁字母中的第2个字母。关于其他用法,请见「B (消歧义)」。   提示:此条目页的主题不是希腊字母Β、西里尔字母В、Б、Ъ、Ь或德语字母ẞ、ß。 BB b(见下)用法書寫系統拉丁字母英文字母ISO基本拉丁字母(英语:ISO basic Latin alphabet)类型全音素文字相关所属語言拉丁语读音方法 [b][p][ɓ](适应变体)Unicode编码U+0042, U+0062字母顺位2数值 2歷史發展…

Process by which an organism grows from a spore or seed Not to be confused with Gemination or Germanization. Sunflower seedlings, three days after germination Sunflower time lapse with soil. cross section, showing how the root and the upper part of the plant grow Germination is the process by which an organism grows from a seed or spore. The term is applied to the sprouting of a seedling from a seed of an angiosperm or gymnosperm, the growth of a sporeling from a spore, such as the spores of fun…

Species of carnivore Colombian weasel Conservation status Vulnerable  (IUCN 3.1)[1] Scientific classification Domain: Eukaryota Kingdom: Animalia Phylum: Chordata Class: Mammalia Order: Carnivora Family: Mustelidae Genus: Neogale Species: N. felipei Binomial name Neogale felipei(Izor and de la Torre, 1978) Colombian weasel range Synonyms Mustela felipei The Colombian weasel (Neogale felipei), also known as Don Felipe's weasel, is a very rare species of weasel only known with ce…

«Последний еврей Винницы» Часть серии статей о Холокосте Идеология и политика Расовая гигиена · Расовый антисемитизм · Нацистская расовая политика · Нюрнбергские расовые законы Шоа Лагеря смерти Белжец · Дахау · Майданек · Малый Тростене…

River in Louisiana, United StatesRigoletsThe abandoned West Rigolets Light in 2004. It was destroyed by Hurricane Katrina in 2005.NOAA Coast Survey nautical map 2016LocationCountryUnited StatesStateLouisianaPhysical characteristicsSourceLake Pontchartrain • coordinates30°10′40″N 89°44′40″W / 30.177778°N 89.744444°W / 30.177778; -89.744444 MouthLake Borgne • coordinates30°09′16″N 89°37′31″W / 30.154…

Italian painter (1881–1918) Adriana Bisi FabbriAdriana Bisi Fabbri , Autoritratto, 1914BornAdriana Fabbri1881 (1881)Ferrara, ItalyDied1918 (aged 36–37)Travedona-Monate, ItalyNationalityItalianKnown forPaintingSpouseGiannetto Bisi All'ippodromo, 1913 (Art collections of Fondazione Cariplo) Adriana Bisi Fabbri (1881–1918) was an Italian painter. Biography Adriana Fabbri was born in Ferrara, where she met her future husband, journalist Giannetto Bisi, and she spent part of …

Bermuda RailwayBermuda Railway (in red) between St. George's, Hamilton, and Somerset in Sandys ParishOverviewStatusPartially converted to rail trailLocaleBermudaTerminiSt. George'sSomersetServiceTypeCommon carrierServices2Depot(s)HamiltonHistoryOpened1931 (1931)Closed1948TechnicalLine length21.7 mi (34.9 km)Track gauge4 ft 8+1⁄2 in (1,435 mm) standard gauge Route map Legend Somerset Broom Street Scott's Hill Road Sound View Road Somerset Bridge Brid…

Kembali kehalaman sebelumnya