802.1X WLAN Survivability
With the WLAN Survivability feature enabled, the RUCKUS device caches the user's credentials for reuse in the event of disconnection from the AAA server.
Complete the following steps to configure WLAN Survivability for 802.1X WLAN clients.
- Select and click Add. Alternatively, click the checkbox for the specific Wi-Fi network that you want to configure, then click Edit. The Edit Wi-Fi Network page is displayed.
- For Name, enter a name for the Wi-Fi network.
- For Usage Type, select Standard.
- For Authentication Method, select 802.1X EAP.
- For Encryption Method, select WPA3.
- For Authentication Server, select a RADIUS authentication server from the list or click Add to create a new RADIUS authentication server.
- For WLAN Survivability, select Enabled.
- For Cache Time, enter a value in hours (from 1 through 128) to cache the user credentials.
- (Optional) For Accounting Server, select a RADIUS accounting server from the list or click Add to create a new RADIUS accounting server.
- Click
Apply to save your changes.
The RUCKUS controller will send the RADIUS request with the attribute:
RADIUS_RUCKUS_AUTH_SURVIVABILITY = 15after enabling the survivability feature.The RADIUS server must have the capability of recognizing the request and answering with the following attributes in the access-accept message:
RADIUS_RUCKUS_USER_NAME = 16 , /*Survivability-Usr-Name*/ RADIUS_RUCKUS_PASSWORD_NT_HASH = 17 /*Survivability-MD5-NT-Passwd*/.How the RADIUS server calculates the two new attributes:
RADIUS_RUCKUS_USER_NAME: This is the user name created in the RADIUS server.RADIUS_RUCKUS_PASSWORD_NT_HASH: This is a 32 byte binary data value. RADIUS uses the following steps to create this attribute:- The server generates a Windows NT hash of the user’s password using the MS_CHAPv2 algorithm.
- It uses the first
random 16 bytes as an authenticator and the shared secret to
encrypt the data generated by the previous step via MD5 as a
user password does (refer to RFC 2865, Chapter 5.2). The
following is a code snippet of the user password encryption
algorithm:
struct radius_attr_hdr * radius_msg_add_attr_user_password(struct radius_msg *msg, TAC_U8 *data, size_t data_len, TAC_U8 *secret, size_t secret_len) { TAC_U8 buf[128]; int padlen, i, pos; MD5_CTX context; size_t buf_len; TAC_U8 hash[16]; if (data_len > 128) return NULL; memcpy(buf, data, data_len); buf_len = data_len; padlen = data_len % 16; if (padlen) { padlen = 16 - padlen; memset(buf + data_len, 0, padlen); buf_len += padlen; } MD5Init(&context); MD5Update(&context, secret, secret_len); MD5Update(&context, msg->hdr->authenticator, 16); MD5Final(hash, &context); for (i = 0; i < 16; i++) buf[i] ^= hash[i]; pos = 16; while (pos < buf_len) { MD5Init(&context); MD5Update(&context, secret, secret_len); MD5Update(&context, &buf[pos - 16], 16); MD5Final(hash, &context); for (i = 0; i < 16; i++) buf[pos + i] ^= hash[i]; pos += 16; } return radius_msg_add_attr(msg, RADIUS_ATTR_USER_PASSWORD, buf, buf_len); } - Replace
msg->hdr->authenticatorwith that first 16 bytes of random data. - Place the results into the second 16 bytes.
