Educause Security Discussion mailing list archives

Wireless WPA2 MSCHAPv2


From: "Parker, Ben C" <parkerbc () MOUNTUNION EDU>
Date: Tue, 31 Jul 2012 12:58:35 +0000

Hello Everyone,

Reading through the news, I saw that at Defcon MSCHAPv2  has been effectively compromised. 
https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/ This includes the use of it in WPA2 connections to 
radius servers for authentication.  Per the article, the current recommendation for enterprise wireless deployments is 
to move to using client certificates for authentication.

 

It seems that using client certificates for authentication will be difficult for many schools because of the issue of 
publishing and distributing certificates to user on their multitudes of different devices. Does anyone have any good 
thoughts or recommendations on migrating to certificate based authentication with the  proliferation of students owned 
computers and mobile devices we all experience.

 

Thanks,

 

Ben Parker

Network Support Technician

University of Mount Union

330-829-2866

Attachment: PGP.sig
Description:


Current thread: