Other authentication methods
There are two other authentication methods that are worth mentioning here. They are one-time passwords and certificates.
One-time passwords
FreeRADIUS includes a module called rlm_otp
that can be used to handle OTP (one-time password) tokens. This module should be used in conjunction with additional programs. Unfortunately the company that contributed the code for the additional programs, Tri-D Systems, does not exist anymore. However, the code was forked and is now available from Google Code (http://code.google.com/p/otpd/).
If you want to implement your own one-time password functionality you can use a module like rlm_perl
or rlm_python
to handle the logic behind a one-time password. The NAS may still send User-Name
and User-Password
attributes to FreeRADIUS, but the way the User-Password
is managed will be unique in order to handle a one-time password.
Certificates
Certificates do not involve the presentation of a username and password combination. EAP can use...