Page MenuHomeVyOS Platform

accel-ppp-ng: MS-CHAPv1/v2 auth fails on OpenSSL 3.x for all protocols - legacy provider (MD4/DES) not loaded
Closed, ResolvedPublicBUG

Description

MS-CHAP needs the old MD4/DES algorithms, which on OpenSSL 3.x only work when the legacy provider is explicitly loaded. Accel-ppp-ng doesn't load it, so the password hash is not computed and MS-CHAP login is rejected even with the correct password.

Server config:

set service pppoe-server interface eth1
set service pppoe-server gateway-address '192.0.2.1'
set service pppoe-server client-ip-pool RV-POOL range '192.0.2.100-192.0.2.110'
set service pppoe-server default-pool 'RV-POOL'
set service pppoe-server authentication mode 'local'
set service pppoe-server authentication local-users username test password 'test'
set service pppoe-server authentication protocols 'mschap-v2'
commit

Client:

set interfaces pppoe pppoe0 source-interface 'eth1'
set interfaces pppoe pppoe0 no-default-route
set interfaces pppoe pppoe0 authentication username 'test'
set interfaces pppoe pppoe0 authentication password 'test'
commit

No session established, auth error in the server log:

MSCHAP-v2 Failure "E=691 R=0 V=3 M=Authentication failure"

Details

Version
1.5
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)