Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 654
  • Last Modified:

why is PAP more secure than CHAP?

What are the features that make PAP security better than CHAP security?
0
matthewharris38
Asked:
matthewharris38
1 Solution
 
Adam BrownSr Solutions ArchitectCommented:
Actually, PAP is much *less* security than CHAP, because PAP actually sends authentication information unencrypted over the network (Please read the wiki on PAP: http://en.wikipedia.org/wiki/Password_authentication_protocol). Unless clients are using Windows 95 or some other really old client OS to connect remotely, PAP is *not* a good thing to use. CHAP, on the other hand, transmits a challenge request to a client, which is based on the client's authentication information, and the client then responds with a hashed value that the server then checks against an expected result. If the result matches the expected result, the connection is then established. CHAP performs this check at random intervals for the duration of the remote session.

Now, if you happen to be referring to PEAP and not PAP, PEAP is significantly better than CHAP because it uses stronger algorithms and also involves a bit of Public Key cryptography to secure authentication traffic. PEAP utilizes TLS to encrypt authentication traffic. In order to work properly, PEAP requires the connection server to have a PKI certificate installed in order to encrypt traffic. Stronger versions of PEAP can utilize smart cards for authentication with full Public Key Cryptography.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now