https://de.wikipedia.org/w/index.php?action=history&feed=atom&title=MS-CHAP MS-CHAP - Versionsgeschichte 2025-12-03T14:03:33Z Versionsgeschichte dieser Seite in Wikipedia MediaWiki 1.46.0-wmf.4 https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=261933253&oldid=prev At40mha: Hilfe:Wikisyntax/Validierung#Ignoriertes Tag behoben 2025-11-27T22:19:45Z <p><a href="/wiki/Hilfe:Wikisyntax/Validierung#Ignoriertes_Tag" title="Hilfe:Wikisyntax/Validierung">Hilfe:Wikisyntax/Validierung#Ignoriertes Tag</a> behoben</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 27. November 2025, 23:19 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 19:</td> <td colspan="2" class="diff-lineno">Zeile 19:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Im Juli 2012 gab der Online-Dienst CloudCracker bekannt, VPN- und WLAN-Verbindungen, die auf MS-CHAPv2 basieren, innerhalb von 24 Stunden knacken zu können.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |hrsg=heise online |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/hintergrund/Der-Todesstoss-fuer-PPTP-1701365.html |titel=Der Todesstoß für PPTP |hrsg=heise online |datum=2012-09-22 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication |werk=MSRC Blog |hrsg=Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt; Der Brute-Force-Angriff gelingt dabei über Parallelisierung und speziell abgestimmte Hardware. Ein Durchbruch von Moxie Marlinspike reduzierte die Sicherheit von MS-CHAPv2 auf eine einzige DES-Verschlüsselung (2^56) unabhängig von der Passwortlänge.&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication |werk=MSRC Blog |hrsg=Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Im Juli 2012 gab der Online-Dienst CloudCracker bekannt, VPN- und WLAN-Verbindungen, die auf MS-CHAPv2 basieren, innerhalb von 24 Stunden knacken zu können.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |hrsg=heise online |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/hintergrund/Der-Todesstoss-fuer-PPTP-1701365.html |titel=Der Todesstoß für PPTP |hrsg=heise online |datum=2012-09-22 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication |werk=MSRC Blog |hrsg=Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt; Der Brute-Force-Angriff gelingt dabei über Parallelisierung und speziell abgestimmte Hardware. Ein Durchbruch von Moxie Marlinspike reduzierte die Sicherheit von MS-CHAPv2 auf eine einzige DES-Verschlüsselung (2^56) unabhängig von der Passwortlänge.&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication |werk=MSRC Blog |hrsg=Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2&lt;<del style="font-weight: bold; text-decoration: none;">v</del>&gt;56&lt;/sup&gt; möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |hrsg=heise online |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2&lt;<ins style="font-weight: bold; text-decoration: none;">sup</ins>&gt;56&lt;/sup&gt; möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |hrsg=heise online |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von „Windows Defender Credential Guard“ nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{Internetquelle |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |titel=Considerations when using Windows Defender Credential Guard |werk=learn.microsoft.com |hrsg=Windows Security |datum=2023-01-27 |abruf=}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von „Windows Defender Credential Guard“ nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{Internetquelle |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |titel=Considerations when using Windows Defender Credential Guard |werk=learn.microsoft.com |hrsg=Windows Security |datum=2023-01-27 |abruf=}}&lt;/ref&gt;</div></td> </tr> </table> At40mha https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=261931642&oldid=prev PerfektesChaos: tk k 2025-11-27T21:06:40Z <p>tk k</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 27. November 2025, 22:06 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 1:</td> <td colspan="2" class="diff-lineno">Zeile 1:</td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker"><a class="mw-diff-movedpara-right" title="Der Absatz wurde verschoben. Klicken, um zur alten Stelle zu springen." href="#movedpara_2_0_lhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_0_0_rhs"></a>'''MS-CHAP''' ist die [[Microsoft]]-Version des [[Challenge Handshake Authentication Protocol|Challenge-Handshake Authentication Protocol]] (CHAP).</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><br /></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"><a class="mw-diff-movedpara-left" title="Der Absatz wurde verschoben. Klicken, um zur neuen Stelle zu springen." href="#movedpara_0_0_rhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_2_0_lhs"></a>'''MS-CHAP''' ist die [[Microsoft]]-Version des [[Challenge Handshake Authentication Protocol|Challenge-Handshake Authentication Protocol]] (CHAP).<del style="font-weight: bold; text-decoration: none;"> </del></div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]] 2433) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]] 2759). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows<del style="font-weight: bold; text-decoration: none;"> </del>98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{<del style="font-weight: bold; text-decoration: none;">cite</del> <del style="font-weight: bold; text-decoration: none;">web</del> |<del style="font-weight: bold; text-decoration: none;">title</del>=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |<del style="font-weight: bold; text-decoration: none;">date=1998-08 |publisher</del>=Microsoft |<del style="font-weight: bold; text-decoration: none;">url</del>=<del style="font-weight: bold; text-decoration: none;">https://support.microsoft.com/en</del>-<del style="font-weight: bold; text-decoration: none;">us/kb/189771</del> |<del style="font-weight: bold; text-decoration: none;">website</del>=<del style="font-weight: bold; text-decoration: none;">Support</del>}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows<del style="font-weight: bold; text-decoration: none;"> </del>95]] im <del style="font-weight: bold; text-decoration: none;">"Dial</del> Up Networking 1.3 Performance &amp; Security Update for MS Windows<del style="font-weight: bold; text-decoration: none;"> 95"</del> Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]] 2433) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]] 2759). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows<ins style="font-weight: bold; text-decoration: none;">&amp;nbsp;</ins>98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{<ins style="font-weight: bold; text-decoration: none;">Internetquelle</ins> <ins style="font-weight: bold; text-decoration: none;">|url=https://support.microsoft.com/en-us/kb/189771</ins> |<ins style="font-weight: bold; text-decoration: none;">titel</ins>=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |<ins style="font-weight: bold; text-decoration: none;">hrsg</ins>=Microsoft<ins style="font-weight: bold; text-decoration: none;"> Support</ins> |<ins style="font-weight: bold; text-decoration: none;">datum</ins>=<ins style="font-weight: bold; text-decoration: none;">1998</ins>-<ins style="font-weight: bold; text-decoration: none;">08</ins> |<ins style="font-weight: bold; text-decoration: none;">abruf</ins>=}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows<ins style="font-weight: bold; text-decoration: none;">&amp;nbsp;</ins>95]] im <ins style="font-weight: bold; text-decoration: none;">„Dial</ins> Up Networking 1.3 Performance &amp; Security Update for MS Windows<ins style="font-weight: bold; text-decoration: none;">&amp;nbsp;95“</ins> Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">[[rfc:</del>2548|<del style="font-weight: bold; text-decoration: none;">''</del>Microsoft Vendor-specific RADIUS Attributes<del style="font-weight: bold; text-decoration: none;">''</del>.]] </div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]<ins style="font-weight: bold; text-decoration: none;"> verwendet</ins>. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">{{RFC-Internet |RFC=</ins>2548<ins style="font-weight: bold; text-decoration: none;"> </ins>|<ins style="font-weight: bold; text-decoration: none;">Titel=</ins>Microsoft Vendor-specific RADIUS Attributes<ins style="font-weight: bold; text-decoration: none;"> |Datum=}}&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802</ins>.<ins style="font-weight: bold; text-decoration: none;">1X|802.1X</ins>]] <ins style="font-weight: bold; text-decoration: none;">eingesetzt werden (z.&amp;nbsp;B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[Protected Extensible Authentication Protocol]] (PEAP) verwendet.</ins></div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><br /></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.&amp;nbsp;B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[Protected Extensible Authentication Protocol]] (PEAP) verwendet.</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">''[[rfc:</del>1994|PPP Challenge Handshake Authentication Protocol (CHAP)<del style="font-weight: bold; text-decoration: none;">]]''.</del> <del style="font-weight: bold; text-decoration: none;">[[Digital Object Identifier</del>|<del style="font-weight: bold; text-decoration: none;">doi]]:[[doi:10.17487/RFC2548|10.17487/RFC1994]]. [[Request for Comments|RFC]] [[rfc:1994|1994]].</del>&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">''[[rfc:</del>2433|Microsoft PPP CHAP Extensions<del style="font-weight: bold; text-decoration: none;">]]''. [[Digital Object</del> <del style="font-weight: bold; text-decoration: none;">Identifier</del>|<del style="font-weight: bold; text-decoration: none;">doi]]:[[doi:10.17487/RFC2433|10.17487/RFC2433]]. [[Request for Comments|RFC]] [[rfc:2433|2433]].</del>&lt;/ref&gt;&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">[[rfc:</del>2759|<del style="font-weight: bold; text-decoration: none;">''</del>Microsoft PPP CHAP Extensions, Version 2<del style="font-weight: bold; text-decoration: none;">''.]]</del> <del style="font-weight: bold; text-decoration: none;">[[Digital Object Identifier</del>|<del style="font-weight: bold; text-decoration: none;">doi]]:[[doi:10.17487/RFC2759|10.17487/RFC2759]]. [[Request for Comments|RFC]] [[rfc:2759|2759]].</del>&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden.<del style="font-weight: bold; text-decoration: none;"> </del></div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">{{RFC-Internet |RFC=</ins>1994<ins style="font-weight: bold; text-decoration: none;"> </ins>|<ins style="font-weight: bold; text-decoration: none;">Titel=</ins>PPP Challenge Handshake Authentication Protocol (CHAP) |<ins style="font-weight: bold; text-decoration: none;">Datum=}}</ins>&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">{{RFC-Internet |RFC=</ins>2433<ins style="font-weight: bold; text-decoration: none;"> </ins>|<ins style="font-weight: bold; text-decoration: none;">Titel=</ins>Microsoft PPP CHAP Extensions |<ins style="font-weight: bold; text-decoration: none;">Datum=}}</ins>&lt;/ref&gt;&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">{{RFC-Internet |RFC=</ins>2759<ins style="font-weight: bold; text-decoration: none;"> </ins>|<ins style="font-weight: bold; text-decoration: none;">Titel=</ins>Microsoft PPP CHAP Extensions, Version 2 |<ins style="font-weight: bold; text-decoration: none;">Datum=}}</ins>&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:MSCHAPv2 Flow.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:MSCHAPv2 Flow.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP erfordert, dass jeder Peer entweder das Klartext-Passwort oder einen MD4-Hash des Passworts kennt, und überträgt das Passwort nicht über die Verbindung. Daher ist es mit den meisten [[Passwort]]&lt;nowiki/&gt;speicherformaten nicht kompatibel.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP erfordert, dass jeder Peer entweder das Klartext-Passwort oder einen MD4-Hash des Passworts kennt, und überträgt das Passwort nicht über die Verbindung. Daher ist es mit den meisten [[Passwort]]&lt;nowiki<ins style="font-weight: bold; text-decoration: none;"> </ins>/&gt;speicherformaten nicht kompatibel.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Sicherheitsprobleme ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Sicherheitsprobleme ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Die Authentifizierung mit MS-CHAPv2 gilt bereits seit längerer Zeit als geknackt, wird aber in bestimmten Szenarien mit [[Microsoft Windows|Windows]]-Computern immer noch eingesetzt.&lt;ref&gt;{{Internetquelle |url=https://www.elektronik-kompendium.de/sites/net/0906181.htm |titel=MS-CHAPv2 <del style="font-weight: bold; text-decoration: none;">-</del> Microsoft CHAP |abruf=2025-08-06}}&lt;/ref&gt; Microsoft weist darauf hin, dass Organisationen, die MS-CHAP v2 ohne [[Datenkapselung (Programmierung)|Kapselung]] in Verbindung mit [[PPTP]]-Tunneln verwenden, eine potenziell unsichere Konfiguration nutzen.&lt;ref&gt;{{Internetquelle |url=https://support.microsoft.com/de-de/topic/implementieren-der-peap-ms-chap-v2-authentifizierung-f%C3%BCr-microsoft-pptp-vpns-d5ca1ebe-d9ee-4379-fd3f-e7be05fa3ae2 |titel=Implementieren der PEAP-MS-CHAP v2-Authentifizierung für Microsoft-PPTP-VPNs - Microsoft-Support |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Die Authentifizierung mit MS-CHAPv2 gilt bereits seit längerer Zeit als geknackt, wird aber in bestimmten Szenarien mit [[Microsoft Windows|Windows]]-Computern immer noch eingesetzt.&lt;ref&gt;{{Internetquelle |url=https://www.elektronik-kompendium.de/sites/net/0906181.htm |titel=MS-CHAPv2 <ins style="font-weight: bold; text-decoration: none;">–</ins> Microsoft CHAP |abruf=2025-08-06}}&lt;/ref&gt; Microsoft weist darauf hin, dass Organisationen, die MS-CHAP v2 ohne [[Datenkapselung (Programmierung)|Kapselung]] in Verbindung mit [[<ins style="font-weight: bold; text-decoration: none;">Point-to-Point Tunneling Protocol|</ins>PPTP]]-Tunneln verwenden, eine potenziell unsichere Konfiguration nutzen.&lt;ref&gt;{{Internetquelle |url=https://support.microsoft.com/de-de/topic/implementieren-der-peap-ms-chap-v2-authentifizierung-f%C3%BCr-microsoft-pptp-vpns-d5ca1ebe-d9ee-4379-fd3f-e7be05fa3ae2 |titel=Implementieren der PEAP-MS-CHAP v2-Authentifizierung für Microsoft-PPTP-VPNs - Microsoft-Support |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Im Juli 2012 gab der Online-Dienst CloudCracker bekannt, VPN- und WLAN-Verbindungen, die auf MS-CHAPv2 basieren, innerhalb von 24 Stunden knacken zu können.&lt;ref&gt;{{Internetquelle<del style="font-weight: bold; text-decoration: none;"> |autor=heise online</del> |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle<del style="font-weight: bold; text-decoration: none;"> |autor=heise online</del> |url=https://www.heise.de/hintergrund/Der-Todesstoss-fuer-PPTP-1701365.html |titel=Der Todesstoß für PPTP |datum=2012-09-22 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication <del style="font-weight: bold; text-decoration: none;">{{!}} </del>MSRC Blog <del style="font-weight: bold; text-decoration: none;">{{!}} </del>Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt; Der Brute-Force-Angriff gelingt dabei über Parallelisierung und speziell abgestimmte Hardware. Ein Durchbruch von Moxie Marlinspike reduzierte die Sicherheit von MS-CHAPv2 auf eine einzige DES-Verschlüsselung (2^56) unabhängig von der Passwortlänge.&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication <del style="font-weight: bold; text-decoration: none;">{{!}} </del>MSRC Blog <del style="font-weight: bold; text-decoration: none;">{{!}} </del>Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Im Juli 2012 gab der Online-Dienst CloudCracker bekannt, VPN- und WLAN-Verbindungen, die auf MS-CHAPv2 basieren, innerhalb von 24 Stunden knacken zu können.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP<ins style="font-weight: bold; text-decoration: none;"> |hrsg=heise online</ins> |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/hintergrund/Der-Todesstoss-fuer-PPTP-1701365.html |titel=Der Todesstoß für PPTP<ins style="font-weight: bold; text-decoration: none;"> |hrsg=heise online</ins> |datum=2012-09-22 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication <ins style="font-weight: bold; text-decoration: none;">|werk=</ins>MSRC Blog <ins style="font-weight: bold; text-decoration: none;">|hrsg=</ins>Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt; Der Brute-Force-Angriff gelingt dabei über Parallelisierung und speziell abgestimmte Hardware. Ein Durchbruch von Moxie Marlinspike reduzierte die Sicherheit von MS-CHAPv2 auf eine einzige DES-Verschlüsselung (2^56) unabhängig von der Passwortlänge.&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication <ins style="font-weight: bold; text-decoration: none;">|werk=</ins>MSRC Blog <ins style="font-weight: bold; text-decoration: none;">|hrsg=</ins>Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2<del style="font-weight: bold; text-decoration: none;">^</del>56 möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle<del style="font-weight: bold; text-decoration: none;"> |autor=heise online</del> |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2<ins style="font-weight: bold; text-decoration: none;">&lt;v&gt;</ins>56<ins style="font-weight: bold; text-decoration: none;">&lt;/sup&gt;</ins> möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP<ins style="font-weight: bold; text-decoration: none;"> |hrsg=heise online</ins> |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von <del style="font-weight: bold; text-decoration: none;">"Windows</del> Defender Credential <del style="font-weight: bold; text-decoration: none;">Guard"</del> nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{<del style="font-weight: bold; text-decoration: none;">Cite web |title=Considerations when using Windows Defender Credential Guard - Windows Security |date=2023-01-27</del> |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |<del style="font-weight: bold; text-decoration: none;">website</del>=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von <ins style="font-weight: bold; text-decoration: none;">„Windows</ins> Defender Credential <ins style="font-weight: bold; text-decoration: none;">Guard“</ins> nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{<ins style="font-weight: bold; text-decoration: none;">Internetquelle</ins> |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |<ins style="font-weight: bold; text-decoration: none;">titel=Considerations when using Windows Defender Credential Guard |werk</ins>=learn.microsoft.com<ins style="font-weight: bold; text-decoration: none;"> |hrsg=Windows Security |datum=2023-01-27 |abruf=</ins>}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Siehe auch ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Siehe auch ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><br /></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* [[EFF DES Cracker|EFF DES cracker]]</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>* [[EFF DES Cracker|EFF DES cracker]]</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Einzelnachweise ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Einzelnachweise ==</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>&lt;references /&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>&lt;references /&gt;</div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Authentifizierungsprotokoll]]</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Authentifizierungsprotokoll]]</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Internetprotokollfamilie]]</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Internetprotokollfamilie]]</div></td> </tr> </table> PerfektesChaos https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258709583&oldid=prev Squasher: Interwikilink gem. Richtlinie unerwünscht, daher entfernt bzw. angepasst 2025-08-09T06:04:22Z <p>Interwikilink gem. <a href="/wiki/Wikipedia:V#ANR" class="mw-redirect" title="Wikipedia:V">Richtlinie</a> unerwünscht, daher entfernt bzw. angepasst</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 9. August 2025, 07:04 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 3:</td> <td colspan="2" class="diff-lineno">Zeile 3:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]]<del style="font-weight: bold; text-decoration: none;"> [https://www.rfc-editor.org/rfc/rfc2433</del> 2433<del style="font-weight: bold; text-decoration: none;">]</del>) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]]<del style="font-weight: bold; text-decoration: none;"> [https://www.rfc-editor.org/rfc/rfc2759</del> 2759<del style="font-weight: bold; text-decoration: none;">]</del>). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows 98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web |title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |date=1998-08 |publisher=Microsoft |url=https://support.microsoft.com/en-us/kb/189771 |website=Support}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows 95]] im "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]] 2433) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]] 2759). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows 98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web |title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |date=1998-08 |publisher=Microsoft |url=https://support.microsoft.com/en-us/kb/189771 |website=Support}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows 95]] im "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;[[rfc:2548|''Microsoft Vendor-specific RADIUS Attributes''.]] </div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;[[rfc:2548|''Microsoft Vendor-specific RADIUS Attributes''.]] </div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.&amp;nbsp;B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[<del style="font-weight: bold; text-decoration: none;">:en:Protected_Extensible_Authentication_Protocol|</del>Protected Extensible Authentication Protocol (PEAP)<del style="font-weight: bold; text-decoration: none;">]]</del> verwendet.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.&amp;nbsp;B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[Protected Extensible Authentication Protocol<ins style="font-weight: bold; text-decoration: none;">]]</ins> (PEAP) verwendet.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> </tr> </table> Squasher https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258660873&oldid=prev Invisigoth67: form 2025-08-07T07:01:15Z <p>form</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 7. August 2025, 08:01 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 3:</td> <td colspan="2" class="diff-lineno">Zeile 3:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Versionen ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]] [https://www.rfc-editor.org/rfc/rfc2433 2433]) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]] [https://www.rfc-editor.org/rfc/rfc2759 2759]). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows 98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web |title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |date=<del style="font-weight: bold; text-decoration: none;">August </del>1998 |publisher=Microsoft |url=https://support.microsoft.com/en-us/kb/189771 |website=Support}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows 95]] im "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Protokoll existiert in zwei Versionen: MS-CHAPv1 (definiert in [[Request for Comments|RFC]] [https://www.rfc-editor.org/rfc/rfc2433 2433]) und MS-CHAPv2 (definiert in [[Request for Comments|RFC]] [https://www.rfc-editor.org/rfc/rfc2759 2759]). MS-CHAPv2 wurde mit pptp3-fix eingeführt, das in [[Microsoft Windows NT|Windows NT]] 4.0 SP4 enthalten war und zu [[Microsoft Windows 98|Windows 98]] im "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web |title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998) |date=1998<ins style="font-weight: bold; text-decoration: none;">-08</ins> |publisher=Microsoft |url=https://support.microsoft.com/en-us/kb/189771 |website=Support}}&lt;/ref&gt; und zu [[Microsoft Windows 95|Windows 95]] im "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" Upgrade hinzugefügt wurde. Mit [[Microsoft Windows Vista|Windows Vista]] stellte Microsoft die Unterstützung für MS-CHAPv1 ein.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;[[rfc:2548|''Microsoft Vendor-specific RADIUS Attributes''.]] </div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;[[rfc:2548|''Microsoft Vendor-specific RADIUS Attributes''.]] </div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[:en:Protected_Extensible_Authentication_Protocol|Protected Extensible Authentication Protocol (PEAP)]] verwendet.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.<ins style="font-weight: bold; text-decoration: none;">&amp;nbsp;</ins>B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[:en:Protected_Extensible_Authentication_Protocol|Protected Extensible Authentication Protocol (PEAP)]] verwendet.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;''[[rfc:1994|PPP Challenge Handshake Authentication Protocol (CHAP)]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC1994]]. [[Request for Comments|RFC]] [[rfc:1994|1994]].&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;''[[rfc:2433|Microsoft PPP CHAP Extensions]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2433|10.17487/RFC2433]]. [[Request for Comments|RFC]] [[rfc:2433|2433]].&lt;/ref&gt;&lt;ref&gt;[[rfc:2759|''Microsoft PPP CHAP Extensions, Version 2''.]] [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2759|10.17487/RFC2759]]. [[Request for Comments|RFC]] [[rfc:2759|2759]].&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden. </div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;''[[rfc:1994|PPP Challenge Handshake Authentication Protocol (CHAP)]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC1994]]. [[Request for Comments|RFC]] [[rfc:1994|1994]].&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;''[[rfc:2433|Microsoft PPP CHAP Extensions]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2433|10.17487/RFC2433]]. [[Request for Comments|RFC]] [[rfc:2433|2433]].&lt;/ref&gt;&lt;ref&gt;[[rfc:2759|''Microsoft PPP CHAP Extensions, Version 2''.]] [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2759|10.17487/RFC2759]]. [[Request for Comments|RFC]] [[rfc:2759|2759]].&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden. </div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:<del style="font-weight: bold; text-decoration: none;">MSCHAPv2_Flow</del>.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:<ins style="font-weight: bold; text-decoration: none;">MSCHAPv2 Flow</ins>.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-lineno">Zeile 24:</td> <td colspan="2" class="diff-lineno">Zeile 24:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2^56 möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |autor=heise online |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2^56 möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |autor=heise online |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker"><a class="mw-diff-movedpara-right" title="Der Absatz wurde verschoben. Klicken, um zur alten Stelle zu springen." href="#movedpara_9_0_lhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_7_0_rhs"></a>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von "Windows Defender Credential Guard" nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web |title=Considerations when using Windows Defender Credential Guard - Windows Security |date=2023<ins style="font-weight: bold; text-decoration: none;">-01-27</ins> |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |website=learn.microsoft.com}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><br /></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"><a class="mw-diff-movedpara-left" title="Der Absatz wurde verschoben. Klicken, um zur neuen Stelle zu springen." href="#movedpara_7_0_rhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_9_0_lhs"></a>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von "Windows Defender Credential Guard" nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web |title=Considerations when using Windows Defender Credential Guard - Windows Security |date=<del style="font-weight: bold; text-decoration: none;">January 27, </del>2023 |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |website=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Siehe auch ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Siehe auch ==</div></td> </tr> </table> Invisigoth67 https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258637241&oldid=prev Chewbacca2205: 100 Versionen von :en:MS-CHAP importiert: WP:IMP * user:Luke081515Bot 2025-08-06T13:03:53Z <p>100 Versionen von <a href="https://en.wikipedia.org/wiki/MS-CHAP" class="extiw" title="en:MS-CHAP">en:MS-CHAP</a> importiert: WP:IMP * <a href="/wiki/Benutzer:Luke081515Bot" title="Benutzer:Luke081515Bot">user:Luke081515Bot</a></p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <tr class="diff-title" lang="de"> <td colspan="1" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="1" style="background-color: #fff; color: #202122; text-align: center;">Version vom 6. August 2025, 14:03 Uhr</td> </tr><tr><td colspan="2" class="diff-notice" lang="de"><div class="mw-diff-empty">(kein Unterschied)</div> </td></tr></table> Chewbacca2205 https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258636048&oldid=prev TZRU: Erstellt durch Übersetzen der Seite „MS-CHAP“ 2025-08-06T12:16:47Z <p>Erstellt durch Übersetzen der Seite „<a href="https://en.wikipedia.org/wiki/Special:Redirect/revision/1273475138" class="extiw" title="en:Special:Redirect/revision/1273475138">MS-CHAP</a>“</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 6. August 2025, 13:16 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 6:</td> <td colspan="2" class="diff-lineno">Zeile 6:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">{{Cite IETF|</del>rfc<del style="font-weight: bold; text-decoration: none;">=</del>2548|<del style="font-weight: bold; text-decoration: none;">title=</del>Microsoft Vendor-specific RADIUS Attributes<del style="font-weight: bold; text-decoration: none;">}}</del>&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[:en:Protected_Extensible_Authentication_Protocol|Protected Extensible Authentication Protocol (PEAP)]] verwendet.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">[[</ins>rfc<ins style="font-weight: bold; text-decoration: none;">:</ins>2548|<ins style="font-weight: bold; text-decoration: none;">''</ins>Microsoft Vendor-specific RADIUS Attributes<ins style="font-weight: bold; text-decoration: none;">''.]] </ins></div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div></div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">[[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC2548]]. [[Request for Comments|RFC]] [[rfc:2548|2548]].</ins>&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[:en:Protected_Extensible_Authentication_Protocol|Protected Extensible Authentication Protocol (PEAP)]] verwendet.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">{{cite IETF|</del>rfc<del style="font-weight: bold; text-decoration: none;">=</del>1994|<del style="font-weight: bold; text-decoration: none;">title=</del>PPP Challenge Handshake Authentication Protocol (CHAP)<del style="font-weight: bold; text-decoration: none;">}}</del>&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">{{Cite IETF|</del>rfc<del style="font-weight: bold; text-decoration: none;">=</del>2433|<del style="font-weight: bold; text-decoration: none;">title=</del>Microsoft PPP CHAP Extensions<del style="font-weight: bold; text-decoration: none;">}}</del>&lt;/ref&gt;&lt;ref&gt;<del style="font-weight: bold; text-decoration: none;">{{Cite IETF|</del>rfc<del style="font-weight: bold; text-decoration: none;">=</del>2759|<del style="font-weight: bold; text-decoration: none;">title=</del>Microsoft PPP CHAP Extensions, Version 2<del style="font-weight: bold; text-decoration: none;">}}</del>&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden. </div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Im Vergleich zu CHAP&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">''[[</ins>rfc<ins style="font-weight: bold; text-decoration: none;">:</ins>1994|PPP Challenge Handshake Authentication Protocol (CHAP)<ins style="font-weight: bold; text-decoration: none;">]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2548|10.17487/RFC1994]]. [[Request for Comments|RFC]] [[rfc:1994|1994]].</ins>&lt;/ref&gt; funktioniert MS-CHAP&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">''[[</ins>rfc<ins style="font-weight: bold; text-decoration: none;">:</ins>2433|Microsoft PPP CHAP Extensions<ins style="font-weight: bold; text-decoration: none;">]]''. [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2433|10.17487/RFC2433]]. [[Request for Comments|RFC]] [[rfc:2433|2433]].</ins>&lt;/ref&gt;&lt;ref&gt;<ins style="font-weight: bold; text-decoration: none;">[[</ins>rfc<ins style="font-weight: bold; text-decoration: none;">:</ins>2759|<ins style="font-weight: bold; text-decoration: none;">''</ins>Microsoft PPP CHAP Extensions, Version 2<ins style="font-weight: bold; text-decoration: none;">''.]] [[Digital Object Identifier|doi]]:[[doi:10.17487/RFC2759|10.17487/RFC2759]]. [[Request for Comments|RFC]] [[rfc:2759|2759]].</ins>&lt;/ref&gt; folgendermaßen: es arbeitet durch Aushandlung des CHAP-Algorithmus 0x80 (0x81 für MS-CHAPv2) in der LCP-Option 3, Authentifizierungsprotokoll. Es bietet einen vom Authentifikator kontrollierten Passwort-Änderungsmechanismus. Es bietet einen vom Authentifikator kontrollierten Authentifizierungs-Wiederholungsmechanismus und definiert Fehlercodes, die im Nachrichtenfeld des Failure-Pakets zurückgegeben werden. </div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:MSCHAPv2_Flow.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>[[Datei:MSCHAPv2_Flow.pdf|mini|Ablauf eines MSCHAPv2 Flusses]]</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> </tr> </table> TZRU https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258635797&oldid=prev TZRU: Erstellt durch Übersetzen der Seite „MS-CHAP“ 2025-08-06T12:05:48Z <p>Erstellt durch Übersetzen der Seite „<a href="https://en.wikipedia.org/wiki/Special:Redirect/revision/1273475138" class="extiw" title="en:Special:Redirect/revision/1273475138">MS-CHAP</a>“</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 6. August 2025, 13:05 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 1:</td> <td colspan="2" class="diff-lineno">Zeile 1:</td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>{{Short description|Authentication protocol to validate users}}</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"><a class="mw-diff-movedpara-left" title="Der Absatz wurde verschoben. Klicken, um zur neuen Stelle zu springen." href="#movedpara_2_0_rhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_0_1_lhs"></a>'''MS-CHAP''' <del style="font-weight: bold; text-decoration: none;">is</del> <del style="font-weight: bold; text-decoration: none;">the</del> [[Microsoft]] <del style="font-weight: bold; text-decoration: none;">version of the</del> [[Challenge-Handshake Authentication Protocol]]<del style="font-weight: bold; text-decoration: none;">,</del> (CHAP). </div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker"><a class="mw-diff-movedpara-right" title="Der Absatz wurde verschoben. Klicken, um zur alten Stelle zu springen." href="#movedpara_0_1_lhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_2_0_rhs"></a>'''MS-CHAP''' <ins style="font-weight: bold; text-decoration: none;">ist</ins> <ins style="font-weight: bold; text-decoration: none;">die</ins> [[Microsoft]]<ins style="font-weight: bold; text-decoration: none;">-Version</ins> <ins style="font-weight: bold; text-decoration: none;">des</ins> [[<ins style="font-weight: bold; text-decoration: none;">Challenge Handshake Authentication Protocol|</ins>Challenge-Handshake Authentication Protocol]] (CHAP). </div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>== Versions ==</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"><a class="mw-diff-movedpara-left" title="Der Absatz wurde verschoben. Klicken, um zur neuen Stelle zu springen." href="#movedpara_7_0_rhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_4_0_lhs"></a><del style="font-weight: bold; text-decoration: none;">The</del> <del style="font-weight: bold; text-decoration: none;">protocol</del> <del style="font-weight: bold; text-decoration: none;">exists</del> in <del style="font-weight: bold; text-decoration: none;">two</del> <del style="font-weight: bold; text-decoration: none;">versions,</del> MS-CHAPv1 (<del style="font-weight: bold; text-decoration: none;">defined</del> in <del style="font-weight: bold; text-decoration: none;">{{IETF</del> <del style="font-weight: bold; text-decoration: none;">RFC</del>|2433<del style="font-weight: bold; text-decoration: none;">}}</del>) <del style="font-weight: bold; text-decoration: none;">and</del> MS-CHAPv2 (<del style="font-weight: bold; text-decoration: none;">defined</del> in <del style="font-weight: bold; text-decoration: none;">{{IETF</del> <del style="font-weight: bold; text-decoration: none;">RFC</del>|2759<del style="font-weight: bold; text-decoration: none;">}}</del>). MS-CHAPv2 <del style="font-weight: bold; text-decoration: none;">was</del> <del style="font-weight: bold; text-decoration: none;">introduced with</del> pptp3-fix <del style="font-weight: bold; text-decoration: none;">&lt;!--</del> <del style="font-weight: bold; text-decoration: none;">from MS's old FTP site --&gt; that was included</del> in [[Windows NT 4.0<del style="font-weight: bold; text-decoration: none;">]]</del> SP4 <del style="font-weight: bold; text-decoration: none;">and</del> <del style="font-weight: bold; text-decoration: none;">was</del> <del style="font-weight: bold; text-decoration: none;">added</del> <del style="font-weight: bold; text-decoration: none;">to</del> [[Windows 98]] <del style="font-weight: bold; text-decoration: none;">in the</del> "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web|title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998)|url=https://support.microsoft.com/en-us/kb/189771|website=Support<del style="font-weight: bold; text-decoration: none;">|publisher=Microsoft|date=August 1998</del>}}&lt;/ref&gt; <del style="font-weight: bold; text-decoration: none;">and</del> [[Windows 95]] <del style="font-weight: bold; text-decoration: none;">in the</del> "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" <del style="font-weight: bold; text-decoration: none;">upgrade</del>. [[Windows Vista]] <del style="font-weight: bold; text-decoration: none;">dropped</del> <del style="font-weight: bold; text-decoration: none;">support</del> <del style="font-weight: bold; text-decoration: none;">for</del> MS-CHAPv1.</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>== <del style="font-weight: bold; text-decoration: none;">Applications</del> ==</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>== <ins style="font-weight: bold; text-decoration: none;">Versionen</ins> ==</div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker"><a class="mw-diff-movedpara-right" title="Der Absatz wurde verschoben. Klicken, um zur alten Stelle zu springen." href="#movedpara_4_0_lhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_7_0_rhs"></a><ins style="font-weight: bold; text-decoration: none;">Das</ins> <ins style="font-weight: bold; text-decoration: none;">Protokoll</ins> <ins style="font-weight: bold; text-decoration: none;">existiert</ins> in <ins style="font-weight: bold; text-decoration: none;">zwei</ins> <ins style="font-weight: bold; text-decoration: none;">Versionen:</ins> MS-CHAPv1 (<ins style="font-weight: bold; text-decoration: none;">definiert</ins> in <ins style="font-weight: bold; text-decoration: none;">[[Request</ins> <ins style="font-weight: bold; text-decoration: none;">for Comments</ins>|<ins style="font-weight: bold; text-decoration: none;">RFC]] [https://www.rfc-editor.org/rfc/rfc2433 </ins>2433<ins style="font-weight: bold; text-decoration: none;">]</ins>) <ins style="font-weight: bold; text-decoration: none;">und</ins> MS-CHAPv2 (<ins style="font-weight: bold; text-decoration: none;">definiert</ins> in <ins style="font-weight: bold; text-decoration: none;">[[Request</ins> <ins style="font-weight: bold; text-decoration: none;">for Comments</ins>|<ins style="font-weight: bold; text-decoration: none;">RFC]] [https://www.rfc-editor.org/rfc/rfc2759 </ins>2759<ins style="font-weight: bold; text-decoration: none;">]</ins>). MS-CHAPv2 <ins style="font-weight: bold; text-decoration: none;">wurde</ins> <ins style="font-weight: bold; text-decoration: none;">mit</ins> pptp3-fix <ins style="font-weight: bold; text-decoration: none;">eingeführt,</ins> <ins style="font-weight: bold; text-decoration: none;">das</ins> in [[<ins style="font-weight: bold; text-decoration: none;">Microsoft </ins>Windows NT<ins style="font-weight: bold; text-decoration: none;">|Windows NT]]</ins> 4.0 SP4 <ins style="font-weight: bold; text-decoration: none;">enthalten</ins> <ins style="font-weight: bold; text-decoration: none;">war</ins> <ins style="font-weight: bold; text-decoration: none;">und</ins> <ins style="font-weight: bold; text-decoration: none;">zu</ins> [[<ins style="font-weight: bold; text-decoration: none;">Microsoft Windows 98|</ins>Windows 98]] <ins style="font-weight: bold; text-decoration: none;">im</ins> "Windows 98 Dial-Up Networking Security Upgrade Release"&lt;ref&gt;{{cite web<ins style="font-weight: bold; text-decoration: none;"> </ins>|title=Windows 98 Dial-Up Networking Security Upgrade Release Notes (August 1998)<ins style="font-weight: bold; text-decoration: none;"> |date=August 1998 |publisher=Microsoft </ins>|url=https://support.microsoft.com/en-us/kb/189771<ins style="font-weight: bold; text-decoration: none;"> </ins>|website=Support}}&lt;/ref&gt; <ins style="font-weight: bold; text-decoration: none;">und zu</ins> [[<ins style="font-weight: bold; text-decoration: none;">Microsoft Windows 95|</ins>Windows 95]] <ins style="font-weight: bold; text-decoration: none;">im</ins> "Dial Up Networking 1.3 Performance &amp; Security Update for MS Windows 95" <ins style="font-weight: bold; text-decoration: none;">Upgrade hinzugefügt wurde</ins>.<ins style="font-weight: bold; text-decoration: none;"> Mit</ins> [[<ins style="font-weight: bold; text-decoration: none;">Microsoft Windows Vista|</ins>Windows Vista]] <ins style="font-weight: bold; text-decoration: none;">stellte</ins> <ins style="font-weight: bold; text-decoration: none;">Microsoft</ins> <ins style="font-weight: bold; text-decoration: none;">die Unterstützung für</ins> MS-CHAPv1<ins style="font-weight: bold; text-decoration: none;"> ein</ins>.</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP is used as one authentication option in Microsoft's implementation of the [[PPTP]] protocol for [[virtual private network]]s. It is also used as an authentication option with [[RADIUS]]&lt;ref&gt;{{Cite IETF |rfc=2548 |title=Microsoft Vendor-specific RADIUS Attributes}}&lt;/ref&gt; servers which are used with [[IEEE 802.1X]] (e.g., [[WiFi]] security using the [[Wi-Fi Protected Access|WPA-Enterprise]] protocol). It is further used as the main authentication option of the [[Protected Extensible Authentication Protocol]] (PEAP).</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>== Anwendungen ==</div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP wird als eine Authentifizierungsoption in Microsofts Implementierung des [[Point-to-Point Tunneling Protocol|PPTP]]-Protokolls für [[Virtual Private Network|virtuelle private Netzwerke (VPNs)]]. Es wird auch als Authentifizierungsoption mit [[RADIUS]]-Servern&lt;ref&gt;{{Cite IETF|rfc=2548|title=Microsoft Vendor-specific RADIUS Attributes}}&lt;/ref&gt; die mit [[Institute of Electrical and Electronics Engineers|IEEE]] [[IEEE 802.1X|802.1X]] eingesetzt werden (z.B. [[Wi-Fi|WiFi]]-Sicherheit mit dem [[Wi-Fi Protected Access|WPA-Enterprise-Protokoll]]). Des Weiteren wird es als die Hauptauthentifizierungsoption des [[:en:Protected_Extensible_Authentication_Protocol|Protected Extensible Authentication Protocol (PEAP)]] verwendet.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>== Features ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><del style="font-weight: bold; text-decoration: none;">Compared</del> <del style="font-weight: bold; text-decoration: none;">with</del> CHAP<del style="font-weight: bold; text-decoration: none;">,</del>&lt;ref&gt;{{cite IETF<del style="font-weight: bold; text-decoration: none;"> </del>|rfc=1994<del style="font-weight: bold; text-decoration: none;"> </del>|title=PPP Challenge Handshake Authentication Protocol (CHAP)}}&lt;/ref&gt; MS-CHAP<del style="font-weight: bold; text-decoration: none;">:</del>&lt;ref&gt;{{Cite IETF<del style="font-weight: bold; text-decoration: none;"> </del>|rfc=2433<del style="font-weight: bold; text-decoration: none;"> </del>|title=Microsoft PPP CHAP Extensions}}&lt;/ref&gt;&lt;ref&gt;{{Cite IETF<del style="font-weight: bold; text-decoration: none;"> </del>|rfc=2759<del style="font-weight: bold; text-decoration: none;"> </del>|title=Microsoft PPP CHAP Extensions, Version 2}}&lt;/ref&gt; <del style="font-weight: bold; text-decoration: none;">works</del> <del style="font-weight: bold; text-decoration: none;">by</del> <del style="font-weight: bold; text-decoration: none;">negotiating</del> <del style="font-weight: bold; text-decoration: none;">CHAP</del> <del style="font-weight: bold; text-decoration: none;">Algorithm</del> 0x80 (0x81 <del style="font-weight: bold; text-decoration: none;">for</del> MS-CHAPv2) in LCP<del style="font-weight: bold; text-decoration: none;"> option</del> 3, <del style="font-weight: bold; text-decoration: none;">Authentication Protocol</del>. <del style="font-weight: bold; text-decoration: none;">It</del> <del style="font-weight: bold; text-decoration: none;">provides</del> <del style="font-weight: bold; text-decoration: none;">an</del> <del style="font-weight: bold; text-decoration: none;">authenticator-controlled</del> <del style="font-weight: bold; text-decoration: none;">password</del> <del style="font-weight: bold; text-decoration: none;">change</del> <del style="font-weight: bold; text-decoration: none;">mechanism</del>. <del style="font-weight: bold; text-decoration: none;">It</del> <del style="font-weight: bold; text-decoration: none;">provides</del> <del style="font-weight: bold; text-decoration: none;">an</del> <del style="font-weight: bold; text-decoration: none;">authenticator-controlled</del> <del style="font-weight: bold; text-decoration: none;">authentication</del> <del style="font-weight: bold; text-decoration: none;">retry</del> <del style="font-weight: bold; text-decoration: none;">mechanism</del> <del style="font-weight: bold; text-decoration: none;">and</del> <del style="font-weight: bold; text-decoration: none;">defines</del> <del style="font-weight: bold; text-decoration: none;">failure</del> <del style="font-weight: bold; text-decoration: none;">codes</del> <del style="font-weight: bold; text-decoration: none;">returned</del> <del style="font-weight: bold; text-decoration: none;">in</del> <del style="font-weight: bold; text-decoration: none;">the</del> Failure <del style="font-weight: bold; text-decoration: none;">packet message</del> <del style="font-weight: bold; text-decoration: none;">field</del>. </div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><ins style="font-weight: bold; text-decoration: none;">Im</ins> <ins style="font-weight: bold; text-decoration: none;">Vergleich zu</ins> CHAP&lt;ref&gt;{{cite IETF|rfc=1994|title=PPP Challenge Handshake Authentication Protocol (CHAP)}}&lt;/ref&gt;<ins style="font-weight: bold; text-decoration: none;"> funktioniert</ins> MS-CHAP&lt;ref&gt;{{Cite IETF|rfc=2433|title=Microsoft PPP CHAP Extensions}}&lt;/ref&gt;&lt;ref&gt;{{Cite IETF|rfc=2759|title=Microsoft PPP CHAP Extensions, Version 2}}&lt;/ref&gt; <ins style="font-weight: bold; text-decoration: none;">folgendermaßen:</ins> <ins style="font-weight: bold; text-decoration: none;">es</ins> <ins style="font-weight: bold; text-decoration: none;">arbeitet</ins> <ins style="font-weight: bold; text-decoration: none;">durch</ins> <ins style="font-weight: bold; text-decoration: none;">Aushandlung des CHAP-Algorithmus</ins> 0x80 (0x81 <ins style="font-weight: bold; text-decoration: none;">für</ins> MS-CHAPv2) in<ins style="font-weight: bold; text-decoration: none;"> der</ins> LCP<ins style="font-weight: bold; text-decoration: none;">-Option</ins> 3, <ins style="font-weight: bold; text-decoration: none;">Authentifizierungsprotokoll</ins>. <ins style="font-weight: bold; text-decoration: none;">Es</ins> <ins style="font-weight: bold; text-decoration: none;">bietet</ins> <ins style="font-weight: bold; text-decoration: none;">einen</ins> <ins style="font-weight: bold; text-decoration: none;">vom</ins> <ins style="font-weight: bold; text-decoration: none;">Authentifikator</ins> <ins style="font-weight: bold; text-decoration: none;">kontrollierten</ins> <ins style="font-weight: bold; text-decoration: none;">Passwort-Änderungsmechanismus</ins>. <ins style="font-weight: bold; text-decoration: none;">Es</ins> <ins style="font-weight: bold; text-decoration: none;">bietet</ins> <ins style="font-weight: bold; text-decoration: none;">einen</ins> <ins style="font-weight: bold; text-decoration: none;">vom</ins> <ins style="font-weight: bold; text-decoration: none;">Authentifikator</ins> <ins style="font-weight: bold; text-decoration: none;">kontrollierten</ins> <ins style="font-weight: bold; text-decoration: none;">Authentifizierungs-Wiederholungsmechanismus</ins> <ins style="font-weight: bold; text-decoration: none;">und</ins> <ins style="font-weight: bold; text-decoration: none;">definiert</ins> <ins style="font-weight: bold; text-decoration: none;">Fehlercodes,</ins> <ins style="font-weight: bold; text-decoration: none;">die</ins> <ins style="font-weight: bold; text-decoration: none;">im</ins> <ins style="font-weight: bold; text-decoration: none;">Nachrichtenfeld</ins> <ins style="font-weight: bold; text-decoration: none;">des</ins> Failure<ins style="font-weight: bold; text-decoration: none;">-Pakets</ins> <ins style="font-weight: bold; text-decoration: none;">zurückgegeben</ins> <ins style="font-weight: bold; text-decoration: none;">werden</ins>. </div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[<del style="font-weight: bold; text-decoration: none;">File</del>:MSCHAPv2_Flow.pdf|<del style="font-weight: bold; text-decoration: none;">thumb</del>]]</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[<ins style="font-weight: bold; text-decoration: none;">Datei</ins>:MSCHAPv2_Flow.pdf|<ins style="font-weight: bold; text-decoration: none;">mini|Ablauf eines MSCHAPv2 Flusses</ins>]]</div></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 ermöglicht die gegenseitige Authentifizierung zwischen Peers, indem es eine Peer-Anforderung an das Antwortpaket und eine Authentifizierungsantwort an das "success packet" anhängt.</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAPv2 provides mutual authentication between peers by piggybacking a peer challenge on the response packet and an authenticator response on the success packet.</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP erfordert, dass jeder Peer entweder das Klartext-Passwort oder einen MD4-Hash des Passworts kennt, und überträgt das Passwort nicht über die Verbindung. Daher ist es mit den meisten [[Passwort]]&lt;nowiki/&gt;speicherformaten nicht kompatibel.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>== Sicherheitsprobleme ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>MS-CHAP requires each peer to either know the plaintext password, or an MD4 hash of the password, and does not transmit the password over the link. As such, it is not compatible with most [[Password#Form_of_stored_passwords|password storage]] formats.</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Die Authentifizierung mit MS-CHAPv2 gilt bereits seit längerer Zeit als geknackt, wird aber in bestimmten Szenarien mit [[Microsoft Windows|Windows]]-Computern immer noch eingesetzt.&lt;ref&gt;{{Internetquelle |url=https://www.elektronik-kompendium.de/sites/net/0906181.htm |titel=MS-CHAPv2 - Microsoft CHAP |abruf=2025-08-06}}&lt;/ref&gt; Microsoft weist darauf hin, dass Organisationen, die MS-CHAP v2 ohne [[Datenkapselung (Programmierung)|Kapselung]] in Verbindung mit [[PPTP]]-Tunneln verwenden, eine potenziell unsichere Konfiguration nutzen.&lt;ref&gt;{{Internetquelle |url=https://support.microsoft.com/de-de/topic/implementieren-der-peap-ms-chap-v2-authentifizierung-f%C3%BCr-microsoft-pptp-vpns-d5ca1ebe-d9ee-4379-fd3f-e7be05fa3ae2 |titel=Implementieren der PEAP-MS-CHAP v2-Authentifizierung für Microsoft-PPTP-VPNs - Microsoft-Support |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Im Juli 2012 gab der Online-Dienst CloudCracker bekannt, VPN- und WLAN-Verbindungen, die auf MS-CHAPv2 basieren, innerhalb von 24 Stunden knacken zu können.&lt;ref&gt;{{Internetquelle |autor=heise online |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |autor=heise online |url=https://www.heise.de/hintergrund/Der-Todesstoss-fuer-PPTP-1701365.html |titel=Der Todesstoß für PPTP |datum=2012-09-22 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication {{!}} MSRC Blog {{!}} Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt; Der Brute-Force-Angriff gelingt dabei über Parallelisierung und speziell abgestimmte Hardware. Ein Durchbruch von Moxie Marlinspike reduzierte die Sicherheit von MS-CHAPv2 auf eine einzige DES-Verschlüsselung (2^56) unabhängig von der Passwortlänge.&lt;ref&gt;{{Internetquelle |url=https://msrc.microsoft.com/blog/2012/08/weaknesses-in-ms-chapv2-authentication/ |titel=Weaknesses in MS-CHAPv2 authentication {{!}} MSRC Blog {{!}} Microsoft Security Response Center |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>== Flaws ==</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>Weaknesses have been identified in MS-CHAP and MS-CHAPv2.&lt;ref&gt;{{Cite web |url=http://www.schneier.com/paper-pptpv2.pdf |title=Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first1=Bruce |last1=Schneier |authorlink1=Bruce Schneier |author2=Mudge |first3=David |last3=Wagner |website=schneier.com |date=19 October 1999 }}&lt;/ref&gt; The [[Data Encryption Standard|DES]] encryption used in NTLMv1 and MS-CHAPv2 to encrypt the [[NTLM]] password hash enable custom hardware attacks utilizing the method of brute force.&lt;ref&gt;{{Cite web |url=http://penguin-breeder.org/pptp/download/pptp_mschapv2.pdf |title=Exploiting known security holes in Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first=Jochen |last=Eisinger |date=23 July 2001 |website=penguin-breeder.org}}&lt;/ref&gt;</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Das Grundproblem liegt darin, dass MS-CHAP v2 auf eine vermischte Kombination dreier DES-Operationen setzt. Diese lässt sich durch Durchprobieren aller 2^56 möglichen DES-Schlüssel verlässlich knacken – ganz egal wie kompliziert das verwendete Passwort ist.&lt;ref&gt;{{Internetquelle |autor=heise online |url=https://www.heise.de/news/Microsoft-warnt-vor-PPTP-und-MS-CHAP-1671706.html |titel=Microsoft warnt vor PPTP und MS-CHAP |datum=2012-08-21 |sprache=de |abruf=2025-08-06}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken. The divide-and-conquer attack only requires breaking a single DES key, which is not difficult with modern [[GPU]]s and [[FPGA]]s.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt; MS-CHAP as a whole can be viewed as a smoke-and-mirrors protocol, in that ~80% of the protocol provides no real security; it just makes the construction very complicated and thus appear infeasible to crack. In reality, this ~80% is either plaintext messages, or messages easily derived from those sent in plaintext. The actual security core is reduced to the NTLM password hash and DES encryptions keyed by the hash output, which is fundamentally weak.</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or [[Extensible_Authentication_Protocol#EAP-TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>Nach [[Windows 11]] 22H2 können sich Benutzer mit der standardmäßigen Aktivierung von "Windows Defender Credential Guard" nicht mehr mit MSCHAPv2 authentifizieren. Die Entwickler empfehlen einen Wechsel von MSCHAPv2-basierten Verbindungen zu zertifikatbasierter Authentifizierung (wie PEAP-TLS oder [[Extensible Authentication Protocol#TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web |title=Considerations when using Windows Defender Credential Guard - Windows Security |date=January 27, 2023 |url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations |website=learn.microsoft.com}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>==See also==</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"><a class="mw-diff-movedpara-left" title="Der Absatz wurde verschoben. Klicken, um zur neuen Stelle zu springen." href="#movedpara_36_0_rhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_31_0_lhs"></a>* [[EFF DES cracker]]</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>== <del style="font-weight: bold; text-decoration: none;">References</del> ==</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>== <ins style="font-weight: bold; text-decoration: none;">Siehe auch</ins> ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>{{Reflist|30em}}</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker"><a class="mw-diff-movedpara-right" title="Der Absatz wurde verschoben. Klicken, um zur alten Stelle zu springen." href="#movedpara_31_0_lhs">&#x26AB;</a></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div><a name="movedpara_36_0_rhs"></a>* [[<ins style="font-weight: bold; text-decoration: none;">EFF DES Cracker|</ins>EFF DES cracker]]</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>{{Authentication APIs}}</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>== Einzelnachweise ==</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Category:Broken cryptography algorithms]]</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>&lt;references /&gt;</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Category:Internet protocols]]</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Authentifizierungsprotokoll]]</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Category:Microsoft Windows security technology]]</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> <tr> <td colspan="2" class="diff-empty diff-side-deleted"></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>[[Kategorie:Internetprotokollfamilie]]</div></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>[[Category:Computer access control protocols]]</div></td> <td colspan="2" class="diff-empty diff-side-added"></td> </tr> </table> TZRU https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258637240&oldid=prev 2001:8003:26A1:A700:B7C3:67AC:17BB:A1E0: /* Flaws */ 2025-02-02T13:29:38Z <p><span class="autocomment">Flaws</span></p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 2. Februar 2025, 14:29 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 18:</td> <td colspan="2" class="diff-lineno">Zeile 18:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Weaknesses have been identified in MS-CHAP and MS-CHAPv2.&lt;ref&gt;{{Cite web |url=http://www.schneier.com/paper-pptpv2.pdf |title=Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first1=Bruce |last1=Schneier |authorlink1=Bruce Schneier |author2=Mudge |first3=David |last3=Wagner |website=schneier.com |date=19 October 1999 }}&lt;/ref&gt; The [[Data Encryption Standard|DES]] encryption used in NTLMv1 and MS-CHAPv2 to encrypt the [[NTLM]] password hash enable custom hardware attacks utilizing the method of brute force.&lt;ref&gt;{{Cite web |url=http://penguin-breeder.org/pptp/download/pptp_mschapv2.pdf |title=Exploiting known security holes in Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first=Jochen |last=Eisinger |date=23 July 2001 |website=penguin-breeder.org}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Weaknesses have been identified in MS-CHAP and MS-CHAPv2.&lt;ref&gt;{{Cite web |url=http://www.schneier.com/paper-pptpv2.pdf |title=Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first1=Bruce |last1=Schneier |authorlink1=Bruce Schneier |author2=Mudge |first3=David |last3=Wagner |website=schneier.com |date=19 October 1999 }}&lt;/ref&gt; The [[Data Encryption Standard|DES]] encryption used in NTLMv1 and MS-CHAPv2 to encrypt the [[NTLM]] password hash enable custom hardware attacks utilizing the method of brute force.&lt;ref&gt;{{Cite web |url=http://penguin-breeder.org/pptp/download/pptp_mschapv2.pdf |title=Exploiting known security holes in Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first=Jochen |last=Eisinger |date=23 July 2001 |website=penguin-breeder.org}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken. The divide-and-conquer attack only requires breaking a single DES key, which is not difficult with modern [[GPU]]s and [[FPGA]]s.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt; MS-CHAP as a whole can be viewed as a smoke<del style="font-weight: bold; text-decoration: none;"> </del>and<del style="font-weight: bold; text-decoration: none;"> </del>mirrors protocol, in that ~80% of the protocol provides no real security; it just makes the construction very complicated and thus appear infeasible to crack. In reality, this ~80% is either plaintext messages, or messages easily derived from those sent in plaintext. The actual security core is reduced to the NTLM password hash and DES encryptions keyed by the hash output, which is fundamentally weak.</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken. The divide-and-conquer attack only requires breaking a single DES key, which is not difficult with modern [[GPU]]s and [[FPGA]]s.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt; MS-CHAP as a whole can be viewed as a smoke<ins style="font-weight: bold; text-decoration: none;">-</ins>and<ins style="font-weight: bold; text-decoration: none;">-</ins>mirrors protocol, in that ~80% of the protocol provides no real security; it just makes the construction very complicated and thus appear infeasible to crack. In reality, this ~80% is either plaintext messages, or messages easily derived from those sent in plaintext. The actual security core is reduced to the NTLM password hash and DES encryptions keyed by the hash output, which is fundamentally weak.</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or [[Extensible_Authentication_Protocol#EAP-TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or [[Extensible_Authentication_Protocol#EAP-TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> </tr> </table> 2001:8003:26A1:A700:B7C3:67AC:17BB:A1E0 https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258637239&oldid=prev 2001:8003:26A1:A700:B7C3:67AC:17BB:A1E0: /* Flaws */Added details on an attack and flaws pertaining to MS-CHAP 2025-02-02T13:15:05Z <p><span class="autocomment">Flaws: </span>Added details on an attack and flaws pertaining to MS-CHAP</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 2. Februar 2025, 14:15 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 18:</td> <td colspan="2" class="diff-lineno">Zeile 18:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Weaknesses have been identified in MS-CHAP and MS-CHAPv2.&lt;ref&gt;{{Cite web |url=http://www.schneier.com/paper-pptpv2.pdf |title=Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first1=Bruce |last1=Schneier |authorlink1=Bruce Schneier |author2=Mudge |first3=David |last3=Wagner |website=schneier.com |date=19 October 1999 }}&lt;/ref&gt; The [[Data Encryption Standard|DES]] encryption used in NTLMv1 and MS-CHAPv2 to encrypt the [[NTLM]] password hash enable custom hardware attacks utilizing the method of brute force.&lt;ref&gt;{{Cite web |url=http://penguin-breeder.org/pptp/download/pptp_mschapv2.pdf |title=Exploiting known security holes in Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first=Jochen |last=Eisinger |date=23 July 2001 |website=penguin-breeder.org}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>Weaknesses have been identified in MS-CHAP and MS-CHAPv2.&lt;ref&gt;{{Cite web |url=http://www.schneier.com/paper-pptpv2.pdf |title=Cryptanalysis of Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first1=Bruce |last1=Schneier |authorlink1=Bruce Schneier |author2=Mudge |first3=David |last3=Wagner |website=schneier.com |date=19 October 1999 }}&lt;/ref&gt; The [[Data Encryption Standard|DES]] encryption used in NTLMv1 and MS-CHAPv2 to encrypt the [[NTLM]] password hash enable custom hardware attacks utilizing the method of brute force.&lt;ref&gt;{{Cite web |url=http://penguin-breeder.org/pptp/download/pptp_mschapv2.pdf |title=Exploiting known security holes in Microsoft's PPTP Authentication Extensions (MS-CHAPv2) |first=Jochen |last=Eisinger |date=23 July 2001 |website=penguin-breeder.org}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken<ins style="font-weight: bold; text-decoration: none;">. The divide-and-conquer attack only requires breaking a single DES key, which is not difficult with modern [[GPU]]s and [[FPGA]]s</ins>.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt;<ins style="font-weight: bold; text-decoration: none;"> MS-CHAP as a whole can be viewed as a smoke and mirrors protocol, in that ~80% of the protocol provides no real security; it just makes the construction very complicated and thus appear infeasible to crack. In reality, this ~80% is either plaintext messages, or messages easily derived from those sent in plaintext. The actual security core is reduced to the NTLM password hash and DES encryptions keyed by the hash output, which is fundamentally weak.</ins></div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or [[Extensible_Authentication_Protocol#EAP-TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or [[Extensible_Authentication_Protocol#EAP-TLS|EAP-TLS]]).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> </tr> </table> 2001:8003:26A1:A700:B7C3:67AC:17BB:A1E0 https://de.wikipedia.org/w/index.php?title=MS-CHAP&diff=258637238&oldid=prev en>Stout256: /* Flaws */ Add link to EAP-TLS 2024-11-23T12:09:15Z <p><span class="autocomment">Flaws: </span> Add link to EAP-TLS</p> <table style="background-color: #fff; color: #202122;" data-mw="interface"> <col class="diff-marker" /> <col class="diff-content" /> <col class="diff-marker" /> <col class="diff-content" /> <tr class="diff-title" lang="de"> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">← Nächstältere Version</td> <td colspan="2" style="background-color: #fff; color: #202122; text-align: center;">Version vom 23. November 2024, 13:09 Uhr</td> </tr><tr> <td colspan="2" class="diff-lineno">Zeile 20:</td> <td colspan="2" class="diff-lineno">Zeile 20:</td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt;</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>As of 2012, MS-CHAP had been completely broken.&lt;ref&gt;{{cite web|url=https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|title=Divide and Conquer: Cracking MS-CHAPv2 with a 100% success rate|year=2012|publisher=[[DEF CON|David Hulton]]|archive-url=https://web.archive.org/web/20160316174007/https://www.cloudcracker.com/blog/2012/07/29/cracking-ms-chap-v2/|archive-date=16 March 2016|access-date=2013-03-10}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker" data-marker="−"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or EAP-TLS).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> <td class="diff-marker" data-marker="+"></td> <td style="color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;"><div>After [[Windows 11]] 22H2, with the default activation of Windows Defender Credential Guard, users can no longer authenticate with MSCHAPv2. The developers recommend a move from MSCHAPv2-based connections to certificate-based authentication (such as PEAP-TLS or <ins style="font-weight: bold; text-decoration: none;">[[Extensible_Authentication_Protocol#</ins>EAP-TLS<ins style="font-weight: bold; text-decoration: none;">|EAP-TLS]]</ins>).&lt;ref&gt;{{Cite web|url=https://learn.microsoft.com/en-us/windows/security/identity-protection/credential-guard/credential-guard-considerations|title=Considerations when using Windows Defender Credential Guard - Windows Security|date=January 27, 2023|website=learn.microsoft.com}}&lt;/ref&gt;</div></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><br /></td> </tr> <tr> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==See also==</div></td> <td class="diff-marker"></td> <td style="background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;"><div>==See also==</div></td> </tr> </table> en>Stout256