Learning about MS-CHAP

Opinion
May 12, 20031 min

Where can I find information on MS-CHAP Versions 1 and 2? I’m looking for details on the authentication mechanism used, why it might be better than CHAP and what extensions there might be.

The Windows 2000 Security Little Black Book by Ian McLean says MS-CHAP provides more security than CHAP “because it allows the server to store hashed passwords rather than clear-text passwords.”

MS-CHAP is described in RFC documents at www.ietf.org/rfc.html. RFCs describe the protocols in great detail. Newer documents have larger numbers and may make earlier RFCs obsolete. RFC 2433 defines the packet-level protocol differences between MS-CHAP and CHAP (the primary differences are in the format of the Response packets).

CHAP is defined in RFC 1994. Version 2 of MS-CHAP (used in Windows 2000) is defined in RFC 2759, which says that Version 2 is “similar to, but incompatible with MS-CHAP” and explains why. The most recent mention of MS-CHAP we found was in RFC 3079, on Deriving Keys for use with Microsoft Point-to-Point Encryption.