Why does the server say the password is bad, when its obviously correct?
It is possible for the password to encoded properly (in any method but PAP) yet the shared secret is wrong. The server will deduce that the password is correct but the client will discover that the response packet’s authenticator is incorrect (ms-signed). The client MUST treat the packet as an Access-Reject.