You can use normal user/password and use the same "word" for both.
In html or javascript you would post the same value.
I'll try to include an example later if needed.
$(if chap-id)
<form name="sendin" action="$(link-login-only)" method="post">
<input type="hidden" name="username" />
<input type="hidden" name="password" />
<input type="hidden" name="dst" value="$(link-orig)" />
<input type="hidden" name="popup" value="true" />
<script type="text/javascript" src="/md5.js"></script>
<script type="text/javascript">
function doLogin() {
document.sendin.username.value = document.login.username.value;
document.sendin.password.value = hexMD5('$(chap-id)' + document.login.username.value + '$(chap-challenge)');
return false;