Project

General

Profile

Actions

Feature #15952

closed

Support Message-Authenticator in the PHP RADIUS client

Added by Matthew Ross about 1 year ago. Updated 25 days ago.

Status:
Resolved
Priority:
Normal
Category:
Authentication
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.03
Release Notes:
Default

Description

In response to Blast-RADIUS (CVE-2024-3596), we need more secure options for User Authentication via RADIUS. Ideally, we'd have support for EAP protocol types rather than the insecure MS-CHAP and even more insecure PAP. Or at the least, support for using the Message-Authenticator attribute in the packet.

We already have support for EAP protocol types in FreeRADIUS and for authenticating IPSec, so I'm not sure why it's not part of the User authentication RADIUS client too.


Files

RADIUSPRTCL.png (47.8 KB) RADIUSPRTCL.png List of currently available protocols for RADIUS authentication client Matthew Ross, 12/24/2024 04:14 PM
clipboard-202511121020-gmo8v.png (88.2 KB) clipboard-202511121020-gmo8v.png Ansley Barnes, 11/12/2025 03:20 PM
clipboard-202512131136-oilga.png (8.31 KB) clipboard-202512131136-oilga.png Stefano Ceccherini, 12/13/2025 10:36 AM
Actions

Also available in: Atom PDF