@bottledpaul Check SeLinux :) Or, tcpdump to see if the packets are actually arriving at the machine. If so, it's likely the OS which isn't delivering them to FreeRADIUS
Un ancien physicien canadien contrôle l'authentification de 100 millions d'utilisateurs quotidiens. Alan DeKok maintient seul FreeRADIUS depuis 1999 — la moitié des connexions internet mondiales passent par son code.
https://t.co/0IO15G2Xv6
@FFmpeg This, 100%. A multi-billion dollar company can't find the time to send a patch? No reasonable person should expect a volunteer to write a patch, just to keep that company happy.
@MyNameIsMurray@beamflash The cloud RADIUS solutions haven't given a single penny or line of code to help with FreeRADIUS. While they're welcome to do more, history shows that they won't.
We're working on updated TEAP for TEAPv2. Any external help is welcome.
@MyNameIsMurray@beamflash Unfortunately while the spec allows for certificate provisioning, the Microsoft client doesn't do this. Which means that any certificate provisioning has to be done outside of TEAP.
@beamflash@MyNameIsMurray Huh? FreeRADIUS supports device success and no user auth, which can be used for onboarding. The TEAP protocol doesn't allow for the inner user auth to fail, but still have the outer TEAP succeed. Read the specs to see why.
@yosida95 Problems with FR usually fall into one of two issues.
1. under specified requirements. "I want to do stuff" is not an actionable requirement.
2. Not reading the debug output. "I changed a bunch of stuff and now it doesn't work". Maybe look at the debug output to see why?
@AnyunguWanyungu We don't recommend LLMs for configuring FreeRADIUS. There's not a lot of good training data for them to use, so they just make things up. A lot.
The LLM suggestions for FreeRADIUS configuration will be wrong. Most aren't even correct FR syntax!
@beamflash@Collab_Seth@MyNameIsMurray That works today in FreeRADIUS. We've pushed some things recently which make it easier to configure. These changes will be in 3.2.8
@MyNameIsMurray@Collab_Seth At this point, pretty much everything that isn't Cisco, Microsoft, or Nokia is "FreeRADIUS under the hood". Especially various "cloud" or "product" vendors who have long marketing articles about how terrible FreeRADIUS is. :)
@l0ldbl00d@Xxxxuuuuy_ If the module is useful for other people, send it over in a GitHub PR. We'll take a look at integrating it into the next release.
@Collab_Seth@MyNameIsMurray TEAP has limited uses right now. Only small parts of the standard are interoperable across all vendors. We're working on RFC717-bis, and then after that TEAPv2. These updates will fix all of the issues with TEAP.
There is a lot of misleading security advice out there. e.g. many sites copy the same tired myths about PAP vs CHAP.
This is wrong: https://t.co/ndNdUglpMe
The truth: https://t.co/vf1MZQtTbV
Don't use CHAP. PAP is better.
@michal_aibin
The RADIUS conference went very well. We have agreement from operators and impementers on how to fix long-standing issues with the protocol. https://t.co/PJRSYxZIxs