security(freeradius): enforce require_message_authenticator globally

- Set require_message_authenticator = yes in security block
- Set limit_proxy_state = yes
- Mitigate BLASTRADIUS vulnerability
- Harden RADIUS request validation
This commit is contained in:
2026-02-27 21:59:10 +01:00
parent fc35d35b00
commit 629a51a905
+2 -2
View File
@@ -720,7 +720,7 @@ security {
# this flag to "no", in which case the network will work,
# but will be vulnerable to the attack.
#
require_message_authenticator = auto
require_message_authenticator = yes
#
# Global configuration for limiting the combination of
@@ -811,7 +811,7 @@ security {
# this flag to "no", in which case the network will work,
# but will be vulnerable to the attack.
#
limit_proxy_state = auto
limit_proxy_state = yes
}