security(freeradius): enforce require_message_authenticator globally
- Set require_message_authenticator = yes in security block - Set limit_proxy_state = yes - Mitigate BLASTRADIUS vulnerability - Harden RADIUS request validation
This commit is contained in:
+2
-2
@@ -720,7 +720,7 @@ security {
|
||||
# this flag to "no", in which case the network will work,
|
||||
# but will be vulnerable to the attack.
|
||||
#
|
||||
require_message_authenticator = auto
|
||||
require_message_authenticator = yes
|
||||
|
||||
#
|
||||
# Global configuration for limiting the combination of
|
||||
@@ -811,7 +811,7 @@ security {
|
||||
# this flag to "no", in which case the network will work,
|
||||
# but will be vulnerable to the attack.
|
||||
#
|
||||
limit_proxy_state = auto
|
||||
limit_proxy_state = yes
|
||||
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user