From 629a51a905622fb605800115abc14c9d8e134de1 Mon Sep 17 00:00:00 2001 From: "noussair.hamrit" Date: Fri, 27 Feb 2026 11:17:09 +0100 Subject: [PATCH] security(freeradius): enforce require_message_authenticator globally - Set require_message_authenticator = yes in security block - Set limit_proxy_state = yes - Mitigate BLASTRADIUS vulnerability - Harden RADIUS request validation --- files/radius.conf | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/files/radius.conf b/files/radius.conf index 7105a01..cb9f3d3 100644 --- a/files/radius.conf +++ b/files/radius.conf @@ -720,7 +720,7 @@ security { # this flag to "no", in which case the network will work, # but will be vulnerable to the attack. # - require_message_authenticator = auto + require_message_authenticator = yes # # Global configuration for limiting the combination of @@ -811,7 +811,7 @@ security { # this flag to "no", in which case the network will work, # but will be vulnerable to the attack. # - limit_proxy_state = auto + limit_proxy_state = yes }