security(freeradius): enforce require_message_authenticator globally
- Set require_message_authenticator = yes in security block - Set limit_proxy_state = yes - Mitigate BLASTRADIUS vulnerability - Harden RADIUS request validation
This commit is contained in:
+2
-2
@@ -720,7 +720,7 @@ security {
|
|||||||
# this flag to "no", in which case the network will work,
|
# this flag to "no", in which case the network will work,
|
||||||
# but will be vulnerable to the attack.
|
# but will be vulnerable to the attack.
|
||||||
#
|
#
|
||||||
require_message_authenticator = auto
|
require_message_authenticator = yes
|
||||||
|
|
||||||
#
|
#
|
||||||
# Global configuration for limiting the combination of
|
# Global configuration for limiting the combination of
|
||||||
@@ -811,7 +811,7 @@ security {
|
|||||||
# this flag to "no", in which case the network will work,
|
# this flag to "no", in which case the network will work,
|
||||||
# but will be vulnerable to the attack.
|
# but will be vulnerable to the attack.
|
||||||
#
|
#
|
||||||
limit_proxy_state = auto
|
limit_proxy_state = yes
|
||||||
|
|
||||||
|
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user