security(freeradius): enforce require_message_authenticator globally

- Set require_message_authenticator = yes in security block
- Set limit_proxy_state = yes
- Mitigate BLASTRADIUS vulnerability
- Harden RADIUS request validation
This commit is contained in:
2026-02-27 21:59:10 +01:00
parent fc35d35b00
commit 629a51a905
+2 -2
View File
@@ -720,7 +720,7 @@ security {
# this flag to "no", in which case the network will work, # this flag to "no", in which case the network will work,
# but will be vulnerable to the attack. # but will be vulnerable to the attack.
# #
require_message_authenticator = auto require_message_authenticator = yes
# #
# Global configuration for limiting the combination of # Global configuration for limiting the combination of
@@ -811,7 +811,7 @@ security {
# this flag to "no", in which case the network will work, # this flag to "no", in which case the network will work,
# but will be vulnerable to the attack. # but will be vulnerable to the attack.
# #
limit_proxy_state = auto limit_proxy_state = yes
} }