Commit Graph
25 Commits
Author SHA1 Message Date
gitea_admin 728b99e138 fix(radius): prevent devices from using sqlippool during accounting 2026-09-16 17:04:06 +02:00
gitea_admin 8434a13338 fix(freeradius): check IP after pool allocation 2026-09-10 13:47:55 +02:00
gitea_admin cf98b8dd81 fix(freeradius): log no-IP rejection reason 2026-09-09 16:26:59 +02:00
gitea_admin 8217c2ee61 fix(freeradius): disable VLAN assignment 2026-09-09 13:27:05 +02:00
gitea_admin 4f9937d351 fix(freeradius): replace MySQL SUBSTRING_INDEX with PostgreSQL split_part 2026-09-08 11:37:20 +02:00
gitea_admin a656e83473 fix(freeradius): add post-auth reason to PostgreSQL queries
- include reason in radpostauth INSERT columns
- store Reply-Message as the authentication reason
2026-09-08 10:31:28 +02:00
gitea_admin 20b260a795 feat(freeradius): add PostgreSQL support and release 2.0.0
- add separate MySQL and PostgreSQL query configurations
- fix radpostauth INSERT query for PostgreSQL
- remove obsolete pass column from post-auth query
- update ConfigMap and Deployment templates
- bump chart version to 2.0.0
2026-09-08 10:04:31 +02:00
gitea_admin 1a1e37ffdf feat(freeradius): add dynamic tenant VLAN assignment via unlang policy 2026-05-12 15:50:18 +02:00
gitea_admin 328ff7511c feat: enforce Framed-IP-Address presence in access decisions
Add hard validation to reject requests without assigned IP address,
including clear rejection message for audit trail.
2026-04-22 19:15:04 +02:00
gitea_admin 064bda9e20 feat(freeradius): log Reply-Message in radpostauth instead of only packet type
- Store Reply-Message when available, fallback to Packet-Type otherwise
- Improves visibility of authentication failures (e.g. "already logged in")
2026-04-21 12:51:12 +02:00
gitea_admin 69a4e3a3b8 feat(freeradius): implement node pinning and dynamic IP allocation
- add node pinning logic in authorize (reject if wrong node)
- optimize SQL queries using control variables
- assign Pool-Name dynamically for engineers
- integrate sqlippool for dynamic IP allocation (engineers only)
- add Session-Timeout aligned with lease_duration
- fix duplicate sqlippool execution in post-auth/accounting
- configure sqlippool with NAS-IP scoping for multi-node isolation

Ensures correct routing, tenant isolation, and scalable IP management.
2026-04-20 16:15:55 +02:00
gitea_admin fca66dfa52 Add RADIUS node pinning to enforce client connection to assigned OpenVPN node 2026-04-14 16:24:35 +02:00
gitea_admin 8c1289f92e Disable strict realm validation to allow username format user@tenant (non-DNS realm). 2026-04-13 18:50:15 +02:00
gitea_admin c245ab29af feat(freeradius): enable sqlippool for centralized IP allocation
- Add sqlippool module configuration
- Integrate sqlippool into authorize, post-auth, and accounting sections
- Add radippool table schema (InnoDB)
- Update Helm ConfigMap and Deployment templates
- Enable centralized IP management for OpenVPN cluster
- Bump Helm chart version to 1.0.12
2026-03-03 11:31:41 +01:00
gitea_admin 629a51a905 security(freeradius): enforce require_message_authenticator globally
- Set require_message_authenticator = yes in security block
- Set limit_proxy_state = yes
- Mitigate BLASTRADIUS vulnerability
- Harden RADIUS request validation
2026-02-27 21:59:10 +01:00
gitea_admin fc35d35b00 fix(radius/openvpn): activate SQL authorize pipeline to enforce static IP allocation
- Enable `sql` in sites-enabled/default authorize section
- Allow processing of radreply attributes (e.g. Framed-IP-Address)
- Fix static IP assignment from RADIUS for OpenVPN clients
- Bump Helm chart version to 1.0.11
2026-02-26 16:34:51 +01:00
gitea_admin 35e0f2f419 feat(freeradius): add radius.conf and queries.conf ConfigMaps and bump chart version
- Move FreeRADIUS SQL and radius.conf into ConfigMaps
- Add /etc/freeradius/mods-config/sql/main/mysql/queries.conf and /etc/freeradius/radius.conf templates for Helm deployment
- Update SQL post-auth query formatting
- Enable suppress_secrets in radius.conf
- Bump Helm chart version to 1.0.10
- Adjust GitLab CI and Deployment to use new config structure
2026-02-03 15:33:08 +01:00
gitea_admin a08dcf6983 feat(radius): enable dynamic client support via SQL nas table
- Activated `dynamic_clients` module to allow loading RADIUS clients dynamically from the database
- Configured SQL query to fetch client secret, shortname, and type based on Packet-Src-IP-Address
- Integrated `dynamic_clients` into the `authorize` section for real-time NAS resolution
- Eliminated need to restart FreeRADIUS when adding new NAS entries
2025-07-01 12:13:43 +02:00
gitea_admin aad17e7b3f enable SQL accounting and disable detail logging in FreeRADIUS 2025-07-01 10:35:07 +02:00
gitea_admin 4885bc1eb4 edit mods-availabe/eap form default_eap_type= md5 to default_eap_type=peap 2025-06-30 13:19:44 +02:00
gitea_admin 3ccf50ed57 feat: add EAP module support with dynamic CA file path and config injection
- Added `files/mods-available/eap` with environment-based `ca_file` reference
- Updated `mods-enabled.yaml` to include EAP module via Helm `.Files.Glob`
- Modified `Deployment.yaml` to mount EAP config into /mods-enabled/eap
2025-06-30 12:35:39 +02:00
gitea_admin bb0a10b2bf Disable Client Certificate Requirement 2025-06-24 16:43:25 +02:00
gitea_admin a7e7202761 comment out clients = radsec on freeradius/files/sites-available/tls 2025-06-24 15:49:19 +02:00
gitea_admin 642f747b48 comment out the “dh_file” configuration element from files/sites-available/tls 2025-06-24 12:04:48 +02:00
gitea_admin 98c2fa6240 Initial commit
- update else condition on the line 239 in templates/Deployment
- update  st-common version from 0.1.10 to 0.1.12 on Chart.yaml file
- add gitlab ci/cd pipeline to  package the Helm chart into a .tgz. and Publish it to GitLab’s Helm package registry
2025-06-24 11:20:34 +02:00