Network World
Friday, September 5, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Wireless & Mobile

Navigation

Re: Securing a RADIUS server

"For instance if you're using an LDAP directory to store authentication information, you can easily use SSL to encrypt traffic to and from it."

Really... I would be interested in hearing how? Using OpenLDAP and FreeRADIUS?

Re: Securing a RADIUS server.

OpenLDAP + FreeRADIUS + SSL/TLS

0

If you already have a working OpenLDAP and FreeRADIUS setup, but are not using SSL/TLS you can try out using stunnel on both sides of the connection: http://www.stunnel.org/examples/generic_tunnel.html

It's not quite as elegant as using each project's built-in SSL/TLS support, but you can set it up without mucking with your current configuration too much.

Setting up OpenLDAP to support SSL/TLS is documented here:
http://www.openldap.org/faq/data/cache/185.html

The default radiusd.conf supplied with FreeRADIUS also contains
examples for how to setup TLS on the RADIUS server side of the
operation.

Hope that helps. If you have any other questions don't hesitate to send them to wireless-security@nww.com.

--Andrew

OpenLDAP + FreeRADIUS + SSL/TLS

0

Yes, this solution can greatly improve wireless network security, but if you implement something different from Eap/tls with mutual authentification with previous installed certicate, it could happen that a user "forget" to authenticate the AAA server (freeradius in this case) and mitm attack raises (read mitm as Rouge AP). Keep in mind that even with mutual authentication there's still room for an attack as exaplained in "An initial security analysis of the IEEE802.1x Standard" by Arunesh Mishra and William A. Arbaugh 6 Feb 2002.

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Latest wireless headlines from Network World:

Vodafone to resell Dell's netbook

Six common complaints about Apple's iPhone 3G

Latest 802.11 standards: Too little too late?

Two "iGadgets" enhance music experience

Samsung builds Russian WiMax network

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: