Re: RADIUS shared secret over internet

2013-04-09 Thread Stefan Winter
Hi, RADSEC These days, the more proper answer is: RFC6614 http://tools.ietf.org/html/rfc6614 :-) Stefan -- Stefan WINTER Ingenieur de Recherche Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et de la Recherche 6, rue Richard Coudenhove-Kalergi L-1359 Luxembourg Tel:

Re: RADIUS shared secret over internet

2013-04-09 Thread Fajar A. Nugraha
On Tue, Apr 9, 2013 at 2:52 PM, Muhammad Nuzaihan Kamal Luddin muham...@taqisystems.com wrote: Hi, I have read on the archives regarding the above issue and that the RADIUS shared secret is an obfuscation method of securing the communications between the NAS and RADIUS Server. One method i

Re: RADIUS shared secret over internet

2013-04-09 Thread Muhammad Nuzaihan bin Kamal Luddin
Interesting method by using TLS. This is what i had in mind but couldn't find the answer. The only method i see is through proxying the requests, based on a whitepaper i read - if this is what RFC6614 may contain. What are the roadmap for this? Are there any initial work being done or

Re: RADIUS shared secret over internet

2013-04-09 Thread Marinko Tarlać
As I remmember, Alan mentioned that RADSEC will be implemented in freeRadius 3... On 9.4.2013 10:54, Muhammad Nuzaihan bin Kamal Luddin wrote: Interesting method by using TLS. This is what i had in mind but couldn't find the answer. The only method i see is through proxying the requests,

Re: RADIUS shared secret over internet

2013-04-09 Thread A . L . M . Buxey
Hi, As I remmember, Alan mentioned that RADSEC will be implemented in freeRadius 3... correct. you can try/test/run FR3 today from GIT but if you want to keep with FR2.x in the meantime you can always have a local proxy eg RadSecProxy which works fine with FR2.x (and each end can do

RE: RADIUS shared secret over internet

2013-04-09 Thread Brian Julin
Muhammad Nuzaihan wrote: What are the roadmap for this? Are there any initial work being done or proof-of-concept work on this? By looking at implementations of TLS (in combination of openssl/gnutls) on other protocols might be similar to this but i may be wrong (i have yet to read on the