I don't disagree with you there, but at lease the wire it's going over
can't easily be accessed.  Plus, my firewall prohibits radius queries
from anyone but trusted hosts.  Agreed it would be nice, but it's what I
have to work with.  I don't want to do mac access lists in each AP ....


Charlie





-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Alan DeKok
Sent: Tuesday, July 16, 2002 7:39 AM
To: [EMAIL PROTECTED]
Subject: Re: Can Radius be used to my wireless network users 


"Charles J. Boening" <[EMAIL PROTECTED]> wrote:
> My Orinoco equipment sends the MAC address as the username and the 
> radius shared secret as the password.

  That's *horrible*!

  The whole point of the shared secret is that it never goes over the
wire, in *any* form.  The Orinoco equipment should be passing
*another* string in the password field.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See
http://www.freeradius.org/list/users.html


- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to