Alan DeKok wrote:
In my project, I don't own the hotspots, and don't know about the hotspots ISPs. The hotspots communicate to the radius server though the internet. Ok. I don't know much about the radius protocol details, maybe you could help me understanding how secure would be a solution where the secret is know by everybody. Chillispot uses CHAP authentication with a different secret per hotspot. I consider is part as secure. Now, once a user is authenticated, how does the nas send accounting info? Does it have to authenticate again, or is its ip address (and its (public known)secret) sufficient to authenticate? Do you need at least a session id? Imagine that the malicious use cannot listen to the radius communications. What can it do without authentication? I need security, because I will use accounting info to perform facturation... Thanks for your great help. this means I must use a vpn client to connect to the radius server? I would have liked a simple chillispot installation... Regards Sophana KOK |