Is it possible to execute check-eap-tls before checking ocsp?

Alan DeKok aland at deployingradius.com
Sat Apr 23 14:51:21 CEST 2016


On Apr 23, 2016, at 6:24 AM, Mitsuhiro Nakamura <mitsuhiro.nakamura at nabiq.co.jp> wrote:
> I have to protect cert ddos attacks for OCSP server.

  The solution is to limit the number of EAP authentications which can be done.

  And to be honest, EAP takes more work than OCSP checks.  If your OCSP server can't keep up with EAP traffic, you need to upgrade your OCSP server.

  Alan DeKok.




More information about the Freeradius-Users mailing list