[EXT] TLS 1.3

HERCEK, Marián marian.hercek at ucm.sk
Fri Jun 4 11:40:13 CEST 2021


I had to downgrade to 3.0.21 where old devices work.

I've tried config from 3.0.21 with 3.0.22 binary - didn't work.
I've tried config shipped with 3.0.22 binary - didn't work.
I've tried numerous config changes suggested on internet and here - didn't work.

I've tried 3.0.21 binary with backuped 3.0.21 config - it works.


-----Pôvodná správa-----
Od: Freeradius-Users <freeradius-users-bounces+marian.hercek=ucm.sk at lists.freeradius.org> V mene používateľa Alan DeKok
Odoslané: pondelok 31. mája 2021 14:16
Komu: FreeRadius users mailing list <freeradius-users at lists.freeradius.org>
Predmet: Re: [EXT] TLS 1.3

On May 31, 2021, at 8:10 AM, L.P.H. van Belle via Freeradius-Users <freeradius-users at lists.freeradius.org> wrote:
> 
> For Android 4.4: it may be compatible with TLS 1.1 and TLS 1.2 but 
> some devices with Android 4.4.x may not support TLS 1.1 or higher.

  Yup.  Which is why we changed the default configuration, but didn't forbid the use of TLS 1.0 and TLS 1.1 in the code.

  RFC 8996 officially deprecates TLS 1.0 and 1.1.  Which means we'll likely be using them for another 5 years.  :(

  Alan DeKok.


-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6860 bytes
Desc: not available
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20210604/929804a0/attachment-0001.bin>


More information about the Freeradius-Users mailing list