public secret and public radius server. Is it secure?

vertito mnisay at aim-consultants.com
Fri Jun 2 17:42:40 CEST 2006


 
vertito wrote:

> 
>
>My question is :
>- What can a malicious user can do with the secret? Can it alter 
>accounting and other things? (chillispot uses chap auth-type)
>
>one is spell it out and try rumble it so he forms a new word from it
>  
>
Is it a real security problem? I will be using accounting for facturation
purposes...

>- Is there a way of maintaining a per hotspot secret with dynamic ip 
>addresses?
>
>yes. check client and clients.conf relationship
>  
>
I did not find. clients.conf entry seems to be ip based.
How do I setup a NAS without knowing its ip? (and differentiate between
several of them)
-

why not implement static IP for APs?


-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.394 / Virus Database: 268.8.1/354 - Release Date: 6/1/2006
 




More information about the Freeradius-Users mailing list