Accounting request duplication check

Alan DeKok aland at deployingradius.com
Thu Jul 28 13:38:33 CEST 2016


On Jul 27, 2016, at 8:24 PM, L Wu via Freeradius-Users <freeradius-users at lists.freeradius.org> wrote:
> 
> I recently noticed that the freeradius server checks duplicated requests by comparing length and authenticator.
> This is fine with authentication request because the Authenticator field in Access-Request is a random number.
> However, in Accounting-Request, the Authenticator is MD5-hashed with same info, unless length is different (assuming same other attributes info.). If length is the same, this way, there is basically no duplicate packet check. 

  If the accounting packets are identical, then they are duplicates.

  Alan DeKok.




More information about the Freeradius-Users mailing list