Issue with OpenSSL

Alan DeKok aland at deployingradius.com
Wed Mar 16 01:56:03 UTC 2022


  If you have EAP-TLS or RadSec configured, you probably want to update OpenSSL:

https://www.openssl.org/news/secadv/20220315.txt

  This isn't an issue in FreeRADIUS but a malicious person can use WiFi + EAP-TLS to "lock up" the RADIUS server.  The only fix is to either disable the use of client certificates, or to upgrade OpenSSL.

  Alan DeKok.



More information about the Freeradius-Users mailing list