Re: [RADIATOR] Radius and TACACS+ password obfuscation

2016-09-22 Thread Heikki Vatiainen
On 21.9.2016 18.13, Nadav Hod wrote: > I read this in the Radiator 4.17 release notes: > > "Added initial support for encrypting and obfuscating TACACS+ keys in > the configuration file. This is similar to the recently added RADIUS > client shared secret obfuscation. Client and ServerTACACASPLUS n

[RADIATOR] ServerRADSEC: TLSv1.1 and TLSv1.2 are by default disabled even if all software supports them

2016-09-22 Thread Stefan Winter
Hello, I am just now setting up a new incarnation of our RadSEC enabled Radiator server: Radiator 4.17 Net::SSLeay 1.78 OpenSSL 1.0.1e (newest CentOS 7.2 backports) All of which support TLS 1.2. I use a ServerRADSEC clause with UseTLS on but that only establishes TLS 1.0 connections. When pok

Re: [RADIATOR] Radius and TACACS+ password obfuscation

2016-09-22 Thread Nadav Hod
Thanks for the quick reply Heikki, >From the looks of things, this requires certain Linux primitives (for lack of >better term) such as rcrypt. This could just be a misunderstanding. Is there a >supported solution for Windows Server deployments? From: r