sthen a4d4b9922a update to freeradius 3.0.14.
Security update for configurations with TLS; FreeRADIUS intentionally
skips inner authentication for TLS resumption, however it allows a
session to be resumed before the initial connection has authenticated,
allowing access without auth to a malicious supplicant. CVE-2017-9148,
See http://seclists.org/oss-sec/2017/q2/342

Workaround: set "enabled = no" in the cache section of raddb/mods-enabled/eap.
2017-05-30 13:12:30 +00:00
..
2017-05-30 13:12:30 +00:00
2017-05-30 13:12:30 +00:00
2017-05-30 13:12:30 +00:00
2017-05-30 13:12:30 +00:00