Showing posts with label radius AAA. Show all posts
Showing posts with label radius AAA. Show all posts

Tuesday, November 21, 2023

RADIUS news from IETF118

Practically all current Wi-Fi controllers and APs for enterprise and carriers support RADIUS. Mobile network APN and DNN authentication, fixed line fiber-to-the-home gateways and other broadband equipment depend on RADIUS authentication. The industry that uses RADIUS is growing and the standardisation work is active proving RADIUS is in rude health.

The latest Internet Engineering Task Force (IETF) meeting was held earlier this month in Prague, Czechia - with the Radiator team in attendance. RADIUS work is mainly done by the RADIUS EXTensions (radext) working group. The current radext draft documents are related to security enhancements, protocol extensions, maintenance and best practices.

TLS-PSK and RADIUS 1.1

TLS-PSK for RADIUS over TLS and DTLS (also known as RadSec) draft is moving towards the publication phase. The draft has completed its development within the working group. The intended status for the draft is to become an Informational RFC. TLS-PSK greatly eases the configuration of RadSec by using Pre-Shared Keys with TLS instead of certificates.

Closely following the TLS-PSK draft is the draft for RADIUS Version 1.1. This draft is currently in the working group last call phase before it moves on towards publication. With RADIUS Version 1.1, the obsolete methods for RADIUS integrity and authentication are replaced by TLS and DTLS.

RadSec update and depreciation of insecure methods

Other work still in the draft development phase includes an update to RadSec. The update obsoletes the current RFCs for RADIUS over TLS (RFC 6614) and RADIUS over DTLS (RFC 7360) by merging them into a single specification. The draft obsoletes TLS 1.1 and earlier versions, requires TLS-PSK for servers, clarifies the use of DTLS, TLS session resumption, certificate verification and other topics.

Security of RADIUS is updated by a draft that deprecates insecure transport and authentication methods. The draft discusses the problems with unencrypted UDP and TCP transports and common RADIUS authentication methods, such as CHAP. The draft formally deprecates a number of ways these are currently insecurely used. Use of TLS or IPsec transport is now mandated and scope of UDP and TCP transports is reduced.These unsecured transports can be used in secure networks only.

RadSec CoA and Roaming support enhancements

RADIUS dynamic authorisation is updated by a draft that defines how to use existing RadSec connections to send change of authorization (CoA) requests. This allows easier CoA deployments in environments where firewalls, routing or other reasons make it hard to send requests towards a RADIUS client. This specification documents the existing usage that is already implemented by a number of server and client vendors.

Roaming support enhancements are defined in a draft that is currently in working group adoption phase. These enhancements include RADIUS request routing loop detection, remote realm status check and RADIUS request path discovery. This draft is likely approved as a working group draft before the end of the year.

The radext working group is also helping other IETF working groups with draft reviews, liaison work with other organisations, such as Wireless Broadband Alliance (WBA). The working group may continue to work on other documents after the current ones are finished.

What do I gain as a Radiator user?

The new functionality becomes available in Radiator when the drafts are nearing completion. For example TLS-PSK support is made available with the existing RadSec support allowing the Radiator customers to choose between PSK and certificate authentication. As a Radiator user, you will directly benefit from the work we do in the IETF. This will ensure your authentication service stays current and secure and follows the latest standards.

Want to know more?

For status of all current drafts and the working group in general, see https://datatracker.ietf.org/wg/radext/documents/

If you want to know more about Radiator team’s involvement in standardisation or discuss Radiator roadmap items from these drafts, please contact info@radiatorsoftware.com

Tuesday, September 18, 2018

Radiator as a Cisco ACS replacement

Since Cisco announced the end of sale of their Secure Access Control System (Cisco ACS), customers have contacted Radiator Software looking for a replacement solution, and they have found Radiator AAA Server Software to be just the alternative they need. Radiator is a cost-effective, flexible solution that is known in the market as the “Swiss Army of AAA Servers”.

Radiator AAA Server Software is actively developed and it runs with a variety of platforms, including Linux, Windows, and others. You can be sure that you will have a supported, continuously developed AAA solution that is always kept up to date for years to come. Radiator has at least two releases per year, with interim patches made for security and other urgent needs.

Making it a flexible solution with multi-vendor support, key features of Radiator include:

  • Supports authentication by over 60 different types of methods
  • Interoperates with a huge range of devices, databases, billing packages, and tokens
  • Includes RadSec - secure, reliable RADIUS proxying
  • Includes Diameter - the RADIUS successor protocol used already by mobile operators
  • Includes TACACS+ - for infrastructure management
  • Integration with AD, LDAP, SQL databases among others
  • Accounting logs in variety of formats to be integrated with external systems
  • See also full feature list 

How migration to Radiator works?

When doing the migration to Radiator, you do not need to have new appliances; Radiator can be cost-efficiently fitted into your current infrastructure.

All you need is to install Radiator into your preferred platform, implement the initial configuration, and integrate Radiator to your preferred database. The use of a separate database enables your organization a secure way to store user credentials and data. Additionally, it is possible to include management and logging systems, which you may already have in use. When doing the migration, our team can provide you with assistance and experience from a wide range of use cases.

Typical Radiator set-up in a Wi-Fi authentication use case using RADIUS and TACACS+.

You do not need to worry about complicated licensing; all you need is a Radiator AAA Server Software license pack, available from one server license, two server license for high-availability, and unlimited server count license for large scale deployments. If you need an additional AAA server for a different use case within your organization, you can use a remaining available license, or upgrade your existing pack.

Would you like to know more?

With Radiator, you get direct professional technical support for configuration, deployment, and custom development. Our support packages range from basic email support to 24x7 telephone support.

Our consulting services are available to assist with migration projects. As we have had a wide range of customers with different needs migrating to Radiator, we can easily tailor a cost-effective consulting package for your needs. Thanks to our experience with similar projects, Radiator configuration can be adjusted to new environments without any extra hassle. Our customers include ISPs, enterprises, carriers, universities, public organizations, and utility companies.

If you would like to know more about Radiator, licensing options, and support, please contact our team at sales@radiatorsoftware.com

Blog post revised Feb 2nd 2022.