-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Open
Labels
feature enhancementcategory: a new feature (an extension of functionality)category: a new feature (an extension of functionality)
Description
What type of feature is needed?
Changed behavior to existing functionality
What is the feature?
TACACS+ over TCP uses MD5 for obfuscation of secrets on the network and the use of a weak algorithm presents a security risk in modern networks. RFC9887 addresses this problem by proposing a mechanism to transport TACACS+ traffic over a secure TLS 1.3 connection, eliminating the obfuscation mechanism defined in RFC8907.
FreeRADIUS should add support for RFC9887 by allowing users to authenticate a remote network device through the verification and authentication of the client certificate presented by the device as defined in the RFC.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
feature enhancementcategory: a new feature (an extension of functionality)category: a new feature (an extension of functionality)