This memo is not a complete survey by any means. It is a
representative summary of practices that I am aware of at the time of
writing. I still appreciate input from vendors or users on practices
and details known, and particularly any reference material you can
pass me.
10. Security Considerations
This document documents known practices, and does not propose any
particular new protocols. Extensions to RADIUS protocols create new
security implications because of their functions go beyond those
considered in the RFCs. Some of these include:
- The ability to change passwords via a RADIUS exchange was
deliberately left out of the protocol by the working group,
because of security concerns.
- The Pseudo-User profiles and the Call-Check operation may allow
unintended access if static and well-know account names and
passwords are allowed to be used by regular interactive accounts.
- Resource Management operations must be protected from denial of
service attacks.
- Client side authorization change exchanges need to be secured from
attacks that could disconnect or restrict user services.
11. Implementation Documents
Information about the following implementations can be obtained from
the respective owners. Most listed are available from the
manufacturer's web site.
11.1. Clients:
- 3Com(USR) Total Control Hub
- Ericsson(ACC) Tigris
draft-ilgun-radius-accvsa-01.txt, Dec 1998
- Lucent(Ascend) MAX TNT
- Lucent(Livingston) Portmaster
- Nortel(Aptis) CVX 1800
- Nortel(Bay Networks) Versalar 5399/8000 Remote Access Controller
- Intel(Shiva)
Mitton Informational [Page 13]
RFC 2882 Extended RADIUS Practices July 2000
11.2. Servers:
- Ericsson(ACC) Virtual Port Server Manager
- Funk Steel-Belted RADIUS
- Intel(Shiva) Access Manager
- Lucent(Ascend) Access Control
- Lucent(Ascend) NavisAccess
- Lucent(Ascend) Modified Livingston 1.16
- Lucent(Livingston) V2.01
- Lucent(Livingston) ABM
- Lucent Port Authority
- MERIT AAA Servers
- Nortel(Bay Networks) BaySecure Access Control
- Nortel Preside Radius
- Nortel CVX Policy Manager
Comentarios a estos manuales