Network access control on wired networks with IEEE 802.1X
The last step for the administrator is to set the RADIUS server to production mode: enable the init script using service freeradius start, and type chkconfig freeradius on to set up the server to use the same start procedure when rebooted.
The components for device-based authentication of terminal devices exist in many environments. It is up to the administrator to combine those components.
For some people, Network Access Control includes additional aspects, such as technical validation of version status or up-to-date virus signatures, in line with a security policy. NAC offers a number of customization options: Besides LDAP or SQL database integration, more complex environments might want to deploy a PKI with the use of Tiny CA , for example. Smartcards such as the Aladdin E-Token protect private user certificates.
IPv6 is supported with FreeRADIUS Version 2 or later; however, some 802.1X-capable switches might not comply. If you are experimenting with IKEv2, check out the project's experimental.conf.
An identically named SourceForge project is also researching IKEv2 . Thanks to the Hostapd project , administrators can soon look forward to a new implementation of EAP in FreeRADIUS known as EAP2.
- IEEE 802.1x-2004: http://www.ieee802.org/1/pages/802.1x-2004.html
- RFC 5216, "EAP-TLS Authentication Protocol": http://tools.ietf.org/rfc/rfc5216.txt
- Cisco 802.1x Guide: http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/dot1x.html
- FreeRADIUS Wiki on Cisco IOS commands: http://wiki.freeradius.org/Cisco
- FreeRADIUS Project: http://freeradius.org
- FreeRADIUS at GitHub: http://github.com/Antti/freeradius-server/tree/master
- OpenSEA: http://openseaalliance.org
- Open1X project: http://open1x.sf.net
- WPA supplicant: http://hostap.epitest.fi/wpa_supplicant/
- Tiny CA: http://tinyca.sm-zone.net
- EAP-IKEv2 project on Sourceforge: http://eap-ikev2.sf.net
- EAP modes supported by FreeRADIUS: http://freeradius.org/features/eap.html
Xen project announces a privilege escalation problem for Qemu host systems
Attackers can compromise an Android phone just by sending a text message
PC vendor will pre-install Ubuntu on portables in India.
More embarrassment for Adobe's embattled multimedia tool
Mozilla’s script blocker add-on could be putting malware sites on the whitelist.
The Internet community officially banishes the notoriously unsafe Secure Sockets Layer protocol.
Popular desktop environment continues the Gnome 2 legacy – with new support for the Gnome 3 toolkit.
The Obama White House has issued a memorandum telling all US government agencies they must use HTTPS for all websites and web communication.
New program will dial up security for the Firefox browser.
Red Hat's community distro embraces the cloud.