OTP verification over RADIUS
Etienne Dysli-Metref
etienne.dysli-metref at switch.ch
Wed Oct 19 11:36:08 EDT 2016
On 19/10/16 16:35, Cantor, Scott wrote:
> In principle, yes, but RADIUS over UDP is pretty lousy security-wise,
> and from your other comment, doesn't sound like RADSEC is there.
I wasn't even aware of RadSec before! :O TinyRadius certainly doesn't
support it. I haven't dug enough into jradius to say, but I suppose it
doesn't.
I totally agree with the lousiness.
> Generally speaking I would also just do a JAAS module for something
> like this, there isn't tremendous value in making it specific to the
> IdP. If the interface is just username + password, there's not much
> reason I can see not to just use JAAS.
It could fit inside JAAS, yes. It's basically sending the username and
OTP in an Access-Request packet.
> That would probably be a problem for me. We don't rely on
> unsupported libraries and I don't think maintaining our own RADIUS code is
> practical.
Yep, the implied maintenance is a rather big downside...
Etienne
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/dev/attachments/20161019/4576069f/attachment.sig>
More information about the dev
mailing list