OTP verification over RADIUS

Etienne Dysli-Metref etienne.dysli-metref at switch.ch
Wed Oct 19 11:36:08 EDT 2016


On 19/10/16 16:35, Cantor, Scott wrote:
> In principle, yes, but RADIUS over UDP is pretty lousy security-wise,
> and from your other comment, doesn't sound like RADSEC is there.

I wasn't even aware of RadSec before! :O TinyRadius certainly doesn't
support it. I haven't dug enough into jradius to say, but I suppose it
doesn't.
I totally agree with the lousiness.

> Generally speaking I would also just do a JAAS module for something
> like this, there isn't tremendous value in making it specific to the
> IdP. If the interface is just username + password, there's not much
> reason I can see not to just use JAAS.

It could fit inside JAAS, yes. It's basically sending the username and
OTP in an Access-Request packet.

> That would probably be a problem for me. We don't rely on
> unsupported libraries and I don't think maintaining our own RADIUS code is
> practical.

Yep, the implied maintenance is a rather big downside...

  Etienne

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signature
URL: <http://shibboleth.net/pipermail/dev/attachments/20161019/4576069f/attachment.sig>


More information about the dev mailing list