=?Windows-1252?Q?Pascal_S=E9guy?= <[EMAIL PROTECTED]> wrote:
> You mean that the remote radius (proxy) is broken ? some could think
> FR is broken :)

  Those people would be wrong.

  The RFC's have defined the CHAP-Challenge attribute for many years.
If a RADIUS server uses the authentication vector, even when a
CHAP-Challenge attribute is in the packet, then that RADIUS server is
crap.  It's probably 6 years old, and is subject to attacks, due to
security flaws in its implementation.

  Upgrade broken software.  Breaking other (working) software to
inter-operate with broken software is asking for trouble.

> >   It will work for you, but that patch will never go into the server.
> 
> You find it so ugly ?

  The patch is nonsense.  It breaks the server to inter-operate with
other broken software.  The patch will NEVER go into the server.

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to