[RADIATOR] ServerRADSEC: TLSv1.1 and TLSv1.2 are by default disabled even if all software supports them

2016-09-22 Thread Stefan Winter
Hello, I am just now setting up a new incarnation of our RadSEC enabled Radiator server: Radiator 4.17 Net::SSLeay 1.78 OpenSSL 1.0.1e (newest CentOS 7.2 backports) All of which support TLS 1.2. I use a ServerRADSEC clause with UseTLS on but that only establishes TLS 1.0 connections. When pok

Re: [RADIATOR] ServerRADSEC: TLSv1.1 and TLSv1.2 are by default disabled even if all software supports them

2016-09-23 Thread Heikki Vatiainen
On 22.9.2016 11.45, Stefan Winter wrote: > The default that "UseTLS" should trigger is: all TLS versions that are > supported in the system. Agreed. The current UseTLS behaviour is to do what it has done since it was first implemented: enable TLS 1.0. We could, for example, enable all TLS proto