[RADIATOR] Password/certificate security seems next to none on Radiator server

Nick Lowe nick.lowe at lugatech.com
Fri Oct 2 09:52:50 CDT 2015


Nadav,

You're just obfuscating by doing this as the RADIUS server still have
to get access to those things. Security through obscurity really
doesn't exist. It is a complete waste of time in my opinion.

You have to reply on encryption of the backing storage and OS security
primitives with administrative best practice to do this properly.
There is no other way.

Once somebody owns a box, all bets are off.

Regards,

Nick


More information about the radiator mailing list