Some basic advice needed: RADIUS "light"



Hi everyone,

I am planning to make my first steps in the RADIUS world. The objective is to use RADIUS to do some basic authentication for simple devices like routers and switches to centralize management passwords.

Seen from the device side I can enter a username, a password and the IP address of the RADIUS server. Seems to be pretty easy.

I tried to install Microsofts IAS service on top of my existing Active Directory infrastructure and soon got lost in a jungle of blablabla about protocols, certificates and design strategies for worldwide corporate PKI infrastructures, Policy based access strategies and such, which I currently am not interested in.

* Is there a fairly easy and straightforward documentation from MS or anyone else about how to set up a very basic RADIUS server using Windows 2003 services doing nothing but authentication for simple boxes? Is IAS indeed a *must* or is tehre a simpler way?

* I feel that the MS software is probably way too big for what I intend to do. If so, is there a different RADIUS server software for the Windows 2003 platform available that does the job? The only thing I consider a "must" is AD support, I do not wish to maintain two different user/password databases.

Thnx,

Armin
.



Relevant Pages

  • Re: Security. WPA?/-TKIP /-CCMP
    ... immature technology while not making it mandatory to support unique ... key for each connection. ... Only a very small number of access points have built in RADIUS ... authorization and authentication requests to a real RADIUS server. ...
    (alt.internet.wireless)
  • Re: use of RADIUS
    ... trying to access with the authentication type set to WebAuth. ... User opens up application, Netscreen sees host has authenticated and ... No RADIUS necessary. ... If it did and I installed a RADIUS server inside I am curious how the ...
    (comp.security.firewalls)
  • You might protect your radius
    ... CERT Advisory CA-2002-06 Vulnerabilities in Various ... Systems running any of the following RADIUS implementations: ... * Cistron RADIUS versions 1.6.5 and prior ... Block packets to the RADIUS server at the firewall ...
    (comp.security.firewalls)
  • [NEWS] Vulnerabilities in Multiple RADIUS Clients and Servers
    ... Remote Authentication Dial-In User Service (RADIUS) is widely used by ... To validate few types of RADIUS packets RADIUS calculates packet digest. ... In most cases it will cause DoS against RADIUS server. ... validate the Vendor-Specific attribute Vendor-Length ...
    (Securiteam)
  • SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations
    ... * - vulnerability presents but is not exploitable ... Remote Authentication Dial In User Service (RADIUS) is widely used by ... packet proxing. ... To exploit this vulnerabilities against RADIUS server attacker should ...
    (Bugtraq)