Re: Way to verify RADIUS status-server of proxy server over RadSec / TLS

Bjørn Mork via Freeradius-Users <[email protected]>
Newsgroups gmane.comp.freeradius.user
Organization m
Message-ID <[email protected]>
Alan DeKok <[email protected]> writes:

>> To be honest, I let this interpret by an AI and this is what the AI
>> told me: "You’re trying to receive UDP packets on port 11812 and send
>> them via TLS/TCP using socat. That conceptually makes sense — it’s
>> what RADIUS-over-TLS (RadSec) does — but unfortunately, RADIUS over
>> TLS is not just “UDP in TLS over TCP”. RadSec uses a specific
>> framing: each RADIUS packet must be prefixed with a 2-byte length
>> field when encapsulated over TCP/TLS (per RFC 6614).“
>
>   Please don't use AI for this kind of thing.  It's garbage, and it
>   lies to you.  It's *worse* than doing nothing.

Funny.  Wonder if the AI confused RADIUS over TLS with DNS over TCP?
Almost the same, I guess.  At least for "intelligence" based on simple
extrapolation.  If you know how one UDP based protocol translates to a
stream, then you can guess how all other UDP based protocols translates
to streams.


Bjørn
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.