Re: filter_inner_identity

Alan DeKok via Freeradius-Users <[email protected]>
Newsgroups gmane.comp.freeradius.user
Message-ID <[email protected]>
On Jun 11, 2025, at 3:46 PM, Rodrigo Prieto <[email protected]> wrote:
> Hi, I’m configuring TTLS+PAP and I have some doubts about how to hide
> users' identities.

  Use "anonymous" for the outer identity, or if you're proving somewhere a domain name as @example.com

> The configuration in the filter file rejects the request if the user
> doesn’t use the word “anon”, but if I use anonrprieto as the outer identity
> and rprieto as the inner identity, obviously it doesn’t reject it and the
> inner identity gets exposed.

  So change the rule to check for "anomymous".  The rules are text, and are editable.

> Is there any way to protect against this, or is it unnecessary?

  You decide if it's necessary.

  In general, this kind of filtering is most important when the packets are being proxied outside of your local network.  If you're not proxying, it doesn't matter.

  Alan DeKok.

-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.