Fwd: [saag] RADIUS is deprecating MD5

Ira McDonald via ipp <[email protected]>
Newsgroups gmane.ietf.ipp
Message-ID <CAN40gSvA8NZiRxhbFnt0eaDFwjfTGEzqXRR1CQeTzYHTNWf92w@mail.gmail.com>
FYI - RADIUS is cleaning up its act - this will impact many users and
systems.

---------- Forwarded message ---------
From: Alan DeKok <[email protected]>
Date: Sun, Mar 24, 2024 at 2:23 PM
Subject: [saag] RADIUS is deprecating MD5
To: <[email protected]>


  To follow up on my comments at the mic in Brisbane, the RADEXT group is
working on two documents:

* moving TLS to standards track:
https://datatracker.ietf.org/doc/draft-rieckers-radext-rfc6614bis/

* deprecating insecure practices:
https://datatracker.ietf.org/doc/draft-ietf-radext-deprecating-radius/

  We expect to submit these documents for publication around IETF 120.

  We will be deprecating the use of RADIUS/UDP, in large part due to it's
reliance on MD5.  Everyone shipping RADIUS clients should take a serious
look at moving to TLS immediately.

  MD5 isn't getting any more secure, and there are few reasons left for
staying with it.

  Alan DeKok.

_______________________________________________
saag mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/saag

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.