RADIUS Authenticator
Authenticator that calls a RADIUS server to check credentials.
Note: If used as second step in a two-step authentication process, this plugin must ask for a token in the first step (before calling the RADIUS server). Please check the property "If Credential Is Missing" to enable this.
Stealth Mode Support: For unknown users this plugin will always ask for a token (OTP) and never use a different challenge type. Example: The RADIUS server always responds with a matrix challenge. Therefore the expected response would be a matrix challenge and the attacker - knowing the setup - knows that a user id does not exist, if asked for an OTP token.
radiusServers) If more than one is provided, the list is used for failover.
ifCredentialIsMissing) - Access-Reject: Rejects all requests with missing credential information.
- Ask for token in first step: If the first credential does not encompass a token, the plugin prompts the user to enter a token before calling the RADIUS server. This is useful if this authenticator is used as second factor in an authentication process.
- Send fixed password to RADIUS server: Sends the username and a fixed password to the RADIUS server. In such a case, the server is expected to respond with an Access-Challenge. This setting is useful if the Radius Authenticator is used as second step of a Main Authenticator.
nasIdentifier) staticRoles) accessRejectRules) Defines a list of rules (processed in order of definition) that define how to map RADIUS access reject response's reply messages to authentication results.
If no rules are defined or no rule matches, an unspecified authentication failure is used for access reject responses.accessChallengeRules) Defines a list of rules (processed in order of definition) that define how to map RADIUS access challenge response's reply messages to authentication results.
If no rules are defined or no rule matches, an unspecified authentication failure is used for access challenge responses.accessAcceptRules) Configures rules that influence the authenticationr result in case of successful authentication ("AccessAccept").
This can be used for example to extract roles from the response.
Note: In contrast to the access challenge and access reject rules, all rules in the list are processed as long as the authentication result is successful.
reportedAuthMethod) If not defined, "RADIUS" will be used as Authentication Method.
logRadiusAttributes) This is useful during integration and for debugging but it is generally not suitable for productive sytems.
passwordAndTokenUsage) Example:
password = pass
token = 1234
Result:
PASSWORD_ONLY = pass
TOKEN_ONLY = 1234
CONCATENATE = pass1234
usernameTransformers) encoding)
type: RadiusAuthenticator
id: RadiusAuthenticator-xxxxxx
displayName:
comment:
properties:
accessAcceptRules:
accessChallengeRules:
accessRejectRules:
encoding: UTF-8
ifCredentialIsMissing: ACCESS_REJECT
logRadiusAttributes: false
nasIdentifier:
passwordAndTokenUsage: TOKEN_ONLY
radiusServers:
reportedAuthMethod: RADIUS
staticRoles:
usernameTransformers: