← Back to plugin index

Radius Connection Settings

Description
Information needed to connect to a RADIUS server.
Type name
RadiusConnectionSettings
Class
com.airlock.iam.core.misc.util.radius.RadiusConnectionSettings
May be used by
Properties
Host (host)
Description
RADIUS server name or IP.
Attributes
String
Mandatory
Example
radiushost
Example
192.168.12.13
Example
accessserver
Port (port)
Description
The RADIUS server port. The default RADIUS port is 1812 (1645 for older RADIUS servers). Do not use the RADIUS accounting port.
Attributes
Integer
Mandatory
Connection Timeout [s] (connectionTimeout)
Description
The RADIUS timeout in seconds. This plug-in will wait up the specified amount of seconds for an answer from the RADIUS server before it gives up.
Hint: If failover is used, it is useful to set a low timeout (e.g. 1) for the first RADIUS server and a higher timeout (e.g. 4) for the failover server. This results in fast switching when the first server fails but keeps the system running if the network or the servers are slow.
Attributes
Integer
Optional
Default value
3
Max Retries (maxRetries)
Description

Maximum number of retries to send an access request before giving up.

If multiple RADIUS servers are configured (for failover), it makes sense to set this value to zero (no retries) for the first and to a value greater than zero for the failover server(s). A typical value is 2.

Attributes
Integer
Optional
Default value
2
Shared Secret (sharedSecret)
Description
The shared secret. It is used to encrypt the secret credentials (e.g. passwords) passed to the RADIUS server. It must be the same in this plugin and the RADIUS server.
Attributes
String
Mandatory
Sensitive
Example
secret
Example
ai38d7f3
Example
password
Enforce Message-Authenticator (enforceMessageAuthenticator)
Description
If enabled, all servers must include a valid Message-Authenticator attribute in their responses, otherwise the messages will be discarded.

Note: even when disabled, received responses containing a Message-Authenticator will always be validated. Also, requests from this radius client will always include the Message-Authenticator attribute.

Warning: when disabled, this client is vulnerable to the BlastRADIUS attack.

Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: RadiusConnectionSettings
id: RadiusConnectionSettings-xxxxxx
displayName: 
comment: 
properties:
  connectionTimeout: 3
  enforceMessageAuthenticator: true
  host:
  maxRetries: 2
  port:
  sharedSecret: