Skip to content

Commit

Permalink
document new behavior of the EAP in pre-proxy
Browse files Browse the repository at this point in the history
  • Loading branch information
alandekok committed Jan 6, 2025
1 parent a8121e1 commit 5394a9c
Showing 1 changed file with 7 additions and 9 deletions.
16 changes: 7 additions & 9 deletions raddb/sites-available/default
Original file line number Diff line number Diff line change
Expand Up @@ -1153,17 +1153,15 @@ post-proxy {
# attr_filter.post-proxy

#
# If you are proxying LEAP, you MUST configure the EAP
# module, and you MUST list it here, in the post-proxy
# stage.
# The EAP module will perform some validation of proxied EAP
# packets. Malformed EAP packets will be rejected, and will
# not be proxied.
#
# You MUST also use the 'nostrip' option in the 'realm'
# configuration. Otherwise, the User-Name attribute
# in the proxied request will not match the user name
# hidden inside of the EAP packet, and the end server will
# reject the EAP request.
# This configuration is most useful to prevent bad
# supplicants or APs from attacking the proxies and home
# servers.
#
eap
# eap

#
# If the server tries to proxy a request and fails, then the
Expand Down

0 comments on commit 5394a9c

Please sign in to comment.