Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Does FreeS/WAN support user authentication (Radius, SecureID, …)?

0
Posted

Does FreeS/WAN support user authentication (Radius, SecureID, …)?

0

Not yet. So far, there is no standard way to authenticate users for IPsec, though there is a very active IETF working group looking at the problem, and several vendors have implemented various things already. In the absence of a standard, user authentication has not been a priority for the FreeS/WAN team, and is unlikely to become one. This would be a good project for a volunteer, perhaps a staff member or contractor at some company that needs the feature. Certainly our team would co-operate with such an effort; we just don’t have time to do it. The patches section of our web links document has links to some user work on this. Of course, there are various ways to avoid any requirement for user authentication in IPsec. Consider the situation where road warriors build IPsec tunnels to your office net and you are considering requiring user authentication during tunnel negotiation. Alternatives include: • If you can trust the road warrior machines, then set them up so that only authorised

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123