(PM) Re: Caller-ID with tcp-clear sessions (fwd)

Christopher Masto (chris@netmonger.net)
Tue, 23 Mar 1999 22:40:58 -0500

On Tue, Mar 23, 1999 at 03:46:27PM -0800, MegaZone wrote:
> 1. The NAS is NOT required to send NAS-IP-Address. It may send NAS-Identifier
> instead.
> 2. The NAS-IP-Address may not actually be the IP source address of the TCP
> connection. As has been discussed on the WG, some NASen may have multiple
> IP addresses (multiple interfaces, subinterfaces, etc) and the IP used to
> talk to RADIUS may NOT be the IP address used for an authorized service.
>
> So really you have no reliable info on the NAS side of the connection -
> though there are fair odds that NAS-IP-Address will be the source IP.

That doesn't change the fact that there's information missing. I'm not
saying make it a MUST or even a SHOULD. Not everything has to work in
every situation. Just because Access-Challenge is useless to me in
a certain configuration doesn't mean it shouldn't be available.

I don't need this feature. I don't care too much. But I do think it's
ridiculous to be digging for reasons to shoot it down, since it is in
fact a glaring oversight now that someone has brought it up. It didn't
come up before.. well, neither did a lot of security holes in software.
Should we not fix them because nobody ever asked for a fix for the past
three years?

Sometimes it's too late to fix something. In the case of RADIUS, it
is probably too late. IIRC, the WG was trying to dissolve two years
ago, and there are definately practical considerations to trying to
add a silly little attribute that nobody's going to use.

And for now, Livingston should implement it as a VSA. And this issue
should be kept in mind for the next generation protocol.

On the other hand, now that I think about it, TCP-Clear is silly.
rlogin is nearly a clear channel.. if you ignore window size messages,
it is completely. Something based on rlogin that maybe sent a
session ID would be nice.

-- 
Christopher Masto        Director of Operations      NetMonger Communications
chris@netmonger.net        info@netmonger.net        http://www.netmonger.net

Free yourself, free your machine, free the daemon -- http://www.freebsd.org/ - To unsubscribe, email 'majordomo@livingston.com' with 'unsubscribe portmaster-users' in the body of the message. Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>