[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Router -- WPA = { sym, asym via 802.1x = { Radius, Kerberos,



On Wed, 2005-01-26 at 16:38, Casey Boone wrote:
> well the problem being that all of the 802.1x supporting switches and
> APs i have used in real life have this limitation.  not a myth anymore
> it would seem.

It might be their default option, but it's not the only.

Furthermore, if you buy a lot of Microsoft-aligned equipment, like
Cisco, this is why.

> i agree authentication is authentication, and there are lots of ways
> of doing authentication, but all of the 802.1x implimentations i have
> ran accross thusfar require radius (which isnt a big deal, you can run
> a radius server on just about anything nowdays and use it to proxy
> authentication against something else)

The Radius element can be a security concern.  Anytime you add another
component of "middleware," you're adding another point of exploit.


-- 
Bryan J. Smith                                   b.j.smith@ieee.org 
------------------------------------------------------------------- 
Linux Is Everywhere Insight #5:  Branding Requirements in Licenses
How do you tell if an embedded appliance runs Linux?  You can't
There is no requirement that a vendor disclose it runs Linux
How do you tell if an embedded appliance runs Windows?  The logo
Because the Microsoft Windows logo will be bigger than the vendor's



-
To unsubscribe, send email to majordomo@silug.org with
"unsubscribe silug-discuss" in the body.