Bug 49858 - univention-radius does not use the UCR port specifications for IPv6
univention-radius does not use the UCR port specifications for IPv6
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Radius
UCS 4.4
Other Linux
: P5 normal (vote)
: UCS 4.4-1-errata
Assigned To: Jürn Brodersen
Arvid Requate
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-16 22:16 CEST by Sönke Schwardt-Krummrich
Modified: 2019-08-22 15:30 CEST (History)
2 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 4: Minor Usability: Impairs usability in secondary scenarios
Who will be affected by this bug?: 1: Will affect a very few installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.046
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:
schwardt: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sönke Schwardt-Krummrich univentionstaff 2019-07-16 22:16:22 CEST
univention-radius does not use the UCR port specifications for IPv6.
The UCR variables freeradius/conf/accountingport and freeradius/conf/port are only respected for IPv4 but not for IPv6.

This leads to problems if an instance cannot use the default ports (e.g. because they are used by another radius instance).
Comment 1 Sönke Schwardt-Krummrich univentionstaff 2019-07-16 22:17:36 CEST
Patch available in branch "sschwardt/4.4-1/freeradius-ports" for UCS 4.4-1
Comment 2 Jürn Brodersen univentionstaff 2019-08-19 16:25:01 CEST
[4.4-1 092b073fad] Bug #49858: respect UCR port configuration also for IPv6

successful build
Package: univention-radius
Version: 6.0.2-11A~4.4.0.201908191534
Branch: ucs_4.4-0-errata4.4-1
Scope: errata4.4-1
Comment 3 Arvid Requate univentionstaff 2019-08-20 16:41:16 CEST
Verified:

* UCR freeradius/conf/port and freeradius/conf/accountingport are now also considered for IPv6 as well.

* Additionally the new UCR variable freeradius/conf/inner-tunnel-port allows configuring the IPv4 port for the inner tunnel. In combination the changes of this bug allow running two instances of radius with different ports on the same server - that much I was told about the purpose of this new variable and its relevance with respect to the topic of this bug.


* Advisory
Comment 4 Arvid Requate univentionstaff 2019-08-22 15:30:07 CEST
<http://errata.software-univention.de/ucs/4.4/237.html>