Bug 55182 - TLS1.3 with freeradius 3.0.17 fails
TLS1.3 with freeradius 3.0.17 fails
Status: NEW
Product: UCS
Classification: Unclassified
Component: Radius
UCS 5.0
Other Linux
: P5 normal (vote)
: ---
Assigned To: UCS maintainers
UCS maintainers
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-09-08 12:16 CEST by Nico Stöckigt
Modified: 2023-02-14 17:39 CET (History)
2 users (show)

See Also:
What kind of report is it?: Bug Report
What type of bug is this?: 4: Minor Usability: Impairs usability in secondary scenarios
Who will be affected by this bug?: 2: Will only affect a few installed domains
How will those affected feel about the bug?: 2: A Pain – users won’t like this once they notice it
User Pain: 0.091
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number: 2022090721000793, 2022111821000661
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Nico Stöckigt univentionstaff 2022-09-08 12:16:46 CEST
Ältere Geräte können sich nicht verbinden.

Nach einiger Recherche sieht es so aus, als würde das Problem durch freeradius 3.0.17 verursacht, in der TLS1.3 noch unvollständig implementiert ist. Siehe dazu hier: https://github.com/FreeRADIUS/freeradius-server/issues/2385

Ein Setzen von 'tls_max_version = "1.2"' in der Konfiguration des EAP Moduls behebt das Problem.
Comment 2 Nico Stöckigt univentionstaff 2022-09-08 12:37:05 CEST
freeradius 3.0.18 seems to be fixed. We should update that component.
Comment 3 Nico Stöckigt univentionstaff 2022-09-09 14:57:16 CEST
(In reply to Nico Stöckigt from comment #0)

Older devices cannot connect.

After some research, it looks like the problem is caused by freeradius 3.0.17, in which TLS1.3 is still incompletely implemented. See here: https://github.com/FreeRADIUS/freeradius-server/issues/2385

Setting 'tls_max_version = "1.2"' in the configuration of the EAP module solves the problem.
Comment 4 Mirac Erdemiroglu univentionstaff 2022-11-21 08:57:09 CET
Same on 2022111821000661
Comment 5 Jan-Luca Kiok univentionstaff 2023-02-14 15:29:53 CET
The customer noted that newer devices can be affected too as long as they do not prioritize a TLS version.
Comment 6 Mirac Erdemiroglu univentionstaff 2023-02-14 17:39:17 CET
To set the TLS Version via UCRV is maybe the sustainably for our product i guess