Bug 58374 - EAP tls_min_version configurable
Summary: EAP tls_min_version configurable
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Radius
Version: UCS 5.0
Hardware: Other Linux
: P5 normal
Target Milestone: UCS 5.2-3-errata
Assignee: Jan Meier
QA Contact: Dirk Wiesenthal
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2025-06-04 15:39 CEST by Fabian Schneider
Modified: 2025-11-27 13:19 CET (History)
3 users (show)

See Also:
What kind of report is it?: Feature Request
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?: Yes
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID: 20677
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Fabian Schneider univentionstaff 2025-06-04 15:39:32 CEST
currently tls_min_version is not included in the template (/etc/univention/templates/files/etc/freeradius/3.0/mods-available/eap) but tls_max_version is. To ensure simple configuration changes, we might also want to make that configurable using UCR
Comment 2 Dirk Wiesenthal univentionstaff 2025-11-26 09:29:45 CET
univention-radius.yaml
839acced702e | chore(radius): Advisory

univention-radius (9.3.1)
4f891a9d8f06 | chore(radius): bump changelog

univention-radius (9.3.0)
5ac34bbf4b54 | feat(radius): add new template tls_min_version and cipher_list
Comment 3 Andreas Peichert univentionstaff 2025-11-26 14:14:39 CET
Discussed with Dirk: automated tests looks good
Comment 4 Dirk Wiesenthal univentionstaff 2025-11-27 13:19:31 CET
<https://errata.software-univention.de/#/?erratum=5.2x292>