Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Wireless Security » Windows/FreeRADIUS Default TLS Cipher Suite
Search Topic:
Uniqs:
287
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Sharing printer with WiFi router »
« Article: Getting Started w / BT3 for Basic Wi-Fi Tracing  
AuthorAll Replies

jbibe
Premium,MVM
join:2001-02-22

Windows/FreeRADIUS Default TLS Cipher Suite

About two years ago, Jason Cohen discussed the fact that the default TLS cipher suite suggested by a Windows XP station and accepted by FreeRADIUS during WPA and WPA2 authentication is:

TLS_RSA_WITH_RC4_128_MD5

In its default state, FreeRADIUS selects the first suite in the client list. Jason recommended changing the FreeRADIUS configuration to select a stronger cipher suite from the list. For more information, see:

»Questions about WPA2 and WPA

A quick test today verified that Windows XP with SP3 sends the same 11 cipher suites, in the same order, and that the FreeRADIUS server selects the first cipher suite, as before.

I also ran some tests using a Vista station. The first cipher suite in the Vista client list is:

TLS_RSA_WITH_AES_128_CBC_SHA

Again, FreeRADIUS selects the first suite. This cipher suite is a major improvement.

docrice

join:2008-03-31
Fremont, CA
I haven't read through that thread you linked, but that's quite interesting and I never thought of this. Thanks for the info. Do you know if this is also the case with other AAAs such as IAS, ACS, or SBR?

jbibe
Premium,MVM
join:2001-02-22
I don't know.
Forums » Up and Running » Security » Wireless SecuritySharing printer with WiFi router »
« Article: Getting Started w / BT3 for Basic Wi-Fi Tracing  


Friday, 05-Sep 01:16:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [175] Google Browser Available Today
· [123] The Best Bandwidth Meters For Comcast Customers
· [96] Labor Day Open Thread
· [87] Verizon, AT&T Offer New DSL Promotions
· [65] Routing Around The United States
· [60] Google Chrome Runs The Internet Gauntlet
· [55] iPhone Users Greeted With Morning Outage
· [51] Deconstructing The Exaflood Myth
· [48] Infected Botnet PCs Quadruple In 90 Days
· [41] Will Qwest Come Clean About Usage Cap Like Comcast?
Most people now reading
· Google's Chrome Browser - Security & Privacy Issues [Security]
· The iPhone is wonderful but... [All things Macintosh]
· eBay Listing Removed [General Questions]
· Replacing a beyond repair chimney [Home Repair & Improvement]
· Bandwidth Monitor for Computers-Suggestions? [Comcast HSI]