How to configure FreeRADIUS authentication in FIPS mode
Issue
- How to configure FreeRadius authentication in FIPS mode for IPA users using the
ldap
module in FreeRADIUS. - How to configure FreeRadius authentication in FIPS mode for local users using the
/etc/raddb/users
configuration file.
NOTE(1): You can use the same set of steps to configure FreeRADIUS authentication in default non-FIPS mode, except that you can skip step 1.
NOTE(2): Though FreeRADIUS can run in FIPS mode, it does not mean that it is FIPS compliant as it uses weak ciphers and functions when in FIPS mode.
Environment
- Red Hat Enterprise Linux 8.5 or later
- FIPS mode enabled - running IPA server in FIPS mode is supported from >= RHEL 7.4.
- freeradius-3.0.20-7
- IPA server 4.9.x
- krb5-server-1.18.2-7
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.