opnsense / plugins

OPNsense plugin collection
https://opnsense.org/
BSD 2-Clause "Simplified" License
835 stars 623 forks source link

os-freeradius: EAP max TLS version increase #4040

Open Soswald opened 3 months ago

Soswald commented 3 months ago

Important notices Before you add a new report, we ask you kindly to acknowledge the following:

Describe the solution you'd like Currently the TLS version is hardcoded to a maximum of 1.2 via the entry tls_max_version = "1.2" in the config file /usr/local/etc/raddb/mods-enabled/eap generated by /usr/local/opnsense/service/templates/OPNsense/Freeradius/mods-enabled-eap

Since both OpenSSL (since 1.1.1) and FreeRADIUS (since 3.0.26) support TLS 1.3, the maximum version should probably be increased to this version if nothing else speaks against it.

Describe alternatives you've considered None