{"id":961,"date":"2026-02-06T07:49:04","date_gmt":"2026-02-06T06:49:04","guid":{"rendered":"https:\/\/whoami.lausitz-event.info\/?p=961"},"modified":"2026-02-06T08:00:25","modified_gmt":"2026-02-06T07:00:25","slug":"freeradius-fortigate-no-message-authenticator-attribute","status":"publish","type":"post","link":"https:\/\/whoami.lausitz-event.info\/?p=961","title":{"rendered":"Freeradius &#8211; FortiGate &#038; &#8222;No Message-Authenticator attribute&#8220;"},"content":{"rendered":"\n\n<p>Falls ihr auf der FortiGate einen Freeradius Server einbinden wollt, und diesen unter Debian betreibt, bekommt ihr vermutlich beim Radius Connect Test die Fehlermeldung \"<strong>No Message-Authenticator attribute<\/strong>\". Hintergrund daf\u00fcr ist eine Sicherheitsl\u00fccke im Radius Protokoll. Aus diesem Grund wurden zwei neue Konfigurationsoptionen in der \/etc\/freeradius\/3.0\/radiusd.conf hinzugef\u00fcgt.<\/p>\n\n\n\n\n\n<pre class=\"wp-block-code\"><code>security {\n    ...\n    require_message_authenticator = auto\n    limit_proxy_state = auto\n}<\/code><\/pre>\n\n\n\n\n\n<p>Damit w\u00e4ren die meisten Systeme gesch\u00fctzt. Idealerweise macht man jedoch ein Update der Systeme, sodass diese gesch\u00fctzt sind.<\/p>\n\n\n\n\n\n<p>Damit kommen wir aber zur Achillesferse des Ganzen. Viele Linux Repositories aktualisieren ihre Paket jedoch nicht zeitnah, sodass uns nur der Bau aus den Quellen bleibt, oder aber folgender Workaround:<\/p>\n\n\n\n\n\n<p><strong>\/etc\/freeradius\/3.0\/sites-enabled\/default<\/strong><\/p>\n\n\n\n\n\n<pre class=\"wp-block-code\"><code>authorize {\n    if (!EAP-Message) {\n        update reply {\n            Message-Authenticator := 0x00\n        }\n    }\n...<\/code><\/pre>\n\n\n\n\n\n<p>Ein Neustart des Freeradius Dienstes mit <em>systemctl restart freeradius<\/em> und der Radius Test sollte funktionieren.<\/p>\n\n\n","protected":false},"excerpt":{"rendered":"<p>Falls ihr auf der FortiGate einen Freeradius Server einbinden wollt, und diesen unter Debian betreibt, bekommt ihr vermutlich beim Radius Connect Test die Fehlermeldung \"No Message-Authenticator attribute\". Hintergrund daf\u00fcr ist eine Sicherheitsl\u00fccke im Radius Protokoll. Aus diesem Grund wurden zwei neue Konfigurationsoptionen in der \/etc\/freeradius\/3.0\/radiusd.conf hinzugef\u00fcgt. Damit w\u00e4ren die meisten Systeme gesch\u00fctzt. Idealerweise macht man [&hellip;]<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[19,3,12,23,11],"tags":[],"class_list":["post-961","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-it","category-linux","category-netzwerk","category-security"],"_links":{"self":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=961"}],"version-history":[{"count":2,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/961\/revisions"}],"predecessor-version":[{"id":964,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=\/wp\/v2\/posts\/961\/revisions\/964"}],"wp:attachment":[{"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/whoami.lausitz-event.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}