From: Scott Armitage Date: Sun, 21 Oct 2012 15:20:13 +0000 (+0100) Subject: Added the cui hash to cui policy X-Git-Tag: release_3_0_0_beta1~1656^2^2~6 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=92ec137fd5a6d4ef8b08aee518b5117919788c4c;p=thirdparty%2Ffreeradius-server.git Added the cui hash to cui policy --- diff --git a/raddb/policy.d/cui b/raddb/policy.d/cui index 52c4de69fb5..2b580b373c8 100644 --- a/raddb/policy.d/cui +++ b/raddb/policy.d/cui @@ -6,6 +6,14 @@ # cui.authorize etc..) from the various config sections. # +# +# cui_hash_key definition +# This key serves the purpose of protecting CUI values against +# dictionary attacks, therefore should be chosen as a "random" +# string and kept secret. +# +cui_hash_key = "some_hash_key" + # # The client indicates it can do CUI by sending a CUI attribute # containing one zero byte