Hide Forgot
When FreeRADIUS is configured to use the 'unix' module and shadow passwords, the password expiration field is ignored. This could allow a user with an expired password to authenticate against FreeRADIUS. This was corrected upstream: https://github.com/alandekok/freeradius-server/commit/1b1ec5ce75e224bd1755650c18ccdaa6dc53e605 And was also corrected in Red Hat Enterprise Linux 6 via RHBA-2012:0881: https://rhn.redhat.com/errata/RHBA-2012-0881.html Statement: (none)
This issue affects the version of freeradius and freeradius2 as shipped with Red Hat Enterprise Linux 5.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2013:0134 https://rhn.redhat.com/errata/RHSA-2013-0134.html