Hacker News new | ask | show | jobs
by 1letterunixname 896 days ago
Just run FreeRADIUS yourself. If you need your own PKI to generate certs in a manageable way, there is OPNsense [0] or smallstep's FOSS step-ca [1].

Friends don't let friends delegate AAA to an external provider like Smallstep or SSO to Okta. While outsourcing to a third party is fine for a limited test, it's not fine for anything enduring.

Once upon a time, when open, spoofable WiFi was the norm, there was a collective WiFi sharing app that took control of retail WiFi routers with WPA1 enterprise RADIUS support called Radiuz. [2]

0. https://opnsense.org

1. https://github.com/smallstep/certificates

2. https://web.archive.org/web/20040617153148/http://radiuz.net...