<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability ) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591511#M5545</link>
    <description>&lt;P&gt;Does the Global Protect RADIUS implementation support Messaging Authentication?&lt;/P&gt;
&lt;P&gt;If not, how quickly will a hotfix to patch this vulnerable implementation of RADIUS be released?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Background info:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When configuring Global Protect we used RADIUS to integrate RSA Secure ID as a second factor to LDAP, to ensure it took more than just a password to log in, but now it turns out RADIUS was designed to use MD5 hash sums in a way that is inherently insecure as detailed here:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.blastradius.fail/pdf/radius.pdf" target="_blank"&gt;https://www.blastradius.fail/pdf/radius.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RSA Secure ID released a patch which adds a new value to set in the RADIUS server config files (FreeRadius-Client-require-MA = yes), but the support documentation says the RADIUS client needs to support Messaging Authentication.&amp;nbsp;&lt;A href="https://community.securid.com/s/article/RSA-Announces-Critical-Security-Updates-for-RSA-ID-Plus-Components-RSA-Authentication-Manager-and-RSA-Identity-Router" target="_blank"&gt;https://community.securid.com/s/article/RSA-Announces-Critical-Security-Updates-for-RSA-ID-Plus-Components-RSA-Authentication-Manager-and-RSA-Identity-Router&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2024 22:24:30 GMT</pubDate>
    <dc:creator>mmason</dc:creator>
    <dc:date>2024-07-09T22:24:30Z</dc:date>
    <item>
      <title>Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591511#M5545</link>
      <description>&lt;P&gt;Does the Global Protect RADIUS implementation support Messaging Authentication?&lt;/P&gt;
&lt;P&gt;If not, how quickly will a hotfix to patch this vulnerable implementation of RADIUS be released?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Background info:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When configuring Global Protect we used RADIUS to integrate RSA Secure ID as a second factor to LDAP, to ensure it took more than just a password to log in, but now it turns out RADIUS was designed to use MD5 hash sums in a way that is inherently insecure as detailed here:&amp;nbsp;&amp;nbsp;&lt;A href="https://www.blastradius.fail/pdf/radius.pdf" target="_blank"&gt;https://www.blastradius.fail/pdf/radius.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RSA Secure ID released a patch which adds a new value to set in the RADIUS server config files (FreeRadius-Client-require-MA = yes), but the support documentation says the RADIUS client needs to support Messaging Authentication.&amp;nbsp;&lt;A href="https://community.securid.com/s/article/RSA-Announces-Critical-Security-Updates-for-RSA-ID-Plus-Components-RSA-Authentication-Manager-and-RSA-Identity-Router" target="_blank"&gt;https://community.securid.com/s/article/RSA-Announces-Critical-Security-Updates-for-RSA-ID-Plus-Components-RSA-Authentication-Manager-and-RSA-Identity-Router&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="GlobalProtect" id="GlobalProtect"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Panorama" id="Panorama"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2024 22:24:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591511#M5545</guid>
      <dc:creator>mmason</dc:creator>
      <dc:date>2024-07-09T22:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591521#M5546</link>
      <description>&lt;P&gt;Even I'm not sure this is what we are looking at, I found new command on 11.1.3 and above.&lt;/P&gt;
&lt;P&gt;I'm not testing anything about it yet and also I'm not researching it on other branches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"set auth radius-require-msg-authentic yes/no" might be answer for us.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;admin@PA-VM&amp;gt; show system info | match sw-version
sw-version: 11.1.1
admin@PA-VM&amp;gt; set auth ?
* strict-username-check   Use strict username check for user role access

admin@PA-VM&amp;gt; 


admin@PA-VM&amp;gt; show system info | match sw-version
sw-version: 11.1.2
admin@PA-VM&amp;gt; set auth ?
* strict-username-check   Use strict username check for user role access

admin@PA-VM&amp;gt; 


admin@PA-VM&amp;gt; show system info | match sw-version
sw-version: 11.1.3
admin@PA-VM&amp;gt; set auth ?
&amp;gt; radius-require-msg-authentic   Flag to check Message-Authenticator in RADIUS response
&amp;gt; remote-host-check              check remote host (client IP address) during auth redirects
&amp;gt; strict-username-check          Use strict username check for user role access

admin@PA-VM&amp;gt; 
&lt;/LI-CODE&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 01:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591521#M5546</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2024-07-10T01:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591605#M5549</link>
      <description>&lt;P&gt;That looks promising! Will try it out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 16:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591605#M5549</guid>
      <dc:creator>mmason</dc:creator>
      <dc:date>2024-07-10T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591616#M5550</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/250657"&gt;@mmason&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;based on advisory for&amp;nbsp;&lt;A href="http://CVE-2024-3596" target="_self"&gt;CVE-2024-3596&lt;/A&gt;&amp;nbsp;the authentication check in RADIUS has been introduced in these versions and newer:&amp;nbsp;PAN-OS 9.1.19, PAN-OS 10.1.14, PAN-OS 10.2.10, PAN-OS 11.0.7, PAN-OS 11.1.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 22:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591616#M5550</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-07-10T22:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591617#M5551</link>
      <description>&lt;P&gt;Thanks for confirming, waiting for our maintenance window to apply 11.1.3 so we can enable this setting, much appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jul 2024 22:43:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/591617#M5551</guid>
      <dc:creator>mmason</dc:creator>
      <dc:date>2024-07-10T22:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/594964#M5673</link>
      <description>&lt;P&gt;I ran this command on a PA-5430 with 11.1.3-h4 installed.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;I set it to yes to require message authentication and ran the show command to see if it was accepted but I got no output. As a result, the connection to my RADIUS server is still broken until I find a workaround.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Aug 2024 23:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/594964#M5673</guid>
      <dc:creator>NetworkEnginear</dc:creator>
      <dc:date>2024-08-14T23:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Does Global Protect RADIUS support Message Authentication? (to mitigate BlastRADIUS 9/10 CVSS vulnerability )</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/597402#M5800</link>
      <description>&lt;P&gt;re: no output:&amp;nbsp; Same experience on 10.2.10-h1 and 11.2.0&lt;BR /&gt;&lt;BR /&gt;On the API, when set to yes or no, response is the same.&amp;nbsp; Missing CDATA.&amp;nbsp; I'll be opening a ticket with PA to check on this today.&lt;BR /&gt;&lt;BR /&gt;&amp;lt;show&amp;gt;&amp;lt;auth&amp;gt;&amp;lt;radius-require-msg-authentic&amp;gt;&amp;lt;/radius-require-msg-authentic&amp;gt;&amp;lt;/auth&amp;gt;&amp;lt;/show&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;response&lt;SPAN class="html-attribute"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="html-attribute-name"&gt;status&lt;/SPAN&gt;="&lt;SPAN class="html-attribute-value"&gt;success&lt;/SPAN&gt;"&lt;/SPAN&gt;&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="opened"&gt;
&lt;DIV id="folder1" class="folder"&gt;
&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;result&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="opened"&gt;
&lt;DIV class="line"&gt;&lt;SPAN&gt;&amp;lt;![CDATA[ ]]&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/result&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&amp;lt;/response&amp;gt;&lt;BR /&gt;-------------------------------------------&lt;BR /&gt;Edit/Add:&amp;nbsp; PA noted it the lack of display is a bug.&amp;nbsp; Can be gathered through one of the three methods currently&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="line"&gt;&lt;SPAN class="html-tag"&gt;&lt;BR /&gt;&lt;SPAN&gt;Verified the sdb variable is set to True from TSF at location &amp;lt;tsffile&amp;gt;\tmp\cli\logs\sdb.txt&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cfg.auth.radius-require-msg-authentic: True&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;you can verify the same from CLI using the command&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;gt; show system state | match cfg.auth.radius-require-msg-authentic&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;API command below:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://urldefense.com/v3/__https://*3Cfirewall*3E/api/?type=op&amp;amp;cmd=*3Cshow*3E*3Csystem*3E*3Cstate*3E*3Cfilter*3Ecfg.auth.radius-require-msg-authentic*3C*filter*3E*3C*state*3E*3C*system*3E*3C*show*3E&amp;amp;target=SERIAL&amp;amp;key=KEY__;JSUlJSUlJSUlJSUvJSUvJSUvJSUvJQ!!Nyu6ZXf5!s4xknOqsqqNKP5hr560Hn5FbJ8RO270PejwSGd27zP2mXCE9PQgw-f9lSJlMBswWI6a-hQ3M8PZxFd89VDZwX4uOOaw88Q-clQ$" target="_blank" rel="noopener noreferrer nofollow" data-auth="NotApplicable" data-linkindex="1"&gt;https://&amp;lt;firewall&amp;gt;/api/?type=op&amp;amp;cmd=&amp;lt;show&amp;gt;&amp;lt;system&amp;gt;&amp;lt;state&amp;gt;&amp;lt;filter&amp;gt;cfg.auth.radius-require-msg-authent...&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 Sep 2024 13:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/does-global-protect-radius-support-message-authentication-to/m-p/597402#M5800</guid>
      <dc:creator>Chris_Johnston</dc:creator>
      <dc:date>2024-09-10T13:40:02Z</dc:date>
    </item>
  </channel>
</rss>

