000020216 - RADIUS sends back empty Reply-Message attribute in Access-Accept packet if so configured

Document created by RSA Customer Support Employee on Jun 16, 2016Last modified by RSA Customer Support Employee on Apr 21, 2017
Version 4Show Document
  • View in full screen mode

Article Content

Article Number000020216
Applies ToRSA ACE/Server 5.0.3 (no longer supported as of 8-15-2004)
RSA ACE/Server 5.1 (no longer supported as of 7-14-2006)
Microsoft Windows 2000
IssueRADIUS sends back empty Reply-Message attribute in Access-Accept packet if so configured
If the RADIUS Server has been configured with an empty Reply-Message attribute in its Access-Accept response (see solution Avaya switch always denies access even though the RADIUS server sends an Access-Accept packet back), the ACE/Server RADIUS Server sends an empty Reply-Message attribute in the Access-Accept packet. This is incorrect as RFC 2865 states specifically that empty attributes must not be sent to RADIUS clients.
ResolutionRSA Security has identified this problem and fixed it - please contact RSA Security Technical Support and ask for hot fix tst00034098.
Legacy Article IDa15427

Attachments

    Outcomes