FreeRADIUS With Its Own EAP Certificate And BlastRADIUS Settings

FreeRADIUS from AppStream made to start: its own CA and EAP certificate (the package ships none), a secret per client, every client required to sign its requests, SHA-512 crypt users, loopback listeners, each change checked on a copy. The live test accepts the right password and gets no answer for a wrong secret or an unsigned request. Original role, live-tested on Rocky Linux 10.

ansibleSecurity & Secrets

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-freeradius/badge)](https://www.iac-bazaar.com/catalog/ansible-freeradius?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [FreeRADIUS With Its Own EAP Certificate And BlastRADIUS Settings](https://www.iac-bazaar.com/catalog/ansible-freeradius?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# FreeRADIUS With Its Own EAP Certificate And BlastRADIUS Settings: https://www.iac-bazaar.com/catalog/ansible-freeradius (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

freeradius

FreeRADIUS from AppStream, made to start and made safe to point a NAS at: a CA and an EAP server certificate of its own, a generated shared secret per client, every client required to sign its requests (the BlastRADIUS settings), users stored as SHA-512 crypt hashes, listeners on loopback by default, and every change checked by radiusd -XC on a copy of the configuration before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages FreeRADIUS 3.2 in AppStream, so the role installs freeradius by name (and openssl for the certificates) and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the server works.

The distribution's unit, our configuration. The package's unit runs radiusd -C before every start, and the role keeps it. The role edits the package's own files in place rather than replacing them - the four EAP certificate lines, the listen addresses of the default site, the auth log switch, two include lines at the top of the users file - and writes clients.conf (root:radiusd 0640) whole.

The package does not start as installed. /etc/raddb/certs holds only the generator for EAP's certificates, so rlm_eap_tls fails, radiusd -XC exits 1, and the unit's own radiusd -C refuses to start the server (measured). The generator, run by hand, makes example certificates - "Example Server Certificate", key password "whatever" - that expire in 60 days, so a server set up that way loses EAP two months later. The role makes a CA of its own (10 years) and a server certificate it signs (825 days, the name from freeradius_tls_server_name), with no key password: the server's key root:radiusd 0640, the CA's key root 0600, because radiusd never needs the key that signs certificates. Set freeradius_tls_generate: false and the paths to bring your own.

Signed requests only. Every client gets require_message_authenticator = yes and limit_proxy_state = yes, the BlastRADIUS (CVE-2024-3596) settings. The live test sends the same request with and without a Message-Authenticator: signed, it is answered; unsigned, it gets no answer at all - and with the setting at no the unsigned one was answered (measured), so it is the setting that refuses it. A request with the wrong shared secret is dropped too, and radius.log says why: "Received packet from 127.0.0.1 with invalid Message-Authenticator! (Shared secret is incorrect.)".

A secret per client, made on the host. The stock localhost client's secret is testing123. The role writes clients.conf from freeradius_clients; a client given no secret gets one made on the host, kept in /etc/raddb/iacbazaar-secrets/<name> (root 0600) for you to give the NAS.

Hashes, never passwords. freeradius_users takes a SHA-512 crypt hash per user (openssl passwd -6). Users managed outside Ansible go in /etc/raddb/mods-config/files/local-users, which the role creates empty once and never writes; both files are included at the top of the users list. FreeRADIUS has no optional include there ($-INCLUDE and a missing target both fail the check - measured), which is why the role makes the file.

Checked on a copy. FreeRADIUS checks its whole configuration, not one file, so /usr/local/libexec/iacbazaar-radiusd-check puts the candidate into a copy of /etc/raddb and runs radiusd -XC there; the four EAP lines change together, so the whole tree is checked again before any restart.

What the live test does not cover. No EAP conversation: EL 10 packages no eapol_test. The certificate EAP would present is checked (issuer, name, validity), the EAP methods themselves are not exercised.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-lynis

Lynis from EPEL on a systemd timer, with the units the package keeps only in its docs, your skipped tests in custom.prf, and a minimum hardening index below which the audit unit fails, so a falling score shows as a failed unit. The live test runs the audit, reads the index and the tests that ran, and finds the timer enabled. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-suricata

Suricata from EPEL watching the default-route interface as the suricata user, ET Open fetched at install and refreshed daily, plus a canary rule that proves the sensor is alive. A root-run check left root-owned logs and a daemon recording nothing; the role prevents it. The live test raises the canary alert while a second lookup is logged, not alerted. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-aide

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-389-ds

389 Directory Server from AppStream. A fresh instance listens on every interface and lets anonymous clients read the tree; this role binds both listeners to loopback and limits anonymous clients to the rootDSE. The live test adds a user who binds, sees a wrong password and an anonymous search refused, and reads the LDAPS certificate. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-krb5-kdc

An MIT Kerberos KDC: the realm created once with a stash, kadmind behind an ACL, a default policy that locks an account after five wrong passwords, every listener on loopback. The KDC starts on a broken config without a word, so the live test proves each setting by behaviour: the ticket lifetime, the refusals, the lockout. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

View module