Version Affected: RADIUS
Bug Number: Not provided in source
Bug Status: Closed - Fixed
Fixed in Version(s): SecureAuth RADIUS Server 24.07.05+
Overview
After upgrading Ivanti Connect Secure (ICS) to 22.7R2.6, RADIUS authentication through SecureAuth fails, even though the RADIUS logs show an Access-Accept response.
Cause
Ivanti ICS 22.7R2.6 introduced a hardcoded requirement for the Message-Authenticator attribute to be present in the RADIUS response. Some versions of SecureAuth RADIUS do not include the Message-Authenticator attribute in their response packet — even with the Message-Authenticator checkbox selected in SecureAuth RADIUS 24.07.03 — so Ivanti silently drops the response and authentication fails for the end user.
Resolution / Workaround
Upgrade SecureAuth RADIUS to 24.07.05 or later, which sends the Message-Authenticator attribute correctly. See the SecureAuth RADIUS Server release notes for details, and the Product Downloads page to get the update.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.