pyrad – RADIUS for Python

Author:

Christian Giese (GIC-de), Istvan Ruzman (Istvan91) and Stefan Lieberth (slieberth)

Version:

2.5.4

Introduction

pyrad is an implementation of a RADIUS client/server as described in RFC 2865. It takes care of all the details like building RADIUS packets, sending them and decoding responses.

Here is an example of doing an authentication request:

from pyrad.client import Client
from pyrad.dictionary import Dictionary
import pyrad.packet

srv = Client(server="localhost", secret=b"Kah3choteereethiejeimaeziecumi",
             dict=Dictionary("dictionary"))

# create request
req = srv.CreateAuthPacket(code=pyrad.packet.AccessRequest,
                           User_Name="wichert", NAS_Identifier="localhost")
req["User-Password"] = req.PwCrypt("password")

# send request
reply = srv.SendPacket(req)

if reply.code == pyrad.packet.AccessAccept:
    print("access accepted")
else:
    print("access denied")

print("Attributes returned by server:")
for key in reply.keys():
    print(f"{key}: {reply[key]}")

See Usage for more examples.

BlastRADIUS

pyrad implements the countermeasures against the BlastRADIUS attack (CVE-2024-3596, https://blastradius.fail):

  • Clients add a Message-Authenticator as first attribute to all Access-Request and Status-Server packets (disable per packet with message_authenticator=False).

  • A Message-Authenticator in a reply or request is always verified. Replies containing Proxy-State attributes which were not sent in the request are discarded.

  • Servers add a Message-Authenticator as first attribute to all replies to Access-Requests and copy the Proxy-State attributes from the request.

  • Client(enforce_ma=True) and ClientAsync(enforce_ma=True) discard replies to Access-Request and Status-Server packets without Message-Authenticator, and Server(enforce_ma=True) and ServerAsync(enforce_ma=True) drop Access-Requests without Message-Authenticator. This is recommended if all peers support it.

Requirements & Installation

pyrad requires Python 3.10 or later.

pyrad is available on PyPI and can be installed with pip:

pip install pyrad

To install from a source checkout, run the following in the project directory:

pip install .

Usage

API Documentation

Per-module pyrad API documentation.

Indices and tables