pyrad – RADIUS for Python
- Author:
Christian Giese (GIC-de), Istvan Ruzman (Istvan91) and Stefan Lieberth (slieberth)
- Version:
2.5.4
Introduction
pyrad is an implementation of a RADIUS client/server as described in RFC 2865. It takes care of all the details like building RADIUS packets, sending them and decoding responses.
Here is an example of doing an authentication request:
from pyrad.client import Client
from pyrad.dictionary import Dictionary
import pyrad.packet
srv = Client(server="localhost", secret=b"Kah3choteereethiejeimaeziecumi",
dict=Dictionary("dictionary"))
# create request
req = srv.CreateAuthPacket(code=pyrad.packet.AccessRequest,
User_Name="wichert", NAS_Identifier="localhost")
req["User-Password"] = req.PwCrypt("password")
# send request
reply = srv.SendPacket(req)
if reply.code == pyrad.packet.AccessAccept:
print("access accepted")
else:
print("access denied")
print("Attributes returned by server:")
for key in reply.keys():
print(f"{key}: {reply[key]}")
See Usage for more examples.
BlastRADIUS
pyrad implements the countermeasures against the BlastRADIUS attack (CVE-2024-3596, https://blastradius.fail):
Clients add a Message-Authenticator as first attribute to all Access-Request and Status-Server packets (disable per packet with
message_authenticator=False).A Message-Authenticator in a reply or request is always verified. Replies containing Proxy-State attributes which were not sent in the request are discarded.
Servers add a Message-Authenticator as first attribute to all replies to Access-Requests and copy the Proxy-State attributes from the request.
Client(enforce_ma=True)andClientAsync(enforce_ma=True)discard replies to Access-Request and Status-Server packets without Message-Authenticator, andServer(enforce_ma=True)andServerAsync(enforce_ma=True)drop Access-Requests without Message-Authenticator. This is recommended if all peers support it.
Requirements & Installation
pyrad requires Python 3.10 or later.
pyrad is available on PyPI and can be installed with pip:
pip install pyrad
To install from a source checkout, run the following in the project directory:
pip install .
Usage
API Documentation
Per-module pyrad API documentation.