Configuring RADIUS Authentication

RADIUS is a client/server security protocol widely used to enable remote authentication and access.

About Configuring RADIUS Authentication

Oracle AI Database supports the RADIUS standard for user authentication.

Note: Starting with Oracle AI Database 26ai, the older RADIUS API that is based on Request for Comments (RFC) 2138 is deprecated.Oracle AI Database 26ai introduces an updated RADIUS API based on RFC 6613 and RFC

  1. Oracle recommends that you start planning on migrating to use the new RADIUS API as soon as possible. The new API is enabled by default. These parameters associated with the older RADIUS API are also deprecated: SQLNET.RADIUS_ALTERNATE, SQLNET.RADIUS_ALTERNATE_PORT, SQLNET.RADIUS_AUTHENTICATION, and SQLNET.RADIUS_AUTHENTICATION_PORT. Refer to the Radius API documentation for information on changing the default to use the older RADIUS API.

RADIUS is frequently used for multi-factor authentication (MFA) when it is used to access an Oracle AI Database. The specific MFA technologies (such as smart cards or biometric cards) depend on the RADIUS server. The database server and client support asynchronous and synchronous challenges for MFA.

The Oracle AI Database RADIUS implementation uses the TLS/TCPS standards that are described in RFC 6013 and 6014 and is enabled by default by the Oracle AI Database. If you want to use the older implementation (before Oracle AI Database 26ai) using an older RADIUS standard, then you must enable one or both of the SQLNET.RADIUS_ALLOW_WEAK_CLIENTS and SQLNET.RADIUS_ALLOW_WEAK_PROTOCOL parameters to use the older RADIUS implementation.

From an end user’s perspective, the entire authentication process is transparent. When the user seeks access to an Oracle AI Database server, the Oracle AI Database server, acting as the RADIUS client, notifies the RADIUS server. The RADIUS server then:

Figure 26-1 illustrates the Oracle AI Database-RADIUS environment.

Figure 1: RADIUS in an Oracle Environment

Description of the illustration asoag003.png

The Oracle AI Database server acts as the RADIUS client, passing information between the Oracle client and the RADIUS server. Similarly, the RADIUS server passes information between the Oracle AI Databasee server and the appropriate authentication servers.

A RADIUS server vendor is often the authentication server vendor as well. In this case authentication can be processed on the RADIUS server.

Related Topics