Group administrators:
Recent members:
Advisory: Microsoft Security Bulletin Affecting NPS and IAS
Microsoft Security Bulletin MS14-066 -relevant to NPS and IAS eduroam Deployments
eduroam administrators at all organisations providing eduroam using Microsoft NPS or IAS are advised to be aware that MS14-066 affects eduroam (and any other 802.1X deployment).
Caution! The MS14-066 update will change your server configuration and may break eduroam authentications since it adjusts SChannel behaviour and TLS methods available. Please check your config and deploy onto a test system before production use. If you experience problems you should contact your Microsoft support provider.
The following URLs provide further information:
http://blogs.cisco.com/security/talos/ms-tuesday-nov-2014
https://technet.microsoft.com/en-us/library/security/ms14-066.aspx
To get the specific security update go to: https://support.microsoft.com/kb/2992611
Note that whilst your NPS/IAS ORPS server may only be addressable from the UK National RADIUS Proxy Servers (NRPS) which do not pose a threat, it is the *authenticating client* that can send malicious data in the EAP session, not just an attacking RADIUS client. You should therefore apply the security update as soon as possible and remember how important it is in general to patch your servers in a timely fashion.