docs

AAA connectivity

How partner RADIUS infrastructure peers with Helium's network.

This section is a placeholder. The content is owned by Helium's network team and will land before GA. The shape below is a sketch; treat names and details as not yet authoritative.

What this section will cover

For the offload path to work, your RADIUS infrastructure has to be reachable from Helium's hotspots. This section will document:

  • RADSEC peering: the TLS-wrapped RADIUS transport between Helium and your AAA.
  • Common Name conventions: the CN format Helium expects on your RADSEC peer certificate, and how it maps back to your partner ID.
  • Realm / domain handoff: how subscribers in your realm (for example subscriber@your-partner.com) are routed to your AAA from a Helium hotspot.
  • Radiator DB: the central Radiator-DB integration, how partner location data lands there, and which columns matter.
  • Connectivity smoke tests: a runbook to verify peering before you go live.

Today

If you're integrating now and need this content, email your account owner. Helium's network team can walk you through the setup directly while these docs are being written.

Open questions

  • Is RADSEC the only supported transport, or is IPSec-wrapped RADIUS also supported?
  • What's the minimum TLS version and cipher set accepted on partner RADSEC peers?
  • How do partners get their RADSEC peer certificate provisioned?
  • What does the partner-side configuration look like for FreeRADIUS, Radiator, or radsecproxy?

TODO (@SkoRo): replace this stub with the real content. Capture the four bullets above as discrete pages once we know the shape.