freeradius: Update to version 3.2.10
Commit Message
- Update from version 3.2.8 to 3.2.10
- Update of rootfile
- Changelog
3.2.10
Correct bug where detail file reader would not read files. Patch from Bjørn
Mork. Fixes #5870
3.2.9
Configuration changes
Add protocol_error = yes configuration to clients. If set, the server can return
Protocol-Error responses to the client.
radclient can now suppress Message-Authenticator in Access-Request, when the
input packet contains Message-Authenticator !* ANY Don't use this in production!
Set suppress_secrets = true by default.
Add connect_fail_interval to home_server configuration. If a connection fails,
the server will wait this time before trying to connect again.
Add certificate_fail_interval to home_server configuration. If a connection
succeeds but the home_server certificate is invalid, the server will wait
this time before trying to connect again.
Add update section to home_server configuration. Status-Server packets can
therefore be customized.
Add cipher_suites to tls{} configuration. See raddb/sites-available/tls. This is
mainly used to set the cipher suites for TLS-PSK with TLS 1.3.
Feature improvements
Initial implementation of Protocol-Failure as per IETF draft. The functionality
is disabled by default, but can be enabled via new configuration flags.
Always allow Protocol-Error packet as valid response to any packet.
Add Error-Cause attributes to CoA-NAK and Disconnect-NAK
Added filter_username_nai to policy.d/filter, mainly for use in eduroam.
Updates to VSCode default configuration.
Cleanups and add log messages for rlm_proxy_rate_limit.
Allow 389ds legacy PBKDF2_SHA256 to use arbitrary iteration count. (#5654)
Amend policy insert_acct_class/acct_unique to work in environments with multiple
Class attributes (#5337)
Tweak sqlippool messages to make them clearer.
Print log message if the server receives a correct authenticated proxy response
packet, but which has an unexpected code. e.g. received Access-Accept in
response to an Accounting-Request.
New installations now set "suppress_secrets=true" by default. The server also
prints messages in debug mode which explains why the secrets are being
suppressed.
Allow parallel build for Debian. Fixes #5774.
Add RTBrick and other dictionaries.
Add documentation for ntlm_auth and spaces in passwords. Addresses #5654.
Bug fixes
Many minor bug fixes and cleanups.
Fixes to RadSec.
Many other fixes to socket and event handling, which enable increased scalability.
Fix issues found with EAP-MSCHAPv2, EAP-PWD, and EAP-MD5.
Fix run_dir (#5637) and MemoryLimit (#5639)
Disable the PCRE JIT at run time if it can't allocate executable memory.
Set selinux boolean to allow PCRE2 JIT
If you set the clock 25 years in the future, don't spam systemd. Fixes #5642
Don't load the OpenSSL legacy provider when built with --enable-fips-workaround.
Fixes #5644.
Address potential leaks when opening many RADIUS/TLS proxy sockets.
Encode multiple DHCP Option 82 as one option, instead of as multiple options.
Update the rlm_cache_redis driver to reconnect on connection failure. Fixes #5651.
Tweaks to the processing state machine to handle more corner cases / race
conditions. Thanks to Paul Dekkers for testing.
Don't close the main listen socket for TCP. Fixes #5661.
Fix rlm_dspk to properly support dynamic filenames.
Don't crash in corner cases when running Post-Proxy-Type Fail.
Use correct name offsets in proxy_rate_limit. Fixes #5675.
push fallback virtual server to child thread. Fixes #5679.
Correct corner case in hash table. Fixes #5680.
Allow new proxy sockets after reaching "too many sockets", when we close an
existing proxy connection. Fixes #5964.
fix consistent load balancing. Fixes #5770.
Address pthread APIs. Fixes #5772.
Install headers needed to build modules. Fixes #5778.
Initialize scope in IPv6 address lookups. Fixes #5798.
Don't load legacy provider on --enable-fips-workaround. Fixes #5775.
Hoist mutex lock in TLS sockets. Fixes #5480
Fix occasional EAP-PWD authentication failure.
Fix memcache storing of dates.
Add more debugging information for TEAP. TEAP has limited utility, due to the
incompleteness of the spec, and the severe limitations of the Windows TEAP
supplicant.
Return stats for "auth+acct" home servers. Fixes #5866.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/packages/freeradius | 18 ++++++++++++++----
lfs/freeradius | 24 +++++++++++-------------
2 files changed, 25 insertions(+), 17 deletions(-)
@@ -250,6 +250,7 @@ etc/raddb
#etc/raddb/mods-enabled/detail
#etc/raddb/mods-enabled/detail.log
#etc/raddb/mods-enabled/digest
+#etc/raddb/mods-enabled/dpsk
#etc/raddb/mods-enabled/dynamic_clients
#etc/raddb/mods-enabled/eap
#etc/raddb/mods-enabled/echo
@@ -331,9 +332,12 @@ usr/bin/map_unit
usr/bin/rad_counter
usr/bin/radattr
usr/bin/radclient
+usr/bin/radconf2json
usr/bin/radcrypt
+usr/bin/raddict2json
usr/bin/radeapclient
usr/bin/radlast
+usr/bin/radmod2json
usr/bin/radsecret
usr/bin/radsniff
usr/bin/radsqlrelay
@@ -346,10 +350,13 @@ usr/bin/smbencrypt
#usr/include/freeradius
#usr/include/freeradius/attributes.h
#usr/include/freeradius/autoconf.h
+#usr/include/freeradius/automask.h
#usr/include/freeradius/base64.h
#usr/include/freeradius/build.h
+#usr/include/freeradius/clients.h
#usr/include/freeradius/conf.h
#usr/include/freeradius/conffile.h
+#usr/include/freeradius/connection.h
#usr/include/freeradius/detail.h
#usr/include/freeradius/event.h
#usr/include/freeradius/features.h
@@ -357,6 +364,8 @@ usr/bin/smbencrypt
#usr/include/freeradius/hash.h
#usr/include/freeradius/heap.h
#usr/include/freeradius/libradius.h
+#usr/include/freeradius/listen.h
+#usr/include/freeradius/log.h
#usr/include/freeradius/map.h
#usr/include/freeradius/md4.h
#usr/include/freeradius/md5.h
@@ -364,6 +373,7 @@ usr/bin/smbencrypt
#usr/include/freeradius/modcall.h
#usr/include/freeradius/modules.h
#usr/include/freeradius/packet.h
+#usr/include/freeradius/process.h
#usr/include/freeradius/rad_assert.h
#usr/include/freeradius/radius.h
#usr/include/freeradius/radiusd.h
@@ -411,9 +421,11 @@ usr/bin/smbencrypt
#usr/include/freeradius/tcp.h
#usr/include/freeradius/threads.h
#usr/include/freeradius/tls.h
+#usr/include/freeradius/tmpl.h
#usr/include/freeradius/token.h
#usr/include/freeradius/udpfromto.h
#usr/include/freeradius/vqp.h
+#usr/include/freeradius/xlat.h
#usr/lib/freeradius
#usr/lib/freeradius/libfreeradius-dhcp.a
#usr/lib/freeradius/libfreeradius-dhcp.la
@@ -597,9 +609,6 @@ usr/lib/freeradius/rlm_sqlippool.so
#usr/lib/freeradius/rlm_totp.a
#usr/lib/freeradius/rlm_totp.la
usr/lib/freeradius/rlm_totp.so
-#usr/lib/freeradius/rlm_unbound.a
-#usr/lib/freeradius/rlm_unbound.la
-usr/lib/freeradius/rlm_unbound.so
#usr/lib/freeradius/rlm_unix.a
#usr/lib/freeradius/rlm_unix.la
usr/lib/freeradius/rlm_unix.so
@@ -686,6 +695,7 @@ usr/sbin/radmin
#usr/share/doc/freeradius/antora/modules/developers/pages/coverage.adoc
#usr/share/doc/freeradius/antora/modules/developers/pages/index.adoc
#usr/share/doc/freeradius/antora/modules/developers/pages/profile.adoc
+#usr/share/doc/freeradius/antora/modules/developers/pages/protocol-error.adoc
#usr/share/doc/freeradius/antora/modules/developers/pages/release-method.adoc
#usr/share/doc/freeradius/antora/modules/howto
#usr/share/doc/freeradius/antora/modules/howto/nav.adoc
@@ -899,7 +909,6 @@ usr/sbin/radmin
#usr/share/doc/freeradius/rfc/draft-kamath-pppext-eap-mschapv2-00.txt
#usr/share/doc/freeradius/rfc/draft-sterman-aaa-sip-00.txt
#usr/share/doc/freeradius/rfc/genref.pl
-#usr/share/doc/freeradius/rfc/leap.txt
#usr/share/doc/freeradius/rfc/per-rfc.pl
#usr/share/doc/freeradius/rfc/rewrite.pl
#usr/share/doc/freeradius/rfc/rfc1157.txt
@@ -1198,6 +1207,7 @@ usr/share/freeradius
#usr/share/freeradius/dictionary.riverbed
#usr/share/freeradius/dictionary.riverstone
#usr/share/freeradius/dictionary.roaringpenguin
+#usr/share/freeradius/dictionary.rtbrick
#usr/share/freeradius/dictionary.ruckus
#usr/share/freeradius/dictionary.ruggedcom
#usr/share/freeradius/dictionary.sangoma
@@ -26,7 +26,7 @@ include Config
SUMMARY = RADIUS Server
-VER = 3.2.8
+VER = 3.2.10
THISAPP = freeradius-server-$(VER)
DL_FILE = $(THISAPP).tar.bz2
@@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE)
DIR_APP = $(DIR_SRC)/$(THISAPP)
TARGET = $(DIR_INFO)/$(THISAPP)
PROG = freeradius
-PAK_VER = 26
+PAK_VER = 27
DEPS = libtalloc samba
@@ -48,7 +48,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 6266c00c68cbb02de65f88d976453fdcdda552d7554199030640f9bcd60f208afaf75aaac8fbf0a2eea0022eb23ad7b809cb910d48618261ea9f52100732c469
+$(DL_FILE)_BLAKE2 = 2e4b88f13c5742e60fd5b2931e93cb861b8fd0b9b12ba340a08f185884b64e49f035e14387a19b9ae4ae7c71ec9249132c0ccf19febfcdefd4725ddef0877a77
install : $(TARGET)
@@ -83,16 +83,14 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE)
cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/freeradius-no-buildtime-cert-gen.patch
$(UPDATE_AUTOMAKE)
- cd $(DIR_APP) && \
- ./configure \
- --prefix=/usr \
- --sysconfdir=/etc \
- --libdir=/usr/lib/freeradius \
- --localstatedir=/var \
- --with-threads \
- --disable-openssl-version-check \
- LDFLAGS="$(LDFLAGS)"
-
+ cd $(DIR_APP) && ./configure \
+ --prefix=/usr \
+ --sysconfdir=/etc \
+ --libdir=/usr/lib/freeradius \
+ --localstatedir=/var \
+ --with-threads \
+ --disable-openssl-version-check \
+ LDFLAGS="$(LDFLAGS)"
cd $(DIR_APP) && make $(MAKETUNING)
cd $(DIR_APP) && make install