freeradius: Update to version 3.2.10

Message ID 20261002112330.3568361-4-adolf.belka@ipfire.org
State Staged
Commit 14890ba13110032cffd8f2b7503b8b193c1fbad5
Headers
Series freeradius: Update to version 3.2.10 |

Commit Message

Adolf Belka 2 Oct 2026, 11:23 a.m. UTC
- Update from version 3.2.8 to 3.2.10
- Update of rootfile
- Changelog
3.2.10
	Correct bug where detail file reader would not read files. Patch from Bjørn
	 Mork. Fixes #5870
3.2.9
Configuration changes
    Add protocol_error = yes configuration to clients. If set, the server can return
	Protocol-Error responses to the client.
    radclient can now suppress Message-Authenticator in Access-Request, when the
	input packet contains Message-Authenticator !* ANY Don't use this in production!
    Set suppress_secrets = true by default.
    Add connect_fail_interval to home_server configuration. If a connection fails,
	the server will wait this time before trying to connect again.
    Add certificate_fail_interval to home_server configuration. If a connection
	succeeds but the home_server certificate is invalid, the server will wait
	this time before trying to connect again.
    Add update section to home_server configuration. Status-Server packets can
	therefore be customized.
    Add cipher_suites to tls{} configuration. See raddb/sites-available/tls. This is
	mainly used to set the cipher suites for TLS-PSK with TLS 1.3.
Feature improvements
    Initial implementation of Protocol-Failure as per IETF draft. The functionality
	is disabled by default, but can be enabled via new configuration flags.
    Always allow Protocol-Error packet as valid response to any packet.
    Add Error-Cause attributes to CoA-NAK and Disconnect-NAK
    Added filter_username_nai to policy.d/filter, mainly for use in eduroam.
    Updates to VSCode default configuration.
    Cleanups and add log messages for rlm_proxy_rate_limit.
    Allow 389ds legacy PBKDF2_SHA256 to use arbitrary iteration count. (#5654)
    Amend policy insert_acct_class/acct_unique to work in environments with multiple
	Class attributes (#5337)
    Tweak sqlippool messages to make them clearer.
    Print log message if the server receives a correct authenticated proxy response
	packet, but which has an unexpected code. e.g. received Access-Accept in
	response to an Accounting-Request.
    New installations now set "suppress_secrets=true" by default. The server also
	prints messages in debug mode which explains why the secrets are being
	suppressed.
    Allow parallel build for Debian. Fixes #5774.
    Add RTBrick and other dictionaries.
    Add documentation for ntlm_auth and spaces in passwords. Addresses #5654.
Bug fixes
    Many minor bug fixes and cleanups.
    Fixes to RadSec.
    Many other fixes to socket and event handling, which enable increased scalability.
    Fix issues found with EAP-MSCHAPv2, EAP-PWD, and EAP-MD5.
    Fix run_dir (#5637) and MemoryLimit (#5639)
    Disable the PCRE JIT at run time if it can't allocate executable memory.
    Set selinux boolean to allow PCRE2 JIT
    If you set the clock 25 years in the future, don't spam systemd. Fixes #5642
    Don't load the OpenSSL legacy provider when built with --enable-fips-workaround.
	Fixes #5644.
    Address potential leaks when opening many RADIUS/TLS proxy sockets.
    Encode multiple DHCP Option 82 as one option, instead of as multiple options.
    Update the rlm_cache_redis driver to reconnect on connection failure. Fixes #5651.
    Tweaks to the processing state machine to handle more corner cases / race
	conditions. Thanks to Paul Dekkers for testing.
    Don't close the main listen socket for TCP. Fixes #5661.
    Fix rlm_dspk to properly support dynamic filenames.
    Don't crash in corner cases when running Post-Proxy-Type Fail.
    Use correct name offsets in proxy_rate_limit. Fixes #5675.
    push fallback virtual server to child thread. Fixes #5679.
    Correct corner case in hash table. Fixes #5680.
    Allow new proxy sockets after reaching "too many sockets", when we close an
	existing proxy connection. Fixes #5964.
    fix consistent load balancing. Fixes #5770.
    Address pthread APIs. Fixes #5772.
    Install headers needed to build modules. Fixes #5778.
    Initialize scope in IPv6 address lookups. Fixes #5798.
    Don't load legacy provider on --enable-fips-workaround. Fixes #5775.
    Hoist mutex lock in TLS sockets. Fixes #5480
    Fix occasional EAP-PWD authentication failure.
    Fix memcache storing of dates.
    Add more debugging information for TEAP. TEAP has limited utility, due to the
	incompleteness of the spec, and the severe limitations of the Windows TEAP
	supplicant.
    Return stats for "auth+acct" home servers. Fixes #5866.

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 config/rootfiles/packages/freeradius | 18 ++++++++++++++----
 lfs/freeradius                       | 24 +++++++++++-------------
 2 files changed, 25 insertions(+), 17 deletions(-)
  

Patch

diff --git a/config/rootfiles/packages/freeradius b/config/rootfiles/packages/freeradius
index 411769253..fdd5a4598 100644
--- a/config/rootfiles/packages/freeradius
+++ b/config/rootfiles/packages/freeradius
@@ -250,6 +250,7 @@  etc/raddb
 #etc/raddb/mods-enabled/detail
 #etc/raddb/mods-enabled/detail.log
 #etc/raddb/mods-enabled/digest
+#etc/raddb/mods-enabled/dpsk
 #etc/raddb/mods-enabled/dynamic_clients
 #etc/raddb/mods-enabled/eap
 #etc/raddb/mods-enabled/echo
@@ -331,9 +332,12 @@  usr/bin/map_unit
 usr/bin/rad_counter
 usr/bin/radattr
 usr/bin/radclient
+usr/bin/radconf2json
 usr/bin/radcrypt
+usr/bin/raddict2json
 usr/bin/radeapclient
 usr/bin/radlast
+usr/bin/radmod2json
 usr/bin/radsecret
 usr/bin/radsniff
 usr/bin/radsqlrelay
@@ -346,10 +350,13 @@  usr/bin/smbencrypt
 #usr/include/freeradius
 #usr/include/freeradius/attributes.h
 #usr/include/freeradius/autoconf.h
+#usr/include/freeradius/automask.h
 #usr/include/freeradius/base64.h
 #usr/include/freeradius/build.h
+#usr/include/freeradius/clients.h
 #usr/include/freeradius/conf.h
 #usr/include/freeradius/conffile.h
+#usr/include/freeradius/connection.h
 #usr/include/freeradius/detail.h
 #usr/include/freeradius/event.h
 #usr/include/freeradius/features.h
@@ -357,6 +364,8 @@  usr/bin/smbencrypt
 #usr/include/freeradius/hash.h
 #usr/include/freeradius/heap.h
 #usr/include/freeradius/libradius.h
+#usr/include/freeradius/listen.h
+#usr/include/freeradius/log.h
 #usr/include/freeradius/map.h
 #usr/include/freeradius/md4.h
 #usr/include/freeradius/md5.h
@@ -364,6 +373,7 @@  usr/bin/smbencrypt
 #usr/include/freeradius/modcall.h
 #usr/include/freeradius/modules.h
 #usr/include/freeradius/packet.h
+#usr/include/freeradius/process.h
 #usr/include/freeradius/rad_assert.h
 #usr/include/freeradius/radius.h
 #usr/include/freeradius/radiusd.h
@@ -411,9 +421,11 @@  usr/bin/smbencrypt
 #usr/include/freeradius/tcp.h
 #usr/include/freeradius/threads.h
 #usr/include/freeradius/tls.h
+#usr/include/freeradius/tmpl.h
 #usr/include/freeradius/token.h
 #usr/include/freeradius/udpfromto.h
 #usr/include/freeradius/vqp.h
+#usr/include/freeradius/xlat.h
 #usr/lib/freeradius
 #usr/lib/freeradius/libfreeradius-dhcp.a
 #usr/lib/freeradius/libfreeradius-dhcp.la
@@ -597,9 +609,6 @@  usr/lib/freeradius/rlm_sqlippool.so
 #usr/lib/freeradius/rlm_totp.a
 #usr/lib/freeradius/rlm_totp.la
 usr/lib/freeradius/rlm_totp.so
-#usr/lib/freeradius/rlm_unbound.a
-#usr/lib/freeradius/rlm_unbound.la
-usr/lib/freeradius/rlm_unbound.so
 #usr/lib/freeradius/rlm_unix.a
 #usr/lib/freeradius/rlm_unix.la
 usr/lib/freeradius/rlm_unix.so
@@ -686,6 +695,7 @@  usr/sbin/radmin
 #usr/share/doc/freeradius/antora/modules/developers/pages/coverage.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/index.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/profile.adoc
+#usr/share/doc/freeradius/antora/modules/developers/pages/protocol-error.adoc
 #usr/share/doc/freeradius/antora/modules/developers/pages/release-method.adoc
 #usr/share/doc/freeradius/antora/modules/howto
 #usr/share/doc/freeradius/antora/modules/howto/nav.adoc
@@ -899,7 +909,6 @@  usr/sbin/radmin
 #usr/share/doc/freeradius/rfc/draft-kamath-pppext-eap-mschapv2-00.txt
 #usr/share/doc/freeradius/rfc/draft-sterman-aaa-sip-00.txt
 #usr/share/doc/freeradius/rfc/genref.pl
-#usr/share/doc/freeradius/rfc/leap.txt
 #usr/share/doc/freeradius/rfc/per-rfc.pl
 #usr/share/doc/freeradius/rfc/rewrite.pl
 #usr/share/doc/freeradius/rfc/rfc1157.txt
@@ -1198,6 +1207,7 @@  usr/share/freeradius
 #usr/share/freeradius/dictionary.riverbed
 #usr/share/freeradius/dictionary.riverstone
 #usr/share/freeradius/dictionary.roaringpenguin
+#usr/share/freeradius/dictionary.rtbrick
 #usr/share/freeradius/dictionary.ruckus
 #usr/share/freeradius/dictionary.ruggedcom
 #usr/share/freeradius/dictionary.sangoma
diff --git a/lfs/freeradius b/lfs/freeradius
index 1a5ea7117..ec13b8ce3 100644
--- a/lfs/freeradius
+++ b/lfs/freeradius
@@ -26,7 +26,7 @@  include Config
 
 SUMMARY    = RADIUS Server
 
-VER        = 3.2.8
+VER        = 3.2.10
 
 THISAPP    = freeradius-server-$(VER)
 DL_FILE    = $(THISAPP).tar.bz2
@@ -34,7 +34,7 @@  DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = freeradius
-PAK_VER    = 26
+PAK_VER    = 27
 
 DEPS       = libtalloc samba
 
@@ -48,7 +48,7 @@  objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 6266c00c68cbb02de65f88d976453fdcdda552d7554199030640f9bcd60f208afaf75aaac8fbf0a2eea0022eb23ad7b809cb910d48618261ea9f52100732c469
+$(DL_FILE)_BLAKE2 = 2e4b88f13c5742e60fd5b2931e93cb861b8fd0b9b12ba340a08f185884b64e49f035e14387a19b9ae4ae7c71ec9249132c0ccf19febfcdefd4725ddef0877a77
 
 install : $(TARGET)
 
@@ -83,16 +83,14 @@  $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects))
 	@rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE)
 	cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/freeradius-no-buildtime-cert-gen.patch
 	$(UPDATE_AUTOMAKE)
-	cd $(DIR_APP) && \
-		./configure \
-			--prefix=/usr \
-			--sysconfdir=/etc \
-			--libdir=/usr/lib/freeradius \
-			--localstatedir=/var \
-			--with-threads \
-			--disable-openssl-version-check \
-			LDFLAGS="$(LDFLAGS)"
-
+	cd $(DIR_APP) && ./configure \
+				--prefix=/usr \
+				--sysconfdir=/etc \
+				--libdir=/usr/lib/freeradius \
+				--localstatedir=/var \
+				--with-threads \
+				--disable-openssl-version-check \
+				LDFLAGS="$(LDFLAGS)"
 	cd $(DIR_APP) && make $(MAKETUNING)
 	cd $(DIR_APP) && make install