From patchwork Fri Oct 2 11:23:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Adolf Belka X-Patchwork-Id: 10294 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hx5y563jGz3wqG for ; Fri, 02 Oct 2026 11:23:41 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hx5y367HYz88b for ; Fri, 02 Oct 2026 11:23:39 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hx5y23FmLz37Dr for ; Fri, 02 Oct 2026 11:23:38 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [IPv6:2001:678:b28::25]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hx5xz5lFmz30WN for ; Fri, 02 Oct 2026 11:23:35 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4hx5xz3CDlz3kH; Fri, 02 Oct 2026 11:23:35 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790940215; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zSGjM0V/m5mfC9FpD8ADQneSO4byZ2tg80GhkAoCZps=; b=MvVRcDRTPHN5Q6BqbPkGh8JEbsaVkabCfzIFuXRzDiM/0RdtegeGx2ThnICfHYhWvc5f6v mEP9FUvvBVNkczDQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790940215; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zSGjM0V/m5mfC9FpD8ADQneSO4byZ2tg80GhkAoCZps=; b=RNrgq6w6j7kH/XkTDTRhLmUU5ZFuXI5Pvo2syeOaWNnllVzN/jXqXZ9XsmI2yHZ9Qr0/WQ 3KqtZz3qfEu4dODisjWAA01LQlvo94d+IRT0A8q2qwon95RX0o99ajdSj28Jqo/CIipnYo xD8QzmvtiIWNLA5c3BYGIl79MrxVOl5PUBDSpoM10UZ8S3sF/41UP2rcTvx1HRg7oV1B7+ V1SkvSALolOpl1JPW91nRlCq8T3tCJtHk3tWnS5nd/CqD78AjbWXzHTwooG8fPwsrMgiyQ KjybjieugqwaER4vppWgXx6fnQA50jkzfVLpKaVgmAgdbDi0QuZurK25gEG4jw== From: Adolf Belka To: development@lists.ipfire.org Cc: Adolf Belka Subject: [PATCH] freeradius: Update to version 3.2.10 Date: Fri, 2 Oct 2026 13:23:21 +0200 Message-ID: <20261002112330.3568361-4-adolf.belka@ipfire.org> In-Reply-To: <20261002112330.3568361-1-adolf.belka@ipfire.org> References: <20261002112330.3568361-1-adolf.belka@ipfire.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 - Update from version 3.2.8 to 3.2.10 - Update of rootfile - Changelog 3.2.10 Correct bug where detail file reader would not read files. Patch from Bjørn Mork. Fixes #5870 3.2.9 Configuration changes Add protocol_error = yes configuration to clients. If set, the server can return Protocol-Error responses to the client. radclient can now suppress Message-Authenticator in Access-Request, when the input packet contains Message-Authenticator !* ANY Don't use this in production! Set suppress_secrets = true by default. Add connect_fail_interval to home_server configuration. If a connection fails, the server will wait this time before trying to connect again. Add certificate_fail_interval to home_server configuration. If a connection succeeds but the home_server certificate is invalid, the server will wait this time before trying to connect again. Add update section to home_server configuration. Status-Server packets can therefore be customized. Add cipher_suites to tls{} configuration. See raddb/sites-available/tls. This is mainly used to set the cipher suites for TLS-PSK with TLS 1.3. Feature improvements Initial implementation of Protocol-Failure as per IETF draft. The functionality is disabled by default, but can be enabled via new configuration flags. Always allow Protocol-Error packet as valid response to any packet. Add Error-Cause attributes to CoA-NAK and Disconnect-NAK Added filter_username_nai to policy.d/filter, mainly for use in eduroam. Updates to VSCode default configuration. Cleanups and add log messages for rlm_proxy_rate_limit. Allow 389ds legacy PBKDF2_SHA256 to use arbitrary iteration count. (#5654) Amend policy insert_acct_class/acct_unique to work in environments with multiple Class attributes (#5337) Tweak sqlippool messages to make them clearer. Print log message if the server receives a correct authenticated proxy response packet, but which has an unexpected code. e.g. received Access-Accept in response to an Accounting-Request. New installations now set "suppress_secrets=true" by default. The server also prints messages in debug mode which explains why the secrets are being suppressed. Allow parallel build for Debian. Fixes #5774. Add RTBrick and other dictionaries. Add documentation for ntlm_auth and spaces in passwords. Addresses #5654. Bug fixes Many minor bug fixes and cleanups. Fixes to RadSec. Many other fixes to socket and event handling, which enable increased scalability. Fix issues found with EAP-MSCHAPv2, EAP-PWD, and EAP-MD5. Fix run_dir (#5637) and MemoryLimit (#5639) Disable the PCRE JIT at run time if it can't allocate executable memory. Set selinux boolean to allow PCRE2 JIT If you set the clock 25 years in the future, don't spam systemd. Fixes #5642 Don't load the OpenSSL legacy provider when built with --enable-fips-workaround. Fixes #5644. Address potential leaks when opening many RADIUS/TLS proxy sockets. Encode multiple DHCP Option 82 as one option, instead of as multiple options. Update the rlm_cache_redis driver to reconnect on connection failure. Fixes #5651. Tweaks to the processing state machine to handle more corner cases / race conditions. Thanks to Paul Dekkers for testing. Don't close the main listen socket for TCP. Fixes #5661. Fix rlm_dspk to properly support dynamic filenames. Don't crash in corner cases when running Post-Proxy-Type Fail. Use correct name offsets in proxy_rate_limit. Fixes #5675. push fallback virtual server to child thread. Fixes #5679. Correct corner case in hash table. Fixes #5680. Allow new proxy sockets after reaching "too many sockets", when we close an existing proxy connection. Fixes #5964. fix consistent load balancing. Fixes #5770. Address pthread APIs. Fixes #5772. Install headers needed to build modules. Fixes #5778. Initialize scope in IPv6 address lookups. Fixes #5798. Don't load legacy provider on --enable-fips-workaround. Fixes #5775. Hoist mutex lock in TLS sockets. Fixes #5480 Fix occasional EAP-PWD authentication failure. Fix memcache storing of dates. Add more debugging information for TEAP. TEAP has limited utility, due to the incompleteness of the spec, and the severe limitations of the Windows TEAP supplicant. Return stats for "auth+acct" home servers. Fixes #5866. Signed-off-by: Adolf Belka --- config/rootfiles/packages/freeradius | 18 ++++++++++++++---- lfs/freeradius | 24 +++++++++++------------- 2 files changed, 25 insertions(+), 17 deletions(-) diff --git a/config/rootfiles/packages/freeradius b/config/rootfiles/packages/freeradius index 411769253..fdd5a4598 100644 --- a/config/rootfiles/packages/freeradius +++ b/config/rootfiles/packages/freeradius @@ -250,6 +250,7 @@ etc/raddb #etc/raddb/mods-enabled/detail #etc/raddb/mods-enabled/detail.log #etc/raddb/mods-enabled/digest +#etc/raddb/mods-enabled/dpsk #etc/raddb/mods-enabled/dynamic_clients #etc/raddb/mods-enabled/eap #etc/raddb/mods-enabled/echo @@ -331,9 +332,12 @@ usr/bin/map_unit usr/bin/rad_counter usr/bin/radattr usr/bin/radclient +usr/bin/radconf2json usr/bin/radcrypt +usr/bin/raddict2json usr/bin/radeapclient usr/bin/radlast +usr/bin/radmod2json usr/bin/radsecret usr/bin/radsniff usr/bin/radsqlrelay @@ -346,10 +350,13 @@ usr/bin/smbencrypt #usr/include/freeradius #usr/include/freeradius/attributes.h #usr/include/freeradius/autoconf.h +#usr/include/freeradius/automask.h #usr/include/freeradius/base64.h #usr/include/freeradius/build.h +#usr/include/freeradius/clients.h #usr/include/freeradius/conf.h #usr/include/freeradius/conffile.h +#usr/include/freeradius/connection.h #usr/include/freeradius/detail.h #usr/include/freeradius/event.h #usr/include/freeradius/features.h @@ -357,6 +364,8 @@ usr/bin/smbencrypt #usr/include/freeradius/hash.h #usr/include/freeradius/heap.h #usr/include/freeradius/libradius.h +#usr/include/freeradius/listen.h +#usr/include/freeradius/log.h #usr/include/freeradius/map.h #usr/include/freeradius/md4.h #usr/include/freeradius/md5.h @@ -364,6 +373,7 @@ usr/bin/smbencrypt #usr/include/freeradius/modcall.h #usr/include/freeradius/modules.h #usr/include/freeradius/packet.h +#usr/include/freeradius/process.h #usr/include/freeradius/rad_assert.h #usr/include/freeradius/radius.h #usr/include/freeradius/radiusd.h @@ -411,9 +421,11 @@ usr/bin/smbencrypt #usr/include/freeradius/tcp.h #usr/include/freeradius/threads.h #usr/include/freeradius/tls.h +#usr/include/freeradius/tmpl.h #usr/include/freeradius/token.h #usr/include/freeradius/udpfromto.h #usr/include/freeradius/vqp.h +#usr/include/freeradius/xlat.h #usr/lib/freeradius #usr/lib/freeradius/libfreeradius-dhcp.a #usr/lib/freeradius/libfreeradius-dhcp.la @@ -597,9 +609,6 @@ usr/lib/freeradius/rlm_sqlippool.so #usr/lib/freeradius/rlm_totp.a #usr/lib/freeradius/rlm_totp.la usr/lib/freeradius/rlm_totp.so -#usr/lib/freeradius/rlm_unbound.a -#usr/lib/freeradius/rlm_unbound.la -usr/lib/freeradius/rlm_unbound.so #usr/lib/freeradius/rlm_unix.a #usr/lib/freeradius/rlm_unix.la usr/lib/freeradius/rlm_unix.so @@ -686,6 +695,7 @@ usr/sbin/radmin #usr/share/doc/freeradius/antora/modules/developers/pages/coverage.adoc #usr/share/doc/freeradius/antora/modules/developers/pages/index.adoc #usr/share/doc/freeradius/antora/modules/developers/pages/profile.adoc +#usr/share/doc/freeradius/antora/modules/developers/pages/protocol-error.adoc #usr/share/doc/freeradius/antora/modules/developers/pages/release-method.adoc #usr/share/doc/freeradius/antora/modules/howto #usr/share/doc/freeradius/antora/modules/howto/nav.adoc @@ -899,7 +909,6 @@ usr/sbin/radmin #usr/share/doc/freeradius/rfc/draft-kamath-pppext-eap-mschapv2-00.txt #usr/share/doc/freeradius/rfc/draft-sterman-aaa-sip-00.txt #usr/share/doc/freeradius/rfc/genref.pl -#usr/share/doc/freeradius/rfc/leap.txt #usr/share/doc/freeradius/rfc/per-rfc.pl #usr/share/doc/freeradius/rfc/rewrite.pl #usr/share/doc/freeradius/rfc/rfc1157.txt @@ -1198,6 +1207,7 @@ usr/share/freeradius #usr/share/freeradius/dictionary.riverbed #usr/share/freeradius/dictionary.riverstone #usr/share/freeradius/dictionary.roaringpenguin +#usr/share/freeradius/dictionary.rtbrick #usr/share/freeradius/dictionary.ruckus #usr/share/freeradius/dictionary.ruggedcom #usr/share/freeradius/dictionary.sangoma diff --git a/lfs/freeradius b/lfs/freeradius index 1a5ea7117..ec13b8ce3 100644 --- a/lfs/freeradius +++ b/lfs/freeradius @@ -26,7 +26,7 @@ include Config SUMMARY = RADIUS Server -VER = 3.2.8 +VER = 3.2.10 THISAPP = freeradius-server-$(VER) DL_FILE = $(THISAPP).tar.bz2 @@ -34,7 +34,7 @@ DL_FROM = $(URL_IPFIRE) DIR_APP = $(DIR_SRC)/$(THISAPP) TARGET = $(DIR_INFO)/$(THISAPP) PROG = freeradius -PAK_VER = 26 +PAK_VER = 27 DEPS = libtalloc samba @@ -48,7 +48,7 @@ objects = $(DL_FILE) $(DL_FILE) = $(DL_FROM)/$(DL_FILE) -$(DL_FILE)_BLAKE2 = 6266c00c68cbb02de65f88d976453fdcdda552d7554199030640f9bcd60f208afaf75aaac8fbf0a2eea0022eb23ad7b809cb910d48618261ea9f52100732c469 +$(DL_FILE)_BLAKE2 = 2e4b88f13c5742e60fd5b2931e93cb861b8fd0b9b12ba340a08f185884b64e49f035e14387a19b9ae4ae7c71ec9249132c0ccf19febfcdefd4725ddef0877a77 install : $(TARGET) @@ -83,16 +83,14 @@ $(TARGET) : $(patsubst %,$(DIR_DL)/%,$(objects)) @rm -rf $(DIR_APP) && cd $(DIR_SRC) && tar axf $(DIR_DL)/$(DL_FILE) cd $(DIR_APP) && patch -Np1 < $(DIR_SRC)/src/patches/freeradius-no-buildtime-cert-gen.patch $(UPDATE_AUTOMAKE) - cd $(DIR_APP) && \ - ./configure \ - --prefix=/usr \ - --sysconfdir=/etc \ - --libdir=/usr/lib/freeradius \ - --localstatedir=/var \ - --with-threads \ - --disable-openssl-version-check \ - LDFLAGS="$(LDFLAGS)" - + cd $(DIR_APP) && ./configure \ + --prefix=/usr \ + --sysconfdir=/etc \ + --libdir=/usr/lib/freeradius \ + --localstatedir=/var \ + --with-threads \ + --disable-openssl-version-check \ + LDFLAGS="$(LDFLAGS)" cd $(DIR_APP) && make $(MAKETUNING) cd $(DIR_APP) && make install