-2011-12-12 1.6-dev
+2012-10-25 1.6.2
+ Bug fixes (security):
+ - Fix the issue with verification of clients when using multiple
+ 'tls' config blocks (RADSECPROXY-43) for DTLS too. Fixes
+ CVE-2012-4523. Reported by Raphael Geissert.
+
+2012-09-14 1.6.1
+ Bug fixes (security):
+ - When verifying clients, don't consider config blocks with CA
+ settings ('tls') which differ from the one used for verifying the
+ certificate chain. Reported by Ralf Paffrath. (RADSECPROXY-43,
+ CVE-2012-4523).
+
+ Bug fixes:
+ - Make naptr-eduroam.sh check NAPTR type case insensitively.
+ Fix from Adam Osuchowski.
+
+2012-04-27 1.6
+ Incompatible changes:
+ - The default shared secret for TLS and DTLS connections change
+ from "mysecret" to "radsec" as per draft-ietf-radext-radsec-12
+ section 2.3 (4). Please make sure to specify a secret in both
+ client and server blocks to avoid unwanted surprises.
+ (RADSECPROXY-19)
+ - The default place to look for a configuration file has changed
+ from /etc to /usr/local/etc. Let radsecproxy know where your
+ configuration file can be found by using the `-c' command line
+ option. Or configure radsecproxy with --sysconfdir=/etc to
+ restore the old behaviour. (RADSECPROXY-31)
+
+ New features:
+ - Improved F-Ticks logging options. F-Ticks can now be sent to a
+ separate syslog facility and the VISINST label can now be
+ configured explicitly. This was implemented by Maja
+ Gorecka-Wolniewicz and Paweł Gołaszewski. (RADSECPROXY-29)
+ - New config option PidFile. (RADSECPROXY-32)
+ - Preliminary support for DynamicLookupCommand added. It's for
+ TLS servers only at this point. Also, beware of risks for memory
+ leaks. In addition to this, for extra adventurous users, there's
+ a new configure option --enable-experimental-dyndisc which enables
+ even more new code for handling of dynamic discovery of TLS
+ servers.
+ - Address family (IPv4 or IPv6) can now be specified for clients
+ and servers. (RADSECPROXY-37)
+
Bug fixes:
- Stop the autoconfery from warning about defining variables
conditionally and unconditionally.
+ - Honour configure option --sysconfdir. (RADSECPROXY-31)
+ - Don't crash on failing DynamicLookupCommand scripts. Fix made
+ with help from Ralf Paffrath. (RADSECPROXY-33)
+ - When a DynamicLookupCommand script is failing, fall back to
+ other server(s) in the realm. The timeout depends on the kind of
+ failure.
+ - Other bugs. (RADSECPROXY-26, -28, -34, -35, -39, -40)
2011-10-08 1.5
New features: