]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
Arran Cudbard-Bell [Tue, 10 Dec 2013 13:35:19 +0000 (13:35 +0000)]
Typo in MIT krb5
Arran Cudbard-Bell [Mon, 9 Dec 2013 19:30:28 +0000 (19:30 +0000)]
Remove restrictions on VSAs in sqlcounter
Tobias Hachmer [Mon, 9 Dec 2013 06:46:19 +0000 (07:46 +0100)]
Update dictionary.xylan
Arran Cudbard-Bell [Mon, 9 Dec 2013 13:42:52 +0000 (13:42 +0000)]
base_dn is no longer required
Arran Cudbard-Bell [Sat, 7 Dec 2013 22:55:49 +0000 (22:55 +0000)]
Fix conflicting names
Arran Cudbard-Bell [Sat, 7 Dec 2013 22:29:13 +0000 (22:29 +0000)]
Dictionary formatting
Arran Cudbard-Bell [Sat, 7 Dec 2013 22:28:06 +0000 (22:28 +0000)]
Additions to the Juniper dictionary
Alan T. DeKok [Fri, 6 Dec 2013 15:20:38 +0000 (10:20 -0500)]
We can proxy nodup sockets. We can't proxy synchronous
The nodup ones can come out of order, but they can't be duplicates.
The synchronous ones wait for a response before replying. Proxying
can take a long time, so we can't do synchronous there
Alan T. DeKok [Thu, 5 Dec 2013 17:34:26 +0000 (12:34 -0500)]
Use correct struct entry for pedanticism
Arran Cudbard-Bell [Thu, 5 Dec 2013 20:54:53 +0000 (12:54 -0800)]
Merge pull request #485 from kokel/freeradius.spec
Update spec file for sqlite counter files
Arran Cudbard-Bell [Thu, 5 Dec 2013 20:54:40 +0000 (12:54 -0800)]
Merge pull request #484 from kokel/openldap-schema30x
radiusProfileDn is now a multivalued attribute
Tobias Hachmer [Thu, 5 Dec 2013 20:48:38 +0000 (21:48 +0100)]
Update spec file for sqlite counter files
Tobias Hachmer [Thu, 5 Dec 2013 20:41:20 +0000 (21:41 +0100)]
radiusProfileDn is now a multivalued attribute
Arran Cudbard-Bell [Thu, 5 Dec 2013 16:15:41 +0000 (11:15 -0500)]
Formatting
Arran Cudbard-Bell [Thu, 5 Dec 2013 19:05:02 +0000 (19:05 +0000)]
Formatting
Arran Cudbard-Bell [Thu, 5 Dec 2013 11:45:12 +0000 (11:45 +0000)]
Output more verbose errors for eDirectory
Arran Cudbard-Bell [Thu, 5 Dec 2013 10:24:58 +0000 (10:24 +0000)]
Increase debug level required to show missing attribute messages in rlm_ldap
Arran Cudbard-Bell [Wed, 4 Dec 2013 22:06:16 +0000 (17:06 -0500)]
Note case insensitivity
Arran Cudbard-Bell [Wed, 4 Dec 2013 19:38:30 +0000 (19:38 +0000)]
base_dn defaults to a zero length string to allow top of tree searching like in >= 2.2.3
Arran Cudbard-Bell [Wed, 4 Dec 2013 18:52:37 +0000 (13:52 -0500)]
Update ChangeLog
Arran Cudbard-Bell [Wed, 4 Dec 2013 18:50:30 +0000 (18:50 +0000)]
radiusProfileDn is now a multivalued attribute
Arran Cudbard-Bell [Wed, 4 Dec 2013 18:25:35 +0000 (18:25 +0000)]
Small tweak to ldap debug output
Arran Cudbard-Bell [Wed, 4 Dec 2013 17:15:34 +0000 (17:15 +0000)]
Use a single generic attribute in the RADIUS LDAP schema
Add ldiff version of the standard RADIUS LDAP schema for newer versions of OpenLDAP
Schema can be loaded with sudo ldapadd -Y EXTERNAL -H ldapi:/// -f ./radius.ldif
Arran Cudbard-Bell [Wed, 4 Dec 2013 15:39:34 +0000 (15:39 +0000)]
Add comments field to other forms of schema
Arran Cudbard-Bell [Wed, 4 Dec 2013 15:14:55 +0000 (10:14 -0500)]
Update ChangeLog
Arran Cudbard-Bell [Wed, 4 Dec 2013 14:54:31 +0000 (14:54 +0000)]
Use pairmove to add SQL-User-Name
Alan T. DeKok [Wed, 4 Dec 2013 14:18:17 +0000 (09:18 -0500)]
Added test for error parsing IP address
Alan T. DeKok [Wed, 4 Dec 2013 14:17:17 +0000 (09:17 -0500)]
Added flag to disallow hostname -> IP lookups.
Mainly for the tests . It's still OK (and needed) for admins
to use "client.example.com" in the configs. Requiring them to
use only IP addresses is annoying.
Arran Cudbard-Bell [Wed, 4 Dec 2013 11:49:04 +0000 (11:49 +0000)]
Add test for literal values
Only do RHS literal validation in updates and rlm_cache
Alan T. DeKok [Wed, 4 Dec 2013 02:58:41 +0000 (21:58 -0500)]
Run "radiusd -C" only if something changed
Alan T. DeKok [Wed, 4 Dec 2013 02:58:01 +0000 (21:58 -0500)]
No need to end a line with a trailing quotation mark
Alan T. DeKok [Wed, 4 Dec 2013 02:57:40 +0000 (21:57 -0500)]
Quieter output
Alan T. DeKok [Wed, 4 Dec 2013 02:50:00 +0000 (21:50 -0500)]
Building raddb is an order dependency
re-doing it changes the directory, which causes the tests to be run again
Alan T. DeKok [Wed, 4 Dec 2013 00:24:17 +0000 (19:24 -0500)]
Word smithing
Arran Cudbard-Bell [Tue, 3 Dec 2013 23:18:12 +0000 (23:18 +0000)]
We don't need to print out query errors to the mains server log
Arran Cudbard-Bell [Tue, 3 Dec 2013 22:31:42 +0000 (22:31 +0000)]
Add sqlcounter queries for sqlite
Arran Cudbard-Bell [Tue, 3 Dec 2013 22:21:19 +0000 (22:21 +0000)]
Update sqlite queries so they actually work with sqlite
Alan T. DeKok [Tue, 3 Dec 2013 14:33:39 +0000 (09:33 -0500)]
Note recent changes
Alan T. DeKok [Tue, 3 Dec 2013 14:25:39 +0000 (09:25 -0500)]
Fix typo
Arran Cudbard-Bell [Tue, 3 Dec 2013 12:16:24 +0000 (12:16 +0000)]
Typo
Arran Cudbard-Bell [Mon, 2 Dec 2013 23:19:06 +0000 (23:19 +0000)]
Fix formatting and typo
Arran Cudbard-Bell [Mon, 2 Dec 2013 23:18:47 +0000 (23:18 +0000)]
Add GREATEST(x, ...) to sqlite to support sqlcounter
Arran Cudbard-Bell [Mon, 2 Dec 2013 19:35:41 +0000 (19:35 +0000)]
Add policy to create 64bit octet counters
Arran Cudbard-Bell [Mon, 2 Dec 2013 19:15:25 +0000 (19:15 +0000)]
Fix typos in xlat function docs
Arran Cudbard-Bell [Mon, 2 Dec 2013 18:39:38 +0000 (18:39 +0000)]
Add power operator to expr
Who needs left shift when you can do %{expr:(%{Acct-Output-Gigawords} * (2 ^ 32)) + %{Acct-Input-Octets}}}. Ok bad example, but i'm sure someone will find it useful.
Arran Cudbard-Bell [Sun, 1 Dec 2013 21:37:50 +0000 (16:37 -0500)]
radusergroup needs a primary key too, else PgAdmin (rightly) refuses to work with it
Arran Cudbard-Bell [Sun, 1 Dec 2013 21:19:03 +0000 (21:19 +0000)]
Temporary fix for SQL counter module
Really need nested expansion of config items to do this properly
Alan T. DeKok [Sun, 1 Dec 2013 13:57:38 +0000 (08:57 -0500)]
Typo
Arran Cudbard-Bell [Sat, 30 Nov 2013 22:51:24 +0000 (17:51 -0500)]
Update ChangeLog
Arran Cudbard-Bell [Sat, 30 Nov 2013 22:36:24 +0000 (22:36 +0000)]
Initialise TLS *ONCE* in main, don't reinitialise it every time a new ctx is created.
Late initialisation was causing the PostgreSQL driver to fail with rlm_sql_postgresql: Connection failed: could not create SSL context: SSL error code
336236705
Arran Cudbard-Bell [Sat, 30 Nov 2013 22:04:23 +0000 (22:04 +0000)]
Allow arbitrary connection parameters to be listed in radius_db in the PostgreSQL driver, this allows things like open SSL to be disabled/enabled.
Arran Cudbard-Bell [Sat, 30 Nov 2013 11:47:46 +0000 (06:47 -0500)]
Note more changes
Arran Cudbard-Bell [Fri, 29 Nov 2013 22:23:46 +0000 (22:23 +0000)]
Add SSL support to the MySQL driver, and document driver specific options.
Arran Cudbard-Bell [Fri, 29 Nov 2013 20:53:31 +0000 (20:53 +0000)]
LDAP_OPT_DEBUG_LEVEL only appears to work if set in the global context
Arran Cudbard-Bell [Fri, 29 Nov 2013 20:53:08 +0000 (20:53 +0000)]
Initialise TLS context last, after setting all the TLS options, else they're not respected...
Alan T. DeKok [Fri, 29 Nov 2013 15:08:31 +0000 (10:08 -0500)]
Note recent changes
Arran Cudbard-Bell [Thu, 28 Nov 2013 13:08:42 +0000 (13:08 +0000)]
Move some useful functions into misc.c
Arran Cudbard-Bell [Thu, 28 Nov 2013 13:25:48 +0000 (13:25 +0000)]
Do compile time checks of literal map values
Alan T. DeKok [Wed, 27 Nov 2013 16:25:49 +0000 (11:25 -0500)]
Files have CR at EOF
Alan T. DeKok [Wed, 27 Nov 2013 16:25:27 +0000 (11:25 -0500)]
Abstract module dependencies
So that we link the raddb config and the module.la before
running the tests
Alan T. DeKok [Wed, 27 Nov 2013 16:06:42 +0000 (11:06 -0500)]
Ensure that the raddb directory is set up before running tests
Alan T. DeKok [Wed, 27 Nov 2013 14:32:36 +0000 (09:32 -0500)]
Use different context for input and output REQUESTs
Arran Cudbard-Bell [Wed, 27 Nov 2013 13:47:25 +0000 (13:47 +0000)]
Fix typo
Arran Cudbard-Bell [Wed, 27 Nov 2013 13:40:41 +0000 (13:40 +0000)]
Always respect control:Response-Packet-Type if it's present, no matter what the request type was.
This allows:
accounting {
update {
control:Response-Packet-Type := Accounting-Response
}
handled
}
If you want to short circuit accounting. This is consistent with authentication behaviour.
Conflicts:
src/main/process.c
Arran Cudbard-Bell [Wed, 27 Nov 2013 12:25:03 +0000 (12:25 +0000)]
Should be case insensitive comparison
Arran Cudbard-Bell [Wed, 27 Nov 2013 11:16:55 +0000 (06:16 -0500)]
Add example to access_attribute
Alan T. DeKok [Wed, 27 Nov 2013 04:02:12 +0000 (23:02 -0500)]
Added "status" to the init script
Arran Cudbard-Bell [Tue, 26 Nov 2013 17:30:14 +0000 (12:30 -0500)]
Add note about access attribute 'false' value
Arran Cudbard-Bell [Tue, 26 Nov 2013 17:16:33 +0000 (17:16 +0000)]
Process attribute maps if we just have a generic attribute set
Arran Cudbard-Bell [Tue, 26 Nov 2013 17:16:11 +0000 (17:16 +0000)]
Use the map functions to parse VALUE_PAIR string tuples
Arran Cudbard-Bell [Tue, 26 Nov 2013 16:37:25 +0000 (16:37 +0000)]
Formatting
Arran Cudbard-Bell [Tue, 26 Nov 2013 16:37:15 +0000 (16:37 +0000)]
attribute with value 'false' always negates result of LDAP access_check
Alan T. DeKok [Tue, 26 Nov 2013 16:08:18 +0000 (11:08 -0500)]
Run tests only when doing "make test"
Alan T. DeKok [Tue, 26 Nov 2013 16:03:11 +0000 (11:03 -0500)]
Ensure that "break" can only occur in "foreach" sections
Alan T. DeKok [Tue, 26 Nov 2013 16:02:34 +0000 (11:02 -0500)]
Ensure we only grab one error message
Alan T. DeKok [Tue, 26 Nov 2013 15:47:04 +0000 (10:47 -0500)]
Make "break" jump out of the "foreach" loop
and add a test to that effect!
Alan T. DeKok [Tue, 26 Nov 2013 15:30:52 +0000 (10:30 -0500)]
Print input VPs to the log
Alan T. DeKok [Tue, 26 Nov 2013 14:54:49 +0000 (09:54 -0500)]
Simple tests for parse errors
Alan T. DeKok [Tue, 26 Nov 2013 13:52:20 +0000 (08:52 -0500)]
From extreme
Alan T. DeKok [Mon, 25 Nov 2013 20:37:57 +0000 (15:37 -0500)]
Ensure a one-way check
Alan T. DeKok [Mon, 25 Nov 2013 15:22:41 +0000 (10:22 -0500)]
Do allocate_clear no more than once per second
To lower the load on the database.
Alan T. DeKok [Mon, 25 Nov 2013 15:19:16 +0000 (10:19 -0500)]
Put a separate transaction around allocate_clear
to deal with MySQL issues. It reduces deadlocks
Alan T. DeKok [Fri, 22 Nov 2013 15:12:17 +0000 (10:12 -0500)]
Don't need debugging when we open a new TLS socket
Alan T. DeKok [Fri, 22 Nov 2013 14:50:26 +0000 (09:50 -0500)]
Don't worry about threading when doing radiusd -C
We're not opening sockets or starting threads, so the error
message isn't necessary
Alan T. DeKok [Fri, 22 Nov 2013 03:30:05 +0000 (22:30 -0500)]
Fix the test. Fixes #480
Returns aren't recursive.
See doc/configuration/configurable_failover.rst
The "Handle accounting packets" line doesn't do "detail2" if
"detail1" succeeds. However, it DOES do the "redundant" block
immediately following the "group" which contains both "detail1"
and "detail2"
Arran Cudbard-Bell [Thu, 21 Nov 2013 23:47:52 +0000 (23:47 +0000)]
Add return and return-group tests
annanymous2 [Mon, 4 Nov 2013 12:26:54 +0000 (13:26 +0100)]
Update rcradiusd
Two new Parameters for SuSe init-Script
Arran Cudbard-Bell [Thu, 21 Nov 2013 12:41:13 +0000 (12:41 +0000)]
libiodbc2 now needs to be install before libiodbc2-dev
Alan T. DeKok [Thu, 21 Nov 2013 00:16:05 +0000 (19:16 -0500)]
Clean up counters when we close the socket
Alan T. DeKok [Thu, 21 Nov 2013 00:14:31 +0000 (19:14 -0500)]
Use sock context for allocating packets
So they get free'd correctly when we exit
Alan T. DeKok [Wed, 20 Nov 2013 23:04:29 +0000 (18:04 -0500)]
check_config is now a bool
Alan T. DeKok [Wed, 20 Nov 2013 14:49:09 +0000 (09:49 -0500)]
Note recent changes
Alan T. DeKok [Wed, 20 Nov 2013 04:35:55 +0000 (23:35 -0500)]
Fix typo
Alan T. DeKok [Mon, 18 Nov 2013 22:05:54 +0000 (17:05 -0500)]
Remove rlm_eap from messages. It's no longer in a module
Arran Cudbard-Bell [Sun, 17 Nov 2013 17:55:25 +0000 (17:55 +0000)]
Proper fix for .gitignore and debian packaging
Arran Cudbard-Bell [Sun, 17 Nov 2013 17:04:45 +0000 (17:04 +0000)]
Remove patches after build
Arran Cudbard-Bell [Sun, 17 Nov 2013 13:26:25 +0000 (13:26 +0000)]
Debian fixes
Arran Cudbard-Bell [Sun, 17 Nov 2013 13:01:16 +0000 (13:01 +0000)]
Quiet static analysis
Arran Cudbard-Bell [Sat, 16 Nov 2013 21:32:43 +0000 (21:32 +0000)]
We should probably still make a minimal effort not to leak memory
Arran Cudbard-Bell [Sat, 16 Nov 2013 21:22:03 +0000 (21:22 +0000)]
Set operator correctly when calling paircompare from radius_evaluate_map