]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
Alan T. DeKok [Mon, 26 Feb 2018 19:41:41 +0000 (14:41 -0500)]
don't lock the file if it has been renamed
Alan DeKok [Mon, 26 Feb 2018 19:22:21 +0000 (14:22 -0500)]
Merge pull request #2164 from frenche/ssl_read
TLS: Treat SSL_read returning zero as an error
Alan DeKok [Mon, 26 Feb 2018 19:21:54 +0000 (14:21 -0500)]
Merge pull request #2162 from frenche/partial_chain
TLS: Allow partial certificate chain to trusted CA
Alan T. DeKok [Sat, 24 Feb 2018 16:07:56 +0000 (11:07 -0500)]
note recent changes
Alan T. DeKok [Sat, 24 Feb 2018 16:07:07 +0000 (11:07 -0500)]
allow duplicate "authhost" for duplicate realms.
Alan T. DeKok [Fri, 23 Feb 2018 17:50:05 +0000 (12:50 -0500)]
note recent changes
Alan T. DeKok [Fri, 23 Feb 2018 14:00:26 +0000 (09:00 -0500)]
copy tag over from template
Alan T. DeKok [Fri, 23 Feb 2018 14:00:06 +0000 (09:00 -0500)]
copy tag over from template
Alan T. DeKok [Fri, 23 Feb 2018 13:17:11 +0000 (08:17 -0500)]
more error messages
Alan T. DeKok [Thu, 22 Feb 2018 14:47:55 +0000 (09:47 -0500)]
skip empty accounting packets, not all empty packets
Alan T. DeKok [Tue, 13 Feb 2018 00:37:00 +0000 (19:37 -0500)]
one last check
Arran Cudbard-Bell [Tue, 13 Feb 2018 15:08:58 +0000 (15:08 +0000)]
Merge pull request #2180 from spbnick/double_free_in_acct_redundant
Fix double free in rlm_sql acct_redundant
Nikolai Kondrashov [Tue, 13 Feb 2018 14:56:10 +0000 (16:56 +0200)]
Fix double free in rlm_sql acct_redundant
Do not free "expanded" buffer twice in "acct_redundant" in rlm_sql.c.
This fixes a crash in the case of an accounting packet not matching a
Start entry in the database.
See also https://bugzilla.redhat.com/show_bug.cgi?id=
1540580
Found and fixed by Benoit Welterlen.
Alan T. DeKok [Mon, 12 Feb 2018 23:49:34 +0000 (18:49 -0500)]
clean up fr_pton()
strchr() from the previous commit didn't work, because it
ignored inlen. Instead, walk over the *whole* string, checking
*all* of the characters. The issue with the earlier code was
that it bailed too early, and forced IPv4 even when the address
was IPv6.
Alan T. DeKok [Mon, 12 Feb 2018 22:31:42 +0000 (17:31 -0500)]
note recent changes
Alan T. DeKok [Mon, 12 Feb 2018 22:30:14 +0000 (17:30 -0500)]
hoist IPv6 raw checks outside of the look
"face:i..." is a valid IPv6 address, and the "f" portion
shouldn't cause it to do a DNS lookup.
Alan T. DeKok [Wed, 7 Feb 2018 19:44:44 +0000 (14:44 -0500)]
return size of *output* data, not input data
Alan T. DeKok [Wed, 7 Feb 2018 15:23:13 +0000 (10:23 -0500)]
typo
Alan T. DeKok [Wed, 7 Feb 2018 15:20:24 +0000 (10:20 -0500)]
added expected / got text so we know WTF went wrong
Alan T. DeKok [Wed, 7 Feb 2018 14:25:18 +0000 (09:25 -0500)]
updates
Alan T. DeKok [Tue, 6 Feb 2018 19:57:18 +0000 (14:57 -0500)]
cast for correct value
Alan T. DeKok [Tue, 6 Feb 2018 19:47:38 +0000 (14:47 -0500)]
check prefix length values, too
Alan T. DeKok [Tue, 6 Feb 2018 19:42:57 +0000 (14:42 -0500)]
don't copy short data for complex types
Alan T. DeKok [Tue, 6 Feb 2018 19:36:00 +0000 (14:36 -0500)]
re-add byte, ipv4prefix, ipv6prefix
Alan T. DeKok [Tue, 6 Feb 2018 19:03:20 +0000 (14:03 -0500)]
note recent changes.
Alan T. DeKok [Mon, 5 Feb 2018 21:54:11 +0000 (16:54 -0500)]
leave one byte of room for the trailing zero
and zero out the array, too
Alan T. DeKok [Mon, 5 Feb 2018 20:30:14 +0000 (15:30 -0500)]
Revert "re-add SSL wrappers for freeing VPs and Certs."
This reverts commit
63559782c19507cbe9e616d783e51b11c9e6dc72 .
Now that we've disabled the internal OpenSSL cache, we can
rely on talloc to clean up memory.
It turns out that OpenSSL doesn't call our cleanup handlers
when removing SSL sessions.
Alan T. DeKok [Mon, 5 Feb 2018 19:45:28 +0000 (14:45 -0500)]
check lengths for these, too
Alan T. DeKok [Mon, 5 Feb 2018 18:52:01 +0000 (13:52 -0500)]
allow casting from integer to date
Alan T. DeKok [Mon, 5 Feb 2018 18:50:26 +0000 (13:50 -0500)]
zero out memory, and copy only as much as necessary
Alan T. DeKok [Mon, 5 Feb 2018 12:47:08 +0000 (07:47 -0500)]
talloc_free is useful, even for temporary things
Arran Cudbard-Bell [Mon, 5 Feb 2018 16:14:01 +0000 (16:14 +0000)]
Merge pull request #2177 from qnet-herwin/patch-1
Typo fix in README
Herwin [Mon, 5 Feb 2018 13:18:50 +0000 (14:18 +0100)]
Typo fix in README
s/dialip/dialup/
Alan DeKok [Fri, 2 Feb 2018 15:50:54 +0000 (10:50 -0500)]
Merge pull request #2175 from frenche/may_be_attr
parser: relax may-be-attr logic
Isaac Boukris [Fri, 2 Feb 2018 14:42:58 +0000 (14:42 +0000)]
parser: relax may-be-attr logic
we check for too many hyphens later
Alan Buxey [Thu, 1 Feb 2018 12:50:48 +0000 (12:50 +0000)]
change RuntimeDirectory to a location
as per systemd docs and various other blogs, this value is the directory name relative to the parent path, not the fully defined path
with this change /var/run/radiusd will be created and used
Alan T. DeKok [Wed, 31 Jan 2018 13:22:45 +0000 (08:22 -0500)]
typo. fixes #2169
Matthew Newton [Thu, 25 Jan 2018 20:57:32 +0000 (20:57 +0000)]
rhel7 libwbclient RPM dependencies
Alan T. DeKok [Tue, 30 Jan 2018 14:31:04 +0000 (09:31 -0500)]
add and use "find home server using src_ip" function
Alan T. DeKok [Tue, 30 Jan 2018 14:19:25 +0000 (09:19 -0500)]
allow stats to specify 'src <ipaddr>'. Helps with #2169
The underlying "find home server using src IP" isn't there yet,
but this is the start.
Alan T. DeKok [Thu, 25 Jan 2018 22:12:30 +0000 (17:12 -0500)]
note recent changes
Alan T. DeKok [Thu, 25 Jan 2018 22:10:33 +0000 (17:10 -0500)]
use "raw" string values. Fixes #2168
Alan DeKok [Wed, 24 Jan 2018 18:57:27 +0000 (13:57 -0500)]
Merge pull request #2167 from nchaigne/3.0.x-2018-rest-cainfo
3.0.x - rest - curl option CURLOPT_CAINFO
Nicolas C [Wed, 24 Jan 2018 17:53:38 +0000 (18:53 +0100)]
3.0.x - rest - curl option CURLOPT_CAINFO
As proposed on the ML, this patch adds support for curl option
CURLOPT_CAINFO (through a new parameter "ca_info_file").
This new parameter can be used instead of "ca_file" (which sets curl
option CURLOPT_ISSUERCERT).
(They can also be used both at the same time.)
CURLOPT_CAINFO is useful to validate a chain of certificate authorities.
If this option is not set, curl will try to validate the CA chain using
a default location, and it may fail.
CURLOPT_ISSUERCERT is useful to check the issuer of the server
certificate.
For reference, see:
https://curl.haxx.se/libcurl/c/CURLOPT_ISSUERCERT.html
https://curl.haxx.se/libcurl/c/CURLOPT_CAINFO.html
Alan T. DeKok [Wed, 24 Jan 2018 16:08:53 +0000 (11:08 -0500)]
home_server may be NULL
Alan T. DeKok [Mon, 22 Jan 2018 20:21:06 +0000 (15:21 -0500)]
note recent changes
Isaac Boukris [Sat, 20 Jan 2018 11:26:57 +0000 (11:26 +0000)]
TLS: Treat SSL_read returning zero as an error
As according to the doc, as well as other usage
of it in our code.
Isaac Boukris [Fri, 19 Jan 2018 02:23:30 +0000 (02:23 +0000)]
TLS: Allow partial certificate chain to trusted CA
This lets for example to only trust a local sub CA
without having to trust the whole hierarchy.
Alan DeKok [Fri, 19 Jan 2018 01:04:31 +0000 (20:04 -0500)]
Merge pull request #2161 from mcnewton/v3.0.x
don't call process_proxy_reply twice when proxying to a virtual server
Matthew Newton [Thu, 18 Jan 2018 23:42:19 +0000 (23:42 +0000)]
don't call process_proxy_reply twice when proxying to a virtual server
Matthew Newton [Tue, 16 Jan 2018 11:41:01 +0000 (11:41 +0000)]
don't try to build rlm_eap_fast if it can't be built
Arran Cudbard-Bell [Mon, 15 Jan 2018 23:22:26 +0000 (16:22 -0700)]
Merge pull request #2158 from mcnewton/gccnodt
autoconf updates
Matthew Newton [Mon, 15 Jan 2018 22:59:15 +0000 (22:59 +0000)]
autoconf typo
Matthew Newton [Mon, 15 Jan 2018 22:31:37 +0000 (22:31 +0000)]
Check for -Wno-date-time to pacify ancient compilers
Alan T. DeKok [Fri, 12 Jan 2018 15:34:11 +0000 (10:34 -0500)]
these attributes are "string". Fixes #2130
Alan T. DeKok [Fri, 12 Jan 2018 14:04:36 +0000 (09:04 -0500)]
remove LN-S from warnings
Alan T. DeKok [Thu, 11 Jan 2018 18:22:33 +0000 (13:22 -0500)]
bump for 3.0.17
Alan T. DeKok [Thu, 11 Jan 2018 16:10:59 +0000 (11:10 -0500)]
note recent changes
Alan T. DeKok [Wed, 10 Jan 2018 14:58:50 +0000 (09:58 -0500)]
don't re-generate `configure` unless asked to
Alan DeKok [Wed, 10 Jan 2018 13:33:41 +0000 (08:33 -0500)]
Merge pull request #2155 from nchaigne/3.0.x-2018-dhcpcli-raw
3.0.x - dhcpclient - raw socket fixes
Nicolas C [Wed, 10 Jan 2018 08:19:43 +0000 (09:19 +0100)]
3.0.x - dhcpclient - raw socket fixes
Following the commits by Alan to reintroduce the raw socket code to
dhcpclient, I have:
- fixed a few compilation warnings
- added autoconf for HAVE_LINUX_IF_PACKET_H
I'm not so sure of myself for the autoconf part, can you check it's done
properly?
Thanks!
Matthew Newton [Tue, 9 Jan 2018 15:28:53 +0000 (15:28 +0000)]
include dhcpclient binary in freeradius-dhcp debian package
Matthew Newton [Tue, 9 Jan 2018 12:53:33 +0000 (12:53 +0000)]
don't fail in removing freeradius-config .deb pkg if dir no longer exists
Matthew Newton [Tue, 9 Jan 2018 11:16:14 +0000 (11:16 +0000)]
also don't pull in boiler.mk whilst doing make deb
Alan T. DeKok [Tue, 28 Nov 2017 16:39:42 +0000 (11:39 -0500)]
allow "make deb" before running "configure"
as "make deb" runs "configure" itself in a fake root
Matthew Newton [Tue, 9 Jan 2018 10:35:12 +0000 (10:35 +0000)]
make sure install continues even if the daemon isn't running
First install fails if freeradius package and module packages are
installed at the same time.
Alan T. DeKok [Mon, 8 Jan 2018 01:46:42 +0000 (20:46 -0500)]
remove groupname from radacct
it's not used, and it was confusing too many people.
Alan T. DeKok [Fri, 5 Jan 2018 13:39:59 +0000 (08:39 -0500)]
note recent changes
Alan T. DeKok [Thu, 4 Jan 2018 19:37:38 +0000 (14:37 -0500)]
add fr_dhcp_recv_raw_loop()
Alan T. DeKok [Thu, 4 Jan 2018 19:34:13 +0000 (14:34 -0500)]
more cleanups for raw sockets
Alan T. DeKok [Thu, 4 Jan 2018 18:51:19 +0000 (13:51 -0500)]
set timeout for all sockets
Alan T. DeKok [Thu, 4 Jan 2018 18:49:44 +0000 (13:49 -0500)]
start pulling raw socket code back in
Alan T. DeKok [Tue, 2 Jan 2018 15:06:54 +0000 (10:06 -0500)]
remove OCSP for now.
Alan T. DeKok [Tue, 2 Jan 2018 14:37:40 +0000 (09:37 -0500)]
remove dependency on ocsp.cnf
it seems to be confusing travis?
Alan T. DeKok [Tue, 2 Jan 2018 14:18:34 +0000 (09:18 -0500)]
note recent changes
Alan T. DeKok [Mon, 1 Jan 2018 19:32:07 +0000 (14:32 -0500)]
add OCSP and provisions for external_ca from v4.0.x branch
Alan T. DeKok [Wed, 27 Dec 2017 16:02:00 +0000 (11:02 -0500)]
create state on Access-Challenge, if it isn't already there
Alan T. DeKok [Tue, 19 Dec 2017 18:48:42 +0000 (13:48 -0500)]
Ensure that the LHS is a RADIUS attribute
Alan T. DeKok [Tue, 19 Dec 2017 18:44:54 +0000 (13:44 -0500)]
typo
Alan T. DeKok [Mon, 18 Dec 2017 21:07:29 +0000 (16:07 -0500)]
OCSP fixes
Alan T. DeKok [Sun, 17 Dec 2017 23:06:04 +0000 (18:06 -0500)]
more checks for NULL
Alan T. DeKok [Sun, 17 Dec 2017 22:10:37 +0000 (17:10 -0500)]
'rev' may be NULL even on success. Fixes #2143
Alan T. DeKok [Wed, 13 Dec 2017 19:52:19 +0000 (14:52 -0500)]
don't complain about "chase_referrals" if it's already set
Arran Cudbard-Bell [Fri, 15 Dec 2017 23:15:14 +0000 (23:15 +0000)]
Merge pull request #2142 from mrizvic/v3.0.x
implemented redis query and connect timeout
Marko Rizvic [Fri, 15 Dec 2017 22:05:23 +0000 (23:05 +0100)]
implemented redis query and connection timeout
Alan DeKok [Tue, 12 Dec 2017 17:44:15 +0000 (12:44 -0500)]
Merge pull request #2139 from BriceSchaffner/patch-3
Added missing attributes
Alan DeKok [Tue, 12 Dec 2017 13:52:25 +0000 (08:52 -0500)]
Merge pull request #2141 from mcnewton/v3.0.x
inner-server openssl config install
Matthew Newton [Tue, 12 Dec 2017 13:39:18 +0000 (13:39 +0000)]
bomb out immediately rather than silently fail
if we can't generate passwords.mk, we're stuffed anyway
Matthew Newton [Tue, 12 Dec 2017 13:37:56 +0000 (13:37 +0000)]
install inner-server.cnf config file
Brice Schaffner [Tue, 12 Dec 2017 06:54:46 +0000 (07:54 +0100)]
Added missing attributes
Patton-Group and Patton-Web-Privilege-Level attributes were missing. These attributes can be used in an Accept Request to specify the user group (operator, administrator or superuser) or the web privilege level of the user (wizard-exec or advanced).
Alan T. DeKok [Mon, 11 Dec 2017 15:35:28 +0000 (10:35 -0500)]
note recent changes
Alan T. DeKok [Mon, 11 Dec 2017 15:33:33 +0000 (10:33 -0500)]
added disconnect-reason
and reformatted
Alan T. DeKok [Mon, 11 Dec 2017 15:32:25 +0000 (10:32 -0500)]
add "inner-server" scripts and configuration
Matthew Newton [Mon, 11 Dec 2017 14:19:58 +0000 (14:19 +0000)]
spelling, remove spaces
Matthew Newton [Mon, 11 Dec 2017 13:46:51 +0000 (13:46 +0000)]
debian packaging fixes
- Remove disable-dhcp-by-default patch, as it's now disabled
by default since
2662182b
- Refresh quilt patches
Alan T. DeKok [Fri, 8 Dec 2017 20:51:23 +0000 (15:51 -0500)]
debian/ubuntu pkgs need dh-systemd. Fixes #2136
Arran Cudbard-Bell [Fri, 8 Dec 2017 12:17:40 +0000 (12:17 +0000)]
Don't enable dhcp by default as it has a dependency on rlm_dhcp which won't necessarily be installed
Arran Cudbard-Bell [Fri, 8 Dec 2017 12:00:49 +0000 (12:00 +0000)]
Typo
Arran Cudbard-Bell [Fri, 8 Dec 2017 11:59:00 +0000 (11:59 +0000)]
Fixup service file install
See: https://wiki.debian.org/Teams/pkg-systemd/Packaging
Alan T. DeKok [Wed, 6 Dec 2017 15:23:56 +0000 (10:23 -0500)]
document IP / network comparisons