]> git.ipfire.org Git - thirdparty/freeradius-server.git/log
thirdparty/freeradius-server.git
9 years agoUpdate ChangeLog 1281/head
Alan Buxey [Wed, 30 Sep 2015 18:41:54 +0000 (19:41 +0100)] 
Update ChangeLog

9 years agoMerge pull request #1279 from mcnewton/ch30x
Arran Cudbard-Bell [Wed, 30 Sep 2015 11:39:21 +0000 (07:39 -0400)] 
Merge pull request #1279 from mcnewton/ch30x

update recent changes

9 years agoupdate recent changes 1279/head
Matthew Newton [Wed, 30 Sep 2015 10:00:05 +0000 (11:00 +0100)] 
update recent changes

9 years agoclarify other message
Alan T. DeKok [Tue, 29 Sep 2015 15:03:37 +0000 (11:03 -0400)] 
clarify other message

9 years agoMerge pull request #1278 from mcnewton/updatehelp
Alan DeKok [Tue, 29 Sep 2015 15:02:35 +0000 (11:02 -0400)] 
Merge pull request #1278 from mcnewton/updatehelp

update help to show equivalents for some options

9 years agoupdate help to show equivalents for some options 1278/head
Matthew Newton [Tue, 29 Sep 2015 14:39:38 +0000 (15:39 +0100)] 
update help to show equivalents for some options

9 years agonote recent changes
Alan T. DeKok [Mon, 28 Sep 2015 14:39:46 +0000 (10:39 -0400)] 
note recent changes

9 years agoDon't go to next sibling on empty case. Fixes #1274
Alan T. DeKok [Mon, 28 Sep 2015 13:29:13 +0000 (09:29 -0400)] 
Don't go to next sibling on empty case.  Fixes #1274

9 years agoFix checks for EVS
Alan T. DeKok [Mon, 28 Sep 2015 12:28:56 +0000 (08:28 -0400)] 
Fix checks for EVS

9 years agoToo many spaces
Arran Cudbard-Bell [Sat, 26 Sep 2015 03:01:59 +0000 (23:01 -0400)] 
Too many spaces

9 years agoDifferent bits needed for alternation and consumed
Arran Cudbard-Bell [Sat, 26 Sep 2015 03:01:04 +0000 (23:01 -0400)] 
Different bits needed for alternation and consumed

9 years agoShow who is sending the wrong packets
Jorge Pereira [Sat, 26 Sep 2015 02:16:51 +0000 (23:16 -0300)] 
Show who is sending the wrong packets

9 years agonote recent changes
Alan T. DeKok [Fri, 25 Sep 2015 13:49:10 +0000 (09:49 -0400)] 
note recent changes

9 years agoRevert "Don't do tlv checks on 'internal' attributes". Fixes #1272
Alan T. DeKok [Fri, 25 Sep 2015 11:08:28 +0000 (07:08 -0400)] 
Revert "Don't do tlv checks on 'internal' attributes". Fixes #1272

This reverts commit e040518aa15a29d3fbb6fafb764080997a9c9a71.

9 years agoDon't do tlv checks on 'internal' attributes
Alan T. DeKok [Fri, 25 Sep 2015 01:57:05 +0000 (21:57 -0400)] 
Don't do tlv checks on 'internal' attributes

9 years agoCan't use sub-TLVs if the parent isn't a TLV
Alan T. DeKok [Fri, 25 Sep 2015 01:25:41 +0000 (21:25 -0400)] 
Can't use sub-TLVs if the parent isn't a TLV

9 years agobetter implementation of dict_parent
Alan T. DeKok [Fri, 25 Sep 2015 01:09:17 +0000 (21:09 -0400)] 
better implementation of dict_parent

9 years agoInclude session-state in rlm_perl
Herwin Weststrate [Mon, 21 Sep 2015 10:42:18 +0000 (12:42 +0200)] 
Include session-state in rlm_perl

Via the new variable %RAD_STATE.

9 years agoIncrease default query length to 2048.
Alan T. DeKok [Thu, 24 Sep 2015 14:34:58 +0000 (10:34 -0400)] 
Increase default query length to 2048.

In 3.1, this restriction should be removed entirely

9 years agoDon't print secrets for old realms. Fixes #1267
Alan T. DeKok [Thu, 24 Sep 2015 13:40:36 +0000 (09:40 -0400)] 
Don't print secrets for old realms.  Fixes #1267

9 years agoDst seems to be INADDR_ANY in some cases... Weird.
Arran Cudbard-Bell [Wed, 23 Sep 2015 20:42:00 +0000 (16:42 -0400)] 
Dst seems to be INADDR_ANY in some cases... Weird.

9 years agoCorrect precedence for determining src ip of DHCP packet
Arran Cudbard-Bell [Wed, 23 Sep 2015 20:18:59 +0000 (16:18 -0400)] 
Correct precedence for determining src ip of DHCP packet

9 years agoMore fixes for virtual attributes
Alan T. DeKok [Wed, 23 Sep 2015 18:23:04 +0000 (14:23 -0400)] 
More fixes for virtual attributes

9 years agoFix typo
Alan T. DeKok [Wed, 23 Sep 2015 17:48:41 +0000 (13:48 -0400)] 
Fix typo

9 years agoAllow checks for existence of virtual attrs. Fixes #1265
Alan T. DeKok [Wed, 23 Sep 2015 17:36:54 +0000 (13:36 -0400)] 
Allow checks for existence of virtual attrs.  Fixes #1265

9 years agochange minimum pool size to be 2K
Alan T. DeKok [Wed, 23 Sep 2015 16:18:44 +0000 (12:18 -0400)] 
change minimum pool size to be 2K

9 years agoFix crash in rlm_ldap if server goes away whilst processing profiles
Arran Cudbard-Bell [Tue, 22 Sep 2015 18:38:38 +0000 (19:38 +0100)] 
Fix crash in rlm_ldap if server goes away whilst processing profiles

9 years agoInitial stab at machine-readable copyright file
Christopher Hoskin [Mon, 21 Sep 2015 19:57:58 +0000 (20:57 +0100)] 
Initial stab at machine-readable copyright file

9 years agoCorrect minor issues with package descriptions
Christopher Hoskin [Sat, 19 Sep 2015 12:22:07 +0000 (13:22 +0100)] 
Correct minor issues with package descriptions

9 years agoUse buildflags to enable hardening (https://wiki.debian.org/Hardening)
Christopher Hoskin [Sat, 19 Sep 2015 12:19:39 +0000 (13:19 +0100)] 
Use buildflags to enable hardening (https://wiki.debian.org/Hardening)

9 years agoUpdated dh compat to 9
Christopher Hoskin [Sat, 19 Sep 2015 08:33:08 +0000 (09:33 +0100)] 
Updated dh compat to 9
Updated standards to 3.9.6
Removed duplicate entry from debian/control

9 years agoPut state name into request->component
Alan T. DeKok [Tue, 22 Sep 2015 13:01:01 +0000 (09:01 -0400)] 
Put state name into request->component

It makes the debug output a little easier to read, while still
allowing for complaint messages to show the state

9 years agoMerge pull request #1262 from jpereira/fix/better-msg1
Alan DeKok [Tue, 22 Sep 2015 12:34:18 +0000 (08:34 -0400)] 
Merge pull request #1262 from jpereira/fix/better-msg1

Show the name of virtual-server

9 years agoShow the name of virtual-server 1262/head
Jorge Pereira [Tue, 22 Sep 2015 01:08:33 +0000 (22:08 -0300)] 
Show the name of virtual-server

9 years agoMerge pull request #1259 from jpereira/fix/realm1
Arran Cudbard-Bell [Mon, 21 Sep 2015 22:25:29 +0000 (23:25 +0100)] 
Merge pull request #1259 from jpereira/fix/realm1

Fix single space in report message

9 years agoFix single space in report message 1259/head
Jorge Pereira [Mon, 21 Sep 2015 18:54:20 +0000 (15:54 -0300)] 
Fix single space in report message

9 years agoset request->module, too, when dequeuing a request
Alan T. DeKok [Mon, 21 Sep 2015 15:53:34 +0000 (11:53 -0400)] 
set request->module, too, when dequeuing a request

9 years agoSimplify final state transitions with a macro
Alan T. DeKok [Mon, 21 Sep 2015 15:50:54 +0000 (11:50 -0400)] 
Simplify final state transitions with a macro

9 years agoMerge pull request #1258 from qnet-herwin/typo_fixes
Alan DeKok [Mon, 21 Sep 2015 13:40:05 +0000 (09:40 -0400)] 
Merge pull request #1258 from qnet-herwin/typo_fixes

Typo fix: doesnot => does not

9 years agoSet request->module to the request state
Alan T. DeKok [Mon, 21 Sep 2015 13:34:40 +0000 (09:34 -0400)] 
Set request->module to the request state

9 years agoTypo fix: doesnot => does not 1258/head
Herwin Weststrate [Thu, 6 Aug 2015 08:28:48 +0000 (10:28 +0200)] 
Typo fix: doesnot => does not

9 years agoFix minor issues identified by clang-700.0.72
Arran Cudbard-Bell [Sat, 19 Sep 2015 11:39:05 +0000 (12:39 +0100)] 
Fix minor issues identified by clang-700.0.72

9 years agoMerge pull request #1255 from alanbuxey/patch-8
Arran Cudbard-Bell [Sat, 19 Sep 2015 17:13:16 +0000 (18:13 +0100)] 
Merge pull request #1255 from alanbuxey/patch-8

Update sql with example/documented SSL connection for postgresql

9 years agoUpdate sql 1255/head
Alan Buxey [Sat, 19 Sep 2015 16:02:37 +0000 (17:02 +0100)] 
Update sql

9 years agoMerge pull request #1250 from alanbuxey/patch-4
Arran Cudbard-Bell [Sat, 19 Sep 2015 12:26:53 +0000 (13:26 +0100)] 
Merge pull request #1250 from alanbuxey/patch-4

Update sql

9 years agoUpdate sql 1250/head
Alan Buxey [Sat, 19 Sep 2015 12:19:07 +0000 (13:19 +0100)] 
Update sql

9 years agoWith every new clang release, more incredibly useless warnings -Wno-reserved-id-macro
Arran Cudbard-Bell [Sat, 19 Sep 2015 11:32:21 +0000 (12:32 +0100)] 
With every new clang release, more incredibly useless warnings -Wno-reserved-id-macro

9 years agoAdd @ in front of mkdir
Alan T. DeKok [Sat, 19 Sep 2015 01:24:02 +0000 (21:24 -0400)] 
Add @ in front of mkdir

9 years agoDon't grab SIGUSR1 and SIGUSR2.
Alan T. DeKok [Fri, 18 Sep 2015 14:09:54 +0000 (10:09 -0400)] 
Don't grab SIGUSR1 and SIGUSR2.

There are now debug commands for getting talloc reports

9 years agooutlen may be zero, too
Alan T. DeKok [Fri, 18 Sep 2015 13:10:34 +0000 (09:10 -0400)] 
outlen may be zero, too

9 years agoUnify fr_prints() and fr_prints_len().
Alan T. DeKok [Fri, 18 Sep 2015 13:03:27 +0000 (09:03 -0400)] 
Unify fr_prints() and fr_prints_len().

They were different, which was a source of errors.
They are now the same, which means errors are fewer

9 years agonote recent changes
Alan T. DeKok [Fri, 18 Sep 2015 11:39:07 +0000 (07:39 -0400)] 
note recent changes

9 years agoMerge pull request #1246 from mcnewton/v3.0.x
Alan DeKok [Fri, 18 Sep 2015 11:37:59 +0000 (07:37 -0400)] 
Merge pull request #1246 from mcnewton/v3.0.x

don't segfault when asked for help

9 years agodon't segfault when asked for help 1246/head
Matthew Newton [Thu, 17 Sep 2015 23:36:41 +0000 (00:36 +0100)] 
don't segfault when asked for help

print the help for the current command if there are no subcommands
to list

9 years agoMerge pull request #1245 from jpereira/debian/logrotate1
Arran Cudbard-Bell [Thu, 17 Sep 2015 17:56:35 +0000 (18:56 +0100)] 
Merge pull request #1245 from jpereira/debian/logrotate1

Fix logrotate debian

9 years agoFix logrotate debian 1245/head
Jorge Pereira [Thu, 17 Sep 2015 17:29:45 +0000 (14:29 -0300)] 
Fix logrotate debian

9 years agoNo breaking changes in stable versions
Arran Cudbard-Bell [Thu, 17 Sep 2015 16:51:11 +0000 (17:51 +0100)] 
No breaking changes in stable versions

9 years agoRevert "if try to load a wrong client from SQL, don't start"
Arran Cudbard-Bell [Thu, 17 Sep 2015 16:50:02 +0000 (17:50 +0100)] 
Revert "if try to load a wrong client from SQL, don't start"

This is wrong, we don't introduce behaviour changes that will break people's deployments in stable versions of the server

9 years agoRevert "logrotate: send a HUP after rotation"
Arran Cudbard-Bell [Thu, 17 Sep 2015 16:49:22 +0000 (17:49 +0100)] 
Revert "logrotate: send a HUP after rotation"

This is wrong, copyrotate is the correct command to use

9 years agonote recent changes
Alan T. DeKok [Thu, 17 Sep 2015 15:02:50 +0000 (11:02 -0400)] 
note recent changes

9 years agoMerge pull request #1243 from jpereira/bug/debian-logrotate
Alan DeKok [Thu, 17 Sep 2015 15:02:35 +0000 (11:02 -0400)] 
Merge pull request #1243 from jpereira/bug/debian-logrotate

debian: Fixing logrotate script

9 years agodebian: Fixing logrotate script 1243/head
Jorge Pereira [Thu, 17 Sep 2015 14:27:21 +0000 (11:27 -0300)] 
debian: Fixing logrotate script

9 years agologrotate: send a HUP after rotation
Jorge Pereira [Thu, 17 Sep 2015 14:19:59 +0000 (11:19 -0300)] 
logrotate: send a HUP after rotation

9 years agoMore RFCs
Alan T. DeKok [Thu, 17 Sep 2015 14:17:01 +0000 (10:17 -0400)] 
More RFCs

9 years agoMerge pull request #1242 from jpereira/fix/wrong-client-sql
Alan DeKok [Thu, 17 Sep 2015 13:09:07 +0000 (09:09 -0400)] 
Merge pull request #1242 from jpereira/fix/wrong-client-sql

if has a wrong client-settings, don't rise!

9 years agoif try to load a wrong client from SQL, don't start 1242/head
Jorge Pereira [Thu, 17 Sep 2015 12:45:47 +0000 (09:45 -0300)] 
if try to load a wrong client from SQL, don't start

9 years agoAccidentally committed
Alan T. DeKok [Wed, 16 Sep 2015 19:17:34 +0000 (15:17 -0400)] 
Accidentally committed

9 years agonote recent changes
Alan T. DeKok [Wed, 16 Sep 2015 18:09:09 +0000 (14:09 -0400)] 
note recent changes

9 years agoMerge pull request #1241 from jpereira/fix/xlat-space
Alan DeKok [Wed, 16 Sep 2015 18:36:14 +0000 (14:36 -0400)] 
Merge pull request #1241 from jpereira/fix/xlat-space

xlat_explode: trim white space

9 years agoxlat_explode: trim white space 1241/head
Jorge Pereira [Wed, 16 Sep 2015 18:06:48 +0000 (15:06 -0300)] 
xlat_explode: trim white space

9 years agonote recent changes
Alan T. DeKok [Wed, 16 Sep 2015 17:15:40 +0000 (13:15 -0400)] 
note recent changes

9 years agoAllow virtual attrs in switch. Fixes #1240
Alan T. DeKok [Wed, 16 Sep 2015 17:15:00 +0000 (13:15 -0400)] 
Allow virtual attrs in switch.  Fixes #1240

9 years agoForgot a return...
Alan T. DeKok [Wed, 16 Sep 2015 17:07:09 +0000 (13:07 -0400)] 
Forgot a return...

9 years agoBe a bit more careful about thread transitions
Alan T. DeKok [Wed, 16 Sep 2015 16:47:37 +0000 (12:47 -0400)] 
Be a bit more careful about thread transitions

9 years agonote recent changes
Alan T. DeKok [Wed, 16 Sep 2015 00:58:46 +0000 (20:58 -0400)] 
note recent changes

9 years agoProxying to a bad destination is a failure.
Alan T. DeKok [Wed, 16 Sep 2015 00:54:38 +0000 (20:54 -0400)] 
Proxying to a bad destination is a failure.

9 years agoMissed slash
Arran Cudbard-Bell [Tue, 15 Sep 2015 21:04:26 +0000 (22:04 +0100)] 
Missed slash

9 years agoRemove extraneous debug
Alan T. DeKok [Tue, 15 Sep 2015 16:01:17 +0000 (12:01 -0400)] 
Remove extraneous debug

9 years agoPackage memcached
Arran Cudbard-Bell [Tue, 15 Sep 2015 14:06:43 +0000 (15:06 +0100)] 
Package memcached

9 years agoRevert "Include rlm_cache_memcached in spec file"
Arran Cudbard-Bell [Tue, 15 Sep 2015 13:53:52 +0000 (14:53 +0100)] 
Revert "Include rlm_cache_memcached in spec file"

libmemcached on Centos is too old for this to work

9 years agoDocument and fix args
Arran Cudbard-Bell [Tue, 15 Sep 2015 13:43:56 +0000 (14:43 +0100)] 
Document and fix args

9 years agoAllow dots in policy / module names. Fixes #1237
Alan T. DeKok [Tue, 15 Sep 2015 13:22:38 +0000 (09:22 -0400)] 
Allow dots in policy / module names.  Fixes #1237

9 years agoLower the default pool size
Alan T. DeKok [Tue, 15 Sep 2015 13:09:37 +0000 (09:09 -0400)] 
Lower the default pool size

9 years agoInclude rlm_cache_memcached in spec file
Arran Cudbard-Bell [Mon, 14 Sep 2015 20:32:52 +0000 (21:32 +0100)] 
Include rlm_cache_memcached in spec file

9 years agoMerge pull request #1235 from FreeRADIUS/revert-1204-patch-1
Arran Cudbard-Bell [Mon, 14 Sep 2015 20:29:50 +0000 (21:29 +0100)] 
Merge pull request #1235 from FreeRADIUS/revert-1204-patch-1

Revert "Fix libs" - Only memcached will actually be built

9 years agoRevert "Fix libs" 1235/head
Arran Cudbard-Bell [Mon, 14 Sep 2015 20:29:20 +0000 (21:29 +0100)] 
Revert "Fix libs"

9 years agoThis was never backported
Arran Cudbard-Bell [Mon, 14 Sep 2015 17:27:36 +0000 (18:27 +0100)] 
This was never backported

9 years agoUpdate ChangeLog
Arran Cudbard-Bell [Mon, 14 Sep 2015 17:20:03 +0000 (18:20 +0100)] 
Update ChangeLog

9 years agoNo ocsp_ok label either
Arran Cudbard-Bell [Mon, 14 Sep 2015 16:22:56 +0000 (17:22 +0100)] 
No ocsp_ok label either

9 years agoNo skipped label in v3.0.x
Arran Cudbard-Bell [Mon, 14 Sep 2015 16:21:21 +0000 (17:21 +0100)] 
No skipped label in v3.0.x

9 years agoTry to open client socket in fr_server_domain_socket_perm()
Alan T. DeKok [Mon, 14 Sep 2015 16:02:37 +0000 (12:02 -0400)] 
Try to open client socket in fr_server_domain_socket_perm()

Just like in fr_server_domain_socket_peercred()

9 years agoShould skip the OCSP check
Arran Cudbard-Bell [Mon, 14 Sep 2015 16:18:02 +0000 (17:18 +0100)] 
Should skip the OCSP check

9 years agoTypo
Arran Cudbard-Bell [Mon, 14 Sep 2015 16:13:41 +0000 (17:13 +0100)] 
Typo

9 years agoDon't unlink socket if we can't open it
Alan T. DeKok [Mon, 14 Sep 2015 15:48:10 +0000 (11:48 -0400)] 
Don't unlink socket if we can't open it

9 years agoTruncate to actual length, not by trailing zeros
Alan T. DeKok [Mon, 14 Sep 2015 14:48:08 +0000 (10:48 -0400)] 
Truncate to actual length, not by trailing zeros

9 years agoIf there's no OCSP URLs in the certificates, and we have a configured OCSP URL, we...
Arran Cudbard-Bell [Sun, 13 Sep 2015 17:43:23 +0000 (18:43 +0100)] 
If there's no OCSP URLs in the certificates, and we have a configured OCSP URL, we should fall back to that URL

9 years agoFor encrypted attributes, set explicit length if given
Alan T. DeKok [Mon, 14 Sep 2015 12:51:09 +0000 (08:51 -0400)] 
For encrypted attributes, set explicit length if given

for MS-CHAP-MPPE-Keys

9 years agoSet explicit length for MS-CHAP-MPPE-Key
Alan T. DeKok [Mon, 14 Sep 2015 12:50:00 +0000 (08:50 -0400)] 
Set explicit length for MS-CHAP-MPPE-Key

Because it's encrypted with the same method as User-Password,
BUT it contains binary data.  So it may have embedded zeros.
Which means the decoder needs to make it a fixed length,
instead of looking for zeros

9 years agoEnforce more restraints, and allow "octets[24] encrypt=1"
Alan T. DeKok [Mon, 14 Sep 2015 12:47:56 +0000 (08:47 -0400)] 
Enforce more restraints, and allow "octets[24] encrypt=1"

dict_addattr() can be called from places other than process_attribute()
so we move some of the checks to process_attribute()

This lets us do more checks on the "length" flag.

And to allow "octets[24] encrypt=1" for MS-CHAP-MPPE-Key.

9 years agoThe MS-CHAP-MPPE-Keys attribute has 24 octets of data, not 32
Alan T. DeKok [Mon, 14 Sep 2015 12:21:40 +0000 (08:21 -0400)] 
The MS-CHAP-MPPE-Keys attribute has 24 octets of data, not 32

This makes no difference to anyone, as the receiver will always
truncate it at 24 octets, and ignore the trailing zeros