]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
Arran Cudbard-Bell [Mon, 10 Oct 2011 19:39:02 +0000 (21:39 +0200)]
Add additional logging to connection pool api
Arran Cudbard-Bell [Tue, 11 Oct 2011 11:55:34 +0000 (13:55 +0200)]
Set last_used on spawn, else all connections are closed on the first get_connection call
Add counter, and give each connection a unique connection id
Arran Cudbard-Bell [Mon, 10 Oct 2011 22:17:37 +0000 (00:17 +0200)]
Need to check if the max_uses/lifetime/idle_timeout values > 0 (enabled) before enforcing them...
Alan T. DeKok [Mon, 10 Oct 2011 18:16:01 +0000 (20:16 +0200)]
Fixes to make FR use the local libltld
This helps to avoid stupid libtool issues
Alan T. DeKok [Mon, 10 Oct 2011 15:37:18 +0000 (17:37 +0200)]
More information in debug messages
Alan T. DeKok [Sun, 9 Oct 2011 16:15:00 +0000 (18:15 +0200)]
Use parent rather than cs if cs doesn't exist
Alan T. DeKok [Sun, 9 Oct 2011 11:59:34 +0000 (13:59 +0200)]
TLS private key password isn't required
Alan T. DeKok [Sat, 8 Oct 2011 07:15:01 +0000 (09:15 +0200)]
Clean up build to be less verbose
Rather than printing out 10+ lines of text for every C file that
is compiled, it now prints out one: "CC foo.c"
While this can hide some key information from the developer, it
also highlights compiler warnings.
We can later go through and add a developer-specific option
to turn on the old behavior. Probably by suppressing the "--quiet"
option to libtool
Alan T. DeKok [Fri, 7 Oct 2011 22:14:02 +0000 (00:14 +0200)]
Fix typo
compare type to RAD_LISTEN_DETAIL
Arran Cudbard-Bell [Fri, 7 Oct 2011 09:45:12 +0000 (11:45 +0200)]
Add a Message-Authenticator attribute to the response, if we added EAP-Message
Alan T. DeKok [Tue, 4 Oct 2011 14:20:42 +0000 (16:20 +0200)]
Added simple module to "clean" the request of non-UTF-8 data
Arran Cudbard-Bell [Mon, 3 Oct 2011 11:34:50 +0000 (04:34 -0700)]
Merge pull request #21 from alagoutte/master
Update RADIUS Dictionary Aruba
Alexis La Goutte [Mon, 3 Oct 2011 11:22:00 +0000 (13:22 +0200)]
Update RADIUS Dictionary Aruba
Peter Lemenkov [Fri, 30 Sep 2011 11:48:58 +0000 (15:48 +0400)]
Drop dead link
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
Peter Lemenkov [Fri, 30 Sep 2011 11:48:10 +0000 (15:48 +0400)]
Now it's possible to include Zyxel's dictionary by default
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
Peter Lemenkov [Fri, 30 Sep 2011 11:44:29 +0000 (15:44 +0400)]
Another one attribute
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
Peter Lemenkov [Fri, 30 Sep 2011 11:44:02 +0000 (15:44 +0400)]
Proper VENDOR value for Zyxel
Signed-off-by: Peter Lemenkov <lemenkov@gmail.com>
Alan T. DeKok [Fri, 30 Sep 2011 11:22:23 +0000 (13:22 +0200)]
ECONNRESET and EWOULDBLOCK aren't portable
Wrap them in ifdef's
Alan T. DeKok [Thu, 29 Sep 2011 16:03:23 +0000 (18:03 +0200)]
Load "server {...}" sections properly
Alan T. DeKok [Thu, 29 Sep 2011 09:26:03 +0000 (11:26 +0200)]
Be more graceful if caller passes us a NULL ptr
Alan T. DeKok [Wed, 28 Sep 2011 11:15:46 +0000 (13:15 +0200)]
Distinguish virtual servers from physical ones
Alan T. DeKok [Wed, 28 Sep 2011 11:15:31 +0000 (13:15 +0200)]
Updated debug message
Arran Cudbard-Bell [Mon, 26 Sep 2011 20:01:04 +0000 (22:01 +0200)]
Add EAP-Failure if EAP is called in Post-Auth REJECT and no EAP-Message has been inserted
Alan T. DeKok [Fri, 23 Sep 2011 07:45:55 +0000 (09:45 +0200)]
Fix typo (arg)
Alan T. DeKok [Fri, 23 Sep 2011 07:32:59 +0000 (09:32 +0200)]
More checks for -C, to not open sockets
Alan T. DeKok [Thu, 22 Sep 2011 16:43:11 +0000 (18:43 +0200)]
Don't really open sockets if we're doing -C
Alan T. DeKok [Thu, 22 Sep 2011 13:53:51 +0000 (15:53 +0200)]
Acct-Session-Id from Cisco exceeds 64 bytes. Extend it.
Add radpostauth/radhuntgroup tables to the oracle schema
Alan T. DeKok [Thu, 22 Sep 2011 13:53:13 +0000 (15:53 +0200)]
Added missing post-auth configuration
John Dennis [Tue, 20 Sep 2011 21:56:22 +0000 (17:56 -0400)]
Always send Message-Authenticator in radtest
Originally Message-Authenticator was introduced to provide message
integrity for EAP messages and originally the Message-Authenticator
attribute was only required for EAP messages.
But then RFC 5080 came along and suggested Message-Authenticator
always be sent as best practice.
Any Access-Request packet that performs authorization checks,
including Call Check, SHOULD contain a Message-Authenticator
attribute.
RFC 5080 then goes on to say:
... server implementations may be configured to require the
presence of a Message-Authenticator attribute in Access-Request
packets. Requests not containing a Message-Authenticator attribute
MAY then be silently discarded.
The raddb/clients.conf has this configuration option to satisfy the
above suggestion in RFC 5080:
require_message_authenticator = no|yes
If require_message_authenticator == yes then non-EAP auth-requests
generated by radtest will fail because currently radtest only supplies
the Message-Authenticator if EAP is being performed. With modern
Radius servers (e.g. FreeRADIUS) there is no harm in providing the
Message-Authenticator attribute for non-EAP packets, in fact it's
actually recommended in RFC 5080.
Therefore radtest should ALWAYS send the Message-Authenticator
attribute. If it's EAP or if the server is configured with
require_message_authenticator it must be present. If those conditions
do not hold it's benign. However if require_message_authenticator is
configured radtest will fail for non-EAP.
Alan T. DeKok [Tue, 20 Sep 2011 17:56:02 +0000 (19:56 +0200)]
As posted to the list
Alan T. DeKok [Tue, 20 Sep 2011 08:31:05 +0000 (10:31 +0200)]
Ensure src_ipaddr is initialized when finding a home server
Fix left over from
12d87590f7b03f315f14d9b905ed550ddceccf7c
Alan T. DeKok [Tue, 20 Sep 2011 07:25:51 +0000 (09:25 +0200)]
Fixed typo
Alan T. DeKok [Mon, 19 Sep 2011 17:45:35 +0000 (19:45 +0200)]
Add missing "man" files
Alan DeKok [Mon, 19 Sep 2011 12:08:57 +0000 (05:08 -0700)]
Merge pull request #18 from bmork/radsniff-decode
radsniff: decoding encrypted attributes
Dmitry Borodaenko [Sat, 6 Aug 2011 17:15:59 +0000 (20:15 +0300)]
Fix rlm_sql noop for accounting start
When
6ed9727 was merged, else{} in the START case got placed against the
wrong if(). Unlike STOP and ALIVE cases, in START insert comes first,
and we only care if that affects 0 rows. If insert fails and we have to
go for an update, we don't have to check for NOOP because we can assume
the insert failed due to a conflicting row already in the database.
Alan T. DeKok [Sun, 18 Sep 2011 11:23:35 +0000 (13:23 +0200)]
Revert "Remove values for Auth-Type, these values were only defined for legacy reasons"
This reverts commit
296fcf9576394de5bf943e257a8d64751feaf636 .
Removing Auth-Type = {Accept, Reject, MS-CHAP} breaks the server
John Dennis [Sun, 18 Sep 2011 07:17:45 +0000 (09:17 +0200)]
Document all command line args & add missing man pages
Go through every installed command and verify:
* There exists a man page for the command, if not create one
* For every command line arg in each command:
- Assure the arg appears in the synopis section of the man page
- Assure the arg is documented in the options section of the man page
- Assure the arg is documented in the "usage" emitted by the command
In addition to the above this patch also does:
* Clean up captitalization & the use of terminating periods.
* Removed superfluous unused l option from the getopt format string
of radwho
* Remove rlm_ippool_tool.pod, superseded by rlm_ippool_tool.8 man page
The follow new man pages were added:
man/man1/smbencrypt.1
man/man5/checkrad.5
man/man8/radconf2xml.8
man/man8/radcrypt.8
man/man8/radsniff.8
src/modules/rlm_dbm/rlm_dbm_cat.8
src/modules/rlm_dbm//rlm_dbm_parse.8
src/modules/rlm_ippool/rlm_ippool_tool.8
Arran Cudbard-Bell [Sun, 18 Sep 2011 05:50:29 +0000 (13:50 +0800)]
Use our instead of the old vars pragma, and turn on warnings
Bjørn Mork [Fri, 16 Sep 2011 17:50:07 +0000 (19:50 +0200)]
radsniff: decoding encrypted attributes
Save authentication requests and use them to properly decode
entrypted attributes in matching replies.
Also decode encrypted attributes in CoA requests. Some VSAs
can be encrypted in CoA requests using a null vector.
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Alan T. DeKok [Wed, 14 Sep 2011 10:11:07 +0000 (12:11 +0200)]
Note which Auth-Type we're creating
Alan T. DeKok [Wed, 14 Sep 2011 15:33:46 +0000 (17:33 +0200)]
Made more coherent
Alan T. DeKok [Wed, 14 Sep 2011 09:57:04 +0000 (11:57 +0200)]
Make warning message more coherent
Alan T. DeKok [Wed, 14 Sep 2011 09:56:24 +0000 (11:56 +0200)]
WARNING on potential proxy loop
Alan T. DeKok [Mon, 12 Sep 2011 21:41:23 +0000 (23:41 +0200)]
Fixed long-standing typos
I guess no one ever used this...
Arran Cudbard-Bell [Mon, 12 Sep 2011 14:04:28 +0000 (16:04 +0200)]
Remove values for Auth-Type, these values were only defined for legacy reasons
Alan T. DeKok [Sat, 10 Sep 2011 18:32:08 +0000 (20:32 +0200)]
Fixed typo in huntgroup name addition
Alan T. DeKok [Sat, 10 Sep 2011 18:12:01 +0000 (20:12 +0200)]
Document max_queue_size
Alan T. DeKok [Sat, 10 Sep 2011 18:27:58 +0000 (20:27 +0200)]
Twigged blocked messages && logic
Alan T. DeKok [Sat, 10 Sep 2011 17:33:37 +0000 (19:33 +0200)]
No one uses this
Alan T. DeKok [Wed, 7 Sep 2011 15:34:49 +0000 (17:34 +0200)]
Fixed typo
Alan T. DeKok [Wed, 7 Sep 2011 10:59:21 +0000 (12:59 +0200)]
Document keepalive
Alan T. DeKok [Mon, 5 Sep 2011 15:39:53 +0000 (11:39 -0400)]
Updated copyright year
Alan T. DeKok [Wed, 7 Sep 2011 09:31:09 +0000 (11:31 +0200)]
NULL out fields after they've been free'd
Alan T. DeKok [Mon, 5 Sep 2011 14:05:21 +0000 (10:05 -0400)]
Complain if password is !UTF-8
for the "shared secret is incorrect" check. The old code
checked for "printable" characters. Changing it to a check for
!UTF-8 is more general, and likely more robust with fewer false
positives
Alan T. DeKok [Sat, 3 Sep 2011 13:49:09 +0000 (09:49 -0400)]
Ignore more files
Alan T. DeKok [Sat, 3 Sep 2011 13:01:21 +0000 (09:01 -0400)]
Allow entry if UID or GID match
Alan T. DeKok [Fri, 2 Sep 2011 21:38:00 +0000 (17:38 -0400)]
Added %{rand:...} to generate uniformly distributed random numbers
Alan T. DeKok [Fri, 2 Sep 2011 03:48:22 +0000 (23:48 -0400)]
Added "integer64" for 64-bit integer VSAs
Alan T. DeKok [Thu, 1 Sep 2011 12:13:41 +0000 (08:13 -0400)]
Fix strict aliasing complaint
Arran Cudbard-Bell [Wed, 31 Aug 2011 16:17:26 +0000 (18:17 +0200)]
Add support for NAS implementing standard IEEE802.1X mib (Tested against ProCurve 3500)
Fix regular expressions to work with recent versions of snmp_get (should still be backwards compatible)
Alan T. DeKok [Mon, 29 Aug 2011 14:18:46 +0000 (10:18 -0400)]
Pings don't have request->packet, and are never CoA or Disconnect
Alan T. DeKok [Mon, 29 Aug 2011 14:03:11 +0000 (10:03 -0400)]
Note policy for filtering user names
Alan T. DeKok [Sun, 28 Aug 2011 15:01:50 +0000 (11:01 -0400)]
Enable possibility for ecdh by default
Alan T. DeKok [Sun, 28 Aug 2011 20:08:25 +0000 (16:08 -0400)]
Enable elliptical curve cryptography
Manual commit of
1bca962
Alan T. DeKok [Fri, 26 Aug 2011 11:09:05 +0000 (07:09 -0400)]
More/better documentation
Alan T. DeKok [Tue, 23 Aug 2011 12:58:17 +0000 (08:58 -0400)]
Ignore more files
Alan T. DeKok [Tue, 23 Aug 2011 12:53:20 +0000 (08:53 -0400)]
Spelling corrections
Alan T. DeKok [Tue, 23 Aug 2011 12:50:36 +0000 (08:50 -0400)]
Fix for libfreeradius3
Alan T. DeKok [Tue, 23 Aug 2011 12:45:52 +0000 (08:45 -0400)]
Use 3.0 API
Alan T. DeKok [Sat, 20 Aug 2011 13:34:46 +0000 (09:34 -0400)]
Status-Server isn't enabled for TLS yet
Arran Cudbard-Bell [Wed, 24 Aug 2011 11:21:39 +0000 (04:21 -0700)]
Merge pull request #17 from bmork/del-client-fix2
radmin: fixup error message when attemting to delete non-dynamic client
Bjørn Mork [Wed, 24 Aug 2011 10:33:13 +0000 (12:33 +0200)]
radmin: fixup error message when attemting to delete non-dynamic client
commit
b9e5dd2c changed the command syntax in line with docs, but failed
to update the error message accordingly.
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Arran Cudbard-Bell [Tue, 23 Aug 2011 09:18:44 +0000 (02:18 -0700)]
Merge pull request #16 from bmork/del-client-fix
radmin: make "del client ipaddr" command behave as documented
Bjørn Mork [Tue, 23 Aug 2011 09:07:39 +0000 (11:07 +0200)]
radmin: make "del client ipaddr" command behave as documented
Fixes this error:
radmin> del client ipaddr 192.168.168.111
ERROR: Must specify <ipaddr>
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Alan T. DeKok [Sat, 20 Aug 2011 01:08:41 +0000 (21:08 -0400)]
Use confdir instead of raddbdir
Alan T. DeKok [Thu, 18 Aug 2011 01:23:50 +0000 (21:23 -0400)]
Add mkdir, based on patch from Oliver Schroder
This lets the module put logs into automagically created subdirs
Alan T. DeKok [Tue, 16 Aug 2011 12:14:46 +0000 (08:14 -0400)]
Add support for "signed", just like integer64
Arran Cudbard-Bell [Fri, 19 Aug 2011 14:58:01 +0000 (16:58 +0200)]
Should use 8th capture group for Called-Station-ID rewrite
Alan T. DeKok [Tue, 16 Aug 2011 00:36:00 +0000 (20:36 -0400)]
More log message clenups
Alan T. DeKok [Tue, 16 Aug 2011 00:24:04 +0000 (20:24 -0400)]
Use more radlog_request() for proxy messages
Alan T. DeKok [Tue, 16 Aug 2011 00:16:00 +0000 (20:16 -0400)]
Fix compiler warnings
Alan T. DeKok [Mon, 15 Aug 2011 13:20:45 +0000 (09:20 -0400)]
Catch sub-realms && example.net, too
Alan T. DeKok [Mon, 15 Aug 2011 13:01:54 +0000 (09:01 -0400)]
Clean up debug message
Alan T. DeKok [Mon, 15 Aug 2011 12:57:55 +0000 (08:57 -0400)]
Pull integer64 fixes over from dictionary.starent
Alan T. DeKok [Sat, 13 Aug 2011 14:56:28 +0000 (10:56 -0400)]
Allow empty strings to mean NULL
this lets us specify the default (i.e. NULL) virtual server
Alan T. DeKok [Fri, 12 Aug 2011 14:34:52 +0000 (10:34 -0400)]
3.0 supports "integer64" data types
Alan T. DeKok [Fri, 12 Aug 2011 14:25:47 +0000 (10:25 -0400)]
Add conflicting starent dictionary from bug #159
Alan T. DeKok [Fri, 12 Aug 2011 14:20:03 +0000 (10:20 -0400)]
Updated with edits from bug #159
Alan T. DeKok [Fri, 12 Aug 2011 11:51:00 +0000 (07:51 -0400)]
Added siemens dictionary
Alan T. DeKok [Fri, 12 Aug 2011 14:32:55 +0000 (10:32 -0400)]
Note integer64 data type
Alan T. DeKok [Wed, 10 Aug 2011 14:47:33 +0000 (10:47 -0400)]
Add support for encoding/decode 64-bit integers inside of TTLS
Alan T. DeKok [Tue, 9 Aug 2011 14:20:45 +0000 (10:20 -0400)]
Allow integer64 in filtering "update" lists
Alan T. DeKok [Tue, 9 Aug 2011 14:15:58 +0000 (10:15 -0400)]
Add integer64 to xlat
Alan T. DeKok [Tue, 9 Aug 2011 14:06:53 +0000 (10:06 -0400)]
Allow comparisons for integer64 data type
Alan T. DeKok [Tue, 9 Aug 2011 13:36:50 +0000 (09:36 -0400)]
Initial support for integer64 data type
Can print/parse encode/decode them, and read them from dictionaries
The rest of the code (unlang, eval, etc) needs to be audited to
support the new data type
Alan T. DeKok [Mon, 8 Aug 2011 14:00:50 +0000 (10:00 -0400)]
Added FreeDHCP dictionary
Alan T. DeKok [Mon, 8 Aug 2011 03:24:55 +0000 (23:24 -0400)]
Removed DOS line endings
Arran Cudbard-Bell [Tue, 2 Aug 2011 11:33:08 +0000 (04:33 -0700)]
Merge pull request #13 from bmork/dictionary-updates
Adding new attributes to the ERX dictionary
Bjørn Mork [Mon, 1 Aug 2011 08:57:55 +0000 (10:57 +0200)]
Adding new attributes to the ERX dictionary
This should make it compatible with JUNOSe version 12.1.1
and JUNOS version 11.2.
Signed-off-by: Bjørn Mork <bjorn@mork.no>
Alan T. DeKok [Fri, 29 Jul 2011 12:05:56 +0000 (08:05 -0400)]
Do record_minus to reset buffer, instead of just memcpy