1
0
Commit Graph

204 Commits

Author SHA256 Message Date
d2bfda64eb Revert last commit
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=127
2019-08-07 13:54:17 +00:00
eb5e37fca6 Add more CVE references to last version update
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=126
2019-08-07 12:15:53 +00:00
Dominique Leuenberger
bd91892569 Accepting request 707189 from network
backport missing change from SLE

- install license as %license instead of documentation

OBS-URL: https://build.opensuse.org/request/show/707189
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=78
2019-06-03 16:58:17 +00:00
b207fee127 Backport from SLE license install changes
- install license as %license instead of documentation

OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=124
2019-06-03 14:00:53 +00:00
Dominique Leuenberger
f8246434f2 Accepting request 705679 from network
Only reference updates. No changes.

OBS-URL: https://build.opensuse.org/request/show/705679
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=77
2019-05-28 07:43:13 +00:00
6b234e6773 CVE was already fixed long ago and we didn't notice
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=122
2019-05-27 13:22:14 +00:00
838fd1d444 Use correct jira entry
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=121
2019-05-27 12:41:10 +00:00
9599255642 - update to 3.0.19 (jira#SLE-5107)
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=120
2019-05-27 12:40:05 +00:00
c1ac5290fe - CVE-2019-10143.patch: fix potential privilege escalation due to
insecure logrotation permissions (bsc#1136195, CVE-2019-10143)

OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=119
2019-05-27 12:33:30 +00:00
1593aaad80 Adding another bug reference from upstream update
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=118
2019-04-16 16:26:01 +00:00
635cb7e662 Add bug numbers to .changes file
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=117
2019-04-16 11:39:10 +00:00
Dominique Leuenberger
6f93da4522 Accepting request 693123 from network
OBS-URL: https://build.opensuse.org/request/show/693123
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=76
2019-04-11 10:20:16 +00:00
2a9164d43c Accepting request 693007 from home:stroeder:branches:network
update to 3.0.19

OBS-URL: https://build.opensuse.org/request/show/693007
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=115
2019-04-11 07:51:12 +00:00
Stephan Kulow
12914b2ccb Accepting request 679792 from network
- reformat changelog mostly by wrapping lines
- add missing bug numbers for security fixes

- update to 3.0.18
* cleanup_delay can now be 30 seconds. This helps with proxies that have packet loss.
* Do-Not-Respond policies can now be set in the "post-auth" section.
* Encode / Decode ADSL Forum DHCP options.
* Fix module ordering issues. e.g. when "sqlippool" needs "sql".
  See the "instantiate" section of radiusd.conf.
* Add Big Switch dictionary. Fixes #2252.
* Add sql_session_start policy (raddb/policy.d/accounting)
  This minimizes race conditions when using Simultaneous-Use (#2257).
* For rlm_perl, all variables are now tainted by default.
  See raddb/mods-available/perl, and the "perl_flags" configuration item.
  This change should only affect people who are using variables in
  insecure ways.
* Allow "sqlcounter" module to be listed in "post-auth".
* Add support for IPv6 attributes in SQL. Fixes #2280
* The server is better at handling fail-over for outbound RadSec and
  TCP connections. Fixes #2284.
* The server is now more aggressive about retrying failed outbound
  RadSec and TCP connections. Fixes #2284.
* Add TLS-Session-Version and TLS-Session-Cipher-Suite to the "session_state" list.
* Add expansion for Radsec connections. "%{listen:TLS-...}" for
  TLS-Client-Cert-* and TLS-Cert-* attributes.
* Add notes on running "ldapsearch" using the parameters from the LDAP module.
* "ipaddr" attributes can now be cast to "integer" type attributes
  in an "update" section.
* Move main thread queue to using atomic queues. This should help
  with contention in high load scenarios.

OBS-URL: https://build.opensuse.org/request/show/679792
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=75
2019-02-28 20:43:53 +00:00
ff04302a52 - reformat changelog mostly by wrapping lines
- add missing bug numbers for security fixes

OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=113
2019-02-27 11:50:42 +00:00
35096a5f1d Accepting request 679659 from home:stroeder:branches:network
update to 3.0.18

OBS-URL: https://build.opensuse.org/request/show/679659
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=112
2019-02-27 11:28:47 +00:00
Dominique Leuenberger
8e4bb705b1 Accepting request 619197 from network
OBS-URL: https://build.opensuse.org/request/show/619197
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=74
2018-06-27 08:22:42 +00:00
Michael Ströder
7a23e70bb4 Accepting request 619196 from home:stroeder:branches:network
- also fix ownership of /var/log/radius in systemd unit

OBS-URL: https://build.opensuse.org/request/show/619196
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=110
2018-06-26 18:25:55 +00:00
Dominique Leuenberger
f480aff111 Accepting request 597709 from network
OBS-URL: https://build.opensuse.org/request/show/597709
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=73
2018-04-20 15:29:23 +00:00
Michael Ströder
16eca59475 Accepting request 597707 from home:stroeder:branches:network
update to 3.0.17

OBS-URL: https://build.opensuse.org/request/show/597707
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=108
2018-04-18 08:37:20 +00:00
Dominique Leuenberger
516e10916c Accepting request 564437 from network
OBS-URL: https://build.opensuse.org/request/show/564437
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=72
2018-01-22 15:17:13 +00:00
OBS User mrdocs
f4f7f11d57 Accepting request 563800 from home:stroeder:branches:network
update to 3.0.16

OBS-URL: https://build.opensuse.org/request/show/563800
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=106
2018-01-15 00:19:02 +00:00
Dominique Leuenberger
840bbbea92 Accepting request 527291 from network
- Fix permissions of radiusd.service (bnc#1053654)

OBS-URL: https://build.opensuse.org/request/show/527291
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=71
2017-09-20 15:12:10 +00:00
b0d20bd6c1 - Fix permissions of radiusd.service (bnc#1053654):
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=104
2017-09-19 11:58:57 +00:00
Dominique Leuenberger
58b7d01fb6 Accepting request 518837 from network
1

OBS-URL: https://build.opensuse.org/request/show/518837
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=70
2017-08-28 13:17:19 +00:00
OBS User mrdocs
dd94d16c92 Accepting request 518718 from home:varkoly:branches:network
- bsc#1055679 - freeradius-server does not provide winbind/AD auth
  Added libwbclient-devel as buildrequires

OBS-URL: https://build.opensuse.org/request/show/518718
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=102
2017-08-26 03:12:02 +00:00
Dominique Leuenberger
de3b2ecdb1 Accepting request 511084 from network
1

OBS-URL: https://build.opensuse.org/request/show/511084
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=69
2017-07-19 09:22:21 +00:00
bbd77fa15f Accepting request 511049 from home:stroeder:branches:network
update to 3.0.15 - now with CVE ids

successfully tested on Tumbleweed x86_64

OBS-URL: https://build.opensuse.org/request/show/511049
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=100
2017-07-18 08:02:28 +00:00
Dominique Leuenberger
0fa9cf1c51 Accepting request 499629 from network
1

OBS-URL: https://build.opensuse.org/request/show/499629
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=68
2017-05-31 10:19:49 +00:00
44d1db1d6e Accepting request 499628 from home:adamm:branches:network
- update to 3.0.14 (still FATE#322416)
  
  Feature improvements
  * Enforce TLS client certificate expiration on session resumption,
    and Session-Timeout. See CVE-2017-9148 (bnc#1041445)
  * Updated dictionary.cisco.vpn3000, dictionary.patton
  * Added dictionary.dellemc
  * Lowered the log output for failed PEAP sessions.
  * ALlow utc in rlm_date.
  * The internal OpenSSL session cache has been disabled.
    Please see mods-available/eap
  * Update detail reader documentation.
  * Make outgoing RadSec connections non-blocking.
  * Add SQL backing to Moonshot-*-TargetedId generation.
  Bug Fixes
  * radtest uses Cleartext-Password for EAP, not User-Password.
  * Update documentation for mods-enabled/ linking.
  * Enhanced checks for moonshot salt.
  * Allow session resumption for RadSec connections.
  * Update "huntgroups" file to note that port ranges are not supported
  * Fix OpenSSL permissions issues on default key files.
  * Certificates are not required when PSK is used.
  * Allow SubjectAltName as first extension in cert.
  * Fixed talloc issue with TLS session resumption.
  * "&Attr-26 := 0x01" now produces useful error messages.
  * Handle connection error in rlm_ldap_cacheable_groupobj.
  * Fix endian issues in DHCP.
  * Multiple minor fixes for Coverity complaints.
  * Handle unexpected regex.
  * Fix minor issues in dictionaries.
  * Fix typos and grammar. Patches from Alan Buxey.
  * Fix erroneous VP creation in rlm_preproces.
  * Fix MIB. Patch from Jeff Gehlbach.
  * Trust router updates from Alejandro Perez.
  * Allow build with LibreSSL.
  * Use correct packet for channel bindings.
  * Many fixes found by PVS-Studio. Thanks to PVS-Studio for giving us
    a test license. Please see the git commit history for more info.
  * Fix incorrect length check in EAP-PWD. This may be exploitable.
  * Stop rotating session database files (radutmp, radwtmp) since
    these are not logfiles.
- freeradius-server-radiusd-logrotate.patch: updated

OBS-URL: https://build.opensuse.org/request/show/499628
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=98
2017-05-30 09:15:48 +00:00
Dominique Leuenberger
1967e79fb9 Accepting request 480000 from network
this is needed so package is identical to SP3 version

OBS-URL: https://build.opensuse.org/request/show/480000
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=67
2017-03-20 16:09:16 +00:00
2e31162933 - update to 3.0.13 (still FATE#322416)
Changelog only change to keep internal tracking numbers in right places.

OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=96
2017-03-13 13:14:24 +00:00
Dominique Leuenberger
8bb61fb781 Accepting request 477789 from network
1

OBS-URL: https://build.opensuse.org/request/show/477789
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=66
2017-03-12 19:04:03 +00:00
bb21ee0f50 Accepting request 477604 from home:stroeder:branches:network
update to 3.0.13

OBS-URL: https://build.opensuse.org/request/show/477604
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=94
2017-03-08 16:03:06 +00:00
Dominique Leuenberger
99cb6580b4 Accepting request 459264 from network
1

OBS-URL: https://build.opensuse.org/request/show/459264
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=65
2017-03-02 18:27:14 +00:00
3c66ce82fa Accepting request 459251 from home:kukuk:branches:network
- Don't require insserv if we use systemd
- Remove require for unused fillup

OBS-URL: https://build.opensuse.org/request/show/459251
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=92
2017-02-20 14:45:54 +00:00
Dominique Leuenberger
b32d9ac74a Accepting request 455207 from network
- Merge changes from SLE to openSUSE (FATE#322416):
  * freeradius-server-radclient-init-error-buffer.patch - make sure
    we initialize error buffer. bsc#911886: radclient error free()
    invalid pointer
  * freeradius-server-opensslversion.patch: remove OpenSSL version
    check and assume we know what we are doing. (bnc#1013311)
  * merge .changes file, mostly.
- do not attempt to detect "vulnerable" OpenSSL versions. SUSE
  security fixes do not necessarily bump version numbers as
  does upstream OpenSSL (bnc#1021375)
- do not generate certificates in %post. End-user needs to do this
  manually.
- keep FreeTDS disabled on SLE12 - we never shipped it enabled
- require OpenSSL 1.0+
- use pkgconfig(systemd) instead of plain systemd as BuildRequires
- don't list manual pages as %doc

- Add upstream keyring
- 2 new modules: rlm_sql_freetds and rlm_eap_fast

OBS-URL: https://build.opensuse.org/request/show/455207
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=64
2017-02-09 10:16:19 +00:00
ee5d96b532 fix capitalization typo in changes file.
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=90
2017-02-07 09:34:18 +00:00
5d3beec849 Accepting request 453646 from home:adamm:branches:network
- Merge changes from SLE to OpenSUSE (FATE#322416):
  * freeradius-server-radclient-init-error-buffer.patch - make sure
    we initialize error buffer. bsc#911886: radclient error free()
    invalid pointer
  * freeradius-server-opensslversion.patch: remove OpenSSL version
    check and assume we know what we are doing. (bnc#1013311)
  * merge .changes file, mostly.
- do not attempt to detect "vulnerable" OpenSSL versions. SUSE
  security fixes do not necessarily bump version numbers as
  does upstream OpenSSL (bnc#1021375)
- do not generate certificates in %post. End-user needs to do this
  manually.
- keep FreeTDS disabled on SLE12 - we never shipped it enabled
- require OpenSSL 1.0+
- use pkgconfig(systemd) instead of plain systemd as BuildRequires
- don't list manual pages as %doc

- Add upstream keyring
- 2 new modules: rlm_sql_freetds and rlm_eap_fast

OBS-URL: https://build.opensuse.org/request/show/453646
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=89
2017-02-06 10:58:11 +00:00
Dominique Leuenberger
bb915e8574 Accepting request 448419 from network
1

OBS-URL: https://build.opensuse.org/request/show/448419
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=63
2017-01-11 11:03:13 +00:00
849b165adf Accepting request 448405 from home:jengelh:branches:network
- Remove --with-pic which is for static libs only.
- Use SUSE RPM group names. Trim filler words from description.
- Do not hide errors from groupadd/useradd.

OBS-URL: https://build.opensuse.org/request/show/448405
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=87
2017-01-01 15:34:14 +00:00
Dominique Leuenberger
2c69e3c471 Accepting request 432174 from network
1

OBS-URL: https://build.opensuse.org/request/show/432174
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=62
2016-10-01 22:09:59 +00:00
a53ba595f6 Accepting request 432086 from home:stroeder:branches:network
update to 3.0.12 (successfully tested with EAP-TTLS/PAP with LDAP backend)

OBS-URL: https://build.opensuse.org/request/show/432086
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=85
2016-10-01 16:12:11 +00:00
Dominique Leuenberger
92d2a14f65 Accepting request 425081 from network
1

OBS-URL: https://build.opensuse.org/request/show/425081
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=61
2016-09-08 15:38:54 +00:00
Ismail Dönmez
122c166ff2 Accepting request 425076 from home:adamm:branches:network
- use %{with} macro for conditional inclusions instead of hardcoding
  version numbers
- improved package descriptions
- fixed builds on SLE12 and SLE11SP4

OBS-URL: https://build.opensuse.org/request/show/425076
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=83
2016-09-06 11:59:19 +00:00
Dominique Leuenberger
de056174c5 Accepting request 355853 from network
1

OBS-URL: https://build.opensuse.org/request/show/355853
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=60
2016-01-28 16:23:25 +00:00
Rusmir Duško
8f53a8841d Accepting request 355850 from home:stroeder:branches:network
update to 3.0.11

OBS-URL: https://build.opensuse.org/request/show/355850
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=81
2016-01-25 22:13:32 +00:00
Dominique Leuenberger
80728b464b Accepting request 336653 from network
1

OBS-URL: https://build.opensuse.org/request/show/336653
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=59
2015-10-06 11:27:54 +00:00
Ismail Dönmez
f9db905b8c Accepting request 336644 from home:stroeder:branches:network
updated to new upstream release 3.0.10 and successfully tested with EAP-TTLS, PAP with rlm_ldap

OBS-URL: https://build.opensuse.org/request/show/336644
OBS-URL: https://build.opensuse.org/package/show/network/freeradius-server?expand=0&rev=79
2015-10-06 08:34:26 +00:00
Dominique Leuenberger
822fc78533 Accepting request 321226 from network
- Fix boo#912714: freeradius can't use ntlm_auth
  * Create winbind group
  * Add radiusd to winbind group

OBS-URL: https://build.opensuse.org/request/show/321226
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/freeradius-server?expand=0&rev=58
2015-08-10 07:16:03 +00:00