Name: | freeradius |
---|---|
Version: | 3.0.4 |
Release: | 8.el7_3 |
Architecture: | x86_64 |
Group: | System Environment/Daemons |
Size: | 3366202 |
License: | GPLv2+ and LGPLv2+ |
RPM: | freeradius-3.0.4-8.el7_3.x86_64.rpm |
Source RPM: | freeradius-3.0.4-8.el7_3.src.rpm |
Build Date: | Wed Jun 28 2017 |
Build Host: | x86-ol7-builder-01.us.oracle.com |
Vendor: | Oracle America |
URL: | http://www.freeradius.org/ |
Summary: | High-performance and highly configurable free RADIUS server |
Description: | The FreeRADIUS Server Project is a high performance and highly configurable GPL'd free RADIUS server. The server is similar in some respects to Livingston's 2.0 server. While FreeRADIUS started as a variant of the Cistron RADIUS server, they don't share a lot in common any more. It now has many more features than Cistron or Livingston, and is much more configurable. FreeRADIUS is an Internet authentication daemon, which implements the RADIUS protocol, as defined in RFC 2865 (and others). It allows Network Access Servers (NAS boxes) to perform authentication for dial-up users. There are also RADIUS clients available for Web servers, firewalls, Unix logins, and more. Using RADIUS allows authentication and authorization for a network to be centralized, and minimizes the amount of re-configuration which has to be done when adding or deleting new users. |
- Disable internal OpenSSL cache and fix session cache file permissions. Resolves: Bug#1459131 CVE-2017-9148 freeradius: TLS resumption authentication bypass
- Rename lt_ symbols to fr_ to avoid clashes with libltdl. Resolves: Bug#1394787
- Don't remove backslash from unknown escape sequences in LDAP values. Resolves: Bug#1173526 - Improve dhcpclient and rad_counter online help. Resolves: Bug#1146966 - raddb: Move trigger.conf INCLUDE before modules, making it easier to refer to trigger variables from module configurations. Resolves: Bug#1155961 - Fix ipaddr option fallback onto ipv6. Resolves: Bug#1168868 - raddb: Comment on ipaddr/ipv4addr/ipv6addr use. Resolves: Bug#1168247
- Disable rlm_rest building explicitly to avoid unintended builds on some architectures breaking RPM build. Resolves: Bug#1162156 - Add -D option support to dhcpclient. Related: Bug#1146939 - Don't install rbmonkey - a test tool only useful to developers. Related: Bug#1146966 - Update clients(5) man page Resolves: Bug#1147464
- Fix possible group info corruption/segfault in rlm_unix' fr_getgrnam. - Fix file configuration item parsing.
- Fix a number of trigger issues. Resolves: Bug#1110407 radiusd doesn't send snmp trap after "radmin -e 'hup files'" Resolves: Bug#1110414 radiusd doesn't send snmp trap when sql connection is opened,closed or fail Resolves: Bug#1110186 radiusd doesn't send snmp trap when ldap connection fails/opens/closes Resolves: Bug#1109164 snmp trap messages send by radiusd are inconsistent and incomplete - Fix two omissions from radtest manpage. Resolves: Bug#1146898 'eap-md5' value is missing in -t option in SYNOPSIS of radtest man page Resolves: Bug#1114669 Missing -P option in radtest manpage - Disable OpenSSL version checking to avoid the need to edit radiusd.conf to confirm heartbleed is fixed. Resolves: Bug#1155070 FreeRADIUS doesn't start after upgrade due to failing OpenSSL version check
- Fix abort on home server triggers. Resolves: Bug#1113509 radiusd aborts when it has no proxy response with active snmp traps - Fix segfault upon example.pl read failure. Resolves: Bug#1146403 radiusd segfaults when file for perl module has wrong permissions - Fix example.pl permissions. Resolves: Bug#1146406 /etc/raddb/mods-config/perl/example.pl has wrong permissions and radiusd fails to start - Fix integer handling in various cases. Resolves: Bug#1146441 upstream test suite fails - Fix dhcpclient's dictionary.dhcp loading. Resolves: Bug#1146939 dhcpclient lookups dictionary.dhcp file in wrong location
- Upgrade to upstream 3.0.4 release. See upstream ChangeLog for details (in freeradius-doc subpackage).
- Upgrade to upstream 3.0.4-rc2 release. See upstream ChangeLog for details (in freeradius-doc subpackage). - Add installation of SNMP MIB files. - Resolves: Bug#1036562 Missing doc page for kerberos module - Resolves: Bug#1099625 Default message digest defaults to sha1 - Resolves: Bug#1109159 missing mib files in freeradius package - Resolves: Bug#1113010 radiusd doesn't send snmp trap when max_threads value is reached - Resolves: Bug#1114669 Missing -P option in radtest manpage - Resolves: Bug#1115128 radisud can't start if proto = udp is specified - Resolves: Bug#1115134 radiusd aborts after 'Access-Request' when listens on TCP port - Resolves: Bug#1115137 radiusd listens on udp port even if proto = tcp is specified - Resolves: Bug#1126725 radiusd silently fails when start_servers is higher than max_servers - Resolves: Bug#1135446 Radeapclient is not available
- Fix CVE-2014-2015 "freeradius: stack-based buffer overflow flaw in rlm_pap module" - resolves: bug#1066984 (fedora 1066763)