19
|
|
|
yolanda.robla at can... |
|
10 years ago
|
|
|
18
|
|
|
Dmitrijs Ledkovs |
2.1.12+dfsg-1.2ubuntu1 |
11 years ago
|
|
|
17
|
|
|
Kees Cook |
2.1.12+dfsg-1.2 |
11 years ago
|
|
|
16
|
|
|
Nico Golde |
2.1.12+dfsg-1.1 |
11 years ago
|
|
|
15
|
|
|
Josip Rodin |
2.1.12+dfsg-1 |
11 years ago
|
|
|
14
|
|
|
gregor herrmann |
2.1.10+dfsg-3.1 |
11 years ago
|
|
|
13
|
|
|
Josip Rodin |
2.1.10+dfsg-3 |
12 years ago
|
|
|
12
|
|
* The zombie period start time variable mistakenly got set to a random value because of an upstream typo. Cherry-picked upstream commit 7b7dff7724721f8af5fd163f2292d427a869992d into a Debian patch, requested for squeeze in #600465. * Since 2.1.9, the daemon stopped reopening the default radius.log file constantly, which means the default logrotate setup breaks the default logging. D'oh. We now have to send SIGHUP to the daemon as a postrotate action, which makes it reopen log files and continue normally. * Added delaycompress to the logrotate options, just to be on the safe side. * Added a reload action into the init script accordingly, so that the right pidfile is picked up (one that can be overridden by the admin in /etc/default/freeradius, available since the last release). * Called reload from the postrotate section, closes: #602815. * However, the latter signal also makes the server re-read configuration files, but unlike the initial server start, this all happens under the unprivileged user. That in turn means that if by any chance there is any part of FR configuration that happens not to be readable by group freerad (or whatever non-default is configured), the reload will fail, effectively silently, as the log has been moved away. Gah. So we have to make an effort to ensure that the configuration files are still readable by that user, otherwise the reload fails and the aforementioned bug is not fixed. The files seem to revert to root:root upon conffile actions, at least that's what happened to me and I think that was the cause. So, on upgrade, try to re-apply the dpkg-statoverrides on our /etc/freeradius/* stuff, whatever they are, under the assumption they will let the freerad group read config files as is the initial setup. (I wish dpkg-statoverride --update $file just did the right thing, but it doesn't, so there's a new local function that does that.) * While doing the latter, noticed that we were checking for directories in dpkg-statoverride --list output with trailing slashes, but they get output without it, so it was a no-op. Fixed the check by removing the trailing slashes. Also then noticed that we were grepping --list output, but it takes an optional glob pattern, so saved us that pointless grep fork by using that facility, just as described in the policy manual. * force-reload switches from restart to reload, per policy 9.3.2. * lenny backport needed also libltdl-dev (2.2.x) to build properly, rather than libltdl3-dev, which is obsolete and doesn't make sense anyway.
|
Josip Rodin |
2.1.10+dfsg-2 |
13 years ago
|
|
|
11
|
|
* New upstream version, closes a bunch of reproducible SNAFUs, including two tagged as security issues, CVE-2010-3696, CVE-2010-3697, closes: #600176. * Build-depend on newer Libtool because of lt_dladvise_init(), also upstream now has a configure check so we no longer need a patch, yet we still don't want the old behaviour. Noticed by John Morrissey, closes: #584151. * Added the /etc/default/freeradius file as suggested by Rudy Gevaert and Matthew Newton, closes: #564716. * Stop symlinking /dev/urandom into /etc/freeradius/certs/random, it breaks grep -r in /etc. Instead, replace it inside eap.conf, both in the new shipped conffile and in postinst.
|
Josip Rodin |
2.1.10+dfsg-1 |
13 years ago
|
|
|
10
|
|
* New upstream version. + radclient (radtest) should now use IPv4 by default, closes: #569614. * Depend on ca-certificates explicitly, closes: #569601. * I mistook ca.pem for the locally selected acceptable CA, whereas that actually just happens to mean DebConf.org CA, and we want the former by default. That in turn is in /etc/ssl/certs/ca-certificates.crt. Obviously later the users can trivially change this, but this looks like a reasonably reliable default that doesn't involve a lot of magic that can delay or break postinst invocations. In the future, eap.conf will become modules/eap and this will not be so critical. * The private_key_file = ${certdir}/server.pem default doesn't get along with snakeoil, or common sense really (why would you keep a secret key in the same file as the non-secret certificate?), and could have broken upgrades if people accepted the conffile prompt, so adjusted the default conffile too, and adjusted the postinst upgrade logic as well. * Enable HAVE_LT_DLADVISE_INIT as it fixes the module symbol lookup errors from additional libraries, closes: #416266. * Explicate source format as 1.0. * Add ${misc:Depends} to all binary packages. * Update standards version to 3.8.4, no changes necessary.
|
Josip Rodin |
2.1.9+dfsg-1 |
13 years ago
|
|
|
9
|
|
* New upstream version. + Fixes several showstopper bugs, hence increased urgency. + Includes OpenSSL+GPL license exception, closes: #499120. + Fixes typo in a warning, closes: #523074. * Added libssl-dev into build-depends and enabled the building of modules that just depend on OpenSSL, namely rlm_eap_peap, rlm_eap_tls, rlm_eap_ttls, and rlm_otp, closes: #266229. * Because the configuration of EAP+SSL modules now actually kicks in, its non-existent certificate file would break the server start by default. Depend on ssl-cert, make use of make-ssl-cert and openssl, and add freerad to the ssl-cert group in the postinst to get us past the problematic default settings so that we don't crash and burn on clean upgrades, but otherwise leave everything else to the admin. * Ship /etc/freeradius/attrs.access_challenge, like the others. * Moved otp.conf and snmp.conf statoverride handling to the preinst and used rm_conffile on them as well. * Updated upstream changelog handling a bit.
|
Josip Rodin |
2.1.8+dfsg-1 |
14 years ago
|
|
|
8
|
|
|
Josip Rodin |
2.1.7+dfsg-2 |
14 years ago
|
|
|
7
|
|
* Adopting the package, closes: #536623. * New upstream version, closes: #513484. + Fixes the blooper in unlang evaluation logic, closes: #526175. * Used quilt (and added README.source), and moved upstream file patching into debian/patches/. The source is no longer in collab-maint git (to make it simpler for me to finally get this out the door), but kept the .gitignore should we need that again. * Dropped the dialup_admin/bin/backup_radacct patch (integrated upstream). * Dropped the raddb/Makefile patch (problem no longer exists upstream). * Dropped the lib/packet.c lib/radius.c main/listen.c patches (was from upstream 2.0.5 anyway). * Dropped references to otp.conf, it no longer exists upstream. Keep removing the conffile statoverride in prerm. * Dropped references to snmp.conf, it no longer exists upstream. Keep removing the conffile statoverride in prerm. * Ship /etc/freeradius/modules/* in the freeradius package. * Stop shipping sites-enabled symlinks in the package and instead create them only on initial install, thanks to Matej Vela, closes: #533396. * Add export PATH="${PATH:+$PATH:}/usr/sbin:/sbin" to the init script at the request of John Morrissey, closes: #550143. * Stop installing /var/run/freeradius in the package to silence Lintian. The init script already recreates it at will. * Remove executable bit from example.pl to silence Lintian.
|
Josip Rodin |
2.1.7+dfsg-1 |
14 years ago
|
|
|
6
|
|
|
Stephen Gran |
2.0.4+dfsg-7 |
14 years ago
|
|
|
5
|
|
|
Stephen Gran |
2.0.4+dfsg-6 |
15 years ago
|
|
|
4
|
|
|
Mark Hymers |
1.1.3-3 |
17 years ago
|
|
|
3
|
|
|
Paul Hampson |
1.0.1-2 |
19 years ago
|
|
|
2
|
|
|
Paul Hampson |
0.9.3-1 |
20 years ago
|
|
|
1
|
|
|
Paul Hampson |
upstream-0.9.3 |
20 years ago
|
|
|