Version 3.2.0
Original release notes
- Fixed a bug causing failmode and prompt_format configuration values to be case-sensitive.
- The primarygroup is now checked when determining if an AD/LDAP (ad_client) user is a member of the configured security_group_dn group.
- Added support for LDAPCompareRequest LDAP message when the proxy is acting as an LDAP server.
- Support additional username formats for exempt_ou matching when the proxy is acting as an LDAP server.
- Ignores service account credentials when using the "Integrated" (SSPI) authentication type for the Authentication Proxy's connection to your AD Authentication source to support Duo Single Sign-On. If provided in the [cloud] config for use with AD Sync, the service account credentials will be used to negotiate NTLM over SSPI.
- Events in the SIEM-consumable authevents.log now contain the authentication proxy hostname and the IKEY (Integration key) of the protected application.
- Fixed case where logging incorrectly indicated failmode was invoked when an invalid SKEY (Secret key) was used.
- The Windows installer now reports if there was an error installing the "Duo Authentication Proxy" service.
- Proxy startup is prevented if an ldap_server_auto section has no associated ad_client section.
- Bug fixes and enhancements to the connectivity tool.