Moetive Alerts

Version 6.4.0

Released Apr 30, 2024 · Vendor release notes

Original release notes

- Fixes unnecessarily strict Connectivity Tool validation of ldap_server_auto SSL certificates. - Improves logged error messaging for AD DIR_ERROR responses. - The Authentication Proxy Manager now displays additional error information in certain failure scenarios. - Updates the internal build process to use scoped package names. - Upgrade to Cryptography 42.0.5 / OpenSSL 3.2.1 to address CVE-2024-26130, CVE-2023-50782, and CVE-2024-0727. - This version of OpenSSL changes the default SSL/TLS security level from 1 to 2. As a result of the default security level change, certificates with key lengths less than 2048 are no longer acceptable for inbound and outbound SSL, LDAPS, or STARTTLS connections to the Authentication Proxy. Our recommendation is that you reissue your certificates with key lengths of 2048 or greater. If you cannot update your certificates now, a workaround is available. Please see Duo KB article 8866 for details. - Upgrade Python to 3.11.9 to address CVE-2023-6597 and CVE-2024-0450. - Upgrade OpenSSL FIPS module to 3.0.9 to address CVE-2023-1255. - Updates various internal dependencies. - These dependency updates affect use of the Duo Authentication Proxy Manager tool on Windows Server versions 2012 R2 and older, which have reached end-of-support status with both Duo and Microsoft. Please see the Duo End of Sale, Last Date of Support, and End of Life Policy for more information.