Version 6.0.0
Original release notes
- SHA1 signed certificates are no longer supported for LDAPS or StartTLS connections. This affects Duo Single Sign-On Active Directory authentication, Active Directory Sync, OpenLDAP Directory Sync, and ad_client configuration for RADIUS or LDAP authentication. SHA1 certificates issued to Active Directory domain controllers or LDAP directory servers must be reissued as SHA256 or greater. If a SHA256+ certificate cannot be obtained, the alternative is to use unsecured (CLEAR) transport.
- NTLM1 is disabled in FIPS mode, and deprecated in non-FIPS mode.
- Linux installer now supports ARM64/AARCH64 in addition to the existing AMD64/x64 support.
- Updated Cryptography to 40.0.2 to address CVE-2020-25659 and CVE-2020-36242.
- Updated OpenSSL to 3.1.1.
- Updated Python to 3.8.16 to address CVE-2022-26488, CVE-2016-3189, CVE-2019-12900, CVE-2018-25032, CVE-2020-10735, and CVE-2022-37454.