Version 6.6.0
Original release notes
- Beta of RadSec support in radius_client and radius_server_* sections.
- The "Duo Security Authentication Proxy Service" Windows service "Startup type" (Automatic/Manual/Disabled/Delayed Start) is now preserved through upgrades.
- Improves error messaging for LDAPS certificate errors.
- Changes "Aborting AD auth request" messages to debug level to avoid excessive log messages in certain scenarios.
- Fixes spurious "client will be ignored" log message for configurations with multiple radius_server_duo_only sections.
- Upgrades Python to 3.12.12 to address multiple CVEs (CVE-2025-4517, CVE-2024-9287, CVE-2025-4138, CVE-2025-4330, CVE-2025-4435, CVE-2025-8194, CVE-2024-12718, CVE-2024-50602, CVE-2025-0938, CVE-2025-4516, CVE-2025-6069, CVE-2025-8291).
- Upgrades OpenSSL FIPS module to 3.1.2.
- Upgrades various third-party dependencies.