Version 5.1.0
Original release notes
- Adds the authproxyctl executable to Windows installations. This can be used to start or stop the Authentication Proxy from the command line, or show the version of the running proxy. When used to start the proxy, the output of the connectivity tool is shown in the command prompt window.
- The Windows installer now starts the Duo Authentication Proxy after a version upgrade if the service was running when the upgrade started.
- Updates the Authentication Proxy's bundled OpenSSL to version 1.0.2w to address CVE-2020-1968.
- The connectivity tool now checks for newer versions of the Authentication Proxy.
- The default authproxy.cfg file installed on Windows no longer contains Unix line endings, so it may be edited with Notepad.
- Improved error messaging when unable to establish an SSL connection when using FIPS mode.
- Improved error messaging when a StartTLS connection can not be established for Directory Sync or Duo Single Sign-On (SSO).
- Improved error messaging for Directory Sync and Duo SSO when attempting to use the "Integrated" authentication type with a Linux Authentication Proxy.
- The minimum_tls_version option now accepts mixed-case values.
- The connectivity tool no longer incorrectly reports an error when pass_through_attr_names is used with [radius_client].
- Corrected an issue where SSL verification was disabled if an empty or invalid file was provided for ssl_ca_certs_file.
- An exception no longer occurs if a non-string username attribute is used with Duo SSO.
- RADIUS authentications no longer fail if some MPPE attributes are present but the Send Key and Receive Key are missing.
- Fixed a bug causing the Authentication Proxy to parse values in the configuration file as multi-line values if they were accidentally indented.
- Corrected an issue where installed files did not have the correct permissions on Linux.