[tac_plus] tacacs+ F4.0.4.25 is available

heasley heas at shrubbery.net
Wed Mar 28 20:28:13 UTC 2012


tac_plus F4.0.4.25 is available at:
ftp://ftp.shrubbery.net/pub/tac_plus/tacacs+-F4.0.4.25.tar.gz

These are the relevant changes since the last announcement:

F4.0.4.23
        - fix build on netbsd
        - update PAM includes for OSX - YiJia Zhang

F4.0.4.24
        - allow PAM for pap authentication - Jeroen Nijhof
        - replace home-grown vprintf in report() with vsnprintf - Robert Swiecki
        - dont use report in signal handler, since report uses syslog which uses
          malloc - Robert Swiecki
        - use volatile sig_atomic_t 'reinitialize' variable - Robert Swiecki
        - use snprintf in get_authen_continue() and send_authen_error() and 
          check return - Robert Swiecki
        - make snprintf buffers of get_authen_continue() and send_authen_error()
          at least NI_MAXHOST bytes - Robert Swiecki

F4.0.4.25
        - add -m (md5) option to tac_pwd.  XXX could use better salt generation
        - use random() in tac_pwd if available and generate 4 bytes of salt for
          md5.
        - sprintf -> snprintf - Robert Swiecki
        - more pkt size checking in acct.c, authen.c, author.c - Robert Swiecki 
        - free(pak) in start_session() not in account(), for consistency


More information about the tac_plus-announce mailing list