changelog.xml 62 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821
  1. <PAGE>
  2. <INCLUDE file="inc/header.tmpl" />
  3. <VAR match="VAR_SEL_INDEX" replace="selected" />
  4. <VAR match="VAR_SEL_CHANGELOG" replace="selected" />
  5. <PARSE file="menu1.xml" />
  6. <PARSE file="menu2.xml" />
  7. <INCLUDE file="inc/content.tmpl" />
  8. <h1>Changelog</h1>
  9. <p>For full changelog entries including the latest development, see
  10. <a href="https://git.infradead.org/users/dwmw2/openconnect.git">gitweb</a>.</p>
  11. <ul>
  12. <li><b>OpenConnect HEAD</b>
  13. <ul>
  14. <li>Fix receiving multiple packets in one TLS frame for Array (<a href="https://gitlab.com/openconnect/openconnect/-/issues/435">#435</a>).</li>
  15. <li>Fix ESP failures under Windows (<a href="https://gitlab.com/openconnect/openconnect/-/issues/427">#427</a>).</li>
  16. <li>Add <tt>list-system-keys</tt> tool to assist Windows/MacOS users in setup.</li>
  17. </ul><br/>
  18. </li>
  19. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-9.01.tar.gz">OpenConnect v9.01</a></b>
  20. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-9.01.tar.gz.asc">PGP signature</a>)</i> &#8212; 2022-04-29
  21. <ul>
  22. <li>Fix library minor version (missing bump to 5.8).</li>
  23. </ul><br/>
  24. </li>
  25. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-9.00.tar.gz">OpenConnect v9.00</a></b>
  26. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-9.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2022-04-29
  27. <ul>
  28. <li>Add support for AnyConnect "Session Token Re-use Anchor Protocol" (STRAP) (<a href="https://gitlab.com/openconnect/openconnect/-/issues/410">#410</a>).</li>
  29. <li>Add support for AnyConnect "external browser" SSO mode (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/354">!354</a>).</li>
  30. <li>On Windows, fix crash on tunnel setup. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/370">#370</a>, <a href="https://gitlab.com/openconnect/openconnect/commit/6a2ffbbcd1c4ef0b689cce3d17154f6d4c2e3bc0">6a2ffbb</a>)</li>
  31. <li>Bugfix RSA SecurID token decryption and PIN entry forms, broken in v8.20. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/388">#388</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/344">!344</a>)</li>
  32. <li>Support <a href="https://www.cisco.com/c/en/us/support/docs/security/anyconnect-secure-mobility-client-v4x/212483-configure-asa-as-the-ssl-gateway-for-any.html">Cisco's multiple-certificate authentication</a> (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/194">!194</a>).</li>
  33. <li>Append <tt>internal=no</tt> to GlobalProtect authentication/configuration forms, for compatibility with servers which apparently require this to function properly. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/246">#246</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/337">!337</a>)</li>
  34. <li>Revert GlobalProtect default route handling change from v8.20. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/367">!367</a>)</li>
  35. <li>Support split-exclude routes for Fortinet. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/394">#394</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/345">!345</a>)</li>
  36. <li>Add <tt>openconnect_set_useragent()</tt> function.</li>
  37. <li>Add webview callback and SAML/SSO support for AnyConnect, GlobalProtect. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/126">!126</a>).</li>
  38. </ul><br/>
  39. </li>
  40. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.20.tar.gz">OpenConnect v8.20</a></b>
  41. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.20.tar.gz.asc">PGP signature</a>)</i> &#8212; 2022-02-20
  42. <ul>
  43. <li>When the queue length <i>(<tt>-Q</tt> option)</i> is 16 or more, try using <a
  44. href="https://www.redhat.com/en/blog/virtqueues-and-virtio-ring-how-data-travels">vhost-net</a> to accelerate tun device access.</li>
  45. <li>Use <tt>epoll()</tt> where available.</li>
  46. <li>Support non-AEAD ciphersuites in DTLSv1.2 with AnyConnect. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/249">#249</a>)</li>
  47. <li>Make <tt>tncc-emulate.py</tt> work with Python 3.7+. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/152">#152</a>, <a href="https://gitlab.com/openconnect/openconnect/merge_requests/120">!120</a>)</li>
  48. <li>Emulated a newer version of GlobalProtect official clients, 5.1.5-8; was 4.0.2-19 (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/131">!131</a>)</li>
  49. <li>Support Juniper login forms containing both password and 2FA token (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/121">!121</a>)</li>
  50. <li>Explicitly disable 3DES and RC4, unless enabled with <tt>--allow-insecure-crypto</tt> (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/114">!114</a>)</li>
  51. <li>Add obsolete-server-crypto test (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/114">!114</a>)</li>
  52. <li>Allow protocols to delay tunnel setup and shutdown (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/117">!117</a>)</li>
  53. <li>Support for GlobalProtect IPv6 (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/155">!155</a> and <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/188">!188</a>; previous work in <a href="https://gitlab.com/openconnect/openconnect/commit/d6db0ec03394234d41fbec7ffc794ceeb486a8f0">d6db0ec</a>)</li>
  54. <li>SIGUSR1 causes OpenConnect to log detailed connection information and statistics (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/154">!154</a>)</li>
  55. <li>Allow <tt>--servercert</tt> to be specified multiple times in order to accept server certificates matching more than one possible fingerprint (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/162">!162</a>, <a href="https://gitlab.com/openconnect/openconnect/-/issues/25">#25</a>)</li>
  56. <li>Add insecure debugging build mode for developers (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/112">!112</a>)</li>
  57. <li>Demangle default routes sent as split routes by GlobalProtect (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/118">!118</a>)</li>
  58. <li>Improve GlobalProtect login argument decoding (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/143">!143</a>)</li>
  59. <li>Add detection of authentication expiration date, intended to allow front-ends to cache and reuse authentication cookies/sessions (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/156">!156</a>)</li>
  60. <li>Small bug fixes and clarification of many logging messages.</li>
  61. <li>Support more Juniper login forms, including some SSO forms (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/171">!171</a>)</li>
  62. <li>Automatically build Windows installers for OpenConnect command-line interface (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/176">!176</a>)</li>
  63. <li>Restore compatibility with newer Cisco servers, by no longer sending them the <tt>X-AnyConnect-Platform</tt> header (<a href="https://gitlab.com/openconnect/openconnect/-/issues/101">#101</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/175">!175</a>)</li>
  64. <li>Add support for PPP-based protocols, currently over TLS only (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/165">!165</a>).</li>
  65. <li>Add support for two PPP-based protocols, F5 with <tt>--protocol=f5</tt> and Fortinet with <tt>--protocol=fortinet</tt> (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/169">!169</a>).</li>
  66. <li>Add experimental support for <a href="https://www.wintun.net/">Wintun</a> Layer 3 TUN driver under Windows (<a href="https://gitlab.com/openconnect/openconnect/-/issues/231">#231</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/178">!178</a>).</li>
  67. <li>Clean up and improve Windows routing/DNS configuration script (<a href="https://gitlab.com/openconnect/vpnc-scripts/-/merge_requests/26">vpnc-scripts!26</a>, <a href="https://gitlab.com/openconnect/vpnc-scripts/-/merge_requests/41">vpnc-scripts!41</a>, <a href="https://gitlab.com/openconnect/vpnc-scripts/-/merge_requests/44">vpnc-scripts!44</a>).</li>
  68. <li>On Windows, reclaim needed IP addresses from down network interfaces so that configuration script can succeed (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/178">!178</a>).</li>
  69. <li>Fix output redirection under Windows (<a href="https://gitlab.com/openconnect/openconnect/-/issues/229">#229</a>)</li>
  70. <li>More gracefully handle idle timeouts and other fatal errors for Juniper and Pulse (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/187">!187</a>)</li>
  71. <li>Ignore failures to fetch the Juniper/oNCP landing page if the authentication was successful (<a href="https://gitlab.com/openconnect/openconnect/-/commit/3e77943692b511719d9217d2ecc43588b7c6c08b">3e779436</a>).</li>
  72. <li>Add support for <a href="https://arraynetworks.com/products-secure-access-gateways-ag-series.html">Array Networks SSL VPN</a> (<a href="https://gitlab.com/openconnect/openconnect/-/issues/102">#102</a>)</li>
  73. <li>Support TLSv1.3 with TPMv2 EC and RSA keys, add test cases for swtpm and hardware TPM. (<a href="https://gitlab.com/openconnect/openconnect/-/compare/ed80bfacf6baa17a6f5f4a5ec7e11aee541cba95...ee1cd782ab0d91d34785c81425ee27217a66d0aa">ed80bfac...ee1cd782</a>)</li>
  74. <li>Add <tt>openconnect_get_connect_url()</tt> to simplify passing correct server information to the connecting <tt>openconnect</tt> process. <i>(NetworkManager-openconnect <a href="https://gitlab.gnome.org/GNOME/NetworkManager-openconnect/-/issues/46">#46</a>, <a href="https://gitlab.gnome.org/GNOME/NetworkManager-openconnect/-/issues/53">#53</a>)</i></li>
  75. <li>Disable brittle "system policy" enforcement where it cannot be gracefully overridden at user request. <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1960763"><i>(RH#1960763)</i></a>.</li>
  76. <li>Pass "portal cookie" fields from GlobalProtect portal to gateway to avoid repetition of password- or SAML-based login (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/199">!199</a>)</li>
  77. <li>With <tt>--user</tt>, enter username supplied via command-line into all authentication forms, not just the first. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/267">#267</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/220">!220</a>).</li>
  78. <li>Fix a subtle bug which has prevented ESP rekey and ESP-to-TLS fallback from working reliably with the Juniper/oNCP protocol since v8.04. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/322">#322</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/293">!293</a>).</li>
  79. <li>Fix a bug in <tt>csd-wrapper.sh</tt> which has prevented it from correctly downloading compressed Trojan binaries since at least v8.00. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/305">!305</a>)</li>
  80. <li>Make Windows socketpair emulation more robust in the face of Windows's ability to break its localhost routes. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/228">#228</a>, <a href="https://gitlab.com/openconnect/openconnect/-/issues/361">#361</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/320">!320</a>)</li>
  81. <li>Perform proper disconnect and routes cleanup on Windows when receiving Ctrl+C or Ctrl+Break. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/362">#362</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/323">!323</a>)</li>
  82. <li>Improve logging in routing/DNS configuration scripts. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/328">!328</a>, <a href="https://gitlab.com/openconnect/vpnc-scripts/-/merge_requests/45">vpnc-scripts!45</a>)</li>
  83. <li>Support modified configuration packet from Pulse 9.1R14 servers (<a href="https://gitlab.com/openconnect/openconnect/-/issues/379">#379</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/331">!331</a>)</li>
  84. </ul><br/>
  85. </li>
  86. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.10.tar.gz">OpenConnect v8.10</a></b>
  87. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.10.tar.gz.asc">PGP signature</a>)</i> &#8212; 2020-05-14
  88. <ul>
  89. <li>Install bash completion script to <tt>${datadir}/bash-completion/completions/openconnect</tt>.</li>
  90. <li>Improve compatibility of <tt>csd-post.sh</tt> trojan.</li>
  91. <li>Update Android build dependencies and bump API level to support Android 10.</li>
  92. <li>Fix potential buffer overflow with GnuTLS describing local certs (CVE-2020-12823).</li>
  93. </ul><br/>
  94. </li>
  95. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.09.tar.gz">OpenConnect v8.09</a></b>
  96. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.09.tar.gz.asc">PGP signature</a>)</i> &#8212; 2020-04-29
  97. <ul>
  98. <li>Add bash completion support.</li>
  99. <li>Give more helpful error in case of Pulse servers asking for TNCC.</li>
  100. <li>Sanitize non-canonical Legacy IP network addresses (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/97">!97</a>)</li>
  101. <li>Fix OpenSSL validation for trusted but invalid certificates (CVE-2020-12105).</li>
  102. <li>Convert <tt>tncc-wrapper.py</tt> to Python 3, and include modernized <tt>tncc-emulate.py</tt> as well. (<a href="https://gitlab.com/openconnect/openconnect/-/issues/91">!91</a>)</li>
  103. <li>Disable <a href="https://en.wikipedia.org/wiki/Nagle's_algorithm">Nagle's algorithm</a> for TLS sockets, to improve interactivity when tunnel runs over TCP rather than UDP. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/89">!89</a></li>
  104. <li>GlobalProtect: more resilient handling of periodic HIP check and login arguments, and predictable naming of challenge forms
  105. (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/95">!95</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/93/">!93</a>, <a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/90">!90</a>)</li>
  106. <li>Work around PKCS#11 tokens which forget to set <tt>CKF_LOGIN_REQUIRED</tt> (<a href="https://gitlab.com/openconnect/openconnect/issues/123">#123</a>).</li>
  107. </ul><br/>
  108. </li>
  109. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.08.tar.gz">OpenConnect v8.08</a></b>
  110. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.08.tar.gz.asc">PGP signature</a>)</i> &#8212; 2020-04-06
  111. <ul>
  112. <li>Fix check of <tt>pin-sha256:</tt> public key hashes to be case sensitive (<a href="https://gitlab.com/openconnect/openconnect/issues/116">#116</a>).</li>
  113. <li>Don't give non-functioning <tt>stderr</tt> to CSD trojan scripts.</li>
  114. <li>Fix crash with uninitialised OIDC token.</li>
  115. </ul><br/>
  116. </li>
  117. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.07.tar.gz">OpenConnect v8.07</a></b>
  118. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.07.tar.gz.asc">PGP signature</a>)</i> &#8212; 2020-04-04
  119. <ul>
  120. <li>Don't abort Pulse connection when server-provided certificate MD5 doesn't match.</li>
  121. <li>Fix off-by-one in check for bad GnuTLS versions, and add build and run time checks.</li>
  122. <li>Don't abort connection if CSD wrapper script returns non-zero (for now).</li>
  123. <li>Make <tt>--passtos</tt> work for protocols that use ESP, in addition to DTLS.</li>
  124. <li>Convert <tt>tncc-wrapper.py</tt> to Python 3, and include modernized <tt>tncc-emulate.py</tt> as well.</li>
  125. </ul><br/>
  126. </li>
  127. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.06.tar.gz">OpenConnect v8.06</a></b>
  128. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.06.tar.gz.asc">PGP signature</a>)</i> &#8212; 2020-03-31
  129. <ul>
  130. <li>Implement EAP-TTLS fragmentation.</li>
  131. <li>Fix Windows build with MSYS2 (<a href="https://gitlab.com/openconnect/openconnect/issues/74">#74</a>).</li>
  132. <li>Allow custom stoken rcfile to be specified (<a href="https://gitlab.com/openconnect/openconnect/issues/71">#71</a>).</li>
  133. <li>Periodic HIP checking for GlobalProtect, and cross-protocol API (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/56">!56</a>).</li>
  134. <li>Ciphersuite priority override options (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/71">!71</a>).</li>
  135. <li>Clearer GlobalProtect debugging/SAML output (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/66">!66</a>, <a href="https://gitlab.com/openconnect/openconnect/merge_requests/69">!69</a>).</li>
  136. <li>Explain experimental Pulse support for servers where Juniper oNCP is disabled (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/48">!48</a>).</li>
  137. <li>Ignore missing Cisco CSD stub and simply CSD subprocess invocation (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/77">!77</a>, <a href="https://gitlab.com/openconnect/openconnect/merge_requests/74">!74</a>).</li>
  138. <li>Pass <tt>IDLE_TIMEOUT</tt> to vpnc-script (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/67">!67</a>).</li>
  139. <li>Windows line-ending flexibility for standard input (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/78">!78</a>).</li>
  140. <li>Disable DTLS for GnuTLS versions between 3.6.3 and 3.6.13 inclusive due to <a href="https://gitlab.com/gnutls/gnutls/-/issues/960">GnuTLS #960</a>.</li>
  141. <li>Add RFC6750 Bearer token support (<a href="https://gitlab.com/openconnect/openconnect/-/merge_requests/70">!70</a>).</li>
  142. </ul><br/>
  143. </li>
  144. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.05.tar.gz">OpenConnect v8.05</a></b>
  145. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.05.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-09-12
  146. <ul>
  147. <li>Fix GlobalProtect ESP stall (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/55">!55</a>).</li>
  148. <li>Fix HTTP chunked encoding buffer overflow (CVE-2019-16239).</li>
  149. </ul><br/>
  150. </li>
  151. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.04.tar.gz">OpenConnect v8.04</a></b>
  152. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.04.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-08-09
  153. <ul>
  154. <li>Rework DTLS MTU detection. (<a href="https://gitlab.com/openconnect/openconnect/issues/10">#10</a>)</li>
  155. <li>Add Pulse Connect Secure support.</li>
  156. <li>OpenSSL build fixes (<a href="https://gitlab.com/openconnect/openconnect/merge_requests/51">!51</a>).</li>
  157. <li>Add HMAC-SHA256-128 (RFC4868) support for ESP.</li>
  158. <li>Support IPv6 in ESP.</li>
  159. <li>Translate user-visible strings from <tt>openconnect_get_supported_protocols()</tt>.</li>
  160. <li>Fix proxy username/password handling to allow special characters and escaping.</li>
  161. </ul><br/>
  162. </li>
  163. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.03.tar.gz">OpenConnect v8.03</a></b>
  164. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.03.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-05-18
  165. <ul>
  166. <li>Fix detection of <tt>utun</tt> support on OS X (<a href="https://gitlab.com/openconnect/openconnect/issues/18">#18</a>).</li>
  167. <li>Fix Cisco DTLSv1.2 support for <tt>AES256-GCM-SHA384</tt>.</li>
  168. <li>Fix Solaris 11.4 build by properly detecting <tt>memset_s()</tt>.</li>
  169. <li>Fix recognition of OTP password fields (<a href="https://gitlab.com/openconnect/openconnect/issues/24">#24</a>).</li>
  170. </ul><br/>
  171. </li>
  172. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.02.tar.gz">OpenConnect v8.02</a></b>
  173. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.02.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-01-16
  174. <ul>
  175. <li>Fix GNU/Hurd build.</li>
  176. <li>Discover <tt>vpnc-script</tt> in default packaged location on FreeBSD/OpenBSD.</li>
  177. <li>Support split-exclude routes for GlobalProtect.</li>
  178. <li>Fix GnuTLS builds without libtasn1.</li>
  179. <li>Fix DTLS support with OpenSSL 1.1.1+.</li>
  180. <li>Add Cisco-compatible DTLSv1.2 support.</li>
  181. <li>Invoke script with <tt>reason=attempt-reconnect</tt> before doing so.</li>
  182. </ul><br/>
  183. </li>
  184. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.01.tar.gz">OpenConnect v8.01</a></b>
  185. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.01.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-01-05
  186. <ul>
  187. <li>Fix <tt>memset_s()</tt> arguments.</li>
  188. <li>Fix OpenBSD build.</li>
  189. </ul><br/>
  190. </li>
  191. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-8.00.tar.gz">OpenConnect v8.00</a></b>
  192. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-8.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2019-01-05
  193. <ul>
  194. <li>Clear form submissions (which may include passwords) before freeing (CVE-2018-20319).</li>
  195. <li>Allow form responses to be provided on command line.</li>
  196. <li>Add support for SSL keys stored in <a href="tpm.html">TPM2</a>.</li>
  197. <li>Fix ESP rekey when replay protection is disabled.</li>
  198. <li>Drop support for GnuTLS older than 3.2.10.</li>
  199. <li>Fix <tt>--passwd-on-stdin</tt> for Windows to not forcibly open console.</li>
  200. <li>Fix portability of shell scripts in test suite.</li>
  201. <li>Add Google Authenticator TOTP support for Juniper.</li>
  202. <li>Add RFC7469 key PIN support for cert hashes.</li>
  203. <li>Add protocol method to securely log out the Juniper session.</li>
  204. <li>Relax requirements for Juniper hostname packet response to support old gateways.</li>
  205. <li>Add API functions to query the supported protocols.</li>
  206. <li>Verify ESP sequence numbers and warn even if replay protection is disabled.</li>
  207. <li>Add support for PAN GlobalProtect VPN protocol (<tt>--protocol=gp</tt>).</li>
  208. <li>Reorganize listing of command-line options, and include information on supported protocols.</li>
  209. <li>SIGTERM cleans up the session similarly to SIGINT.</li>
  210. </ul><br/>
  211. </li>
  212. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.08.tar.gz">OpenConnect v7.08</a></b>
  213. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.08.tar.gz.asc">PGP signature</a>)</i> &#8212; 2016-12-13
  214. <ul>
  215. <li>Add SHA256 support for server cert hashes.</li>
  216. <li>Enable DHE ciphers for Cisco DTLS.</li>
  217. <li>Increase initial oNCP configuration buffer size.</li>
  218. <li>Reopen <tt>CONIN$</tt> when stdin is redirected on Windows.</li>
  219. <li>Improve support for point-to-point routing on Windows.</li>
  220. <li>Check for non-resumed DTLS sessions which may indicate a MiTM attack.</li>
  221. <li>Add <tt>TUNIDX</tt> environment variable on Windows.</li>
  222. <li>Fix compatibility with Pulse Secure 8.2R5.</li>
  223. <li>Fix IPv6 support in Solaris.</li>
  224. <li>Support DTLS automatic negotiation.</li>
  225. <li>Support <tt>--key-password</tt> for GnuTLS PKCS#11 PIN.</li>
  226. <li>Support automatic DTLS MTU detection with OpenSSL.</li>
  227. <li>Drop support for combined GnuTLS/OpenSSL build.</li>
  228. <li>Update OpenSSL to allow TLSv1.2, improve compatibility options.</li>
  229. <li>Remove <tt>--no-cert-check</tt> option. It was being (mis)used.</li>
  230. <li>Fix OpenSSL support for PKCS#11 EC keys without public key.</li>
  231. <li>Support for final OpenSSL 1.1 release.</li>
  232. <li>Fix polling/retry on "tun" socket when buffers full.</li>
  233. <li>Fix AnyConnect server-side MTU setting.</li>
  234. <li>Fix ESP replay detection.</li>
  235. <li>Allow build with LibreSSL <i>(for fetishists only; do not use this as DTLS is broken)</i>.</li>
  236. <li>Add certificate torture test suite.</li>
  237. <li>Support PKCS#11 PIN via <tt>pin-value=</tt> and <tt>--key-password</tt> for OpenSSL.</li>
  238. <li>Fix integer overflow issues with ESP packet replay detection.</li>
  239. <li>Add <tt>--pass-tos</tt> option as in OpenVPN.</li>
  240. <li>Support rôle selection form in Juniper VPN.</li>
  241. <li>Support DER-format certificates, add certificate format torture tests.</li>
  242. <li>For OpenSSL >= 1.0.2, fix certificate validation when only an
  243. intermediate CA is specified with the <tt>--cafile</tt> option.</li>
  244. <li>Support Juniper "Pre Sign-in Message".</li>
  245. </ul><br/>
  246. </li>
  247. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.07.tar.gz">OpenConnect v7.07</a></b>
  248. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.07.tar.gz.asc">PGP signature</a>)</i> &#8212; 2016-07-11
  249. <ul>
  250. <li>More fixes for OpenSSL 1.1 build.</li>
  251. <li>Support Juniper "Post Sign-in Message".</li>
  252. <li>Add <tt>--protocol</tt> option.</li>
  253. <li>Fix ChaCha20-Poly1305 cipher suite to reflect final standard.</li>
  254. <li>Add ability to disable IPv6 support via library API.</li>
  255. <li>Set groups appropriately when using <tt>setuid()</tt>.</li>
  256. <li>Automatic DTLS MTU detection.</li>
  257. <li>Support SSL client certificate authentication with Juniper servers.</li>
  258. <li>Revamp SSL certificate validation for OpenSSL and stop supporting OpenSSL older than 0.9.8.</li>
  259. <li>Fix handling of multiple DNS search domains with Network Connect.</li>
  260. <li>Fix handling of large configuration packets for Network Connect.</li>
  261. <li>Enable SNI when built with OpenSSL <i>(1.0.1g or later)</i>.</li>
  262. <li>Add <tt>--resolve</tt> and <tt>--local-hostname</tt> options to command line.</li>
  263. </ul><br/>
  264. </li>
  265. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.06.tar.gz">OpenConnect v7.06</a></b>
  266. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.06.tar.gz.asc">PGP signature</a>)</i> &#8212; 2015-03-17
  267. <ul>
  268. <li>Fix <tt>openconnect.pc</tt> breakage after liboath removal.</li>
  269. <li>Refactor Juniper Network Connect receive loop.</li>
  270. <li>Fix some memory leaks.</li>
  271. <li>Add Bosnian translation.</li>
  272. </ul><br/>
  273. </li>
  274. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.05.tar.gz">OpenConnect v7.05</a></b>
  275. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.05.tar.gz.asc">PGP signature</a>)</i> &#8212; 2015-03-10
  276. <ul>
  277. <li>Fix alignment issue which broke LZS compression on ARM etc.</li>
  278. <li>Support HTTP authentication to servers, not just proxies.</li>
  279. <li>Work around Yubikey <a href="https://forum.yubico.com/viewtopica454-3.html?f=26&amp;t=1601">issue</a> with non-ASCII passphrase set on pre-KitKat Android.</li>
  280. <li>Add SHA256/SHA512 support for OATH.</li>
  281. <li>Remove liboath dependency.</li>
  282. <li>Support DTLS v1.2 and AES-GCM with OpenSSL 1.0.2.</li>
  283. <li>Add OpenSSL 1.0.2 to known-broken releases (<a href="http://rt.openssl.org/Ticket/Display.html?id=3703&amp;amp;user=guest&amp;amp;pass=guest">RT#3703</a>,
  284. <a href="http://rt.openssl.org/Ticket/Display.html?id=3711&amp;amp;user=guest&amp;amp;pass=guest">RT#3711</a>).</li>
  285. <li>Fix build with OpenSSL HEAD <i>(OpenSSL 1.1.x).</i></li>
  286. <li>Preliminary support for Juniper SSL VPN.</li>
  287. </ul><br/>
  288. </li>
  289. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.04.tar.gz">OpenConnect v7.04</a></b>
  290. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.04.tar.gz.asc">PGP signature</a>)</i> &#8212; 2015-01-25
  291. <ul>
  292. <li>Change default behaviour to enable only stateless compression.</li>
  293. <li>Add <tt>--compression</tt> argument and <tt>openconnect_set_compression_mode()</tt>.</li>
  294. <li>Add support for LZS compression <i>(compatible with latest Cisco ASA and ocserv)</i>.</li>
  295. <li>Add support for <a href="https://code.google.com/p/lz4/">LZ4</a> compression <i>(compatible with ocserv)</i>.</li>
  296. </ul><br/>
  297. </li>
  298. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.03.tar.gz">OpenConnect v7.03</a></b>
  299. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.03.tar.gz.asc">PGP signature</a>)</i> &#8212; 2015-01-09
  300. <ul>
  301. <li>Android build infrastructure updates, including 64-bit support.</li>
  302. <li>Clean up handling of incoming packets.</li>
  303. <li>Fix issue with two-stage <i>(i.e. NetworkManager)</i> connection to servers with trick DNS <a href="https://bugzilla.redhat.com/show_bug.cgi?id=1179681"><i>(RH#1179681)</i></a>.</li>
  304. <li>Stop using static variables for received packets.</li>
  305. </ul><br/>
  306. </li>
  307. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.02.tar.gz">OpenConnect v7.02</a></b>
  308. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.02.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-12-19
  309. <ul>
  310. <li>Add PKCS#11 support for OpenSSL.</li>
  311. <li>Fix handling of select options in <tt>openconnect_set_option_value().</tt></li>
  312. </ul><br/>
  313. </li>
  314. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.01.tar.gz">OpenConnect v7.01</a></b>
  315. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.01.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-12-07
  316. <ul>
  317. <li>Try harder to find a PKCS#11 key to match a given certificate.</li>
  318. <li>Handle '<tt>Connection: close</tt>' from proxies correctly.</li>
  319. <li>Warn when MTU is set too low <i>(&lt;1280)</i> to permit IPv6 connectivity.</li>
  320. <li>Add support for <tt>X-CSTP-DynDNS</tt>, to trigger DNS lookup on each reconnect.</li>
  321. </ul><br/>
  322. </li>
  323. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-7.00.tar.gz">OpenConnect v7.00</a></b>
  324. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-7.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-11-27
  325. <ul>
  326. <li>Add support for GnuTLS 3.4 <tt>system:</tt> keys including Windows certificate store.</li>
  327. <li>Add support for HOTP/TOTP keys from Yubikey NEO devices.</li>
  328. <li>Add <tt>---no-system-trust</tt> option to disable default certificate authorities.</li>
  329. <li>Improve <tt>libiconv</tt> and <tt>libintl</tt> detection.</li>
  330. <li>Stop calling <tt>setenv()</tt> from library functions.</li>
  331. <li>Support <tt>utun</tt> driver on OS X.</li>
  332. <li>Change library API so string ownership is never transferred.</li>
  333. <li>Support new NDIS6 TAP-Windows driver shipped with OpenVPN 2.3.4.</li>
  334. <li>Support using PSKC <i>(<a href="https://tools.ietf.org/html/rfc6030">RFC6030</a>)</i> token files for HOTP/TOTP tokens.</li>
  335. <li>Support for updating HOTP token storage when token is used.</li>
  336. <li>Support for reading OTP token data from a file.</li>
  337. <li>Add full <a href="charset.html">character set handling</a> for legacy non-UTF8 systems <i>(including Windows)</i>.</li>
  338. <li>Fix legacy <i>(i.e. not XML POST)</i> submission of non-ASCII form entries <i>(even in UTF-8 locales)</i>.</li>
  339. <li>Add support for 32-bit Windows XP.</li>
  340. <li>Avoid retrying without XML POST, when we failed to even reach the server.</li>
  341. <li>Fix off-by-one in parameter substitution in error messages.</li>
  342. <li>Improve reporting when GSSAPI auth requested but not compiled in.</li>
  343. <li>Fix parsing of split include routes on Windows.</li>
  344. <li>Fix crash on invocation with <tt>--token-mode</tt> but no <tt>--token-secret</tt>.</li>
  345. </ul><br/>
  346. </li>
  347. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-6.00.tar.gz">OpenConnect v6.00</a></b>
  348. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-6.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-07-08
  349. <ul>
  350. <li>Support SOCKS proxy authentication (password, GSSAPI).</li>
  351. <li>Support HTTP proxy authentication (Basic, Digest, NTLM and GSSAPI).</li>
  352. <li>Download XML profile in XML POST mode.</li>
  353. <li>Fix a couple of bugs involving DTLS rekeying.</li>
  354. <li>Fix problems seen when building or connecting without DTLS enabled.</li>
  355. <li>Fix tun error handling on Windows hosts.</li>
  356. <li>Skip password prompts when using PKCS#8 and PKCS#12 certificates with empty passwords.</li>
  357. <li>Fix several minor memory leaks and error paths.</li>
  358. <li>Update several Android dependencies, and make the download process more robust.</li>
  359. </ul><br/>
  360. </li>
  361. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-5.99.tar.gz">OpenConnect v5.99</a></b>
  362. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-5.99.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-03-05
  363. <ul>
  364. <li>Add <a href="https://tools.ietf.org/html/rfc4226">RFC4226</a> HOTP token support.</li>
  365. <li>Tolerate servers closing connection uncleanly after HTTP/1.0 response <a href="https://bugs.launchpad.net/bugs/1225276"><i>(Ubuntu #1225276)</i></a>.</li>
  366. <li>Add support for IPv6 split tunnel configuration.</li>
  367. <li>Add Windows support with MinGW <i>(tested with both IPv6 and Legacy IP with latest <a href="https://git.infradead.org/users/dwmw2/vpnc-scripts.git/blob_plain/HEAD:/vpnc-script-win.js">vpnc-script-win.js</a>)</i></li>
  368. <li>Change library API to support updating the auth form when the authgroup is changed <a href="https://bugs.launchpad.net/bugs/1229195"><i>(Ubuntu #1229195)</i></a>.</li>
  369. <li>Change <tt>--os mac</tt> to <tt>--os mac-intel</tt>, to match the identifier used by Cisco clients.</li>
  370. <li>Add new API functions to support invoking the VPN mainloop directly from an application.</li>
  371. <li>Add JNI interface and sample Java application.</li>
  372. <li>Fix junk in <tt>--cookieonly</tt> output when CSD is enabled.</li>
  373. <li>Enable TOTP, stoken, and JNI support in the Android builds.</li>
  374. <li>Add <tt>--pfs</tt> option to enforce perfect forward secrecy.</li>
  375. <li>Enable elliptic curves with GnuTLS 3.2.9+, where there is a
  376. workaround for certain firewalls that fail with client hellos between
  377. 256 and 512 bytes.</li>
  378. <li>Add padding when sending password, to avoid leakage of password
  379. and username length.</li>
  380. <li>Add support for DTLS 1.2 and AES-GCM when connecting to ocserv.</li>
  381. <li>Add support for server name indication when compiled with GnuTLS
  382. 3.2.9+.</li>
  383. </ul><br/>
  384. </li>
  385. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-5.03.tar.gz">OpenConnect v5.03</a></b>
  386. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-5.03.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-02-03
  387. <ul>
  388. <li>Fix crash on <tt>--authenticate</tt> due to freeing <tt>--cafile</tt> option in <tt>argv</tt>.</li>
  389. </ul><br/>
  390. </li>
  391. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-5.02.tar.gz">OpenConnect v5.02</a></b>
  392. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-5.02.tar.gz.asc">PGP signature</a>)</i> &#8212; 2014-01-01
  393. <ul>
  394. <li>Fix XML POST issues with authgroups by falling back to old style login.</li>
  395. <li>Fix <tt>--cookie-on-stdin</tt> with cookies from ocserv.</li>
  396. <li>Fix reconnection to wrong host after redirect.</li>
  397. <li>Reduce limit of queued packets on DTLS socket, to fix VoIP latency.</li>
  398. <li>Fix Solaris build breakage due to missing <tt>&amp;lt;string.h&amp;gt;</tt> includes.</li>
  399. <li>Include path in <tt>&amp;lt;group-access&amp;gt;</tt> node.</li>
  400. <li>Include supporting CA certificates from PKCS#11 tokens <i>(with GnuTLS 3.2.7+)</i>.</li>
  401. <li>Fix possible heap overflow if MTU is increased on reconnection (CVE-2013-7098).</li>
  402. </ul><br/>
  403. </li>
  404. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-5.01.tar.gz">OpenConnect v5.01</a></b>
  405. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-5.01.tar.gz.asc">PGP signature</a>)</i> &#8212; 2013-06-01
  406. <ul>
  407. <li>Attempt to handle <tt>&amp;lt;client-cert-request&amp;gt;</tt> in aggregate auth mode.</li>
  408. <li>Don't include <tt>X-Aggregate-Auth:</tt> header in fallback mode.</li>
  409. <li>Enable AES256 mode for DTLS with GnuTLS <a href="https://bugzilla.redhat.com/show_bug.cgi?id=955710"><i>(RH#955710)</i></a>.</li>
  410. <li>Add <tt>--dump-http-traffic</tt> option for debugging.</li>
  411. <li>Be more permissive in parsing XML forms.</li>
  412. <li>Use original URL when falling back to non-XML POST mode.</li>
  413. <li>Add <tt>--no-xmlpost</tt> option to revert to older, compatible behaviour.</li>
  414. <li>Close connection before falling back to non-xmlpost mode <a href="https://bugzilla.redhat.com/show_bug.cgi?id=964650"><i>(RH#964650)</i></a>.</li>
  415. <li>Improve error handling when server closes connection <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=708928"><i>(Debian #708928)</i></a>.</li>
  416. </ul><br/>
  417. </li>
  418. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-5.00.tar.gz">OpenConnect v5.00</a></b>
  419. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-5.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2013-05-15
  420. <ul>
  421. <li>Use GnuTLS by default instead of OpenSSL.</li>
  422. <li>Avoid using deprecated <tt>gnutls_pubkey_verify_data()</tt> function.</li>
  423. <li>Fix compatibility issues with XML POST authentication.</li>
  424. <li>Fix memory leaks on <tt>realloc()</tt> failure.</li>
  425. <li>Fix certificate validation problem caused by hostname canonicalisation.</li>
  426. <li>Add <a href="https://tools.ietf.org/html/rfc6238">RFC6238</a> TOTP token support using <a href="https://www.nongnu.org/oath-toolkit/">liboath</a>.</li>
  427. <li>Replace <tt>--stoken</tt> option with more generic <tt>--token-mode</tt> and <tt>--token-secret</tt> options.</li>
  428. </ul><br/>
  429. </li>
  430. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.99.tar.gz">OpenConnect v4.99</a></b>
  431. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.99.tar.gz.asc">PGP signature</a>)</i> &#8212; 2013-02-07
  432. <ul>
  433. <li>Add <tt>--os</tt> switch to report a different OS type to the gateway.</li>
  434. <li>Support new XML POST format.</li>
  435. <li>Add SecurID token support using <a href="http://stoken.sf.net/">libstoken</a>.</li>
  436. </ul><br/>
  437. </li>
  438. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.08.tar.gz">OpenConnect v4.08</a></b>
  439. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.08.tar.gz.asc">PGP signature</a>)</i> &#8212; 2013-02-13
  440. <ul>
  441. <li>Fix overflow on HTTP request buffers (CVE-2012-6128)</li>
  442. <li>Fix connection to servers with round-robin DNS with two-stage auth/connect.</li>
  443. <li>Impose minimum MTU of 1280 bytes.</li>
  444. <li>Fix some harmless issues reported by Coverity.</li>
  445. <li>Improve <tt>"Attempting to connect..."</tt> message to be explicit when it's connecting to a proxy.</li>
  446. </ul><br/>
  447. </li>
  448. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.07.tar.gz">OpenConnect v4.07</a></b>
  449. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.07.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-08-31
  450. <ul>
  451. <li>Fix segmentation fault when invoked with <tt>-p</tt> argument.</li>
  452. <li>Fix handling of write stalls on CSTP (TCP) socket.</li>
  453. </ul><br/>
  454. </li>
  455. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.06.tar.gz">OpenConnect v4.06</a></b>
  456. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.06.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-07-23
  457. <ul>
  458. <li>Fix default CA location for non-Fedora systems with old GnuTLS.</li>
  459. <li>Improve error handing when <tt>vpnc-script</tt> exits with error.</li>
  460. <li>Handle PKCS#11 tokens which won't list keys without login.</li>
  461. </ul><br/>
  462. </li>
  463. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.05.tar.gz">OpenConnect v4.05</a></b>
  464. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.05.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-07-12
  465. <ul>
  466. <li>Use correct CSD script for Mac OS X.</li>
  467. <li>Fix endless loop in PIN cache handling with multiple PKCS#11 tokens.</li>
  468. <li>Fix PKCS#11 URI handling to preserve all attributes.</li>
  469. <li>Don't forget key password on GUI reconnect.</li>
  470. <li>Fix GnuTLS v3 build on OpenBSD.</li>
  471. </ul><br/>
  472. </li>
  473. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.04.tar.gz">OpenConnect v4.04</a></b>
  474. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.04.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-07-05
  475. <ul>
  476. <li>Fix GnuTLS password handling for PKCS#8 files.</li>
  477. </ul><br/>
  478. </li>
  479. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.03.tar.gz">OpenConnect v4.03</a></b>
  480. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.03.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-07-02
  481. <ul>
  482. <li>Fix <tt>--no-proxy</tt> option.</li>
  483. <li>Fix handling of requested vs. received MTU settings.</li>
  484. <li>Fix DTLS MTU for GnuTLS 3.0.21 and newer.</li>
  485. <li>Support more ciphers for OpenSSL encrypted PEM keys, with GnuTLS.</li>
  486. <li>Fix GnuTLS compatibility issue with servers that insist on TLSv1.0 or non-AES ciphers <a href="https://bugzilla.redhat.com/show_bug.cgi?id=836558"><i>(RH#836558)</i></a>.</li>
  487. </ul><br/>
  488. </li>
  489. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.02.tar.gz">OpenConnect v4.02</a></b>
  490. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.02.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-06-28
  491. <ul>
  492. <li>Fix build failure due to unconditional inclusion of <tt>&amp;lt;gnutls/dtls.h&amp;gt;</tt>.</li>
  493. </ul><br/>
  494. </li>
  495. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.01.tar.gz">OpenConnect v4.01</a></b>
  496. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.01.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-06-28
  497. <ul>
  498. <li>Fix DTLS MTU issue with GnuTLS.</li>
  499. <li>Fix reconnect crash when compression is disabled.</li>
  500. <li>Fix build on systems like FreeBSD 8 without <tt>O_CLOEXEC</tt>.</li>
  501. <li>Add <tt>--dtls-local-port</tt> option.</li>
  502. <li>Print correct error when <tt>/dev/net/tun</tt> cannot be opened.</li>
  503. <li>Fix <tt>openconnect.pc</tt> pkg-config file not to require <tt>zlib.pc</tt> on systems which lack it (like RHEL5).</li>
  504. </ul><br/>
  505. </li>
  506. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-4.00.tar.gz">OpenConnect v4.00</a></b>
  507. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-4.00.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-06-20
  508. <ul>
  509. <li>Add support for OpenSSL's odd encrypted PKCS#1 files, for GnuTLS.</li>
  510. <li>Fix repeated passphrase retry for OpenSSL.</li>
  511. <li>Add keystore support for Android.</li>
  512. <li>Support TPM, and also additional checks on PKCS#11 certs, even with GnuTLS 2.12.</li>
  513. <li>Fix library references to OpenSSL's <tt>ERR_print_errors_cb()</tt> when built against GnuTLS v2.12.</li>
  514. </ul><br/>
  515. </li>
  516. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.99.tar.gz">OpenConnect v3.99</a></b>
  517. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.99.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-06-13
  518. <ul>
  519. <li>Enable native TPM support when built with GnuTLS.</li>
  520. <li>Enable PKCS#11 token support when built with GnuTLS.</li>
  521. <li>Eliminate all SSL library exposure through <tt>libopenconnect</tt>.</li>
  522. <li>Parse split DNS information, provide <tt>$CISCO_SPLIT_DNS</tt> environment variable to <tt>vpnc-script</tt>.</li>
  523. <li>Attempt to provide new-style MTU information to server <i>(on Linux only, unless specified on command line)</i>.</li>
  524. <li>Allow building against GnuTLS, including DTLS support.</li>
  525. <li>Add <tt>--with-pkgconfigdir=</tt> option to <tt>configure</tt> for FreeBSD's benefit <i><a href="https://bugs.freedesktop.org/show_bug.cgi?id=48743">(fd#48743)</a></i>.</li>
  526. </ul><br/>
  527. </li>
  528. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.20.tar.gz">OpenConnect v3.20</a></b>
  529. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.20.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-05-18
  530. <ul>
  531. <li>Cope with non-keepalive HTTP response on authentication success.</li>
  532. <li>Fix progress callback with incorrect <tt>cbdata</tt> which caused KDE crash.</li>
  533. </ul><br/>
  534. </li>
  535. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.19.tar.gz">OpenConnect v3.19</a></b>
  536. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.19.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-05-17
  537. <ul>
  538. <li>Add <tt>--config</tt> option for reading options from file.</li>
  539. <li>Improve OpenSSL DTLS compatibility to work on Ubuntu 10.04.</li>
  540. <li>Flush progress logging output promptly after each message.</li>
  541. <li>Add symbol versioning for shared library (on sane platforms).</li>
  542. <li>Add <tt>openconnect_set_cancel_fd()</tt> function to allow clean cancellation.</li>
  543. <li>Fix corruption of URL in <tt>openconnect_parse_url()</tt> if it specifies a port number.</li>
  544. <li>Fix inappropriate <tt>exit()</tt> calls from library code.</li>
  545. <li>Library namespace cleanup &#8212; all symbols now have the prefix <tt>openconnect_</tt> on platforms where symbol versioning works.</li>
  546. <li>Fix <tt>--non-inter</tt> option so it still uses login information from command line.</li>
  547. </ul><br/>
  548. </li>
  549. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.18.tar.gz">OpenConnect v3.18</a></b>
  550. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.18.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-04-25
  551. <ul>
  552. <li>Fix autohate breakage with <tt>--disable-nls</tt>... hopefully.</li>
  553. <li>Fix buffer overflow in banner handling.</li>
  554. </ul><br/>
  555. </li>
  556. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.17.tar.gz">OpenConnect v3.17</a></b>
  557. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.17.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-04-20
  558. <ul>
  559. <li>Work around <tt>time()</tt> brokenness on Solaris.</li>
  560. <li>Fix interface plumbing on Solaris 10.</li>
  561. <li>Provide <tt>asprintf()</tt> function for (unpatched) Solaris 10.</li>
  562. <li>Make <tt>vpnc-script</tt> mandatory, like it is for <tt>vpnc</tt></li>
  563. <li>Don't set Legacy IP address on tun device; let <tt>vpnc-script</tt> do it.</li>
  564. <li>Detect OpenSSL even without pkg-config.</li>
  565. <li>Stop building static library by default.</li>
  566. <li>Invoke <tt>vpnc-script</tt> with "pre-init" reason to load tun module if necessary.</li>
  567. </ul><br/>
  568. </li>
  569. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.16.tar.gz">OpenConnect v3.16</a></b>
  570. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.16.tar.gz.asc">PGP signature</a>)</i> &#8212; 2012-04-08
  571. <ul>
  572. <li>Fix build failure on Debian/kFreeBSD and Hurd.</li>
  573. <li>Fix memory leak of deflated packets.</li>
  574. <li>Fix memory leak of zlib state on CSTP reconnect.</li>
  575. <li>Eliminate <tt>memcpy()</tt> calls on packets from DTLS and tunnel device.</li>
  576. <li>Use <tt>I_LINK</tt> instead of <tt>I_PLINK</tt> on Solaris to plumb interface for Legacy IP.</li>
  577. <li>Plumb interface for IPv6 on Solaris, instead of expecting <tt>vpnc-script</tt> to do it.</li>
  578. <li>Refer to <a href="vpnc-script.html">vpnc-script</a> and <a href="mail.html">help</a> web pages in openconnect output.</li>
  579. <li>Fix potential crash when processing libproxy results.</li>
  580. <li>Be more conservative in detecting libproxy without pkg-config.</li>
  581. </ul><br/>
  582. </li>
  583. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.15.tar.gz">OpenConnect v3.15</a></b>
  584. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.15.tar.gz.asc">PGP signature</a>)</i> &#8212; 2011-11-25
  585. <ul>
  586. <li>Fix for reading multiple packets from Solaris tun device.</li>
  587. <li>Call <tt>bindtextdomain()</tt> to ensure that translations are found in install path.</li>
  588. </ul><br/>
  589. </li>
  590. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.14.tar.gz">OpenConnect v3.14</a></b>
  591. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.14.tar.gz.asc">PGP signature</a>)</i> &#8212; 2011-11-08
  592. <ul>
  593. <li>Move executable to <tt>$prefix/sbin</tt>.</li>
  594. <li>Fix build issues on OSX, OpenIndiana, DragonFlyBSD, OpenBSD, FreeBSD &amp;amp; NetBSD.</li>
  595. <li>Fix non-portable <tt>(void *)</tt> arithmetic.</li>
  596. <li>Make more messages translatable.</li>
  597. <li>Attempt to make NLS support more portable (with fewer dependencies).</li>
  598. </ul><br/>
  599. </li>
  600. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.13.tar.gz">OpenConnect v3.13</a></b>
  601. <i>(<a href="https://www.infradead.org/openconnect/download/openconnect-3.13.tar.gz.asc">PGP signature</a>)</i> &#8212; 2011-09-30
  602. <ul>
  603. <li>Add <tt>--cert-expire-warning</tt> option.</li>
  604. <li>Give visible warning when server dislikes client SSL certificate.</li>
  605. <li>Add localisation support.</li>
  606. <li>Fix build on Debian systems where <tt>dtls1_stop_timer()</tt> is not available.</li>
  607. <li>Fix libproxy detection.</li>
  608. <li>Enable a useful set of compiler warnings by default.</li>
  609. <li>Fix various minor compiler warnings.</li>
  610. </ul><br/>
  611. </li>
  612. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.12.tar.gz">OpenConnect v3.12</a></b> &#8212; 2011-09-12
  613. <ul>
  614. <li>Fix DTLS compatibility with ASA firmware 8.4.1(11) and above.</li>
  615. <li>Fix build failures on GNU Hurd, on systems with ancient OpenSSL,
  616. and on Debian.</li>
  617. <li>Add <tt>--pid-file</tt> option.</li>
  618. <li>Print SHA1 fingerprint with server certificate details.</li>
  619. </ul><br/>
  620. </li>
  621. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.11.tar.gz">OpenConnect v3.11</a></b> &#8212; 2011-07-20
  622. <ul>
  623. <li>Add <tt>Android.mk</tt> file for Android build support</li>
  624. <li>Add logging support for Android, in place of standard <tt>syslog()</tt>.</li>
  625. <li>Switch back to using TLSv1, but without extensions.</li>
  626. <li>Make TPM support optional, dependent on OpenSSL ENGINE support.</li>
  627. </ul><br/>
  628. </li>
  629. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.10.tar.gz">OpenConnect v3.10</a></b> &#8212; 2011-06-30
  630. <ul>
  631. <li>Switch to using GNU autoconf/automake/libtool.</li>
  632. <li>Produce shared library for authentication.</li>
  633. <li>Improve library API to make life easier for C++ users.</li>
  634. <li>Be more explicit about requiring <tt>pkg-config</tt>.</li>
  635. <li>Invoke script with <tt>reason=reconnect</tt> on CSTP reconnect.</li>
  636. <li>Add <tt>--non-inter</tt> option to avoid all user input.</li>
  637. </ul><br/>
  638. </li>
  639. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.02.tar.gz">OpenConnect v3.02</a></b> &#8212; 2011-04-19
  640. <ul>
  641. <li>Install man page in <tt>make install</tt> target.</li>
  642. <li>Add <tt>openconnect_vpninfo_free()</tt> to libopenconnect.</li>
  643. <li>Clear cached <tt>peer_addr</tt> to avoid reconnecting to wrong host.</li>
  644. </ul><br/>
  645. </li>
  646. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.01.tar.gz">OpenConnect v3.01</a></b> &#8212; 2011-03-09
  647. <ul>
  648. <li>Add libxml2 to pkg-config requirements.</li>
  649. </ul><br/>
  650. </li>
  651. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-3.00.tar.gz">OpenConnect v3.00</a></b> &#8212; 2011-03-09
  652. <ul>
  653. <li>Create libopenconnect.a for GUI authentication dialog to use.</li>
  654. <li>Remove auth-dialog, which now lives in the <a href="https://gitlab.gnome.org/GNOME/NetworkManager-openconnect">network-manager-openconnect</a> package.</li>
  655. <li>Cope with more entries in authentication forms.</li>
  656. <li>Add <tt>--csd-wrapper</tt> option to wrap CSD trojan.</li>
  657. <li>Report error and abort if CA file cannot be opened.</li>
  658. </ul><br/>
  659. </li>
  660. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.26.tar.gz">OpenConnect v2.26</a></b> &#8212; 2010-09-22
  661. <ul>
  662. <li>Fix potential crash on relative HTTP redirect.</li>
  663. <li>Use correct TUN/TAP device node on Android.</li>
  664. <li>Check client certificate expiry date.</li>
  665. <li>Implement CSTP and DTLS rekeying <i>(both by reconnecting CSTP)</i>.</li>
  666. <li>Add <tt>--force-dpd</tt> option to set minimum DPD interval.</li>
  667. <li>Don't print <tt>webvpn</tt> cookie in debug output.</li>
  668. <li>Fix host selection in NetworkManager auth dialog.</li>
  669. <li>Use SSLv3 instead of TLSv1; some servers <i>(or their firewalls)</i>
  670. don't accept any <tt>ClientHello</tt> options.</li>
  671. <li>Never include address family prefix on <tt>script-tun</tt> connections.</li>
  672. </ul><br/>
  673. </li>
  674. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.25.tar.gz">OpenConnect v2.25</a></b> &#8212; 2010-05-15
  675. <ul>
  676. <li>Always validate server certificate, even when no extra <tt>--cafile</tt> is provided.</li>
  677. <li>Add <tt>--no-cert-check</tt> option to avoid certificate validation.</li>
  678. <li>Check server hostname against its certificate.</li>
  679. <li>Provide text-mode function for reviewing and accepting "invalid" certificates.</li>
  680. <li>Fix libproxy detection on NetBSD.</li>
  681. </ul><br/>
  682. </li>
  683. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.24.tar.gz">OpenConnect v2.24</a></b> &#8212; 2010-05-07
  684. <ul>
  685. <li>Forget preconfigured password after a single attempt; don't retry infinitely if it's failing.</li>
  686. <li>Set <tt>$CISCO_BANNER</tt> environment variable when running script.</li>
  687. <li>Better handling of passphrase failure on certificate files.</li>
  688. <li>Fix NetBSD build (thanks to Pouya D. Tafti).</li>
  689. <li>Fix DragonFly BSD build.</li>
  690. </ul><br/>
  691. </li>
  692. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.23.tar.gz">OpenConnect v2.23</a></b> &#8212; 2010-04-09
  693. <ul>
  694. <li>Support "Cisco Secure Desktop" trojan in NetworkManager auth-dialog.</li>
  695. <li>Support proxy in NetworkManager auth-dialog.</li>
  696. <li>Add <tt>--no-http-keepalive</tt> option to work around Cisco's incompetence.</li>
  697. <li>Fix build on Debian/kFreeBSD.</li>
  698. <li>Fix crash on receiving HTTP 404 error.</li>
  699. <li>Improve workaround for server certificates lacking SSL_SERVER purpose, so that it also works with OpenSSL older than 0.9.8k.</li>
  700. </ul><br/>
  701. </li>
  702. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.22.tar.gz">OpenConnect v2.22</a></b> &#8212; 2010-03-07
  703. <ul>
  704. <li>Fix bug handling port numbers above 9999.</li>
  705. <li>Ignore "<tt>Connection: Keep-Alive</tt>" in HTTP/1.0 to work around server bug with certificate authentication.</li>
  706. <li>Handle non-standard port (and full URLs) when used with NetworkManager.</li>
  707. <li>Cope with relative redirect and form URLs.</li>
  708. <li>Allocate HTTP receive buffer dynamically, to cope with arbitrary size of content.</li>
  709. <li>Fix server cert SHA1 comparison to be case-insensitive.</li>
  710. <li>Fix build on Solaris and OSX <i>(<tt>strndup()</tt>, <tt>AI_NUMERICSERV</tt>).</i></li>
  711. <li>Fix exit code with <tt>--background</tt> option.</li>
  712. </ul><br/>
  713. </li>
  714. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.21.tar.gz">OpenConnect v2.21</a></b> &#8212; 2010-01-10
  715. <ul>
  716. <li>Fix handling of HTTP 1.0 responses with keepalive <a href="https://bugzilla.redhat.com/show_bug.cgi?id=553817"><i>(RH#553817)</i></a>.</li>
  717. <li>Fix case sensitivity in HTTP headers and hostname comparison on redirect.</li>
  718. </ul><br/>
  719. </li>
  720. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.20.tar.gz">OpenConnect v2.20</a></b> &#8212; 2010-01-04
  721. <ul>
  722. <li>Fix use-after-free bug in NetworkManager authentication dialog <a href="https://bugzilla.redhat.com/show_bug.cgi?id=551665"><i>(RH#551665)</i></a>.</li>
  723. <li>Allow server to be specified with <tt>https://</tt> URL, including port and pathname (which Cisco calls 'UserGroup')</li>
  724. <li>Support connection through HTTP and SOCKS proxies.</li>
  725. <li>Handle HTTP redirection with port numbers.</li>
  726. <li>Handle HTTP redirection with IPv6 literal addresses.</li>
  727. </ul><br/>
  728. </li>
  729. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.12.tar.gz">OpenConnect v2.12</a></b> &#8212; 2009-12-07
  730. <ul>
  731. <li>Fix buffer overflow when generating useragent string.</li>
  732. <li>Cope with idiotic schizoDNS configurations by not repeating DNS lookup for VPN server on reconnects.</li>
  733. <li>Support DragonFlyBSD. Probably.</li>
  734. </ul><br/>
  735. </li>
  736. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.11.tar.gz">OpenConnect v2.11</a></b> &#8212; 2009-11-17
  737. <ul>
  738. <li>Add IPv6 support for FreeBSD.</li>
  739. <li>Support "split tunnel" mode for IPv6 routing.</li>
  740. <li>Fix bug where client certificate's MD5 was only given to the
  741. CSD trojan if a PKCS#12 certificate was used.</li>
  742. </ul><br/>
  743. </li>
  744. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.10.tar.gz">OpenConnect v2.10</a></b> &#8212; 2009-11-04
  745. <ul>
  746. <li>OpenSolaris support.</li>
  747. <li>Preliminary support for IPv6 connectivity.</li>
  748. <li>Fix session shutdown on exit.</li>
  749. <li>Fix reconnection when TCP connection is closed.</li>
  750. <li>Support for "Cisco Secure Desktop" idiocy.</li>
  751. <li>Allow <tt>User-Agent:</tt> to be specified on command line.</li>
  752. <li>Fix session termination on disconnect.</li>
  753. <li>Fix recognition of certificates from OpenSSL 1.0.0.</li>
  754. </ul><br/>
  755. </li>
  756. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.01.tar.gz">OpenConnect v2.01</a></b> &#8212; 2009-06-24
  757. <ul>
  758. <li>Fix bug causing loss of DTLS (and lots of syslog spam about it)
  759. after a CSTP reconnection.</li>
  760. <li>Don't apply OpenSSL certificate chain workaround if we already
  761. have "extra" certificates loaded (e.g. from a PKCS#12 file).</li>
  762. <li>Load "extra" certificates from <tt>.pem</tt> files too.</li>
  763. <li>Fix SEGV caused by freeing certificates after processing cert
  764. chain.</li>
  765. </ul><br/>
  766. </li>
  767. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-2.00.tar.gz">OpenConnect v2.00</a></b> &#8212; 2009-06-03
  768. <ul>
  769. <li>Add OpenBSD and FreeBSD support.</li>
  770. <li>Build with OpenSSL-0.9.7 (Mac OS X, OpenBSD, etc.)</li>
  771. <li>Support PKCS#12 certificates.</li>
  772. <li>Automatic detection of certificate type (PKCS#12, PEM, TPM).</li>
  773. <li>Work around OpenSSL trust chain issues (<a href="http://rt.openssl.org/Ticket/Display.html?id=1942&amp;amp;user=guest&amp;amp;pass=guest">RT#1942</a>).</li>
  774. <li>Allow PEM passphrase to be specified on command line.</li>
  775. <li>Allow PEM passphrase automatically generated from the <tt>fsid</tt> of the file system on which the certificate is stored.</li>
  776. <li>Fix certificate comparisons (in NM auth-dialog and <tt>--servercert</tt> option) to use SHA1 fingerprint, not signature.</li>
  777. <li>Fix segfault in NM auth-dialog when changing hosts.</li>
  778. </ul><br/>
  779. </li>
  780. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-1.40.tar.gz">OpenConnect v1.40</a></b> &#8212; 2009-05-27
  781. <ul>
  782. <li>Fix validation of server's SSL certificate when NetworkManager runs openconnect as an unprivileged user (which can't read the real user's trust chain file).</li>
  783. <li>Fix double-free of DTLS Cipher option on reconnect.</li>
  784. <li>Reconnect on SSL write errors</li>
  785. <li>Fix reporting of SSL errors through syslog/UI.</li>
  786. </ul><br/>
  787. </li>
  788. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-1.30.tar.gz">OpenConnect v1.30</a></b> &#8212; 2009-05-13
  789. <ul>
  790. <li>NetworkManager auth-dialog will now cache authentication form options.</li>
  791. </ul><br/>
  792. </li>
  793. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-1.20.tar.gz">OpenConnect v1.20</a></b> &#8212; 2009-05-08
  794. <ul>
  795. <li>DTLS cipher choice fixes.</li>
  796. <li>Improve handling of authentication group selection.</li>
  797. <li>Export more information to connection script.</li>
  798. <li>Add <tt>--background</tt> option to dæmonize after connection.</li>
  799. <li>Detect TCP connection closure.</li>
  800. </ul><br/>
  801. </li>
  802. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-1.10.tar.gz">OpenConnect v1.10</a></b> &#8212; 2009-04-01
  803. <ul>
  804. <li>NetworkManager UI rewrite with many improvements.</li>
  805. <li>Support for "UserGroups" where a single server offers multiple
  806. configurations according to the URL used to connect.</li>
  807. </ul><br/>
  808. </li>
  809. <li><b><a href="https://www.infradead.org/openconnect/download/openconnect-1.00.tar.gz">OpenConnect v1.00</a></b> &#8212; 2009-03-18
  810. <ul>
  811. <li>First non-beta release.</li>
  812. </ul>
  813. </li>
  814. </ul>
  815. <INCLUDE file="inc/footer.tmpl" />
  816. </PAGE>