Back

Duo Security
Patches for Duo Security Authentication Proxy x64
Windows
12 patches available
The Duo Authentication Proxy is an on-premises software service that receives authentication requests from your local devices and applications via RADIUS or LDAP, optionally performs primary authentication against your existing LDAP directory or RADIUS authentication server, and then contacts Duo to perform secondary authentication.
Duo Security Authentication Proxy x64 Version 6.5.1
Release Date
5/27/2025
Bug Fix?
No
Minor Release?
Yes
Patch Notes

Version 6.5.1 - May 27; 2025$$$Adds support for new Duo certificate authorities.
Duo Security Authentication Proxy x64 Version 6.5.0
Release Date
4/23/2025
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.5.0 - April 23; 2025$$$IPv6 support for communicating with other on-premises applications; servers; and devices. Please note that communication with Duos cloud service will still resolve the API hostname to an IPv4 address.$$$Connections to DNS hostnames will now honor multiple IP addresses and choose the fastest connection.$$$No longer prints ModuleNotFoundError during successful build.$$$Fix logfile rotation when an extra file exists in log directory$$$Improves handling of None values in HTTP client.$$$Add rate-limiting logic for 429 errors.$$$Upgrade Python to 3.11.10 to address multiple CVEs; such as CVE-2024-6923 and CVE-2024-4030.$$$Upgrade to Cryptography 43.01 / OpenSSL 3.3.2 to address CVE-2024-6119.$$$Updates to various third party dependencies.
Duo Security Authentication Proxy x64 Version 6.4.2
Release Date
10/21/2024
Bug Fix?
No
Minor Release?
Yes
Patch Notes

Version 6.4.2 - October 21; 2024$$$Adds the configuration option force_message_authenticator to radius_server modules.$$$Set force_message_authenticator to true to force the Authentication Proxy to include a message-authenticator attribute in reply packets.$$$Ensures that reply packets containing a message-authenticator attribute send that as the first attribute.
Duo Security Authentication Proxy x64 Version 6.4.1
Release Date
5/8/2024
Bug Fix?
Yes
Minor Release?
No
Patch Notes

Version 6.4.1 - May 8; 2024$$$Fixes a resource leak related to failed TLS connections in ldap_server_auto.
Duo Security Authentication Proxy x64 Version 6.4.0
Release Date
4/30/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.4.0 - April 30; 2024$$$Fixes unnecessarily strict Connectivity Tool validation of ldap_server_auto SSL certificates.$$$Improves logged error messaging for AD DIR_ERROR responses.$$$The Authentication Proxy Manager now displays additional error information in certain failure scenarios.$$$Updates the internal build process to use scoped package names.$$$Upgrade to Cryptography 42.0.5 / OpenSSL 3.2.1 to address CVE-2024-26130; CVE-2023-50782; and CVE-2024-0727.$$$Upgrade Python to 3.11.9 to address CVE-2023-6597 and CVE-2024-0450.$$$Upgrade OpenSSL FIPS module to 3.0.9 to address CVE-2023-1255.$$$Updates various internal dependencies.$$$These dependency updates affect use of the Duo Authentication Proxy Manager tool on Windows Server versions 2012 R2 and older; which have reached end-of-support status with both Duo and Microsoft. Please see the Duo End of Sale; Last Date of Support; and End of Life Policy for more information.
Duo Security Authentication Proxy x64 Version 6.3.0
Release Date
2/6/2024
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.3.0 - February 6; 2024$$$Fixes sort order of factors from preauth result.$$$Fixes OpenSSL error when enabling FIPS mode on certain systems.$$$Updates Python to 3.11.7 to address CVE-2023-36632; CVE-2023-24329; CVE-2023-40217; CVE-2023-27043; and CVE-2007-4559.$$$Updates various internal dependencies to resolve CVEs including CVE-2023-49083; CVE-2023-46137; CVE-2022-40898; CVE-2021-32559; and CVE-2022-42969.
Duo Security Authentication Proxy x64 Version 6.2.0
Release Date
11/28/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.2.0 - November 28; 2023$$$Connectivity checker no longer rejects ECC SSL keys.$$$Improves integration with systemd on Linux systems.$$$Improves handling of corrupted SSO configuration file.$$$IFrame reconfiguration script no longer creates duplicate configuration sections.$$$Resolves various CVEs including CVE-2023-5363; CVE-2023-4807; and CVE-2022-40897.
Duo Security Authentication Proxy x64 Version 6.1.0
Release Date
9/19/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.1.0 - September 19; 2023$$$Restores the default for allow_concat to false in the radius_server_eap section.$$$Fixes various bugs in radius_server_eap functionality.$$$No longer logs configured server sections twice at startup.$$$Authentication Proxy upgrades no longer fail when there is a subdirectory inside the conf directory.$$$The Windows service now correctly installs/uninstalls when there is an invalid authproxy.cfg.$$$Provides a utility script to assist with converting radius_server_iframe sections to radius_server_auto. See Guide to Duos iFrame Reconfiguration Script.$$$Updates Cryptography to 41.0.3.$$$Updates OpenSSL to 3.1.2.
Duo Security Authentication Proxy x64 Version 6.0.2
Release Date
7/24/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.0.2 - July 24; 2023$$$$$$ The value for allow_concat in the radius_server_eap section now correctly defaults to True.$$$ The Authentication Proxy connectivity tool and Authentication Proxy Manager now raise an exception if the Authentication Proxy is given a password-protected certificate.$$$ Fixed a resource leak related to failed TLS connections.$$$
Duo Security Authentication Proxy x64 Version 6.0.2
Release Date
7/24/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 6.0.2 - July 24; 2023$$$$$$ The value for allow_concat in the radius_server_eap section now correctly defaults to True.$$$ The Authentication Proxy connectivity tool and Authentication Proxy Manager now raise an exception if the Authentication Proxy is given a password-protected certificate.$$$ Fixed a resource leak related to failed TLS connections.$$$
Duo Security Authentication Proxy x64 Version 5.8.0
Release Date
2/15/2023
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Version 5.8.0 - February 15; 2023$$$Removes git commit hashes from binaries and folder names.$$$The authproxy_support script now honors the log_dir configured in [main] section of authproxy.cfg; --log-dir script argument removed.$$$Sends a users distinguishedName (DN) back to Duo Single Sign-On on a failed SSO AD authentication.$$$Nested conf directories underneath the Authentication Proxys conf directory are no longer valid (i.e. /opt/duoauthproxy/conf/conf/certs.crt).$$$Fixed a bug causing Proxy-State to be duplicated in RADIUS responses.$$$Updated to Twisted 22.4.0 to resolve CVE-2022-24801.$$$Additional bug fixes and enhancements.
Duo Security Authentication Proxy x64 Version 5.7.4
Release Date
11/8/2022
Bug Fix?
Yes
Minor Release?
Yes
Patch Notes

Improved logging for LDAP timeouts.$$$The Authentication Proxy Manager and connectivity tool now warn against use of clear transport in ad_client with certificates specified.$$$Removes the misleading no reply message in packet RADIUS error message to reduce confusion while troubleshooting authentication failures.$$$No longer duplicates the proxy-state RADIUS attribute when both the RADIUS client and server configuration sections specify pass_through_all=true.$$$The connectivity tool no longer exits prematurely when it fails to connect to a RADIUS server that is not running.$$$Fixed an issue that could result in multiple redundant connections to the Duo SSO service in certain race conditions.
Duo Security Authentication Proxy x64 Version 5.7.3
Release Date
8/30/2022
Bug Fix?
Yes
Minor Release?
No
Patch Notes

Fixed a bug where the Authentication Proxy incorrectly included a reply message in EAP packets.
Duo Security Authentication Proxy x64 Version 5.7.3
Release Date
8/30/2022
Bug Fix?
Yes
Minor Release?
No
Patch Notes

Fixed a bug where the Authentication Proxy incorrectly included a reply message in EAP packets.
Interested in automating patching for Duo Security Authentication Proxy x64?