Skip to content

Releases: OpenIDC/mod_oauth2

release 4.1.0

06 Jan 05:01

Choose a tag to compare

The -2 RPM packages below are signed with the following RSA PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBGh53lgBCADCyoOkfnE5h5rBLlf02oFpI/z2vUXK5W4T56xnNPu0/iIOxbBk
YX9rSypZFhfjv28lhGgelWEg28Ab/Yxs6l0obCgDEuFUDQ5Dv+N+YSMy67vtLwYW
9LM5p9fMN9bXOa62PwvtzRzh+xRyRBcIfMacGJC+SqUK6QhzC0lNwCsr1OaWjzon
mkaodwrloNMxEZVvFn63PvuQDZ3wwQty+0XpYiiChMssGBn6nmPDQJ7pDtQDkhfD
Z5FKY6K7AQJ4fneiVCLGngPBwTXBGcfWa+Y0HCS2ghQwDO6jYXd5GjowVDTjfMK3
QJ3e26Ox9X3V0Fl04R1i5EthEkAWGfy1lksvABEBAAG0HU9wZW5JREMgPHN1cHBv
cnRAb3BlbmlkYy5jb20+iQFRBBMBCgA7FiEEFdjWJA1IGDkAITSxnyZY1L0OSOMF
Amh53lgCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQnyZY1L0OSONG
Jgf+II0wG96R0g28Kp+R4AYzSdX0CEqr6OhwHHw4cFpLsHxZNhojo7I4OnLKEdfc
lFl37rE+hG3QpzD/b4S/fpPjd4hcLkguBQxtdxqZZVAIT8HWbveHRkI8MNnjOPwv
Hy6jBncMs1IT/URV2si/Q34+PLo8tvo/lXNa16svVl2DoYXO8MCszgCE1bx055EF
XPh4Teu5Y4OLHECSicMxrmN746dAD121zy4bLLx9mZ0erhLjvkj1vkFmlHFKyvwY
/pbSqXs9hW/wweW1oQ/xEIJWWS71PeoutUBjr0WC4sILnR5PBPZplgNh297Qex6g
qaW3io0tCH9KxU1tXYn/iL/hbQ==
=mlOy
-----END PGP PUBLIC KEY BLOCK-----

release 4.0.0

22 Aug 11:29

Choose a tag to compare

release 3.4.0

05 Jun 18:57

Choose a tag to compare

Packaging

release 3.3.1

21 Jan 19:23

Choose a tag to compare

Edit: on May 11, 2023 the Debian/Ubuntu packages were updated from 3.3.1-1 to 3.3.1-2 because of packaging bug OpenIDC/liboauth2#46

Bugfixes

  • clean WWW-Authenticate header in main request as well if this is a subrequest; closes #42
    this avoids the WWW-Authenticate header to be sent in HTTP 200 responses; thanks @ErmakovDmitriy

Packaging

release 3.3.0

06 Dec 13:11

Choose a tag to compare

Features

  • depend on liboauth2 >= 1.4.5.2

Packaging

release 3.2.3

27 Jul 18:23

Choose a tag to compare

Bugfixes

  • depend on liboauth2 >= 1.4.5 with multi-treading fix for OAuth2TokenVerify jwk <key>, see #23

Packaging

  • change configure.ac to find Apache flags correctly

release 3.2.2

07 Jun 10:40

Choose a tag to compare

Bugfixes

  • depend on liboauth2 1.4.2.1 with fixed iat slack validation defaults
  • set WWW-Authenticate environment variable on scope requirement mismatch to allow for complex Require logic; see also OpenIDC/mod_auth_openidc#572

Packaging

release 3.2.1

01 Feb 10:49

Choose a tag to compare

Features

  • depend on liboauth2 1.4.1 with support for RFC 8705 mTLS Client Certificate bound access tokens

Bugfixes

  • depend on liboauth2 1.4.1 with fix for Apache semaphore/shared memory restart issues

Packaging

release 3.2.0

22 Dec 11:13

Choose a tag to compare

Features

  • depend on liboauth2 >= 1.4.0

Packaging

release 3.1.0

27 Feb 10:14

Choose a tag to compare

Features

  • depend on liboauth2 >= 1.2.0 with new request header API

Packaging