January, 2012: ClearBox TACACS+ RADIUS Server 4.5 released:
- New accounting pseudo-attributes available for logging
- Windows Vista/7/2008 compatibility improved
- Numerous fixes
December, 2010: ClearBox TACACS+ RADIUS Server 4.4 released:
- Working as a RADIUS and TACACS server simultaneously
- Dialogic VSA attributes handling
- Debug logging for better troubleshooting
April, 2009 ClearBox TACACS RADIUS Server 3.2
with Windows Vista and Windows 2008 support.
November, 2008 ClearBox TACACS RADIUS Server 3.1.6
with fixes to 3.1 released.
April, 2008 ClearBox TACACS RADIUS Server 3.1
released.
- Several TACACS+ realm rules may be turned on in any combination.
- TACACS+ client group may be used as a realm rule.
February, 2008 ClearBox TACACS RADIUS Server 3.0
released.
- New optimized TACACS core with no limitations on the number of concurrent NAS connections.
- NAS's may be included in a NAS group. A group name may be used in any LDAP/SQL operation.
- The server may initiate the password change sequence (for TACACS+ ASCII authentication).
- New extra TACACS+ authentication check via LDAP search.
- A realm may be limited by a set of TACACS+ clients.
- A TACACS+ client may be restricted by a set of realms.
September, 2007 ClearBox TACACS RADIUS Server 2.8
released.
- A realm may be selected by Windows domain or local group membership (TACACS+ server mode).
- Alerts are sent to a syslog server when a user authentication fails (TACACS+ server mode).
- Simplified installation process.
April, 2007 ClearBox TACACS RADIUS Server 2.7
released.
- LDAP directories authentication (TACACS server only).
- Support for hashed passwords.
November, 2005 ClearBox Server v2.6 released.
- RADIUS proxy engine redesigned for better speed and reliability.
- TACACS authorization requests may be logged into a database.
- TACACS realms may be selected by a requested service or
privilege level.
- Error information now includes the source realm name.
April, 2005 ClearBox Server v2.5 released.
- TACACS clients information (IP addresses and shared secrets)
may be stored in a data source.
- State servers works for TACACS sessions, enabling control
over concurrent sessions number.
- Command authorization becomes easier with the new interface.
Separate lists of allowed and denied commands are maintained.
- TACACS-specific authentication process may control the
requested privilege level, requested service, port or remote
address.
- TACACS realms may be selected according to user name format.
Realm part can be stripped off user names.
- $f may be use in authentication packet loggers to denote
the address a packet was forwarded to.
- Several enhances to the RADIUS proxy engine.
- Server statistics includes average time of processing
a RADIUS request.
- ClearBox can bind to a specific IP address.
- Arbitrary attributes can be added to Access-Reject responses.
- Several recordsets are supported for each SQL command
in Black, Check and Response authorization lists.
- State servers can handle interim accounting records.
- $s key (number of concurrent sessions for a user) may
be used in Black, Check and Response authorization lists.
November, 2004 ClearBox Server v2.4.5 released.
- Performance and stability improvements and fixes.
August, 2004 ClearBox Server v2.4 released.
- ClearBox now supports proxy filtering. It may add, remove
or change any attributes and values in the packets being
forwarded to or received from a remote RADIUS server.
- Evaluation period doesn't end now after the server uninstallation.
If you install it again before 30 days are over since the
first installation, the server will work properly.
- A data source has the new option: Automatic reconnection
on errors. It allows the server establishing a new connection
when some operation has ended with a connection error.
- Cisco and Quintum date/time attributes (h323-setup-time,
h323-connect-time and h323-disconnect-time) are handled
and formatted automatically.
- New authorization list added: it's possible now to include
arbitrary attributes in Access-Reject packets.
- ClearBox enhances its failover resistance and automatically
restarts after a specific number of severe error occurs.
- ClearBox performs the same attribute handling of Quintum
h323 attributes as it does for Cisco attributes.
- A user may now change his password during ASCII TACACS+
logon.
- ClearBox may merge several 'cmd-arg' attribute-value pairs
sent in an authorization request into one 'cmd' AV pair.
March, 2004 ClearBox Server v2.3 released.
- General Extension now replaces Advanced Extension used
for TACACS+ processing. All settings are now edited with
General Extension Configurator in the same manner as for
RADIUS protocol. Multiple data sources and realms are supported;
full support of TACACS+ authorization is implemented.
- Cisco-specific attribute-value pairs, including VoIP attributes,
are automatically handled correctly when specified in accounting
query string.
- Regular expressions may be used for matching attributes
in RADIUS and TACACS+ authorization checks.
- User name may be rewritten according to a regular expression.
- Each realm accounting settings may include more than one
accounting query.
- RADIUS client secrets may be queried by the server at
run-time via SQL queries.
- RADIUS realm matching rule may now contain an arbitrary
client IP address with wildcards, so the rule "pick up this
realm for clients with IP addresses [192.168.2.1 - 192.168.255]"
may be configures, for instance.
- Server Manager now can display statistics summary for
all the server clients.
- RADIUS proxy server fixes and improvements.
December, 2003 ClearBox Server v2.2 released.
- General Extension Configurator is enhanced and simplified
without loss of effectiveness.
- Fully integrated with the Advanced ISP Billing system
for Windows.
- Server performance is improved.
- RADIUS tunnel attributes may be specified as "tagged"
with General Extension Configurator.
- New private 'Login-Time' attribute added so to restrict
logon time intervals.
November, 2003 ClearBox Server v2.1 released.
- State servers support introduced enabling double-logon
prevention.
- Fully integrated with the Platypus
Billing System.
- User name can be taken from any RADIUS attribute present
in an access request.
- Authentication protocols (PAP,CHAP, etc.) can be explicitly
allowed or denied in a realm.
- OLE DB data sources support added.
- A realm can be marked as default.
- 'None' realm matching rule added.
October, 2003 ClearBox Server v2.0 released.
- General Server Extension with rich set of capabilities
turning ClearBox into ready-for use, full-featured RADIUS
server. All authentication, authorization and accounting
functions for RADIUS protocol are available just after server
installation. See the
full list of its features.
- Using Class attribute to pass realm names to ClearBox
in accounting requests.
- New Ignore Authenticate-Only option introduced.
- Client Tool enhancements (easier attribute selection with
vendor-selection list, configurable response time-out, restoring
data after restart).
- MS-CHAPv2 Success message correction (now sent with Access-Accept
only).
- Dictionary Parser can be run from command line parameters
for batch updates and installations.
- New RFCs are supported now: RFC 3579, 3580.
May, 2003 ClearBox Server v1.2 released.
- Built-in support of EAP-MD5 authentication protocol.
Existing server extensions may use of it without any changes.
- New advanced tutorial and sample server extension included.
Now users are authenticated against MS Access, MS SQL,
ODBC-compliant data sources, Windows Active Directory and
NT SAM database.
- Server Manager enhancements for easier troubleshooting.
Now it has buttons to open Event Viewer and error log file
quickly.
- PAP passwords may be logged in cleartext to RADIUS packet
dumps.
- IServer2, ILivingstonAccounting and ICSVAccounting
interfaces introduced. They provide new server services
of accounting and debug logging.
- Bug with proxy-forwarding Message-Authenticator attributes
fixed.
January, 2003 ClearBox Server v1.15 released.
- Raw packet data dumping feature introduced.
- Minor bug fixes in Client Tool.
- CHAP and MS-CHAP challenges may now have an arbitrary
size.
- Server returns 'MS-CHAP2-Success' attribute with the right
attribute type.
- Dictionary Parser parses VENDOR directives correctly.
- 'Proxy-State' attributes from request packets are included
in response packets correctly.
October, 2002 ClearBox Server v1.1 released.
- RADIUS/TACACS+ Client Tool for easier testing and debugging.
- Updated and improved documentation.
- Some bugs fixes.
- ICommonExtenderEx and IServer interfaces introduced.
August, 2002. First public release of ClearBox
Server v0.98.
January, 2002. Private release of ClearBox Server.
Pending Changes and Updates
VoIP version of General Extension.
RFC 2619
and 2620
support (SNMP server monitoring).
Performance counters support.
We appreciate your opinion about our product. Please visit
Feedback page if you
have any suggestions on features you would like to see in
the next ClearBox Server releases.