Duo Authentication Proxy Upgrade - 夜莺博客

Duo Authentication Proxy Upgrade

原文:Duo Authentication Proxy Upgrade — theDXT (Daniel Keer)

Duo Authentication Proxy is a very useful way to add MFA to LDAP and RADIUS. It is also a way to sync your users with Duo. You can install Duo Authentication Proxy on Windows or Linux.

While older versions of Duo Auth Proxy typically keep working, a Duo certificate expires in February 2026, and you will need to upgrade to version 6.5.1 or higher to avoid being affected.

In this post, I will show you step by step how to upgrade the Duo Authentication Proxy for Windows.

What the Duo Authentication Proxy Actually Does

The Duo Authentication Proxy is an on-premises service that sits between the systems that want to authenticate users and the Duo cloud service. It exists for one reason: a large number of devices and applications speak RADIUS or LDAP but have no way to talk to a modern web API. A VPN concentrator, a switch with administrative login, a Linux host using PAM, or a legacy application all fall into that category. The proxy accepts their RADIUS or LDAP request, checks the user password against your existing directory or RADIUS server if you configure it to, and then contacts Duo to complete the second factor.

That gives you three useful capabilities in one process:

  • Multi-factor authentication for anything that can speak RADIUS or LDAP, without replacing the device or the application.
  • Primary authentication against Active Directory, OpenLDAP or another RADIUS server, so passwords stay where they already are.
  • User synchronisation from your directory up to Duo, so accounts and phones stay in step without manual work.

The proxy runs on Windows or Linux. On Windows the service is named Duo Security Authentication Proxy Service, and the short name used by command line tools is DuoAuthProxy. On Linux the service is duoauthproxy under systemd. Configuration lives in authproxy.cfg in the conf folder of the installation, which on Windows is C:\Program Files\Duo Security Authentication Proxy\conf\authproxy.cfg and on Linux is /opt/duoauthproxy/conf/authproxy.cfg. Logs land in the log subfolder of the same installation directory, so on a modern Windows build they are in C:\Program Files\Duo Security Authentication Proxy\log, with /opt/duoauthproxy/log on Linux.

Because the proxy sits directly in the login path, an upgrade is a change to production authentication. Every login that depends on it stops working while the service is stopped, which is why the planning steps below matter as much as the installer wizard itself.

Why the February 2026 Certificate Expiry Matters

Older builds of the Duo Authentication Proxy carry a bundled certificate that the proxy uses when it establishes its connection to the Duo service. Duo has announced that this certificate expires in February 2026. Once it does, a proxy running an affected build can no longer complete its outbound connection to the Duo cloud, even though everything else on the server looks healthy.

The failure mode is worth understanding, because it is not obvious from the server side. The proxy keeps accepting RADIUS or LDAP requests, and primary authentication against Active Directory still succeeds, so the password check works exactly as it always has. What breaks is the second factor, because that half of the transaction needs to reach Duo. Depending on how you configured the proxy and the application behind it, one of two things then happens:

  • If the application fails closed, every user protected by that proxy is unable to log in. That is a total outage of the services behind the proxy.
  • If the application fails open, users get in without completing the second factor. That is quieter, and considerably worse from a security point of view, because you lose MFA without any visible error.

The fix is to run Duo Authentication Proxy 6.5.1 or later, which trusts the replacement certificate chain. This is not something you can patch by editing authproxy.cfg on an old build, because the trust anchor is part of the shipped proxy components rather than something you supply. Upgrading the software is the supported remedy, and doing it during a planned window is far less painful than discovering it during an unplanned incident.

Planning the Upgrade

Work through the following before you touch any server:

  • Inventory every host running the Duo Authentication Proxy. Environments commonly run more than one, for example a pair behind a load balancer for VPN RADIUS or separate instances for LDAP primary authentication and directory sync.
  • Record the current version on each host. On Windows, query the installed applications, or read the last Init Complete line in authproxy.log, which prints the running version. On Linux, run the package manager query or check the same log line.
  • Read the release notes for the whole range of versions between your current build and your target build, not just the newest one. Some releases change behaviour or configuration in ways that need an adjustment first.
  • Confirm from Duo whether you can jump straight to the target version from your current one, because not every upgrade path is supported.
  • Download the installer from Duo and record its hash. The always-current Windows installer URL is https://dl.duosecurity.com/duoauthproxy-latest.exe, which is convenient for automation but always verify what you actually get.
  • Book a maintenance window that covers the services behind the proxy: the VPN, the switches, the Linux SSH estate, or whatever else depends on it.
  • Back up the conf and log folders before you start. The configuration contains integration keys, secret keys and any bind account credentials, so store the backup somewhere encrypted and access-controlled rather than on a share anyone can read.
  • Upgrade one instance at a time. If two proxies sit behind a load balancer, take one out of service, upgrade and test it, then return it and repeat for the second. That way the estate never has zero working proxies.

If the same change window also covers the end-user side of Duo, note that the Windows Logon component follows a completely different installer, which is covered in Install or Upgrade Duo Authentication for Windows Logon. The identity provider side of the house, including single sign-on, is covered separately in Windows Admin Center SSO.

The Process

  • Review the release notes for each Duo Authentication Proxy version between your current and target versions.

Here are the Duo Authentication Proxy release notes.

  • Check the Duo documentation to confirm if you can upgrade directly to the target version.

Typically, you can skip versions when upgrading, but some versions introduce changes that may affect compatibility or functionality, and not all upgrades are backwards compatible. Here is the Duo documentation about skipping versions of the Duo Auth Proxy.

  • Download the new version of the Duo Authentication Proxy.

An always current URL you can use is https://dl.duosecurity.com/duoauthproxy-latest.exe

  • Connect to your Duo Auth Proxy server.
  • Open Services.

Image 1

  • Stop the service named Duo Security Authentication Proxy Service.

Image 2

  • Back up the conf and log folders of the Duo Auth Proxy installation.

Typically, they are located in the C:\Program Files\Duo Security Authentication Proxy folder.

Store the backup securely, as it contains your configuration’s passwords and secrets.

Image 3

  • Start the service named Duo Security Authentication Proxy Service.

Image 4

  • Run the new Duo Auth Proxy installer as administrator.

Image 5

  • Click Nextto start the upgrade installation wizard.

Image 6

  • Select the features you want to upgrade, then click Install.

Image 7

  • Wait while Duo Auth Proxy is upgraded.

Image 8

  • During the upgrade, the connectivity tool will run. Review the connectivity tool output. If all is good, press enter.

Image 9

  • Click Nextto complete the install.

Image 10

  • Click Finishto close the Duo Authentication Proxy upgrade installation wizard.

Image 11

  • Test your Duo Auth Proxy setup to make sure everything is working as expected.

If you have more than one Duo Auth Proxy server, you’ll need to repeat the process for each of them.

That’s all it takes to upgrade the Duo Authentication Proxy on Windows.

If you want to learn more about the Duo Authentication Proxy upgrade, see the Duo documentation.

If you want to read more about the Duo certificate expiry, here is the Duo support article.

Verifying the Upgrade

An upgrade is not finished when the wizard closes. Verify the running version, the service state and an actual authentication before you call it done.

The quickest version check on Windows is to query the installed application entries in the registry. Both the 64-bit and the 32-bit uninstall keys are worth checking, because the proxy has lived in both locations across its lifetime:

$paths = @(
  'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\*',
  'HKLM:\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\*'
)
Get-ItemProperty $paths -ErrorAction SilentlyContinue |
  Where-Object { $_.DisplayName -like 'Duo Authentication*' } |
  Select-Object DisplayName, DisplayVersion

Confirm the service is running and set to start automatically, so a reboot does not silently take authentication down:

Get-Service 'Duo Security Authentication Proxy Service' |
  Select-Object Name, Status, StartType

The log file is the most trustworthy source, because it reports the version the proxy is actually executing rather than the version that happens to be registered with the installer. Look for the most recent Init Complete line:

Select-String -Path 'C:\Program Files\Duo Security Authentication Proxy\log\authproxy.log' `
  -Pattern 'Init Complete' | Select-Object -Last 1

If the version is right but you want to be certain the proxy can still reach Duo, enable debug logging temporarily by adding debug=true under a [main] section at the top of authproxy.cfg, restart the service, perform a test login, then remove the line again. Debug output is verbose and should not be left on in production. On Linux, the equivalent restart is a systemctl restart of duoauthproxy, and on Windows the same effect can be had from an elevated command prompt:

net start DuoAuthProxy

Finally, test a real login. Authenticate through one of the clients the proxy protects, ideally with an account you control, and confirm that primary authentication succeeds and that the push, passcode or phone call completes. If you have SIEM logging enabled through log_auth_events, check authevents.log for the corresponding allow entries, which give you both stages of the authentication in structured form.

Troubleshooting the Upgrade

Most issues after an in-place upgrade fall into a small number of categories.

The service does not start

Check the Windows Application event log for errors from the source DuoAuthProxy, and read the tail of authproxy.log. The usual cause is a configuration file that the installer replaced or reformatted, or a permissions problem on the conf and log folders. Restore authproxy.cfg from the backup you took before the upgrade, compare it against the shipped example configuration, and check the release notes for any setting that changed meaning.

Primary authentication works but the second factor fails

This points at the connection between the proxy and Duo rather than at your directory. Confirm the server can reach its api-xxxxxxxx.duosecurity.com host on port 443, and that no outbound filtering rule has been tightened since the last successful login. Check that the server clock is correct, because a significant time skew breaks TLS validation. On a freshly upgraded host, also confirm the integration key and secret key in the configuration match the application in the Duo Admin Panel.

Users who were working yesterday are denied today

Verify that directory sync still runs. If the proxy instance that performs the synchronisation is the one you upgraded last, users may be present in Duo but not updated. The sync interval is set in the configuration, and authproxy.log records each sync attempt.

You need to roll back

Keep the previous installer until the change is signed off. Uninstall the upgraded version, reinstall the previous one, and restore the conf folder from your backup. Because the configuration is a plain file, rollback is usually a ten-minute operation as long as the backup exists.

PowerShell Scripts

I created a few PowerShell scripts to assist with the Duo Auth Proxy upgrade.

The PowerShell scripts I created perform the following tasks.

  • Checks if Duo Auth Proxy is installed and which version is installed
  • A silent install of Duo Auth Proxy.
  • An upgrade script that is a combination of the Duo Auth Proxy installation check and the Duo Auth Proxy install script that performs both in the same script, but only takes action if Duo Auth Proxy is installed and the version is less than the defined version.

Image 12

You can find all 3 scripts on my GitHub. https://github.com/thedxt/Duo

Summary

Upgrading the Duo Authentication Proxy on Windows is a short piece of work once the preparation is done, but it is a change to a service that is directly in the login path, so it deserves a maintenance window and a verification step at the end.

  • Target version 6.5.1 or later, so the proxy is not caught out by the Duo certificate that expires in February 2026.
  • Stop the service, back up the conf and log folders, then run the new installer as an administrator.
  • Read the connectivity tool output during the install, and confirm the version, the service state and a real authentication afterwards.
  • Upgrade one proxy at a time, keep the previous installer for a rollback, and only close the change once a live login has succeeded.

The PowerShell approach in the section above is the same sequence with the interactive parts removed, which is what makes it usable across an estate of proxy servers. If you use an earlier revision of the Windows Logon installer rather than the EXE installer described in the companion post, then Upgrading Duo Authentication for Windows Logon covers that older MSI-based path.