This new release candidate for 2.2.0 includes a new marking module, mark_flag, which can be used to mark packet using indications stored in the acl. It also features a new decision mode (when prio_to_nok is set to 2). This permits to have a true ordering in acls.
The full changelog is as follows:
By default, do not compile pam_nufw anymore.
nutcpc does now check presence of certificate authority.
Complete rewrite of debian packaging.
log_nuprelude: Add user info to idmef message when there is authentication failure.
nuauth: implement acl ordering (prio_to_nok=2)
mark_flag: new module used to modify packet mark using acl indication