Michael Tremer [Sun, 29 Dec 2013 19:46:41 +0000 (20:46 +0100)]
openssl: Don't propose too weak ciphers.
Michael Tremer [Sat, 28 Dec 2013 16:06:38 +0000 (17:06 +0100)]
pakfire: Prevent an infinite loop with empty server list.
Michael Tremer [Fri, 27 Dec 2013 12:37:40 +0000 (13:37 +0100)]
fifteen: Add openssl and depending packages to core update.
Michael Tremer [Fri, 27 Dec 2013 12:32:38 +0000 (13:32 +0100)]
Merge branch 'openssl-update' into fifteen
Alexander Marx [Fri, 27 Dec 2013 10:09:34 +0000 (11:09 +0100)]
Firewall: remove old firewall scripts in update.sh
Michael Tremer [Fri, 27 Dec 2013 10:29:10 +0000 (11:29 +0100)]
sslh: Move binary to /usr/sbin.
Michael Tremer [Fri, 27 Dec 2013 10:11:29 +0000 (11:11 +0100)]
sslh: Cleanup initscript.
Calling setxtaccess has been removed and never have been used
at this place.
Also, it is checked if the external IP address was properly
read from file.
Erik Kapfer [Mon, 23 Dec 2013 16:38:41 +0000 (17:38 +0100)]
fetchmail: Update to 6.3.26.
Erik Kapfer [Mon, 23 Dec 2013 16:38:41 +0000 (17:38 +0100)]
git: Update to 1.8.5.2.
Erik Kapfer [Mon, 23 Dec 2013 16:38:41 +0000 (17:38 +0100)]
wget: Update to 1.14.
Erik Kapfer [Mon, 23 Dec 2013 16:38:41 +0000 (17:38 +0100)]
Net-SSLeay: Update to 1.55.
Erik Kapfer [Mon, 23 Dec 2013 16:23:17 +0000 (17:23 +0100)]
imspector: Fix build with openssl 1.0.1.
Michael Tremer [Wed, 25 Dec 2013 19:44:24 +0000 (20:44 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into openssl-update
Alexander Marx [Tue, 24 Dec 2013 08:11:49 +0000 (09:11 +0100)]
Firewall: editedt update.sh to get rid of errormessages
Erik Kapfer [Mon, 23 Dec 2013 16:23:17 +0000 (17:23 +0100)]
openssl: Update to 1.0.1e.
Contains also the old openssl-0.9.8 libs for compatibility purposes.
Michael Tremer [Wed, 25 Dec 2013 14:12:34 +0000 (15:12 +0100)]
openvpn: Fix verify script.
Former versions of openvpn called the script where the arguments
in the certificate's common name where separated by /.
Now, those are separated by ", " (comma, space).
Arne Fitzenreiter [Tue, 24 Dec 2013 09:05:07 +0000 (10:05 +0100)]
fifteen: fix rootfile.
Arne Fitzenreiter [Mon, 23 Dec 2013 21:28:27 +0000 (22:28 +0100)]
partresize: fix partresize for new arm image layout.
Arne Fitzenreiter [Mon, 23 Dec 2013 21:27:58 +0000 (22:27 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen
Arne Fitzenreiter [Mon, 23 Dec 2013 21:25:13 +0000 (22:25 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen
Arne Fitzenreiter [Mon, 23 Dec 2013 21:24:23 +0000 (22:24 +0100)]
Merge remote-tracking branch 'stevee/imx6q-wandboard-rbased' into fifteen
Michael Tremer [Mon, 23 Dec 2013 14:18:47 +0000 (15:18 +0100)]
fifteen: Add url-filter.cgi to updater.
This file has been updated for core update 73,
but unfortunately was forgotten to be put into the
updater.
Michael Tremer [Mon, 23 Dec 2013 14:18:12 +0000 (15:18 +0100)]
fifteen: Add credits.cgi to core update.
Alexander Marx [Mon, 23 Dec 2013 14:14:25 +0000 (15:14 +0100)]
Firewall: added amarx to credits.cgi
Michael Tremer [Mon, 23 Dec 2013 13:59:56 +0000 (14:59 +0100)]
Merge remote-tracking branch 'amarx/firewall-beta10' into fifteen
Alexander Marx [Mon, 23 Dec 2013 13:52:33 +0000 (14:52 +0100)]
Firewall: Edited update.sh for fifteen core update
Michael Tremer [Mon, 23 Dec 2013 13:36:19 +0000 (14:36 +0100)]
fifteen: Adjust path to firewall converter scripts.
Alexander Marx [Mon, 23 Dec 2013 10:05:04 +0000 (11:05 +0100)]
Firewall: now it is possible to connect from one ipfire to a green network of another openvpn connected ipfire
Please take care to put this into the docu! One can create DROP rules if
the remote ipfire should NOT be able to connect to the others internal
networks. Therefor you have to take the green interface IP as SOURCE!
Alexander Marx [Mon, 23 Dec 2013 07:08:27 +0000 (08:08 +0100)]
Firewall: changed outgoingfw converter to reflect new counters
Stefan Schantl [Sat, 21 Dec 2013 16:15:44 +0000 (17:15 +0100)]
Kernel: Provide a working kernel configuration for wandboard.
Stefan Schantl [Sat, 21 Dec 2013 16:15:03 +0000 (17:15 +0100)]
Kernel: Add support for PCI Express on wandboard.
When manualy a PCI Express Slot has been soldered to the board, any kind of
PCI-E hardware can be used after loading the pcie_imx kernel module.
Arne Fitzenreiter [Sat, 21 Dec 2013 09:05:39 +0000 (10:05 +0100)]
Merge remote-tracking branch 'origin/next' into fifteen
Arne Fitzenreiter [Fri, 20 Dec 2013 22:31:40 +0000 (23:31 +0100)]
kernel: update to 3.10.25.
Alexander Marx [Fri, 20 Dec 2013 11:53:46 +0000 (12:53 +0100)]
Firewall: when DNAT external port is given and dest port is empty, theres now an errormessage displayed
Alexander Marx [Fri, 20 Dec 2013 10:56:18 +0000 (11:56 +0100)]
Firewall: Now servicegroups and networkgroups can be renamed
Alexander Marx [Fri, 20 Dec 2013 08:40:24 +0000 (09:40 +0100)]
Firewall: added JS to automatically select radiobuttons in fwhosts
Alexander Marx [Thu, 19 Dec 2013 16:32:37 +0000 (17:32 +0100)]
FIrewall: Rewrote complete counters for firewall-groups (hosts,networks, network-groups)
Alexander Marx [Thu, 19 Dec 2013 16:26:12 +0000 (17:26 +0100)]
Firewall: Bugfix - When editing a DNAT rule and setting prot to "all" the port from previus rule was not resettet
Arne Fitzenreiter [Thu, 19 Dec 2013 21:46:48 +0000 (22:46 +0100)]
collectd initskript: parse new lm_sensors config.
Arne Fitzenreiter [Thu, 19 Dec 2013 21:45:34 +0000 (22:45 +0100)]
lm_sensors: update to 3.3.4.
Stefan Schantl [Thu, 19 Dec 2013 20:42:56 +0000 (21:42 +0100)]
Kernel: Add SATA support on imx6 wandboard.
The imx6q wandboard has a soldered SATA port which can be used by loading the ahci_imx kernel module.
Stefan Schantl [Thu, 19 Dec 2013 20:34:09 +0000 (21:34 +0100)]
Kernel: Add support for wifi and bluetooth on imx6 wandboards.
Stefan Schantl [Thu, 19 Dec 2013 20:31:39 +0000 (21:31 +0100)]
Kernel: Add terminal driver support on imx platforms.
Stefan Schantl [Thu, 19 Dec 2013 20:29:11 +0000 (21:29 +0100)]
Kernel: Add CK01 clock support for imx6 wandboard.
Stefan Schantl [Thu, 19 Dec 2013 20:26:15 +0000 (21:26 +0100)]
Kernel: In case of busy i2c try again to get ACK on imx platforms.
Stefan Schantl [Thu, 19 Dec 2013 20:15:30 +0000 (21:15 +0100)]
Kernel: Add initial support for compulab utilite.
Stefan Schantl [Thu, 19 Dec 2013 20:11:54 +0000 (21:11 +0100)]
Kernel: Add initial support for imx6q wandboard.
The required entries for the device tree are taken from kernel 3.12.
Stefan Schantl [Tue, 12 Nov 2013 20:54:12 +0000 (21:54 +0100)]
Rework of flash-images.
Stefan Schantl [Sat, 16 Nov 2013 21:12:55 +0000 (16:12 -0500)]
uboot: Update to 2013.10.
Arne Fitzenreiter [Thu, 19 Dec 2013 09:55:57 +0000 (10:55 +0100)]
xen-downloader: build only on i586.
Arne Fitzenreiter [Wed, 18 Dec 2013 10:29:48 +0000 (11:29 +0100)]
kernel: update to 3.10.24.
Michael Tremer [Mon, 16 Dec 2013 11:31:19 +0000 (12:31 +0100)]
Merge remote-tracking branch 'amarx/difflang' into fifteen
Alexander Marx [Thu, 12 Dec 2013 14:44:45 +0000 (15:44 +0100)]
Firewall: Bugfix: in /etc/init.d/firewall the REDNAT chain was affected BEFORE NAT_SOURCE. Outgoing SNAT rules where not working though
Michael Tremer [Mon, 16 Dec 2013 11:28:08 +0000 (12:28 +0100)]
iptables: Update to 1.4.21.
Arne Fitzenreiter [Sat, 14 Dec 2013 21:01:16 +0000 (22:01 +0100)]
finalize core 74.
Alexander Marx [Fri, 13 Dec 2013 07:03:23 +0000 (08:03 +0100)]
TOOLS: new script langdiff added. With this script one can check a languagefile against another and gets a txtfile conatining the missing lines.
Michael Tremer [Thu, 12 Dec 2013 20:20:56 +0000 (21:20 +0100)]
core74: Add httpscert script.
Michael Tremer [Thu, 12 Dec 2013 20:18:56 +0000 (21:18 +0100)]
httpscert: Increase size of the RSA key to 4096.
RSA keys with length of 1024 bits are considered weak.
Michael Tremer [Thu, 12 Dec 2013 20:17:53 +0000 (21:17 +0100)]
httpscert: Use regular random source.
Previous to this patch, the kernel image file and internal
configuration settings have been used as a source for random
data, which is not random at all.
Michael Tremer [Thu, 12 Dec 2013 20:15:24 +0000 (21:15 +0100)]
strongswan: Disable rdrand plugin.
Disabled because of security concerns.
Michael Tremer [Thu, 12 Dec 2013 20:05:56 +0000 (21:05 +0100)]
wirelesscrtl: Add --wait to iptables command line.
With a huge number of access rules, inserting all rules
into the kernel took a long while in which other iptables
tried to access the kernel's ruleset as well, which then
lead to resource conflicts.
Since iptables 1.4.20, the --wait parameter is supported
that will wait for a global xtables lock and then proceed.
Michael Tremer [Wed, 11 Dec 2013 20:59:22 +0000 (21:59 +0100)]
Always create squid.conf.
In some cases, /var/ipfire/proxy/squid.conf does not belong to
nobody:nobody, so we do this explicitely.
Michael Tremer [Tue, 10 Dec 2013 12:31:38 +0000 (13:31 +0100)]
Merge remote-tracking branch 'amarx/firewall-fifteen-beta9' into fifteen
Alexander Marx [Tue, 10 Dec 2013 11:21:48 +0000 (12:21 +0100)]
Firewall: rebuild complete counter procedure in firewall-groups. This way the counters are on the fly generated and stable. also this is a prequisite to the new option that firewall-servicegroups can be rolled out by installation
Arne Fitzenreiter [Mon, 9 Dec 2013 23:15:01 +0000 (00:15 +0100)]
Merge branch 'next' into fifteen
Arne Fitzenreiter [Mon, 9 Dec 2013 23:14:12 +0000 (00:14 +0100)]
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Mon, 9 Dec 2013 23:13:20 +0000 (00:13 +0100)]
Merge branch 'master' into next
Arne Fitzenreiter [Mon, 9 Dec 2013 23:07:36 +0000 (00:07 +0100)]
samba: update to 3.6.22.
Samba 3.6.22 have been issued as security releases in order
to address CVE-2013-4408 (DCE-RPC fragment length field is incorrectly checked)
and CVE-2012-6150 (pam_winbind login without require_membership_of
restrictions).
Arne Fitzenreiter [Mon, 9 Dec 2013 16:13:34 +0000 (17:13 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen
Arne Fitzenreiter [Mon, 9 Dec 2013 16:10:59 +0000 (17:10 +0100)]
kernel: update to 3.10.23.
Alexander Marx [Mon, 9 Dec 2013 10:06:50 +0000 (11:06 +0100)]
Firewall: added DNS (UDP,TCP) to default services
Alexander Marx [Mon, 9 Dec 2013 08:33:21 +0000 (09:33 +0100)]
Firewall: Fix BETA8 - It was not possible to delete single services from servicegroups
Alexander Marx [Mon, 9 Dec 2013 08:29:50 +0000 (09:29 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into firewall-fifteen1
Arne Fitzenreiter [Sun, 8 Dec 2013 15:07:35 +0000 (16:07 +0100)]
mountkernfs: fix mount of /sys and /proc without initrd.
Arne Fitzenreiter [Sun, 8 Dec 2013 15:03:25 +0000 (16:03 +0100)]
kernel: enable grsecurity on rpi kernel.
Alexander Marx [Fri, 6 Dec 2013 07:47:11 +0000 (08:47 +0100)]
Firewall: Added new feature: Now protocols can be added to servicegroups (GRE,AH,ESP,IPIP,IPV6)
Arne Fitzenreiter [Thu, 5 Dec 2013 18:46:25 +0000 (19:46 +0100)]
kernel: update to 3.10.22.
Alexander Marx [Thu, 5 Dec 2013 14:51:15 +0000 (15:51 +0100)]
Firewall: forgot to delete a development test string
Alexander Marx [Mon, 2 Dec 2013 06:56:01 +0000 (07:56 +0100)]
Firewall: Bugfix: Fixed wrong language strings in outgoing FW rules when using std networks or ipfire
Alexander Marx [Fri, 29 Nov 2013 12:41:57 +0000 (13:41 +0100)]
Firewall: FIxed wrong language strings in outgoing Firewall
Alexander Marx [Tue, 26 Nov 2013 12:34:08 +0000 (13:34 +0100)]
Firewall: Fixes commit git.ipfire.org/?p=people/amarx/ipfire-2.x.git;a=commitdiff;h=
e19a36c4a09ea417ce9d577c262f17242eec4a31
Now all "active" Strings from all languagefiles are checked against the old rule to find out if logging is enabled
Conflicts:
config/firewall/convert-outgoingfw
Alexander Marx [Tue, 26 Nov 2013 12:02:08 +0000 (13:02 +0100)]
Firewall: fixes commit git.ipfire.org/?p=people/amarx/ipfire-2.x.git;a=commitdiff;h=
1ed4b214d785ad0538b0a864f43babccd55475b1
Conflicts:
html/cgi-bin/firewall.cgi
Alexander Marx [Tue, 26 Nov 2013 10:45:05 +0000 (11:45 +0100)]
Firewall: BUGFIX: RUles.pl did not create LOGGING rules properly.
Michael Tremer [Wed, 4 Dec 2013 23:00:28 +0000 (00:00 +0100)]
Merge remote-tracking branch 'earl/tor' into next
Michael Tremer [Tue, 3 Dec 2013 13:42:30 +0000 (14:42 +0100)]
squid: Update to 3.3.11.
Michael Tremer [Thu, 24 Oct 2013 17:41:17 +0000 (19:41 +0200)]
strongswan: Rootfile update.
Michael Tremer [Mon, 2 Dec 2013 20:41:12 +0000 (21:41 +0100)]
core74: Fix incrementation.
Michael Tremer [Mon, 2 Dec 2013 20:35:12 +0000 (21:35 +0100)]
core74: Ship dnsforward.cgi in update as well.
Adds the CGI file on systems which have been installed
with an ISO image where dnsforward.cgi was not included.
Michael Tremer [Mon, 2 Dec 2013 19:55:58 +0000 (20:55 +0100)]
core74: Add strongswan update.
Michael Tremer [Mon, 2 Dec 2013 19:48:58 +0000 (20:48 +0100)]
core74: Add dnsforward.cgi to ISO.
Bug #10447.
Michael Tremer [Mon, 2 Dec 2013 19:45:20 +0000 (20:45 +0100)]
core74: Add updated proxy.cgi.
Reflects the FD changes.
Michael Tremer [Mon, 2 Dec 2013 19:44:28 +0000 (20:44 +0100)]
core74: Add openvpn.
This package has been updated before.
Michael Tremer [Mon, 2 Dec 2013 19:43:58 +0000 (20:43 +0100)]
core74: Add squid.
Covers the filedescriptors issues.
Michael Tremer [Mon, 2 Dec 2013 19:41:25 +0000 (20:41 +0100)]
Create Core Update 74.
Will automatically increase the transparent proxy port
if it is set to 81.
Arne Fitzenreiter [Sun, 1 Dec 2013 13:09:02 +0000 (14:09 +0100)]
Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen
Arne Fitzenreiter [Sun, 1 Dec 2013 13:08:08 +0000 (14:08 +0100)]
rootfile fixes for arm.
Arne Fitzenreiter [Sat, 30 Nov 2013 11:45:31 +0000 (12:45 +0100)]
Merge branch 'next' into fifteen
Conflicts:
doc/language_issues.tr
Arne Fitzenreiter [Sat, 30 Nov 2013 11:39:33 +0000 (12:39 +0100)]
Merge branch 'master' into next
Arne Fitzenreiter [Sat, 30 Nov 2013 11:38:16 +0000 (12:38 +0100)]
samba: update to 3.6.21.
Arne Fitzenreiter [Fri, 29 Nov 2013 22:37:39 +0000 (23:37 +0100)]
kernel: update to 3.10.21.