]> git.ipfire.org Git - people/teissler/ipfire-2.x.git/log
people/teissler/ipfire-2.x.git
9 years agokernel: rootfile update.
Arne Fitzenreiter [Thu, 1 May 2014 09:30:07 +0000 (11:30 +0200)] 
kernel: rootfile update.

9 years agoMerge remote-tracking branch 'ms/stunnel-addon'
Michael Tremer [Wed, 30 Apr 2014 13:02:51 +0000 (15:02 +0200)] 
Merge remote-tracking branch 'ms/stunnel-addon'

9 years agofcron: fix /var/spool/cron permissions.
Arne Fitzenreiter [Wed, 30 Apr 2014 08:57:14 +0000 (10:57 +0200)] 
fcron: fix /var/spool/cron permissions.

9 years agoflash-image: increase initial size of root partition.
Arne Fitzenreiter [Wed, 30 Apr 2014 07:21:31 +0000 (09:21 +0200)] 
flash-image: increase initial size of root partition.

9 years agorpi-firmware: update to cd50136.
Arne Fitzenreiter [Tue, 29 Apr 2014 21:01:45 +0000 (23:01 +0200)] 
rpi-firmware: update to cd50136.

9 years agokernel: update rpi-patchset to 1b49b45.
Arne Fitzenreiter [Tue, 29 Apr 2014 20:47:20 +0000 (22:47 +0200)] 
kernel: update rpi-patchset to 1b49b45.

9 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Tue, 29 Apr 2014 12:37:58 +0000 (14:37 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

9 years agopound: Update to 2.7c.
Michael Tremer [Tue, 29 Apr 2014 12:37:34 +0000 (14:37 +0200)] 
pound: Update to 2.7c.

Also fix multiple initscript symlinks.

9 years agomake.sh: Load loop module (if not loaded, yet).
Michael Tremer [Tue, 29 Apr 2014 11:09:56 +0000 (13:09 +0200)] 
make.sh: Load loop module (if not loaded, yet).

9 years agoentropy.cgi: Show status of rngd.
Michael Tremer [Tue, 29 Apr 2014 11:09:42 +0000 (13:09 +0200)] 
entropy.cgi: Show status of rngd.

9 years agopppsetup: add atm device selection.
Arne Fitzenreiter [Mon, 28 Apr 2014 21:36:03 +0000 (23:36 +0200)] 
pppsetup: add atm device selection.

9 years agoFirewall: When using DNAT AUTO, don't display the IP anymore in brackets
Alexander Marx [Mon, 28 Apr 2014 12:55:22 +0000 (14:55 +0200)] 
Firewall: When using DNAT AUTO, don't display the IP anymore in brackets

9 years agoFirewall: outgoingconverter fix for ipfire-src
Alexander Marx [Mon, 28 Apr 2014 06:07:16 +0000 (08:07 +0200)] 
Firewall: outgoingconverter fix for ipfire-src

9 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Sun, 27 Apr 2014 17:38:05 +0000 (19:38 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

9 years agowatchdog: Update addon.
Michael Tremer [Sun, 27 Apr 2014 17:37:42 +0000 (19:37 +0200)] 
watchdog: Update addon.

9 years agokernel: update to 3.10.38.
Arne Fitzenreiter [Sun, 27 Apr 2014 09:37:14 +0000 (11:37 +0200)] 
kernel: update to 3.10.38.

9 years agomc: update to 4.8.12.
Arne Fitzenreiter [Sat, 26 Apr 2014 20:00:25 +0000 (22:00 +0200)] 
mc: update to 4.8.12.

9 years agokernel: Enable various watchdog modules on i586.
Michael Tremer [Sat, 26 Apr 2014 11:22:49 +0000 (13:22 +0200)] 
kernel: Enable various watchdog modules on i586.

9 years agostunnel: New package.
Michael Tremer [Fri, 25 Apr 2014 10:42:52 +0000 (12:42 +0200)] 
stunnel: New package.

9 years agokernel: rt2800usb: add dlink dwa-137 usbid.
Arne Fitzenreiter [Fri, 25 Apr 2014 08:34:07 +0000 (10:34 +0200)] 
kernel: rt2800usb: add dlink dwa-137 usbid.

9 years agoFirewall: BUG 10528 - allow subnets greater than /8
Alexander Marx [Wed, 23 Apr 2014 12:19:34 +0000 (14:19 +0200)] 
Firewall: BUG 10528 - allow subnets greater than /8

9 years agoAdd locales to installed.
Michael Tremer [Tue, 22 Apr 2014 19:09:03 +0000 (21:09 +0200)] 
Add locales to installed.

Because of the locale switch, no locales have been included
in the installer initrd and no characters other than the
ASCII characters could be shown.

9 years agoUpdate Turkish translation.
Ersan Yildirim Ersan [Tue, 22 Apr 2014 16:00:30 +0000 (18:00 +0200)] 
Update Turkish translation.

9 years agostrongswan: Enable XAUTH noauth plugin.
Michael Tremer [Tue, 22 Apr 2014 15:46:32 +0000 (17:46 +0200)] 
strongswan: Enable XAUTH noauth plugin.

See #10468.

9 years agoFirewall: BUG 10526 (missing RED iface in SNAT Dropdown)
Alexander Marx [Tue, 22 Apr 2014 08:03:50 +0000 (10:03 +0200)] 
Firewall: BUG 10526 (missing RED iface in SNAT Dropdown)

10 years agoMerge remote-tracking branch 'ms/modem-status' into next
Michael Tremer [Mon, 21 Apr 2014 12:02:17 +0000 (14:02 +0200)] 
Merge remote-tracking branch 'ms/modem-status' into next

Conflicts:
doc/language_issues.es
doc/language_issues.fr
doc/language_issues.nl
doc/language_issues.pl
doc/language_issues.ru
doc/language_issues.tr
doc/language_missings

10 years agofirewall: Fix accessing port forwardings from internal networks.
Michael Tremer [Sun, 20 Apr 2014 16:13:35 +0000 (18:13 +0200)] 
firewall: Fix accessing port forwardings from internal networks.

When a different "external port" was used, false rules have
been created in the mangle table.

10 years agoUpdate layer7 patch.
Michael Tremer [Fri, 18 Apr 2014 21:11:39 +0000 (23:11 +0200)] 
Update layer7 patch.

This should fix some issues with concurrent access to skbuf.

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Fri, 18 Apr 2014 20:24:24 +0000 (22:24 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agoFix spelling of "IPsec".
Michael Tremer [Thu, 17 Apr 2014 10:44:18 +0000 (12:44 +0200)] 
Fix spelling of "IPsec".

10 years agoUpdate translations.
Michael Tremer [Thu, 17 Apr 2014 10:40:04 +0000 (12:40 +0200)] 
Update translations.

10 years agoFirewall: Bug10513
Alexander Marx [Thu, 17 Apr 2014 09:14:25 +0000 (11:14 +0200)] 
Firewall: Bug10513

10 years agofirewall: Explicitely allow DHCP messages.
Michael Tremer [Thu, 17 Apr 2014 10:31:27 +0000 (12:31 +0200)] 
firewall: Explicitely allow DHCP messages.

10 years agoAdd modem status page.
Michael Tremer [Tue, 15 Apr 2014 23:26:28 +0000 (01:26 +0200)] 
Add modem status page.

On this page, much useful information is displayed about
the hardware and the status of an LTE/3G or other kinds
of modems that respond to AT commands.

10 years agostrongswan: rootfile update.
Arne Fitzenreiter [Wed, 16 Apr 2014 04:52:01 +0000 (06:52 +0200)] 
strongswan: rootfile update.

10 years agomove core75 files to oldcore.
Arne Fitzenreiter [Tue, 15 Apr 2014 23:54:14 +0000 (01:54 +0200)] 
move core75 files to oldcore.

10 years agoRename IPFire 2.15 Core Update 76 -> 77.
Michael Tremer [Tue, 15 Apr 2014 19:38:24 +0000 (21:38 +0200)] 
Rename IPFire 2.15 Core Update 76 -> 77.

10 years agostrongswan: Update to 5.1.3.
Michael Tremer [Tue, 15 Apr 2014 19:16:14 +0000 (21:16 +0200)] 
strongswan: Update to 5.1.3.

Fixes CVE-2014-2338.

10 years agoFirewall: Bug 10514 fixed
Alexander Marx [Mon, 14 Apr 2014 06:02:16 +0000 (08:02 +0200)] 
Firewall: Bug 10514 fixed

10 years agokernel: update to 3.10.37.
Arne Fitzenreiter [Mon, 14 Apr 2014 18:13:14 +0000 (20:13 +0200)] 
kernel: update to 3.10.37.

10 years agoMerge remote-tracking branch 'ummeegge/openvpn' into next
Michael Tremer [Sun, 13 Apr 2014 13:45:19 +0000 (15:45 +0200)] 
Merge remote-tracking branch 'ummeegge/openvpn' into next

10 years agoOpenVPN:Add HMAC, cipher 'n2n' and DH key selection. Fixes and new design.
Erik Kapfer [Sun, 13 Apr 2014 05:14:25 +0000 (07:14 +0200)] 
OpenVPN:Add HMAC, cipher 'n2n' and DH key selection. Fixes and new design.

Added HMAC algorithm selection menu for N2N and RW.
Added cipher selection menu for N2N connections.
Added DH key selection also for existing installations incl. DH key upload possibility.
Adjusted the ovpn main WUI design to IPSec WUI.
Extend key lenght for CA, cert and control channel with faktor 2.
Some code and typo cleanup.
Bugfixes for #10317, #10149, #10462, #10463
V.2 New changes:
Integrated changes in langs and ovpnmain.cgi until 20.03.2014 2.15-Beta3.
ovpn.cnf have now default bits of 2048 instead of 1024.
ovpn.cnf default_md works now with sha256 instead of md5.
Bugfix: By new installation the auth directive for RWs is faded out #10462 Comment 15.
Added error message if the crl should be displayed but no crl is present.

10 years agofirewall: Fix outgoing OpenVPN N2N tunnel packets.
Michael Tremer [Sat, 12 Apr 2014 14:17:20 +0000 (16:17 +0200)] 
firewall: Fix outgoing OpenVPN N2N tunnel packets.

Don't throw away packets from the firewall that pass through
an OpenVPN N2N tunnel.

10 years agofirewall: Fix spelling and seperate spelling issues.
Michael Tremer [Sat, 12 Apr 2014 14:01:11 +0000 (16:01 +0200)] 
firewall: Fix spelling and seperate spelling issues.

10 years agofirewall: Change headlines for rule sections.
Michael Tremer [Sat, 12 Apr 2014 13:55:44 +0000 (15:55 +0200)] 
firewall: Change headlines for rule sections.

10 years agorules.pl: Rewrite P2P protocol filter.
Michael Tremer [Sat, 12 Apr 2014 13:39:08 +0000 (15:39 +0200)] 
rules.pl: Rewrite P2P protocol filter.

10 years agofirewall.cgi: Sort protocols alphabetically.
Michael Tremer [Sat, 12 Apr 2014 13:23:45 +0000 (15:23 +0200)] 
firewall.cgi: Sort protocols alphabetically.

10 years agofirewall: Fix creation of automatic rules for the firewall.
Michael Tremer [Sat, 12 Apr 2014 13:16:08 +0000 (15:16 +0200)] 
firewall: Fix creation of automatic rules for the firewall.

If the firewall is part of a local network (e.g. GREEN),
we automatically add rules that grant/forbid access for the firewall,
too.

This has been broken for various default policies other than ALLOWED.

10 years agomedia.cgi: Add missing 'tr'.
Michael Tremer [Sat, 12 Apr 2014 10:18:57 +0000 (12:18 +0200)] 
media.cgi: Add missing 'tr'.

10 years agoMerge branch 'master' into next
Michael Tremer [Fri, 11 Apr 2014 13:18:50 +0000 (15:18 +0200)] 
Merge branch 'master' into next

Conflicts:
doc/language_issues.tr

10 years agoUpdate translations.
Michael Tremer [Fri, 11 Apr 2014 13:17:21 +0000 (15:17 +0200)] 
Update translations.

10 years agoMerge remote-tracking branch 'amarx/RC2-master'
Michael Tremer [Fri, 11 Apr 2014 13:17:08 +0000 (15:17 +0200)] 
Merge remote-tracking branch 'amarx/RC2-master'

10 years agoFirewall: When having rules with more than 3 protocols, show "many" and tooltip
Alexander Marx [Fri, 11 Apr 2014 10:06:52 +0000 (12:06 +0200)] 
Firewall: When having rules with more than 3 protocols, show "many" and tooltip

10 years agokernel: disable intel mei.
Arne Fitzenreiter [Wed, 9 Apr 2014 16:20:46 +0000 (18:20 +0200)] 
kernel: disable intel mei.

Intel Management Engine Interface is still crashing the kernel.

10 years agoFirewall: Fix 10510 - Show all protocols from servicegroups (GRE,IPIP,IPV6,...)
Alexander Marx [Wed, 9 Apr 2014 14:23:55 +0000 (16:23 +0200)] 
Firewall: Fix 10510 - Show all protocols from servicegroups (GRE,IPIP,IPV6,...)

10 years agokernel: disable intel mei.
Arne Fitzenreiter [Wed, 9 Apr 2014 16:20:46 +0000 (18:20 +0200)] 
kernel: disable intel mei.

Intel Management Engine Interface is still crashing the kernel.

10 years agofirewall-policy: Remove empty line.
Michael Tremer [Wed, 9 Apr 2014 13:14:25 +0000 (15:14 +0200)] 
firewall-policy: Remove empty line.

10 years agoFix missing Connection Scheduler strings.
Michael Tremer [Wed, 9 Apr 2014 13:11:41 +0000 (15:11 +0200)] 
Fix missing Connection Scheduler strings.

10 years agoaliases.cgi: Mark name field as mandatory.
Michael Tremer [Wed, 9 Apr 2014 12:19:16 +0000 (14:19 +0200)] 
aliases.cgi: Mark name field as mandatory.

10 years agofirewall: Apply destination NAT rules for the firewall itself, too.
Michael Tremer [Wed, 9 Apr 2014 12:16:32 +0000 (14:16 +0200)] 
firewall: Apply destination NAT rules for the firewall itself, too.

10 years agofirewall: Fix rule generation for protocols without ports.
Michael Tremer [Wed, 9 Apr 2014 12:06:32 +0000 (14:06 +0200)] 
firewall: Fix rule generation for protocols without ports.

10 years agoopenssl: update to 1.0.1g.
Arne Fitzenreiter [Mon, 7 Apr 2014 19:33:34 +0000 (21:33 +0200)] 
openssl: update to 1.0.1g.

Fix for CVE-2014-0160
Add TLS padding extension workaround for broken servers.
Fix for CVE-2014-0076

10 years agoFirewall: fix coloring of internet hosts
Alexander Marx [Mon, 7 Apr 2014 14:14:20 +0000 (16:14 +0200)] 
Firewall: fix coloring of internet hosts

10 years agoFirewall: Fix source preselection of alias when Firewall is selected
Alexander Marx [Mon, 7 Apr 2014 10:09:16 +0000 (12:09 +0200)] 
Firewall: Fix source preselection of alias when Firewall is selected

10 years agoFirewall: BUGFIX 10505
Alexander Marx [Mon, 7 Apr 2014 10:04:50 +0000 (12:04 +0200)] 
Firewall: BUGFIX 10505

10 years agoFirewall: BUGFIX 10507
Alexander Marx [Mon, 7 Apr 2014 06:24:54 +0000 (08:24 +0200)] 
Firewall: BUGFIX 10507

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Mon, 7 Apr 2014 14:49:33 +0000 (16:49 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agoglibc: rootfile update (arm).
Arne Fitzenreiter [Sun, 6 Apr 2014 22:35:31 +0000 (00:35 +0200)] 
glibc: rootfile update (arm).

10 years agokernel-header: rootfile update.
Arne Fitzenreiter [Sun, 6 Apr 2014 21:33:51 +0000 (23:33 +0200)] 
kernel-header: rootfile update.

10 years agomedia.cgi: Fix typo once again.
Michael Tremer [Sun, 6 Apr 2014 15:24:13 +0000 (17:24 +0200)] 
media.cgi: Fix typo once again.

10 years agoUpdate Turkish translation.
Ersan Yildirim [Sun, 6 Apr 2014 15:22:31 +0000 (17:22 +0200)] 
Update Turkish translation.

10 years agocore76: Include changed /etc/sysctl.conf in update.
Michael Tremer [Sun, 6 Apr 2014 10:53:30 +0000 (12:53 +0200)] 
core76: Include changed /etc/sysctl.conf in update.

10 years agoglibc: fix image, updater and filecount in installer.
Arne Fitzenreiter [Sun, 6 Apr 2014 08:29:27 +0000 (10:29 +0200)] 
glibc: fix image, updater and filecount in installer.

switch from locale-archive to normale locales add est. 5000 files.
todo: arm-rootfile.

10 years agofirewall: Fix using aliases.
Michael Tremer [Sat, 5 Apr 2014 15:09:56 +0000 (17:09 +0200)] 
firewall: Fix using aliases.

Fix coding errors, actually read aliases configuration
and fall back to default RED IP address if no suitable
alias was found.

10 years agoconvert-portfw: Fix converting aliases.
Michael Tremer [Sat, 5 Apr 2014 15:08:17 +0000 (17:08 +0200)] 
convert-portfw: Fix converting aliases.

ALL is not suitable as it is not a valid configuration value.

10 years agoMerge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x
Michael Tremer [Sat, 5 Apr 2014 15:02:33 +0000 (17:02 +0200)] 
Merge branch 'master' of ssh://git.ipfire.org/pub/git/ipfire-2.x

10 years agofirewall: fix green only mode.
Arne Fitzenreiter [Sat, 5 Apr 2014 09:04:25 +0000 (11:04 +0200)] 
firewall: fix green only mode.

disable masquerade and green IP/NET check if internet is
connected via green.

10 years agoapache2: update to 2.2.27.
Arne Fitzenreiter [Fri, 4 Apr 2014 19:17:08 +0000 (21:17 +0200)] 
apache2: update to 2.2.27.

10 years agokernel: update to 3.10.36.
Arne Fitzenreiter [Fri, 4 Apr 2014 11:53:41 +0000 (13:53 +0200)] 
kernel: update to 3.10.36.

10 years agokernel: update to 3.10.35.
Arne Fitzenreiter [Thu, 3 Apr 2014 08:06:47 +0000 (10:06 +0200)] 
kernel: update to 3.10.35.

10 years agoglibc: Install all known locales.
Michael Tremer [Tue, 1 Apr 2014 14:24:50 +0000 (16:24 +0200)] 
glibc: Install all known locales.

10 years agofirewall: Fix perl coding error.
Michael Tremer [Mon, 31 Mar 2014 11:16:26 +0000 (13:16 +0200)] 
firewall: Fix perl coding error.

Example:
my @as = (1, 2, 3);
foreach my $a (@as) {
$a += 1;
print "$a\n";
}

$a will be a reference to the number in the array and not
copied. Therefore $a += 1 will change the numbers in the
array as well, so that after the loop the content of @as
would be (2, 3, 4).
To avoid that, the number needs to be copied into a new
variable like: my $b = $a; and we are fine.

This caused that the content of the @sources and @destinations
array has been altered for the second run of the loop and
incorrect (i.e. no) rules were created.

10 years agoMerge branch 'kernel-layer7-oom'
Michael Tremer [Sun, 30 Mar 2014 21:28:35 +0000 (23:28 +0200)] 
Merge branch 'kernel-layer7-oom'

10 years agokernel: Update layer7 patch.
Michael Tremer [Sun, 30 Mar 2014 21:26:29 +0000 (23:26 +0200)] 
kernel: Update layer7 patch.

Brings back the /proc interface and is supposed to
fix a memory leak.

10 years agofirewall-policy: Clarify policy rules.
Michael Tremer [Sun, 30 Mar 2014 20:33:58 +0000 (22:33 +0200)] 
firewall-policy: Clarify policy rules.

There are no functional changes here. Everything that
is not explicitely allowed is now forbidden when the
forward policy is "ALLOWED".

10 years agoMerge branch 'beyond-next' into next
Michael Tremer [Sat, 29 Mar 2014 23:21:33 +0000 (00:21 +0100)] 
Merge branch 'beyond-next' into next

10 years agofirewall-policy: fix drop and logging on red0;
Arne Fitzenreiter [Sat, 29 Mar 2014 14:06:35 +0000 (15:06 +0100)] 
firewall-policy: fix drop and logging on red0;

10 years agoset version to IPFire 2.15 rc1.
Arne Fitzenreiter [Fri, 28 Mar 2014 17:16:31 +0000 (18:16 +0100)] 
set version to IPFire 2.15 rc1.

10 years agofirewall: Create mangle chain NAT_DESTINATION to silence error messages when updating.
Michael Tremer [Thu, 27 Mar 2014 14:08:17 +0000 (15:08 +0100)] 
firewall: Create mangle chain NAT_DESTINATION to silence error messages when updating.

10 years agoFirewall: fix Update from core 75 to 76
Alexander Marx [Thu, 27 Mar 2014 10:58:48 +0000 (11:58 +0100)] 
Firewall: fix Update from core 75 to 76

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Thu, 27 Mar 2014 14:07:26 +0000 (15:07 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agocups: Fix rootfile.
Michael Tremer [Thu, 27 Mar 2014 10:36:12 +0000 (11:36 +0100)] 
cups: Fix rootfile.

Basically, include just everything.

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Arne Fitzenreiter [Thu, 27 Mar 2014 06:30:56 +0000 (07:30 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next

10 years agorpi-firmware: update to 18a7921.
Arne Fitzenreiter [Thu, 27 Mar 2014 06:29:19 +0000 (07:29 +0100)] 
rpi-firmware: update to 18a7921.

10 years agokernel: update RPi patchset to dea8280.
Arne Fitzenreiter [Thu, 27 Mar 2014 06:25:24 +0000 (07:25 +0100)] 
kernel: update RPi patchset to dea8280.

10 years agoipsecctrl: Fix compiler warning.
Michael Tremer [Wed, 26 Mar 2014 22:47:14 +0000 (23:47 +0100)] 
ipsecctrl: Fix compiler warning.

10 years agoMerge branch 'ppp-update' into beyond-next
Michael Tremer [Wed, 26 Mar 2014 22:43:04 +0000 (23:43 +0100)] 
Merge branch 'ppp-update' into beyond-next

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into beyond-next
Michael Tremer [Wed, 26 Mar 2014 22:42:57 +0000 (23:42 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into beyond-next

10 years agoppp: Update to 2.4.6.
Michael Tremer [Wed, 26 Mar 2014 22:42:05 +0000 (23:42 +0100)] 
ppp: Update to 2.4.6.

10 years agoMerge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
Michael Tremer [Wed, 26 Mar 2014 22:35:18 +0000 (23:35 +0100)] 
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next