Michael Tremer
ab79dc43bf
vpnmain.cgi: Set MTU to a default when editing an old connection
...
This field is required and therefore we need to initialize it
for old connections. Right now, the CGI throws an error message
when editing an existing connection without the MTU being filled
in.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 11:53:11 +01:00
Michael Tremer
aeecc7ae10
core130: Ship updated wget
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:07:16 +01:00
Michael Tremer
0ce95859da
core130: Ship updated nettle
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:06:41 +01:00
Michael Tremer
c95ba2bbcc
core130: Ship updated GnuTLS
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:05:52 +01:00
Michael Tremer
ef1cb80375
core130: Ship updated apache
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:04:28 +01:00
Michael Tremer
b666975ec2
unbound-dhcp-leases-bridge: Replace leases file atomically
...
When there is a large number of leases, writing the file may
take a long time. When unbound is re-reading its configuration
in that time, the file might syntactically incorrect.
This change writes the file first and then moves it
to the right place in one transaction.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-28 12:51:06 +00:00
Michael Tremer
abe2149852
GeoIP: Do not crash when locations database does not exist
...
Fixes : #12021
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 02:58:57 +00:00
Michael Tremer
3210e92212
core130: Ship updated lua
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:48:39 +00:00
Michael Tremer
67b943c18a
core130: Ship rrdtool and collectd
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:39:51 +00:00
Michael Tremer
b6c60092db
openvpn: Remove subnet check for static pools
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 15:24:03 +00:00
Stefan Schantl
b60fd7a3e2
Core 130: Remove files after convert-snort has been launched
...
The converter requires /etc/snort/snort.conf to grab the used rule files
(categories). After all settings have been converted, we are fine to delete all
snort related files, because none of them is needed anymore.
Also the /var/ipfire/snort directory needs to be deleted. If it will be left on the
system and at any later time a backup will get restored, the converter will be
started by the backup script, because it detects that a snort settins dir exists
and would be restore the old snort settings and replaces all current IPS settings.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 21:22:50 +00:00
Michael Tremer
08ded6035f
dnsforward.cgi: Check DISABLE_DNSSEC checkbox when editing
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:36:04 +00:00
Michael Tremer
3b521c724f
ipsec-interfaces: Apply static routes (again) after creating IPsec interfaces
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:25:48 +00:00
Michael Tremer
a46903cce3
core130: Ship updated unbound
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:32:10 +00:00
Michael Tremer
2c703afc04
core130: Ship updated ntp
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:30:22 +00:00
Stefan Schantl
9c4477d0f3
core130: Fix another error in rootfile
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-15 14:36:15 +00:00
Michael Tremer
03f68cbca9
core130: Fix errors in rootfile
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-15 13:20:23 +00:00
Michael Tremer
f9219b91a1
core130: Ship suricata
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 13:48:25 +00:00
Michael Tremer
c578cbd35f
core130: Ship updated firewall script
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 13:16:33 +00:00
Michael Tremer
b450e7e3e6
Start Core Update 130
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 13:15:03 +00:00
Arne Fitzenreiter
668119063c
u-boot: try to boot without ramdisk if the system cannot load it
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-13 15:17:28 +01:00
Arne Fitzenreiter
eaf004a468
knot: update to 2.8.0 and build/install only kdig
...
This fix compile errors on small arm boards. (cc1 internal error)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-13 15:06:23 +01:00
Arne Fitzenreiter
b57220aacd
groff: update to 1.22.4
...
This fix compile problems on small arm boards. (cc1 internal error)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-13 15:04:40 +01:00
Michael Tremer
e26e86dcaa
core129: Ship updated dnsforward.cgi
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-11 15:58:04 +00:00
Michael Tremer
f1042a5d44
core129: Ship updated dhcp.cgi
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-11 09:54:19 +00:00
Michael Tremer
61424e9c67
core129: Ship updated less
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-10 18:23:22 +00:00
Michael Tremer
ea9cb48ae7
core129: Ship wpa_supplicant
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-04 09:26:58 +00:00
Michael Tremer
a079f7aaee
core129: Ship updated proxy.cgi
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:14:14 +00:00
Michael Tremer
3d01a8f1a6
core129: Ship updated ipset
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:12:18 +00:00
Michael Tremer
7c57cbe24b
core129: Ship updated tar
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:11:02 +00:00
Michael Tremer
15c71234ca
core129: Ship updated bind
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:10:21 +00:00
Michael Tremer
ae4ca7ef13
core129: Ship updated squid
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 14:09:00 +00:00
Michael Tremer
771c9b78ee
binutils: Ship strings & readelf
...
This is needed by the spectre meltdown checker script
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-02 13:01:42 +00:00
Michael Tremer
f907865389
core129: Ship updated OpenSSL
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-26 17:25:11 +00:00
Michael Tremer
2f7e8b59a6
core129: Ship updated credits.cgi
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 02:31:23 +00:00
Michael Tremer
97499aa8a3
core129: Ship updated OpenVPN
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 02:29:29 +00:00
Michael Tremer
cc0104dce3
core129: Ship updated libgcrypt
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 00:58:04 +00:00
Michael Tremer
07b73b195c
core129: Ship updated unbound
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 00:56:49 +00:00
Michael Tremer
59db01c753
core129: Ship changes from ipsec branch
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 00:55:31 +00:00
Michael Tremer
b5ef99df2c
Start Core Update 129
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-25 00:47:28 +00:00
Michael Tremer
232c42e14d
core128: Drop old openssl engines
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-24 04:06:52 +00:00
Arne Fitzenreiter
1e1273df1d
core128: add openldap to update
...
openldap was linked against old openssl lib
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-24 20:50:16 +01:00
Arne Fitzenreiter
ed971af3a4
core128: add sse2 openssl libs
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-24 17:04:44 +01:00
Arne Fitzenreiter
42e48984ad
core128: apply local sshd config
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-24 10:55:49 +01:00
Arne Fitzenreiter
186402fbe8
core128: stop apache before replacing files
...
apache will not restart without stopped before
the files was replaced.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-22 19:26:08 +01:00
Arne Fitzenreiter
4a25ada199
core128: add kernel to updater
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-21 19:23:05 +01:00
Michael Tremer
9bc1760052
unbound: Drop certificates for local control connection
...
These are a cause of worry because they are sometimes generated with
an invalid timestamp and therefore render unbound being unusable.
There is no strong reason to use self-signed certificates for extra
security here.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-17 13:46:51 +00:00
Michael Tremer
5368ccb0fc
core128: Ship kdig
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-13 11:32:00 +00:00
Michael Tremer
59d673ae44
core128: Ship libedit
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-13 11:31:24 +00:00
Michael Tremer
02a8a241bb
core128: Ship updated firewall initscript
...
Require reboot after the update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-07 15:15:37 +00:00