Commit Graph

2123 Commits

Author SHA1 Message Date
Michael Tremer
6e87f0aa53 firewall: Allow accessing port forwardings from internal networks. 2014-03-02 20:37:44 +01:00
Michael Tremer
13585cc922 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-03-01 16:59:32 +01:00
Michael Tremer
5c3de120aa openvpnctrl: Allow ICMP error messages to pass the transfer net. 2014-03-01 16:51:03 +01:00
Michael Tremer
a0a5c14f85 firewall: Make sure that only packets that go through the tunnel are passing OVPNBLOCK. 2014-03-01 16:44:05 +01:00
Arne Fitzenreiter
d0ff84a675 red: change mac address of nas0 device.
Traverse Technology has reported that ppp over atm-bridge is not working
because there is a bogus mac address at the virtual nas0 device.
2014-03-01 16:01:11 +01:00
Michael Tremer
bb3834231e firewall: Sort order in which chains are initialized.
This has been some real trouble because multiple rules could
not be properly inserted into the rule chains in the kernel
because the chains did not exist, yet.
2014-03-01 15:02:42 +01:00
Michael Tremer
c9cd26f200 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-02-27 13:14:02 +01:00
Arne Fitzenreiter
b3aa7a1231 ntp: wait only if wpa_supplicant is running. 2014-02-27 08:22:11 +01:00
Michael Tremer
55a5bcae74 firewall: Call firewallctrl with full path. 2014-02-26 20:03:32 +01:00
Michael Tremer
25bd6edaaf Merge remote-tracking branch 'alfh/feature_html_validating' into next 2014-02-25 22:02:34 +01:00
Michael Tremer
66f6b279b0 Reload all firewall rules when /etc/init.d/firewall reload is executed. 2014-02-25 12:23:09 +01:00
Michael Tremer
22fd89c656 sshd: Fix warning that oom_adj is deprecated.
Also make startup faster.
2014-02-24 21:36:15 +01:00
Arne Fitzenreiter
0a79ec4505 ntp: check/wait for onlineconnection. 2014-02-23 18:28:34 +01:00
Alf Høgemark
c010871ab1 index.cgi: Make html valid, and improve dialup and vpn display
Make the html validate. One part of the changes is to
move style from using deprecated attributes to using
style attribute on tag.
The other part is to make sure that tables, rows and cells
are properly closed and nested.

Use a table for showing output from the dialctrl script.
2014-02-22 17:36:45 +01:00
Michael Tremer
c2f7250b23 firewall: Remove even more redundant rules. 2014-02-21 11:35:05 +01:00
Michael Tremer
29201ca84b firewall: Remove redundant rule. 2014-02-20 13:01:36 +01:00
Michael Tremer
f2b22ab7b5 glibc: Backport hotfixes from RHEL6. 2014-02-15 19:40:08 +01:00
Michael Tremer
e39096cf66 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-02-15 18:42:37 +01:00
Michael Tremer
7e8b0ca029 fireinfo: Exclude some more patterns. 2014-02-15 18:40:55 +01:00
Arne Fitzenreiter
841193ead5 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-02-15 17:48:35 +01:00
Arne Fitzenreiter
d10a7de134 leds: add geos router support, updated alix leds. 2014-02-15 16:39:22 +01:00
Arne Fitzenreiter
1e67b3c3bb kernel: cs5535audio spam the syslog with access errors.
On geos boards the cs5535 is present but the ac97 is not there.
2014-02-15 16:29:31 +01:00
Arne Fitzenreiter
3bf58b324c Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-02-14 23:41:45 +01:00
Arne Fitzenreiter
d006af40db kernel: add some omap/pandaboard patches. 2014-02-14 23:41:13 +01:00
Arne Fitzenreiter
2fff11756f kernel: fix imq patch for 3.10.30.
kernel: fix imq patch for 3.10.30 and remove old patches.
2014-02-14 22:24:05 +01:00
Michael Tremer
7c475cd6e1 fireinfo: Remove old patch. 2014-02-14 17:38:16 +01:00
Michael Tremer
0f5c5ce72d firewall: Load init script functions. 2014-02-14 16:10:21 +01:00
Michael Tremer
cdb725da87 firewall: Load conntrack modules in firewall script. 2014-02-14 12:54:08 +01:00
Michael Tremer
1108a15cc6 Move enabling nf_conntrack_acct where it should be. 2014-02-14 12:52:28 +01:00
Michael Tremer
7d7740a467 firewall: Initialize basic ruleset before entering runlevel 3. 2014-02-14 12:48:11 +01:00
Michael Tremer
e7c5b9dabb network: Remove redundant insertion of wireless rules. 2014-02-14 12:41:23 +01:00
Michael Tremer
4bc91affe0 network: Remove old accounting code. 2014-02-14 12:40:57 +01:00
Michael Tremer
159c55c5c8 firewall: Call firewall.local start at the very end. 2014-02-14 12:40:11 +01:00
Michael Tremer
c581b670ef firewall: Use --wait for every iptables call. 2014-02-14 12:35:40 +01:00
Michael Tremer
501e7b8654 tor: Bump package version to 6 and fix backup.
The backup include file is missing in older releases
and will be created on the fly when updating old packages.
2014-02-13 15:39:35 +01:00
Arne Fitzenreiter
d2b1aa09df partresize: fix output redirection to dev/zero. 2014-02-12 01:02:08 +01:00
Michael Tremer
62667a709f linux: Fix grsecurity-related crash on Intel Haswell CPUs. 2014-02-11 16:54:48 +01:00
Arne Fitzenreiter
6450609d74 partresize: resize partition before c,h,s changes. 2014-02-11 00:23:11 +01:00
Michael Tremer
8ec868ab22 linux: Fix IMQ crash.
Fixes #10474.
2014-02-10 23:00:19 +01:00
Michael Tremer
f17f51e873 fireinfo: Fix finding the root device. 2014-02-07 14:59:50 +01:00
Michael Tremer
e360e50ac4 strongswan: Update to 5.1.2dr3. 2014-02-07 14:49:03 +01:00
Arne Fitzenreiter
b8101c50ea partresize: update c,h,s values before resize.
Some cards fail with wrong translations so the values are updated before resize.
2014-02-05 10:52:46 +01:00
Arne Fitzenreiter
97461f500b krng: default entropy pool has 2kb with grsecurity. 2014-02-04 18:50:02 +01:00
Arne Fitzenreiter
af789b69a8 Revert "krng: use kernel entropy if no random-seed is stored."
This reverts commit 1c72742bca.
2014-02-04 18:49:00 +01:00
Arne Fitzenreiter
1c72742bca krng: use kernel entropy if no random-seed is stored. 2014-02-02 12:50:22 +01:00
Michael Tremer
73794dad87 apache: Don't show the signal of sync.
evaluate_retval prints the return code of sync
which is not what we want here.

Also changed some console output.
2014-02-01 19:35:27 +01:00
Arne Fitzenreiter
c2bf88c1a4 apache: sync filesystem after key generating. 2014-02-01 17:14:39 +01:00
Michael Tremer
2af8179385 rngd: Mix-in RDRAND and reload for HWRNGs added at runtime. 2014-02-01 16:46:22 +01:00
Michael Tremer
167e6ec7a8 openssh: Update to 6.5p1.
Adds support for ed25519.
2014-02-01 16:15:10 +01:00
Michael Tremer
a20395a645 Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next 2014-02-01 13:38:58 +01:00