Michael Tremer
37a83c83cd
hostap: Enable option to force clients to use 802.11w
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-24 10:39:25 +01:00
Michael Tremer
ea10f1a0b5
hostap: Allow to use Automatic Channel Selection (ACS)
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-24 10:12:29 +01:00
Jonatan Schlag
010d4a85a9
Enable seccomp support for qemu
...
Fixes : #11941
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-20 14:13:50 +01:00
Jonatan Schlag
43c3a386d1
Add new package libseccomp
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-20 14:12:50 +01:00
Arne Fitzenreiter
08639bc2a9
kernel: update 4.14.113
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-20 17:21:03 +02:00
Arne Fitzenreiter
5fa063f859
kernel: update to 4.14.112
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-17 22:30:19 +02:00
Arne Fitzenreiter
e91c83490b
wireless-regdb: update to 2019.03.01
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-16 18:05:18 +02:00
Michael Tremer
fea27a56f7
haproxy: Backup certificates, too
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-16 13:23:17 +01:00
Michael Tremer
a32c219fa4
zabbix_agentd: Bump package version
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-11 07:55:36 +01:00
Alexander Koch
41b7369f80
zabbix_agentd: Bugfix for /etc/sudoers.d/zabbix.user
...
Files containing an '~' or '.' are ignored by sudo when placed in the includedir /etc/sudoers.d This makes the file useless. The file is renamed to "zabbix" instead of "zabbix.user" to fix this.
See: https://www.sudo.ws/man/1.8.13/sudoers.man.html#Including_other_files_from_within_sudoers
Signed-off-by: Alexander Koch <ipfire@starkstromkonsument.de >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-11 07:55:10 +01:00
Alexander Koch
854b63c42a
zabbix_agentd: update to 4.2.0
...
Relase Notes: https://www.zabbix.com/rn/rn4.2.0
Signed-off-by: Alexander Koch <ipfire@starkstromkonsument.de >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-11 07:55:07 +01:00
Arne Fitzenreiter
f2afd5e70d
kernel: update to 4.14.111
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-08 21:47:23 +02:00
Michael Tremer
918ee4a4cf
strongswan: Manually install all routes for non-routed VPNs
...
This is a regression from disabling charon.install_routes.
VPNs are routing fine as long as traffic is passing through
the firewall. Traps are not propertly used as long as these
routes are not present and therefore we won't trigger any
tunnels when traffic originates from the firewall.
Fixes : #12045
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-08 16:44:57 +01:00
Peter Müller
f40cd26de2
Postfix: update to 3.4.5
...
See http://www.postfix.org/announcements/postfix-3.4.5.html for
release notes.
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-06 16:09:02 +01:00
Matthias Fischer
ee44d509b6
wget: Update to 1.20.3
...
For details see:
https://fossies.org/linux/wget/ChangeLog
Excerpt from "NEWS":
"2019-04-05 Tim Ruehsen <tim.ruehsen@gmx.de >
Fix a buffer overflow vulnerability
* src/iri.c(do_conversion): Reallocate the output buffer to a larger
size if it is already full"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-06 16:08:53 +01:00
Arne Fitzenreiter
aa20f1b277
kernel: update to 4.14.110
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-05 07:46:34 +02:00
Matthias Fischer
7dd8193684
wget: Update to 1.20.2
...
For details see:
https://fossies.org/linux/wget/ChangeLog
Excerpt from "NEWS":
* Changes in Wget 1.20.2
** NTLM authentication will retry under certain cases
** Fixed a buffer overflow vulnerability"
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:07:01 +01:00
Matthias Fischer
a4cc65bc48
nettle: Update to 3.4.1
...
For details see:
https://fossies.org/linux/nettle/ChangeLog
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:06:19 +01:00
Matthias Fischer
34bbcff61f
gnutls: Update to 3.6.7.1
...
For details see:
https://lists.gnupg.org/pipermail/gnutls-help/2019-March/004497.html
Please note:
A few days after the "3.6.7" release, "3.6.7.1" came out.
See:
https://www.gnupg.org/ftp/gcrypt/gnutls/v3.6/
But the compressed directory version is still versioned 3.6.7.
Because of this, the fourth (sub)-version number required some lfs adjustments.
And:
This version requires "nettle 3.4.1", which is sent in another commit.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:05:18 +01:00
Matthias Fischer
5f2e713ec8
apache: Update to 2.4.39
...
For details see:
http://mirror.checkdomain.de/apache//httpd/CHANGES_2.4.39
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:03:22 +01:00
Michael Tremer
7299559611
freeradius: Fix extra whitespace
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:00:29 +01:00
Arne Fitzenreiter
df95c62f3a
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-04-03 21:53:22 +00:00
Michael Tremer
94f89b821e
freeradius: handle special LDFLAGS to configure
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-03 21:52:04 +00:00
Michael Tremer
0e54ca2602
pcengines-apu-firmware: New package
...
This package ships the latest BIOS for PC Engines APU boards.
With help of the firmware-update package, this can be very easily
updated when running IPFire.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:42:19 +01:00
Michael Tremer
2aca6aa061
firmware-update: New package
...
This is a script that can update firmware on PC Engines APU systems
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:33:44 +01:00
Michael Tremer
82d176d33b
flashrom: New package
...
This is required to flash firmware
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:26:13 +01:00
Michael Tremer
4038d70b76
freeradius: Fix build on armv5tel
...
Reported-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 21:35:56 +01:00
Arne Fitzenreiter
78c8fe06a5
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-03-31 18:36:44 +02:00
Jonatan Schlag
56f4ba9b01
Update borgbackup to version 1.1.9
...
Fixes : #12016
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-31 13:32:10 +01:00
Arne Fitzenreiter
d00d788be4
kernel: update to 4.14.109
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-31 11:46:34 +02:00
Arne Fitzenreiter
3005eb2234
kernel: update user regd patch from openwrt
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-30 16:56:56 +01:00
Erik Kapfer
9f52e35066
freeradius: Update to version 3.0.18
...
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-29 13:50:18 +00:00
Matthias Fischer
10945e38f3
clamav: Update to 0.101.2
...
For details see:
https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html
"ClamAV 0.101.2 is a patch release to address a handful of security related bugs."
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-29 13:50:18 +00:00
Erik Kapfer
effa44650e
nginx: Update to 1.15.9
...
Fixes #12023 .
Added support for http2.
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-25 23:44:24 +00:00
Michael Tremer
2547e73e6b
freeradius: Bump version because package is linked against old version of OpenSSL
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 07:28:23 +00:00
Matthias Fischer
6bc94afa0d
lua: Update to 5.3.5
...
For details see:
http://www.lua.org/bugs.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:41:44 +00:00
Matthias Fischer
b3a7120c15
rrdtool: Update to 1.7.1
...
Disabled 'lua' because otherwise building failed.
I didn't find any place or reason where 'lua' was used by 'rrdtool', so it
was deactivated.
Disabling had no noticeable effects by now. Running.
Please note:
'/usr/lib/collectd/rrdcached.so' and '/usr/lib/collectd/rrdtool.so' have to
be updated, too.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:38:41 +00:00
Michael Tremer
fd0b2742bf
dnsdist: Update to 1.3.3
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 04:38:41 +00:00
Michael Tremer
5b8ff1ccb6
dnsdist: Add backup include
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 02:54:30 +00:00
Michael Tremer
57521504a8
hostapd: Bump package version
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:34:19 +00:00
Matthias Fischer
6f8b156bf0
unbound: Update to 1.9.1
...
For details see:
https://nlnetlabs.nl/pipermail/unbound-users/2019-March/011415.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:31:29 +00:00
Matthias Fischer
f81c222519
ntp: Update to 4.2.8p13
...
For details see:
http://support.ntp.org/bin/view/Main/SecurityNotice#Recent_Vulnerabilities
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:28:58 +00:00
Stefan Schantl
728f3d2e8f
suricata: Fix ownership and file permissions of files inside /var/lib/suricata.
...
These files needs to have nobody.nobody as owner but requires read-acces from everyone
to allow the suricata user reading-in this files during startup.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:28:30 +00:00
Michael Tremer
acb718b0bb
nut: Disable parallel build
...
nut just fails to build when running in parallel
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 14:01:45 +00:00
Michael Tremer
01604708c3
Merge remote-tracking branch 'stevee/next-suricata' into next
2019-03-14 13:19:35 +00:00
Peter Müller
4680d554fc
run Tor under dedicated user
...
This allows more-fine granular firewall rules (see first patch for
further information). Further, it prevents other services running as
"nobody" (Apache, ...) from reading Tor relay keys.
Fixes #11779 .
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-14 13:15:18 +00:00
Peter Müller
4fc1a0045b
amavisd: update to 2.11.1
...
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-13 09:35:07 +00:00
Peter Müller
867151a8b2
Postfix: update to 3.4.3
...
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-13 09:35:07 +00:00
Arne Fitzenreiter
eaf004a468
knot: update to 2.8.0 and build/install only kdig
...
This fix compile errors on small arm boards. (cc1 internal error)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-13 15:06:23 +01:00
Arne Fitzenreiter
b57220aacd
groff: update to 1.22.4
...
This fix compile problems on small arm boards. (cc1 internal error)
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-13 15:04:40 +01:00