Commit Graph

6754 Commits

Author SHA1 Message Date
Arne Fitzenreiter
3ec3329dff unbound: rework dns-forwader handling
add check if red interface has an IPv4 address before test the servers at
red up and simply remove forwarders at down process.

This also fix the hung at dhcpd shutdown.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-07-16 19:20:48 +02:00
Peter Müller
4a46575628 unbound-dhcp-leases-bridge: handle PTR generation parameter
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Reported-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-15 12:22:51 +01:00
Arne Fitzenreiter
6511460487 unbound: update root.hints to 2019070301
IPv4 of server B has changed. Other changes are whitespace only.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-07-14 07:45:51 +02:00
Michael Tremer
d0d79462d6 core135: Ship updated squid
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-09 09:54:55 +01:00
Peter Müller
dd4f9a87c1 Core Update 135: ship updated tzdata
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-08 11:15:05 +01:00
Michael Tremer
65650ec69b core135: Ship updated sysctl.conf
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-04 11:22:13 +01:00
Peter Müller
ef21f3e49d sysctl: improve KASLR effectiveness for mmap
By feeding more random bits into mmap allocation, the
effectiveness of KASLR will be improved, making attacks
trying to bypass address randomisation more difficult.

Changed sysctl values are:

vm.mmap_rnd_bits = 32 (default: 28)
vm.mmap_rnd_compat_bits = 16 (default: 8)

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-04 11:22:13 +01:00
Michael Tremer
8650d11bc3 core135: Ship forgotten ddns package
This was updated before, but I forgot to ship it in the updater.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-03 14:57:04 +01:00
Michael Tremer
2aab3e9a33 core135: Ship cloud-init changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-01 07:55:53 +01:00
Michael Tremer
acf47bfa80 cloud-init: Import experimental configuration script for Azure
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-01 07:53:58 +01:00
Michael Tremer
ffb37e51d4 Rename AWS initscript to cloud-init
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-01 07:53:58 +01:00
Michael Tremer
7d38e8a941 core135: Ship updated packages/files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-01 07:52:57 +01:00
Michael Tremer
12f462f154 Start Core Update 135
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-07-01 07:50:48 +01:00
Matthias Fischer
1c505151cb nettle: Update to 3.5.1
For details see:
https://git.lysator.liu.se/nettle/nettle/blob/master/ChangeLog

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-25 08:18:15 +01:00
Michael Tremer
759be5855f linux: Fix rootfile to ship GeoIP modules
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-24 14:39:30 +01:00
Matthias Fischer
4e5802a9be mc: Update to 4.8.23
For details see:
http://midnight-commander.org/wiki/NEWS-4.8.23

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-21 15:21:58 +01:00
Arne Fitzenreiter
4e69701332 intel-microcode: update to 20190618
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-06-22 21:05:21 +02:00
Michael Tremer
92f6c5ed86 core134: Ship updated firewall initscript
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-21 01:39:18 +01:00
Michael Tremer
7866fa2513 core134: Ship updated bind
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-21 01:39:18 +01:00
Matthias Fischer
f3959d13e8 bind: Update to 9.11.8
For Details see:
https://downloads.isc.org/isc/bind9/9.11.8/RELEASE-NOTES-bind-9.11.8.html

"Security Fixes
    A race condition could trigger an assertion failure when a large number
    of incoming packets were being rejected.
    This flaw is disclosed in CVE-2019-6471. [GL #942]"

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-21 01:39:18 +01:00
Arne Fitzenreiter
744f16e45a core134: ship core133 late fixes again
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-06-21 11:58:58 +02:00
Arne Fitzenreiter
70590cef48 Kernel: update to 4.14.128
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-06-19 21:01:29 +02:00
Michael Tremer
4b64da2914 core134: Ship updated vim
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 22:35:23 +01:00
Matthias Fischer
beac384541 Remove old vim 7.4 data
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 22:35:07 +01:00
Matthias Fischer
98f55e136f vim: Update to 8.1
Please note:
If this gets merged, the update process must deal with the otherwise remaining
files in '/usr/share/vim74' (~16 MB).

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 22:34:55 +01:00
Arne Fitzenreiter
a04eedfe7d core134: add kernel to updater
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-06-18 18:55:11 +02:00
Arne Fitzenreiter
15ca18a3d9 Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next 2019-06-18 18:42:02 +02:00
Arne Fitzenreiter
82c279a518 kernel: update to 4.14.127
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2019-06-18 18:41:19 +02:00
Michael Tremer
7516e8b7f1 core134: Ship changed general-functions.pl
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 09:13:21 +01:00
Alexander Marx
cc724c142a BUG12070: Its not possible to use the underscore in email addresses
Using IPFire's Mailservice does not allow to enter a senders mail address with the underscore.
The function used to verify that is used from general-functions.pl.
Now the function 'validemail' allows the underscore in the address.

Fixes: #12070

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 09:12:49 +01:00
Michael Tremer
82899ad1ce core134: Ship updated unbound
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-18 09:11:18 +01:00
Matthias Fischer
2f278de868 unbound: Update to 1.9.2
For details see:
https://nlnetlabs.nl/pipermail/unbound-users/2019-June/011632.html

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-17 17:39:37 +01:00
Michael Tremer
527078e439 core134: Ship updated OpenSSL
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-12 17:25:13 +01:00
Michael Tremer
ce46df9b83 Start Core Update 134
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-12 17:18:23 +01:00
Michael Tremer
5d65813aa3 core133: Ship updated wpa_supplicant
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-11 07:00:38 +01:00
Peter Müller
8e101c0bda ship language files in Core Update 133
These were missing in Core Update 132, and some strings
(especially on the "CPU vulnerabilities" page) missed translations.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-10 19:44:59 +01:00
Michael Tremer
35f12f2998 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-10 09:58:15 +01:00
Stefan Schantl
33afb0681f convert-ids-modifysids-file: Fix check if the ids is running.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-10 09:46:00 +01:00
Michael Tremer
28093c8376 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-08 11:34:37 +01:00
Michael Tremer
09b9910696 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-07 11:14:11 +01:00
Michael Tremer
c0fc25861f core133: Ship updated knot package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-07 11:13:01 +01:00
Stefan Schantl
3c91ee8092 convert-ids-modifysids-file: Adjust code to use changed write_modify_sids_file function
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:43:09 +01:00
Michael Tremer
e1f8f870ea core133: Ship snort configuration converter
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:42:53 +01:00
Stefan Schantl
f1add9a8dd convert-snort: Adjust code to use changed modify_sids_file function.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:42:00 +01:00
Stefan Schantl
81bae51f61 ids-functions.pl: Rework function write_modify_sids_file().
Directly implement the logic to determine the used ruleset and if
IDS or IPS mode should be used into the function instead of pass those
details as arguments.

This helps to prevent from doing this stuff at several places again and again.

Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:41:49 +01:00
Michael Tremer
a40bcbb02c core133: Ship IPS changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:41:37 +01:00
Tim FitzGeorge
a5ba473c15 suricata: correct rule actions in IPS mode
In IPS mode rule actions need to be have the action 'drop' for the
protection to work, however this is not appropriate for all rules.
Modify the generator for oinkmaster-modify-sids.conf to leave
rules with the action 'alert' here this is appropriate.  Also add
a script to be run on update to correct existing downloaded rules.

Fixes #12086

Signed-off-by: Tim FitzGeorge <ipfr@tfitzgeorge.me.uk>
Tested-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:39:57 +01:00
Michael Tremer
9734a58faf core133: Ship IDS ruleset updater
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 12:34:44 +01:00
Michael Tremer
dc9ac30c8d core133: Ship updated vpnmain.cgi file and regenerate configuration
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 05:08:31 +01:00
Matthias Fischer
01320a141d monit: Some fixes for 'monitrc'
Just cosmetics:
Removed all trailing spaces - there were a few...

Activated 'monit' start delay:
I activated this option to avoid running into a race condition while started through
'/etc/init.d/monit start'.

As mentioned in 'monit' manual:
"...if a service is slow to start, Monit can assume that the service is not running
and possibly try to start it [again] and raise an alert, while, in fact the service
is already about to start or already in its startup sequence."

This happened here during testing with (e.g.) Clamav.

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2019-06-05 05:04:17 +01:00