Michael Tremer
5e6fa03e1e
vpnmain.cgi: Correctly carry over INACTIVITY_TIMEOUT
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
326728d53d
IPsec: Write tunnel/transport mode to strongSwan configuration
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
29f5e0e2b9
IPsec: Add selection for transport/tunnel mode
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Jonatan Schlag
08d91c0f7a
python3-msgpack: Fix build on i586
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 09:02:18 +00:00
Michael Tremer
e20b7de067
python3-dateutil: Update rootfiles
...
Changed because of new python3-setuptools
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 07:00:13 +00:00
Michael Tremer
1cca99e3a1
core128: Ship updated dhcpcd
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 00:40:02 +00:00
Matthias Fischer
2378f373dd
dhcpcd: Update to 7.1.0
...
For some informations about this update see:
https://roy.marples.name/blog/dhcpcd-7-1-0-released
"dhcpcd-7.1.0 has been released with the following changes:
- OpenBSD: works alongside slaacd(8)
- NetBSD: sets SO_RERROR on to detect receive socket overflow
- BSD: route improvements to avoid listening for own changes
- Linux: use NETLINK_BROADCAST_ERROR
- BSD: avoid late address deletion messages by testing address existance
- IP6: implement IP6 address sharing
- BSD: catch UP/DOWN events when interfaces does support media changes
- IPv4LL: remember old address when carrier is lost
Many other minor fixes and documenation updates have been submitted by various
community members for this release..."
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 00:39:25 +00:00
Michael Tremer
60c692e385
core128: Ship updated curl
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 00:15:24 +00:00
Matthias Fischer
d2b7811b15
curl: Update to 7.63.0
...
For details see:
https://curl.haxx.se/changes.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 00:14:59 +00:00
Erik Kapfer
b4285088a1
update.sh: Delete .rnd files
...
Since RANDFILE has been disabled in OpenSSL configurations, .rnd files are not needed anymore.
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-03 21:43:23 +00:00
Michael Tremer
06232b041a
core128: Ship updated apr
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-03 21:42:43 +00:00
Wolfgang Apolinarski
33f7d610fb
Updated apr, stabilized apache build
...
- Updated apr to 1.6.5
- Stabilized apache build (rebuild)
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-03 21:41:33 +00:00
Arne Fitzenreiter
22f7be0d4d
python3-llfuse: fix rootfile for non x86_64 builds
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-03 15:28:52 +01:00
Arne Fitzenreiter
329788dee5
kernel: update to 4.14.97
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-02-03 12:45:52 +01:00
Michael Tremer
2a915f98cb
haproxy: Bump version to support TLSv1.3 (and PCRE JIT)
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 17:34:02 +00:00
Michael Tremer
83064ee34e
core128: Restart updated apache
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 17:12:23 +00:00
Matthias Fischer
57bc05a53d
apache: Update to 2.4.38
...
For details see:
http://mirror.checkdomain.de/apache//httpd/CHANGES_2.4.38
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 17:09:49 +00:00
Michael Tremer
2d8187e8e0
core128: Ship AWS scripts again
...
It seems that this was missing in Core Update 125/126 so not all
bug fixes made it into the release.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 17:08:44 +00:00
Jonatan Schlag
46114d79d9
Add new package borgbackup
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 16:27:23 +00:00
Jonatan Schlag
def9f4a3e0
Add new package python3-msgpack
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 16:27:16 +00:00
Jonatan Schlag
3be819876b
Add new package python3-llfuse
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 16:27:06 +00:00
Jonatan Schlag
662b2a812f
Add new package python3-setuptools-scm
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 16:26:59 +00:00
Jonatan Schlag
2d17377aa0
Add new package python3-settuptools
...
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-01 16:26:39 +00:00
Michael Tremer
feeda1e4dd
core128: Delete SSE2-optimised legacy OpenSSL libraries, too
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-30 18:37:26 +00:00
Michael Tremer
898fe209ff
core128: Ship updated OpenSSL configuration files
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-29 13:51:37 +00:00
Erik Kapfer
a946892338
del_rand: Deletion of RAND file in openssl config
...
Fixes #11943
Since the kernel RNG should do this, there is no need for this anymore.
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-29 13:49:29 +00:00
Matthias Fischer
61ee842911
ghostscript: Update to 9.26
...
For details see:
https://www.ghostscript.com/doc/9.26/News.htm
This version fixes CVE-2019-6116 ("code execution via subroutines within pseudo-operators")
Some details (german) can be found here:
https://www.heise.de/security/meldung/Boeser-Bug-in-PostScript-trifft-ghostscript-und-damit-Viele-mehr-4286563.html
I saw this article and found it could be the time for an update...
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-27 22:26:55 +00:00
Michael Tremer
d03916e558
Enable some performance tuning
...
These parameters increase the throughput on various (large-ish)
systems by 5-10% on the slight expense of higher power consumption.
Socket buffers are increases and the system is configured to be
less aggressive when scheduling processes from one processor to
another one which ensures that the cache remains "hot" for longer.
On a slower system (apu1d) no performance improvement or loss
could have been measured.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-24 12:31:27 +00:00
Michael Tremer
7ec83993e5
proxy: Show error messages in English by default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 06:21:53 +00:00
Peter Müller
75936b067f
Postfix: update to 3.3.2
...
See http://www.postfix.org/announcements/postfix-3.3.2.html for release
note. This makes Postfix TLS 1.3/OpenSSL 1.1.1a ready.
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 05:41:33 +00:00
Michael Tremer
0a44d9bcec
core128: Ship updated ca-certificates
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 05:40:41 +00:00
Peter Müller
07c36be56f
update ca-certificates CA bundle
...
Update the CA certificates list to what Mozilla NSS ships currently.
The original file can be retrieved from:
https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 05:40:21 +00:00
Michael Tremer
bdc8310154
core128: Ship updated openssh
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 05:40:04 +00:00
Peter Müller
fee8b1c504
OpenSSH: update to 7.9p1
...
Update OpenSSH to 7.9p1 (release note is available at
https://www.openssh.com/txt/release-7.9 ). Patching support
for OpenSSL 1.1.0 is no longer required, thus the orphaned
patchfile has been deleted.
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 05:13:47 +00:00
Arne Fitzenreiter
be838808e1
Merge remote-tracking branch 'origin/master' into next
2019-01-23 21:19:01 +01:00
Arne Fitzenreiter
7c26f07dab
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-01-23 21:18:44 +01:00
Arne Fitzenreiter
b9d494e773
kernel: update to 4.14.95
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-01-23 18:44:26 +01:00
Peter Müller
903052ddea
use HTTPS for downloading GeoIP database files
...
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 04:12:49 +00:00
Michael Tremer
480e301442
xtables-addons: Fix generating GeoIP database
...
Perl seems to have a very funny feature where you cannot rely on
how it formats IP addresses into a binary string.
This seems to be 16 bytes long for IPv4 addresses when we (and the kernel)
only expect 4.
This patch changes this so that the last 12 bytes are just being dropped.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 04:12:41 +00:00
Michael Tremer
26d07ee5da
core128: Ship updated tzdata
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 03:06:07 +00:00
Peter Müller
0661be620b
tzdata: update to 2018i
...
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-23 02:53:20 +00:00
Michael Tremer
b7ddf23b72
strongswan: Update to 5.7.2
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-22 05:32:42 +00:00
Arne Fitzenreiter
ec7d630b62
kernel: x86_64 encrease NR_CPUS to 64
...
fixes #11963
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-01-22 07:46:08 +01:00
Arne Fitzenreiter
503a6f155b
kernel: update to 4.14.94
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-01-22 07:41:18 +01:00
Michael Tremer
eacf8dc4b7
core128: Ship updated xt_geoip_update script
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-21 21:04:10 +00:00
Peter Müller
d38e7e256d
use HTTPS for downloading GeoIP database files
...
Signed-off-by: Peter Müller <peter.mueller@link38.eu >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-21 21:03:38 +00:00
Michael Tremer
f6326e4f77
core128: Ship updated logrotate
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-21 10:20:29 +00:00
Matthias Fischer
6f1aa31f01
logrotate: Update to 3.15
...
For details see:
https://github.com/logrotate/logrotate/releases
- timer unit: change trigger fuzz from 12h to 1h (#230 )
- service unit: only run if /var/log is mounted (#230 )
- preserve fractional part of timestamps when compressing (#226 )
- re-indent source code using spaces only (#188 )
- minage: avoid rounding issue while comparing the amount of seconds (#36 )
- never remove old log files if rotate -1 is specified (#202 )
- return non-zero exit status if a config file contains an error (#199 )
- make copytruncate work with rotate 0 (#191 )
- warn user if both size and the time interval options are used (#192 )
- pass rotated log file name as the 2nd argument of the postrotate script
when sharedscript is not enabled (#193 )
- rename logrotate-default to logrotate.conf (#187 )
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-01-21 10:20:12 +00:00
Arne Fitzenreiter
9b86a7ec28
Merge remote-tracking branch 'origin/master' into next
2019-01-19 19:58:48 +01:00
Arne Fitzenreiter
f29ff21cd6
core127: run xt_geoip_update
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-01-19 17:24:47 +01:00