Matthias Fischer
5f2e713ec8
apache: Update to 2.4.39
...
For details see:
http://mirror.checkdomain.de/apache//httpd/CHANGES_2.4.39
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:03:22 +01:00
Michael Tremer
7299559611
freeradius: Fix extra whitespace
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-04 02:00:29 +01:00
Arne Fitzenreiter
df95c62f3a
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-04-03 21:53:22 +00:00
Michael Tremer
94f89b821e
freeradius: handle special LDFLAGS to configure
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-04-03 21:52:04 +00:00
Michael Tremer
0e54ca2602
pcengines-apu-firmware: New package
...
This package ships the latest BIOS for PC Engines APU boards.
With help of the firmware-update package, this can be very easily
updated when running IPFire.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:42:19 +01:00
Michael Tremer
2aca6aa061
firmware-update: New package
...
This is a script that can update firmware on PC Engines APU systems
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:33:44 +01:00
Michael Tremer
82d176d33b
flashrom: New package
...
This is required to flash firmware
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-03 00:26:13 +01:00
Michael Tremer
48d3cde9ce
kernel: Disable some debugging in expactation to increase performance
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 21:58:23 +01:00
Michael Tremer
474a6a5978
kernel: Enable strict checks for /dev/mem
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 21:55:03 +01:00
Michael Tremer
4038d70b76
freeradius: Fix build on armv5tel
...
Reported-by: Arne Fitzenreiter <arne.fitzenreiter@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 21:35:56 +01:00
Michael Tremer
84fca55b33
Update translations
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 16:53:50 +01:00
Stefan Schantl
d38f3eed08
IDS: Rename sourcefire VRT rulesets to Talos VRT rulesets
...
Fixes #12019
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-01 16:53:26 +01:00
Arne Fitzenreiter
78c8fe06a5
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2019-03-31 18:36:44 +02:00
Jonatan Schlag
56f4ba9b01
Update borgbackup to version 1.1.9
...
Fixes : #12016
Signed-off-by: Jonatan Schlag <jonatan.schlag@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-31 13:32:10 +01:00
Arne Fitzenreiter
d00d788be4
kernel: update to 4.14.109
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-31 11:46:34 +02:00
Arne Fitzenreiter
3005eb2234
kernel: update user regd patch from openwrt
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2019-03-30 16:56:56 +01:00
Arne Fitzenreiter
c955ae653a
Merge remote-tracking branch 'ms/dfs' into next
2019-03-30 16:55:35 +01:00
Erik Kapfer
9f52e35066
freeradius: Update to version 3.0.18
...
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-29 13:50:18 +00:00
Matthias Fischer
10945e38f3
clamav: Update to 0.101.2
...
For details see:
https://blog.clamav.net/2019/03/clamav-01012-and-01003-patches-have.html
"ClamAV 0.101.2 is a patch release to address a handful of security related bugs."
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-29 13:50:18 +00:00
Michael Tremer
b666975ec2
unbound-dhcp-leases-bridge: Replace leases file atomically
...
When there is a large number of leases, writing the file may
take a long time. When unbound is re-reading its configuration
in that time, the file might syntactically incorrect.
This change writes the file first and then moves it
to the right place in one transaction.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-28 12:51:06 +00:00
Michael Tremer
35cdc506b0
suricata: Enable CPU affinity
...
This will tie the detection threads to a certain CPU and
slightly increases throughput on my system.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-26 21:58:01 +00:00
Michael Tremer
4d093b8105
suricata: Tie queues to a CPU core
...
This should improve performance by a small margin
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-26 21:18:45 +00:00
Erik Kapfer
effa44650e
nginx: Update to 1.15.9
...
Fixes #12023 .
Added support for http2.
Signed-off-by: Erik Kapfer <ummeegge@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-25 23:44:24 +00:00
Michael Tremer
2547e73e6b
freeradius: Bump version because package is linked against old version of OpenSSL
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 07:28:23 +00:00
Michael Tremer
3657df4ea3
DHCP: Remove double colon
...
In some languages, there were double colons in the DNS Update section
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 03:29:01 +00:00
Michael Tremer
abe2149852
GeoIP: Do not crash when locations database does not exist
...
Fixes : #12021
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 02:58:57 +00:00
Michael Tremer
d4767896cb
make.sh: Build libedit very early
...
Many packages can make use of this
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:50:30 +00:00
Michael Tremer
3210e92212
core130: Ship updated lua
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:48:39 +00:00
Matthias Fischer
6bc94afa0d
lua: Update to 5.3.5
...
For details see:
http://www.lua.org/bugs.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:41:44 +00:00
Michael Tremer
67b943c18a
core130: Ship rrdtool and collectd
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:39:51 +00:00
Matthias Fischer
b3a7120c15
rrdtool: Update to 1.7.1
...
Disabled 'lua' because otherwise building failed.
I didn't find any place or reason where 'lua' was used by 'rrdtool', so it
was deactivated.
Disabling had no noticeable effects by now. Running.
Please note:
'/usr/lib/collectd/rrdcached.so' and '/usr/lib/collectd/rrdtool.so' have to
be updated, too.
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-21 20:38:41 +00:00
Michael Tremer
b6c60092db
openvpn: Remove subnet check for static pools
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-22 15:24:03 +00:00
Michael Tremer
fd0b2742bf
dnsdist: Update to 1.3.3
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 04:38:41 +00:00
Michael Tremer
aac6015042
dnsdist: Install some symlinks to start the service
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 02:54:37 +00:00
Michael Tremer
5b8ff1ccb6
dnsdist: Add backup include
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 02:54:30 +00:00
Michael Tremer
af2dc11c92
Rootfile update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 23:09:11 +00:00
Stefan Schantl
b60fd7a3e2
Core 130: Remove files after convert-snort has been launched
...
The converter requires /etc/snort/snort.conf to grab the used rule files
(categories). After all settings have been converted, we are fine to delete all
snort related files, because none of them is needed anymore.
Also the /var/ipfire/snort directory needs to be deleted. If it will be left on the
system and at any later time a backup will get restored, the converter will be
started by the backup script, because it detects that a snort settins dir exists
and would be restore the old snort settings and replaces all current IPS settings.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 21:22:50 +00:00
Michael Tremer
ceaf0ef008
dnsforward.cgi: Add DNSSEC option to legend
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 17:26:16 +00:00
Michael Tremer
08ded6035f
dnsforward.cgi: Check DISABLE_DNSSEC checkbox when editing
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:36:04 +00:00
Michael Tremer
3b521c724f
ipsec-interfaces: Apply static routes (again) after creating IPsec interfaces
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:25:48 +00:00
Michael Tremer
c31c8078cf
hostapd: Always enable 80 MHz channel width for 802.11ac
...
This is mandatory to support by all hardware and works well.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Michael Tremer
70a7c454af
hostapd: Automatically disassociate any clients with high error rates
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Michael Tremer
30c33cb318
kernel: Enable debugging for Atheros drivers
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Michael Tremer
62bf7bd2b2
kernel: Enable DFS support for ath*k drivers
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:36:03 +00:00
Michael Tremer
57521504a8
hostapd: Bump package version
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:34:19 +00:00
Peter Müller
5b4464a944
hostapd: make client isolation configurable via WebUI
...
hostapd supports client-isolation, but this feature could
not be configured via the WebUI so far. Since it might be
desired in public wireless networks, or even private ones,
it makes sense to provide a radio button to let the user
decide on.
Fixes #11974 .
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:34:06 +00:00
Peter Müller
a10b0e5b44
ensure Tor daemon files have correct permissions
...
Set permissions for /var/lib/tor and /var/ipfire/tor to
tor:tor, regardless whether Tor user has been created before
or not.
This ensures Tor starts properly on existing systems after
reinstallation of the add-on. Thanks to Michael for the hint.
Further, a comment for new Tor user in /etc/passwd has been added.
Fixes #11779 .
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:32:57 +00:00
Michael Tremer
a46903cce3
core130: Ship updated unbound
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:32:10 +00:00
Matthias Fischer
6f8b156bf0
unbound: Update to 1.9.1
...
For details see:
https://nlnetlabs.nl/pipermail/unbound-users/2019-March/011415.html
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:31:29 +00:00
Michael Tremer
2c703afc04
core130: Ship updated ntp
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-16 12:30:22 +00:00