Arne Fitzenreiter
3d0e252e35
intel-microcode: update to 20180807
...
fixes #11590
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-11 20:52:45 +02:00
Stefan Schantl
f7d76eecc6
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next
2018-08-11 19:50:20 +02:00
Michael Tremer
98ce897520
avahi: Bump package version
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-10 12:20:38 +01:00
Michael Tremer
5221a852e8
avahi: Build without dbus
...
We don't have any services connected to dbus, so what is the
point of avahi trying to connect to it?
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-10 12:20:06 +01:00
Michael Tremer
4ec7c2936d
avahi: Build with -U_FORTIFY_SOURCE
...
Avahi locks up when built with -D_FORTIFY_SOURCE=2
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-10 12:18:29 +01:00
Michael Tremer
467581b8ab
avahi: Update to 0.7
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-10 11:19:25 +01:00
Michael Tremer
6064cd87cc
Revert "avahi: Drop package"
...
This reverts commit aa6ee515c5 .
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-10 11:11:48 +01:00
Michael Tremer
ebbca90d70
openssh: Disable password authentication by default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-09 16:28:14 +01:00
Stefan Schantl
8d2f6b0b59
ids.cgi: Dynamically generate the HOME_NET details for suricata.
...
Introduce generate_home_net_file() which uses the current network
config to obtain the network address and subnetmask for each
available network zone, generate and write these HOME_NET information
into a yaml compatible file which can be included into the suricata
configuration file.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-09 15:33:25 +02:00
Arne Fitzenreiter
7f841117c5
kernel: fix build on x86_64
...
oops i deleted a wrong line...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-08 10:26:38 +02:00
Arne Fitzenreiter
07664187ac
kernel: fix build on armv5tel
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-07 19:05:35 +02:00
Stefan Schantl
e0bfd338ee
ids.cgi: Rename form name from SNORT to IDS
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-05 19:42:33 +02:00
Arne Fitzenreiter
7529349754
kernel: apu2 leds: update string for newer bios
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-05 17:19:52 +02:00
Arne Fitzenreiter
28b252145a
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2018-08-05 17:19:36 +02:00
Stefan Schantl
8766096429
ids.cgi: Display if the IDS is running
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-05 14:24:20 +02:00
Stefan Schantl
796eea2154
ids-functions.pl: Add function to check if the IDS is running
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-05 14:23:45 +02:00
Arne Fitzenreiter
b403b04a13
initrd: add early microcode load
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-05 13:32:36 +02:00
Stefan Schantl
1286e0d41e
ids.cgi: Rework section to configure the IDS
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-05 12:57:44 +02:00
Erik Kapfer
4a50681905
tor: Update to version 0.3.3.9
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-05 11:10:28 +01:00
Erik Kapfer
351567966d
nginx: Update to version 1.15.1
...
Deleted last slash in --prefix configure option to prevent such -->
https://forum.ipfire.org/viewtopic.php?t=19213#p109787 problems.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-05 11:10:28 +01:00
Matthias Fischer
b856ad695a
rng-tools: Update to 6.3.1
...
Bugfix release, for details see:
https://github.com/nhorman/rng-tools/releases
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-05 11:10:28 +01:00
Michael Tremer
1fb7f56e11
make.sh: Add command to update list of contributors
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-05 11:10:28 +01:00
Stefan Schantl
1cae702c22
ids-functions.pl: Add function to get the available network zones
...
The get_available_network_zones() function uses the /var/ipfire/ethernet/settings
file and translates the configured mode into an array, which contains the names
of the configured network zones.
The array will be returned and easily can be used to loop over this list of
available network zones and perform any kind of actions in other scripts.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-05 10:33:46 +02:00
Arne Fitzenreiter
79bcc6f769
collectd: fix cpufreq plugin enable
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-03 16:13:12 +02:00
Michael Tremer
f32cbd89d9
backup: Bump release number in ISO download script
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-08-03 13:07:31 +01:00
Stefan Schantl
ab114c276b
ids.cgi: Call suricatactrl for restarting the IDS
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 13:51:59 +02:00
Stefan Schantl
06b569a442
oinkmaster: Install config file to /var/ipfire/suricata
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 13:48:46 +02:00
Stefan Schantl
d33874f496
daq: Drop package
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 10:20:18 +02:00
Stefan Schantl
843a8c570c
snort: Drop package
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 10:19:35 +02:00
Stefan Schantl
914cca3d8e
initscripts: Link against suricata initscript in runlevels and red.up hook
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 10:02:34 +02:00
Stefan Schantl
74b7d695c6
misc-progs: Rename snortctrl to suricatactrl
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-03 09:50:31 +02:00
Arne Fitzenreiter
b5a1294c98
linux-firmware: update to 30.7.2018
...
include new amd microcodes for Spectre updates
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-08-02 21:15:11 +02:00
Stefan Schantl
ef640882ab
make.sh: Add ids-ruleset-source
...
I accidently forgot to commit this file in 1d9b879140
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 19:58:41 +02:00
Stefan Schantl
d72b3e64c2
suricata: Introduce basic initscript
...
Add a very basic initscript, which currently allows to start/stop/restart suricata and
check if the daemon is running.
The script will detect when starting suricata how many CPU cores are present on the system and
will launch suricata in inline mode (NFQUEUE) and listen to as much queues as CPU cores are
detected.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 19:54:22 +02:00
Stefan Schantl
101d3ece24
ids-ruleset-sources: Update download URL for snort rules
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 19:33:37 +02:00
Stefan Schantl
bce84f3975
ids-functions.pl: Rename ruleset-sources.list to ruleset-sources
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 19:31:52 +02:00
Stefan Schantl
1d9b879140
ids-ruleset-sources: New package
...
Move the file which contains the download URL's for the IDS rulesets
into an own common package. This will allow us in future to easily ship
a changed file with a core update.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 19:29:36 +02:00
Stefan Schantl
72b2109c72
configroot: Move from snort to suricata
...
Create /var/ipfire/suricata and /var/ipfire/suricata/settings instead of
/var/ipfire/snort and /var/ipfire/snort/settings.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 15:47:31 +02:00
Stefan Schantl
4c6d6c1ee3
suricata: Install very basic config file
...
This config file is mostly based on the example configuration shipped
by the suricata project and needs to be enhanched.
See #11808 .
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 09:10:25 +02:00
Stefan Schantl
101c888174
ids.cgi: Generate suricata compatiple used-rulefiles file
...
* Rename filename to suricata-used-rulefiles.yaml
* Adjust file generation as a yaml file to be compatible with suricata
* Adjust code to correctly read-in and parse the changed file
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-08-02 09:07:12 +02:00
Michael Tremer
87589bce00
backup: Make backup ISO bootable on EFI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-07-31 16:36:09 +01:00
Stefan Schantl
164eab6627
ids-functions.pl: Move path details from snort to suricata
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-30 21:36:07 +02:00
Stefan Schantl
a8b8c9e5b2
Merge branch 'next-new-ids.cgi' into next-suricata-and-cgi
2018-07-30 21:33:25 +02:00
Stefan Schantl
67752a9510
suricata: New package
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-30 21:31:15 +02:00
Michael Tremer
0cf70cae66
aws: Disable SSH password authentication by default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-07-30 16:54:50 +01:00
Stefan Schantl
3498300d87
libhtp: New package
...
This is build and runtime dependency for suricata.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-29 09:45:05 +02:00
Stefan Schantl
91cc908f84
yaml: New package
...
This is a build and runtime dependency for suricata.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-29 09:44:52 +02:00
Stefan Schantl
434001d0a0
IDS: Rework error and log handling in ids-functions.pl
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-28 16:34:50 +02:00
Stefan Schantl
02844177af
IDS: Introduce settingsdir variable
...
The $settingsdir variable is declared in the ids-functions.pl and used to to
store the path where the various files which contains the settings for the IDS and
oinkmaster is located.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-27 07:58:23 +02:00
Stefan Schantl
298ef5bafa
IDS: Move rulepath declaration to ids-functions.pl
...
This will help if the path ever changed. Also remove hard coded rulepath
from oinkmaster call.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-07-26 15:56:47 +02:00