Commit Graph

2057 Commits

Author SHA1 Message Date
Michael Tremer
c98304604b core120: Ship updated QoS script and gnupg
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:04:41 +01:00
Michael Tremer
dfdfafc7af core120: Ship updated vnstat
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-20 20:36:15 +00:00
Michael Tremer
eb68e27dd2 pakfire: Import key when system boots up
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 19:44:50 +00:00
Michael Tremer
b2318b5e35 core120: Ship updated logrotate and restart unbound
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-18 13:51:38 +00:00
Erik Kapfer
e779b6bc7a PAM: Delete old lib and symlinks
Core 119 update delivers an updated PAM whereby the libdir has been changed from /lib to /usr/lib
but the old libraries and symlinks are still presant. Since the system searches /lib before
/usr/lib , the old libs and symlinks are used which ends up in an `LIBPAM_EXTENSION_1.1' not found.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-18 13:44:04 +00:00
Michael Tremer
35b892b0dd pakfire: Drop old key import mechanism
This was error-prone and allowed to potentially inject another
key.

Fixes: #11539
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-16 14:37:21 +00:00
Michael Tremer
ceed3534e1 core120: Import new pakfire PGP key
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-16 14:28:17 +00:00
Michael Tremer
dcd60d274e core120: Ship updated qos.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-06 15:13:56 +00:00
Michael Tremer
318434affb core120: Ship updated proxy.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-06 15:12:42 +00:00
Michael Tremer
01bec95655 core120: Ship updated unbound init script
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-05 15:21:56 +00:00
Michael Tremer
568a227bd3 vpnmain.cgi: Fix reading common names from certificates
OpenSSL has changed the output of the subject lines of
certificates.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-01 19:59:14 +00:00
Michael Tremer
e707599d2c core120: Call openvpnctrl with full path
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-28 10:48:29 +00:00
Michael Tremer
d192815e83 core120: Ship everything that is linked against OpenSSL
This will make sure that everything is using the new version
of the library.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 16:22:32 +00:00
Michael Tremer
1c0cfaa594 Disable Path MTU discovery
This seems to be a failed concept and causes issues with transferring
large packets through an IPsec tunnel connection.

This configures the kernel to still respond to PMTU ICMP discovery
messages, but will not try this on its own.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 15:37:49 +00:00
Michael Tremer
f0e308ab2f core120: Fix typo in initscript name
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 15:34:10 +00:00
Michael Tremer
0eccedd1c8 dhcp: Allow adding extra DHCP interfaces
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 11:12:20 +00:00
Erik Kapfer via Development
39d11d265e OpenVPN: Ship missing OpenSSL configuration file for update
Core 115 delivered a patch which prevents the '--ns-cert-type server is deprecated' message
and introduced also '--remote-cert-tls server' -->
https://patchwork.ipfire.org/patch/1441/ whereby the changed ovpn.cnf has not been delivered.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 10:15:30 +00:00
Michael Tremer
8b080ef12b core120: Remove deprecated sshd configuration option
This just created a warning and is now dropped

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 13:06:22 +00:00
Michael Tremer
c8e4391ecc core120: Remove forgotten PHP file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:41:05 +00:00
Michael Tremer
53929f5ae8 core120: Ship updated OpenSSL 1.1.0
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:39:55 +00:00
Michael Tremer
cb8a6bf5a4 Start Core Update 120
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:20:57 +00:00
Michael Tremer
83d6101b9d core119: Reload apache after configuration changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:06:02 +00:00
Michael Tremer
3f42cf5cb9 backup: Don't backup apache configuration, keys only
In the past the apache configuration was part of the backup
and may have been restored after Core Update 118 was installed
with PHP being dropped amongst other things.

This patch will make sure that only keys are being backuped.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:06:02 +00:00
Michael Tremer
ea3b9a4f88 strongswan: Update to 5.6.2
Fixed a DoS vulnerability in the parser for PKCS#1 RSASSA-PSS
signatures that was caused by insufficient input validation.
One of the configurable parameters in algorithm identifier
structures for RSASSA-PSS signatures is the mask generation
function (MGF). Only MGF1 is currently specified for this purpose.
However, this in turn takes itself a parameter that specifies
the underlying hash function. strongSwan's parser did not
correctly handle the case of this parameter being absent,
causing an undefined data read.

This vulnerability has been registered as CVE-2018-6459.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-19 23:46:17 +00:00
Michael Tremer
a261cb06c6 IPsec: Try to restart always-on tunnels immediately
When a tunnel that is in always-on configuration closes
unexpectedly, we can instruct strongSwan to restart it
immediately which is precisely what we do now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-19 23:46:17 +00:00
Michael Tremer
429af17883 i2c-tools: New package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-16 20:01:55 +00:00
Michael Tremer
4ef4d82baa core119: Ship changed proxy.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-14 22:23:20 +00:00
Michael Tremer
71cf8c8a6f Drop perl-DBD-mysql
This package is not used by anything and depends on MySQL
which has been dropped, too.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 12:07:29 +00:00
Michael Tremer
2d5940daca Drop MySQL
This is outdated and still on 5.0.x and nobody volunteered to
update this package.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 12:05:46 +00:00
Michael Tremer
3e8ce0dd86 Drop pammysql
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:44:28 +00:00
Michael Tremer
e3e17107ba Drop tcpwrapper
This library has been unused for quite a while

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:42:47 +00:00
Michael Tremer
a350ea6dea Drop mISDN userspace tools
This is unsupported for quite a while and nobody should be using this.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:41:50 +00:00
Michael Tremer
922ec43f99 Drop capi4k-utils
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:33:51 +00:00
Michael Tremer
690a8b9d89 core119: Remove dropped lcr package during update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:31:14 +00:00
Michael Tremer
0d29afc2c1 core119: Import changed packages
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:29:53 +00:00
Michael Tremer
338087530c Start Core Update 119
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-12 11:22:58 +00:00
Michael Tremer
0da2f155fd core118: Ship changed vpnmain.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-31 13:00:44 +00:00
Michael Tremer
acbc11f342 core118: Ship changed ovpnmain.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-30 20:06:14 +00:00
Arne Fitzenreiter
f6c97e0b44 remove dropped pakages to make sure that apache not miss php files.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-01-29 19:44:17 +01:00
Michael Tremer
61f45200cf core118: Ship forgotten menu file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-29 17:29:11 +00:00
Michael Tremer
637eb1eda5 Revert "core118: Ship microcode updates for Intel processors"
This reverts commit c015d425d1.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:07:58 +00:00
Michael Tremer
a996dd211f core118: Ship updated wget
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:07:11 +00:00
Michael Tremer
68fa5e7810 core118: Ship updated sed
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-24 16:06:32 +00:00
Michael Tremer
cad9257ae2 core118: Ship LZ4
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-23 13:21:36 +00:00
Michael Tremer
fb55a868c6 core118: Ship updated squid
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-23 13:09:37 +00:00
Michael Tremer
1f91201011 firewall: Suppress warning about uninitialized array in GeoIP code
Fixes #11597

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-22 13:20:04 +00:00
Michael Tremer
e0a048fe21 poppler is now linking against glib2
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-22 13:12:56 +00:00
Peter Müller
1a9ccdf996 ship updated CA bundle
Add new generated CA bundle files to updater and remove
accidentally inserted blank line at the end of certdata.txt .

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 15:37:15 +00:00
Michael Tremer
898ff14a28 core118: Ship updated bind package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 15:34:56 +00:00
Michael Tremer
1e7b718cd4 syslogdctrl: Fix compiler error and SEGV
Fixes #11574

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-01-20 14:51:40 +00:00