Stefan Schantl
ea5c8eeb83
ids.cgi: Seperate IPS and ruleset settings
...
Now each of both have their own corresponding configuration areas.
The taken settings will be saved in "/var/ipfire/suricata/settings" for
all IDS/IPS related settings and in "/var/ipfire/suricata/rules-settings" for
ruleset related settings.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-24 08:26:39 +01:00
Stefan Schantl
aac8e30831
langs/en.pl: Fix typo
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-23 21:05:37 +01:00
Stefan Schantl
ebdd0f9a90
ids.cgi: Prevent from starting suricata without ruleset or selected network zone
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-20 13:18:48 +01:00
Stefan Schantl
0a1bba1a1d
ids.cgi: Access ruleset by its own name
...
This improves accessing the single rules of a rule category.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-20 11:55:13 +01:00
Stefan Schantl
8353c3fd36
ids.cgi: Allways use the whitelist
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-18 15:19:30 +01:00
Stefan Schantl
25b6545a6e
ids-functions.pl: Use temporary file in downloader.
...
Download the requested rules tarball into a temporay file
and if every thing is fine, replace the old by the
downloaded one.
In addition with the previously implemented file size check,
we are saved now from a corrupt rules tarball on disk.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-18 15:14:08 +01:00
Stefan Schantl
96da5803a7
ids-functions.pl: Introduce filesize check for downloader
...
The downloader now requests the html header for the rulestarball
and obtain the size of the file bevore downloading it.
After success the size of the downloaded file will be compared with
the requested one before. If they do not match, an error will be gained.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-18 14:16:13 +01:00
Stefan Schantl
1201c1e746
ids-functions.pl: Fix sub _cleanup_rulesdir() function
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-18 14:12:52 +01:00
Stefan Schantl
f5ad510e3c
suricata: Use "2" as repeat-mark and repeat-mask.
...
The previous used "1" was already used to mark source-natted
packets.
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-17 15:04:48 +01:00
Stefan Schantl
208cb3363f
suricata: Update to 4.0.6
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-17 15:03:10 +01:00
Stefan Schantl
a13ddf04d9
Merge branch 'next' of ssh://git.ipfire.org/pub/git/ipfire-2.x into next-suricata
...
Signed-off-by: Stefan Schantl <stefan.schantl@ipfire.org >
2018-12-12 09:27:59 +01:00
Michael Tremer
58e840bd96
installer: Intialize part_boot_efi_idx
...
This variable was not initialized on systems where EFI was not
in use. Therefore the generated parted command line was not
valid and caused the installation to abort.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 20:43:24 +00:00
Michael Tremer
de4f303186
core127: Ship updated unbound
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:46:10 +00:00
Matthias Fischer
707846392e
unbound: Update to 1.8.2
...
For details see:
https://nlnetlabs.nl/projects/unbound/download/
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:45:28 +00:00
Matthias Fischer
5df66de303
clamav: Update to 0.101.0
...
For details see:
https://blog.clamav.net/
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:42:22 +00:00
Michael Tremer
8b02a92fe7
core127: Ship updated fireinfo
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:41:31 +00:00
Michael Tremer
66f7b646cd
Start Core Update 127
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:41:09 +00:00
Michael Tremer
7e17de5f86
fireinfo: Add authentication for upstream proxies
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-11 19:38:21 +00:00
Arne Fitzenreiter
adde1ca8ce
Merge branch 'master' into next
2018-12-11 08:01:59 +01:00
Arne Fitzenreiter
ed4bbe44d1
kernel: fix dwc2 (usb) dma crashes on RPi1-3
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-10 20:45:54 +01:00
Michael Tremer
c519be4226
haproxy: Create/restore backup when package is installed/uninstalled
...
Fixes : #11946
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-10 00:36:04 +00:00
Arne Fitzenreiter
ede4314397
core126: finish core126
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-08 17:47:16 +01:00
Arne Fitzenreiter
c030bfba2e
core126: fix "need reboot display"
...
The display should displayed always except the linux-pae
packages is planned to be installed after this update.
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-07 21:16:43 +01:00
Arne Fitzenreiter
d05fe8e3e5
Merge branch 'next' of git.ipfire.org:/pub/git/ipfire-2.x into next
2018-12-07 21:06:45 +01:00
Arne Fitzenreiter
23a3aec100
cpufrequtils: update initskript for xz compressed modules
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-07 21:05:50 +01:00
Michael Tremer
f354601bbe
initscripts: Import pakfire keys before importing AWS configuration
...
This is useful when the user-data script is installing
packages. For that it will need valid keys for course.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-07 11:38:55 +00:00
Arne Fitzenreiter
56726ed954
rngd: update initskript and add hwrngtty support
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-06 22:33:05 +01:00
Arne Fitzenreiter
8d638b63f8
core126: add kernel files to update
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-06 16:05:31 +01:00
Arne Fitzenreiter
19f37f2493
core126: add kernel to updater
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-06 11:27:46 +01:00
Arne Fitzenreiter
827dd0faa4
kernel: update to 4.14.86
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-06 11:18:37 +01:00
Michael Tremer
93363446e4
AWS: Add a timestamp to user-data.log
...
This way, multiple (failed) runs of the script won't
overwrite the log file.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-05 14:42:54 +00:00
Michael Tremer
1022b203ad
AWS: Write user-data.log to /var/log
...
This should not be in /root at all.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-05 14:38:28 +00:00
Michael Tremer
87487585c0
make.sh: Build for x86_64 by default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-02 10:23:15 +00:00
Arne Fitzenreiter
91e08f20ff
kernel: update to 4.14.85
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-12-02 00:01:37 +01:00
Michael Tremer
e0986954d4
bird: Launch service on install and add symlinks to start at boot time
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
a4e3a76af9
bird: Add initscript
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
b5b8920cf0
bird: Add forgotten file
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
e122256d8f
core126: Ship recently updated packages
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Matthias Fischer
9a12784047
BUG 11929: Build 'bind'-binaries dynamically and install needed libraries (V2)
...
Hi,
To save space linking the 'bind 9.11.5'-binaries was changed from statically to dynamically.
Changes to V2:
Removed unnecessary '*.so'-links.
Complete file sizes shrinked from ~4800K to ~1700K. Needs testing and confirmation!
I'm running this version right now under Core 124 - no seen problems so far.
Best,
Matthias
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org >
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
046b436c76
bird: Update to 2.0.2
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
be7f989249
bird: Backup configuration file on update
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-12-01 16:13:25 +00:00
Michael Tremer
4fc73ace76
docker: Always agree to install all updates
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-30 20:16:08 +00:00
Arne Fitzenreiter
ef9cc2e5d5
kernel: update arm-multi patchset
...
now patches for Raspberry Pi 3B+
LAN and WLAN included to patchset.
https://git.ipfire.org/?p=people/arne_f/kernel.git;a=shortlog;h=refs/tags/v4.14.84-multi
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-11-30 07:35:07 +01:00
Michael Tremer
cd022294d9
nfs: Fix build
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-29 13:17:30 +00:00
Arne Fitzenreiter
9743182472
kernel: update to 4.14.84
...
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org >
2018-11-29 07:02:25 +01:00
Michael Tremer
3eea5c6f3a
nfs: Add backup include file
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-28 19:08:17 +00:00
Michael Tremer
77729e5be8
nfs: Install configuration in package
...
This was lost in the last update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-28 19:02:53 +00:00
Michael Tremer
1ee8c6732f
Update maintainers
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-27 10:24:29 +00:00
Michael Tremer
86705346a7
git: Fix spelling of some contributors with umlauts
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-27 10:23:46 +00:00
Michael Tremer
9bdc8f854c
credits.cgi: Remove old dev section
...
I do not know why I forgot this. Now it is how it was intended
in the first place.
This commit removes all email addresses because people keep
emailing me for private support. Use the forum guys!
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2018-11-27 10:20:09 +00:00