Commit Graph

12011 Commits

Author SHA1 Message Date
Peter Müller
eeab80f8dc libnetfilter_conntrack: update to 1.0.7
Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 12:35:53 +01:00
Peter Müller
733fae2abe iptables: update to 1.6.2
Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 12:35:52 +01:00
Michael Tremer
46a5bac6ed vpnmain.cgi: Remove unused code that prevented the page from loading without GREEN
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 12:24:25 +01:00
Michael Tremer
080e79f149 Don't show proxy configuration pages when GREEN is not available
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 12:21:59 +01:00
Michael Tremer
dc845b6c81 AWS: Hide certain things on the web UI
Those are practically unusable on AWS.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 12:15:00 +01:00
Michael Tremer
eb7ccf87c5 AWS: Store instance id
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:54:51 +01:00
Michael Tremer
464c27554c aws: Re-enable check if we are actually running on EC2
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:52:54 +01:00
Michael Tremer
9a56118b61 aws: Suppress any output from ending dhclient
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:51:39 +01:00
Michael Tremer
787469ebd6 aws: No need to wake up udev again
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:51:18 +01:00
Michael Tremer
475ae4b3db firewall: Suppress more warnings when initialising without GREEN
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:49:57 +01:00
Michael Tremer
470e85c365 AWS: Rename network interfaces only when necessary
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:44:14 +01:00
Michael Tremer
2e42a9eaa1 AWS: Import SSH keys before meddling with the network
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 11:43:35 +01:00
Michael Tremer
48a7737fdd firewall: Allow starting without a green interface
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-07-01 10:32:31 +01:00
Michael Tremer
f487e37393 AWS: No need to restart udev any more
The renames the network interfaces itself now

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 20:35:29 +01:00
Michael Tremer
4c0bd63ea4 localnet: Don't write local hostname to /etc/hosts
This is now being provided by nss-myhostname

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:58:42 +01:00
Michael Tremer
a1c5ceeb34 nsswitch.conf: Use nss-myhostname to resolve local hostname
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:56:56 +01:00
Michael Tremer
4e9000b4d8 nss-myhostname: New package
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:51:38 +01:00
Michael Tremer
c7141f0479 AWS: Rename all interfaces when booting up
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:40:31 +01:00
Michael Tremer
8f2c3b49b6 aws: Apply SSH configuration changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:25:29 +01:00
Michael Tremer
16c31d1004 openssh: Write port 22 into the default configuration file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-30 19:25:15 +01:00
Michael Tremer
7d06d0de7b AWS: Restart udev to rename network interfaces
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-28 11:15:29 +01:00
Michael Tremer
0f224ad770 AWS: Add support for ORANGE
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-28 11:01:33 +01:00
Michael Tremer
1a0d8b0573 AWS: Remove some debugging line
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-28 10:57:50 +01:00
Michael Tremer
c86fd963d2 AWS: Calculate gateway and DNS IP addresses only for RED
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-28 10:57:13 +01:00
Michael Tremer
607240e28c AWS: Use correct IP address for the internal DNS
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-28 10:56:06 +01:00
Michael Tremer
3273ff48f0 aws: Write HOSTNAME and DOMAINNAME when not set
Previously we expected the entire settings file to be empty
but since we are now shipping some defaults for other settings.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-27 10:05:55 +01:00
Michael Tremer
0009de91e8 Ship default settings for language, theme, etc. in all images
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-27 09:59:47 +01:00
Michael Tremer
8b59ef085e aws: Ensure that SSH checkbox is enabled, too
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-27 09:56:32 +01:00
Michael Tremer
7fa83c2fe7 aws: Enable SSH on the first start
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-27 09:55:39 +01:00
Michael Tremer
fd52e82a72 setup: Write /etc/hosts in initscript
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 11:08:04 +01:00
Michael Tremer
d97ba75fe5 setup: Don't write configuration files for TCP wrapper any more
This has been removed from the distribution a long time ago

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 11:01:24 +01:00
Michael Tremer
6723afef09 apache: Write hostname into configuration at boot time
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 10:59:49 +01:00
Michael Tremer
bd3bcb45d6 AWS: Import aws setup script
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 10:55:39 +01:00
Michael Tremer
563c502163 dhcp: Ship dhclient
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 10:54:36 +01:00
Michael Tremer
3483602929 ssh: Update default configuration
This patch removes an old switch to enable SSH 1 and
makes port 22 the default port.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-25 10:53:53 +01:00
Michael Tremer
1c21ebf8d5 Add initscript that automatically configures IPFire on AWS EC2
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-21 16:45:40 +01:00
Michael Tremer
1f2a90b552 flash-image: Make sure that GRUB boots the first entry
This is required when importing an image into AWS EC2 or
the import of the image fails.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-21 16:45:40 +01:00
Michael Tremer
bc91a66281 core123: Ship updated iana-etc
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:34:38 +01:00
Peter Müller
319aedce97 iana-etc: update to 2.30
Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:34:25 +01:00
Erik Kapfer
823c6d270a libstatgrab: Update tp 0.91
Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:33:51 +01:00
Erik Kapfer
e3dda65eba OpenVPN: Delete 1024 bit DH-parameter from menu
Since OpenVPN-2.4.x do not accepts 1024 bit DH-parameter for security concerns anymore,
    it has been removed from the menu.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:31:19 +01:00
Michael Tremer
1feef6be7c core123: Ship /var/ipfire/backup/exclude
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:31:01 +01:00
Erik Kapfer
291bfda71e backup: Exclude OpenVPNs ovpn.cnf from backup
This fixes also bug #11773

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:30:40 +01:00
Michael Tremer
b1f4acadde core123: Ship updated gnupg
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:30:26 +01:00
Peter Müller
e4529a9bc0 gnupg: update to 1.4.23
Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-19 11:29:46 +01:00
Erik Kapfer
beac479f2d OpenVPN: Prevent that a Roadwarrior name will be set two times
Fixes bug #11307

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-18 16:48:24 +01:00
Michael Tremer
28aacf565b Start Core Update 123
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-18 16:43:04 +01:00
Erik Kapfer
87ea30ff56 OpenVPN: Fix upload check for root and host certificate
Fix for #11766 .
Since the new OpenSSL output differs in the 'Subject' section, the regex needed to be adapted.
Old and new output should now be possible.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-18 16:31:48 +01:00
Erik Kapfer
c0a7c9b278 OpenVPN: Set default of 730 days for client certificate validity
Since OpenSSL 1.1.0x it is required to set a value for the 'valid til (days)' field.
The WUI delivers now a guide value of two years.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-18 15:49:24 +01:00
Erik Kapfer
7ea54fee01 ipset: Update to 6.38
Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-06-18 15:06:22 +01:00