Commit Graph

2048 Commits

Author SHA1 Message Date
Arne Fitzenreiter
481988c68d Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen 2013-12-30 10:35:25 +01:00
Arne Fitzenreiter
aa8512fac6 firstsetup: init udev hwdb at first boot. 2013-12-30 10:34:33 +01:00
Michael Tremer
33c4c29b5e openssl: Don't propose too weak ciphers. 2013-12-29 20:46:41 +01:00
Michael Tremer
63efc01c84 pakfire: Prevent an infinite loop with empty server list. 2013-12-28 17:06:38 +01:00
Michael Tremer
ec8c14746c Merge branch 'openssl-update' into fifteen 2013-12-27 13:32:38 +01:00
Michael Tremer
0206795e57 sslh: Move binary to /usr/sbin. 2013-12-27 11:29:10 +01:00
Michael Tremer
230eeac04d sslh: Cleanup initscript.
Calling setxtaccess has been removed and never have been used
at this place.
Also, it is checked if the external IP address was properly
read from file.
2013-12-27 11:11:29 +01:00
Erik Kapfer
55e16317fd wget: Update to 1.14. 2013-12-26 14:03:31 +01:00
Erik Kapfer
2f90f73a98 imspector: Fix build with openssl 1.0.1. 2013-12-25 20:49:26 +01:00
Erik Kapfer
0f90adc0aa openssl: Update to 1.0.1e.
Contains also the old openssl-0.9.8 libs for compatibility purposes.
2013-12-25 20:42:17 +01:00
Arne Fitzenreiter
bb234c63ef partresize: fix partresize for new arm image layout. 2013-12-23 22:28:27 +01:00
Arne Fitzenreiter
dcbb8e4f41 Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen 2013-12-23 22:27:58 +01:00
Arne Fitzenreiter
0dc552342b Merge branch 'fifteen' of ssh://git.ipfire.org/pub/git/ipfire-2.x into fifteen 2013-12-23 22:25:13 +01:00
Arne Fitzenreiter
03f02bcd20 Merge remote-tracking branch 'stevee/imx6q-wandboard-rbased' into fifteen 2013-12-23 22:24:23 +01:00
Alexander Marx
c0f99754df Firewall: now it is possible to connect from one ipfire to a green network of another openvpn connected ipfire
Please take care to put this into the docu! One can create DROP rules if
the remote ipfire should NOT be able to connect to the others internal
networks. Therefor you have to take the green interface IP as SOURCE!
2013-12-23 11:05:04 +01:00
Stefan Schantl
f7075c3a37 Kernel: Add support for PCI Express on wandboard.
When manualy a PCI Express Slot has been soldered to the board, any kind of
PCI-E hardware can be used after loading the pcie_imx kernel module.
2013-12-21 17:15:03 +01:00
Arne Fitzenreiter
30f68903d3 Merge remote-tracking branch 'origin/next' into fifteen 2013-12-21 10:05:39 +01:00
Arne Fitzenreiter
dd6c9bb9c3 collectd initskript: parse new lm_sensors config. 2013-12-19 22:46:48 +01:00
Stefan Schantl
2b230b77f5 Kernel: Add SATA support on imx6 wandboard.
The imx6q wandboard has a soldered SATA port which can be used by loading the ahci_imx kernel module.
2013-12-19 21:42:56 +01:00
Stefan Schantl
0c41633ee1 Kernel: Add support for wifi and bluetooth on imx6 wandboards. 2013-12-19 21:36:37 +01:00
Stefan Schantl
d24c586a95 Kernel: Add terminal driver support on imx platforms. 2013-12-19 21:31:39 +01:00
Stefan Schantl
14ef7de439 Kernel: Add CK01 clock support for imx6 wandboard. 2013-12-19 21:29:11 +01:00
Stefan Schantl
0520e6a5d0 Kernel: In case of busy i2c try again to get ACK on imx platforms. 2013-12-19 21:26:15 +01:00
Stefan Schantl
83d8e3a6db Kernel: Add initial support for compulab utilite. 2013-12-19 21:15:30 +01:00
Stefan Schantl
9bfde8ed40 Kernel: Add initial support for imx6q wandboard.
The required entries for the device tree are taken from kernel 3.12.
2013-12-19 21:11:54 +01:00
Alexander Marx
fac3861429 Firewall: Bugfix: in /etc/init.d/firewall the REDNAT chain was affected BEFORE NAT_SOURCE. Outgoing SNAT rules where not working though 2013-12-16 12:29:02 +01:00
Michael Tremer
325aa1e1f4 httpscert: Increase size of the RSA key to 4096.
RSA keys with length of 1024 bits are considered weak.
2013-12-12 21:18:56 +01:00
Michael Tremer
a1365ee37c httpscert: Use regular random source.
Previous to this patch, the kernel image file and internal
configuration settings have been used as a source for random
data, which is not random at all.
2013-12-12 21:17:53 +01:00
Michael Tremer
7506baa2eb wirelesscrtl: Add --wait to iptables command line.
With a huge number of access rules, inserting all rules
into the kernel took a long while in which other iptables
tried to access the kernel's ruleset as well, which then
lead to resource conflicts.

Since iptables 1.4.20, the --wait parameter is supported
that will wait for a global xtables lock and then proceed.
2013-12-12 21:05:56 +01:00
Arne Fitzenreiter
5d4d41b18c Merge branch 'next' into fifteen 2013-12-10 00:15:01 +01:00
Arne Fitzenreiter
be33adfb3d kernel: update to 3.10.23. 2013-12-09 17:10:59 +01:00
Arne Fitzenreiter
3a3759c625 mountkernfs: fix mount of /sys and /proc without initrd. 2013-12-08 16:07:35 +01:00
Michael Tremer
a408e02da2 squid: Update to 3.3.11. 2013-12-03 14:42:30 +01:00
Arne Fitzenreiter
0037264780 Merge branch 'next' into fifteen
Conflicts:
	doc/language_issues.tr
2013-11-30 12:45:31 +01:00
Michael Tremer
78c2b230d4 squid: Apply patch for properly detect rlimit.
https://bugzilla.ipfire.org/show_bug.cgi?id=10445
2013-11-26 11:43:11 +01:00
Arne Fitzenreiter
44ed2a42f0 linux-pae: rebuild module deps before initrd build. 2013-11-21 14:14:41 +01:00
Arne Fitzenreiter
5702b0cee5 install: create /var/run folder on rootfs. 2013-11-20 17:15:31 +01:00
Arne Fitzenreiter
a5d81233a3 setup: change persistent network rules for new udev. 2013-11-20 07:37:51 +01:00
Arne Fitzenreiter
147446202f udev: disable new netdev names and systemd log prefix. 2013-11-20 07:37:01 +01:00
Arne Fitzenreiter
80469a8935 initskripts: updates for new udev. 2013-11-18 23:36:10 +01:00
Arne Fitzenreiter
5c3fa3223a dracut: fixes for new udev and missing scsi_wait. 2013-11-18 23:30:27 +01:00
Arne Fitzenreiter
1ee33ddadf util-linux: update to 2.24.
this is needed for newer udev versions but need some initskript
changes. The updater and arm rootfile is not finished yet.
2013-11-17 18:51:04 +01:00
Arne Fitzenreiter
d0d3fe9d26 Merge remote-tracking branch 'origin/next' into fifteen
Conflicts:
	lfs/samba
	lfs/strongswan
2013-11-13 14:05:15 +01:00
Michael Tremer
c648458609 strongswan: Delay sending DPD packets after rekeying. 2013-11-13 00:25:27 +01:00
Michael Tremer
34daf4dbf8 Merge branch 'master' into next 2013-11-09 14:33:16 +01:00
Michael Tremer
ac14b325e0 Merge branch 'master' into fifteen 2013-11-09 14:19:52 +01:00
Michael Tremer
36b1c19138 squid: Update to 3.3.10 + SSL options fix. 2013-11-08 14:13:30 +01:00
Michael Tremer
ab4876ad42 firewall: Don't require to enable the RW server for N2N networks.
The firewall rules for OpenVPN have not been applied for N2N
connections when the road warrior server was disabled.
2013-11-08 13:38:09 +01:00
Michael Tremer
47a83092b5 Merge branch 'next' into fifteen 2013-10-27 13:12:12 +01:00
Michael Tremer
64c5bbc453 mpage: New package.
Required for foomatic 4.x.
2013-10-24 15:20:48 +02:00