Commit Graph

5795 Commits

Author SHA1 Message Date
Wolfgang Apolinarski
ff2b65c193 Updated Apache 2.4
- Updated Apache from 2.4.29 to 2.4.33
- Updated Apr from 1.6.1 to 1.6.3
- Updated Apr-Util from 1.6.0 to 1.6.1

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-11 20:03:53 +01:00
Michael Tremer
c79cbc1594 core120: Update OepnVPN configurations for PMTU changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-09 11:36:46 +01:00
Michael Tremer
d6d058a56b core120: Update pakfire keystore
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-03 17:34:24 +01:00
Michael Tremer
6ae5439e5c core120: Ship changed pakfire files
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-03 17:33:04 +01:00
Michael Tremer
4d888e6854 curl: Drop old compatibility symlink
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:50:09 +01:00
Michael Tremer
e7cda9ac7f curl: Rootfile update
Main library was missing

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:48:50 +01:00
Michael Tremer
0471d32b85 core120: Import new pakfire keys
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Michael Tremer
74e715a5a2 pakfire: Import old key, too
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Michael Tremer
397d3a8e15 pakfire: Rename new key to pakfire-2018.key
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-04-02 15:46:40 +01:00
Arne Fitzenreiter
36600cef36 Merge branch 'core119' into next 2018-03-30 09:35:28 +02:00
Michael Tremer
f7e9c14842 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-29 13:49:44 +01:00
Michael Tremer
d97f43b309 Rootfile update for curl
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-28 11:22:06 +01:00
Michael Tremer
d9e656bb82 asterisk: Ship documentation
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-27 20:56:31 +01:00
Michael Tremer
c98304604b core120: Ship updated QoS script and gnupg
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:04:41 +01:00
Matthias Fischer
be7878d5c9 Fix typo in 'makeqosscripts.pl'
Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-26 19:03:30 +01:00
Michael Tremer
dfdfafc7af core120: Ship updated vnstat
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-20 20:36:15 +00:00
Michael Tremer
eb68e27dd2 pakfire: Import key when system boots up
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 19:44:50 +00:00
Michael Tremer
5876642d17 ffmpeg: Ship libraries correctly
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 18:07:49 +00:00
Michael Tremer
35cdaa194a Fix python-m2crypto rootfile
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-19 11:52:44 +00:00
Michael Tremer
b2318b5e35 core120: Ship updated logrotate and restart unbound
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-18 13:51:38 +00:00
Matthias Fischer
9e9fdb39e6 unbound: Update to 1.7.0
For details see:
http://www.unbound.net/download.html

Best,
Matthias

Signed-off-by: Matthias Fischer <matthias.fischer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-18 13:49:40 +00:00
Erik Kapfer
e779b6bc7a PAM: Delete old lib and symlinks
Core 119 update delivers an updated PAM whereby the libdir has been changed from /lib to /usr/lib
but the old libraries and symlinks are still presant. Since the system searches /lib before
/usr/lib , the old libs and symlinks are used which ends up in an `LIBPAM_EXTENSION_1.1' not found.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-18 13:44:04 +00:00
Michael Tremer
35b892b0dd pakfire: Drop old key import mechanism
This was error-prone and allowed to potentially inject another
key.

Fixes: #11539
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-16 14:37:21 +00:00
Michael Tremer
ceed3534e1 core120: Import new pakfire PGP key
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-16 14:28:17 +00:00
Michael Tremer
5e5c2e5413 Import new Pakfire Signing Key
We will swap the key that we use to sign Pakfire packages
since the current one is considered outdated cryptography.

Fixes: #11539

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-16 14:26:07 +00:00
Michael Tremer
dcd60d274e core120: Ship updated qos.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-06 15:13:56 +00:00
Michael Tremer
318434affb core120: Ship updated proxy.cgi
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-06 15:12:42 +00:00
Michael Tremer
01bec95655 core120: Ship updated unbound init script
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-05 15:21:56 +00:00
Michael Tremer
568a227bd3 vpnmain.cgi: Fix reading common names from certificates
OpenSSL has changed the output of the subject lines of
certificates.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-03-01 19:59:14 +00:00
Michael Tremer
63b515dc26 apache: Require TLSv1.2 for access to the web user interface
This will work fine for FF 27 or newer, Chrome 30 or newer,
IE 11 on Windows 7 or newer, Opera 17 or newer, Safari 9 or
newer, Android 5.0 or newer and Java 8 or newer

Since IPFire is not supposed to host any other applications and
all have been removed in the last few Core Updates, only the web
user interface is served over HTTPS here. We clearly prefer
security over compatibility.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-28 11:55:35 +00:00
Peter Müller
464426d363 change Apache TLS cipher list to "Mozilla Modern"
Change the TLS cipher list of Apache to "Mozilla Modern".

ECDSA is preferred over RSA to save CPU time on both server
and client. Clients without support for TLS 1.2 and AES will
experience connection failures.

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-28 11:54:08 +00:00
Michael Tremer
e707599d2c core120: Call openvpnctrl with full path
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-28 10:48:29 +00:00
Michael Tremer
d192815e83 core120: Ship everything that is linked against OpenSSL
This will make sure that everything is using the new version
of the library.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 16:22:32 +00:00
Michael Tremer
1c0cfaa594 Disable Path MTU discovery
This seems to be a failed concept and causes issues with transferring
large packets through an IPsec tunnel connection.

This configures the kernel to still respond to PMTU ICMP discovery
messages, but will not try this on its own.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 15:37:49 +00:00
Michael Tremer
f0e308ab2f core120: Fix typo in initscript name
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 15:34:10 +00:00
Michael Tremer
61fcd32f15 Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 13:06:34 +00:00
Michael Tremer
0eccedd1c8 dhcp: Allow adding extra DHCP interfaces
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 11:12:20 +00:00
Erik Kapfer via Development
39d11d265e OpenVPN: Ship missing OpenSSL configuration file for update
Core 115 delivered a patch which prevents the '--ns-cert-type server is deprecated' message
and introduced also '--remote-cert-tls server' -->
https://patchwork.ipfire.org/patch/1441/ whereby the changed ovpn.cnf has not been delivered.

Signed-off-by: Erik Kapfer <erik.kapfer@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-26 10:15:30 +00:00
Arne Fitzenreiter
4038a83961 core119: restart init after unpack new glibc
this is needed to prevent problems at unmout filesystems at reboot.

Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
2018-02-24 14:30:19 +01:00
Michael Tremer
c560b903a9 core119: Ship updated libgcc_s.so.1
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-23 20:43:41 +00:00
Michael Tremer
8b080ef12b core120: Remove deprecated sshd configuration option
This just created a warning and is now dropped

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 13:06:22 +00:00
Michael Tremer
c8e4391ecc core120: Remove forgotten PHP file
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:41:05 +00:00
Michael Tremer
53929f5ae8 core120: Ship updated OpenSSL 1.1.0
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:39:55 +00:00
Michael Tremer
9434bffaf2 Merge branch 'openssl-11' into next 2018-02-21 12:21:10 +00:00
Michael Tremer
cb8a6bf5a4 Start Core Update 120
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:20:57 +00:00
Michael Tremer
83d6101b9d core119: Reload apache after configuration changes
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:06:02 +00:00
Peter Müller
51bf74a1c8 disable Apache server signature
Sending the server signature is unnecessary and might leak
some internal information (although ServerTokens is already
set to "Prod").

Signed-off-by: Peter Müller <peter.mueller@link38.eu>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:06:02 +00:00
Michael Tremer
3f42cf5cb9 backup: Don't backup apache configuration, keys only
In the past the apache configuration was part of the backup
and may have been restored after Core Update 118 was installed
with PHP being dropped amongst other things.

This patch will make sure that only keys are being backuped.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-21 12:06:02 +00:00
Michael Tremer
bbe8e248fe Rootfile update
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-20 20:10:30 +00:00
Michael Tremer
ea3b9a4f88 strongswan: Update to 5.6.2
Fixed a DoS vulnerability in the parser for PKCS#1 RSASSA-PSS
signatures that was caused by insufficient input validation.
One of the configurable parameters in algorithm identifier
structures for RSASSA-PSS signatures is the mask generation
function (MGF). Only MGF1 is currently specified for this purpose.
However, this in turn takes itself a parameter that specifies
the underlying hash function. strongSwan's parser did not
correctly handle the case of this parameter being absent,
causing an undefined data read.

This vulnerability has been registered as CVE-2018-6459.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
2018-02-19 23:46:17 +00:00