Projet

Général

Profil

Statistiques
| Branche: | Tag: | Révision:

univnautes / etc @ e792ac36

# Date Auteur Commentaire
e792ac36 20 juin 2014 15:35 Renato Botelho

Remove extra data after space and fix pf rule syntax. It should fix #3688

fa73c7cd 18 juin 2014 12:38 Renato Botelho

Always set httponly attribute on cookies

3034b371 17 juin 2014 19:27 Renato Botelho

Add comment I forgot on last commit

ff9b30ec 17 juin 2014 19:26 Renato Botelho

Re-generate session ID on a successful login to avoid session fixation

e7eeb5ce 12 juin 2014 14:31 Renato Botelho

Do not expire already disabled users, it fixes #3644

b2821f7d 10 juin 2014 16:28 Renato Botelho

Revert "Revert "Fix #3700 and other syntax issues:""

This reverts commit 4cc2ae78d3027c349969437f08a88b1fb88c9de8.

4cc2ae78 10 juin 2014 15:54 Renato Botelho

Revert "Fix #3700 and other syntax issues:"

This reverts commit e912bfae186b6b657daf52607f9d027f46be0478.

e912bfae 10 juin 2014 15:40 Renato Botelho

Fix #3700 and other syntax issues:

- Remove G parameter from pfctl since it doesn't exist anymore
Initialize $old_router
- Fix sh syntax on variable assign, it couldn't have space before =
- Simplify logic
- Avoid flush states twice, if it was done on IP change, don't do it...

ad03afb6 06 juin 2014 16:54 Renato Botelho

Escape argument on call to is_process_running too, also remove some unecessary mwexec() calls

4cc34245 06 juin 2014 16:53 Renato Botelho

Add some protection to parameters that come through _GET

cbf16c30 06 juin 2014 14:26 jim-p

Escape this before running.

3bbc23b8 05 juin 2014 20:36 Renato Botelho

Bump version to 2.1.4

764ac8c7 05 juin 2014 13:55 Renato Botelho

Fix #3691, use curl instead of fetch to download update files

466cabed 03 juin 2014 20:18 Matt Smith

allow ipaliases to be configured on lo0

bc76b18e 31 mai 2014 02:57 Chris Buechler

remove openbgpd bits from system_gateways_edit and system.inc. The package
match is case-sensitive and hasn't matched the openbgpd package's name in
at least 5 years, so it doesn't do anything. It's far from functional in
any useful manner even fixing that issue.

7d363e57 30 mai 2014 14:45 jim-p

client-config-dir is also useful when using OpenVPN's internal DHCP while bridging.

1930a63e 28 mai 2014 22:48 Manuel Silvoso

Convert protocol ssl:// to https:// when creating http headers

d62a265c 21 mai 2014 19:30 jim-p

Properly handle this rename, and squelch errors if it fails.

8d6c5f66 21 mai 2014 19:22 Renato Botelho

Delete all ip aliases when interface is disabled, it should fix #3650

38f6f50a 21 mai 2014 05:57 Chris Buechler

fix variable typo. ticket #3669

c42a35e5 16 mai 2014 19:11 jim-p

/etc/version_kernel and /etc/version_base no longer exist, use php_uname to get the info instead.

d0f365c2 06 mai 2014 22:09 jim-p

Remove units from burst as it is always specified in bytes. (Per ipfw(8)).
Worked for me in testing, I watched a file briefly burst until and then be clamped down to the limiter's rate.

4ec6b54d 03 mai 2014 18:27 Ermal

Merge the forgotten Ticket #3062 patch for CP pipeno leaking issue which leads to the 'Maximum login reached' on CP

5216e359 01 mai 2014 18:32 Renato Botelho

Obsolete old clog binary from /usr/sbin

25f7f725 30 avril 2014 23:13 Renato Botelho

Bump version to 2.1.3-RELEASE

4d076356 30 avril 2014 20:41 Ermal

Take care of interfaces that have no ip but might be part of the bridge as done for openvpn to avoid loops

6657d23c 30 avril 2014 08:50 Ermal

Signal a reload if anything got updated

2392ed60 30 avril 2014 08:48 Ermal

Merge the patch suggested in Ticket #3629. It also Fixes #3629. The question is why this is using config lock? Also where is filter configure called here?

2db29614 28 avril 2014 16:56 Renato Botelho

Move clog from /usr to /usr/local

Conflicts:
etc/inc/filter_log.inc
etc/inc/system.inc
etc/rc
usr/local/www/guiconfig.inc

dc5c69f1 28 avril 2014 10:27 Ermal

Correct the ridirection URL to unbreak ones passed through Radius attributes and repsect user choices. Reported-by: Antoine Guillemot

67273d72 25 avril 2014 19:05 Renato Botelho

Merge pull request #1105 from florian-asche/RELENG_2_1

8dcf0a57 25 avril 2014 18:45 Florian Asche

Update services.inc

fix

1ccccb84 24 avril 2014 22:02 Renato Botelho

Resolver has no option for remote syslog, remove wrong copy/paste that was adding it when apinger was enabled

4ac23286 24 avril 2014 22:00 Renato Botelho

Merge pull request #1119 from phil-davis/patch-4

5f91c28e 24 avril 2014 00:33 Chris Buechler

fix typo

9fca7574 21 avril 2014 07:01 Phil Davis

Cut paste bug fix in Remote Syslog DHCP events

This version for 2.1 branch.
apinger is repeated here from the code above, but it should be dhcp.
Forum https://forum.pfsense.org/index.php?topic=73734.0
Selecting to remote syslog "Gateway Monitor events" would also switch on "DHCP service events" unintentionally.

90e5ca6f 18 avril 2014 23:44 Florian Asche Moved my changes from Pull Request #1025 , #1019 , #1018 , #1012 (master) to RELENG_2_1
  • Added missing usepublicip with dyndnsCheckIP
  • Added missing CURL setops
856be311 14 avril 2014 12:25 Ermal

Merge pull request #1078 from phil-davis/patch-4

c58dbe2f 14 avril 2014 11:10 Phil Davis

Fix typo

7fd38f44 12 avril 2014 18:32 m0se

fixing typo for GIF tunnels to work over IPv6

the call of get_interface_gatewayv6() in the creation of a GIF tunnel over IPv6 leads to a "Fatal error: Call to undefined function get_interface_gatewayv6() in /etc/inc/interfaces.inc on line 934". changeing the function call to get_interface_gateway_v6() fixed it for me on my local system.

d530f8f7 12 avril 2014 16:44 Phil Davis

Get real interface when dhcrelay uses default GW

If the DHCP Relay server is not on any local subnet, and not on any subnet that has an internal static route, but is somewhere that no specific route is known, then this code finds the default gateway and uses that in the DHCP relay "-i" parameter. The current code gets just the interface name (like "wan", "opt1"). But DHCP Relay command needs to be fed the actual device name "vr0", "vr1" etc....

5aba8d90 12 avril 2014 13:28 Ermal

Also add similar checks on rc.newwanipv6 as in the v4 version

1f43ccf5 12 avril 2014 13:25 Ermal

Forgot to remove the problematic part from previous OpenVPN loop fix commit

f96b9a18 12 avril 2014 08:20 Ermal

Take care of the loops reported for OpenVPN in tap mode. Also fixes the problems of tap disappearing from bridge if its a member.

def5d042 08 avril 2014 19:07 Renato Botelho

No pre release this time

8294066e 08 avril 2014 15:25 jim-p

Make extra sure that we do not start multiple instances of dhcpleases if, for example, the PID is stale/invalid and there is still a running instance.

e222576c 08 avril 2014 15:10 Renato Botelho

Bump to 2.1.2-PRERELEASE since 2.1.1 was released

bde74857 07 avril 2014 17:29 Ermal

Correct typo on function name that has slipped unnoticed. Reported-by: https://forum.pfsense.org/index.php?topic=74688.0

aa87bae5 31 mars 2014 16:40 jim-p

Remove TRIM_set and TRIM_unset support. This method isn't very elegant and isn't necessary in the long run. It's better handled in the installer stage and not after the fact.

6e474fa9 28 mars 2014 16:18 Ermal

Correct check that was broken even before to actually make the ieee8021x enable from proper setting. Reported-by: https://forum.pfsense.org/index.php?topic=74013.0

c40d6c7a 28 mars 2014 08:24 Chris Buechler

time for 2.1.1-RELEASE

ffe35f4c 26 mars 2014 09:40 Chris Buechler

send crash reports via HTTPS

c4fb986b 24 mars 2014 20:25 Renato Botelho

Fix deletion of ipfw rules and pipes for passthru mac, it fixes #3538

fbacfb90 20 mars 2014 18:42 jim-p

Clarify note on limiter queue weight to state that higher values get a larger share.

311464a1 20 mars 2014 17:18 Ermal

Do not garble the error logging message

b6f67168 20 mars 2014 17:09 jim-p

Avoid placing an empty "interface listen" directive in ntpd.conf

3ec2fca1 20 mars 2014 16:56 Ermal

Try to restore last working ruleset rather than staying without configuration at all

22889e9e 17 mars 2014 22:25 Ermal

Disable default allow incoming rules for 6to4 and 6rd interfaces. This rule unintentionally allows all services on the interface to be reachble and maybe more!

01df4035 15 mars 2014 02:12 Chris Buechler

fix typo

358b6cdc 15 mars 2014 01:36 Chris Buechler

standardize URLs

b1d64b46 15 mars 2014 01:33 Chris Buechler

standardize URLs

e5644377 15 mars 2014 01:28 Chris Buechler

standardize URLs

5579d12a 15 mars 2014 01:19 Chris Buechler

standardize URLs

d1ec51ba 15 mars 2014 01:07 Chris Buechler

standardize pfsense.com references to https://www.pfsense.org

85e92a06 15 mars 2014 00:59 Chris Buechler

s/http/https/ for www.pfsense.org

dd246dc4 13 mars 2014 08:46 Chris Buechler

set package URL to https://packages.pfsense.org

7057761c 13 mars 2014 08:42 Chris Buechler

use xmlrpcbaseurl here too, not product_website

13e6fb2e 13 mars 2014 08:18 Chris Buechler

we actually use xmlrpcbaseurl here, not product_website

e5b009b8 12 mars 2014 15:50 Ermal

Try a different strategy for fixing #3514 just send a HUP to dhcp6 to get it to reload.

c1846841 11 mars 2014 12:38 Renato Botelho

Do not delete linklocal address

11e4dcc7 10 mars 2014 21:17 Renato Botelho

Merge pull request #991 from phil-davis/RELENG_2_1

Return GWG IP protocol (version) when no gateway IP - 2.1 version

7324b14b 10 mars 2014 16:15 Ermal

Fix for now 'IPv6 - LAN looses Prefix after link event'(forums) with a not elegant solution but works. Probably dhcpv6 client should solve this by itself and generate and event for it. For now just bump dhcpv6 client again to have the prefix interface reconfigured.

0d8fc8ec 10 mars 2014 14:20 Renato Botelho

Fixes typo on variable name

9aa6ad5c 10 mars 2014 14:16 Renato Botelho

pfSense_interface_deladdress() only knows how to delete an ip address, not a subnet. It should fix #3513

be11dd70 07 mars 2014 18:34 Ermal

Make the voucher auth through xmlrpc work.

f3e65ef4 06 mars 2014 23:10 Chris Buechler

default openssl to 2048

9149b33e 06 mars 2014 20:18 Chris Buechler

update year, links for 2.1.1

3945116d 06 mars 2014 07:50 Chris Buechler

bring up appropriate interface for GRE/GIF. Ticket #3281

218a4ffa 03 mars 2014 20:21 Renato Botelho

s/unlink/unlink_if_exists/

2ccaa575 03 mars 2014 17:31 Renato Botelho

Remove broken 'dynamic6' gateway, we already have ipprotocol to tell us the IP version, leave it more simple using only 'dynamic'. It helps #3484

246950c3 03 mars 2014 17:31 Renato Botelho

Fix typo on var name

d557438a 03 mars 2014 14:54 Renato Botelho

Merge pull request #990 from N0YB/RELENG_2_1

XHTML Compliance

263f1c9c 01 mars 2014 23:54 Chris Buechler

sync up ALTQ-capable interfaces list

0a173e6b 01 mars 2014 19:56 N0YB

XHTML Compliance

Firewall - Traffic Shaper

3ffc016b 01 mars 2014 19:06 jim-p

Wrap this in an is_array() test, or else if you have no manually configured DNS servers, saving the DHCP settings produces a PHP error.

6d0f5a63 28 février 2014 21:25 Renato Botelho

Add an option to verify peers_identifier when it's ASN.1 distinguished name. It should fix #2904

9cca1a4f 28 février 2014 15:13 Ermal

Ticket #3484 Correct the case for GRE tunnels as well since they behave the same. GRE seems to need the prefixlen 128 specified all the time so do it explicitly to be on safe side

ddb30ebf 28 février 2014 14:38 Ermal

Fixes #3484. Provide a dynamic gateway for gif v6 tunnels so it can be used on firewall rules etc. The guide for setting up this tunnels on docs need to change to leave the gif interface as none type. People upgrading need to fix this themselves with a not on release notes. This can be fixed if the kernel condition is relaxed to allow setting the prefixlen on the tunnel as ipv4

1de88429 28 février 2014 13:13 Ermal

Ticket #3484 Note that for now prefixlen is useless in ipv6 tunnels. IPv4 accepts them

c6708833 28 février 2014 04:04 Phil Davis

Return GWG IP protocol (version) when no gateway IP - 2.1 branch

6a201696 25 février 2014 04:47 Phil Davis

Fix #3483 only use IPv4 DNS servers in DHCP v4 conf

Version for 2.1 branch

f13a1d6a 24 février 2014 20:05 Renato Botelho

Make is_linklocal case-insensitive and fix #3433

2c02c4d0 24 février 2014 15:58 Ermal

Properly detect when there are issues with communicating with syncip and to use the local DB for this. Otherwise detect if the remote says the voucher is not valid say its not valid.

846bedf9 24 février 2014 15:38 Ermal

Properly compile the query to insert the values. Pointy-hat: myself. While here respect the redirurl when passed to portal_allow and use proper function to do redirection.

11aa4666 21 février 2014 14:45 Ermal

Ticket #2627. Just pass the array over no need to traverse it

080fd00b 21 février 2014 14:28 Ermal

Fixes #2627. When an interface goes down try to shut the RAs and dhcpd6 service on that interface

9510780f 21 février 2014 12:55 Ermal

Avoid recursion of convert_real_interface_to_friendly_interface_name with get_parent and on linkup of parent interface properly configure especially useful on ppp type links

57cd35cf 21 février 2014 11:03 Ermal

Be friendly to memory

be1e9342 21 février 2014 11:00 Ermal

Fix problem with the voucher synching that was introduced during conversion to zones

4cdd20bc 21 février 2014 00:36 Ermal

Rather than having issues with not started radvd try to start radvd to discover by itself the prefix on the interface by using the special directive :: on the prefix declaration. Related to many tickets and forum posts