Projet

Général

Profil

Révision:

Révisions

# Date Auteur Commentaire
ccb2af23 17 mars 2015 16:47 Thomas Noël

config.xml: use idps-only renater federation

16b9c78e 17 mars 2015 15:04 Thomas Noël

add UnivNautes in version

f9a5d44b 17 mars 2015 14:36 Thomas Noël

config.xml: add idp group & firmwareurl

95282bb2 27 janvier 2015 12:09 Thomas Noël

idp: syncdata when federations are updated

16d78fb8 27 janvier 2015 12:07 Thomas Noël

config.xml: prepare idp by default (disable but ready)

b62e4e4d 26 janvier 2015 18:01 Thomas Noël

local idp (beta)

4af9283c 26 janvier 2015 16:20 Thomas Noël

rc.bootup: start idp

69f21f64 22 janvier 2015 15:26 Thomas Noël

idp: management interface

9344d387 15 janvier 2015 19:01 Thomas Noël

univnautes: custom templates&static (#5570)

202e2f2c 15 janvier 2015 16:34 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

b57ea0b7 22 décembre 2014 12:04 Ermal LUÇI

Do not apply bw limits if the setting is not enabled in CP. Though still respect radius attributes for now with this setting. Resolves #4127

be544b90 01 décembre 2014 09:47 Ermal LUÇI

Ticket #4053, manually merge improvements on rrd restore handling.

02b81e84 01 décembre 2014 09:43 Ermal LUÇI

Ticket #4053, manually merge improvements on rrd backup handling.

64cda11e 21 novembre 2014 12:10 Ermal LUÇI

Actually an interface is detstroyed here no need for this merge!

Revert "Merge e3cffd6cefc - Properly remove IPv6 carp vips as reported from https://forum.pfsense.org/index.php?topic=84392.0"

This reverts commit e5e16cfc962bcc98a06b89574309bc2ef0ed3542.

e5e16cfc 21 novembre 2014 12:10 Ermal LUÇI

Merge e3cffd6cefc - Properly remove IPv6 carp vips as reported from https://forum.pfsense.org/index.php?topic=84392.0

c1a50dd7 20 novembre 2014 13:25 Renato Botelho

Remove debugging code that can lead us to XSS injection, also pass variables through htmlspecialchars() to sanitize

a8c82ef9 18 novembre 2014 15:03 Renato Botelho

Pass path parameter through htmlpecialchars()

f376043c 18 novembre 2014 15:03 Renato Botelho

Define a local boolean var for showact to avoid security issues, also pass order parameter trough htmlspecialchars()

7e44a029 13 novembre 2014 15:14 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

8105ffa6 13 novembre 2014 13:10 Renato Botelho

Fix logic to find available next number for limiters and queues. It fixes #3998

89cf3dc0 13 novembre 2014 13:09 Renato Botelho

Fix logic to find available next number for limiters and queues. It fixes #3998

340ce958 13 novembre 2014 12:10 Renato Botelho

Add an extra protection to avoid having an empty group created

bd0bb466 12 novembre 2014 22:06 Ermal

Do not display the disabled tunnels since they are not needed in the widget. Ticket #3955

6a151c91 12 novembre 2014 21:43 Ermal

Commit the other part of the fix for Ticket #3955

21cd92ac 12 novembre 2014 21:41 Ermal

Oops wrong choice the checkbox is only for javascript

c9b70c0a 12 novembre 2014 21:41 Ermal

Remove redundant code and check for dpd_enable checkbox to be set

38d21414 12 novembre 2014 19:44 jim-p

Fixup some redirected URLs.

4dbabbc6 12 novembre 2014 19:36 jim-p

Fixup some URLs that changed.

4b2223f2 12 novembre 2014 19:36 jim-p

Standardize quotes in help.php

71f45fed 12 novembre 2014 18:26 Chris Buechler

Don't allow interface descriptions that are strictly numbers as that
generates an invalid ruleset. Ticket #4005

a19cc600 12 novembre 2014 18:22 Chris Buechler

fix variable typo

2b114010 12 novembre 2014 18:20 Chris Buechler

fix text

61dec0b0 12 novembre 2014 17:22 Renato Botelho

Make sure empty group or user are not created when editing

2951a06a 12 novembre 2014 15:27 Renato Botelho

Only create missing ssh keys, do not overwrite existing ones. It fixes #4003

aa5acb42 12 novembre 2014 14:57 Ermal

Use route command directly rather than trying to make a route search on php thorugh netstat. It Fixes #4000

285acd60 12 novembre 2014 12:46 Ermal

Oops do the right thing here by passing proper argument rather than breaking the ipsec status page. Ticket #3955

39f93e00 12 novembre 2014 12:42 Ermal

Revert "Make phase1_status function wok whnever there is a smp dump. This should unbreak Ticket #3955"

This reverts commit 694d368d818508a40bdef4f1a3f64b414b11c442.

5823df59 12 novembre 2014 07:32 Chris Buechler

remove this log, it's never logged anything useful that I've seen, and unnecessarily spams the secondary's system log on every config sync.

4de91fda 12 novembre 2014 02:13 Chris Buechler

hn(4) is ALTQ-capable, mark as such.

694d368d 11 novembre 2014 23:18 Ermal

Make phase1_status function wok whnever there is a smp dump. This should unbreak Ticket #3955

c7f5b55a 11 novembre 2014 21:36 Ermal

Actually require group name!

baca968c 11 novembre 2014 21:35 Ermal

Do not do operations for empty group members

e16f6d03 11 novembre 2014 21:28 Ermal

Do not do this during boot

63ba4729 11 novembre 2014 20:57 Ermal

Use leftcert for more options on IPsec authentication

1f2f38f5 11 novembre 2014 20:49 Ermal

Ticket #3967 also sync other vip types that can be synched.

94115b93 11 novembre 2014 20:08 Ermal

Fixes #3967, properly resolve interface

992f60d0 11 novembre 2014 14:57 Renato Botelho

Set proxy env vars on interactive shell and also on crontab to make all scripts be able to use it. Ticket #3789

eacdbc4d 11 novembre 2014 14:33 Renato Botelho

Revert "Ticket #3789. Put a start at using the proxyurl/proxyport from system configured settings for bogons. It still does not consider the user/pass configured"

This reverts commit 664adf3845cf1df89769bb0ed5fc113048e0912e.

0b7dbebe 11 novembre 2014 07:03 Chris Buechler

touch up text

5f4f8365 11 novembre 2014 06:53 Chris Buechler

fix text

29aef6c4 11 novembre 2014 06:36 Jim Thompson

Change copyright statement to reflect reality

dd447bde 11 novembre 2014 05:49 Jim Thompson

modify copyright statement to reflect reality

e7896fc8 11 novembre 2014 05:24 Jim Thompson

Change copyright statement to reflect reality

e120d5ce 11 novembre 2014 05:13 Chris Buechler

Fix syntax error in CARP status page. Ticket #3967

a1b66bec 11 novembre 2014 05:07 Chris Buechler

Restore the CARP parent display in firewall_virtual_ip.php. Ticket #3967

a9b305a8 11 novembre 2014 04:52 Chris Buechler

Set this to /8 instead since that's how it's done in stock FreeBSD 10.1. Ticket #3941

b0533f16 11 novembre 2014 04:37 Chris Buechler

Setting an interface's IP to 0.0.0.0 with mask 0.0.0.0 overwrites the
default route with that interface's link route. Later in dhclient, that
gets deleted and leaves the system with no default route. Using a /32 mask
here works in every scenario I can find, and stops the default route...

7cdfe39e 10 novembre 2014 23:45 Ermal

Strengthen check

f4443dce 10 novembre 2014 23:32 Ermal

Compare the right things here.

d87fcac9 10 novembre 2014 21:47 Ermal

Do not require the default sysctl items to be set on the config.xml but rather extract the definitions from the sysctl tree. Also to reduce config.xml size

24d728bb 10 novembre 2014 20:36 Ermal

Retire flowtable_configure as a useless code since its not in kernel

c46f9695 10 novembre 2014 20:32 Ermal

Actually make default sysctls reside on globals.inc and use those by default this allows to trim down the config.xml sysctl and also fixes #3666 by setting set source interface on reply of icmp

d3c36b1d 10 novembre 2014 20:29 Ermal

Put the new sysctl on the config as needed.

894a0159 10 novembre 2014 17:03 Ermal

Tighten checks here to avoid overriding the default gw with garbage

d3c269d3 10 novembre 2014 16:15 Ermal

Make some more useful checks here

6704590b 10 novembre 2014 16:09 Ermal

Be sure the same gateway is not processed for v4 and v6

c87d89ae 10 novembre 2014 15:38 Ermal

Lets put a logging to see what is bing passed to the rtsold script on calling. Helps with Ticket #3361

6f55af1c 10 novembre 2014 15:20 Ermal

Ticket 3967, revert upgrade code. Existing 2.2 installs might be impacted

b0d054ca 10 novembre 2014 15:18 Ermal

Fixes #3967, configure ip alias on top of carp by joining them to the same vhid as its parent

5063f1df 10 novembre 2014 15:00 Ermal

Ticket #3967. Allow to have carp as parent of ipaliases - continued

9c97df26 10 novembre 2014 14:34 Ermal

Ticket #3967. Allow to have carp as parent of ipaliases

80be089f 07 novembre 2014 19:28 Ermal

Fixes #3995. Do not set rightsourceip on site-to-site VPNs but only on mobile users ones otherwise nothing works.

20a95904 07 novembre 2014 14:37 Ermal

Make ipsec_starter log go to ipsec.log rather than system one

e82a1d11 07 novembre 2014 14:14 Ermal

Reload also the configuration not only the secrets before trying to apply existing configuration. Ticket #3981

a8380480 07 novembre 2014 05:11 Chris Buechler

fix text

6859f881 07 novembre 2014 05:09 Chris Buechler

show interface name, not identifier

d3d23754 07 novembre 2014 05:03 Chris Buechler

fix text, PPPoE Server, not VPN

7bd413eb 07 novembre 2014 03:19 Chris Buechler

add a route debug option to log info about route commands executed (where those aren't already logged) to help with troubleshooting various routing scenarios.

708af634 07 novembre 2014 00:16 Chris Buechler

remove unnecessary is_array check, thanks Renato

6c3be365 06 novembre 2014 23:36 Chris Buechler

Don't allow P2 local+remote network combinations that overlap with
interface+remote-gateway of the P1. Fixes #3812

dbb95f38 06 novembre 2014 19:49 Chris Buechler

set install_routes=no for charon to avoid the issues noted in ticket

459e95a3 06 novembre 2014 19:39 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

27c2e32e 06 novembre 2014 19:38 Renato Botelho

Pass zone id to pfSense_ipfw_getTablestats(), should fix #3990

118218cb 06 novembre 2014 14:54 Renato Botelho

Make sure target has scope when it's a link-local. Fixes #3969

049c74ec 06 novembre 2014 14:40 Renato Botelho

Check if array is set

10435fa9 06 novembre 2014 14:07 jim-p

Merge pull request #1330 from phil-davis/patch-1

3f6525c1 06 novembre 2014 11:30 Renato Botelho

Make sure srcip has scope when it's link-local. Should fix #3969

e7752fc4 06 novembre 2014 10:57 Renato Botelho

Remove extra ; and space

e7a00514 06 novembre 2014 10:57 Renato Botelho

Process obsolete files in shell script instead of php

48f77cef 06 novembre 2014 10:57 Renato Botelho

Simplify post_upgrade_command logic and obsolete /usr/local/sbin/cvs_sync.sh instead of removing it on post_upgrade_command

a68c6785 06 novembre 2014 10:29 Phil Davis

Fix to SMART disk matching

preg_match returns 0 when the string does not match the regex.
0 does not "===" FALSE
So this check is not always working.
preg_match returns 1 when the string matches the regex.
IMO it is better to check for !== 1 - then anything that is not success (0 or false or...) will be unset.

a012464e 06 novembre 2014 05:58 Chris Buechler

fix captive portal status page display

bb18cfcb 06 novembre 2014 05:45 Chris Buechler

fix up text

e8fa9843 06 novembre 2014 03:45 Chris Buechler

Pass friendlyifname to handle_argument_group, not realifname. Fixes #3984. clean up some text while here.

e55e4b74 06 novembre 2014 02:47 Chris Buechler

isset($_GET) seems to always evaluate to true, use something more specific. Fixes use of rc.linkup when run from CLI. Others likely fix similar circumstances, though maybe not ones that are used anywhere.

c75e8aed 06 novembre 2014 02:33 Chris Buechler

Disable delete_old_states in dhclient-script. rc.newwanip handles this correctly in 2.2, and this killed states in multiple circumstances where that isn't necessary nor desirable.

9aec47b7 06 novembre 2014 00:18 Chris Buechler

don't duplicate $message in CP log entries

d9b05eb4 05 novembre 2014 18:31 Renato Botelho

When an alias contain hosts, add IPs and networks to filterdns too, otherwise you end up with a pre-defined and non-persistent table. Fixes #3939

fcfa23da 05 novembre 2014 10:12 Renato Botelho

Merge pull request #1319 from phil-davis/patch-1

87d4456c 05 novembre 2014 10:07 Renato Botelho

Merge pull request #1323 from derelict-pf/master

5940e655 05 novembre 2014 10:06 Renato Botelho

Merge pull request #1326 from phil-davis/patch-5

798d8644 05 novembre 2014 10:06 Phil Davis

Fix obviously broken test in rc.initial.setlanip

IMO might as well back-port any obviously wrong code to 2.1 branch, just in case anybody on 2.1.n cares for it or there is a need for another 2.1.n release.

f81011ea 05 novembre 2014 10:05 Renato Botelho

Merge pull request #1320 from phil-davis/patch-2

e39c963a 05 novembre 2014 06:31 Chris Buechler

fix up text

75756ab9 05 novembre 2014 06:19 Chris Buechler

use a bit stronger of defaults in OpenVPN wizard

1c1fe666 05 novembre 2014 06:08 Chris Buechler

Fix WINS description. It's not 1999, and it wasn't a good description for back then either. If you're running WINS at this point on your AD DCs...get rid of the Win 9x boxes, or realize you don't actually need or want WINS on anything Windows 2000 and newer.

7a22ab9b 05 novembre 2014 06:05 Chris Buechler

fix up text

cbc6a13f 05 novembre 2014 05:01 Chris Buechler

Fix updating of hosts file on host override updates by bringing back the same behavior from previous releases.

b7419cfc 05 novembre 2014 04:22 Chris Buechler

skip disabled phase 1 entries in status output

261f2efe 05 novembre 2014 02:57 Chris Buechler

fix NAT-T status. The 'nat' in the status array just tells how the connection is configured, not what it's actually using. Port seems to be the best way to determine what it's using. Fix up some other text while here

531686c1 05 novembre 2014 02:09 Chris Buechler

use tabs rather than spaces, as most of this already did.

d3c414e3 05 novembre 2014 02:02 Chris Buechler

strongswan only has two options for NAT-T, force or auto.

a43ddd1a 05 novembre 2014 01:44 Chris Buechler

setting nmbclusters to 0 just results in an error, remove unnecessary line

41367b9c 05 novembre 2014 01:34 Chris Buechler

remove old DISABLE_PHP_LINT_CHECKING, which dates way back to the CVS days and hasn't been relevant in years.

276efd64 05 novembre 2014 01:24 Chris Buechler

touch up text

32171e59 05 novembre 2014 01:18 Chris Buechler

fix invalid ipsec.conf

f643a1f1 05 novembre 2014 01:02 Chris Buechler

clean up text

ea20169a 04 novembre 2014 21:49 jim-p

Use a better method of finding disks for SMART.
Old code was inaccurate and also listed entries that were symlinks to other disks

0810a719 04 novembre 2014 21:21 Ermal

Restore 3 values back on NAT-T settings Just Enable now its Auto as per strongswan default. and off disabled mobike. Ticket #3979

1db2634e 04 novembre 2014 21:08 Ermal

Rename the options to actually make sense with strongswan

86ef7a0a 04 novembre 2014 21:07 Ermal

Remove Force options since it has not meaning for now.

756d867a 04 novembre 2014 20:31 Chris Buechler

fix comment

5711c446 04 novembre 2014 18:44 jim-p

Catch some more sensitive info when sanitizing.

8a2229e3 04 novembre 2014 18:43 jim-p

Catch some more sensitive info when sanitizing.

f384d8a5 03 novembre 2014 18:27 Renato Botelho

Merge pull request #1329 from phil-davis/patch-3

a3fad592 03 novembre 2014 17:43 Phil Davis

Fixup dhcpd interface enabled check

ba667cc6 03 novembre 2014 16:04 Phil Davis

Fix console set interface IP address

Problem as per forum https://forum.pfsense.org/index.php?topic=83651.0
The problem comes whenever services_dhcpd_configure is called - the global $config gets reset from the actual current config, and any pending changes in the current process are lost....

ec290464 03 novembre 2014 13:56 Renato Botelho

Merge pull request #1328 from wagonza/master

fe9d4894 03 novembre 2014 13:54 Renato Botelho

Fix indent

2783e408 03 novembre 2014 13:52 Renato Botelho

Revert "Indent better"

This reverts commit a431bfc9e698c753d9a54218af9076184deb6251.

d5566d43 03 novembre 2014 13:45 Warren Baker

Make sure defaults values are actually used. Fixes #3974

7bb24e18 03 novembre 2014 11:48 Renato Botelho

Merge pull request #1327 from wagonza/pfSense-master

46a989ce 03 novembre 2014 11:08 Warren Baker

Indent here as well

a431bfc9 03 novembre 2014 11:08 Warren Baker

Indent better

1b436de1 03 novembre 2014 11:04 Warren Baker

Be consistent with the other pages

be11b6f1 03 novembre 2014 11:03 Warren Baker

Add braces

4c3abd34 03 novembre 2014 09:27 Phil Davis

Fix obviously broken test in rc.initial.setlanip

IMO might as well back-port any obviously wrong code to 2.1 branch, just in case anybody on 2.1.n cares for it or there is a need for another 2.1.n release.

0a89d059 03 novembre 2014 08:54 Renato Botelho

Merge pull request #1324 from phil-davis/patch-3

8727b3c8 03 novembre 2014 07:04 Phil Davis

Set interface address from consol tidy output

While trying to see why this is not working for me (forum https://forum.pfsense.org/index.php?topic=83651.0 ) I have fixed some little things:
1) Get the new-lines right so the output of the restarting looks neat...

ce21dfca 02 novembre 2014 00:20 Ermal

Correct dispaly of checkboxes for ipsec

8cb7d3e3 01 novembre 2014 23:41 Ermal

Properly configure NAT Tranversal setting.

6af85718 01 novembre 2014 20:54 Ermal

Remove debugging code

f3dd7e8c 01 novembre 2014 18:56 Ermal

Properly test if FCGI is calling or are being triggered from shell. Normally Fixes #3361

9fdc167f 01 novembre 2014 18:55 Ermal

Properly test if FCGI is calling or are being triggered from shell. Normally Fixes #3361

d338018f 01 novembre 2014 18:49 Ermal

Fixes #3938. Do more error checking.

935fcedb 01 novembre 2014 18:44 Ermal

Fixes #3941. When optimizations of the loops were made this brought the problems of overriding default gateway by dynamic interfaces. Try to stick to the first found for now!

d35dfaae 01 novembre 2014 18:43 Ermal

Fixes #3941. When optimizations of the loops were made this brought the problems of overriding default gateway by dynamic interfaces. Try to stick to the first found for now!

038f6e96 01 novembre 2014 07:42 Chris Buechler

clarify logs generated by newwanip(v6) when restarting packages, it's not only IP changes that end up here (by design).

a94a16cd 31 octobre 2014 23:05 derelict-pf

s/a/an/ and speling.

162a7b4e 31 octobre 2014 22:55 derelict-pf

s/then/than/

4045cf1e 31 octobre 2014 15:26 jim-p

Fix two more instances of rrd.tgz renaming.

8560c756 31 octobre 2014 15:26 jim-p

Fix two more instances of rrd.tgz renaming.

c656bc75 31 octobre 2014 03:24 Phil Davis

Fix getext to gettext typo

41aa5cd4 31 octobre 2014 03:23 Phil Davis

Fix getext to gettext typo

29af6265 31 octobre 2014 03:23 Phil Davis

Fix getext to gettext typo

24516832 31 octobre 2014 03:22 Phil Davis

Fix getext to gettext typo

b3f0b2e1 31 octobre 2014 03:21 Phil Davis

Fix getext to gettext typo

687712ee 31 octobre 2014 03:10 Phil Davis

More gettext typos

95169728 31 octobre 2014 03:10 Phil Davis

More gettext typos

c69f62b8 31 octobre 2014 03:09 Phil Davis

More gettext typos

91ee10c0 31 octobre 2014 03:07 Phil Davis

More gettext typos

e4982b90 31 octobre 2014 02:30 Chris Buechler

fix typoed gettext

1ae41bfe 30 octobre 2014 22:37 Chris Buechler

Kill states associated with the old WAN IP when WAN IP has changed. Retain
hidden config option to wipe all states on IP change, as there seemed to
be circumstances where the 'pfctl -k $oldip' didn't suffice for others
(much of history in redmine ticket, some on forum and elsewhere). ticket

737b18f2 30 octobre 2014 21:35 Ermal

Allow accept_unencrypted_mainmode_messages to be enabled if needed

461eac09 30 octobre 2014 19:15 Chris Buechler

only kill all states if the IP changed. ticket #1629

a2bb22e9 30 octobre 2014 17:44 Thomas Noël

config.xml: better examples for blacklists

58c2a7da 30 octobre 2014 17:42 Thomas Noël

css: red messages !

64bfdb18 30 octobre 2014 17:19 Thomas Noël

blacklisted people cannot see homepage

6ef1aac1 30 octobre 2014 16:11 Thomas Noël

update-geoinfos: use shutil.move (cross-device mv) (#5831)

5274102e 29 octobre 2014 21:39 Chris Buechler

Hide burst for limiters, since it doesn't do anything. more details in
ticket #3933

f9299058 29 octobre 2014 15:54 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

beead36d 29 octobre 2014 15:51 Thomas Noël

fix next_url cookie, don't store "None" (#5819)

adcce0a3 29 octobre 2014 15:23 Thomas Noël

redirect after login: organize options page

706c7eef 29 octobre 2014 15:09 Thomas Noël

config.xml: add example of local federation

f0626bd5 29 octobre 2014 14:48 Thomas Noël

config.xml: add default blacklists (empty, commented examples) (#5820)

a4372874 29 octobre 2014 14:02 Renato Botelho

Fix a typo on array index, related to ticket #3963

b24998f3 29 octobre 2014 13:22 Thomas Noël

fix default blacklists (#5820)

a663852e 29 octobre 2014 13:06 Thomas Noël

fix utf8 for local metadata (pfsense use iso8859-1)

5db56e35 29 octobre 2014 12:14 Thomas Noël

update-metadatas.py: fix local metadata system

714be795 29 octobre 2014 11:51 Thomas Noël

pluralize: whitelistS and blacklistS

002d286c 29 octobre 2014 07:08 Chris Buechler

fix up text

eea2ad5d 28 octobre 2014 22:33 Chris Buechler

FreeBSD fails to set advskew back to 0 after you set it to any other
value. That's a separate issue that needs fixing upstream, but in the mean
time, we can work around it by removing all CARP VIPs in the same way we
do when "Temporarily Disable CARP" is chosen before adding them all back....

70eef835 28 octobre 2014 20:06 Renato Botelho

Remove redundancy as pointed out by phil-davis

44c7d73c 28 octobre 2014 20:06 Renato Botelho

Decode recently created cert and key. It fixes #3964. While here, fix logical condition to create a new cert if crt or key is not present

569e2fdf 28 octobre 2014 19:31 Chris Buechler

Add option to kill all states on IP change, currently a hidden option for more testing. ticket #1629

fd057a56 28 octobre 2014 18:00 Renato Botelho

Merge pull request #1317 from phil-davis/patch-1

0a8dd27b 28 octobre 2014 17:55 Renato Botelho

Remove redundancy as pointed out by phil-davis

7c199791 28 octobre 2014 17:26 Renato Botelho

Merge pull request #1297 from phil-davis/patch-23

c2071338 28 octobre 2014 14:49 Serghei Mihai

useless code removed

143c22f7 28 octobre 2014 13:17 Renato Botelho

Decode recently created cert and key. It fixes #3964. While here, fix logical condition to create a new cert if crt or key is not present

d0b100eb 28 octobre 2014 12:50 Serghei Mihai

redirecting user after login: to a specific url or to one requested by him

Closes #5574

0a8d7fe9 28 octobre 2014 12:49 Renato Botelho

Back to use listr instead of vncellt since it has small fonts and mitigate changes of go outside the sidget. It should fix #3937

30cb409d 28 octobre 2014 12:24 Renato Botelho

Simplify logic

bf50b0a4 28 octobre 2014 12:10 Renato Botelho

Remove unecessary variables

9c76c0f1 28 octobre 2014 12:08 Renato Botelho

Whitespace and indent

4721677d 27 octobre 2014 21:36 Chris Buechler

fix ping_hosts.sh to not ping IPsec if CARP is in backup

7e1aa4b7 27 octobre 2014 21:32 Chris Buechler

fix ping_hosts.sh to not ping IPsec if CARP is in backup

c8a28de7 27 octobre 2014 18:46 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

0782931a 27 octobre 2014 17:08 Serghei Mihai

tiles url can be specified in SP params

Closes #5579

de95c825 27 octobre 2014 16:57 Thomas Noël

consolidate local metadata system (#5568)

9136aa1f 27 octobre 2014 16:02 Serghei Mihai

federation's metadata raw content can be added

Closes #5568

e8b5f724 26 octobre 2014 04:11 Chris Buechler

domain and search should not both be defined in resolv.conf per FreeBSD man page and handbook (only the latter is actually used). Change this to just not use domain, and set the search to the system's domain where not using the function that generates the search list for dynamic WANs.

23ed5b78 24 octobre 2014 19:18 Ermal

Enable unity plugin as per request from https://forum.pfsense.org/index.php?topic=79737.msg452808#msg452808

577b776e 24 octobre 2014 16:38 Phil Davis

Warn if attempting to import IPv6 range

There is currently no code to convert an IPv6 range to a set of corresponding IPv6 subnets, so warn the user if they attempt that from the alias bulk import GUI.

bb67ac32 24 octobre 2014 16:32 Phil Davis

Support converting an IP range to an array of addresses

so that it can be used for expanding ranges in host alias input.

feb1953e 24 octobre 2014 16:25 Phil Davis

Expand range or subnet for host alias

When entering a host alias, if the user put an IP range (like 192.168.0.10-192.168.0.20) or a subnet (like 192.168.1.200/29) then expand it into a list of individual IP addresses. Check that it will not make too many rows to exceed the existing 5000 row limit on the GUI....

e112f9ee 23 octobre 2014 16:25 Renato Botelho

Merge pull request #1312 from phil-davis/patch-8

095707fe 23 octobre 2014 16:24 Renato Botelho

Merge pull request #1313 from phil-davis/patch-9

0ffacdb6 22 octobre 2014 16:40 Jérôme Schneider

Add support for mac addresses blacklist

Closes #5572

f4578106 22 octobre 2014 16:34 Jérôme Schneider

Add support for mac addresses blacklist

Closes #5571

f2bfdcbb 22 octobre 2014 16:31 Jérôme Schneider

Add support for nameIDs blacklist

Closes #5571

c2c61717 22 octobre 2014 16:31 Jérôme Schneider

Interface: add a page to configure blacklists

fa12833c 22 octobre 2014 16:31 Jérôme Schneider

www: factorise saml tabs in a function

a596b114 21 octobre 2014 23:36 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

63b2c30c 21 octobre 2014 20:45 Chris Buechler

Merge pull request #1312 from phil-davis/patch-8

Prevent Internal Server Error if range is backwards

a376c57d 21 octobre 2014 20:43 jim-p

Teach the certificate generation code how to make a self-signed certificate, and
change the GUI cert generation code to use it. Also, move the GUI cert
generation code to its own function so we can add a GUI option to regenerate it
later. Also use some more sane defaults for the contents of the default self-...

c25d1fd7 21 octobre 2014 20:25 jim-p

Encode values before displaying them back to the user in notification settings

5b473705 21 octobre 2014 20:25 jim-p

Encode values before displaying them back to the user in notification settings.

687d0a6d 21 octobre 2014 19:46 Chris Buechler

remove the command number shown in the shell prompt, it's a pointless
waste of screen space

99ba943a 21 octobre 2014 11:32 Phil Davis

Prevent Internal Server Error if range is backwards

Fixes redmine #3950 - ip_range_to_subnet_array can easily swap the input parameters if the caller has passed/entered them the wrong way around. That is both friendly to the caller and ensures that a hostile caller can't blow up the routine....

29b3bb05 21 octobre 2014 11:18 Phil Davis

Prevent Internal Server Error if range is backwards

Fixes redmine #3950 - ip_range_to_subnet_array can easily swap the input parameters if the caller has passed/entered them the wrong way around. That is both friendly to the caller and ensures that a hostile caller can't blow up the routine....

9b86d3fe 21 octobre 2014 08:54 Chris Buechler

+ is a valid character in some dynamic DNS providers' usernames. Fixes #3912

2fb66948 21 octobre 2014 07:40 Chris Buechler

hostnames can end with a . (and actually always do, it's just usually implied), so allow that here. Fixes wrong input validation in parts of nsupdate GUI, among other things.

a23adfba 20 octobre 2014 19:00 Renato Botelho

Merge pull request #1306 from phil-davis/patch-3

6d951458 20 octobre 2014 17:41 Renato Botelho

Let user decide if he wants to proceed to the upgrade when sha256 fails to download. Fixes #3576

2c296872 20 octobre 2014 02:31 Chris Buechler

h-node should be 8

13ec619c 20 octobre 2014 02:30 Chris Buechler

h-node should be 8

bc12ae8a 20 octobre 2014 01:38 Chris Buechler

Underscores are valid characters in domains. Fixes #3219

621fed0e 18 octobre 2014 01:33 Ermal

Ticket #3932 For more than 100 entries create pipes in line with the rules file to speedup the process

2ac79ade 16 octobre 2014 23:46 Renato Botelho

Merge pull request #1310 from phil-davis/patch-6

308e3042 16 octobre 2014 23:44 Renato Botelho

Merge pull request #1311 from phil-davis/patch-7

2f17d32e 16 octobre 2014 21:22 jim-p

Fix the log widget to lookup hosts by DNS using a link rather than AJAX. Quick fix for now. Ticket #3829

497563be 16 octobre 2014 21:21 jim-p

Fix the log widget to lookup hosts by DNS using a link rather than AJAX. Quick fix for now. Ticket #3829

7c89cb5c 16 octobre 2014 10:29 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

b6dbbebc 15 octobre 2014 20:01 jim-p

Add command line script to generate and activate a new GUI certificate.

2cf2c62b 15 octobre 2014 20:01 jim-p

Fix descriptions and cn on generated GUI cert to be consistent.

2f5488df 15 octobre 2014 16:23 Ermal

Reintroduce the vfs.forcesync systl

29fb23d4 15 octobre 2014 15:49 Renato Botelho

Merge pull request #1309 from phil-davis/patch-5

29be59ad 15 octobre 2014 14:41 jim-p

Tame the poodle. Disable SSLv3.

5ff7f58e 15 octobre 2014 14:40 jim-p

Tame the poodle. Disable SSLv3.

466aae83 15 octobre 2014 10:41 Phil Davis

Manage dhcpleaseinlocaltime consistently

dhcpleaseinlocaltime is actually a global setting, but the setting is stored per-DHCP-enabled-interface.
The display code in status_dhcp_leases already sorts this out - if any interface has the setting enabled then the displayed lease times are adjusted to local time....

73a96698 15 octobre 2014 08:41 Phil Davis

Provide an edit button for static mapped entries

As suggested in forum https://forum.pfsense.org/index.php?topic=82883.msg0#new
Instead of a non-functioning red plus icon, show an edit icon for static mapped entries, and take the user to services_dhcp_edit page if it is clicked. IMHO this makes it much easier to correct things that are noticed when viewing the Status, DHCP Leases display.

fff9ee45 15 octobre 2014 07:47 Phil Davis

Whitespace in status_dhcp_leases.php

5d49ceac 15 octobre 2014 06:19 Phil Davis

Fix #3935 Properly allow WAN without LAN

Was broken by https://github.com/pfsense/pfsense/commit/bd0b5d2dc7a279d3473a65a11d67efb5e39392be

8ff85c39 15 octobre 2014 01:39 Ermal

rename interfaces_carp_setup to interfaces_sync_setup and call it during bootup since it does not only relate to carp interfaces.

4703c007 15 octobre 2014 00:59 Ermal

Fixes #3727 Do not unset ondemand for ppp type interfaces since it is controlled here only for pppoe/l2tp

664adf38 15 octobre 2014 00:55 Ermal

Ticket #3789. Put a start at using the proxyurl/proxyport from system configured settings for bogons. It still does not consider the user/pass configured

e02ea742 15 octobre 2014 00:36 Ermal

Fixes #3213. Allow up to 2900 limiters. This was set to 30 since limiters are to be controlled by mask and not created manually!

febe0112 14 octobre 2014 23:21 Ermal

Make proper check here

7c4c77ee 14 octobre 2014 21:30 jim-p

Teach the certificate generation code how to make a self-signed certificate, and change the GUI cert generation code to use it. Also, move the GUI cert generation code to its own function so we can add a GUI option to regenerate it later.
Also use some more sane defaults for the contents of the default self-signed certificate's fields so it will be more unique and less likely to trigger problems in browser certificate storage handling.

1f4ad8f4 14 octobre 2014 20:44 Chris Buechler

update comment to reflect breakage caused here and reference associated redmine ticket, not high priority, can be fixed later

eb71461c 14 octobre 2014 20:21 Chris Buechler

block IPv4 link-local. Per RFC 3927, hosts "MUST NOT send the packet to
any router for forwarding", and "any network device receiving such a
packet MUST NOT forward it". FreeBSD won't route it (route-to can override in
some circumstances), so it can't be in use as a real network anywhere with...

69b79ff0 14 octobre 2014 19:41 Renato Botelho

Fix PSK for non-ascii also here, ticket #3917

5a42d9ef 14 octobre 2014 19:23 Renato Botelho

Fix initial console menu layout, it fixes #3884

b907136c 14 octobre 2014 18:50 Renato Botelho

Improve IPsec status page for mobile. It fixes #3917

ca1fdcce 14 octobre 2014 18:46 Renato Botelho

Add missing gettext call

d6c9dcf9 14 octobre 2014 18:40 Renato Botelho

Add missing gettext calls

6795e0da 14 octobre 2014 18:23 Renato Botelho

Fix indent and spaces

123d8700 14 octobre 2014 17:50 Renato Botelho

Does not accept non-ascii characters on IPsec PSK. It fiixes #3931

a4c1fff2 14 octobre 2014 17:48 Renato Botelho

Close this form early since there is another form below

8d745901 14 octobre 2014 17:43 Jérôme Schneider

snmp: update SNMP ucd to work with univnautes 2.1

Closes #5566

9f813a61 14 octobre 2014 17:42 Jérôme Schneider

univnautes.js: move idp link outside the button for Fx

Closes #5678

dc4a8b9e 14 octobre 2014 06:07 Chris Buechler

update input_error description after changes for ticket #3491

71c26c22 13 octobre 2014 19:36 Renato Botelho

Properly set MTU for lagg interface, it fixes #3922

5c2e6873 13 octobre 2014 18:09 Renato Botelho

Make sentence more accurate as pointed out by phil-davis

1c764a3a 13 octobre 2014 17:42 Renato Botelho

GIF interfaces MTU must be something between 1280 and 8192, make the correct check. It fixes #3927

c772b37c 13 octobre 2014 14:23 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

07c24bf1 13 octobre 2014 13:54 Renato Botelho

Merge pull request #1308 from phil-davis/patch-4

3b5b437b 11 octobre 2014 05:17 Chris Buechler

fix text

0c4cd13f 11 octobre 2014 04:54 Chris Buechler

fix up text on sys_adv_misc

5046435d 11 octobre 2014 04:10 Chris Buechler

fix text and descriptions in GRE edit page

b22f436a 11 octobre 2014 02:09 Chris Buechler

s/removing/omitting/g for gateway monitor log entires. "Removing" is not necessarily correct, there are many circumstances where this runs where it wasn't there to begin with, and is potentially misleading.

1f237bb4 10 octobre 2014 16:17 Renato Botelho

Fix pf syntax s/divert/divert-to/. It should fix #3921

cce09d94 09 octobre 2014 18:42 Phil Davis

Ticket #3860 Correctly display SMTP SSL TLS boxes

After using the "Test" button, $_POST['smtpssl'] and $_POST['smtptls'] was 'on' or null - this got blindly copied back into $pconfig[] and resulted in the state of the SSL/TLS/STARTTLS checkboxes not being redisplayed....

9da083fc 08 octobre 2014 13:54 Renato Botelho

Fix an error introduced in bd0b5d2dc7 that makes system believe interfaces always mismatch

bd0b5d2d 08 octobre 2014 06:33 Chris Buechler

Remove the minimum NIC warning, this dates back to when minimum 2 NICs were supported and it made sense to throw this message at people. It's obvious a network appliance requires at least one NIC.

b4bd9c56 07 octobre 2014 20:17 Ermal

Update the URL for snapshots update

86ce2df7 07 octobre 2014 19:44 Renato Botelho

Be more strict when checking if olsrd is enabled, otherwise when package is deinstalled and configuration is kept dhcpd will consider it's always as enabled

3b5707db 07 octobre 2014 04:00 Phil Davis

Support up to 4 DNS Servers in DHCP

81af6a08 07 octobre 2014 03:59 Phil Davis

Support up to 4 DNS Servers in DHCP

3d88ea11 07 octobre 2014 03:57 Phil Davis

Support up to 4 DNS Servers in DHCP

6190312f 07 octobre 2014 03:55 Phil Davis

Support up to 4 DNS Servers in DHCP

8cbb140a 07 octobre 2014 03:52 Phil Davis

Support up to 4 DNS Servers in DHCP

a3cc8dcc 06 octobre 2014 18:05 Ermal

Add an option to restart php-fpm from console

9c296826 06 octobre 2014 12:31 Ermal

Fixes #3909 Properly report and detect carp_status

2d5fd3c2 06 octobre 2014 10:22 Ermal

Remove function that is not implemented properly. Nothing seems to use it.

4aa7f542 06 octobre 2014 10:21 Ermal

Merge pull request #1303 from PiBa-NL/carp_without_matching_subnet

042f0d12 06 octobre 2014 10:16 Ermal

Merge pull request #1304 from sselph/powerd_normal_mode

78aadc14 06 octobre 2014 10:15 Ermal

Merge pull request #1305 from phil-davis/patch-2

fb0a4e7a 06 octobre 2014 06:48 Phil Davis

Fix not rules for OPTn network case

Reported in forum https://forum.pfsense.org/index.php?topic=82319.0
The "if (is_subnet($src)) ... filter_address_add_vips_subnets" code needs to go outside all of the if that checks for opt interfaces (not just in the else part). That makes filter_address_add_vips_subnets get called in all cases, including when optn network is specified. (line 2264, 2265)...

3d77cc35 06 octobre 2014 00:35 Steven Selph

Add powerd normal mode flag (-n)

4665dbdd 03 octobre 2014 17:15 Renato Botelho

Make proper check if IP address is configured on another interfaces and ignore current one. It fixes #3807

3c4fc30b 02 octobre 2014 23:19 Chris Buechler

get back to our standard RFC-defined capitalization of IPsec

80a261a2 02 octobre 2014 22:56 PiBa-NL

CARP, allow carp ip to be outside interface and alias subnets (FreeBSD10 feature)

3258d442 02 octobre 2014 22:09 Renato Botelho

Merge pull request #1300 from jean-m-cyr/master

90a430c7 02 octobre 2014 22:09 Renato Botelho

Merge pull request #1298 from PiBa-NL/vips_sort

8d3c338e 02 octobre 2014 22:01 PiBa-NL

firewall_virtual_ip make the table sortable remove double tfoot, but use 2 tr inside.

d4f4ebc7 01 octobre 2014 19:06 jim-p

Remove stray 'i'.
Reported-by: https://forum.pfsense.org/index.php?topic=82393.0

c7fa58ac 29 septembre 2014 05:35 Jean Cyr

Fix up NTP status page formatting

Number of columns is not the same for all table rows

547d7641 28 septembre 2014 22:56 PiBa-NL

firewall_virtual_ip make the table sortable

762a7b89 28 septembre 2014 17:23 Phil Davis

Spelling

e7b03bc1 27 septembre 2014 21:17 Renato Botelho

Merge pull request #1295 from phil-davis/patch-21

6b18c66b 27 septembre 2014 19:19 Phil Davis

Clarify bracketing

to minimize risk of a problem when adding code here in the future.

055a43d2 27 septembre 2014 19:10 Phil Davis

Allow extended alias inputs #3890

Currently if you enter a space-separated list of subnets in the IP address box when entering an alias, the code reports that the data is invalid. But it does actually expand the list of subnets into multiple rows, and enters the various subnet CIDRs into the CIDR column for the user. The user can press Save a second time and the data is now valid so the code saves it happily. This is rather odd, as reported in redmine #3890....

da7f6588 27 septembre 2014 14:08 Phil Davis

Spelling

ff5fa759 27 septembre 2014 14:04 Phil Davis

Spelling

3c4cddc7 27 septembre 2014 14:02 Phil Davis

Spelling

0a97a7bb 27 septembre 2014 13:59 Phil Davis

Spelling

51dc66c9 27 septembre 2014 13:51 Phil Davis

Spelling

ec074a86 27 septembre 2014 13:49 Phil Davis

Spelling

f64b0b8e 27 septembre 2014 13:47 Phil Davis

Spelling

15c58806 27 septembre 2014 13:45 Phil Davis

Spelling

abe63176 27 septembre 2014 13:38 Phil Davis

Spelling

fb3b7640 27 septembre 2014 13:37 Phil Davis

Spelling

4304dd97 27 septembre 2014 13:35 Phil Davis

Spelling

8913533d 27 septembre 2014 13:34 Phil Davis

Spelling

47e1f0d4 27 septembre 2014 13:26 Phil Davis

Spelling

adab585d 26 septembre 2014 18:56 Renato Botelho

Merge pull request #1294 from phil-davis/patch-19

45cd176a 26 septembre 2014 18:56 Renato Botelho

Merge pull request #1293 from phil-davis/patch-20

bbd1f783 26 septembre 2014 18:18 Phil Davis

firewall_aliases_edit UI text changes

If type URL Table then the heading "Description" on the 3rd column gets suppressed (I am not really sure why that is, since the description data entry box still appears - I guess someone intended that the data entry box itself also be suppressed, since URL Table takes just a single line entry, the overall description of the alias should be enough - no need for a per-line description.)...

c5cfa06b 26 septembre 2014 18:01 Phil Davis

Minor fixes to firewall_aliases_edit

for 2.1 branch

ace5483e 26 septembre 2014 12:13 Renato Botelho

Merge pull request #1292 from phil-davis/patch-18

62218b4d 26 septembre 2014 04:40 Phil Davis

Remove useless check for alias description matching an interface description

While looking at other checks in the code I noticed this check. It was not effective anyway, because the first line inside "if ($_POST)" below does
unset($input_errors);
which undoes this check anyway....

7ea27b0d 25 septembre 2014 14:55 Renato Botelho

Be more strict on removing groups checking group id and group name, it avoids issues like happened to users on ticket #3856. While I'm here, replace GET by POST

fbe0d698 25 septembre 2014 14:29 Renato Botelho

Be more strict on user removal checking array id and also username to avoid removing wrong users when browser back button is used. It should fix #3856

e45e3bf4 25 septembre 2014 13:18 Renato Botelho

Merge pull request #1290 from jean-m-cyr/master

b4db2d0e 25 septembre 2014 13:13 Renato Botelho

Remove also old unbound startup script

31377265 25 septembre 2014 03:26 Jean Cyr

Support IPV6 in unbound.conf

IPv6 addresses are not included in unbound config and access list

78244277 25 septembre 2014 01:58 Renato Botelho

Merge pull request #1289 from jean-m-cyr/master

806bf882 25 septembre 2014 01:10 Jean Cyr

outgoing ip incorrectly set in unbound.conf

DNS resolver outgoing IP interface IP address is incorrectly set to the
last inbound interface IP address... fix it.

c11b7ffe 24 septembre 2014 23:43 Renato Botelho

Remove unbound files, menu and service during config upgrade, otherwise things can go really bad with functions redeclared un base and package unbound.inc and config corrupted when upgrading from 2.1.x with unbound installed to 2.2. PBI and package section are both removed later during package upgrade

90a95930 24 septembre 2014 20:28 Renato Botelho

Merge pull request #1288 from brunostein/fix_button_close_info_box

370b4666 24 septembre 2014 20:20 bruno

Fix close button in the info box

abf2e0f1 24 septembre 2014 12:10 Renato Botelho

Merge pull request #1287 from jean-m-cyr/master

a99547e4 24 septembre 2014 11:53 Ermal

Provide a toggle for apinger debug messages to be logged to syslog. To help with roubleshooting issues

3be4caf9 24 septembre 2014 04:09 Jean Cyr

NTP Service GPS page always reverts to 'Custom' GPS type

Remember and correctly display GPS type setting

73b8c162 23 septembre 2014 18:08 jim-p

Add a note clarifying the usage of OpenVPN's Auth Digest setting.

bdbb4dba 23 septembre 2014 14:08 Renato Botelho

Make sure unbound user and group is also created during upgrade config

3f257101 23 septembre 2014 13:57 Renato Botelho

Provide upgrade config code to migrate unbound settings from 2.1 package to 2.2 base. Bump config version to 11.1. It fixes #3880

8d5b31a2 23 septembre 2014 11:58 Renato Botelho

Merge pull request #1286 from jean-m-cyr/master

63d5a5e0 23 septembre 2014 09:16 Jean Cyr

NTP server configuration does not highlight selected interfaces

Missing explode of selected interface list prevent logic from working.

5d14b13e 22 septembre 2014 16:45 jim-p

Add a more obvious note about the use of WAN interface on group rules.

4ce44163 22 septembre 2014 13:42 Renato Botelho

Obsolete recently removed jquery files

c9f63b08 22 septembre 2014 13:18 Renato Botelho

Apply previous progressbar customizations for jquery-ui 1.11.1

b9cf74c3 22 septembre 2014 13:18 Renato Botelho

Update jquery-ui components to 1.11.1, it fixes #3879"

b446562b 20 septembre 2014 16:55 Renato Botelho

Simplify logic

ad970c21 20 septembre 2014 16:41 Renato Botelho

Add missing <form> and require filter.inc for filter_configure()

130a84c5 19 septembre 2014 21:58 Ermal

Do the proper action if Apply button is pressed even on the preshared keys page

8718669c 19 septembre 2014 21:53 Renato Botelho

Recent versions of miniupnpd does not accept IPv4 address anymore, use interface name always. It fixes #3874

9ec8e1f2 19 septembre 2014 19:16 Renato Botelho

Allow hostname to start with '@.' for namecheap. It fixes #3568

de29dadc 19 septembre 2014 19:15 Renato Botelho

Allow hostname to start with '@.' for namecheap. It fixes #3568

93ee78b7 19 septembre 2014 13:16 Renato Botelho

Check if there are leases to show, it fixes warning when $mobile['pool'] is empty or not array

eda1b56f 19 septembre 2014 11:59 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

9f8bbe95 19 septembre 2014 11:58 Thomas Noël

logout view: disconnect from cp

beae652c 19 septembre 2014 11:57 dariomas

Correct evaluation for "Acct-Interim-Interval" from RADIUS

Setting "Acct-Interim-Interval :=600" in FreeRadius2 evaluates to 'random' values with PfSense 2.1.
Possibly a bug related to:
https://forum.pfsense.org/index.php?topic=60079.0
https://forum.pfsense.org/index.php?topic=60262.0

880f44c1 19 septembre 2014 11:56 Ermal

Merge pull request Bug #1285: Metadata namespace definition from dariomas/patch-1

53b801b7 19 septembre 2014 11:56 Thomas Noël

add cp_disconnect command (php)

7f7705db 19 septembre 2014 11:55 Thomas Noël

auth.py: fix import django settings

d2fdc707 19 septembre 2014 11:43 dariomas

Correct evaluation for "Acct-Interim-Interval" from RADIUS

Setting "Acct-Interim-Interval :=600" in FreeRadius2 evaluates to 'random' values with PfSense 2.1.
Possibly a bug related to:
https://forum.pfsense.org/index.php?topic=60079.0
https://forum.pfsense.org/index.php?topic=60262.0

7015ccc5 19 septembre 2014 10:34 Thomas Noël

homepage.html: dont use <button>

2a9ee7e9 19 septembre 2014 10:08 Thomas Noël

update-whitelists: dont use ipfw_context

d02f08dc 19 septembre 2014 10:05 Thomas Noël

add manage configxml

e5b3335a 18 septembre 2014 20:57 Renato Botelho

Do not call write_config() when click on Apply Changes because it was already done and it causes dhcpd to restart one more time on secondary nodes. It fixes #3797

0b42518d 18 septembre 2014 19:31 jim-p

fix syntax

565488c9 18 septembre 2014 19:08 Renato Botelho

Do now call write_config() when click on Apply Changes because it was already done and it causes dhcpd to restart one more time on secondary nodes. It fixes #3797

24395438 18 septembre 2014 15:50 Renato Botelho

Update jquery to 1.11.1

  • Update jquery to latest version
  • Use production version instead of development
  • Rename file to have version on it and avoid browser cache issues
  • Add jquery-migrate to keep backward compatible with old version
2e70388a 18 septembre 2014 14:28 Thomas Noël

www/services_captiveportal_saml_*: use rc.sh actions

feeef1ac 18 septembre 2014 14:26 Thomas Noël

rc.sh: add syncwl action

844bed17 18 septembre 2014 14:00 Thomas Noël

update-whitelists: use table 42

e7fae17e 18 septembre 2014 13:45 Thomas Noël

ipfw_context_list.py (just for the record)

e5c257d1 18 septembre 2014 12:23 Thomas Noël

config.xml: no whitelist in firewall

888c4ddd 18 septembre 2014 12:21 Thomas Noël

captiveportal.inc: (re)add table 42 for whitelist

whitelist in firewall does not work...

9499ce39 18 septembre 2014 11:50 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

7c1d7949 18 septembre 2014 11:50 Thomas Noël

services_captiveportal_zones.php: direct links to saml tabs

11fbb86d 17 septembre 2014 22:54 Thomas Noël

Revert "captiveportal.inc: add table 42 for whitelist"

This reverts commit 82baf4a83e1031566bff16b51798695246f488aa
useless on UnivNautes2014

1d88bb1b 17 septembre 2014 22:38 Thomas Noël

update-whitelists.sh: to php, with love

f74657db 17 septembre 2014 22:35 Thomas Noël

rc.sh: paralleliez syncdata

347f0edc 17 septembre 2014 22:34 Thomas Noël

config.xml: whitelists aliases

f5af3d98 17 septembre 2014 22:14 Thomas Noël

minicron for update whitelists

1d30fbf1 17 septembre 2014 22:10 Thomas Noël

update-whitelists.sh (funny, isn't it ?)

1fd3903e 17 septembre 2014 19:32 jim-p

Fix typos

c4372d3c 17 septembre 2014 19:26 Renato Botelho

Restore id for cancel button to fix js error

c07e853b 17 septembre 2014 18:29 jim-p

Add a basic command line password reset script.

ac5934df 17 septembre 2014 16:10 Renato Botelho

While I'm touching this file, replace GET by POST

b1b5bb79 17 septembre 2014 15:35 Thomas Noël

manage prepare-whitelists

cc265e2e 17 septembre 2014 15:34 Renato Botelho

Deduplicate <form>, fixes #3864

729b9f01 17 septembre 2014 15:32 Renato Botelho

Deduplicate <form>, fixes #3864

41fac9b9 17 septembre 2014 14:32 Thomas Noël

captiveportal: dont redirect 443/tcp

75cf353b 17 septembre 2014 12:27 Renato Botelho

It's time to move to 2.2-BETA

022fe5b0 16 septembre 2014 19:12 Renato Botelho

Merge pull request #1284 from phil-davis/patch-17

e5d2c660 16 septembre 2014 19:12 Renato Botelho

Merge pull request #1283 from phil-davis/patch-16

0b857543 16 septembre 2014 18:13 Phil Davis

Fix #3866 Firewall Log Filtering

on master

9036e766 16 septembre 2014 18:11 Phil Davis

Fix #3866 Firewall Log Filtering

on 2.1 branch

76266acd 16 septembre 2014 15:33 Ermal

Correct speeling as reported by: Phil Davis via github

8f097bdd 16 septembre 2014 14:41 Renato Botelho

Merge pull request #1282 from ExolonDX/branch_master_06

cc98be5a 16 septembre 2014 14:40 Renato Botelho

Merge pull request #1281 from ExolonDX/branch_master_05

05bf20a3 16 septembre 2014 14:40 Renato Botelho

Merge pull request #1280 from ExolonDX/branch_master_04

17b86608 16 septembre 2014 14:40 Renato Botelho

Merge pull request #1279 from ExolonDX/branch_master_03

9ab5042e 16 septembre 2014 14:39 Renato Botelho

Merge pull request #1278 from ExolonDX/branch_master_02

a77b360c 16 septembre 2014 14:39 Renato Botelho

Merge pull request #1277 from ExolonDX/branch_master_01

384aa755 16 septembre 2014 11:33 Thomas Noël

pfconfigxml: add get_whitelists()

82baf4a8 16 septembre 2014 10:44 Thomas Noël

captiveportal.inc: add table 42 for whitelist

32513b90 15 septembre 2014 19:33 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

326238ce 15 septembre 2014 19:32 Thomas Noël

use rc.sh with mwexec_bg()

236c9163 15 septembre 2014 19:25 Thomas Noël

config.xml: stop lan by default (ooops)

95f1795a 15 septembre 2014 14:42 Thomas Noël

rc.sh: start/stop crons

a4c835ea 15 septembre 2014 14:22 Thomas Noël

add clearsessions-pf.sh

55ab408c 15 septembre 2014 12:41 Thomas Noël

update settings

8f669cfb 15 septembre 2014 12:39 Thomas Noël

clearsessions-pf manage command

b1a27b8a 15 septembre 2014 11:10 Thomas Noël

add cp_get_sessions script (php)

d02491e6 14 septembre 2014 14:17 Colin Fleming

Tidy up "status_rrd_graph.php" XHTML

"id" attributes cannot start with a numeric character, so change "8hour"
to "eighthour" and "4year" to "fouryear".

8de8ff0f 14 septembre 2014 14:06 Colin Fleming

Tidy up "diag_dns.php" XHTML

Tidy up the "=" sign properly!
Remove "=" sign from INPUT tag
Change alignment to the "middle" of the TD tag
Add missing closing FONT tag

24e183cd 14 septembre 2014 13:57 Colin Fleming

Tidy up "gateways.widget.php" XHTML

Remove invalid "summary" attribute from TD tag

607e15db 14 septembre 2014 13:54 Colin Fleming

Tidy up "interfaces.widget.php" XHTML

Remove duplicate closing TR tag
DIV tag cannot be enclosed in a B (bold) tag
Change class and style

e3e1f748 14 septembre 2014 13:49 Colin Fleming

Tidy up "pkg_mgr_install.php" XHTML

While using the widescreen theme, when you update the firmware or add a
new package the TEXTAREAs are side-by-side which doesn't look neat.
Add BR tag between TEXTAREA

c5709378 14 septembre 2014 13:43 Colin Fleming

Tidy up "fbegin.inc" XHTML

"id" must be a unique attribute.

62424bdb 12 septembre 2014 21:37 Renato Botelho

Remove almost all calls to history.back() and make Cancel button back to HTTP_REFERER, there are a couple of places I didn't touch on this commit because it requires more work

7e7f07ae 12 septembre 2014 21:17 Ermal

This really does not need the =

e9a9e1a7 12 septembre 2014 21:17 Ermal

Remove wrongly used type

3d77ec5d 12 septembre 2014 19:49 Ermal

Ooops restore this

3b9ef0ef 12 septembre 2014 19:40 Ermal

Inverse the sense of the toggles to avoid configuration upgrades

16c02722 12 septembre 2014 19:34 Ermal

Actually use the new toggles

0e7aad67 12 septembre 2014 19:31 Ermal

Provide Advanced Options for controlling rekey and reauth, might be usable with iOS devices

ac19d32a 12 septembre 2014 19:23 Ermal

Only for movile users

fa4e059e 12 septembre 2014 19:22 Ermal

Provide a first implementation of EAP-TLS authentication with IKEv2. It is a start and might not work on all cases

e373e4cd 12 septembre 2014 17:13 Ermal

Make this work properly and not throw out errors.

1a6769a6 11 septembre 2014 23:22 Renato Botelho

Replace GET by POST on system_usermanager.php and make necessary adjustments on necessary pages. It fixes #3856

7c2d0050 11 septembre 2014 23:22 Renato Botelho

Back to referer instead of hard coded system_usermanager.php since this page is called from other places

111bea0d 11 septembre 2014 23:22 Renato Botelho

Add a function to redirect to a page passing parameters through POST

d83a4264 11 septembre 2014 23:22 Renato Botelho

Add a cancel button for user and group edit page

415b71f1 11 septembre 2014 21:57 Ermal

Fixes #3666. Set the sysctl net.inet.icmp.reply_from_interface to 1 to use the incoming interface to send the icmp reply from. It uses another part of patch to pf to undo NAT if it was already performed before

77bf9d5e 11 septembre 2014 20:31 Ermal

Add security priviledge for new page

6ca4d471 11 septembre 2014 20:28 Ermal

Get rid of the /

ca4e3e4c 11 septembre 2014 20:27 Ermal

Actually do not refer with Name but just pool

bb55330a 11 septembre 2014 20:25 Ermal

Do not let the user mess with SAs from this page. The daemon and primary status page handles tat

eb183863 11 septembre 2014 20:24 Ermal

Provide a page on IPSec:status t check the leases to mobile clients

6c2abb0f 11 septembre 2014 20:01 Ermal

Show friendly names

048dd7b9 11 septembre 2014 19:57 Ermal

Remove extra char

5e09285e 11 septembre 2014 19:55 Ermal

Correct widget displaying of status for tunnels

6f276cba 11 septembre 2014 19:47 Ermal

Properly display number of mobile users

7a668bd8 11 septembre 2014 19:28 Ermal

Fix path to xml and make sure the parser will see the custom tags

929dfb4c 11 septembre 2014 19:23 jim-p

Add pages missing from the Status > Traffic Graph privilege that are required for the full page to load

8a2f80b2 11 septembre 2014 19:23 jim-p

Add pages missing from the Status > Traffic Graph privilege that are required for the full page to load

6da9a160 11 septembre 2014 18:33 Ermal

Display all new information on ipsec:status and also fix displaying of some previous statistics

4889b4c0 11 septembre 2014 13:38 Renato Botelho

Merge pull request #1260 from DasTestament/master

ee4da773 11 septembre 2014 13:26 Renato Botelho

Merge pull request #1274 from phil-davis/patch-13

b7063ed3 11 septembre 2014 13:25 Renato Botelho

Merge pull request #1275 from phil-davis/patch-14

63673f3c 11 septembre 2014 04:17 Phil Davis

Standardise size of Duplicate Slice button

The Duplicate Slice button currently is displayed in smaller text and in a row of its own, separate from the row above that has the rest of the "Duplicate bootup slice" text and slice selection.
This change puts the button in the same row as the slice selection and text, and makes the button text be the same size as the text in other buttons on this page....

ffda0775 11 septembre 2014 04:10 Phil Davis

Standardise size of Duplicate Slice button

The Duplicate Slice button currently is displayed in smaller text and in a row of its own, separate from the row above that has the rest of the "Duplicate bootup slice" text and slice selection.
This change puts the button in the same row as the slice selection and text, and makes the button text be the same size as the text in other buttons on this page....

45dbc75f 10 septembre 2014 22:39 Ermal

Try to make the ipsec widget usable again

7ab6ad70 10 septembre 2014 22:39 Ermal

Make use of the xml output from stroke leases command

9060f420 10 septembre 2014 22:02 Renato Botelho

Change is_port() to only validate a single port, we have is_portrange() for specific cases. Make necessary adjustments after check all is_port() calls. It fixes #3857

be32a003 10 septembre 2014 20:39 Renato Botelho

Delete IP Alias on CARP VIP interface on secondary node when it's deleted on primary. It fixes #3855

7397f643 10 septembre 2014 20:39 Renato Botelho

Fix operator

846dc21c 10 septembre 2014 20:39 Renato Botelho

Fix operator

ed5fc757 10 septembre 2014 19:34 Ermal

Return something meaningful until the widget is made to work correctly

4881e5a9 10 septembre 2014 19:33 Ermal

Remove racoon references

537940c8 10 septembre 2014 19:33 Ermal

Remove all remnants of racoon from log page

5f875147 10 septembre 2014 19:32 Ermal

Correct status.php for new ipsec

e952906e 10 septembre 2014 19:23 Ermal

Remove traces of older implementation still present

3b977eff 10 septembre 2014 18:38 Ermal

Put some tuning on number of half open connection possible in one time.

816672f1 10 septembre 2014 18:36 Ermal

Provide some parallellizm on the IKESA lookups for heavy loaded boxes.

f86f928d 10 septembre 2014 16:49 Thomas Noël

add cp_allow script

30d33074 10 septembre 2014 16:49 Thomas Noël

auth.py: send cpzone to cp_allow

505cddae 10 septembre 2014 16:42 Thomas Noël

system.inc/lighttpd: add X-pfsense-cpzone header

a0ab6dae 10 septembre 2014 10:49 Thomas Noël

saml/post_form.html: force Send button

f692f5ed 10 septembre 2014 10:49 Thomas Noël

Merge branch 'RELENG_2_1' into UNIVNAUTES_2_1

a695c2aa 10 septembre 2014 10:48 Thomas Noël

settings.py: TEMPLATE_DIRS disabled by mistake

c966c7ec 10 septembre 2014 00:43 Ermal

Actually roll this back since it was a testing glitch

eadda967 10 septembre 2014 00:08 Ermal

Also here be more strict on checking to return proper result. (some missed from previous commit)

fe06990e 10 septembre 2014 00:04 Ermal

Also here be more strict on checking to return proper result

fe0430f7 09 septembre 2014 23:56 Ermal

Put some more statistics and the user that gets connected now that we can

76e656ba 09 septembre 2014 22:55 Renato Botelho

Merge pull request #1273 from fsSnowboard/master

60ef0911 09 septembre 2014 22:53 Renato Botelho

Make sure dhclient is not running before start it, it fixes console interface setup when interface is using dhcpv4. It should also help #3482

d9d1bd20 09 septembre 2014 22:52 Renato Botelho

Implement a function to kill dhclient process, sometimes it takes a little time to die, so use a sleep(1) there

397e40d5 09 septembre 2014 22:50 Renato Botelho

find_dhclient_process() returns an int, not string

9e74f980 09 septembre 2014 22:30 Ermal

Be more explicit

9eb4257f 09 septembre 2014 22:26 Ermal

Correct log prepending value

f049d544 09 septembre 2014 22:12 Renato Botelho

Some device names are bigger now (eg vtnet, ixgbe, cxgbe)

38f5ac9b 09 septembre 2014 21:38 Ermal

Correct generating loglevels for startup through ipsec.conf

aa352bb3 09 septembre 2014 21:34 Tyler Turner

Fix minor typo to name and port range

Typo on the name of the FaceTime shape rule, and missing 1 from Google
Talk port range.

572f6ccc 09 septembre 2014 19:07 jim-p

Fix guess_interface_from_ip() to account for differences in netstat output. Fixes #3853

76fa9adb 09 septembre 2014 17:28 Ermal

Blah unconditionally set rightsourceip per https://forum.pfsense.org/index.php?topic=80300.0 Until pools can be supported properly.

64a0aa33 09 septembre 2014 17:11 Thomas Noël

handle user_login_callback (attributes, call cp_allow..)

6c62895c 09 septembre 2014 17:11 Thomas Noël

add messages in base.html template

3b0bc8c3 09 septembre 2014 16:54 Renato Botelho

Import fix for http://bugs.jquery.com/ticket/9521

ccefd603 09 septembre 2014 16:53 Renato Botelho

Import fix for http://bugs.jquery.com/ticket/9521

b22ef160 09 septembre 2014 14:14 Renato Botelho

As pointed out by Ermal, VIPs should go first in the list since NAT is first match. Ticket #983

d629f1ca 08 septembre 2014 23:35 Renato Botelho

igmpproxy param -d doesn't like the space before optarg. Fixes #3852

354a1d3f 08 septembre 2014 23:35 Renato Botelho

igmpproxy param -d doesn't like the space before optarg. Fixes #3852

fd875a8d 08 septembre 2014 23:31 Ermal

Ticket #3826 correct point number 2) by showing not connected tunnels in the end of the status page

a1b5f07b 08 septembre 2014 22:44 Ermal

Fixes #3664, actually make sense of this function to work properly

7c611a3e 08 septembre 2014 22:36 Renato Botelho

Improvements on interfaces_assign.php:

- Let user select network port to add instead of pick the first
available, it fixes #3846
- While I'm here, drop GET and use only POST

fa9667d2 08 septembre 2014 22:28 Ermal

Fixes #3823 Properly parse auth tags as variables

1c4b1636 08 septembre 2014 22:24 Renato Botelho

Convert this block into a function for later use

e4034dcb 08 septembre 2014 22:24 Renato Botelho

Fix indent

eb2ab5eb 08 septembre 2014 22:24 Renato Botelho

Remove unecessary var initialization

19498fbf 08 septembre 2014 22:24 Renato Botelho

Replace mwexec() by unlink_if_exists() and respect global tmp_path

1b0e073e 08 septembre 2014 22:24 Renato Botelho

Fix indent and whitespaces

ea0efb36 08 septembre 2014 22:19 Ermal

Show properly a setting of any for Identifiers to use in the status page

(1-500/25468) Par page : 25, 50, 100, 500, 1000

Formats disponibles : Atom