10476 Commits

Author SHA1 Message Date
Franco Fichtner
2a910e797a system: bump syslog version 2019-03-05 08:04:28 +01:00
Björn Kalkbrenner
8e361f3051 dhcp: added TFTP bootfile-name
PR: https://github.com/opnsense/core/pull/3074
2019-03-05 07:11:55 +01:00
Ad Schellevis
d9dbcaf052 IPSec / routed (VTI). add tunnel settings to phase2, https://github.com/opnsense/core/issues/2332 2019-03-04 19:41:44 +01:00
Ad Schellevis
a045d3e9f6 IPSec / routed (VTI), when auto_routes_disable is set, set auto = start in stead of route, for https://github.com/opnsense/core/issues/2332 2019-03-04 16:10:09 +01:00
Ad Schellevis
4c3d069ca4 IPSec / routed (VTI), make sure all connections use predefined reqid, for https://github.com/opnsense/core/issues/2332
it would be good to refactor this code at some point, maybe wrap some of its logic in a class.
There's just too much logic in ipsec_configure_do at the moment
2019-03-04 15:43:08 +01:00
Ad Schellevis
9ccabe68a6 IPsec / routed (VTI), make installpolicy optional, for https://github.com/opnsense/core/issues/2332 2019-03-04 14:10:05 +01:00
Ad Schellevis
a5f4d1c0ec configd + python3, missing decode() in _encode_idna, dumping byte output in stead of string 2019-03-04 13:55:59 +01:00
Franco Fichtner
1f41c14ce9 pkg: fix plist 2019-03-04 13:13:23 +01:00
Franco Fichtner
b24725c6da system: tweak previous, same file suffix, ordering 2019-03-04 13:12:54 +01:00
Franco Fichtner
7a40a22c2a system: small tweaks to auth templates 2019-03-04 12:58:11 +01:00
Ad Schellevis
060a3e2cbf IPsec+pam, forgot to add the template, for https://github.com/opnsense/core/issues/3265 2019-03-04 12:30:18 +01:00
Franco Fichtner
80feeafa46 unbound: remove debug output #3260 2019-03-04 07:29:32 +01:00
Franco Fichtner
6d66dd81b2 system: avoid short PHP tag 2019-03-04 07:24:31 +01:00
Ad Schellevis
7943492d84 configd, logging, align message string entries with parameters, closes https://github.com/opnsense/core/issues/3271 2019-03-03 18:08:47 +01:00
Franco Fichtner
7e7f432b72 unbound: add aliases to listing; closes #3260 2019-03-03 11:11:47 +01:00
Franco Fichtner
7ee5ed2a43 www: style updates 2019-03-03 10:44:38 +01:00
Franco Fichtner
0e407b1215 firmware: finally revoke 18.7 fingerprint 2019-03-01 19:06:46 +01:00
Franco Fichtner
0242bac1f9 src: style sweep 2019-03-01 19:02:32 +01:00
Michael
c8840c3e89 Proxy: add auth to parent proxy (#3269) 2019-03-01 18:45:59 +01:00
Ad Schellevis
f685abcc9c Trust/cert, disable https://github.com/opnsense/core/pull/3234 until @fichtner adds phpseclib 2019-03-01 18:39:07 +01:00
Ad Schellevis
e65669383d Trust/cert, cleanup sign_cert_csr type 2019-03-01 18:36:44 +01:00
Ad Schellevis
2f919443dc cherry-pick https://github.com/opnsense/core/pull/3234 2019-03-01 18:35:50 +01:00
Ad Schellevis
e505fe0374 Merge branch 'MichaelDeciso-reorder-log-settings' 2019-03-01 15:06:29 +01:00
Ad Schellevis
be93dfcabb Merge branch 'reorder-log-settings' of https://github.com/MichaelDeciso/core into MichaelDeciso-reorder-log-settings 2019-03-01 15:06:13 +01:00
Ad Schellevis
3d07a9eb77 minor cleanups, closes https://github.com/opnsense/core/pull/3112 2019-03-01 14:55:36 +01:00
Ad Schellevis
5fae3bcb7c shaper, fix https://github.com/opnsense/core/pull/3213 template 2019-03-01 14:22:09 +01:00
Ad Schellevis
86a5013c15 Merge branch 'fbrendel-monit_validations' 2019-03-01 10:45:57 +01:00
Ad Schellevis
5bde17012d Monit, minor cleanups and fixes for https://github.com/opnsense/core/pull/3155 2019-03-01 10:45:23 +01:00
Ad Schellevis
1849a3b61d Merge branch 'monit_validations' of https://github.com/fbrendel/core into fbrendel-monit_validations 2019-03-01 10:25:55 +01:00
Franco Fichtner
81438578db unbound: add alias support for #3260
Break the rules of the Dnsmasq implementation while at it:

An alias can consist of a host and/or domain and/or description.
At least a host name or a domain need to be set, the rest will be
taken from the original entry.

Missing GUI parts in the override section...
2019-03-01 08:55:50 +01:00
Ad Schellevis
2babeae771 firewall: logging for NAT rules, within the possibilities of what pf has to offer.... closes https://github.com/opnsense/core/issues/3033 2019-02-28 21:26:36 +01:00
Ad Schellevis
b214b89e20 HAsync, prevent sloppy apply behaviour in various places due to configuring the backup device and point the user to our status page.
- since the apply never has been complete, the current situations either results in user not knowning where their waiting for  (an openvpn client for example) or users assuming all is in sync (which isn't the case)
- move restart filter action to existing sync page

closes https://github.com/opnsense/core/issues/3165
2019-02-28 18:32:17 +01:00
Ad Schellevis
b82e54fb2f whitespace 2019-02-28 16:38:54 +01:00
Ad Schellevis
e7d04751c9 OpenVPN server, validate certificate type, closes https://github.com/opnsense/core/issues/3045 2019-02-28 16:36:40 +01:00
Ad Schellevis
6fe924c1f7 revert 7504bd00a2 since phalcon-3.4.2 fixes the earlier scope issues, closes https://github.com/opnsense/core/issues/3026 2019-02-28 16:17:44 +01:00
Ad Schellevis
21f1580348 IPsec, switch to PAM, closes https://github.com/opnsense/core/issues/3265 2019-02-28 15:32:03 +01:00
Michael Steenbeek
15ac90d94d Remote logging: move 'enable' to the top 2019-02-28 10:43:31 +01:00
Ad Schellevis
02fd4f4c7f Web proxy, switch to PAM, closes https://github.com/opnsense/core/issues/3261 2019-02-28 09:57:54 +01:00
Franco Fichtner
38919ec895 firmware: be more careful about parsing; closes #3254 2019-02-27 19:13:14 +01:00
Franco Fichtner
65a60c9d34 system: rename binary, rename service 2019-02-27 17:30:08 +01:00
Franco Fichtner
bece7dc2df pkg: fix plist 2019-02-27 13:13:55 +01:00
Ad Schellevis
e4285e97fb Revert "System->Settings->Miscellaneous : add "Reset usb on boot" option"
This reverts commit 6dd8bbe14b1068d462654be46102a6f7f239c3c1.
2019-02-27 12:21:14 +01:00
Ad Schellevis
f5dade45cc Revert ""Reset usb on boot" add sleep, since we can't seem to detect the initial usb detection is still active...."
This reverts commit a0fb31c652386ef6d4f161950bf8a79c87035624.
2019-02-27 12:21:10 +01:00
Ad Schellevis
464996af84 Authentication framework, catch login, su, sudo pam services
- add aliases() to IService, so one service can be used for multiple pam services, eases implementation (pam has an include statement for this purpose)
- move logging to AuthenticationFactory->authenticate() and communicate more about choices taken, eases debugging
- remove OpnsenseAuthTest, Sshd, implemented by System

for https://github.com/opnsense/core/issues/3242
2019-02-27 11:20:29 +01:00
Ad Schellevis
d9eb9cb29a ACL::hasPrivilege() overlapping variable, related to https://github.com/opnsense/core/issues/3242 2019-02-27 10:41:37 +01:00
Ad Schellevis
538b74ca63 escaping, b24e7acf3f (commitcomment-32490347) 2019-02-27 09:00:48 +01:00
Franco Fichtner
69ff2fa8ad system: move opnsense-auth to libexec
... but keep a symlink for backwards compatibility
2019-02-27 01:26:15 +01:00
Franco Fichtner
64e74ce75b mvc: more close / cancel, translation 2019-02-27 00:53:05 +01:00
Franco Fichtner
66e6efccd8 firewall: alias close button is really cancel 2019-02-27 00:47:15 +01:00
Franco Fichtner
8724ba878d mvc: simplify save button label 2019-02-27 00:44:40 +01:00