10388 Commits

Author SHA1 Message Date
Ad Schellevis
47a3b2419d python 2->3 iteritems() in core templates 2019-02-22 19:23:52 +01:00
Ad Schellevis
9e082449aa IDS, minor template cleanups using https://github.com/opnsense/core/issues/3100 2019-02-22 16:07:48 +01:00
Ad Schellevis
245513f970 configd, add helpers.empty(), closes https://github.com/opnsense/core/issues/3100 2019-02-22 16:06:42 +01:00
Ad Schellevis
cc2b41bf15 OpenVPN export, add auth-nocache option, closes https://github.com/opnsense/core/issues/3193 2019-02-22 15:29:48 +01:00
Ad Schellevis
a8d89dadc5 mvc/forms, add support for tokenize2 sortable tag, closes https://github.com/opnsense/core/issues/3145 2019-02-22 14:54:10 +01:00
Ad Schellevis
3a361f8e59 auth/pam, better CamelCase for https://github.com/opnsense/core/issues/3242 2019-02-21 21:29:37 +01:00
Ad Schellevis
2e14587955 Auth, add example authentication service and some filename cleansing. for https://github.com/opnsense/core/issues/3242 2019-02-21 21:04:05 +01:00
Ad Schellevis
bdd4c8db03 refresh logo, small scaling issue in previous 2019-02-20 15:08:58 +01:00
Ad Schellevis
63065a9f1f theme, sharpen our theme a bit 2019-02-20 09:16:19 +01:00
Ad Schellevis
f7213e84ea psec_mobile.php fix minor escaping issue 2019-02-20 08:44:18 +01:00
Ad Schellevis
5123277a85 config access, don't try to open config.xml in write mode when file is not writeable. closes https://github.com/opnsense/core/issues/3241 2019-02-19 16:28:00 +01:00
Ad Schellevis
dd1d8cba05 minor simplification for https://github.com/opnsense/core/issues/3242 2019-02-18 22:11:23 +01:00
Ad Schellevis
0793375e3f Authentication/pam, initial (working) version to move already implemented pam services into our framework. for https://github.com/opnsense/core/issues/3242 2019-02-18 22:03:50 +01:00
Ad Schellevis
ab3b5b58de MVC/Exception handling, prevent UserException from being pushed to /tmp/PHP_errors.log 2019-02-18 15:14:59 +01:00
Ad Schellevis
a22e5a7690 php session, fix previous 2019-02-18 14:46:47 +01:00
Ad Schellevis
426b0e1ea6 Revert "php session path, 3eba9a739e"
This reverts commit 545f29a7d2a883696f4923286bbb21dd9e5618d6.
2019-02-18 14:43:42 +01:00
Ad Schellevis
545f29a7d2 php session path, 3eba9a739e 2019-02-18 14:03:55 +01:00
Ad Schellevis
7d5b9df0d9 php, session.savepath, add to recover as discussed 3eba9a739e (commitcomment-32356556) 2019-02-18 11:50:00 +01:00
nhirokinet
895d6bb5b2 remove "show certificate info" on certificate list from pending CSR (#3243) 2019-02-18 11:36:09 +01:00
Ad Schellevis
3eba9a739e php, move session files into it's own directory 2019-02-17 18:37:51 +01:00
Ad Schellevis
969f4523d5 certs.inc, make sure create_temp_openssl_config() can't wrap lines 2019-02-17 15:57:31 +01:00
Ad Schellevis
02b16dcc03 ids, rule-updater.py, cleanup unused 2019-02-16 11:51:11 +01:00
Ad Schellevis
4337e25521 Merge branch 'fredronnv-dev/ipfwcaptiveportal' 2019-02-15 19:32:03 +01:00
Ad Schellevis
3a02d1ab3e Merge branch 'dev/ipfwcaptiveportal' of https://github.com/fredronnv/core into fredronnv-dev/ipfwcaptiveportal 2019-02-15 19:30:41 +01:00
Franco Fichtner
90c0c395a5 interfaces: check for valid alias IP #3197
Suggested by: @tbandixen
2019-02-15 11:26:14 +01:00
Franco Fichtner
8e9ae38fdc Revert "interfaces: remove arp flush from dhclient-script #3197"
This reverts commit a1dbbb5ef132487c88b2b144ac67eeedb00a576c.
2019-02-15 11:22:07 +01:00
Ad Schellevis
621f84e900 legacy_config_get_interfaces, let's make sure we don't stumble over an empty interface, closes https://github.com/opnsense/core/issues/3231 2019-02-15 11:01:40 +01:00
Fredrik Rönnvall
6c263d4349 Revert "ipfw: there's no need to loop over cp_interfaces"
This reverts commit 6178310af241221faf94e9515235b002a12dfbdf.

Don't want to risk opening 53 on wan
2019-02-15 08:27:36 +01:00
Fredrik Rönnvall
6178310af2 ipfw: there's no need to loop over cp_interfaces
We can allow traffic to this host via all.
2019-02-15 08:15:00 +01:00
Fredrik Rönnvall
f2da545261 ipfw: only allow traffic to/from me via cp_interfaces 2019-02-15 08:09:05 +01:00
Franco Fichtner
b6cdbaa400 interfaces: do not do background ifconfig call 2019-02-14 19:02:26 +01:00
Franco Fichtner
156d6f7287 openvpn: daemon is already in the config #3223 2019-02-14 18:58:59 +01:00
Franco Fichtner
bbe0592b83 system: syslog doesn't need background job
The foreground option is -F so we double-background it...
2019-02-14 18:57:42 +01:00
Franco Fichtner
c217bee6f2 openvpn: proper daemonize instead of background job #3223 2019-02-14 18:37:36 +01:00
Franco Fichtner
f10b710a58 openvpn: remove stale PID file as well
PR: https://github.com/opnsense/core/issues/3223
Suggested by: @marjohn56
2019-02-14 18:22:18 +01:00
Franco Fichtner
5bc3ed8ccf src: style sweep 2019-02-14 18:08:59 +01:00
Fredrik Rönnvall
e8af5bee77 ipfw: Remove VIP loop / Add explicit "to me" for DNS
There's no need to explicitly loop around VIPs. We can get away with
simply allowing DNS "to me" via the captive portal interfaces.

Removed unneccessary attribute in cp_interface_list
2019-02-14 15:31:46 +01:00
Franco Fichtner
9704e0d217 www: html_safe() for value=; closes #3218 2019-02-14 15:22:28 +01:00
Franco Fichtner
a1d5d74b5a www: everything not "dhcp" for #3218 2019-02-14 15:14:15 +01:00
Franco Fichtner
32cd65b9f9 firewall: tweak a help text 2019-02-14 15:02:12 +01:00
Franco Fichtner
0b879022ae www: d+f for #3218 2019-02-14 12:31:48 +01:00
Franco Fichtner
8f80173401 www: a few for #3218 2019-02-14 12:17:07 +01:00
Franco Fichtner
d8f2251d7b LICENSE: sync 2019-02-14 12:16:59 +01:00
Ad Schellevis
2eabec274f temp fix for https://github.com/opnsense/core/issues/3222, partly revert adf314a4ab 2019-02-14 10:29:45 +01:00
Franco Fichtner
c0bbb4bbcb firewall: capture "nat" traffic like we do for "rdr" #3033 2019-02-14 09:41:46 +01:00
Ad Schellevis
67f4948670 OpenVPN, extract ca chain for https://github.com/opnsense/core/issues/1487 2019-02-13 11:19:13 +01:00
Ad Schellevis
2006837d18 system tunables, allow reset sysctl to factory defaults. between versions our defaults may vary, this provides an easy option to just use the current defaults. 2019-02-13 10:02:03 +01:00
Ad Schellevis
b424a2f9b3 defaults, more hardened defaults, prevent icmp redirects being send. 2019-02-13 09:57:40 +01:00
Ad Schellevis
7eb9a4f755 Merge branch 'fabianfrz-rspamd_fix_constraint' 2019-02-13 08:52:10 +01:00
Ad Schellevis
74f7ae60b1 style sweep 2019-02-13 08:51:54 +01:00