Ad Schellevis
4c3d069ca4
IPSec / routed (VTI), make sure all connections use predefined reqid, for https://github.com/opnsense/core/issues/2332
...
it would be good to refactor this code at some point, maybe wrap some of its logic in a class.
There's just too much logic in ipsec_configure_do at the moment
2019-03-04 15:43:08 +01:00
Ad Schellevis
9ccabe68a6
IPsec / routed (VTI), make installpolicy optional, for https://github.com/opnsense/core/issues/2332
2019-03-04 14:10:05 +01:00
Ad Schellevis
a5f4d1c0ec
configd + python3, missing decode() in _encode_idna, dumping byte output in stead of string
2019-03-04 13:55:59 +01:00
Franco Fichtner
1f41c14ce9
pkg: fix plist
2019-03-04 13:13:23 +01:00
Franco Fichtner
b24725c6da
system: tweak previous, same file suffix, ordering
2019-03-04 13:12:54 +01:00
Franco Fichtner
7a40a22c2a
system: small tweaks to auth templates
2019-03-04 12:58:11 +01:00
Ad Schellevis
060a3e2cbf
IPsec+pam, forgot to add the template, for https://github.com/opnsense/core/issues/3265
2019-03-04 12:30:18 +01:00
Franco Fichtner
80feeafa46
unbound: remove debug output #3260
2019-03-04 07:29:32 +01:00
Franco Fichtner
6d66dd81b2
system: avoid short PHP tag
2019-03-04 07:24:31 +01:00
Ad Schellevis
7943492d84
configd, logging, align message string entries with parameters, closes https://github.com/opnsense/core/issues/3271
2019-03-03 18:08:47 +01:00
Franco Fichtner
7e7f432b72
unbound: add aliases to listing; closes #3260
2019-03-03 11:11:47 +01:00
Franco Fichtner
7ee5ed2a43
www: style updates
2019-03-03 10:44:38 +01:00
Franco Fichtner
0e407b1215
firmware: finally revoke 18.7 fingerprint
2019-03-01 19:06:46 +01:00
Franco Fichtner
0242bac1f9
src: style sweep
2019-03-01 19:02:32 +01:00
Michael
c8840c3e89
Proxy: add auth to parent proxy ( #3269 )
2019-03-01 18:45:59 +01:00
Ad Schellevis
f685abcc9c
Trust/cert, disable https://github.com/opnsense/core/pull/3234 until @fichtner adds phpseclib
2019-03-01 18:39:07 +01:00
Ad Schellevis
e65669383d
Trust/cert, cleanup sign_cert_csr type
2019-03-01 18:36:44 +01:00
Ad Schellevis
2f919443dc
cherry-pick https://github.com/opnsense/core/pull/3234
2019-03-01 18:35:50 +01:00
Ad Schellevis
e505fe0374
Merge branch 'MichaelDeciso-reorder-log-settings'
2019-03-01 15:06:29 +01:00
Ad Schellevis
be93dfcabb
Merge branch 'reorder-log-settings' of https://github.com/MichaelDeciso/core into MichaelDeciso-reorder-log-settings
2019-03-01 15:06:13 +01:00
Ad Schellevis
3d07a9eb77
minor cleanups, closes https://github.com/opnsense/core/pull/3112
2019-03-01 14:55:36 +01:00
Ad Schellevis
5fae3bcb7c
shaper, fix https://github.com/opnsense/core/pull/3213 template
2019-03-01 14:22:09 +01:00
Ad Schellevis
86a5013c15
Merge branch 'fbrendel-monit_validations'
2019-03-01 10:45:57 +01:00
Ad Schellevis
5bde17012d
Monit, minor cleanups and fixes for https://github.com/opnsense/core/pull/3155
2019-03-01 10:45:23 +01:00
Ad Schellevis
1849a3b61d
Merge branch 'monit_validations' of https://github.com/fbrendel/core into fbrendel-monit_validations
2019-03-01 10:25:55 +01:00
Franco Fichtner
81438578db
unbound: add alias support for #3260
...
Break the rules of the Dnsmasq implementation while at it:
An alias can consist of a host and/or domain and/or description.
At least a host name or a domain need to be set, the rest will be
taken from the original entry.
Missing GUI parts in the override section...
2019-03-01 08:55:50 +01:00
Ad Schellevis
2babeae771
firewall: logging for NAT rules, within the possibilities of what pf has to offer.... closes https://github.com/opnsense/core/issues/3033
2019-02-28 21:26:36 +01:00
Ad Schellevis
b214b89e20
HAsync, prevent sloppy apply behaviour in various places due to configuring the backup device and point the user to our status page.
...
- since the apply never has been complete, the current situations either results in user not knowning where their waiting for (an openvpn client for example) or users assuming all is in sync (which isn't the case)
- move restart filter action to existing sync page
closes https://github.com/opnsense/core/issues/3165
2019-02-28 18:32:17 +01:00
Ad Schellevis
b82e54fb2f
whitespace
2019-02-28 16:38:54 +01:00
Ad Schellevis
e7d04751c9
OpenVPN server, validate certificate type, closes https://github.com/opnsense/core/issues/3045
2019-02-28 16:36:40 +01:00
Ad Schellevis
6fe924c1f7
revert 7504bd00a2 since phalcon-3.4.2 fixes the earlier scope issues, closes https://github.com/opnsense/core/issues/3026
2019-02-28 16:17:44 +01:00
Ad Schellevis
21f1580348
IPsec, switch to PAM, closes https://github.com/opnsense/core/issues/3265
2019-02-28 15:32:03 +01:00
Michael Steenbeek
15ac90d94d
Remote logging: move 'enable' to the top
2019-02-28 10:43:31 +01:00
Ad Schellevis
02fd4f4c7f
Web proxy, switch to PAM, closes https://github.com/opnsense/core/issues/3261
2019-02-28 09:57:54 +01:00
Franco Fichtner
38919ec895
firmware: be more careful about parsing; closes #3254
2019-02-27 19:13:14 +01:00
Franco Fichtner
65a60c9d34
system: rename binary, rename service
2019-02-27 17:30:08 +01:00
Franco Fichtner
bece7dc2df
pkg: fix plist
2019-02-27 13:13:55 +01:00
Ad Schellevis
e4285e97fb
Revert "System->Settings->Miscellaneous : add "Reset usb on boot" option"
...
This reverts commit 6dd8bbe14b1068d462654be46102a6f7f239c3c1.
2019-02-27 12:21:14 +01:00
Ad Schellevis
f5dade45cc
Revert ""Reset usb on boot" add sleep, since we can't seem to detect the initial usb detection is still active...."
...
This reverts commit a0fb31c652386ef6d4f161950bf8a79c87035624.
2019-02-27 12:21:10 +01:00
Ad Schellevis
464996af84
Authentication framework, catch login, su, sudo pam services
...
- add aliases() to IService, so one service can be used for multiple pam services, eases implementation (pam has an include statement for this purpose)
- move logging to AuthenticationFactory->authenticate() and communicate more about choices taken, eases debugging
- remove OpnsenseAuthTest, Sshd, implemented by System
for https://github.com/opnsense/core/issues/3242
2019-02-27 11:20:29 +01:00
Ad Schellevis
d9eb9cb29a
ACL::hasPrivilege() overlapping variable, related to https://github.com/opnsense/core/issues/3242
2019-02-27 10:41:37 +01:00
Ad Schellevis
538b74ca63
escaping, b24e7acf3f (commitcomment-32490347)
2019-02-27 09:00:48 +01:00
Franco Fichtner
69ff2fa8ad
system: move opnsense-auth to libexec
...
... but keep a symlink for backwards compatibility
2019-02-27 01:26:15 +01:00
Franco Fichtner
64e74ce75b
mvc: more close / cancel, translation
2019-02-27 00:53:05 +01:00
Franco Fichtner
66e6efccd8
firewall: alias close button is really cancel
2019-02-27 00:47:15 +01:00
Franco Fichtner
8724ba878d
mvc: simplify save button label
2019-02-27 00:44:40 +01:00
Franco Fichtner
42e901ce6d
src: another style sweep
2019-02-26 23:57:29 +01:00
Franco Fichtner
46de0646c9
src: style fix
2019-02-26 23:53:14 +01:00
Ad Schellevis
a953a756d9
Merge branch 'mimugmail-master'
2019-02-26 20:58:47 +01:00
Ad Schellevis
ae38c01d5d
Merge branch 'master' of https://github.com/mimugmail/core into mimugmail-master
2019-02-26 20:55:19 +01:00