Project

General

Profile

Activity

From 03/09/2017 to 04/07/2017

04/07/2017

08:03 PM Bug #6603: pfblockerng's Unbound modifications leave system broken post-config restore
maybe now I can only solve the ramfs related problem by completely backup /var and restore it on boot up, maybe with ... giskard rt
07:48 PM Bug #7454: bridge is up after reboot while the enable interface box is not checked
Kill Bill wrote:
> giskard rt wrote:
> > I uncheck the enable box in the interface configuration tab, it works for ...
giskard rt
07:27 AM Bug #7454 (Rejected): bridge is up after reboot while the enable interface box is not checked
Interfaces exist at the OS level even when they are not enabled. The GUI only controls settings applied to the interf... Jim Pingle
02:35 AM Bug #7454: bridge is up after reboot while the enable interface box is not checked
giskard rt wrote:
> I uncheck the enable box in the interface configuration tab, it works for the change. however wh...
Kill Bill
01:28 AM Bug #7454: bridge is up after reboot while the enable interface box is not checked
the similar problem also exist with some other add-ons, like:
1,squid, though it's not enabled, it generate a lot or...
giskard rt
12:52 AM Bug #7454 (Rejected): bridge is up after reboot while the enable interface box is not checked
as described, I add an bridge to bind two different interface, but I do not want the bridge be brought up, so I unche... giskard rt
07:11 PM Feature #7456: pfblockerNG add supportto add or modify self-modified easylist style rule
Kill Bill wrote:
> No idea what's this request about. If you are talking about the DNSBL feature, the "easylist styl...
giskard rt
07:29 AM Feature #7456 (Rejected): pfblockerNG add supportto add or modify self-modified easylist style rule
Please post on the forum to discuss and confirm problems before opening issues here on Redmine. Jim Pingle
02:10 AM Feature #7456: pfblockerNG add supportto add or modify self-modified easylist style rule
No idea what's this request about. If you are talking about the DNSBL feature, the "easylist style rule" support is a... Kill Bill
01:37 AM Feature #7456 (Rejected): pfblockerNG add supportto add or modify self-modified easylist style rule
easylist rule is so convinient and the specific language variant rules cover almost all I need,
But pfblockerNG seem...
giskard rt
09:06 AM Bug #7341 (Resolved): New certificates fail with nsupdate on the first try
Jim Pingle
09:02 AM Bug #7390 (Resolved): SquidGuard
Jim Pingle
07:28 AM Bug #7455 (Duplicate): Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Jim Pingle
02:21 AM Bug #7455: Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
Duplicate of Bug #6603 Kill Bill
01:14 AM Bug #7455 (Duplicate): Unbound DNS Resolver failed with pfBlockerNG after reboot with /var mounted on ramfs
I'd like to say, the var on ramfs is very useful, but the way to handle it is not well considered to back up the var ... giskard rt
07:28 AM Bug #7457 (Rejected): snort use too much resource
Please post on the forum to discuss and confirm problems before opening issues here on Redmine. This is not a bug. Jim Pingle
02:14 AM Bug #7457: snort use too much resource
This is a bug tracker, please use https://forum.pfsense.org/index.php?board=61.0 for performance tuning tips. The mem... Kill Bill
01:48 AM Bug #7457 (Rejected): snort use too much resource
first of all, As official wiki said, pfsense has removed layer7 packets filter feature after version 2.3 for the poor... giskard rt

04/06/2017

10:54 AM Bug #7453 (Closed): DNS-ovh need to save or display consumer key
Consumer key is generated at the first connection to OVH ([Thu Apr 6 17:46:00 CEST 2017] OVH consumer key is empty, L... Cédric Caron

04/05/2017

10:17 AM Feature #7449 (New): feature request for openvpn-client-export package, add the support for openvpn up and down script, for mapping network drive
Hi,
hope i write this to the right place. Someone on the IRC suggested me to post my idea here.
Here is the off...
Geco-it Staff
08:23 AM Bug #7247 (Closed): Update net/ntopng to 2.4.2017.01.20
We just moved to the new quarterly ports branch so there are a number of updates to various things there now or comin... Jim Pingle
08:17 AM Bug #7247: Update net/ntopng to 2.4.2017.01.20
... Kill Bill

04/04/2017

10:19 PM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I just spent some time, installed pfSense 2.4 in Hyper-V and tested.
Yes, there is no STARTTLS setting anymore, wh...
Dmitry Gromov

04/03/2017

02:12 PM Bug #7438: Squid 0.4.36_2 Remote Cache Parent not working
@OP: Need some feedback here. Kill Bill
09:51 AM Bug #7341 (Feedback): New certificates fail with nsupdate on the first try
Fixed by commit:45b4a966b4b0db69d32c697f683aef94e15f56a6
https://github.com/pfsense/FreeBSD-ports/commit/45b4a966b4b...
Jim Pingle

04/01/2017

06:21 PM Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
Ok. Thank you. I can understand it would be difficult to write a parser for these config files, especially since they... Stephen Walker-Weinshenker
06:19 PM Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
Put the settings in the GUI. That's how every part of pfSense works. Manual changes to files will always be overwritt... Jim Pingle
06:16 PM Bug #7440: Tinc package WEB GUI not picking up changes made on filesystem
I understand that this is not the approved way to do things, but now that I have done it, is there any way to get the... Stephen Walker-Weinshenker
06:12 PM Bug #7440 (Rejected): Tinc package WEB GUI not picking up changes made on filesystem
That's not how it's meant to work. All settings must go into the GUI, and the filesystem contents are written out fro... Jim Pingle
05:51 PM Bug #7440 (Rejected): Tinc package WEB GUI not picking up changes made on filesystem
I have been setting up a tinc VPN using a pfsense firewall/router as one of the nodes and everything is working fine,... Stephen Walker-Weinshenker
02:29 PM Feature #6651: Loopback interfaces
+1 for this request. The ability is there as Chris mentioned, but IPs can only be bound to lo0. Additionally, an opti... Anonymous

03/31/2017

08:14 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Is it possible delete or replace attachment here?
Seems like I can edit message, but not delete or replace attached ...
Dmitry Gromov
07:52 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Of course, I tested it - see attached screenshot, in this case notifications cease to works as well as reports.
On...
Dmitry Gromov
05:56 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I'm telling you what to tick so that you have the mail reports working with STARTTLS without any changes needed in th... Kill Bill

03/30/2017

09:53 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Hi!
It looks like you do not understand the difference between SMTPS and STARTTLS.
If I check "Enable SMTP over...
Dmitry Gromov
06:46 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
It works just fine on 2.3.3 when you tick the checkbox that you stubbornly refuse to tick for god knows what reason. ... Kill Bill
06:04 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I am glad it works for you in 2.4, but last I checked 2.3.3-RELEASE-p1 is the current release and it does NOT work th... Dmitry Gromov
03:10 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
I must be speaking Chinese. Tick the "Enable SMTP over SSL/TLS" and it will work. Simple. (The "Enable STARTTLS" thin... Kill Bill

03/29/2017

07:14 PM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Are we looking at different codebases?
There are two checkboxes on /usr/local/www/system_advanced_notifications.ph...
Dmitry Gromov
06:35 PM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Dmitry Gromov wrote:
> And that is _exactly_ what version 3.1 does - it disables handling of STARTTLS if STARTTLS ch...
Kill Bill
06:13 PM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
Hi!
Well, that is kind of strange way to treat the issue, let's not jump to conclusions that fast.
I had a bit ...
Dmitry Gromov
07:37 AM Bug #7437 (Rejected): Mail Report package 3.1 removed support for STARTTLS
It was changed because phpmailer changed. It detects STARTTLS support automatically. If it can't, then the server isn... Jim Pingle
04:49 AM Bug #7437: Mail Report package 3.1 removed support for STARTTLS
It was not removed, it's supposed to be used automatically when you tick SSL and the mailserver is advertising STARTT... Kill Bill
01:17 AM Bug #7437 (Rejected): Mail Report package 3.1 removed support for STARTTLS
I had pfSense configured to send mail reports via FastMail on port 587 with STARTTLS.
All worked great until recent ...
Dmitry Gromov
03:38 PM Bug #7438: Squid 0.4.36_2 Remote Cache Parent not working
Test this: https://github.com/doktornotor/FreeBSD-ports/commit/d2d68063934e1474571e4ef3e0dfb713835b9b22.patch Kill Bill
02:16 PM Bug #7438 (Closed): Squid 0.4.36_2 Remote Cache Parent not working
We had transparent mode proxy working with a Remote Cache parent working on 0.4.36
When we upgraded to 0.4.36_2 it...
Robert Siegman

03/27/2017

09:27 AM Bug #7431: BIND (9.11-2) Log shortcut needs to be updated.
Updated to correct Repo (Hpefully) https://github.com/pfsense/FreeBSD-ports/pull/335 Marc Riley

03/26/2017

12:01 PM Bug #7431: BIND (9.11-2) Log shortcut needs to be updated.
You have submitted this against completely wrong abandoned repo. Any fixes need to go to https://github.com/pfsense/F... Kill Bill
11:04 AM Bug #7431 (Resolved): BIND (9.11-2) Log shortcut needs to be updated.
The Shortcut to the BIND Logs (on page /pkg_edit.php?xml=bind.xml) currently points to /diag_logs_resolver.php
...
Marc Riley

03/22/2017

07:12 AM Bug #7417 (Rejected): Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Please discuss and diagnose the problem on the forum before opening a bug report with the precise details and specifi... Jim Pingle
02:40 AM Bug #7417: Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
This is a bug tracker, use forums for discussions and mystery stories please. Kill Bill

03/21/2017

11:57 PM Bug #7417: Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Just a small edit: I just noticed that the spam started again. My guess is its some device on my lan, I will turn off... rub man
11:02 PM Bug #7417 (Rejected): Avahi ipv6(disabled) port 5353(local link ipv6) firewall log spam until avahi is stopped for a few secs and then restarted
Hi,
I have ipv6 disabled and have not changed anything major changed on my network that has ipv6 enabled. But when ...
rub man

03/20/2017

02:30 PM Feature #7414 (New): snort needs automated refresh on ip change
if pppoe ip changes snort needs refreshed to deal with that ip change would be nice if it happened automatically Michael Kellogg
02:09 PM Todo #7411: LADVD Devices not wide enough
Andy Kniveton wrote:
> The output is when run from a shell is fine , but the output is cut off via the web gui in th...
Andy Kniveton
06:07 AM Todo #7411 (New): LADVD Devices not wide enough
The output is when run from a shell is fine , but the output is cut off via the web gui in the top section :-
+GUI...
Andy Kniveton

03/19/2017

10:46 AM Bug #7310: Packages pre-deinstall script removes temporary files used by pkg
This is not a Snort bug. Beyond already linked #7229, there's another example of pkg being braindead junk here: https... Kill Bill

03/18/2017

02:55 PM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
https://github.com/pfsense/FreeBSD-ports/pull/334
Should be pretty much complete now.
Kill Bill

03/17/2017

09:12 AM Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
https://redmine.pfsense.org/issues/4497 John Wayne
09:08 AM Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
http://lists.freeradius.org/pipermail/freeradius-users/2005-November/004818.html John Wayne
08:36 AM Bug #7403: Captive Portal + freeradius2 + MySQL problems with German Umlaut
In the log files it seems all correct:
Mar 17 13:41:05 radiusd 74676 Login incorrect: [guest/müller] (from clie...
John Wayne
05:02 AM Bug #7403 (New): Captive Portal + freeradius2 + MySQL problems with German Umlaut
We have a setup using a Captive Portal and freeradius2 package + MySQL as database for authentication.
The freerad...
John Wayne
05:22 AM Bug #7404 (Not a Bug): OpenVPN Client Export with custom DynDNS not working
When using the OpenVPN Client Export Utility with a custom DynDNS the Host name resolution combobox-value is empty.
...
John Wayne

03/16/2017

10:59 AM Bug #7319 (Rejected): Tinc uninstall leaves an entry in the firewall rules tab.
The code in the package is OK. Real problem is here: #7401 Jim Pingle
09:11 AM Bug #7390 (Feedback): SquidGuard
Fix pushed. Will show up shortly in pfSense-pkg-squidGuard version 1.16.1. Jim Pingle
08:06 AM Bug #6763: Squid ClamAv wrong redirect URL
Solution:
when I installed pfSense with all packages I use, I gave it a domain name.
After some while, I changed th...
Roma Golbraich
07:33 AM Bug #7263 (Feedback): FreeRADIUS - complete lack of input validation
Jim Pingle
04:09 AM Bug #7263: FreeRADIUS - complete lack of input validation
Merged. Kill Bill

03/15/2017

06:07 PM Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> And FYI regarding the OpenVPN: https://redmine.pfsense.org/issues/4331 (IOW, it will never be aut...
tqwqllrm tqwqllrm
03:30 PM Bug #7391: 0.4.36_1 localnet ACL missing
And FYI regarding the OpenVPN: https://redmine.pfsense.org/issues/4331 (IOW, it will never be auto-added to localnet ... Kill Bill
09:39 AM Bug #7391: 0.4.36_1 localnet ACL missing
No, it's not, noone touched the relevant code for years.
https://github.com/pfsense/FreeBSD-ports/blame/devel/www...
Kill Bill
09:35 AM Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> Look, you need either non-empty local interface, or fill in Allowed Subnets on the ACLs tab. Plea...
tqwqllrm tqwqllrm
09:28 AM Bug #7391: 0.4.36_1 localnet ACL missing
Look, you need either non-empty local interface, or fill in Allowed Subnets on the ACLs tab. Please, use forums for d... Kill Bill
09:25 AM Bug #7391: 0.4.36_1 localnet ACL missing
Kill Bill wrote:
> Kindly tick "Allow local network(s) on interface(s)" if you want such ACL.
This is already tic...
tqwqllrm tqwqllrm
09:23 AM Bug #7391: 0.4.36_1 localnet ACL missing
Additional information: The pfSense box is running OpenVPN so this may be a problem with this version of squid not be... tqwqllrm tqwqllrm
09:23 AM Bug #7391: 0.4.36_1 localnet ACL missing
Kindly tick "Allow local network(s) on interface(s)" if you want such ACL. Kill Bill
08:00 AM Bug #7391 (Not a Bug): 0.4.36_1 localnet ACL missing
Version 0.4.36_1 of Squid on pfSense 2.3.3 does not provide the "localnet" acl anymore in /usr/local/etc/squid/squid.... tqwqllrm tqwqllrm
03:45 PM Bug #7390 (Confirmed): SquidGuard
Jim Pingle
06:44 AM Bug #7390 (Resolved): SquidGuard
When a @'@ caracter is inserted in a comment, the "filter config" button in "Log" tab no longer works.
Javascript ca...
Aurélien BONANNI
11:04 AM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
Thanks, can start killing some code now. :) Kill Bill
10:38 AM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
FYI- I merged that PR, should be good to continue. Jim Pingle
05:17 AM Bug #7388: Suricata does not property recognize MTU for PPPOE interfaces
See this: https://redmine.openinfosecfoundation.org/issues/1556#note-2 Kill Bill

03/14/2017

09:11 PM Bug #7388 (New): Suricata does not property recognize MTU for PPPOE interfaces
Due to path MTU discovery (via ICMPv6) issues with some IPv6 TCP traffic I have to manually set MSS to 1452 in the WA... Kristopher Kolpin
02:02 PM Bug #7319: Tinc uninstall leaves an entry in the firewall rules tab.
Assigned to Pingle for tracking. Jim Thompson

03/13/2017

11:34 AM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
OK, I'll figure something out and do a PR. Need https://github.com/pfsense/FreeBSD-ports/pull/308 merged first before... Kill Bill
08:20 AM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
I agree, it could/should be killed for 2.4.
Not that far out, probably a few weeks.
Jim Pingle
05:35 AM Bug #7170: FreeRADIUS built-in certificate manager defaults to MD5 (!!!), no support for SHA2
Guys, any ETA for 2.4 release (not date, but weeks/months, that sort of thing)? Would be a good opportunity to get ri... Kill Bill

03/11/2017

01:59 AM Feature #7377 (Resolved): ACME Certificate DNS-Digitalocean Verification Method
It would be great to have a DNS verification method for DigitalOcean DNS API that is now natively in GitHub for acme.... the wer

03/10/2017

07:03 PM Feature #7376 (Closed): ACME Package - Please add support Namecheap DNS service
Please add DNS support in the ACME Package for the Namecheap DNS service provider.
Namecheap API documentation
h...
User Name
09:46 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
You can take it whereever you want. There's no reference to Snort in the config [1], and no useful information here.
...
Kill Bill
09:43 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
I'll take it up with Netgate support if this is the attitude I get here.
Easy to be a dick when you don't use your r...
Randy Terbush
09:42 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
I'll track this and contact Bill Meeks.
"Kill Bill", please find a way to interact with a more professional tone....
Jim Thompson
09:33 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Like, read what? There is zero information here to determine anything and it has nothing to do with the PBI junk on <... Kill Bill
09:16 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Maybe you can take a little different attitude and take time to read what I wrote since I took the time to search the... Randy Terbush
08:50 AM Bug #7374: Barnyard2 package has incomplete install when installed as Suricata depedency
Randy Terbush wrote:
> This seems to be possible duplicate of #3756
No, absolutely not, plus completely unclear ...
Kill Bill
08:12 AM Bug #7374 (Closed): Barnyard2 package has incomplete install when installed as Suricata depedency
This seems to be possible duplicate of #3756 which was marked resolved 2 years ago, but still appears to be an issue.... Randy Terbush
 

Also available in: Atom