Project

General

Profile

Activity

From 11/08/2019 to 12/07/2019

12/06/2019

10:40 PM Bug #9960 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
Do not open issues here for this. Post on the forum to discuss and diagnose the problem and obtain more information. ... Jim Pingle
10:38 PM Bug #9960 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
dear in pf sense 2.5.0-DEVELOPMENT (AMD64) when squid proxy sever enable the squid SSL Filtering option for block sec... Noman Akbar
10:32 PM Feature #9959 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
Please post on the forum to discuss and identify the issue. There is not enough information here. 2.5.0 is in develop... Jim Pingle
10:29 PM Feature #9959 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
dear in pf sense 2.5.0-DEVELOPMENT (AMD64) when squid proxy sever enable the squid SSL Filtering option for block sec... Noman Akbar

12/02/2019

04:26 PM Bug #9849: NUT not starting as root? Isn't loading USB drivers?
Braden McGrath wrote:
> Ryan McCullough wrote:
> > It looks like the NUT/UPS driver isn't loading the USB driver un...
Ryan McCullough
04:16 PM Bug #9849: NUT not starting as root? Isn't loading USB drivers?
Ryan McCullough wrote:
> It looks like the NUT/UPS driver isn't loading the USB driver unless I pass the "-u root" p...
Braden McGrath
01:24 PM Bug #9940 (Duplicate): Removing "default" view under monitoring blocked
Duplicate of #9352 Jim Pingle
12:56 PM Bug #9940 (Duplicate): Removing "default" view under monitoring blocked
I managed to add a extra view named "default" in the monitoring page. When trying to remove said misstake it is not p... Joakim Dellrud

11/29/2019

08:29 AM Bug #9935 (Pull Request Review): hide ECDSA certs for Zabbix
Jim Pingle
07:41 AM Bug #9932 (Rejected): Squid is not showing CAs for SSL Interception
Can't reproduce this on 2.5.0 or 2.4.4 Both show CAs as they should. Post on the forum if you are still having issues. Jim Pingle

11/28/2019

10:18 AM Bug #9935 (Resolved): hide ECDSA certs for Zabbix
ECDSA certificates are not yet supported in Zabbix
see https://support.zabbix.com/browse/ZBXNEXT-5475
https:/...
Viktor Gurov
08:00 AM Bug #9934: suricata update kills WAN interface
Suricata is running in INLINE IPS mode. Every time, when suricata is stopped or started, it does a link up/down. Is t... Srijan Nandi
07:28 AM Bug #9934 (Closed): suricata update kills WAN interface
Hello Everyone,
I am running pfSense *2.4.4-RELEASE-p3 (amd64*) with suricata *VERSION 4.1.5_2*. I had set suricat...
Srijan Nandi
02:55 AM Feature #9901 (Resolved): show ECDSA CAs only with correct curves
tested on pfSense 2.5.0.a.20191127.2047 with squid 0.4.44_9
correct, resolved
Viktor Gurov
02:54 AM Feature #9906 (Resolved): show ECDSA CAs and certs only with correct curves

tested on pfSense 2.5.0.a.20191127.2047 with freeradius3 0.15.7_6
correct, resolved
Viktor Gurov
02:53 AM Bug #9919 (Resolved): stunnel server connection failure if ECDSA cert is not in IPsec list
tested on pfSense 2.5.0.a.20191127.2047 with stunnel 5.50_2
correct, resolved
Viktor Gurov
02:51 AM Feature #9929 (Resolved): show only ECDSA-safe exports packages
tested on pfSense 2.5.0.a.20191127.2047 with openvpn-client-export 1.4.19_1
correct, resolved
Viktor Gurov

11/27/2019

12:06 PM Bug #9932: Squid is not showing CAs for SSL Interception
Correct Version: 0.4.44_9 Nicolas Bezutt
11:58 AM Bug #9932 (Rejected): Squid is not showing CAs for SSL Interception
After update to 0.4.4_9, the CA field in SSL Man In The Middle Filtering is no more showing any certificates. Older V... Nicolas Bezutt
10:24 AM Feature #9929 (Feedback): show only ECDSA-safe exports packages
PR has been merged. Thanks! Renato Botelho
07:59 AM Feature #9929 (Pull Request Review): show only ECDSA-safe exports packages
Jim Pingle
04:32 AM Feature #9929: show only ECDSA-safe exports packages
two more packages with certificates left - Zabbix-agent and Net-SNMP Viktor Gurov
04:29 AM Feature #9929 (Resolved): show only ECDSA-safe exports packages
show only ECDSA-safe exports packages on OpenVPN \ Client Export Utility page
i.e. certs with prime256v1, secp384r...
Viktor Gurov
10:23 AM Feature #9901 (Feedback): show ECDSA CAs only with correct curves
PR has been merged. Thanls! Renato Botelho

11/25/2019

10:40 AM Bug #9919 (Feedback): stunnel server connection failure if ECDSA cert is not in IPsec list
PR has been merged. Thanks! Renato Botelho
10:38 AM Feature #9906 (Feedback): show ECDSA CAs and certs only with correct curves
PR has been merged. Thanks! Renato Botelho
08:46 AM Bug #9922 (Feedback): haproxy_version does not use full path to haproxy, leads to errors when run during cron
Fixed:
https://github.com/pfsense/FreeBSD-ports/commit/47f4f91aa8159e47f24990eb2496784cb9ef07c6
https://github.co...
Jim Pingle
08:41 AM Bug #9922 (Resolved): haproxy_version does not use full path to haproxy, leads to errors when run during cron
When /etc/rc.filter_configure_sync is run from cron, it yields errors from haproxy. For example in this simulated run... Jim Pingle

11/23/2019

11:00 PM Bug #9919 (Pull Request Review): stunnel server connection failure if ECDSA cert is not in IPsec list
Jim Pingle
03:03 AM Bug #9919: stunnel server connection failure if ECDSA cert is not in IPsec list
https://github.com/pfsense/FreeBSD-ports/pull/712 Viktor Gurov
02:42 AM Bug #9919 (Resolved): stunnel server connection failure if ECDSA cert is not in IPsec list
stunnel client can use cert with any ECDSA curve,
but if stunnel server use incorrect (not prime256v1, secp384r1, se...
Viktor Gurov

11/22/2019

08:11 AM Feature #9742: Print Patch ID in log while patching
The sshguard log message wouldn't be related.
I see logs for manual patching and reverting, but no log messages wh...
Jim Pingle
01:23 AM Feature #9742: Print Patch ID in log while patching
tested on pfSense 2.5.0.a.20191121.2127 with System_Patches 1.2_4
test patch: https://github.com/pfsense/pfsense/com...
Viktor Gurov
01:26 AM Bug #9850 (Resolved): show huperscan option only for x86 arch
Tested on 2.5.0.a.20191121.1639 (SG-1000, arm) and suricata 4.1.5_2
Ok, Resolved
Viktor Gurov

11/21/2019

02:28 PM Feature #9874 (Pull Request Review): safesearch enforcing
Jim Pingle
03:24 AM Feature #9874: safesearch enforcing
received email from Yandex support with the list of domains for redirection:... Viktor Gurov
02:27 PM Feature #9916 (Pull Request Review): Check allow-transfer in custom option when the zone is slave
Jim Pingle
01:32 PM Feature #9916 (Resolved): Check allow-transfer in custom option when the zone is slave
If i add custom option (allow-transfer) to my slave zone, bind exit with error, because say already defined this opti... Am1g0 B0y

11/19/2019

01:45 PM Bug #9795: FRR add two or more ipv6 BGP Neighbors will system down
i try setup use openbgpd normarl work ipv6 with openvpn. so i think the frr sure has bugs. yon Liu
12:10 AM Feature #9913 (Resolved): Adding note Squid Traffic Managment Settings about feature limit
Squid Traffic Managment Settings mostly works with generic HTTP, so that, it may not work without HTTPS Interception ... Constantine Kormashev

11/18/2019

10:57 AM Feature #9912 (New): add custom DPI to ntopng
hi, since you don't read a conf file at startup, could you add the -p parameter to the startup script and point it to... ROB VANHOOREN
07:35 AM Feature #9906 (Pull Request Review): show ECDSA CAs and certs only with correct curves
Jim Pingle

11/16/2019

03:05 AM Feature #9906 (Resolved): show ECDSA CAs and certs only with correct curves
Do not show incompatible ECDSA CAs or certs for FreeRADIUS
same as https://redmine.pfsense.org/issues/9897
...
Viktor Gurov

11/15/2019

03:05 PM Todo #9900: Status -> Monitoring -> Add View
Thanks Jim a "pkg upgrade -y pfSense-Status_Monitoring" fixed it.
[2.4.4-RELEASE][admin@pfsense]/root: pkg info -x...
Andy Kniveton
07:24 AM Todo #9900 (Duplicate): Status -> Monitoring -> Add View
Duplicate of #9681
See also: https://forum.netgate.com/topic/147819/cannot-create-new-monitoring-views/2
Jim Pingle
04:46 AM Todo #9900 (Duplicate): Status -> Monitoring -> Add View
View names now seem to be forced lower case, seems odd as the default interface names are in upper case.
Andy Kniveton
12:00 PM Feature #9902 (Resolved): add sticky filter for Alert Log please
hi, could the filter be made sticky?
it's not (as of 4.1.5_2)
thanks!
R.
*observed behaviour:*
services>...
ROB VANHOOREN
10:16 AM Bug #9740 (Resolved): empty Status / Tinc VPN page on latest 2.5

Tested on pfSense 2.5.0.a.20191114.1802
tinc 1.0.35_2
OK, Resolved
Viktor Gurov
07:22 AM Feature #9901 (Pull Request Review): show ECDSA CAs only with correct curves
Jim Pingle
05:22 AM Feature #9901: show ECDSA CAs only with correct curves
https://github.com/pfsense/FreeBSD-ports/pull/709 Viktor Gurov
05:21 AM Feature #9901 (Resolved): show ECDSA CAs only with correct curves
Do not show incompatible ECDSA CAs for Squid HTTPS/SSL Interception
same as https://redmine.pfsense.org/issues/9897
Viktor Gurov
07:22 AM Todo #9158: Updates for Squid 4.x
Updated title. 2.5.0 snapshots are already using Squid 4.x (squid-4.8_1), but it may need adjustments to account for ... Jim Pingle

11/14/2019

02:38 AM Bug #9860 (Resolved): Illegal string offset 'config' in /usr/local/pkg/tinc.inc on line 83
tested on tinc 1.0.35_2
pfSense 2.5.0.a.20191113.1759
Resolved
Viktor Gurov
12:16 AM Bug #9895 (New): snort reinstallation failed
got such errors during snort pkg update:... Viktor Gurov

11/13/2019

08:27 AM Feature #9875 (Feedback): add extra engines safe search
PR has been merged. Thanks! Renato Botelho
07:59 AM Bug #8258 (Feedback): BIND responds with SERVFAIL when adding/changing records if 'allow-update' is configured for a zone
PR has been merged. Thanks! Renato Botelho
07:54 AM Bug #9850 (Feedback): show huperscan option only for x86 arch
PR has been merged. Thanks! Renato Botelho

11/10/2019

03:26 AM Feature #9874: safesearch enforcing
PR updated with Firefox DoH blocking support
(see https://forum.netgate.com/topic/133679/heads-up-be-aware-of-truste...
Viktor Gurov

11/09/2019

02:04 PM Feature #6022: Consider MLVPN for bonded VPN
https://forum.netgate.com/topic/144050/multi-wan-bonding-150
Added my 2 cents to the forum post, and added $100 to...
James Tandy
02:59 AM Feature #9874: safesearch enforcing
https://github.com/pfsense/FreeBSD-ports/pull/701 Viktor Gurov

11/08/2019

11:04 AM Feature #9890 (Needs Patch): Improves Network Quality on a High-latency Lossy Link by using Forward Error Correction
Jim Pingle
11:02 AM Feature #9890 (Needs Patch): Improves Network Quality on a High-latency Lossy Link by using Forward Error Correction
Network packet loss occurs frequently on long-distance international networks. like: use openvpn gre so on.
I think ...
yon Liu
09:51 AM Bug #9888 (Feedback): ACME output sent to browser without encoding
Fixed in ACME package version 0.6.3_1
https://github.com/pfsense/FreeBSD-ports/commit/a6f443cde51e7fcf17e51f16014d...
Jim Pingle
09:46 AM Bug #9888 (Resolved): ACME output sent to browser without encoding
ACME issue/renew output is sent directly to the browser without encoding. In some cases, user input may be included i... Jim Pingle
05:11 AM Feature #9885 (Resolved): OpenVPN client 2.4.8 update
Renato Botelho
03:29 AM Feature #9885: OpenVPN client 2.4.8 update
Hi!
Works.
Thanks!
Regards,
G
Greg M
 

Also available in: Atom