Project

General

Profile

Activity

From 12/02/2019 to 12/31/2019

12/31/2019

11:48 AM Bug #9652 (New): Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
Jim Pingle
11:39 AM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
I tried to completely remove the squid package from gui and filesystem... probably thinking about some misconfigurati... Stefano Mereghetti
10:48 AM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
Hello, thanks.
just tested with the last merge (2.4.5.a.20191231.0928) and squid package (0.4.44_12) and after the...
Stefano Mereghetti
09:46 AM Bug #6339 (Pull Request Review): OpenVPN Client Export package option for "Use Microsoft Certificate Storage" does not specify which certificate to use
Jim Pingle
09:37 AM Bug #6339: OpenVPN Client Export package option for "Use Microsoft Certificate Storage" does not specify which certificate to use
https://github.com/pfsense/FreeBSD-ports/pull/739 Viktor Gurov
08:56 AM Feature #10141 (Resolved): pfBlockerNG - MaxMind License Registration
As per MaxMind:
https://blog.maxmind.com/2019/12/18/significant-changes-to-accessing-and-using-geolite2-databases/
...
BBcan177 .
07:35 AM Feature #10140 (Pull Request Review): allow to select webserver certificate
Jim Pingle
05:54 AM Feature #10140 (Closed): allow to select webserver certificate
This feature allow user to select certificate for internal webserver of pfBlocker (lighttpd)
It saves the old /var/u...
Viktor Gurov
07:29 AM Bug #9204 (Needs Patch): ospfd: GRE tunnels became unnumbered since 2.4.4
Looks like it's already been raised upstream with FRR, and the issue is still open: https://github.com/FRRouting/frr/... Jim Pingle
01:18 AM Bug #9204: ospfd: GRE tunnels became unnumbered since 2.4.4
Jim Pingle wrote:
> Can you test this with the current version of FRR (preferably on 2.5.0, if 2.4.4 doesn't work)?
...
Viktor Gurov
06:55 AM Bug #9322 (Feedback): telegraf "Additional configuration for Telegraf" lost configuration after reboot
PR has been merged. Thanks! Renato Botelho
06:39 AM Bug #9322: telegraf "Additional configuration for Telegraf" lost configuration after reboot
https://github.com/pfsense/FreeBSD-ports/pull/737 Viktor Gurov
06:12 AM Bug #9750 (Feedback): squidguard_blacklist.php & squidguard_log.php wrong status icon link
PR has been merged to 2.5.0 and 2.4.5
Thanks
Renato Botelho

12/30/2019

03:13 PM Bug #9652 (Feedback): Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
PR has been merged. Thanks! Renato Botelho
02:52 PM Feature #9563 (Feedback): Syslog-ng TLS support
PR has been merged. Thanks! Renato Botelho
08:42 AM Feature #9563 (Pull Request Review): Syslog-ng TLS support
Jim Pingle
02:50 PM Feature #9523 (Feedback): LADVD: Feature to enable setting interface descriptions
PR has been merged. Thanks! Renato Botelho
08:56 AM Feature #9523 (Pull Request Review): LADVD: Feature to enable setting interface descriptions
Jim Pingle
11:06 AM Feature #10134 (Resolved): pfSense-pkg-softflowd: Add additional options available in softflowd-1.0.0
*DEPENDS* on FreeBSD ports issue https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=242960
pfSense PR: https://gith...
Ross Williams
09:34 AM Feature #10002 (Pull Request Review): allow to use lo0 interface for web-server
Jim Pingle
08:44 AM Feature #9217 (Pull Request Review): Squid LDAP Authentication - spaces in ldif values
Jim Pingle
08:39 AM Bug #9750 (Pull Request Review): squidguard_blacklist.php & squidguard_log.php wrong status icon link
Jim Pingle

12/28/2019

03:13 PM Bug #10003 (Duplicate): Visiting VPN > Apple IPsec Profile renders the navigation dropdown buttons useless
Duplicate of #8502 Jim Pingle
03:05 PM Bug #10003 (Duplicate): Visiting VPN > Apple IPsec Profile renders the navigation dropdown buttons useless
On pfSense 2.4.5.a.20191227.1746, running ipsec-profile-wizard v0.12, when the user visits VPN > Apple IPsec Profile,... Anonymous
02:35 PM Bug #9811 (Resolved): apcupsd - can not set BATTERYLEVEL and MINUTES to -1 although these are valid values
Tested apcupsd version 0.3.91_8, works as expected. Anonymous
10:52 AM Feature #10002 (Closed): allow to use lo0 interface for web-server
By default pfBlocker uses LAN interface for internal web-server and VIP alias, and do not allow to use Loopback for i... Viktor Gurov

12/27/2019

07:48 AM Bug #9635 (Resolved): lldpd (and probably ladvd) doesn't work on units with an integrated switch
no such issue on SG-3100 with pfSense 2.4.4-p3
lldpd updated to version 1.0.4 on 2.4.5/2.5
tested on pfSense ...
Viktor Gurov
01:38 AM Feature #9523: LADVD: Feature to enable setting interface descriptions
https://github.com/pfsense/FreeBSD-ports/pull/731 Viktor Gurov
01:06 AM Bug #9273 (Closed): missing Include=/usr/local/etc/zabbix4/zabbix_agentd.conf.d in /usr/local/etc/zabbix40/zabbix_agentd.conf
You can manually add line ... Viktor Gurov

12/26/2019

11:58 PM Bug #8139 (Resolved): LADVD not working on LAGG interfaces
ladvd updated to 1.1.2 on pfSense 2.4.5 and 2.5
tested on pfSense 2.5.0.a.20191226.0326 and 2.4.5.a.20191209.0732
...
Viktor Gurov
10:19 AM Feature #9217: Squid LDAP Authentication - spaces in ldif values
https://github.com/pfsense/FreeBSD-ports/pull/729 Viktor Gurov
05:47 AM Feature #9563: Syslog-ng TLS support
https://github.com/pfsense/FreeBSD-ports/pull/728 Viktor Gurov
12:17 AM Bug #9676: AS lookup fails
for some reason all online AS databases shows zero prefixes for this AS:
https://api.hackertarget.com/aslookup/?q=AS...
Viktor Gurov

12/25/2019

11:59 PM Bug #9750: squidguard_blacklist.php & squidguard_log.php wrong status icon link
https://github.com/pfsense/FreeBSD-ports/pull/727 Viktor Gurov
08:10 AM Bug #9999: unbound fatal error if System Domain in DNSBL and System Domain Local Zone Type is Redirect
https://github.com/pfsense/FreeBSD-ports/pull/726 Viktor Gurov
12:22 AM Bug #9999 (New): unbound fatal error if System Domain in DNSBL and System Domain Local Zone Type is Redirect
On System / General Setup I have configured <MYHOST> as hostname and mywire.org (dynu.com dyndns provider) as domain ... Viktor Gurov

12/23/2019

08:46 AM Bug #9994 (Rejected): Siproxd can not working
There isn't enough information here to suggest that it's a bug in pfSense, rather than a limitation in siproxd. There... Jim Pingle
01:02 AM Bug #9994 (Rejected): Siproxd can not working
User voip not registration through the siproxd when amount user equal or bigger 130 user quoctu nguyen

12/21/2019

09:09 AM Bug #9962 (Resolved): HAproxy Upgrade needed HTTP/2 CVE-2019-19330
Jim Pingle
12:43 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
Jim Pingle wrote:
> The packages will show up on 2.4.4 immediately, they are already there:
> [...]
>
> For 2.4....
Viktor Gurov
05:17 AM Bug #9807 (Resolved): Packets Monitoring graphs are being incorrectly scaled
tested on pfSense 2.4.5.a.20191220.1407
works,
Resolved
Viktor Gurov

12/20/2019

03:15 PM Feature #9973 (New): Nagios NRPE package isn't IPv6 capable
That PR didn't turn out to be necessary. IPv6 addresses are accepted in the GUI already. If they are rejected for you... Jim Pingle
01:31 PM Bug #9220 (Resolved): STunnel: Tunnel list does not show certificate
Looks good on stunnel 5.50_4 Jim Pingle
07:44 AM Bug #9220 (Feedback): STunnel: Tunnel list does not show certificate
PR has been merged. Thanks! Renato Botelho
11:48 AM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
Looks like the new program called 'security_file_certgen' replace ssl_crtd in the latest version of squid.
Exist 1 ...
Peter Moreno
10:32 AM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
Hello
I modified squid.inc adding security_file_certgen instead ssl_crtd (PF ver 2.4.5) but the result is:...
Stefano Mereghetti
10:31 AM Bug #9986: Squid package Transparent Mode MITM
This issue is closed since it was a duplicate report of another issue. If you have information to add, add it as a co... Jim Pingle
10:30 AM Bug #9986: Squid package Transparent Mode MITM
Hello
I modified squid.inc in my installation 2.4.5 but the result is:...
Stefano Mereghetti
10:05 AM Feature #9982: basic_ldap_auth TLS connection
updated:
https://github.com/pfsense/FreeBSD-ports/pull/725
Viktor Gurov
08:19 AM Feature #9989: Add FreeBSD port and pfSense plugin for HoneyTrap
Might be something we could consider but I do not like the idea of running a service like this on a firewall. Deliber... Jim Pingle
08:08 AM Feature #9989 (Rejected): Add FreeBSD port and pfSense plugin for HoneyTrap
Ezri Mudde
07:32 AM Bug #9988 (Duplicate): Squid - SSL Inspection
Duplicate of #9652 Jim Pingle
05:31 AM Bug #9988 (Duplicate): Squid - SSL Inspection
Hello
with 2.4.5 snapshot, I tried to enable SSL inspection using an OLD CA and a new CA.
The result is:...
Stefano Mereghetti
07:25 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
The packages will show up on 2.4.4 immediately, they are already there:... Jim Pingle
06:14 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
pfSense find it =) DRago_Angel [InV@DER]
06:02 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
Renato Botelho wrote:
> 2.0.10 / 1.8.23 and 1.7 .12 were pushed to proper branches
Thanks, how can I trigger upgr...
DRago_Angel [InV@DER]
05:56 AM Bug #9962 (Feedback): HAproxy Upgrade needed HTTP/2 CVE-2019-19330
2.0.10 / 1.8.23 and 1.7 .12 were pushed to proper branches Renato Botelho
03:49 AM Bug #9962 (In Progress): HAproxy Upgrade needed HTTP/2 CVE-2019-19330
Renato Botelho
07:17 AM Feature #9875 (Resolved): add extra engines safe search
The note is correct when I just installed the package, and it's correct in all the right branches of the repository. ... Jim Pingle
12:22 AM Feature #9875: add extra engines safe search
Renato Botelho wrote:
> PR has been merged. Thanks!
Tested on pfSense 2.5.0.a.20191219.1908 with squidGuard 1.16....
Viktor Gurov

12/19/2019

10:44 PM Todo #9392: Status_Traffic_Totals needs updated for vnstat 2.0
Affects both 2.5.0 and 2.4.5 Jim Pingle
10:44 PM Bug #9987 (Duplicate): Bug #9759 from 2.5 is repro'ing on 2.4.5 as well
Duplicate of #9392 Jim Pingle
09:58 PM Bug #9987 (Duplicate): Bug #9759 from 2.5 is repro'ing on 2.4.5 as well
I'm guessing the same new version of vnstat is now also being used on 2.4.5 and so the vnstat -u command no longer wo... Richard Powell
08:35 PM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
This will need picked back to RELENG_2_4_5 when merged. Jim Pingle
08:35 PM Bug #9986 (Duplicate): Squid package Transparent Mode MITM
Duplicate of #9652 Jim Pingle
08:10 PM Bug #9986 (Duplicate): Squid package Transparent Mode MITM
This issue is related to squid version 4.9.x, this new version no longer use ssl_crtd now is called 'security_file_ce... Peter Moreno

12/18/2019

08:00 AM Feature #9973 (Pull Request Review): Nagios NRPE package isn't IPv6 capable
Jim Pingle
07:52 AM Feature #9973: Nagios NRPE package isn't IPv6 capable
Jim Pingle wrote:
> Not a bug, but a missing feature.
binding IP: I can only give one IP. For Dual Stack I need t...
Viktor Gurov
06:49 AM Feature #9824 (Resolved): Add support for DuckDuckGo's Safe Search
Tested on pfSense 2.5.0.a.20191217.2217, squid 0.4.44_9
Resolved
Viktor Gurov
06:40 AM Feature #9982 (Pull Request Review): basic_ldap_auth TLS connection
Jim Pingle
05:47 AM Feature #9982 (Feedback): basic_ldap_auth TLS connection
Allow to use -Z option by basic_ldap_auth for TLS LDAP connection
see:
http://www.squid-cache.org/Versions/v3/3.2...
Viktor Gurov
06:09 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
any update of status? DRago_Angel [InV@DER]
03:14 AM Bug #9219 (Resolved): STunnel: .pem files are created with incorrect permissions.
Renato Botelho wrote:
> PR has been merged. Thanks!
Tested on pfSense 2.5.0.a.20191217.2217 with stunnel 5.50_3
...
Viktor Gurov

12/17/2019

08:29 PM Bug #9980: Fresh install of Suricata 4.1.5 package warns about CVE-2015-3152; need newer MySQL
Thanks for the fast response!
I don't use Barnyard2, so that's good news for me.
But for others... is this ther...
Sean McBride
08:21 PM Bug #9980: Fresh install of Suricata 4.1.5 package warns about CVE-2015-3152; need newer MySQL
The MySQL dependency is actually being pulled in by Barnyard2 and not Suricata itself. So long as you do not configur... Bill Meeks
06:17 PM Bug #9980 (Closed): Fresh install of Suricata 4.1.5 package warns about CVE-2015-3152; need newer MySQL
5 minutes ago I installed Suricata 4.1.5 package on pfSense 2.4.4-RELEASE-p3 (both newest at this time). It output a... Sean McBride
08:24 PM Bug #9981: Suricata "Use IP Reputation Lists on this interface." actually defaults to ON, despite incorrect comment.
Internal bug tracking list? Should I be filing somewhere else than here? Sean McBride
08:22 PM Bug #9981: Suricata "Use IP Reputation Lists on this interface." actually defaults to ON, despite incorrect comment.
I'll look into this and add it to my internal bug tracking list for Suricata. Bill Meeks
06:32 PM Bug #9981 (Resolved): Suricata "Use IP Reputation Lists on this interface." actually defaults to ON, despite incorrect comment.
See attached.
Despite the comment, that option is *ON* by default. I just did a fresh install.
Sean McBride
08:01 AM Feature #9974 (Feedback): Add pfSense package for sysutils/node_exporter
PR has been manually merged. Thanks! Renato Botelho
08:00 AM Feature #9974 (Resolved): Add pfSense package for sysutils/node_exporter
PR: https://github.com/pfsense/FreeBSD-ports/pull/653 Renato Botelho
07:58 AM Bug #9807: Packets Monitoring graphs are being incorrectly scaled
This was picked back to 2.4.5 as well, so needs testing there. Jim Pingle
06:28 AM Bug #9807 (Feedback): Packets Monitoring graphs are being incorrectly scaled
PR has been merged. Thanks! Renato Botelho
07:28 AM Feature #9973: Nagios NRPE package isn't IPv6 capable
Not a bug, but a missing feature. Jim Pingle
04:54 AM Feature #9973 (New): Nagios NRPE package isn't IPv6 capable
In pfSense 2.4.4p3 Nagios NRPE package lacks IPv6 capabilities.
1. binding IP: I can only give one IP. For Dual St...
Pim Pish
06:19 AM Bug #9219 (Feedback): STunnel: .pem files are created with incorrect permissions.
PR has been merged. Thanks! Renato Botelho

12/16/2019

10:23 AM Bug #9220 (Pull Request Review): STunnel: Tunnel list does not show certificate
Jim Pingle
09:01 AM Bug #9220: STunnel: Tunnel list does not show certificate
https://github.com/pfsense/FreeBSD-ports/pull/720 Viktor Gurov
10:23 AM Bug #9652 (Pull Request Review): Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
Jim Pingle
10:23 AM Bug #9219 (Pull Request Review): STunnel: .pem files are created with incorrect permissions.
Jim Pingle
10:22 AM Bug #9807 (Pull Request Review): Packets Monitoring graphs are being incorrectly scaled
Jim Pingle

12/14/2019

02:00 AM Bug #9652: Squid Proxy Server /var/squid/lib/ssl_db directory not found in squid.inc
https://github.com/pfsense/FreeBSD-ports/pull/719 Viktor Gurov

12/13/2019

11:37 PM Bug #9219: STunnel: .pem files are created with incorrect permissions.
https://github.com/pfsense/FreeBSD-ports/pull/718 Viktor Gurov

12/12/2019

01:28 PM Bug #9807: Packets Monitoring graphs are being incorrectly scaled
https://github.com/pfsense/FreeBSD-ports/pull/717 Viktor Gurov
07:02 AM Bug #9807: Packets Monitoring graphs are being incorrectly scaled
They are a part of the Status_Monitoring package (which is included in the base install), so the files are in the fre... Jim Pingle
06:41 AM Bug #9807: Packets Monitoring graphs are being incorrectly scaled
for some reason there is no rrd_fetch_json.php and status_monitoring.php files on github
fixed version:...
Viktor Gurov

12/11/2019

11:42 PM Bug #9967 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
Please post on the forum to discuss and identify the issue. There is not enough information here to know what the iss... Jim Pingle
10:12 PM Bug #9967 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
ear in pf sense 2.4.4-DEVELOPMENT (AMD64) when squid proxy sever enable the squid SSL Filtering option for block secu... Noman Akbar
08:13 AM Bug #9965 (Resolved): Since 0.15.7_2, legit LDAP server certs cannot be selected anymore
Thanks for testing! Jim Pingle
08:00 AM Bug #9965: Since 0.15.7_2, legit LDAP server certs cannot be selected anymore
Excellent; thank you very much! I can confirm this is fixed here! Didier Raboud
07:50 AM Bug #9965 (Feedback): Since 0.15.7_2, legit LDAP server certs cannot be selected anymore
Fixed in 0.15.7_7 Jim Pingle
05:29 AM Bug #9965 (Resolved): Since 0.15.7_2, legit LDAP server certs cannot be selected anymore
It seems that https://github.com/pfsense/FreeBSD-ports/commit/8cbbd84a374f4942e082c5898e93040c5ac65bbb broke the `/pk... Didier Raboud
07:53 AM Bug #9962: HAproxy Upgrade needed HTTP/2 CVE-2019-19330
The new versions are in the ports tree in master, but need picked back to devel, RELENG_2_4_4, and RELENG_2_4_5 Jim Pingle

12/10/2019

08:11 AM Bug #9962 (Resolved): HAproxy Upgrade needed HTTP/2 CVE-2019-19330
[https://nvd.nist.gov/vuln/detail/CVE-2019-19330]
Haproxy 1.8 need be updated to 1.8.23 (RD: 2019/11/25) from 1.8....
DRago_Angel [InV@DER]

12/06/2019

10:40 PM Bug #9960 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
Do not open issues here for this. Post on the forum to discuss and diagnose the problem and obtain more information. ... Jim Pingle
10:38 PM Bug #9960 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
dear in pf sense 2.5.0-DEVELOPMENT (AMD64) when squid proxy sever enable the squid SSL Filtering option for block sec... Noman Akbar
10:32 PM Feature #9959 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
Please post on the forum to discuss and identify the issue. There is not enough information here. 2.5.0 is in develop... Jim Pingle
10:29 PM Feature #9959 (Rejected): SSL Filter enable stopped Squid Proxy and guard filter services
dear in pf sense 2.5.0-DEVELOPMENT (AMD64) when squid proxy sever enable the squid SSL Filtering option for block sec... Noman Akbar

12/02/2019

04:26 PM Bug #9849: NUT not starting as root? Isn't loading USB drivers?
Braden McGrath wrote:
> Ryan McCullough wrote:
> > It looks like the NUT/UPS driver isn't loading the USB driver un...
Ryan McCullough
04:16 PM Bug #9849: NUT not starting as root? Isn't loading USB drivers?
Ryan McCullough wrote:
> It looks like the NUT/UPS driver isn't loading the USB driver unless I pass the "-u root" p...
Braden McGrath
01:24 PM Bug #9940 (Duplicate): Removing "default" view under monitoring blocked
Duplicate of #9352 Jim Pingle
12:56 PM Bug #9940 (Duplicate): Removing "default" view under monitoring blocked
I managed to add a extra view named "default" in the monitoring page. When trying to remove said misstake it is not p... Joakim Dellrud
 

Also available in: Atom