Project

General

Profile

Download (62.5 KB) Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
cac386b6 05/31/2014 01:01 AM Chris Buechler

remove openbgpd bits from system_gateways_edit and system.inc. The package
match is case-sensitive and hasn't matched the openbgpd package's name in
at least 5 years, so it doesn't do anything. It's far from functional in
any useful manner even fixing that issue.

64a2da80 05/14/2014 04:20 PM Chris Buechler

bind HTTP->HTTPS redirect to IPv6 too. Ticket #3437

66201c96 04/28/2014 09:12 PM Ermal LUÇI

Send HUP to restart syslogd rather than trying to restart it, thus loosing messages

3f06e538 04/28/2014 08:36 PM Warren Baker

make sure unbound is included here

f6248774 04/28/2014 08:00 PM Warren Baker

If Unbound is been used then make sure to reload when system_hosts_generate() is called

2a50fd8a 04/28/2014 02:54 PM Renato Botelho

Move clog from /usr to /usr/local

ebf45d96 04/28/2014 01:41 PM Ermal LUÇI

Add filterlog to separatefacilitylog to avoid logs going elsewhere

686777c4 04/28/2014 08:08 AM Ermal LUÇI

Use the daemon name to send the filter logs

75a8ba83 04/24/2014 08:02 PM Renato Botelho

Resolver has no option for remote syslog, remove wrong copy/paste that was adding it when apinger was enabled

b149b3a1 04/24/2014 08:00 PM Renato Botelho

Merge pull request #1118 from phil-davis/patch-3

bd5737dc 04/23/2014 02:16 PM Jim Pingle

Make sure that the DNS Forwarder/Resolver is actually capable of accepting queries on localhost before using it as a DNS server.

80571c81 04/21/2014 04:57 AM Phil Davis

Cut paste bug fix in Remote Syslog DHCP events

apinger is repeated here from the code above, but it should be dhcp.
Forum https://forum.pfsense.org/index.php?topic=73734.0
Selecting to remote syslog "Gateway Monitor events" would also switch on "DHCP service events" unintentionally.

69e593c1 04/07/2014 02:10 PM Jim Pingle

Make extra sure that we do not start multiple instances of dhcpleases if, for example, the PID is stale/invalid and there is still a running instance.

362fdc4c 03/28/2014 09:54 PM Ermal LUÇI

Remove remenants of pccardd from FreeBSD 5

8b650e57 03/20/2014 04:09 PM Jim Pingle

Avoid placing an empty "interface listen" directive in ntpd.conf

e1a456e6 03/15/2014 12:30 AM Chris Buechler

standardize URLs

703b1ce1 03/14/2014 08:35 PM Ermal LUÇI

Correct variable name, while here unset some large var

f0014c64 03/11/2014 03:40 PM Ermal LUÇI

Make this a bit more efficient

d07bc322 03/03/2014 04:31 PM Renato Botelho

Remove broken 'dynamic6' gateway, we already have ipprotocol to tell us the IP version, leave it more simple using only 'dynamic'. It helps #3484

7335fa53 02/25/2014 10:10 AM Ermal LUÇI
  • Correct logging to syslog and proper file for ipsec from strongswan
  • Use proper commands to reload strongswan rather than just the daemon
e570f0eb 02/20/2014 09:02 AM Ermal LUÇI

silence any errors

ec7bc948 02/19/2014 03:43 PM Ermal LUÇI

More code fixes for ntpd

0fd64e94 02/18/2014 03:06 PM robi robi

Update system.inc

Corrections made as requested

142f7393 02/18/2014 02:12 PM robi robi

Update system.inc

Add new NTPd functions

c79f717a 02/18/2014 09:25 AM Ermal LUÇI

Really need the interface where v6 is running toa dd the gateway/route rather than the one used for the configuration. This Fixes #3357

6240ba7b 02/11/2014 03:05 AM Phil Davis

Check for tmp captiveportal dir before making it

In forum: https://forum.pfsense.org/index.php/topic,72483.0.html
Warning: mkdir(): File exists in /etc/inc/system.inc on line 878
Not sure if you would rather call safe_mkdir here?

873c1701 02/04/2014 02:34 PM Renato Botelho

Add escapeshellarg() calls on exec parameters. While I'm here, replace some exec() calls by php functions like symlink, copy, unlink, mkdir

ca79de53 02/03/2014 02:34 PM Jim Pingle

Using "limited" for ntp in this way denies client access. Issue #3384

3b95d9ec 01/29/2014 03:06 PM Warren Baker

Add EDNS support for to resolv.conf

f4a4bcbc 01/28/2014 07:01 PM Renato Botelho

Fix typo on variable name, it fixes #3414

2ec95f1f 01/24/2014 10:33 AM Renato Botelho

Fix openssl path

fdfa8f43 01/15/2014 05:35 PM Jim Pingle

ports ntp moved to sbin, follow

706ba0e4 01/10/2014 04:41 PM Jim Pingle

Use "disable monitor" in NTP config to mitigate CVE-2013-5211.

6b660731 01/07/2014 10:58 AM Renato Botelho

Add 'limited' to ntpd restrict list to workaround CVE-2013-5211. It fixes #3384

c7a3356e 12/26/2013 08:27 PM Jim Pingle

Add a setting to allow the user to specify the clog file size so more (or less) entries may be kept in the raw logs. Retain previous default size values if the user has not specified a preferred size. Files can only be resized when initialized, so provide a "Reset All Logs" button as well to force clear all logs and set them up at the new size.

83e46727 12/14/2013 09:42 PM Ermal LUÇI

Mute the output of the command since its not really useful

4aea91d8 12/14/2013 07:20 PM Ermal LUÇI

Switch to php-fpm for lighty and check_reload_status will use it. Step by step will migrate the other calls

add913b1 11/01/2013 02:23 PM Renato Botelho

Teach system_timezone_configure() to deal with symlinks to avoid having timezone misconfigured. This fixes #3293

cbe12b8d 10/24/2013 08:33 PM Jim Pingle

Add source address selection to syslog settings, so it can work more effectively over a VPN. Fixes #355

6b0739ac 08/28/2013 08:11 PM Phil Davis

Use new names for get_memory parameters

6d501aef 08/16/2013 07:55 PM Renato Botelho

Use ntpdate from ports also and obsolete base one

2ec52b3e 07/30/2013 05:48 AM Daniel Becker

use correct domain names when registering static DHCP entries in DNS

When registering static DHCP entries in DNS, we first try to use the domain name configured for the static entry (if any), then the domain name configured in the DHCP server settings for the corresponding interface (if any), and as a last resort the system domain name....

dce51b01 07/18/2013 01:35 PM Jim Pingle

Disable the BEAST protection by default because the GUI will break if you use this and have a Hifn card installed. Others may break similarly. Change it into a checkbox option, off by default, and automatically disable it if a conflicting card has been detected.

ab17ed4e 07/14/2013 08:15 PM Dim Hatz

support mitigating BEAST attack

According to http://redmine.lighttpd.net/projects/lighttpd/wiki/Release-1_4_30

"...by setting

ssl.cipher-list = "ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM"

you can mitigate BEAST attacks."

1cf24f0a 07/09/2013 04:02 PM Jim Pingle

Add independent logging choices to disable logging of bogon network rules and private network rules. Add upgrade code to obey the existing behavior for users (if default block logging was disabled, so is bogon/private rule blocking). Also add a checkbox to disable the lighttpd log for people who don't want their system log spammed by lighty.

be544a5e 06/17/2013 08:26 AM Ermal LUÇI

Use family parameter for v6 to get correct interface

12f77b03 06/17/2013 07:44 AM Ermal LUÇI

Provide full path to route binary

8984529d 06/12/2013 07:05 AM Ermal LUÇI

Actually try to get the real interface for v6 family to correctly get stf(virtual) interfaces

e47d24e4 05/27/2013 01:17 PM Renato Botelho

Fixes to get routes + dns working:

. Simplify code using new parameter of get_staticroutes()
. Check for subnets instead of ip addrs
. Avoid touch filterdns when we are just updating dns

356e86d4 05/27/2013 10:23 AM Renato Botelho

Use filterdns to update static routes using hostnames

2a2b9eea 05/27/2013 10:03 AM Renato Botelho

Split system_routing_configure() and teach it to deal with hostnames

046583c3 05/27/2013 10:03 AM Renato Botelho

Simplify logic

db7a628c 05/09/2013 11:05 AM Renato Botelho

Replace all linklocal checks by is_linklocal()

5c8cbb26 05/08/2013 07:48 PM Jim Pingle

Shuffle some more logs around to more appropriate places.

a89b7342 05/08/2013 04:54 PM Jim Pingle

Send filterdns logs to the resolver log.

a80cb9ca 05/05/2013 12:19 AM Pi Ba

Fix dnsmasq host overrides 'enabled' check.

ea1aca13 05/01/2013 04:09 PM Renato Botelho

Fix dnsmasq host overrides and dhcp integration

. Do not execute following actions when dnsmasq is disabled:
. Add host overrides to /etc/hosts
. Register DHCP leases in DNS Forwarder
. Register DHCP static mappings in DNS forwarder

It should fix issue reported at following forum post:...

81448ffa 04/26/2013 05:10 PM Jim Pingle

Show IPv6 link-local IPs as specific sources for ping, traceroute, and port testing.

d28cd156 04/14/2013 05:36 PM Renato Botelho

Make fe80: addresses check case insensitive

0d56c06b 04/02/2013 03:12 PM Jim Pingle

Move some code to a function to avoid future duplication. Allow autocomplete on ping page. Add more escaping to command.

75f4d868 03/01/2013 02:16 PM Renato Botelho

Remove *_defaultgwv6 also

52034432 02/25/2013 12:32 PM Renato Botelho

Make sure captiveportal section of config is an array, reported on ticket #2838

34cb8645 02/18/2013 02:21 AM Jean Cyr

Avoid Warning: Invalid argument supplied for foreach() in /etc/inc/system.inc

Warning: Invalid argument supplied for foreach() in /etc/inc/system.inc

Don't use captiveportal configuration option variable if it isn't set

62f20eab 02/14/2013 11:19 PM Michael Newton

add support for RADIUS NAS accounting, fixes redmine feature request 2143

120404e0 02/14/2013 05:59 PM Warren Baker

Keep Unbound here for syslog messages

950c9a18 02/14/2013 05:50 PM Warren Baker

Backout Unbound for now bring back in 2.2. Fixes #2817

03e96afb 02/14/2013 12:18 PM Renato Botelho

Set $interfacegw properly and avoid losing default route in some circumstances

100f3e71 02/12/2013 08:18 PM Ermal LUÇI

Resolves #1284. Merge patch submitted a bit differentely

c4680ae2 02/11/2013 02:14 AM Jim Pingle

Whoops remove copypasta

3289b42b 02/11/2013 02:08 AM Jim Pingle

The actual variable isn't an array, so this test will never succeed. Remove it. Unbreaks ntp.

6a205b6a 02/10/2013 11:26 AM Ermal LUÇI

Sprinkle some unsets

9d595f6a 02/10/2013 11:26 AM Ermal LUÇI

Correct setting default gateways

df40755d 02/10/2013 11:13 AM Ermal LUÇI

Correct function name

b9f29f84 02/09/2013 09:17 PM Ermal LUÇI

Use mwexec() with signal clearing. Use pid file for killining/tracking ntpd

f934af33 02/09/2013 09:36 AM Ermal LUÇI

Optimize and cleanup routing function

8be135cd 02/09/2013 09:26 AM Ermal LUÇI

Correct system_routing_configure to do the right thing and guess the address family for the routing table correctly. While here cleanup some other code and leave a comment that disabled routing entries probably should not be dealt in here!

a358eec2 02/09/2013 01:09 AM N0YB

System: Advanced: Miscellaneous: PowerD

Add the on battery mode option settings.

94395d86 02/06/2013 10:23 PM Ermal LUÇI

Need to rethink this again
Revert "Ticket #2636 Seems ipsec apart IP-IP does not have any after processing for input packets. Make the filter apropriately so the packets are passed correctly through BPF and pfil(9)"

This reverts commit e0f338eb1b02d7bf4920d4682404412e98a3075c.

e0f338eb 02/05/2013 07:39 PM Ermal LUÇI

Ticket #2636 Seems ipsec apart IP-IP does not have any after processing for input packets. Make the filter apropriately so the packets are passed correctly through BPF and pfil(9)

e141ea70 02/05/2013 04:12 PM Ermal LUÇI

Use global var for path

a11bc497 02/05/2013 04:04 PM Ermal LUÇI

Unlink pid file before starting a new process

dae707f5 01/27/2013 05:20 PM Jim Pingle

Fixup paths when executing OpenSSL.

abdd01f5 01/26/2013 11:59 AM Ermal LUÇI

Correctly generate dhcpleases file to avoid issues with dhcpleases. Also while here correct code and make some optiomizations and corrections

8152f145 01/21/2013 07:33 PM Jim Pingle

Default to using sha256 digest for GUI cert.

b35fdb17 01/21/2013 02:35 PM Ermal LUÇI

Enable cgi for the webgui since some ports like lightsquid need it

76a7d8e4 01/16/2013 01:29 PM Ermal LUÇI

Merge git pull request 313 from bcyrill with some modifications

526102c1 01/10/2013 07:01 PM Jim Pingle

Put syslogd into secure mode so no remote log messages are accepted. Sending to a remote syslog server still works with this option.

d53a9a51 01/05/2013 03:02 PM Seth Mos

The ISC client was far worse then the WIDE client was, back to plan A
Revert "Merge changes required for using the ISC dhclient in pfSense with prefix delegation. This should hopefully be a bit more reliable in the long run."

This reverts commit 651018775c78e38045966825b920b641a0302b43....

e384f16e 01/04/2013 10:55 AM Ermal LUÇI

If less than 78 RAM just do not let php spawn another process

70e454e1 01/04/2013 10:00 AM Ermal LUÇI

Slight code re-organization

a96f2d3d 01/04/2013 09:51 AM Ermal LUÇI

Remove to parameters from system_generate_lighty_config that are unused and do a better job at tuning started php processes to not use less/more than needed. This also avoids DoS the system with php processes

748c7b85 01/03/2013 02:25 PM Ermal LUÇI

Always make sure php has its own process manager to make lighty happy

2ba3ea05 01/03/2013 01:08 PM Renato Botelho

Avoid duplicate log entries for facilities higher or equal daemon.info. It should fix #2626

f7bddb24 01/03/2013 10:22 AM Ermal LUÇI

Simplify lighty config and tune mod_evasive as needed. Mostly a cherry-pick from RELENG_2_0 changes

344016a8 11/20/2012 04:10 PM Ermal LUÇI

Cleanup a bit the syslog generation

73ebd062 11/15/2012 02:32 PM Ermal LUÇI

Remove preload.php which warmed the caches. IT hurts on embedded and really does not help that much

65101877 10/12/2012 10:20 AM Seth Mos

Merge changes required for using the ISC dhclient in pfSense with prefix delegation. This should hopefully be a bit more reliable in the long run.
The dhclient6-script could be merged with dhclient-script in the future.
Still need to cleanup old adresses and prefixes, as well as LAN prefixes when a old prefix dissapears. This needs some thought and clue to strap together.

050fd8ad 10/04/2012 08:55 PM Ermal LUÇI

Rather use the system constants as defined

e4d7130d 10/04/2012 08:51 PM Ermal LUÇI

Use integer rather than hex to put these values. AMD64 builds do rather awkward problems

7b27db03 10/03/2012 05:17 PM Jim Pingle

Add restrict lines to limit what local clients are allowed to do to the ntp server.