Project

General

Profile

Statistics
| Branch: | Tag: | Revision:

# Date Author Comment
d30d2108 12/31/2019 02:21 PM Jim Pingle

Move igmpproxy logs to routing.log. Fixes #10139

1cd960a8 12/31/2019 02:11 PM Renato Botelho

Merge pull request #4132 from vktg/hidenoprvcerts

a5b927e5 12/31/2019 02:10 PM Renato Botelho

Merge pull request #4142 from vktg/routedelete

5a24d994 12/31/2019 06:46 AM Viktor Gurov

fixes

4e8cb2fc 12/31/2019 05:25 AM Viktor Gurov

parenthesis fix

99a641df 12/30/2019 11:02 PM Luiz Souza

Ignore the flash devices during the scan for config files at boot.

db1f9fe5 12/30/2019 09:04 PM Renato Botelho

Merge pull request #4143 from vktg/ipsecgcmnoah

f6d8ae5a 12/30/2019 09:03 PM Renato Botelho

Merge pull request #4129 from luckman212/dns-v6-options-patch-2

3ae60408 12/28/2019 01:56 PM Viktor Gurov

cosmetic

1f8e92a3 12/28/2019 01:41 PM Viktor Gurov

strip hash algo if ealgo == *gcm

988e6c59 12/28/2019 11:02 AM Viktor Gurov

fix route delete code

853c97a7 12/28/2019 10:32 AM Viktor Gurov

fix route delete code

64031495 12/20/2019 04:04 PM Jim Pingle

Update copyright notice years. Issue #9245

9701089e 12/18/2019 09:27 PM Jim Pingle

Rework IPsec P1 Lifetime GUI options. Fixes #9983

d250c48b 12/18/2019 07:32 AM Viktor Gurov

fix

cd91a57c 12/17/2019 04:51 PM Renato Botelho

Use full path for pkg-static

09646aef 12/17/2019 03:31 PM → luckman212

Remove superfluous ( )'s

c58e56fb 12/17/2019 02:24 PM → luckman212

3rd try - change config names

bc18c480 12/17/2019 01:12 PM Renato Botelho

Merge pull request #4109 from vktg/p11ipsec

79fc17f9 12/17/2019 01:00 PM Renato Botelho

Merge pull request #4122 from vktg/ecdsarenew

e43c71ce 12/17/2019 10:42 AM Viktor Gurov

do not show certs without prv by default

9f6432f0 12/16/2019 11:52 PM → luckman212

2nd try
change config option to avoid positive checkbox = negative option

f645d52a 12/16/2019 05:33 PM Viktor Gurov

Token -> PKCS#11

e194f002 12/14/2019 02:48 PM Viktor Gurov

gui renaming pkcs11 -> token + show ID

367d8609 12/14/2019 02:10 PM Viktor Gurov

cert on token check

403add46 12/14/2019 11:07 AM Viktor Gurov

cosmetic

3edfe694 12/14/2019 11:03 AM Viktor Gurov

working

e881843a 12/14/2019 09:57 AM Viktor Gurov

pcscd service

5f143b6e 12/13/2019 08:19 PM Viktor Gurov

some progress

58264457 12/13/2019 06:39 PM Renato Botelho

Fix #9873: Use pkg-static

When pkg repo points to a new major version pkg is updated, use
pkg-static binary to check PHP version and make sure the command works

ef30c0a7 12/13/2019 01:38 PM Jim Pingle

Move syslog format var to syslog.inc. Issue #9808

In some cases, PHP is unhappy with calls to gettext() in globals.inc

e26ad76e 12/13/2019 01:41 AM → luckman212

Add opts to services_dhcpv6.php and services_router_advertisements.php

Adds config options to disable pushing DNS server options to dhcp6
clients via dhcpd or radvd. Fixes an issue when using split-horizon
DNS with dnsmasq via `localise-queries` option since that supports...

b16c3a12 12/12/2019 07:25 PM Jim Pingle

Add option for RFC5424 syslog format. Implements #9808

f829d7e2 12/10/2019 02:20 PM Jim Pingle

Don't dedup DNS from dyn sources if override is disabled. Fixes #9963

88a8d5cf 12/10/2019 01:08 PM Renato Botelho

Merge pull request #4123 from lucasheld/fix-queue-stats

8c120b1f 12/07/2019 02:02 PM Viktor Gurov

conflicts resolved, needs testing

62bac37e 12/06/2019 01:02 PM Jim Pingle

Lower default_cert_expiredays warning threshold to 27 days

Even at 28, ACME still sometimes warns unnecessarily just before renewal.

c6220dcf 12/05/2019 08:29 PM Jim Pingle

IPsec swanctl conversion. Implements #9603

  • Converted IPsec configuration code from ipsec.conf ipsec/stroke style
    to swanctl.conf swanctl/vici style. Issue #9603
  • Split up much of the single large IPsec configuration function into
    multiple functions as appropriate....
5a0f6513 12/02/2019 01:57 PM Lucas Held

simplify queue stats parser

e5deede5 12/01/2019 05:34 PM Lucas Held

support variable value length in queue stats parser

7ee29634 11/29/2019 07:05 PM Viktor Gurov

curve_compatible_list - array of all compat curves

e99c638b 11/29/2019 02:41 PM Jim Pingle

Init aliases array before use. Fixes #9936

1b970bb2 11/29/2019 01:49 PM Luiz Souza

Only try existent devices when looking for the dump device.

00d9ce91 11/28/2019 01:46 PM Viktor Gurov

typo

941470ef 11/28/2019 01:37 PM Viktor Gurov

prime256v1 ec curve for renew

0f64460f 11/27/2019 04:31 PM Renato Botelho

Merge pull request #4098 from vktg/delzombiealiases

0619c2b5 11/27/2019 09:16 AM Viktor Gurov

cosmetic

0de3991f 11/27/2019 09:13 AM vktg

Merge branch 'master' into p11ipsec

aad37244 11/27/2019 08:59 AM Viktor Gurov

rebase

2d604c8b 11/27/2019 08:57 AM Viktor Gurov

successful connection

5fe27d1c 11/27/2019 08:57 AM Viktor Gurov

more

8b859d91 11/27/2019 08:34 AM Viktor Gurov

first steps

43996917 11/27/2019 08:26 AM Viktor Gurov

merge with upstream

647bbe86 11/27/2019 05:22 AM Viktor Gurov

array_diff fix

75b83f36 11/27/2019 05:20 AM Viktor Gurov

array_diff fix

f61a794a 11/26/2019 04:56 PM Jim Pingle

Unset temp vars when refreshing CRLs. Issue #9915

Otherwise it might unintentionally add a CRL to a server which does not
have one selected

475d712b 11/26/2019 04:05 PM Jim Pingle

When refreshing CRLs, increment suffix, do not clean up. Fixes #9915

While here, fix a bug with refresh path.

84041dcf 11/26/2019 03:15 PM Jim Pingle

Correctly populate CRL issuer in crl_contains_cert. Fixes #9924

3c1249b3 11/26/2019 02:14 PM Jim Pingle

Add 'none' option to cert_build_list. Issue #9923

348c2af1 11/25/2019 09:50 PM Jim Pingle

Restructure OpenVPN settings directory layout

  • Changed from /var/etc/openvpn[-csc]/<mode><id>.<file> to
    /var/etc/openvpn/<mode><id>/<x>
  • This keeps all settings for each client and server in a clean
    structure
  • Move to CApath style CA structure for OpenVPN, which implements #9915...
d4b090cb 11/25/2019 05:10 PM Renato Botelho

Merge pull request #4112 from vktg/poly1305tls12

59fac81f 11/25/2019 04:42 PM Jim Pingle

Add select_source compatible output to cert_build_list(). Implements #9923

8afa74bb 11/25/2019 03:06 PM Jim Pingle

Enforce limiter delay 0<=x<=10000. Fixes #9921

e5c4f2a7 11/22/2019 07:19 PM Jim Pingle

Make OpenVPN username-as-common-name options. Implements #8289

7591a72a 11/22/2019 06:59 PM Jim Pingle

Add exit notify to OpenVPN servers/clients. Implements #9078

19a0636d 11/22/2019 04:41 PM Jim Pingle

Prevent OpenVPN tunnel network reuse. Fixes #3244

Ensures that a submitted tunnel network is not already in use on other
OpenVPN client or server instances, to avoid conflicts.

ca3cddbe 11/22/2019 01:44 PM Jim Pingle

Update OpenVPN EC list based on testing. Issue #9744

327ad811 11/21/2019 09:22 PM Jim Pingle

CDATA escape more auth-related fields. Fixes #9327

bc3e78ab 11/21/2019 07:41 PM Jim Pingle

OpenVPN ECDH/ECDSA filtering. Fixes #9744

Can be revisited in the future if the corresponding OpenVPN bug is
resolved.

1d9fbb71 11/20/2019 04:47 PM Jim Pingle

Correct VTI IPv6 test and syntax. Fixes #9801

94ce250e 11/20/2019 04:29 PM Jim Pingle

Move CA random serial option to upper section. Issue #9883

This allows it to be set when creating a new CA, so it doesn't have to
be edited in later.

Also show the next serial/random status in the CA info block
Hide trust store line from non-CA entries since it's not relevant to...

d1f5587d 11/19/2019 04:43 PM Jim Pingle

Rename IPsec "RSA" options to "Certificate". Implements #9903

6ecea21a 11/18/2019 04:52 PM Renato Botelho

Fix #7791: strings binary can be useful for troubleshooting

9dfd57c0 11/15/2019 04:02 PM Jim Pingle

Attempt to fetch EC curve OID if name is blank. Issue #9745

1120b85c 11/15/2019 03:51 PM Jim Pingle

Certificate date calculation changes. Fixes #9899

Make the certificate date calculation more general and also try multiple ways
to determine the date (both timestamp and unix timestamp).

Catch cases where one or the other date fails to calculate to avoid errors....

cffcf9bf 11/14/2019 08:59 PM Jim Pingle

GUI improvements for ECDSA certificate handling

  • Make central functions to check and test ECDSA compatibility. Issue #9843
  • Filter incompatible certificates from being offered for the GUI or Captive Portal. Implements #9897
  • Do the same for IPsec, which implements #4991...
b58fe676 11/14/2019 04:08 PM Viktor Gurov

order fix

f660c27d 11/14/2019 01:55 PM Viktor Gurov

add poly1305-chacha20 to nginx cipher list

c3cda38e 11/14/2019 01:43 PM Jim Pingle

Change default ECSDA curve to prime256v1. Issue #9843

Previous default was brainpool, but brainpool curves are not (widely?)
supported by browsers and were deprecated by IETF for TLS v1.3

4b4df568 11/13/2019 06:28 PM Jim Pingle

Revert "RADVD: In "managed" or "stateless_dhcp" mode, don't use default values for DNS servers etc (these should come from DHCPv6)"

This reverts commit dcc887a355aae49c7df0c29752c04e12922aca83.

b8b33a3e 11/07/2019 04:50 PM Jim Pingle

Use more accurate date calculations for CA/Cert operations.

Otherwise calculations could fail on ARM

26c4679b 11/07/2019 04:49 PM Jim Pingle

Lower default cert expire days to 28.

At 30 days, an ACME cert may not have triggered automatic renewal yet,
so it would warn unnecessarily.

ecb594d0 11/05/2019 09:50 PM Jim Pingle

Use central download function

Reduce duplicated/inconsistent code by using the new download function.

1342f80f 11/05/2019 09:04 PM Jim Pingle

Add central file download function for use throughout the GUI.

a6bd9e78 11/05/2019 04:31 PM Jim Pingle

Validate CA/CRL serial input. Issue #9883 Issue #9869

d5a222cc 11/05/2019 01:32 PM Jim Pingle

Update privilege definitions

3a877e4a 11/04/2019 07:30 PM Jim Pingle

Enforce a max lifetime for CA/Cert/CRL. Issue #3956

2c9601c9 11/04/2019 07:02 PM Jim Pingle

Add support for randomized cert serial numbers. Implements #9883

7997506f 11/03/2019 05:09 PM vktg

Update globals.inc

e15ceee7 11/03/2019 05:08 PM vktg

fixes

783e9a2a 11/03/2019 04:58 PM vktg

Update globals.inc

2fc1e9a2 11/03/2019 02:55 PM Viktor Gurov

successful connection

12deb411 11/03/2019 02:34 PM Viktor Gurov

more

0265d4f9 11/03/2019 01:45 PM Viktor Gurov

first steps

63fb68d7 11/01/2019 08:14 PM Jim Pingle

CRL management overhaul

  • Allow revoking by serial number or cert. Implements #9869
  • Allow revoking multiple entries at a time. Implements #3258
  • Declutter the main CRL list screen
  • Move the create control to the bottom under the list
  • Various other efficiency/style improvements
7daab3d8 10/31/2019 08:28 PM Jim Pingle

Add option to trust local CA entries. Implements #4068

Similar to closed PR #3558 from overhacked, but with a number of
changes.

e78fe74d 10/31/2019 08:04 PM Jim Pingle

Make value of cert notify setting consistent with others. Issue #7332

d1b23f75 10/31/2019 06:40 PM Jim Pingle

Remove duplicate DHCP log block.

3f0b7bc3 10/31/2019 05:10 PM Jim Pingle

Certificate strength improvements. Fixes #9825

  • Change default GUI cert lifetime to 825 days
  • Add notes on CA/Cert pages about using potentially insecure parameter
    chocies
  • Add visible warnings on CA/Cert pages if paramers are insecure/not
    recommended.
b5d2d8d8 10/30/2019 06:11 PM Jim Pingle

Add daily certificate expiration notice. Issue #7332