# 2.2.5 2.2.x maintenance release * Feature #935: User manager RADIUS authentication method * Bug #5238: CA certificates not removed from strongswan cacerts upon deletion * Bug #5241: rightca should be specified in ipsec.conf * Bug #3670: IPv6 DHCP-PD over PPPoE non functional + radvd core dump + solution * Bug #3858: DynDNS errno 47: Address family not supported by protocol family * Bug #4102: Could not find IPv4/IPv6 gateway for interface log spam * Bug #4147: IPsec - IPv4 Phase 1 using FQDN resolves to IPv6 IP * Bug #4227: Too much logging for IPSec DPD * Bug #4558: DHCP traffic getting blocked with DHCP Relay enabled * Bug #4568: mlppp settings lost after save on interface page * Bug #4685: Crash/panic "Sleeping thread owns a non-sleepable lock" * Bug #5111: /usr/bin/dc is missing * Bug #4746: captive portal allowed hostnames not loaded into table at boot time * Feature #4783: Add description as a display option on Traffic Graph * Bug #4825: Mobile client IPsec config omits peer identifier * Bug #4830: "Interface" selected in GUI for L2TP server are not respected in mpd's config * Feature #4863: Add support for Sierra MC7355 * Bug #4874: pf crash related to source tracking: pf_hashsrc: unknown address family 0 * Bug #4878: DHCP pools can be out of range causing DHCP server to exit * Bug #4879: Multiple notices cannot be filed in the same second * Bug #4884: Pkg install additional files can fail but instllation does not abort * Bug #4888: URL Port alias causes error loading rules in 2.2.4 * Bug #4902: XMLRPC Sync version check ineffective in some cases * Bug #4903: Captive Portal ipfw rules are not correctly including interface CARP VIPs * Bug #4904: Captive Portal databases are not upgraded from sqlite 2.x to sqlite 3.x, must be removed post-upgrade * Bug #4906: killing of individual IPv6 states on diag_dump_states.php doesn't work * Bug #4907: diag_dump_states.php individual state kill assumes left IP as source IP * Todo #4908: binding of destination interface of dhcrelay no longer necessary * Bug #4918: DH groups 22-24 do not function * Bug #4925: version_compare_numeric does not work for 2.2.9 to 2.2.10 * Bug #4931: dhcpleases misses some DHCP lease changes * Bug #4935: WAN 6rd without border relay IP creates invalid ruleset * Bug #4985: Improper handling of "too short" voucher codes (1-2 chars) * Bug #4986: Selecting an IP Alias VIP for Test Port does not function * Bug #4990: Dynamic DNS Not Working With GW Group Using CARP VIP * Bug #4994: lighttpd broken on latest 2.2.5 snapshot * Bug #5046: dhcpd only checks arch 00:07 for UEFI network booting * Bug #5113: Captive portal voucher expiration issue * Bug #5129: OpenVPN - incorrect netmask sent to client with static IP set in RADIUS * Bug #5149: memory leak(s) in strongswan * Bug #5152: Assigning a group with SSH privileges to a user does not properly enable SSH when the account is created * Bug #5156: outbound NAT translation port should allow port ranges * Bug #5162: Renaming an alias to an existing name is not prevented by input validation * Todo #5177: Bugs with available PR fixes that needed review and merge before 2.2.5 * Bug #5196: Incorrect text about DNS servers on services_dhcp.php * Bug #5199: Default value fix for package fields is not working properly * Bug #5200: Invalid DHCP Pool notice is a tad too aggressive * Bug #5201: Stored XSS on authentication services * Bug #5203: Directory transversal in Configuration History * Bug #5207: Hybrid RSA + xauth doesn't appear to configure strongswan correctly for hybrid auth * Bug #5210: Package logging entries are not being removed from syslog.conf on package uninstall * Bug #5211: Auto-added IPsec rules overmatch in some circumstances * Bug #5214: Dynamic DNS not updated upon enable/disable of a gateway * Bug #5242: IPsec debug log settings not applied after stop/start or restart * Bug #5243: only CAs specified in a P1 should be written out to cacerts * Bug #5245: iOS IPsec PSK mismatches * Bug #5246: vpn_ipsec_keys.php "any" not specified as %any as described * Todo #5254: TZdata update to 2015f * Feature #5284: Add IPv6 to Virtual Address Pool options for Mobile IPsec with IKEv2 * Bug #5294: System users and groups not fully protected from deletion * Bug #5297: ppp-linkdown and ppp-linkup do not handle SLAAC, DHCP6 and DHCP-PD correctly * Bug #5298: gitsync screws /tmp permissions * Todo #5304: include all logs in status output * Feature #5305: IPv4 and IPv6 can co-exist on P2s when using IKEv2 * Bug #5313: Intermediate internal CA's are created without a reference to the signing internal CA * Bug #5320: IPSec NAT rules are not removed when a tunnel is disabled * Bug #5323: My Certificate Authority is displayed/saved for authentication methods where it is not needed * Bug #5327: generation of split tunnel attribute in strongswan charon.plugins.attr breaks iOS IKEv2 clients * Bug #5334: unbound root.key file corruption can prevent unbound from starting * Bug #5340: IPsec logging - silent can't be configured, issues with defaults * Bug #5342: Cannot change outbound NAT modes when using non-English translation * Bug #5343: Cannot upload or download from exec.php when in non-English language * Bug #5345: IPv6 captive portal allowed hostnames added as /32s * Bug #5353: Add leftsendcert=always to ipsec.conf for mobile profiles using IKEv2 and EAP to better accommodate iOS 9/OS X 10.11