Commit graph

4069 commits

Author SHA1 Message Date
Ad Schellevis
028ee4c653 remove OpenSSL flavor from bug template (https://github.com/opnsense/src/pull/189) 2023-11-11 15:43:57 +01:00
macaddict89
db616c0f00
Update general.volt (#3665)
security\crowdsec: fixed typo
2023-11-11 09:23:50 +01:00
Ad Schellevis
47ccdcc078 net/wireguard - minor regression in addClient, not adding created uuid. closes https://github.com/opnsense/plugins/issues/3663 2023-11-10 18:46:37 +01:00
Franco Fichtner
07133a134a sysutils/api-backup: update endpoint after improvement 2023-11-09 09:25:58 +01:00
Franco Fichtner
2e42daed1c mail/postfix: move to newer postfix version 2023-11-09 07:33:19 +01:00
Franco Fichtner
8cab26f716 dns/bind: wrap new version 2023-11-07 19:54:33 +01:00
Franco Fichtner
77fa2dce42 net/wireguard: last one 2023-11-07 19:48:08 +01:00
Franco Fichtner
57639ea487 net/wireguard: not released yet 2023-11-07 19:44:37 +01:00
Ad Schellevis
7a7b5a5c9c net/wireguard - replace setconf with syncconf in service control for more fluent reloading. (https://github.com/opnsense/plugins/pull/3358) 2023-11-07 18:24:51 +01:00
Ad Schellevis
85e4a256df dns/ddclient - handle empty response (req.text) in dyndns2, for https://github.com/opnsense/plugins/pull/3618 2023-11-07 11:10:57 +01:00
Ad Schellevis
f6f72bb524 dns/ddclient - fix logic issue in 7c6fccdde0 (https://github.com/opnsense/plugins/pull/3618) 2023-11-07 09:22:06 +01:00
Franco Fichtner
9b0f5edf56 net-mgmt/nrpe: switch to supported version 2023-11-06 14:27:57 +01:00
doktornotor
8e57555345
[os-bind] #3650 - break-dnssec toggle needed for Enable filter-aaaa on IPv4/IPv6 clients (#3651)
If DNSSEC validation is disabled, filter-aaaa-on-v4 or filter-aaaa-on-v6 is set to break-dnssec
instead of yes, then AAAA records will be omitted even if they are signed.

See https://github.com/opnsense/plugins/issues/3650
2023-11-06 09:21:58 +01:00
Franco Fichtner
69bc636cd5 security/tor: add rexml; closes #3655 2023-11-06 09:14:28 +01:00
Franco Fichtner
3881ab12d7 README: sync 2023-11-06 09:11:13 +01:00
Franco Fichtner
a5f7a2773c security/openconnect: support more user name chars; closes #3428 2023-11-06 09:10:18 +01:00
Franco Fichtner
f1c56492b8 security/intrusion-detection-content-et-open: tweak description 2023-11-01 08:27:45 +01:00
Franco Fichtner
1d4122b5a1 misc/theme-cicada: bump revision 2023-11-01 08:27:08 +01:00
Franco Fichtner
82860aadeb net/wireguard: changelog 2023-11-01 08:25:11 +01:00
Franco Fichtner
ab9d902df8 net/wireguard: UX and wording 2023-11-01 08:21:44 +01:00
Franco Fichtner
06d0969eb2 net/wireguard: allow instance selection from peer 2023-11-01 08:21:18 +01:00
Franco Fichtner
9af41b126b net/wireguard: bump version 2023-10-31 22:43:08 +01:00
Franco Fichtner
af80514ad8 net/wireguard: use syncconf on newwanip event 2023-10-31 22:42:16 +01:00
Franco Fichtner
8ecf7830a6 security/intrusion-detection-content-et-open: fix revision 2023-10-31 22:41:14 +01:00
0nnyx
d1eb2185ad
Full ET open ruleset as open-extra (#3644)
* Full ET open ruleset as open-extra

Follow up on #3635 to have full ET open ruleset as plugin

* Update et-open-extra.xml
2023-10-31 10:43:25 +01:00
Ad Schellevis
806fb05c1c net/wireguard: Some improvements in carp event handing for https://github.com/opnsense/plugins/issues/3579
This commit addresses a couple of possible issues.

1. When a sequence of carp events is being processed and these processes lock eachother, its possible that collected interface state via legacy_interfaces_details() doesn't match the active one anymore. To prevent this from happening, only fetch the wireguard interface we're interested in inside the lock.

2. To limit the number of events being handled in wg-service-control.php it's likely cleaner to push the vhid as well when we're handling carp events. This means that we should switch between server id (current parameter) and vhid by looking at its format.

3. In case the target (wg) interface doesn't exist, make sure to create it. Although in practice this shouldn't happen (as the stat file is being removed on boot), dropping an interface manually should preferably lead to a funcitonal setup anyway (otherwise it will crash trying to pull it up)

4. When a vhid is passed and affects the interface in question, log relevant information to syslog.
2023-10-30 18:47:12 +01:00
René
354d4348aa
Update bootstrap-select.css (#3642) 2023-10-28 11:42:08 +02:00
Monviech
19eac172c8
wg - fix error when empty tunnel address in instance (#3638) 2023-10-26 13:49:02 +02:00
Ad Schellevis
186ec0713f net/wireguard - startup missing import (bug) 2023-10-25 14:55:28 +02:00
Ad Schellevis
ea20568272 security/intrusion-detection-content-et-open - deprecate version 4 rules (6 should be minimum now) 2023-10-25 09:27:34 +02:00
Franco Fichtner
e474d4b17b net/radsecproxy: style scrubbing 2023-10-24 12:37:57 +02:00
Franco Fichtner
5a912c4edb net/wireguard: make it a full version 2023-10-24 12:28:04 +02:00
Franco Fichtner
cb4cf0cf2d mail/rspamd: new version 2023-10-24 12:23:16 +02:00
Ad Schellevis
26d96b96c7
net/radsecproxy: cleanup service control. os-radsecproxy wasn't used, so we're removing it and hook the required settings in rc.conf.d. To make the grids a bit more usable, make sure to wrap a container arount it. Final change is to hook syslog properly and add a menu item for it. (#3628) 2023-10-23 17:02:45 +02:00
Franco Fichtner
3d4c6735ad net/upnp: fix a typo
PR: https://github.com/opnsense/lang/issues/64
2023-10-23 08:13:47 +02:00
Ad Schellevis
0558d48493 net/wireguard - import c2d07aeef6 and 4bef809bd0 from core 2023-10-20 17:57:51 +02:00
Franco Fichtner
7ff3c44957 net/mdns-repeater: note the recent docs change
2f1b56bc93

It would be nice to have a constraint for this, but it's
probably not worth the work in this case although the validation
should be stating this, not the help text and documentation.
2023-10-20 10:56:06 +02:00
Franco Fichtner
c45755f6dc net/firewall: hide menu hints from page search 2023-10-18 20:01:28 +02:00
Franco Fichtner
ea6550812a sysutils/api-backup: mark obsolete 2023-10-17 14:33:50 +02:00
Franco Fichtner
228d07711a www/nginx: ready for next release 2023-10-17 08:26:44 +02:00
Franco Fichtner
7992ad2f2b dns/ddclient: adjust accordingly 2023-10-17 08:24:42 +02:00
Franco Fichtner
f3695f92d4 net/wireguard: different approach to bootup handling 2023-10-17 08:21:13 +02:00
Franco Fichtner
b276276aeb misc/theme-cicada: apparently the other change was the only change...
... needed and the browser cache was playing tricks on me too.
2023-10-13 16:02:58 +02:00
Ad Schellevis
7c6fccdde0 dns/ddclient - accept response codes between 200 and 300, closes https://github.com/opnsense/plugins/pull/3618 2023-10-12 19:55:55 +02:00
Franco Fichtner
905214458f plugins: sorry, typo 2023-10-12 16:23:59 +02:00
Franco Fichtner
40785d2ec1 plugins: relax shebang requirement 2023-10-12 16:20:38 +02:00
Franco Fichtner
c9f3c7b792 misc/theme-cicada: fix faulty dropdown style 2023-10-12 08:27:26 +02:00
Franco Fichtner
2d900d4c4f Framework: allow license override 2023-10-10 14:09:42 +02:00
Franco Fichtner
fb14a0e04d www/nginx: bump 2023-10-10 13:57:39 +02:00
Franco Fichtner
863411646d mail/rspamd: bump 2023-10-10 13:56:48 +02:00