Commit graph

469 commits

Author SHA1 Message Date
Frank Wall
f3d517cc65 security/acme-client: add support for Hetzner DNS API, closes #1870 2020-06-08 14:43:25 +02:00
Frank Wall
0dbff80fef security/acme-client: restore alnum sorting in DNS API list 2020-06-08 14:37:20 +02:00
Frank Wall
a15bf04c20 security/acme-client: add support for ArvanCloud, closes #1834 2020-06-08 14:34:28 +02:00
Frank Wall
734642abea security/acme-client: bump version 2020-06-08 14:28:01 +02:00
chris42
543209b661 Order by name not tag 2020-06-07 13:58:45 +02:00
chris42
5988514f08 Add core-networks API option 2020-06-07 13:30:28 +02:00
Frank Wall
e1c15a1b20 security/acme-client: bump version 2020-05-28 15:24:15 +02:00
Frank Wall
2dfe7674d5 security/acme-client: move optional field to the bottom, refs #1851 2020-05-28 15:23:59 +02:00
Bill Gertz
c46695c030
security/acme-client: Add NSUPDATE_ZONE support to nsupdate DNS-01 Service (#1851)
Add NSUPDATE_ZONE nsupdate support 

Adds new validation.dns_nsudate_zone field to implement support for NSUPDATE_ZONE. See https://github.com/acmesh-official/acme.sh/pull/1963 for more information.
2020-05-28 15:21:08 +02:00
Ad Schellevis
72980508a7 security/stunnel prepare release version 2020-05-26 21:02:37 +02:00
Ad Schellevis
1f7654103d stunnel: new revision 2020-05-20 06:13:59 +02:00
Ad Schellevis
e845256b1a stunnel: minor bug fixes
- used wrong pid for ident status
- reload syslog on service start
- missing condition in syslog template (hence the service reload)

for https://github.com/opnsense/plugins/issues/1829
2020-05-20 06:11:29 +02:00
Ad Schellevis
84585d959b stunnel: minor cleanups and versioning, closes https://github.com/opnsense/plugins/issues/1829 2020-05-20 00:57:15 +02:00
Ad Schellevis
9510a17266 whitespace 2020-05-20 00:34:04 +02:00
Ad Schellevis
3d4416cf26
Stunnel: add identd (#1845)
stunnel: add identd service and plumbing
2020-05-22 13:12:28 +02:00
Franco Fichtner
aa8ff3e508 security/acme-client: also bump revision 2020-05-22 09:18:24 +02:00
Franco Fichtner
ee799d8c75 security/acme-client: fix #1844 2020-05-22 09:17:42 +02:00
Franco Fichtner
5c004cae08 security/tinc: bump revision after changes 2020-05-19 08:55:21 +02:00
Franco Fichtner
7f90141b60 security/stunnel: style and sync 2020-05-18 16:40:47 +02:00
Ad Schellevis
2a8b0a58ed
stunnel: initial release (#1840)
* stunnel: boilerplate for https://github.com/opnsense/plugins/issues/1829

* stunnel: work in progress for https://github.com/opnsense/plugins/issues/1829

* stunnel: add service control and acl for https://github.com/opnsense/plugins/issues/1829

* stunnel: add cipher selection for https://github.com/opnsense/plugins/issues/1829

Since stunnel uses different parameter pairs for TLSv1.[1,2] and TLSv1.3, we'll try to sort them out in our config template.
When no TLSv1.3 ciphers are allowed, we should limit the sslVersionMax parameter as well as it seems.

* stunnel: set TLS1.2 as minimum

* stunnel: disable rc conf when no services are active https://github.com/opnsense/plugins/issues/1829

* stunnel: CRL support for https://github.com/opnsense/plugins/issues/1829

* stunnel: simplify cert creation, combine cert+key in one file. for https://github.com/opnsense/plugins/issues/1829

* stunnel: syslog and log viewer for https://github.com/opnsense/plugins/issues/1829

* stunnel: add hasync anchor, for https://github.com/opnsense/plugins/issues/1829
2020-05-18 15:31:18 +02:00
Frank Wall
8611398aaa security/acme-client: bump version 2020-05-18 09:50:05 +02:00
Frank Wall
cf1828bc02 post merge fixes for #1838 2020-05-18 09:49:50 +02:00
Maarten den Braber
6628f93fc1 Tabs to spaces 2020-05-16 23:39:28 +02:00
Maarten den Braber
ce5c6be647 Fix formatting issue 2020-05-16 23:38:14 +02:00
Maarten den Braber
4c79d89c8f Add Acmeproxy DNS provider dialogs 2020-05-16 23:36:37 +02:00
0c67e9db29
snort-vrt: Update rulesfile (#1835)
Update rulesfile.
2990 does not exist anymore.
29151 works best with suricata 4.1.8 and 5.0.3
2020-05-15 11:19:53 +02:00
Franco Fichtner
c6de3851f5 plugins: style sweep 2020-05-13 08:42:51 +02:00
Ad Schellevis
faa23ffae9 Syslog-NG: add templates for https://github.com/opnsense/core/issues/4068 2020-05-12 13:55:27 +02:00
vnxme
f2db771984
security/tinc: Fix switch mode (#1733)
* security/tinc: Allow empty subnet for switch mode

A Host class with empty self._payload['subnet'] is considered invalid (lines 38-39). Thus, we can remove self._payload['subnet'] = None from __init__() and add a check for existance to config_text().

* security/tinc: Allow empty subnet for switch mode

Set network.subnet.required and host.subnet.required to N, add a required constraint for network.subnet if network.mode is router.

* security/tinc: Trigger configctl on tinc-up

In order to support various dual-stack configs (primary IPv4/v6 assigned by VPN/Tinc and any combination of alias IPv4/v6 assigned by Firewall/VIP) we need to trigger configctl:
- Primary IPv4: /usr/local/opnsense/service/configd_ctl.py interface newip $interface
- Primary IPv6: /usr/local/opnsense/service/configd_ctl.py interface newipv6 $interface

* security/tinc: Destroy tun/tap interface on stop

Destroying tun/tap interface each time Tinc daemon stops/restarts resolves the issue of losing IPv6 network routes (see #3972).

* security/Tinc: Add a missing reference constraint

The network.mode field is now linked to the network.subnet field.

* security/Tinc: Refactor tincd.py
2020-05-12 12:49:01 +02:00
prunkster
65abab88da security/acme-client: add support for dnsapi "Euserv.eu"
- added option "--insecure"
- increased maximum dns sleep time
2020-04-16 23:10:48 +02:00
Frank Wall
0b835f2510 securiy/acme-client: bump version 2020-04-14 22:34:55 +02:00
Frank Wall
83ae82d929 securiy/acme-client: add support for Leaseweb, closes #1670 2020-04-14 22:28:34 +02:00
Frank Wall
b539d1ff75 securiy/acme-client: add support for EUserv, closes #1779 2020-04-14 22:20:46 +02:00
Frank Wall
edf3633b94 securiy/acme-client: add support for SchlundTech, closes #1728 2020-04-14 22:08:42 +02:00
Jürgen Kellerer
362edb68ad security/acme-client: Added fullchain.pem filename-template to model & dialog 2020-04-11 17:36:09 +02:00
Michael
08c86edd9d
security/maltrail: disable alienvault, update changelog (#1769) 2020-04-06 18:16:17 +02:00
Jürgen Kellerer
1a06985c08 Applied USER_WHITELIST config syntax change
Fixes the whitelist config feature in maltrail sensor.
USER_WHITELIST was changed from comma separated list to whitelist file in recent maltrail versions.
2020-04-06 14:18:00 +02:00
Frank Wall
f1042b463b security/acme-client: bump bersion 2020-03-30 13:00:29 +02:00
Frank Wall
05a4ff8a0c security/acme-client: style fixes, refs #1753 2020-03-30 13:00:00 +02:00
Bjorn Peeters
5e760e1696
letsencrypt/upload_sftp
add export of fullchain.pem
2020-03-28 12:54:40 +01:00
Franco Fichtner
15b5864828 security/acme-client: bump revision for minor release 2020-03-18 08:04:24 +01:00
Kyle
4e1c83bf8f Update Github Link to Reflect Repo rename
Updated Github Web Link to Reflect Github Repository rebrand/rename from: https://github.com/Neilpang/acme.sh to https://github.com/acmesh-official/acme.sh
2020-03-18 06:58:51 +01:00
Franco Fichtner
c58730761d security/tinc: latest change warrants a version bump 2020-03-04 09:34:37 +01:00
Michael
58c43a9802
security/maltrail: switch python version (#1727) 2020-03-03 13:40:00 +01:00
vnxme
5d448639ed
security/tinc: fix a bug in IPv6 support (#1707)
closes https://github.com/opnsense/plugins/issues/1686.
2020-02-20 18:26:09 +01:00
Franco Fichtner
18bc32f3b3 plugins: serious style sweep 2020-02-13 10:42:37 +01:00
Franco Fichtner
d19b35a9d8 plugins: fix shebang foo reported by new lint check 2020-02-12 16:19:34 +01:00
Franco Fichtner
f1a69249f9 plugins: style sweep 2020-02-10 21:12:05 +01:00
Frank Wall
9e45c51384 security/acme-client: use ::1 for safekeeping, refs #1638 2019-12-30 15:29:55 +01:00
Frank Wall
11932d2967
Merge pull request #1638 from fraenki/acme_129
security/acme-client: release 1.29
2019-12-30 15:17:27 +01:00