2015-02-26 21:07:11 +01:00
|
|
|
#
|
|
|
|
# spec file for package ocserv
|
|
|
|
#
|
2020-07-03 13:12:30 +02:00
|
|
|
# Copyright (c) 2020 SUSE LLC
|
2015-02-26 21:07:11 +01:00
|
|
|
#
|
|
|
|
# All modifications and additions to the file contributed by third parties
|
|
|
|
# remain the property of their copyright owners, unless otherwise agreed
|
|
|
|
# upon. The license for this file, and modifications and additions to the
|
|
|
|
# file, is the same license as for the pristine package itself (unless the
|
|
|
|
# license for the pristine package is not an Open Source License, in which
|
|
|
|
# case the license is the MIT License). An "Open Source License" is a
|
|
|
|
# license that conforms to the Open Source Definition (Version 1.9)
|
|
|
|
# published by the Open Source Initiative.
|
|
|
|
|
2020-01-21 14:52:29 +01:00
|
|
|
# Please submit bugfixes or comments via https://bugs.opensuse.org/
|
2015-02-26 21:07:11 +01:00
|
|
|
#
|
|
|
|
|
2016-12-21 16:24:26 +01:00
|
|
|
|
2015-02-26 21:07:11 +01:00
|
|
|
Name: ocserv
|
2020-07-03 20:01:09 +02:00
|
|
|
Version: 1.1.0
|
2016-12-21 16:24:26 +01:00
|
|
|
Release: 0
|
|
|
|
Summary: OpenConnect VPN Server
|
2018-05-13 03:22:59 +02:00
|
|
|
License: GPL-2.0-only
|
2016-12-21 16:24:26 +01:00
|
|
|
Group: Productivity/Networking/Security
|
2020-01-21 14:52:29 +01:00
|
|
|
URL: http://www.infradead.org/ocserv
|
2020-07-03 13:12:30 +02:00
|
|
|
Source: ftp://ftp.infradead.org/pub/ocserv/%{name}-%{version}.tar.xz
|
2020-07-03 20:01:09 +02:00
|
|
|
Source1: ftp://ftp.infradead.org/pub/ocserv/%{name}-%{version}.tar.xz.sig
|
|
|
|
Source2: ca.tmpl
|
|
|
|
Source3: server.tmpl
|
|
|
|
Source4: user.tmpl
|
2016-12-21 16:24:26 +01:00
|
|
|
Source5: ocserv.sysctl
|
2018-02-27 04:21:12 +01:00
|
|
|
Source6: ocserv.firewalld.xml
|
2016-12-21 16:24:26 +01:00
|
|
|
Source99: README.SUSE
|
2020-07-03 20:01:09 +02:00
|
|
|
Source100: gpgkey-1F42418905D8206AA754CCDC29EE58B996865171.gpg
|
2015-02-26 21:07:11 +01:00
|
|
|
#PATCH-FIX-UPSTREAM marguerite@opensuse.org $LIBSYSTEMD_DAEMON env is not set on openSUSE
|
2016-12-21 16:24:26 +01:00
|
|
|
Patch1: %{name}-enable-systemd.patch
|
2015-02-26 21:07:11 +01:00
|
|
|
#PATCH-FIX-UPSTREAM marguerite@opensuse.org tweak configuration
|
2016-12-21 16:24:26 +01:00
|
|
|
Patch2: %{name}.config.patch
|
2018-02-26 03:10:00 +01:00
|
|
|
#PATCH-FIX-OPENSUSE marguerite@opensuse.org leap doesn't have LZ4_compress_default
|
|
|
|
Patch3: %{name}-LZ4_compress_default.patch
|
2016-12-21 16:24:26 +01:00
|
|
|
BuildRequires: autogen
|
|
|
|
BuildRequires: dbus-1-devel
|
2018-02-27 14:30:18 +01:00
|
|
|
%if 0%{suse_version} >= 1500
|
2018-02-27 04:21:12 +01:00
|
|
|
BuildRequires: firewall-macros
|
|
|
|
%endif
|
2016-12-21 16:24:26 +01:00
|
|
|
BuildRequires: freeradius-client-devel
|
|
|
|
BuildRequires: gperf
|
2020-07-03 20:01:09 +02:00
|
|
|
BuildRequires: gpg2
|
2016-12-21 16:24:26 +01:00
|
|
|
BuildRequires: libev-devel
|
|
|
|
BuildRequires: libgnutls-devel >= 3.1.10
|
2020-07-03 13:12:30 +02:00
|
|
|
BuildRequires: libmaxminddb-devel
|
2016-12-21 16:24:26 +01:00
|
|
|
BuildRequires: libnl3-devel
|
|
|
|
BuildRequires: libprotobuf-c-devel
|
|
|
|
BuildRequires: libseccomp-devel
|
|
|
|
BuildRequires: libtalloc-devel
|
|
|
|
BuildRequires: libtool
|
|
|
|
BuildRequires: pam-devel
|
|
|
|
BuildRequires: pkgconfig
|
|
|
|
BuildRequires: protobuf-c
|
2017-05-29 14:02:01 +02:00
|
|
|
BuildRequires: readline-devel
|
2020-07-03 13:12:30 +02:00
|
|
|
BuildRequires: pkgconfig(liboath)
|
2020-01-21 14:52:29 +01:00
|
|
|
BuildRequires: pkgconfig(libsystemd)
|
2019-01-25 17:12:44 +01:00
|
|
|
BuildRequires: rubygem(ronn)
|
2015-02-26 21:07:11 +01:00
|
|
|
# /usr/bin/certtool for generating certificates
|
2016-12-21 16:24:26 +01:00
|
|
|
Requires: gnutls >= 3.1.10
|
2015-02-26 21:07:11 +01:00
|
|
|
BuildRoot: %{_tmppath}/%{name}-%{version}-build
|
|
|
|
%{?systemd_requires}
|
2016-12-21 16:24:26 +01:00
|
|
|
%if 0%{?suse_version} > 1310
|
|
|
|
BuildRequires: liblz4-devel
|
|
|
|
%endif
|
2015-02-26 21:07:11 +01:00
|
|
|
|
|
|
|
%description
|
2016-12-21 16:24:26 +01:00
|
|
|
OpenConnect server (ocserv) is an SSL VPN server. Its purpose is to
|
2015-02-26 21:07:11 +01:00
|
|
|
be a secure, small, fast and configurable VPN server. It implements
|
|
|
|
the OpenConnect SSL VPN protocol, and has also (currently experimental)
|
2016-12-21 16:24:26 +01:00
|
|
|
compatibility with clients using the AnyConnect SSL VPN protocol.
|
|
|
|
The OpenConnect protocol provides a dual TCP/UDP VPN channel, and
|
2015-02-26 21:07:11 +01:00
|
|
|
uses the standard IETF security protocols to secure it. The server
|
2016-12-21 16:24:26 +01:00
|
|
|
is implemented primarily for the GNU/Linux platform but its code
|
2015-02-26 21:07:11 +01:00
|
|
|
is designed to be portable to other UNIX variants as well.
|
|
|
|
|
|
|
|
Ocserv's main features are security through privilege separation
|
|
|
|
and sandboxing, accounting, and resilience due to a combined use
|
2016-12-21 16:24:26 +01:00
|
|
|
of TCP and UDP. Authentication occurs in an isolated security
|
2015-02-26 21:07:11 +01:00
|
|
|
module process, and each user is assigned an unprivileged worker
|
|
|
|
process, and a networking (tun) device. That not only eases the
|
2016-12-21 16:24:26 +01:00
|
|
|
control of the resources of each user or group of users, but also
|
2015-02-26 21:07:11 +01:00
|
|
|
prevents data leak (e.g., heartbleed-style attacks), and privilege
|
|
|
|
escalation due to any bug on the VPN handling (worker) process.
|
2016-12-21 16:24:26 +01:00
|
|
|
A management interface allows for viewing and querying logged-in users.
|
2015-02-26 21:07:11 +01:00
|
|
|
|
|
|
|
%prep
|
2020-07-03 20:10:14 +02:00
|
|
|
gpg --import %{SOURCE100} && gpg --verify %{SOURCE1}
|
2015-06-28 07:23:02 +02:00
|
|
|
%setup -q
|
2015-02-26 21:07:11 +01:00
|
|
|
%patch1 -p1
|
|
|
|
%patch2 -p1
|
2017-01-23 17:50:28 +01:00
|
|
|
%patch3 -p1
|
2015-02-26 21:07:11 +01:00
|
|
|
autoreconf -fiv
|
|
|
|
|
|
|
|
%build
|
|
|
|
%configure --enable-systemd \
|
|
|
|
--enable-seccomp \
|
|
|
|
--disable-rpath \
|
|
|
|
--enable-local-libopts \
|
2016-12-21 16:24:26 +01:00
|
|
|
--enable-libopts-install
|
2016-02-25 15:38:11 +01:00
|
|
|
make V=1 %{?_smp_mflags}
|
2015-02-26 21:07:11 +01:00
|
|
|
|
|
|
|
%install
|
2016-12-21 16:24:26 +01:00
|
|
|
make %{?_smp_mflags} DESTDIR=%{buildroot} install
|
2015-02-26 21:07:11 +01:00
|
|
|
|
2016-02-25 15:38:11 +01:00
|
|
|
install -Dm 0644 %{SOURCE5} %{buildroot}%{_sysconfdir}/sysctl.d/60-ocserv.conf
|
2018-02-27 14:30:18 +01:00
|
|
|
%if 0%{suse_version} >= 1500
|
2018-02-27 04:21:12 +01:00
|
|
|
install -D -m 644 %{SOURCE6} %{buildroot}%{_libexecdir}/firewalld/services/ocserv.xml
|
|
|
|
%endif
|
2016-02-25 15:38:11 +01:00
|
|
|
|
2015-02-26 21:07:11 +01:00
|
|
|
install -d %{buildroot}%{_sysconfdir}/ocserv/certificates
|
|
|
|
install -m 0644 %{SOURCE2} %{buildroot}%{_sysconfdir}/ocserv/certificates
|
|
|
|
install -m 0644 %{SOURCE3} %{buildroot}%{_sysconfdir}/ocserv/certificates
|
2020-07-03 20:01:09 +02:00
|
|
|
install -m 0644 %{SOURCE4} %{buildroot}%{_sysconfdir}/ocserv/certificates
|
2015-02-26 21:07:11 +01:00
|
|
|
install -m 0644 %{SOURCE99} %{buildroot}%{_sysconfdir}/ocserv/
|
|
|
|
install -m 0644 doc/sample.config %{buildroot}%{_sysconfdir}/ocserv/ocserv.conf
|
|
|
|
install -m 0644 doc/sample.passwd %{buildroot}%{_sysconfdir}/ocserv/ocpasswd
|
|
|
|
install -m 0755 doc/scripts/ocserv-script %{buildroot}%{_bindir}
|
|
|
|
|
|
|
|
install -d %{buildroot}%{_unitdir}
|
|
|
|
# if --with-dubs, here should be "standalone"
|
|
|
|
install -m 0644 doc/systemd/socket-activated/ocserv.socket %{buildroot}%{_unitdir}
|
|
|
|
install -m 0644 doc/systemd/socket-activated/ocserv.service %{buildroot}%{_unitdir}
|
|
|
|
|
|
|
|
%pre
|
|
|
|
%service_add_pre ocserv.service ocserv.socket
|
|
|
|
|
|
|
|
%post
|
|
|
|
%service_add_post ocserv.service ocserv.socket
|
2018-02-27 14:30:18 +01:00
|
|
|
%if 0%{suse_version} >= 1500
|
2018-02-27 04:21:12 +01:00
|
|
|
%firewalld_reload
|
|
|
|
%endif
|
2015-02-26 21:07:11 +01:00
|
|
|
|
|
|
|
%preun
|
|
|
|
%service_del_preun ocserv.service ocserv.socket
|
|
|
|
|
|
|
|
%postun
|
|
|
|
%service_del_postun ocserv.service ocserv.socket
|
|
|
|
|
|
|
|
%files
|
|
|
|
%defattr(-,root,root)
|
2019-01-25 17:12:44 +01:00
|
|
|
%doc AUTHORS NEWS README.md TODO
|
|
|
|
%license COPYING LICENSE
|
2015-02-26 21:07:11 +01:00
|
|
|
%config %{_sysconfdir}/ocserv
|
2016-02-25 15:38:11 +01:00
|
|
|
%config(noreplace) %{_sysconfdir}/sysctl.d/60-ocserv.conf
|
2018-02-27 14:30:18 +01:00
|
|
|
%if 0%{suse_version} >= 1500
|
2018-02-27 04:21:12 +01:00
|
|
|
%dir %{_libexecdir}/firewalld
|
|
|
|
%dir %{_libexecdir}/firewalld/services
|
|
|
|
%{_libexecdir}/firewalld/services/ocserv.xml
|
|
|
|
%endif
|
2015-02-26 21:07:11 +01:00
|
|
|
%{_bindir}/occtl
|
|
|
|
%{_bindir}/ocpasswd
|
|
|
|
%{_bindir}/ocserv-script
|
2016-01-08 01:14:52 +01:00
|
|
|
%{_bindir}/ocserv-fw
|
2015-02-26 21:07:11 +01:00
|
|
|
%{_sbindir}/ocserv
|
2020-07-03 20:01:09 +02:00
|
|
|
%{_sbindir}/ocserv-worker
|
2015-02-26 21:07:11 +01:00
|
|
|
%{_unitdir}/ocserv.service
|
|
|
|
%{_unitdir}/ocserv.socket
|
2016-12-21 16:24:26 +01:00
|
|
|
%{_mandir}/man8/occtl.8%{ext_man}
|
|
|
|
%{_mandir}/man8/ocpasswd.8%{ext_man}
|
|
|
|
%{_mandir}/man8/ocserv.8%{ext_man}
|
2015-02-26 21:07:11 +01:00
|
|
|
|
2016-02-25 15:38:11 +01:00
|
|
|
%changelog
|