SHA256
1
0
forked from pool/openvpn
Commit Graph

215 Commits

Author SHA256 Message Date
Dominique Leuenberger
02b1e24f46 Accepting request 400152 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/400152
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=69
2016-06-07 21:48:41 +00:00
Ismail Dönmez
6dac5a8f6a Accepting request 394676 from home:namtrac:branches:network:vpn
- Update to version 2.3.11
  * Fixed port-share bug with DoS potential
  * Fix buffer overflow by user supplied data
  * Fix undefined signed shift overflow
  * Ensure input read using systemd-ask-password is null terminated
  * Support reading the challenge-response from console
  * hardening: add safe FD_SET() wrapper openvpn_fd_set()
  * Restrict default TLS cipher list
- Add BuildRequires on xz for SLE11

OBS-URL: https://build.opensuse.org/request/show/394676
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=105
2016-06-06 07:52:26 +00:00
Dominique Leuenberger
8e0c189a4f Accepting request 352204 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/352204
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=68
2016-01-06 23:25:14 +00:00
Martin Caj
06ccbd25ce Accepting request 351949 from home:namtrac:branches:network:vpn
- Update to version 2.3.10
  * Warn user if their certificate has expired
  * Fix regression in setups without a client certificate

- Update to version 2.3.9
  * Show extra-certs in current parameters.
  * Do not set the buffer size by default but rely on the operation system default.
  * Remove --enable-password-save option
  * Detect config lines that are too long and give a warning/error
  * Log serial number of revoked certificate
  * Avoid partial authentication state when using --disabled in CCD configs
  * Replace unaligned 16bit access to TCP MSS value with bytewise access
  * Fix possible heap overflow on read accessing getaddrinfo() result.
  * Fix isatty() check for good. (obsoletes revert-daemonize.patch)
  * Client-side part for server restart notification
  * Fix privilege drop if first connection attempt fails
  * Support for username-only auth file.
  * Increase control channel packet size for faster handshakes
  * hardening: add insurance to exit on a failed ASSERT()
  * Fix memory leak in auth-pam plugin
  * Fix (potential) memory leak in init_route_list()
  * Fix unintialized variable in plugin_vlog()
  * Add macro to ensure we exit on fatal errors
  * Fix memory leak in add_option() by simplifying get_ipv6_addr
  * openssl: properly check return value of RAND_bytes()
  * Fix rand_bytes return value checking
  * Fix "White space before end tags can break the config parser"

OBS-URL: https://build.opensuse.org/request/show/351949
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=103
2016-01-06 09:47:33 +00:00
Dominique Leuenberger
c5f68dab84 Accepting request 348337 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/348337
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=67
2015-12-20 09:52:41 +00:00
39b88922eb - Adjust /var/run to _rundir macro value in openvpn@.service too.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=101
2015-12-04 08:02:06 +00:00
Stephan Kulow
87d673d2fc Accepting request 324534 from network:vpn
- Removed obsolete --with-lzo-headers option, readded LFS_CFLAGS.
- Moved openvpn-plugin.h into a devel package, removed .gitignore

OBS-URL: https://build.opensuse.org/request/show/324534
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=66
2015-08-23 13:43:34 +00:00
e18eab1a94 - Moved openvpn-plugin.h into a devel package, removed .gitignore
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=99
2015-08-20 09:46:01 +00:00
558e8eaf2f - Removed obsolete --with-lzo-headers option, readded LFS_CFLAGS.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=98
2015-08-20 09:00:14 +00:00
Dominique Leuenberger
baed75c436 Accepting request 322617 from network:vpn
Add revert-daemonize.patch, looks like under systemd the stdin
and stdout are not TTYs by default. This reverts to previous
behaviour fixing bsc#941569

OBS-URL: https://build.opensuse.org/request/show/322617
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=65
2015-08-17 13:35:10 +00:00
f7cfc57d16 Accepting request 322300 from home:namtrac:branches:network:vpn
OBS-URL: https://build.opensuse.org/request/show/322300
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=96
2015-08-13 09:20:17 +00:00
Dominique Leuenberger
8aa0a854ad Accepting request 321625 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/321625
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=64
2015-08-11 06:27:04 +00:00
064dd8062e Accepting request 320680 from home:namtrac:branches:network:vpn
- Update to version 2.3.8
  * Report missing endtags of inline files as warnings
  * Fix commit e473b7c if an inline file happens to have a
    line break exactly at buffer limit
  * Produce a meaningful error message if --daemon gets in the way of
    asking for passwords.
  * Document --daemon changes and consequences (--askpass, --auth-nocache)
  * Del ipv6 addr on close of linux tun interface
  * Fix --askpass not allowing for password input via stdin
  * Write pid file immediately after daemonizing
  * Fix regression: query password before becoming daemon
  * Fix using management interface to get passwords
  * Fix overflow check in openvpn_decrypt()

OBS-URL: https://build.opensuse.org/request/show/320680
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=94
2015-08-10 13:43:50 +00:00
Dominique Leuenberger
e5659743e0 Accepting request 313672 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/313672
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=63
2015-06-30 08:16:16 +00:00
3d06f17727 Accepting request 313671 from home:namtrac:bugfix
- Update to version 2.3.7
  * down-root plugin: Replaced system() calls with execve()
  * sockets: Remove the limitation of --tcp-nodelay to be server-only
  * pkcs11: Load p11-kit-proxy.so module by default
  * New approach to handle peer-id related changes to link-mtu
  * Fix incorrect use of get_ipv6_addr() for iroute options
  * Print helpful error message on --mktun/--rmtun if not available
  * Explain effect of --topology subnet on --ifconfig
  * Add note about file permissions and --crl-verify to manpage
  * Repair --dev null breakage caused by db950be85d37
  * Correct note about DNS randomization in openvpn.8
  * Disallow usage of --server-poll-timeout in --secret key mode
  * Slightly enhance documentation about --cipher
  * On signal reception, return EAI_SYSTEM from openvpn_getaddrinfo()
  * Use EAI_AGAIN instead of EAI_SYSTEM for openvpn_getaddrinfo()
  * Fix --redirect-private in --dev tap mode
  * Updated manpage for --rport and --lport
  * Properly escape dashes on the man-page
  * Improve documentation in --script-security section of the man-page
  * Really fix '--cipher none' regression
  * Set tls-version-max to 1.1 if cryptoapicert is used
  * Account for peer-id in frame size calculation
  * Disable SSL compression
  * Fix frame size calculation for non-CBC modes.
  * Allow for CN/username of 64 characters (fixes off-by-one)
  * Re-enable TLS version negotiation by default
  * Remove size limit for files inlined in config
  * Improve --tls-cipher and --show-tls man page description
  * Re-read auth-user-pass file on (re)connect if required
  * Clarify --capath option in manpage

OBS-URL: https://build.opensuse.org/request/show/313671
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=92
2015-06-25 11:58:40 +00:00
Dominique Leuenberger
1f1d0bdc05 Accepting request 290007 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/290007
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=62
2015-03-11 08:57:59 +00:00
515f549344 adjust plugin dir plageholders in man page
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=90
2015-03-02 10:06:37 +00:00
c4621b5e67 - Fixed to provide actual plugin/doc dirs in openvpn(8) man page.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=89
2015-03-02 09:45:03 +00:00
6a9f5d263c - Fixed to use correct sha digest data length and in fips mode,
use aes instead of the disallowed blowfish crypto (boo#914166).

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=88
2015-03-02 08:27:36 +00:00
Dominique Leuenberger
2168217c89 Accepting request 287767 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/287767
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=61
2015-02-27 09:59:47 +00:00
fbf787a918 fixed previous fix
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=86
2015-02-18 17:21:27 +00:00
b4dab5a27f - Fixed to use correct sha digest data length (boo#914166)
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=85
2015-02-10 15:35:33 +00:00
Dominique Leuenberger
55d0e961ac Accepting request 263672 from network:vpn
- Update to version 2.3.6 fixing a denial-of-service vulnerability
  where an authenticated client could stop the server by triggering
  a server-side ASSERT (bnc#907764,CVE-2014-8104).
  See ChangeLog file for a complete list of changes.

OBS-URL: https://build.opensuse.org/request/show/263672
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=60
2014-12-03 21:47:57 +00:00
5a65bc9e84 - Update to version 2.3.6 fixing a denial-of-service vulnerability
where an authenticated client could stop the server by triggering
  a server-side ASSERT (bnc#907764,CVE-2014-8104).
  See ChangeLog file for a complete list of changes.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=83
2014-12-01 19:43:09 +00:00
Stephan Kulow
bcc937982f Accepting request 260087 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/260087
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=59
2014-11-07 08:06:08 +00:00
Tomáš Chvátal
e52c73c2cc Accepting request 259041 from home:namtrac:branches:network:vpn
- Update to version 2.3.5
  * See included changelog
- Depend on systemd-devel for the daemon check functionality

OBS-URL: https://build.opensuse.org/request/show/259041
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=81
2014-11-06 15:05:03 +00:00
Stephan Kulow
2ea1e59ee7 Accepting request 246648 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/246648
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=57
2014-08-28 19:05:32 +00:00
Martin Caj
e3db630d65 Accepting request 246644 from home:namtrac:branches:network:vpn
- Update to version 2.3.4
  * Add support for client-cert-not-required for PolarSSL.
  * Introduce safety check for http proxy options.

OBS-URL: https://build.opensuse.org/request/show/246644
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=79
2014-08-27 13:08:10 +00:00
Stephan Kulow
865a761652 Accepting request 236695 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/236695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=56
2014-06-10 12:39:19 +00:00
5eff630ee5 Accepting request 235421 from home:elvigia:branches:network:vpn
- Build with large file support in 32 bit systems.

OBS-URL: https://build.opensuse.org/request/show/235421
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=77
2014-06-10 02:55:45 +00:00
Stephan Kulow
e07cf250ae Accepting request 234694 from network:vpn
- use %_rundir for %ghost directory - leaving /var/run everywhere
  else (forwarded request 233447 from coolo)

OBS-URL: https://build.opensuse.org/request/show/234694
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=55
2014-05-21 14:20:41 +00:00
Tomáš Chvátal
0943a7a494 Accepting request 233447 from home:coolo:branches:openSUSE:Factory
- use %_rundir for %ghost directory - leaving /var/run everywhere
  else

OBS-URL: https://build.opensuse.org/request/show/233447
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=75
2014-05-19 11:56:09 +00:00
Stephan Kulow
332c2bb651 Accepting request 214487 from network:vpn
- openvpn-fips140-2.3.2.patch: Allow usage of SHA1 instead of MD5 in
  some internal checking routines. This allows operation in FIPS 140-2
  mode. (forwarded request 214077 from msmeissn)

OBS-URL: https://build.opensuse.org/request/show/214487
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=54
2014-01-20 15:24:24 +00:00
01bef909c4 Accepting request 214077 from home:msmeissn:branches:network:vpn
- openvpn-fips140-2.3.2.patch: Allow usage of SHA1 instead of MD5 in
  some internal checking routines. This allows operation in FIPS 140-2
  mode.

OBS-URL: https://build.opensuse.org/request/show/214077
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=73
2014-01-20 12:12:10 +00:00
Stephan Kulow
8ece16a925 Accepting request 213853 from network:vpn
- Updated README.SUSE, documented also the rcopenvpn compatibility
  wrapper script (bnc#848070).

OBS-URL: https://build.opensuse.org/request/show/213853
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=53
2014-01-14 18:52:22 +00:00
13dc14afbb - Updated README.SUSE, documented also the rcopenvpn compatibility
wrapper script (bnc#848070).

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=71
2014-01-14 10:46:24 +00:00
Stephan Kulow
10b01e8978 Accepting request 212028 from network:vpn
- Readded rcopenvpn helper script under systemd (bnc#848070)
- Fixed a typo (forwarded request 211245 from mtomaschewski)

OBS-URL: https://build.opensuse.org/request/show/212028
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=52
2014-01-02 10:15:18 +00:00
Andreas Jaeger
fcd74cd7cf Accepting request 211245 from home:mtomaschewski:branches:network:vpn
- Readded rcopenvpn helper script under systemd (bnc#848070)
- Fixed a typo

OBS-URL: https://build.opensuse.org/request/show/211245
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=69
2013-12-22 15:48:48 +00:00
Stephan Kulow
db01ad32c5 Accepting request 205448 from network:vpn
- Fixed invalid mode in exec bit removal call from doc files

OBS-URL: https://build.opensuse.org/request/show/205448
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=51
2013-11-04 06:08:37 +00:00
3e9aee291c - Fixed invalid mode in exec bit removal call from doc files
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=67
2013-10-31 18:55:23 +00:00
e8f6fcdbbb - Fixed exec bit removal call from documentation files
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=66
2013-10-31 18:47:58 +00:00
Stephan Kulow
5bbcd6c71b Accepting request 196606 from network:vpn
Add a section about how to control all or a named configuration with the
help of systemctl to the README.SUSE file. (forwarded request 196569 from lmuelle)

OBS-URL: https://build.opensuse.org/request/show/196606
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=49
2013-08-28 19:16:23 +00:00
cc6c5db9fc Accepting request 196569 from home:lmuelle:branches:network:vpn
Add a section about how to control all or a named configuration with the
help of systemctl to the README.SUSE file.

OBS-URL: https://build.opensuse.org/request/show/196569
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=64
2013-08-28 06:33:48 +00:00
Stephan Kulow
432d3edabf Accepting request 177757 from network:vpn
Updated from 2.3.0 to 2.3.2. Detailed changes are in .changes file. (forwarded request 177312 from mrdocs)

OBS-URL: https://build.opensuse.org/request/show/177757
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=48
2013-06-05 15:46:17 +00:00
bf61c39e95 Accepting request 177312 from home:mrdocs:branches:network:vpn
Updated from 2.3.0 to 2.3.2. Detailed changes are in .changes file.

OBS-URL: https://build.opensuse.org/request/show/177312
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=62
2013-06-05 14:47:34 +00:00
Stephan Kulow
4f4f794599 Accepting request 175267 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/175267
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=47
2013-05-16 09:18:49 +00:00
1842097fc7 - Try to migrate openvpn.service autostart to openvpn@<CONF>.service
instance enablement.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=60
2013-05-06 11:17:06 +00:00
Stephan Kulow
6e8070f077 Accepting request 173037 from network:vpn
- Fixed to enable systemd support in configure
- Fixed openvpn-tmpfile.conf to use GID root, there is no openvpn group.
- Added openvpn.target file allowing to handle all instances at once.
- Fixed to install the service template correctly as openvpn@.service.
  Use "systemctl enable openvpn@foo.service" to enable instance using
  /etc/openvpn/foo.conf.
- Disabled systemd variant of restart on update rpm macro, adopted other
  macros to use openvpn.target to e.g. stop all instances on uninstall.

OBS-URL: https://build.opensuse.org/request/show/173037
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=46
2013-04-23 15:25:34 +00:00
d3f926c85f - Fixed openvpn-tmpfile.conf to use GID root, there is no openvpn group.
- Added openvpn.target file allowing to handle all instances at once.
- Disabled systemd variant of restart on update rpm macro, adopted other
  macros to use openvpn.target to e.g. stop all instances on uninstall.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=58
2013-04-23 13:22:31 +00:00
38fd21b2e6 - Fixed to enable systemd support in configure
- Fixed to install the service template correctly as openvpn@.service.
  Use "systemctl enable openvpn@foo.service" to enable instance using
  /etc/openvpn/foo.conf.
- Fixed openvpn-tmpfile.conf to use GID root, there is no openvpn group.
- Disabled all systemd post install macros trying to use not existing
  openvpn.service file.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=57
2013-04-23 12:40:53 +00:00