SHA256
1
0
forked from pool/openvpn
Commit Graph

135 Commits

Author SHA256 Message Date
Dominique Leuenberger
f8aa821b3c Accepting request 531163 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/531163
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=77
2017-10-05 10:02:06 +00:00
Nirmoy Das
6edc27e34c Accepting request 516148 from home:sebix:branches:network:vpn
remove empty wrong directory form filelist

OBS-URL: https://build.opensuse.org/request/show/516148
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=125
2017-10-04 10:52:41 +00:00
Nirmoy Das
774c998664 Accepting request 505857 from home:ndas:branches:network:vpn
- Update to 2.4.3 (bsc#1045489)
    - Ignore auth-nocache for auth-user-pass if auth-token is pushed
    - crypto: Enable SHA256 fingerprint checking in --verify-hash
    - copyright: Update GPLv2 license texts
    - auth-token with auth-nocache fix broke --disable-crypto builds
    - OpenSSL: don't use direct access to the internal of X509
    - OpenSSL: don't use direct access to the internal of EVP_PKEY
    - OpenSSL: don't use direct access to the internal of RSA
    - OpenSSL: don't use direct access to the internal of DSA
    - OpenSSL: force meth->name as non-const when we free() it
    - OpenSSL: don't use direct access to the internal of EVP_MD_CTX
    - OpenSSL: don't use direct access to the internal of EVP_CIPHER_CTX
    - OpenSSL: don't use direct access to the internal of HMAC_CTX
    - Fix NCP behaviour on TLS reconnect.
    - Remove erroneous limitation on max number of args for --plugin
    - Fix edge case with clients failing to set up cipher on empty PUSH_REPLY.
    - Fix potential 1-byte overread in TCP option parsing.
    - Fix remotely-triggerable ASSERT() on malformed IPv6 packet.
    - Preparing for release v2.4.3 (ChangeLog, version.m4, Changes.rst)
    - refactor my_strupr
    - Fix 2 memory leaks in proxy authentication routine
    - Fix memory leak in add_option() for option 'connection'
    - Ensure option array p[] is always NULL-terminated
    - Fix a null-pointer dereference in establish_http_proxy_passthru()
    - Prevent two kinds of stack buffer OOB reads and a crash for invalid input data
    - Fix an unaligned access on OpenBSD/sparc64
    - Missing include for socket-flags TCP_NODELAY on OpenBSD
    - Make openvpn-plugin.h self-contained again.
    - Pass correct buffer size to GetModuleFileNameW()
    - Log the negotiated (NCP) cipher

OBS-URL: https://build.opensuse.org/request/show/505857
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=124
2017-06-23 10:34:54 +00:00
Dominique Leuenberger
2bd316cf34 Accepting request 504783 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/504783
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=76
2017-06-20 07:41:09 +00:00
Nirmoy Das
6eab1b0fe1 Accepting request 504782 from home:ndas:branches:network:vpn
- use %{_tmpfilesdir} for tmpfiles.d/openvpn.conf (bsc#1044223)

OBS-URL: https://build.opensuse.org/request/show/504782
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=122
2017-06-19 14:48:58 +00:00
Dominique Leuenberger
1fcc3292cc Accepting request 501452 from network:vpn
- Update tp 2.4.2
    - auth-token: Ensure tokens are always wiped on de-auth
    - Make --cipher/--auth none more explicit on the risks
    - Use SHA256 for the internal digest, instead of MD5
    - Deprecate --ns-cert-type
    - Deprecate --no-iv
    - Support --block-outside-dns on multiple tunnels
    - Limit --reneg-bytes to 64MB when using small block ciphers
    - Fix --tls-version-max in mbed TLS builds
  Details changelogs are avilable in 
  https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
  [*0001-preform-deferred-authentication-in-the-background.patch
   *openvpn-2.3.x-fixed-multiple-low-severity-issues.patch
   *openvpn-fips140-2.3.2.patch]
- pkcs11-helper-devel >= 1.11 is needed for openvpn-2.4.2
- cleanup the spec file

OBS-URL: https://build.opensuse.org/request/show/501452
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=75
2017-06-12 13:30:13 +00:00
Nirmoy Das
0c21985672 Accepting request 501441 from home:ndas:branches:network:vpn
- cleanup the spec file

OBS-URL: https://build.opensuse.org/request/show/501441
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=120
2017-06-06 15:27:51 +00:00
Nirmoy Das
ea6e8a6af9 Accepting request 501439 from home:ndas:branches:network:vpn
- pkcs11-helper-devel >= 1.11 is needed for openvpn-2.4.2

OBS-URL: https://build.opensuse.org/request/show/501439
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=119
2017-06-06 15:17:18 +00:00
Nirmoy Das
fbd567ff8c - Update tp 2.4.2
- auth-token: Ensure tokens are always wiped on de-auth
    - Make --cipher/--auth none more explicit on the risks
    - Use SHA256 for the internal digest, instead of MD5
    - Deprecate --ns-cert-type
    - Deprecate --no-iv
    - Support --block-outside-dns on multiple tunnels
    - Limit --reneg-bytes to 64MB when using small block ciphers
    - Fix --tls-version-max in mbed TLS builds
  Details changelogs are avilable in 
  https://community.openvpn.net/openvpn/wiki/ChangesInOpenvpn24
  [*0001-preform-deferred-authentication-in-the-background.patch
   *openvpn-2.3.x-fixed-multiple-low-severity-issues.patch
   *openvpn-fips140-2.3.2.patch]

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=118
2017-06-06 13:12:31 +00:00
Nirmoy Das
9b5c6bd385 OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=117 2017-06-06 12:54:53 +00:00
Dominique Leuenberger
31d719f30d Accepting request 492826 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/492826
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=74
2017-05-08 17:02:41 +00:00
9c3259ca06 Accepting request 489820 from home:ndas:branches:network:vpn
- Preform deferred authentication in the background to not
  cause main daemon processing delays when the underlying pam mechanism (e.g.
  ldap) needs longer to response (bsc#959511).
  [+ 0001-preform-deferred-authentication-in-the-background.patch]
- Added fix for possible heap overflow on read accessing getaddrinfo 
  result (bsc#959714).
  [+openvpn-2.3.9-Fix-heap-overflow-on-getaddrinfo-result.patch]
- Added a patch to fix multiple low severity issues (bsc#934237).
  [+openvpn-2.3.x-fixed-multiple-low-severity-issues.patch]

OBS-URL: https://build.opensuse.org/request/show/489820
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=115
2017-04-27 09:50:39 +00:00
Dominique Leuenberger
4aba9d630b Accepting request 452118 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/452118
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=73
2017-01-25 22:33:47 +00:00
Nirmoy Das
9779642307 Accepting request 451851 from home:darix:playground
- silence warning about %{_rundir}/openvpn
  - for non systemd case: just package the %{_rundir}/openvpn in
    the package
  - for systemd case: call systemd-tmpfiles and own the dir as
    %ghost in the filelist

- refreshed patches to apply cleanly again
  openvpn-2.3-plugin-man.dif
  openvpn-fips140-2.3.2.patch

- update to 2.3.14
  - update year in copyright message
  - Document the --auth-token option
  - Repair topology subnet on FreeBSD 11
  - Repair topology subnet on OpenBSD
  - Drop recursively routed packets
  - Support --block-outside-dns on multiple tunnels
  - When parsing '--setenv opt xx ..' make sure a third parameter
    is present
  - Map restart signals from event loop to SIGTERM during
    exit-notification wait
  - Correctly state the default dhcp server address in man page
  - Clean up format_hex_ex()
- enabled pkcs11 support

OBS-URL: https://build.opensuse.org/request/show/451851
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=113
2017-01-24 10:31:30 +00:00
Dominique Leuenberger
e4c4f2fb8d Accepting request 449352 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/449352
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=72
2017-01-10 09:52:00 +00:00
Nirmoy Das
ce8599bf09 Accepting request 443666 from home:stroeder:branches:network:vpn
- update to 2.3.13
- successfully tested as VPN client on TW x86_64
- please review FIPS patch update carefully

OBS-URL: https://build.opensuse.org/request/show/443666
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=111
2017-01-09 12:13:41 +00:00
Dominique Leuenberger
cfd18fe566 Accepting request 442517 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/442517
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=71
2016-11-29 11:50:18 +00:00
71dd389b3e Accepting request 442460 from home:matwey:branches:network:vpn
OBS-URL: https://build.opensuse.org/request/show/442460
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=109
2016-11-29 08:28:48 +00:00
Dominique Leuenberger
a9965a4ad6 Accepting request 427634 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/427634
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=70
2016-09-16 09:01:41 +00:00
Nirmoy Das
336ec975bc Accepting request 425721 from home:AndreasStieger:branches:network:vpn
- Add an example for a FIPS 140-2 approved cipher configuration to
  the sample configuration files. Fixes bsc#988522
  adding openvpn-fips140-AES-cipher-in-config-template.patch
- remove gpg-offline signature verification, now a source service

OBS-URL: https://build.opensuse.org/request/show/425721
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=107
2016-09-14 14:11:18 +00:00
Dominique Leuenberger
02b1e24f46 Accepting request 400152 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/400152
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=69
2016-06-07 21:48:41 +00:00
Ismail Dönmez
6dac5a8f6a Accepting request 394676 from home:namtrac:branches:network:vpn
- Update to version 2.3.11
  * Fixed port-share bug with DoS potential
  * Fix buffer overflow by user supplied data
  * Fix undefined signed shift overflow
  * Ensure input read using systemd-ask-password is null terminated
  * Support reading the challenge-response from console
  * hardening: add safe FD_SET() wrapper openvpn_fd_set()
  * Restrict default TLS cipher list
- Add BuildRequires on xz for SLE11

OBS-URL: https://build.opensuse.org/request/show/394676
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=105
2016-06-06 07:52:26 +00:00
Dominique Leuenberger
8e0c189a4f Accepting request 352204 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/352204
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=68
2016-01-06 23:25:14 +00:00
Martin Caj
06ccbd25ce Accepting request 351949 from home:namtrac:branches:network:vpn
- Update to version 2.3.10
  * Warn user if their certificate has expired
  * Fix regression in setups without a client certificate

- Update to version 2.3.9
  * Show extra-certs in current parameters.
  * Do not set the buffer size by default but rely on the operation system default.
  * Remove --enable-password-save option
  * Detect config lines that are too long and give a warning/error
  * Log serial number of revoked certificate
  * Avoid partial authentication state when using --disabled in CCD configs
  * Replace unaligned 16bit access to TCP MSS value with bytewise access
  * Fix possible heap overflow on read accessing getaddrinfo() result.
  * Fix isatty() check for good. (obsoletes revert-daemonize.patch)
  * Client-side part for server restart notification
  * Fix privilege drop if first connection attempt fails
  * Support for username-only auth file.
  * Increase control channel packet size for faster handshakes
  * hardening: add insurance to exit on a failed ASSERT()
  * Fix memory leak in auth-pam plugin
  * Fix (potential) memory leak in init_route_list()
  * Fix unintialized variable in plugin_vlog()
  * Add macro to ensure we exit on fatal errors
  * Fix memory leak in add_option() by simplifying get_ipv6_addr
  * openssl: properly check return value of RAND_bytes()
  * Fix rand_bytes return value checking
  * Fix "White space before end tags can break the config parser"

OBS-URL: https://build.opensuse.org/request/show/351949
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=103
2016-01-06 09:47:33 +00:00
Dominique Leuenberger
c5f68dab84 Accepting request 348337 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/348337
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=67
2015-12-20 09:52:41 +00:00
39b88922eb - Adjust /var/run to _rundir macro value in openvpn@.service too.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=101
2015-12-04 08:02:06 +00:00
Stephan Kulow
87d673d2fc Accepting request 324534 from network:vpn
- Removed obsolete --with-lzo-headers option, readded LFS_CFLAGS.
- Moved openvpn-plugin.h into a devel package, removed .gitignore

OBS-URL: https://build.opensuse.org/request/show/324534
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=66
2015-08-23 13:43:34 +00:00
e18eab1a94 - Moved openvpn-plugin.h into a devel package, removed .gitignore
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=99
2015-08-20 09:46:01 +00:00
558e8eaf2f - Removed obsolete --with-lzo-headers option, readded LFS_CFLAGS.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=98
2015-08-20 09:00:14 +00:00
Dominique Leuenberger
baed75c436 Accepting request 322617 from network:vpn
Add revert-daemonize.patch, looks like under systemd the stdin
and stdout are not TTYs by default. This reverts to previous
behaviour fixing bsc#941569

OBS-URL: https://build.opensuse.org/request/show/322617
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=65
2015-08-17 13:35:10 +00:00
f7cfc57d16 Accepting request 322300 from home:namtrac:branches:network:vpn
OBS-URL: https://build.opensuse.org/request/show/322300
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=96
2015-08-13 09:20:17 +00:00
Dominique Leuenberger
8aa0a854ad Accepting request 321625 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/321625
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=64
2015-08-11 06:27:04 +00:00
064dd8062e Accepting request 320680 from home:namtrac:branches:network:vpn
- Update to version 2.3.8
  * Report missing endtags of inline files as warnings
  * Fix commit e473b7c if an inline file happens to have a
    line break exactly at buffer limit
  * Produce a meaningful error message if --daemon gets in the way of
    asking for passwords.
  * Document --daemon changes and consequences (--askpass, --auth-nocache)
  * Del ipv6 addr on close of linux tun interface
  * Fix --askpass not allowing for password input via stdin
  * Write pid file immediately after daemonizing
  * Fix regression: query password before becoming daemon
  * Fix using management interface to get passwords
  * Fix overflow check in openvpn_decrypt()

OBS-URL: https://build.opensuse.org/request/show/320680
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=94
2015-08-10 13:43:50 +00:00
Dominique Leuenberger
e5659743e0 Accepting request 313672 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/313672
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=63
2015-06-30 08:16:16 +00:00
3d06f17727 Accepting request 313671 from home:namtrac:bugfix
- Update to version 2.3.7
  * down-root plugin: Replaced system() calls with execve()
  * sockets: Remove the limitation of --tcp-nodelay to be server-only
  * pkcs11: Load p11-kit-proxy.so module by default
  * New approach to handle peer-id related changes to link-mtu
  * Fix incorrect use of get_ipv6_addr() for iroute options
  * Print helpful error message on --mktun/--rmtun if not available
  * Explain effect of --topology subnet on --ifconfig
  * Add note about file permissions and --crl-verify to manpage
  * Repair --dev null breakage caused by db950be85d37
  * Correct note about DNS randomization in openvpn.8
  * Disallow usage of --server-poll-timeout in --secret key mode
  * Slightly enhance documentation about --cipher
  * On signal reception, return EAI_SYSTEM from openvpn_getaddrinfo()
  * Use EAI_AGAIN instead of EAI_SYSTEM for openvpn_getaddrinfo()
  * Fix --redirect-private in --dev tap mode
  * Updated manpage for --rport and --lport
  * Properly escape dashes on the man-page
  * Improve documentation in --script-security section of the man-page
  * Really fix '--cipher none' regression
  * Set tls-version-max to 1.1 if cryptoapicert is used
  * Account for peer-id in frame size calculation
  * Disable SSL compression
  * Fix frame size calculation for non-CBC modes.
  * Allow for CN/username of 64 characters (fixes off-by-one)
  * Re-enable TLS version negotiation by default
  * Remove size limit for files inlined in config
  * Improve --tls-cipher and --show-tls man page description
  * Re-read auth-user-pass file on (re)connect if required
  * Clarify --capath option in manpage

OBS-URL: https://build.opensuse.org/request/show/313671
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=92
2015-06-25 11:58:40 +00:00
Dominique Leuenberger
1f1d0bdc05 Accepting request 290007 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/290007
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=62
2015-03-11 08:57:59 +00:00
515f549344 adjust plugin dir plageholders in man page
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=90
2015-03-02 10:06:37 +00:00
c4621b5e67 - Fixed to provide actual plugin/doc dirs in openvpn(8) man page.
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=89
2015-03-02 09:45:03 +00:00
6a9f5d263c - Fixed to use correct sha digest data length and in fips mode,
use aes instead of the disallowed blowfish crypto (boo#914166).

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=88
2015-03-02 08:27:36 +00:00
Dominique Leuenberger
2168217c89 Accepting request 287767 from network:vpn
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/287767
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=61
2015-02-27 09:59:47 +00:00
fbf787a918 fixed previous fix
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=86
2015-02-18 17:21:27 +00:00
b4dab5a27f - Fixed to use correct sha digest data length (boo#914166)
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=85
2015-02-10 15:35:33 +00:00
Dominique Leuenberger
55d0e961ac Accepting request 263672 from network:vpn
- Update to version 2.3.6 fixing a denial-of-service vulnerability
  where an authenticated client could stop the server by triggering
  a server-side ASSERT (bnc#907764,CVE-2014-8104).
  See ChangeLog file for a complete list of changes.

OBS-URL: https://build.opensuse.org/request/show/263672
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=60
2014-12-03 21:47:57 +00:00
5a65bc9e84 - Update to version 2.3.6 fixing a denial-of-service vulnerability
where an authenticated client could stop the server by triggering
  a server-side ASSERT (bnc#907764,CVE-2014-8104).
  See ChangeLog file for a complete list of changes.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=83
2014-12-01 19:43:09 +00:00
Stephan Kulow
bcc937982f Accepting request 260087 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/260087
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=59
2014-11-07 08:06:08 +00:00
Tomáš Chvátal
e52c73c2cc Accepting request 259041 from home:namtrac:branches:network:vpn
- Update to version 2.3.5
  * See included changelog
- Depend on systemd-devel for the daemon check functionality

OBS-URL: https://build.opensuse.org/request/show/259041
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=81
2014-11-06 15:05:03 +00:00
Stephan Kulow
2ea1e59ee7 Accepting request 246648 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/246648
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=57
2014-08-28 19:05:32 +00:00
Martin Caj
e3db630d65 Accepting request 246644 from home:namtrac:branches:network:vpn
- Update to version 2.3.4
  * Add support for client-cert-not-required for PolarSSL.
  * Introduce safety check for http proxy options.

OBS-URL: https://build.opensuse.org/request/show/246644
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=79
2014-08-27 13:08:10 +00:00
Stephan Kulow
865a761652 Accepting request 236695 from network:vpn
1

OBS-URL: https://build.opensuse.org/request/show/236695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openvpn?expand=0&rev=56
2014-06-10 12:39:19 +00:00
5eff630ee5 Accepting request 235421 from home:elvigia:branches:network:vpn
- Build with large file support in 32 bit systems.

OBS-URL: https://build.opensuse.org/request/show/235421
OBS-URL: https://build.opensuse.org/package/show/network:vpn/openvpn?expand=0&rev=77
2014-06-10 02:55:45 +00:00