summaryrefslogtreecommitdiff
path: root/sysconf
AgeCommit message (Collapse)Author
2010-01-26Get rid of protected-users fileStephen Hemminger
Instead of white-listing special system users, just go with the Debian policy that all users with uid < 1000 are system accounts
2010-01-20Set IPV6 parameters in rl-system.initStephen Hemminger
The problem is that IPV6 module is not loaded when sysctl's are interpreted during boot, and we want to allow marking IPV6 disabled.
2010-01-19Change how IPV4/IPV6 configuration values are doneStephen Hemminger
1. Move vyatta-sysctl.conf from rl-system.init to procps This makes configuration happen early (before networking) 2. Do IPV6 configuration for address_flush in rl-system.init (after IPV6 is loaded) 3. Cleanup shell code for ipv6_params: * no sudo needed in startup scripts * use cleaner iteration
2010-01-14Add sysctl to control IPV6 address flushStephen Hemminger
Bug 3696 This adds parameter to keep Vyatta IPV6 behavior
2009-12-23Set default to only ARP if IP address matches received interfaceStephen Hemminger
This is a resolution of Bug 5031 Set default to 1 - reply only if the target IP address is local address configured on the incoming interface. This makes Vyatta behaves like interface base address model.
2009-12-08Keep udev from borking wireless device namesStephen Hemminger
If second wlan device is created (for multiple ssid), then udev rules don't know how to handle it. For now, just accept what kernel gives us.
2009-11-11Remove blank lineStephen Hemminger
2009-11-05radius: only try first password if first moduleStephen Hemminger
2009-11-05Move user configuration information to filesStephen Hemminger
1. Complete migration of protected-users from hardcoded in User.pm to /opt/vyatta/etc/protected-user 2. Put mapping from level to group in file.
2009-11-03Fix pam-auth-update errors from radiusStephen Hemminger
2009-11-03Remove blank lineStephen Hemminger
Causes pam-auth-update to barf Use of uninitialized value $3 in split at /usr/sbin/pam-auth-update line 620, <CURRENT> line 19. Use of uninitialized value $curmod in quotemeta at /usr/sbin/pam-auth-update line 628, <CURRENT> line 19. Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19. Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19. Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19. Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19.
2009-11-02rename pam-radius to pam_radius.cfgStephen Hemminger
Use a reasonable suffix for file type
2009-10-29radius client: try first password only if not firstStephen Hemminger
2009-10-27Use pam-auth-update to configure radiusStephen Hemminger
This keeps radius from fighting with tacacs+
2009-09-22Bugfix 4951: Don't fail if IPv6 kernel module is not loaded.Bob Gilligan
Handle cases where IPv6 kernel module is not loaded more gracefully.
2009-08-12Don't change name of non-ethernet devicesStephen Hemminger
Don't rename wireless devices to be ethX.
2009-07-30Fix 4748: Pre-login message files (/etc/issue,/etc/issue.net) areStig Thormodsrud
replaced with Debian branding during full-upgrade to Jenner (cherry picked from commit cbdcd18b2e5328d24a9dfe04dfa015f8375b50ac)
2009-07-17Make telnet management smarterStephen Hemminger
Bug 4591 Consolidate check for telnet login Don't remove /etc/securetty edit it (cherry picked from commit c6c477f2ffb0f2fd4cf12882f22c2c44ab57cc46)
2009-06-17Merged from Jenner.Bob Gilligan
2009-05-24Simplify ntp.confStephen Hemminger
Only put comments in about features that are used.
2009-05-22add iburstStephen Hemminger
2009-05-22Put server at end of fileStephen Hemminger
So when CLI updates ntp.conf, the file stays same format
2009-05-22Add NTP configuration fileStephen Hemminger
There are options (like restrict) that should be ntp.conf This would reduce security exposure of the router (see recent CVE). Also, this avoid restarting ntp server on boot when using the default vyatta ntp server.
2009-04-09Resolve problems with syslog.confStephen Hemminger
Default fallback code was broken Change to blocked out region for Vyatta config.
2009-04-08Rewrite existing syslog configuration updateStephen Hemminger
Do most of the work in the rewritten vyatta_update_syslog code. Handle multiple facilities for same target without causing duplicate log messages. Never restart syslog daemon, just reload it and only if the configuration has changed.
2009-04-01Don't double log quagga messagesStephen Hemminger
Bug 4205 Duplicate messages in syslog for quagga notice and above messages.
2009-02-27Fix Bug 2463 Allow the neighbor table threshold values to beMohit Mehta
modified via the CLI - (modify ARP table size) * added cli to configure [arp (ipv4)] and [neighbor (ipv6)] table-size * set default value for arp_announce so as to avoid local addresses that are not in the target's subnet for the interface
2009-02-24set default values for ipv6 accept_redirects and accept_source_routeMohit Mehta
2009-02-19Fix Bug 3951 default values for kernel tunable security parameters under ↵Mohit Mehta
firewall
2008-12-17removed unprintable form-feed characters. This was causing xml validation to ↵slioch
fail within the webgui.
2008-11-17Fix sysctl key valuesStephen Hemminger
Correct value is 'kernel.panic' not 'sys.kernel.panic'
2008-11-14Speed up bootStephen Hemminger
Faster way to make empty files. Load snmp stats in background Move all sysctl settings to one place
2008-10-13add ssh key blacklistsAn-Cheng Huang
2008-10-10Go back to simpler syslog configStephen Hemminger
Bugfix 3567 The command templates for managing the syslog are awkward and brittle and really can't deal with multiple targets or full config format, so just go back to something simple and fix later in a better redesign.
2008-09-23No longer need to turn off SACKStephen Hemminger
The TCP MD5 code is fixed to handle SACK correctly.
2008-07-30Enable IPv6 forwarding.Stig Thormodsrud
2008-06-30Change syslogging of authorization related commandsStephen Hemminger
For sucessful sudo, just log it at info level. Capture any security failures/changes into /var/log/auth.log but skip normal CLI commands Turn off the builtin sync after each write to /var/log/messages by putting - before file name; the sync causes a disk write each time and therefore can be a performance hit during boot.
2008-06-05Turn off TCP SACKStephen Hemminger
This is a workaround for bug 3313. The problem is that MD5 uses up what little space there for TCP options in header.
2008-05-13Move sysctl configuration to /etc/vyatta-sysctl.confStephen Hemminger
Change settings and move sysctl values to separate file /etc/vyatta-sysctl.conf. This allows for user/support to adjust configuration without changing the rl-system.init script.
2008-04-22config.boot.default is not moved to the top level repo (build-iso.git)rbalocca
2008-04-08Remove vestigal version file from vyatta-cfg-systemrbalocca
2008-03-26Move the copyright dates over (bug 3028)rbalocca
2008-03-24Line up the colons with the one from the copyright notice (in show version)rbalocca
2008-03-18Update version file to VC4.0.1Mark O'Brien
2008-03-15Update copyright for "show version"rbalocca
2008-03-10Changes for license/copyrightStephen Hemminger
Put copy of GPLv2 into sysconf/LICENSE and show copyright in version information. Bugfix: 2899
2008-03-04Fix for bug #2934rbalocca
http://bugzilla.vyatta.com/show_bug.cgi?id=2934
2008-02-25Update version file to vc4.0.0Mark O'Brien
2008-02-25These files will be changed by autobuild-git-eureakrbalocca
2008-02-22Update version file to 4.0.0rbalocca