Age | Commit message (Collapse) | Author |
|
Bug 7095
Always keep /var/log/auth.log to allow for 'show log authorization'
|
|
Can't do it early in boot because ipv6 module may not be loaded.
|
|
Bug 6681
Default configuration for IPV6 max routes is too small
|
|
Bug 6663
(cherry picked from commit fa7d81f125033b7ed4bd549eb6905918612a6877)
|
|
Previously, log file rotation was checked by cron daily. Some log
file -- such as those generated by PPP -- can grow rapidly. Such
infrequent checking can lead to running out of disk space on systems
with small disk drives or flash storage. This change checks for
rotation hourly.
|
|
This reverts commit c2c15ef2d6a85d40e778a0d84f243d2ae99c56ba.
|
|
If cpufrequtils is installed, then want the default to be full performance.
|
|
Avoid calling vyatta_net_name on vlan's
|
|
|
|
Bug 6379
Just leave vlan and other pseudo-interface names alone.
|
|
Use existing config parser and perl to handle udev device naming.
Do renaming early in udev boot, and fixup config file later.
This avoids rescanning udev devices on boot and adds preliminary
support for hotplug.
|
|
This fixes case where rsyslog finds no targets on boot
|
|
Kernel messages and repeated message option
|
|
Configuration file is /etc/rsyslog.conf and it is supports
directory of include parameters so do not need to edit
rsyslog.conf directly
|
|
Udev rules have moved from /etc/udev to /lib/udev on Debian Squeeze
|
|
Other udev scripts may have configured the device name before
the Vyatta script runs. Use the convention followed by the
standard persistent network name script; only applly name rules
if interface does not already have name assigned.
|
|
* second udev invocation now has ACTION "change" in squeeze.
* DRIVERS no longer available from squeeze udev.
|
|
* as discussed, remove the wireless rule that causes warning
|
|
|
|
For serviceablity put core files in /var/core.
But core file will still not be created unless process is running
with permission to write there, and has ulimit permission.
|
|
Unionfs should copyup the xattr automatically, but it doesn't
so use touch to force a copyup before setting attributes.
|
|
|
|
Not using auditing for command logging.
|
|
Ping is already setuid root.
|
|
|
|
This sets file capability attributes during package
installation (and build) to allow better security models.
|
|
Instead of white-listing special system users, just go with the
Debian policy that all users with uid < 1000 are system accounts
|
|
The problem is that IPV6 module is not loaded when sysctl's
are interpreted during boot, and we want to allow marking IPV6
disabled.
|
|
1. Move vyatta-sysctl.conf from rl-system.init to procps
This makes configuration happen early (before networking)
2. Do IPV6 configuration for address_flush in rl-system.init
(after IPV6 is loaded)
3. Cleanup shell code for ipv6_params:
* no sudo needed in startup scripts
* use cleaner iteration
|
|
Bug 3696
This adds parameter to keep Vyatta IPV6 behavior
|
|
This is a resolution of Bug 5031
Set default to 1 - reply only if the target IP address is local address
configured on the incoming interface. This makes Vyatta behaves
like interface base address model.
|
|
If second wlan device is created (for multiple ssid), then udev
rules don't know how to handle it. For now, just accept what kernel
gives us.
|
|
|
|
|
|
1. Complete migration of protected-users from hardcoded in User.pm
to /opt/vyatta/etc/protected-user
2. Put mapping from level to group in file.
|
|
|
|
Causes pam-auth-update to barf
Use of uninitialized value $3 in split at /usr/sbin/pam-auth-update line 620, <CURRENT> line 19.
Use of uninitialized value $curmod in quotemeta at /usr/sbin/pam-auth-update line 628, <CURRENT> line 19.
Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19.
Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19.
Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19.
Use of uninitialized value $curmod in hash element at /usr/sbin/pam-auth-update line 650, <CURRENT> line 19.
|
|
Use a reasonable suffix for file type
|
|
|
|
This keeps radius from fighting with tacacs+
|
|
Handle cases where IPv6 kernel module is not loaded more gracefully.
|
|
Don't rename wireless devices to be ethX.
|
|
replaced with Debian branding during full-upgrade to Jenner
(cherry picked from commit cbdcd18b2e5328d24a9dfe04dfa015f8375b50ac)
|
|
Bug 4591
Consolidate check for telnet login
Don't remove /etc/securetty edit it
(cherry picked from commit c6c477f2ffb0f2fd4cf12882f22c2c44ab57cc46)
|
|
|
|
Only put comments in about features that are used.
|
|
|
|
So when CLI updates ntp.conf, the file stays same format
|
|
There are options (like restrict) that should be ntp.conf
This would reduce security exposure of the router (see recent CVE).
Also, this avoid restarting ntp server on boot when using the default
vyatta ntp server.
|
|
Default fallback code was broken
Change to blocked out region for Vyatta config.
|