| Age | Commit message (Collapse) | Author | |
|---|---|---|---|
| 2025-05-31 | nat: T7237: Remove expensive NAT address check | sarthurdev | |
| 2025-05-30 | Merge pull request #4535 from jestabro/default-commit-confirm-action | John Estabrook | |
| config-mgmt: T7508: use recursive defaults to read commit-confirm action | |||
| 2025-05-30 | config-mgmt: T7508: use recursive defaults to read commit-confirm action | John Estabrook | |
| 2025-05-29 | http-api: T3955: add commit-confirm to endpoints /configure /config-file | John Estabrook | |
| 2025-05-29 | Merge pull request #4266 from takehaya/T6013-trusted-ca-keys | Christian Breunig | |
| T6013: Add support for AuthorizedPrincipalsFile to trusted_user_ca_key | |||
| 2025-05-29 | Merge pull request #4532 from vyos/c-po-patch-1 | Christian Breunig | |
| VD-277: use YYYY.MM.DD-HHMM-integration version scheme for builds | |||
| 2025-05-29 | VD-277: use YYYY.MM.DD-HHMM-integration version scheme for builds | Christian Breunig | |
| 2025-05-29 | zebra: T7349: Added importing routes from non to the kernel routing table | aapostoliuk | |
| * zebra: T7349: Added importing routes from non to the kernel routing table Added importing routes from non to the kernel routing table. --------- Co-authored-by: Christian Breunig <christian@breunig.cc> | |||
| 2025-05-29 | Merge pull request #4531 from jestabro/commit-confirm-reboot | Christian Breunig | |
| config-mgmt: T7500: fix typo preventing commit-confirm hard rollback | |||
| 2025-05-29 | Merge pull request #4530 from jestabro/api-extend-load-merge | Christian Breunig | |
| http-api: T7498: allow passing config string in body of 'load' or 'merge' request | |||
| 2025-05-29 | ssh: T6013: rename trusted-user-ca-key -> truster-user-ca | Christian Breunig | |
| The current implementation for SSH CA based authentication uses "set service ssh trusted-user-ca-key ca-certificate <foo>" to define an X.509 certificate from "set pki ca <foo> ..." - fun fact, native OpenSSH does not support X.509 certificates and only runs with OpenSSH ssh-keygen generated RSA or EC keys. This commit changes the bahavior to support antive certificates generated using ssh-keygen and loaded to our PKI tree. As the previous implementation did not work at all, no migrations cript is used. | |||
| 2025-05-29 | pki: T6013: add proper dependencies for SSH CA | Christian Breunig | |
| We need to establish proper dependencies on "system login" and "pki ca" for the SSH subsystem. If the CA is updated or user principal names are modified, we must also ensure that the SSH daemon is restarted accordingly. | |||
| 2025-05-29 | ssh: T6013: move principal name to "system login user <name> authentication" | Christian Breunig | |
| We already support using per-user SSH public keys for system authentication. Instead of introducing a new CLI path to configure per-user principal names, we should continue using the existing CLI location and store the principal names alongside the corresponding SSH public keys. set system login user <name> principal <principal> The certificate used for SSH authentication contains an embedded principal name, which is defined under this CLI node. Only users with matching principal names are permitted to log in. | |||
| 2025-05-29 | ssh: T6013: support SSH AuthorizedPrincipalsFile in use with trusted-user-ca-key | Takeru Hayasaka | |
| Thisc omplements commit e7cab89f9f81 ("T6013: Add support for configuring TrustedUserCAKeys in SSH service with local and remote CA keys"). It introduces a new CLI node per user to support defining the authorized principals used by any given PKI certificate. It is now possible to associate SSH login users with their respective principals. Authored-by: Takeru Hayasaka <hayatake396@gmail.com> | |||
| 2025-05-28 | config-mgmt: T7500: fix typo preventing commit-confirm hard rollback | John Estabrook | |
| 2025-05-28 | Merge pull request #4529 from IDerr/current | John Estabrook | |
| T7395: Add support for renew in REST Server | |||
| 2025-05-28 | http-api: T7498: allow passing config string in body of 'merge' request | John Estabrook | |
| 2025-05-28 | http-api: T7498: allow passing config string in body of 'load' request | John Estabrook | |
| 2025-05-28 | T7395: Add support for renew in REST Server | IDerr | |
| 2025-05-28 | T7432: smoketests for RPKI VRF support | Adam Smith | |
| 2025-05-28 | T7488: Make VPP restartable | Nataliia Solomko | |
| 2025-05-28 | T7169: Initialize interfaces after unsuccessful commit | Nataliia Solomko | |
| 2025-05-27 | T7432: RPKI VRF Support | Adam Smith | |
| 2025-05-27 | T7492: Fix modem connection code | Chris Blackburn | |
| Added another possible condition to the flow through the config apply function so that interfaces will reconnect as expected, even when there has been no significant change to the contig tags. | |||
| 2025-05-27 | Merge pull request #4524 from sarthurdev/T7350 | Daniil Baturin | |
| flowtable: T7350: Prevent interface deletion if referenced on flowtable | |||
| 2025-05-27 | Merge pull request #4523 from aapostoliuk/T7471-current | Daniil Baturin | |
| accel-ppp: T7471: Changed CoA port completion help to standard template | |||
| 2025-05-27 | Merge pull request #4490 from l0crian1/fix-qos-tcp-flags | Daniil Baturin | |
| QoS: T7415: Fix tcp flags matching | |||
| 2025-05-27 | Merge pull request #4496 from l0crian1/add-root-bpdu-guard | Daniil Baturin | |
| Bridge: T7430: Add BPDU Guard and Root Guard support | |||
| 2025-05-26 | T7374: install vyconf_cli and add links for associated vy_* commands | John Estabrook | |
| 2025-05-26 | Merge pull request #35 from kumvijaya/current | Viacheslav Hletenko | |
| T7445: added prs conflict check caller workflows | |||
| 2025-05-26 | bridge: T7430: rephrase bpdu/root-guard error message | Christian Breunig | |
| 2025-05-26 | Merge pull request #39 from kumvijaya/current | Daniil Baturin | |
| T7445: added open prs conflict check caller workflow | |||
| 2025-05-26 | Merge pull request #4525 from yunzheng/T3681-exclusion | Daniil Baturin | |
| vyos-1x-vmware: T3681: Fix Python bytecompile exclusion | |||
| 2025-05-25 | T7445: added prs conflict check caller workflow | kumvijaya | |
| 2025-05-24 | T7445: added open prs conflict check caller workflow | kumvijaya | |
| 2025-05-23 | Merge pull request #4505 from jestabro/config-context | John Estabrook | |
| T7363: Add vyconf aware initialization of Config | |||
| 2025-05-22 | T7363: update hash for vyconf aware initialization of Config | John Estabrook | |
| 2025-05-22 | T7363: retain generated files as imports for nosetests | John Estabrook | |
| 2025-05-22 | vyos-1x-vmware: T3681: Fix Python bytecompile exclusion | Yun Zheng Hu | |
| 2025-05-22 | Merge pull request #38 from jestabro/T7450-fix-use-pcre2 | John Estabrook | |
| T7450: fix dependency for use of PCRE2 instead of PCRE | |||
| 2025-05-22 | T7365: add POSIX-type lock to vyconf_session.commit for compatibility | John Estabrook | |
| We maintain compatibility with the legacy commit lock file until all other references are resolved; this requires a POSIX-type lock instead of the BSD-type lock of vyos.utils.locking. | |||
| 2025-05-22 | T7365: normalize formatting | John Estabrook | |
| 2025-05-22 | T7363: populate ConfigSourceVyconfSession methods | John Estabrook | |
| 2025-05-22 | T7363: add initialization of Config from VyconfSession | John Estabrook | |
| 2025-05-22 | T7121: add missing default version string on init from internal cache | John Estabrook | |
| 2025-05-22 | T7352: use option to load legacy config on start for interoperability | John Estabrook | |
| 2025-05-22 | T7363: distinguish config mode from op mode | John Estabrook | |
| 2025-05-22 | T7352: add util for enabling vyconf backend for smoketests | John Estabrook | |
| 2025-05-22 | T7374: add teardown session util to be called on CLI config session exit | John Estabrook | |
| 2025-05-22 | T7363: add pid aware initialization | John Estabrook | |
