Showing posts with label software release. Show all posts
Showing posts with label software release. Show all posts

Wednesday, 28 August 2013

IPFire Core Update 72 released 28AUG13




An update for IPFire has been released, the following changes have been made

obtained from http://www.ipfire.org/news/ipfire-2-13-core-update-72-released

Today, IPFire 2.13 Core Update 72 and the crowd-funded Tor add-on have been released.
The Core Update comes with a lot of feature enhancements for IPsec, smaller fixes for OpenVPN and fixed two denial-of-service attacks in the Squid web proxy.

strongswan 5.1.0

strongswan, the software package that is responsible for IPsec VPN connections, has been updated to version 5.1.0. This is a major version, which fixes various kinds of bugs and also fixes a denial-of-service bug, which is of very little priority for IPFire users (CVE-2013-5013).

Elliptic Curve Cryptography

It is now possible to use Elliptic Curve Cryptography (ECC) groups in the Internet Key Exchange (IKE) protocols in addition to the previously defined Diffie-Hellman groups. Advantages of using these include better efficiency because the underlying integer arithmetic is much faster than the binary field arithmetic MODP uses. Also ECC requires much smaller keys in order to achieve the same level of security than the Diffie-Hellman algorithm does. Therefore less entropy is consumed.

Smaller default keys

As it has often been pointed out, it is a problem to gather enough entropy on some computers. This makes it hard to do a proper key exchange, because you need to generate keys for that which are of a certain length of random data. The default settings for the key length have been very high since IPFire 2.13 and are now lowered, because of the reasons above. Instead of 8192 bits, the highest selected MODP group uses 4096 bits long keys.
More technical reasons are to be found in the comments of #10396.

squid Web Proxy server

The squid web proxy server has got two denial-of-service issues that are fixed in this Core Update. It was able to crash the cache manager when authenticating and it was possible to crash the entire proxy server with requests with over-long domain names (more information about this).

OpenVPN fixes

The OpenVPN GUI does now more precise validation of the subnet that is used as a transfer network for OpenVPN N2N connections. Incorrect data let the openvpnctrl binary crash when a new connection was started and no firewall rules were added.
It is now permitted to leave the “remote” field empty on a N2N server site, which makes creating connections with clients from dynamic IP addresses easier.
OpenVPN client connections with more than one space character in their names work again.

Misc Changes

  • snort has been enabled to decode packets from non-Ethernet devices again.
  • Dynamic DNS supports all-inkl.com now.
  • This update comes with all the requirements you need for Tor.

Tor – Protecting Online Anonymity

The Tor add-on is finally released together with Core Update 72, which you need to install first if you want to use Tor. Please make sure to reboot your IPFire system after the Tor add-on has been installed.
Documentation about this add-on can be found on our wiki: Tor documentation
We would like to thank all the people who contributed to this wish on the IPFire wishlist. If you want to, there are other things you can support, so those get implemented soon, too!

Please note a deprecation warning for Xen 3.x users!



Thursday, 8 August 2013

IPFire Core Update 71 released 06AUG13




An update for IPFire has been released, the following changes have been made

obtained from http://www.ipfire.org/news/ipfire-2-13-core-update-71-released

This is the official release announcement for IPFire 2.13 – Core Update 71. This update comes with some new features and minor bug fixes.

Wireless Client on RED

It is now possible to assign a wireless adapter as the RED interface. A GUI has been written where you can configure wireless access points, to which the IPFire system will connect when in reach.
You will be able to configure backup access points, to which IPFire will switch when the first one is down or out of reach. You can prioritize them, so that you can connect to the best one when ever that is possible. All common encryption technologies are supported.
This was funded on the IPFire wishlist a while ago, but was delayed because of lack of testers.

DNS forwarding GUI

A new GUI has been written on which you are able to define different name servers than the public name servers for your DNS zones. So, you can use your internal name server for internal name resolution instead of the public one on the Internet.

Performance improvement of squidclamav

Scanning all the HTTP traffic that is going through the proxy is very costly and makes browsing slow. In this update, we put the squidclamav process “in front of the proxy”. It now trusts the cache and won’t scan data that’s coming from the cache again which results in a huge performance increase. You now don’t even reckon that your traffic is scanned for viruses.

snort 2.9.5

The Intrusion Detection System (IDS) snort has been updated to version 2.9.5. Updating the official ruleset from sourcefire is now possible, again.
The VRT community rules package which was not available for a long time has been re-added to the list of rule sources again.

Smaller changes

  • The USB modeswitch database has been updated. This software will configure UMTS/LTE/3G USB adapters that they can be used as modems. Now, more of this hardware is supported.
  • Allow squid, the Web proxy service, to open more files and connections at once (more open file descriptors). This will result in a higher performance and better stability under high loads.
  • The whois tool for whois lookups has been replaced by GNU jwhois. It is much more flexible and does not have an outdated database like the old one.
  • squidclamav freezing when accessing sites that are also available over IPv6 has been fixed.
  • MTU negotiation on PPPoE: The default MTU for DSL lines has been 1492 which is not working on all DSL lines. If not configured correctly, your DSL connection won’t be able to transport big packets. We now allow to leave that field empty so IPFire will try to negotiate an appropriate MTU on itself.

Add-ons

  • VDR 2.0 has been pushed to the stable tree.

Tor from the IPFire wishlist

Thanks to all the people who donated for integrating Tor into IPFire. You can still support this wish or support the advanced firewall GUI.
The Tor add-on is already well advanced, because we worked day and night on it for a couple of days. We are confident that we will be able to ship it with Core Update 72. For that, we will need testers, so please stay tuned for that.



Wednesday, 17 July 2013

Avaya ERS5000 6.2.7 software released 16JUL13

A new version of software for the Avaya ERS5000 (5500 and 5600) family has been released.

Please download the software from here or using the links below


File:

ers5000v6.2.7.0.zip , 6.2.x Enterprise Device Manager COM Plug-in for ERS5000 R6.2.7

File:

ers5xxx_627_webpost.sha512.sig , 6.2.x ERS 5000 Series SHA512 Checksum File Digital Signature

File:

ers5xxx_627_webpost.sha512 , 6.2.x ERS 5000 Series SHA512 Checksum File

File:

ers5xxx_627_webpost.md5.sig , 6.2.x ERS 5000 Series MD5 Checksum File Digital Signature

File:

ers5xxx_627_webpost.md5 , 6.2.x ERS 5000 Series MD5 Checksum File

File:

5xxx_627019s.img , 6.2.x ERS 5000 Series Secure Runtime Image Software

File:

5xxx_627018.img , 6.2.x ERS 5000 Series Standard Runtime Image Software

File:

5xxx_60018_diags.bin , 6.2.x ERS 5000 Series Diagnostic Image




Problems Resolved in This Release
SNMP Query kills the Management access of the switch (wi01079031)

ERS 5530 Port state is down, the port could not be recovered until a reboot of the switch (wi01066585)

L2 traffic not working correctly on ports 29-30 of a 5632 (wi00856971)

Bootp failure for MAC Imaging Server (wi01081777)

EDMGraphical statistics of Minimum/sec values were negative for a port (wi01047631)

Full Mesh SMLT connectivity issues whenthe portswere manually bounced (wi01077465)

"show autotopology nmm-table" was not recognizing ERS4850 (wi01083032)
IST-Cluster-Member unreachable inmanagementVLAN only, after Peer-Mac is cleared(wi01082418)

ERS 5632FD 6.2.5.0 Telnet session to the SMLT interface IP on an ERS 5632 switch/stack from within ERS 8600 abruptly drops (wi01087145)

SNMP walk on ERS5000 produced inconsistent results for the MIB object ipAddressifIndex (wi01082905)

Data Access Exception tIdt occurred on non-base unit (wi01112122)

Ghost APIPA IP address appeared when scanning via SNMP tools with IP routing enabled globally (wi01074372)

VLAN configuration was corrupted on one of NBU when VLANs are created/deleted multiple times and ARP traffic is running in background (wi01112129)

On ERS55xx when the UPS was switched from AC to battery, all PoE ports went down (wi01112133)

When IGMP Query is received on a VLAN with snooping disabled, the query is not flooded not getting flooded to all ports of the VLAN (wi01097626)

Thursday, 11 July 2013

Ubiquiti Networks EdgeMAX router lite software version 1.2.0 released 9JUL12

An update for Ubiquiti Networks EdgeMAX router has been released, the following changes have been made

obtained from http://community.ubnt.com/t5/EdgeMAX-Updates-Blog/EdgeMax-software-release-v1-2-0/ba-p/510277


EdgeMax software release v1.2.0 for EdgeRouter Lite and EdgeRouter PoE is now available from our downloads page: http://www.ubnt.com/download#edgemax.

This release adds support for the newly-announced EdgeRouter PoE model, new features, and enhancements and bug fixes. Many of these are inspired and contributed by the community, so thanks everyone for your participation and contributions! :icon_smile:


[Release Notes v1.2.0]

Changes since v1.1.0

New features

  • Add support for new EdgeRouter PoE features (our Web page has more information including documentation for the EdgeRouter PoE).
  • [HW acceleration] Add hardware acceleration support for IPv6 forwarding. It is disabled by default and can be enabled using the "system ipv6-offload enable" setting.
  • [PBR] Add support for per-connection load balancing using connection marking and probabilistic matching

Changes and bug fixes

  • [HW acceleration] Improve offload algorithms for timeout-sensitive applications. This may resolve/alleviate the timeout-related issues of certain applications reported previously.
  • [HW acceleration] Improve offload algorithms for some netfilter operations
  • [PPPoE] Add pppd-related attributes to RADIUS dictionary to support RADIUS Interim Accounting Updates (RFC 2869). This was suggested and tested by community members (see this thread)!
  • [PPPoE] Allow specifying MTU 1500 for PPPoE client (RFC 4638). Note that there are still issues on the PPP side, and therefore using MTU 1500 may not work in some environments.
  • [PPPoE] Allow VLAN interfaces to be used for PPPoE server
  • [PPPoE] Don't set mru option if MTU is 1500, which enables RFC 4638 support (MTU 1500 for PPPoE) in some environments according to forum reports
  • [PPPoE] Add IPv6 settings for PPPoE client interfaces, which allows a PPPoE client interface to work with IPv6 address according to forum reports
  • [PPP] Enable IPv6 support in pppd build
  • [IPv6] Add free-form "radvd-options" setting for radvd configuration. This may be useful for users who need to use certain radvd options that are not yet in the CLI configuration (e.g., as discussed here and here), for example:
    set interfaces ethernet eth0 ipv6 router-advert radvd-options "RDNSS 2620:0:ccc::2 2620:0:ccd::2 { };"
  • [NetFlow] Add 'ingress-capture' setting for configuring where flows are captured. This is also suggested by community members in this thread.
  • [CLI] Remove unnecessary quotes from config "commands" output, for example, the output of the "show configuration commands" operation command (previously all words are quoted; now only the values are)
  • [DNS forwarding] Add "options" configuration setting to allow any dnsmasq options to be set from the configuration, for example,
    set service dns forwarding options "server=/remote.local/10.0.0.10"
  • [Webproxy] Add support for using free blacklist for URL filtering, which supports blocking based on URL categories defined in the blacklist
  • [Interface] Fix validation for duplicate IP address on bridge, tunnel, loopback, and pseudo-ethernet interfaces
  • [Interface] Disallow deleting physical interfaces from configuration. This prevents accidental deletion and is implemented after discussions with community members.
  • [Bridging] Fix offload-related performance issue with certain bridged interfaces. This should provide more consistent performance for all bridged interfaces.
  • [System] Fix CVE-2013-1427 for lighttpd
  • [System] Fix "rename system image" command
  • [PPTP] Fix attribution for PPTP client scripts/templates
  • [Web UI] Add support to show kernel routes in the Routing tab
  • [Web UI] Fix a corner case where UI may stop working after some time (e.g., days). Several community members have reported such behavior (for example this thread), and this fix may resolve the issue.
  • [Web UI] Allow specifying range of one IP for DHCP server
  • [Web UI] Allow specifying /31 addresses to interface
  • [Web UI] Fix some cosmetic issues (labels, widths, etc.)
  • [QoS] Fix commit error with active PPPoE interface
  • [Firewall] Fix commit error when applying ruleset whose creation fails
  • [Firewall] Fix handling of port names with dash
  • [Firewall] Fix "show firewall modify" command
  • [IPsec] Fix CVE-2013-2944 for strongSwan
  • [DHCP] Fix subnet validation to allow non-existent subnets, permitting DHCP relay operation, for example
  • [DHCP] Add validation to require balanced quotes in free-form parameters

Updated software components

  • Add wide-dhcpv6-client package. Note that there is no configuration support for this in the CLI yet. However, several community members have reported successes with this package (for example see discussions here and here) which is why we are including it.
  • Update krb5 to 1.8.3+dfsg-4squeeze7: Fix CVE-2002-2443
  • Add the "mtr" application
  • Update PHP to 5.3.22
  • Update bind9 to 1:9.7.3.dfsg-1~squeeze10: Fix CVE-2013-2266
  • Update curl 7.21.0-2.1+squeeze3: Fix CVE-2013-1944
  • Update ddclient to 3.8.1-1. This brings ddclient more up-to-date with better support for more providers (for example as tested by the community in this thread).
  • Update libxml2 2.7.8.dfsg-2+squeeze7: Fix CVE-2013-0338, CVE-2013-0339

IPFire Core Update 70 released 09JUL13


An update for IPFire has been released, the following changes have been made

obtained from http://www.ipfire.org/news/ipfire-2-13-core-update-70-released

Today, the IPFire development team released the 70th Core Update for IPFire 2. This update comes with a new kernel and some minor enhancements.
Before we start with the changelog, we would like to encourage you to check out the advanced firewall GUI on the IPFire wishlist. We need your help to get this done!

Kernel Update

Another kernel update to Linux 3.2.48 fixes various smaller bugs.
In addition to that, we switched back to the official in-tree drivers for Realtek r81xx-based network adapters. The kernel modules e1000e and igb which control Intel ethernet adapters have been updated as well.

Wireless Database

IPFire brings some data for wireless networks which basically contains information about which frequencies may be used in which countries. This database has been updated and covers more places in the world.

OpenVPN Net-to-Net hides transfer networks

OpenVPN Net-to-Net connections use transfer networks which are needed to route the packets. To avoid creating more firewall rules, we now hide them (and ban that they are used) from all other networks. Additionally, the firewall’s IP addresses get translated, so that they never use addresses from the transfer nets.
You may need to adjust your firewall rules. The changes are explained in detail on our wiki.
This change is a step towards the new firewall. Please support this project.

Other changes

  • Use libjpeg-turbo instead of the legacy version libjpeg 6.
  • Ship squid error pages in Turkish.
  • VLAN: Allow red0 being a virtual device.
  • DDNS: Better compatibility with DS-lite connections (100.64.0.0/10).
  • igmpproxy has been patched with patches from Deutsche Telekom to improve compatibility with their networks.

mc (4.8.8), htop (1.0.2) and transmission (2.80) have been updated as well. New packages are: keepalived (1.2.7) and ipvsadm (1.26).

We recommend that everyone updates to this version of IPFire as soon as possible. Please reboot afterwards.
If you want to support the IPFire project, please head over to our IPFire wishlist to support us!

Saturday, 22 June 2013

IPFire Core Update 69 released 21JUN13

Today, an update for IPFire has been released, the following changes have been made

obtained from http://www.ipfire.org/news/ipfire-2-13-core-update-69-released

Today, the IPFire development team released the 69th Core Update for IPFire 2. This update comes with a new kernel and some minor enhancements.
Before we start with the changelog, we would like to encourage you to check out the advanced firewall GUI on the IPFire wishlist. We need your help to get this done!

Kernel Update

The Linux kernel has been updated, to address several security issues and other bugs.
The kernel is based on Linux 3.2.46 and comes with a newer wireless stack from kernel 3.8.3.

Some wireless hardware has got better support in term of stability and we have added some more drivers for several networking hardware like USB ethernet adapters and so on. Please report any new hardware on the corresponding hardware compatibility lists.

New boot menu

The install disk has got a new bootloader, where you now can install other versions of IPFire as well. There are also some diagnostic tools and other installation options available.

Turkish Translation

A brand new translation of the IPFire installer and Web User Interface into the Turkish language has been added. Thanks for that to Ersan Yildirim.


openssh (6.2p2), strace (4.7) and tcpdump (4.4.0) have been updated as well.


We recommend that everyone updates to this version of IPFire as soon as possible. Please reboot afterwards.
If you want to support the IPFire project, please head over to our IPFire wishlist to support us!



So how do you update your IPFire installation to this latest update?

Well first login to the web interface of your IPFire installation via "https://IPFIRE_IPADDRESS:444/"  eg "https://10.0.0.1:444"

And you will be presented with the following



In the following image you can see where I have highlighted the core-update notification.  Clicking on the link is the same as clicking on the "ipfire" tab from the top menu, which brings you to the following page.



 Pakfire is advising there are two updates, the "Core-Update --2.13 -- Release 68 -> 69" and "Update: linux-pae -- Version:3.2.38 -> 3.2.46 -- Release 28 -> 29".

To update these two packages, click on the icon that I have highlighted with the orange arrow.  Pakfire will now download the updates and the following page will be displayed.





Pakfire will start downloading the updates, now depending on your internet download speed as well as the speed of your hardware you have IPFire running on this procedure could take some time.

So sit back and relax.

Once Pakfire has downloaded and installed the updates you will be presented with the following screen



IPFire is advising that the update requires a restart.  To reboot IPFire click on "system" from the top menu as highlighted by the orange arrow.

This brings you back to the main page that is opened when you first login to IPFire.



To restart to complete the update, click on the "Reboot?" button as highlighted.


IPFire will ask for confirmation


To confirm the reboot/restart, click on the "Reboot" button again and you should be presented with the following window.


Once IPFire has rebooted, you can confirm that you are running the new update by logging back in, clicking on "ipfire" from the top menu and you should be presented with the following.




Success!!