strongswan 5.7.2-1ubuntu1 source package in Ubuntu

Changelog

strongswan (5.7.2-1ubuntu1) eoan; urgency=medium

  [ Christian Ehrhardt ]
  * Merge with Debian unstable. Remaining changes:
    - Clean up d/strongswan-starter.postinst: section about runlevel changes
    - Clean up d/strongswan-starter.postinst: Removed entire section on
      opportunistic encryption disabling - this was never in strongSwan and
      won't be see upstream issue #2160.
    - d/rules: Removed patching ipsec.conf on build (not using the
      debconf-managed config.)
    - d/ipsec.secrets.proto: Removed ipsec.secrets.inc reference (was
      used for debconf-managed include of private key).
    - Mass enablement of extra plugins and features to allow a user to use
      strongswan for a variety of extra use cases without having to rebuild.
      + d/control: Add required additional build-deps
      + d/control: Mention addtionally enabled plugins
      + d/rules: Enable features at configure stage
      + d/libbstrongswan-extra-plugins.install: Add plugins (so, lib, conf)
      + d/libstrongswan.install: Add plugins (so, conf)
      + d/strongswan-starter.install: Install pool feature, which is useful
        since we now have attr-sql plugin enabled it.
    - Add plugin kernel-libipsec to allow the use of strongswan in containers
      via this userspace implementation (please do note that this is still
      considered experimental by upstream).
      + d/libcharon-extra-plugins.install: Add kernel-libipsec components
      + d/control: List kernel-libipsec plugin at extra plugins description
      + d/p/dont-load-kernel-libipsec-plugin-by-default.patch: As
        upstream recommends to not load kernel-libipsec by default.
    - d/libstrongswan.install: Add kernel-netlink configuration files
    - Complete the disabling of libfast; This was partially accepted in Debian,
      it is no more packaging medcli and medsrv, but still builds and
      mentions it.
      + d/rules: Add --disable-fast to avoid build time and dependencies
      + d/control: Remove medcli, medsrv from package description
    - d/control: Mention mgf1 plugin which is in libstrongswan now
    - Add now built (since 5.5.1) libraries libtpmtss and nttfft to
      libstrongswan-extra-plugins (no deps from default plugins).
    - d/control, d/libcharon-{extras,standard}-plugins.install: Move charon
      plugins for the most common use cases from extra-plugins into a new
      standard-plugins package. This will allow those use cases without pulling
      in too much more plugins (a bit like the tnc package). Recommend that
      package from strongswan-libcharon.
    - d/usr.sbin.charon-systemd: allow to contact mysql for sql and
      attr-sql plugins (LP #1766240)
    - d/usr.lib.ipsec.charon: allow reading of own FDs (LP #1786250)
    - d/usr.sbin.charon-systemd: allow CLUSTERIP for ha plugin (LP: 1773956)
    - executables need to be able to read map and execute themselves otherwise
      execution in some environments e.g. containers is blocked (LP: 1780534)
      + d/usr.lib.ipsec.stroke: add rmix permission to stroke binary
      + d/usr.lib.ipsec.lookip: add rmix permission to lookip binary
    - d/usr.lib.ipsec.charon, d/usr.sbin.charon-systemd: resync apparmor
      profiles of both ways to start charon (LP: 1807664)
    - d/usr.sbin.swanctl: add apparmor rule for af-alg plugin (LP: 1807962)
  * Dropped changes
    - d/p/lp1795813-mysql-Don-t-release-the-connection-if-transactions-a.patch:
      fix SIGSEGV when using mysql plugin (LP: 1795813)
      [upstream in 5.7.2]
    - d/libstrongswan.install: Reorder conf and .so alphabetically
      [was a non functional change, dropped to avoid merge noise]
    - Relocate tnc plugin
      [TNC is back at libcharon-extra-plugins as it is in Debian]
  * Added changes:
    - We fixed up tpmtss and nttfft in the past, but tpmtss is now packaged in
      Debian so this part was be dropped. Two changes remain
      - d/control: fix the mentioning of tpmtss in d/control
      - add nttfft (can be merged with the mass enablement change later)
    - Transitional packages to go back from strongswan-tnc-* being in extra
      packages to be part of libcharon-extra-plugins.
      [can be dropped after 20.04]

  [ Simon Deziel ]
  * Added changes:
    - apparmor fixes for container and root usage (LP: #1826238)
      + d/usr.sbin.swanctl: allow reading own binary
      + d/usr.sbin.charon-systemd: allow accessing the binary
      + d/usr.sbin.swanctl: add attach_disconnected to work inside containers
      + d/usr.lib.ipsec.charon, d/usr.sbin.charon-systemd: add CAP_SETPCAP
        to apparmor to allow dropping caps

strongswan (5.7.2-1) unstable; urgency=medium

  * d/control: remove Rene from Uploaders, thanks!
  * d/copyright: fix typos
  * d/watch: use HTTPS protocol
  * d/control: update standards version to 4.2.1
  * drop unused debconf template
  * use a clean export for upstream signing key
  * d/copyright update
  * New upstream version 5.7.2
  * d/copyright updated
  * d/control: update standards version to 4.3.0
  * d/libstrongswan.dirs: drop lintian overrides dir
  * d/u/signing-key.asc: strip signatures from upstream signing key
  * d/patches: import patches in gbp pq

 -- Christian Ehrhardt <email address hidden>  Fri, 26 Apr 2019 11:31:17 +0200

Upload details

Uploaded by:
Christian Ehrhardt 
Uploaded to:
Eoan
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
net
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
strongswan_5.7.2.orig.tar.bz2 4.8 MiB 308e3ba76e2ce2da070e48fcebbe1fa923a27cc71e43bf63917e6f2a889ecc70
strongswan_5.7.2-1ubuntu1.debian.tar.xz 123.4 KiB 9bff20a4669b9322e1b6018ac313a76d5cc9f9cc8bc65c8de6c2abf0cbe59259
strongswan_5.7.2-1ubuntu1.dsc 3.8 KiB fceb9e2ee6a64f49a7d19cb36867415984c4d12a3ef2d28fe27bae0fb9217dbb

Available diffs

View changes file

Binary packages built by this source

charon-cmd: No summary available for charon-cmd in ubuntu eoan.

No description available for charon-cmd in ubuntu eoan.

charon-cmd-dbgsym: No summary available for charon-cmd-dbgsym in ubuntu eoan.

No description available for charon-cmd-dbgsym in ubuntu eoan.

charon-systemd: No summary available for charon-systemd in ubuntu eoan.

No description available for charon-systemd in ubuntu eoan.

charon-systemd-dbgsym: No summary available for charon-systemd-dbgsym in ubuntu eoan.

No description available for charon-systemd-dbgsym in ubuntu eoan.

libcharon-extra-plugins: No summary available for libcharon-extra-plugins in ubuntu eoan.

No description available for libcharon-extra-plugins in ubuntu eoan.

libcharon-extra-plugins-dbgsym: No summary available for libcharon-extra-plugins-dbgsym in ubuntu eoan.

No description available for libcharon-extra-plugins-dbgsym in ubuntu eoan.

libcharon-standard-plugins: No summary available for libcharon-standard-plugins in ubuntu eoan.

No description available for libcharon-standard-plugins in ubuntu eoan.

libcharon-standard-plugins-dbgsym: No summary available for libcharon-standard-plugins-dbgsym in ubuntu eoan.

No description available for libcharon-standard-plugins-dbgsym in ubuntu eoan.

libstrongswan: No summary available for libstrongswan in ubuntu eoan.

No description available for libstrongswan in ubuntu eoan.

libstrongswan-dbgsym: No summary available for libstrongswan-dbgsym in ubuntu eoan.

No description available for libstrongswan-dbgsym in ubuntu eoan.

libstrongswan-extra-plugins: No summary available for libstrongswan-extra-plugins in ubuntu eoan.

No description available for libstrongswan-extra-plugins in ubuntu eoan.

libstrongswan-extra-plugins-dbgsym: No summary available for libstrongswan-extra-plugins-dbgsym in ubuntu eoan.

No description available for libstrongswan-extra-plugins-dbgsym in ubuntu eoan.

libstrongswan-standard-plugins: No summary available for libstrongswan-standard-plugins in ubuntu eoan.

No description available for libstrongswan-standard-plugins in ubuntu eoan.

libstrongswan-standard-plugins-dbgsym: No summary available for libstrongswan-standard-plugins-dbgsym in ubuntu eoan.

No description available for libstrongswan-standard-plugins-dbgsym in ubuntu eoan.

strongswan: No summary available for strongswan in ubuntu eoan.

No description available for strongswan in ubuntu eoan.

strongswan-charon: No summary available for strongswan-charon in ubuntu eoan.

No description available for strongswan-charon in ubuntu eoan.

strongswan-charon-dbgsym: No summary available for strongswan-charon-dbgsym in ubuntu eoan.

No description available for strongswan-charon-dbgsym in ubuntu eoan.

strongswan-libcharon: No summary available for strongswan-libcharon in ubuntu eoan.

No description available for strongswan-libcharon in ubuntu eoan.

strongswan-libcharon-dbgsym: No summary available for strongswan-libcharon-dbgsym in ubuntu eoan.

No description available for strongswan-libcharon-dbgsym in ubuntu eoan.

strongswan-nm: No summary available for strongswan-nm in ubuntu eoan.

No description available for strongswan-nm in ubuntu eoan.

strongswan-nm-dbgsym: No summary available for strongswan-nm-dbgsym in ubuntu eoan.

No description available for strongswan-nm-dbgsym in ubuntu eoan.

strongswan-pki: No summary available for strongswan-pki in ubuntu eoan.

No description available for strongswan-pki in ubuntu eoan.

strongswan-pki-dbgsym: No summary available for strongswan-pki-dbgsym in ubuntu eoan.

No description available for strongswan-pki-dbgsym in ubuntu eoan.

strongswan-scepclient: No summary available for strongswan-scepclient in ubuntu eoan.

No description available for strongswan-scepclient in ubuntu eoan.

strongswan-scepclient-dbgsym: No summary available for strongswan-scepclient-dbgsym in ubuntu eoan.

No description available for strongswan-scepclient-dbgsym in ubuntu eoan.

strongswan-starter: No summary available for strongswan-starter in ubuntu eoan.

No description available for strongswan-starter in ubuntu eoan.

strongswan-starter-dbgsym: No summary available for strongswan-starter-dbgsym in ubuntu eoan.

No description available for strongswan-starter-dbgsym in ubuntu eoan.

strongswan-swanctl: No summary available for strongswan-swanctl in ubuntu eoan.

No description available for strongswan-swanctl in ubuntu eoan.

strongswan-swanctl-dbgsym: No summary available for strongswan-swanctl-dbgsym in ubuntu eoan.

No description available for strongswan-swanctl-dbgsym in ubuntu eoan.

strongswan-tnc-base: No summary available for strongswan-tnc-base in ubuntu eoan.

No description available for strongswan-tnc-base in ubuntu eoan.

strongswan-tnc-client: No summary available for strongswan-tnc-client in ubuntu eoan.

No description available for strongswan-tnc-client in ubuntu eoan.

strongswan-tnc-ifmap: No summary available for strongswan-tnc-ifmap in ubuntu eoan.

No description available for strongswan-tnc-ifmap in ubuntu eoan.

strongswan-tnc-pdp: No summary available for strongswan-tnc-pdp in ubuntu eoan.

No description available for strongswan-tnc-pdp in ubuntu eoan.

strongswan-tnc-server: No summary available for strongswan-tnc-server in ubuntu eoan.

No description available for strongswan-tnc-server in ubuntu eoan.