ubuntu/+source/openvpn:ubuntu/hardy-security

Last commit made on 2008-06-12
Get this branch:
git clone -b ubuntu/hardy-security https://git.launchpad.net/ubuntu/+source/openvpn
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/hardy-security
Repository:
lp:ubuntu/+source/openvpn

Recent commits

eb37981... by Jamie Strandboge on 2008-06-11

Import patches-unapplied version 2.1~rc7-1ubuntu3.3 to ubuntu/hardy-security

Imported using git-ubuntu import.

Changelog parent: df993d8545b8268f160c503652e93f9b12909cf2

New changelog entries:
  * init.c: send modulus to openssl-vulnkey rather than calling
    openssl-vulnkey on the file. This allows for password protected ssl keys
    (LP: #230197)
  * debian/control: Depends on openssl-blacklist > 0.3.2

df993d8... by Martin Pitt on 2008-05-14

Import patches-unapplied version 2.1~rc7-1ubuntu3.2 to ubuntu/hardy-security

Imported using git-ubuntu import.

Changelog parent: 8f326aa0a48f8d9fcc49bce904cffb03afe8b878

New changelog entries:
  * init.c: Do not attempt to verify the key file with openvpn-vulnkey if it
    is not accessible (any more). This happens when using the 'user', 'group',
    or 'chroot' options in multi-client mode, and the SSL key file thus
    becomes unreadable from the second time on. If the key file is not
    accessible at the very start, this is already handled anyway, so we can
    safely ignore this condition. (LP: #230208)
    Note that this is not an issue when using pre-shared keys
    (do_init_crypto_static(), since multi-client mode only works with TLS.
    However, we also check it here just to be on the safe side.

8f326aa... by Jamie Strandboge on 2008-05-13

Import patches-unapplied version 2.1~rc7-1ubuntu3.1 to ubuntu/hardy-security

Imported using git-ubuntu import.

Changelog parent: 163d1a8145775a883f813ffc58af2cf60bc902c9

New changelog entries:
  * SECURITY UPDATE: don't allow use of known vulnerable weak SSL/TLS and
    shared secret keys caused by Debian openssl bug
  * init.c: patch do_init_crypto_static() to use openvpn-vulnkey and
    do_init_crypto_tls() to use openssl-vulnkey
  * debian/control: Depends on libssl0.9.8 (>= 0.9.8g-4ubuntu3.1),
    openssl-blacklist and openvpn-blacklist
  * add critical debconf note
  * References
    CVE-2008-0166
    http://www.ubuntu.com/usn/usn-612-1

163d1a8... by Chuck Short on 2008-02-20

Import patches-unapplied version 2.1~rc7-1ubuntu3 to ubuntu/hardy

Imported using git-ubuntu import.

Changelog parent: 268e4a1af9b67b217073fd5ddaba6a1c70da880c

New changelog entries:
  * More init script LSB compliance. (LP: #134210)
  * Added warning about max-locked-memory-limit to Readme.Debian. (LP: #154696)

268e4a1... by Chuck Short on 2008-02-15

Import patches-unapplied version 2.1~rc7-1ubuntu2 to ubuntu/hardy

Imported using git-ubuntu import.

Changelog parent: 0cbfcca78bca80929eb249dbd777959fc87fc748

New changelog entries:
  * Made init script more lsb compliant.

0cbfcca... by Chuck Short on 2008-02-12

Import patches-unapplied version 2.1~rc7-1ubuntu1 to ubuntu/hardy

Imported using git-ubuntu import.

Changelog parent: f3722e4b884cf09d6b21f62f55c9bfe45aa6eeb2

New changelog entries:
  * New upstream version (LP: #157144).
  * Disable creation of tun, let udev handle it.

f3722e4... by Alberto Gonzalez Iniesta <email address hidden> on 2007-12-08

Import patches-unapplied version 2.1~rc4-2 to ubuntu/hardy

Imported using git-ubuntu import.

Changelog parent: 760f7b51472599ea8ed0331c3e1fc691a1deb3b5

New changelog entries:
  * Upload to unstable. New upstream fixes:
     - Bug with: Assertion failed at multi.c. (Closes: #411633)
     - Hangs with tcp clients goin down with new option:
       --connect-timeout. (Closes: #296834)
  * Use rm -f to remove PIDFILE, in case rm wants to ask.
    (Closes: #429932)
  * Updated Vietnamese debconf templates. (Closes: #427048)
    Thanks Clytie Siddall.
  * Added note on resolvconf use with openvpn. (Closes: #451319)
  * New upstream release
  * Just forward-push the Debian patches to the new version,
    and upload to experimental (with permission of the maintainer).

760f7b5... by Alberto Gonzalez Iniesta <email address hidden> on 2007-05-19

Import patches-unapplied version 2.0.9-8 to ubuntu/gutsy

Imported using git-ubuntu import.

Changelog parent: e715a6976041245925b8c3cbb31cb7d19ee4302e

New changelog entries:
  * Install /etc/openvpn/update-resolv-conf with correct permissions
  * Added script to update resolv.conf with server's settings.
    The script is located in the /etc/openvpn/ directory.
    Thanks a lot Christof Lauber for the script.
    Added resolvconf to Suggests.
  * Added LSB section to the init.d script.

e715a69... by Alberto Gonzalez Iniesta <email address hidden> on 2007-05-15

Import patches-unapplied version 2.0.9-6 to ubuntu/gutsy

Imported using git-ubuntu import.

Changelog parent: 6ddf31fe74bdf7712c0f63143b861472680e4fa5

New changelog entries:
  * Fixed init.d script to avoid running multiple instances of the
    same VPN. Thanks Keith Kyzivat for pushing me into looking
    again into this issue. (Closes: #326080)
  * Included patch to README.Debian from Peter Rabbitson describing
    /etc/network/interfaces integration. (Closes: #413732)
  * Also included joeyh's suggestion on the previous subject.
    (Closes: 419797)
  * Avoid restarting a vpn instead of reloading it due to wrong
    detection of 'user' option in init.d script. Thanks Josip Rodin.
    (Closes: 403503)
  * Added Russian debconf translation. (Closes: #414088)
    Thanks Yuriy Talakan.
  * Built against liblzo2 instead of liblzo. (Closes: #423366)

6ddf31f... by Alberto Gonzalez Iniesta <email address hidden> on 2007-02-27

Import patches-unapplied version 2.0.9-5 to ubuntu/feisty

Imported using git-ubuntu import.

Changelog parent: 6fdc2a01c447ff08d06588221132d10f6050a7ae

New changelog entries:
  * Added Galician debconf translation. (Closes: #412492)
    Thanks Jacobo Tarrio
  * Updated Swedish debconf translation. (Closes: #407851)
    Thanks Andreas Henriksson
  * Fixed type in Portuguese debconf translation.
  * debian/templates. Changed default value for init.d change
    question to false. (Closes: #403317)