Commit graph

1225 commits

Author SHA1 Message Date
taca
94c055cd9c Update rats package to 1.4. Changes from news release.
April 22, 2002

New releases of RATS and EGADS

RATS 1.4 and EGADS 0.9 have been released. In addition to bugfixes for
both RATS and EGADS, RATS 1.4 includes additional win32 functions in
the database.
2002-05-03 14:14:23 +00:00
shell
a55ab75bd0 Updated p5-Digest-MD5 to 2.17
- Fixed COMMENT
- Updated DESCR

Changes :
- The SvPVbyte in perl-5.6.1 is buggy.  Use the one from 5.7.3
  instead.
- Give warning if the function interface is used as instance
  methods:  $md5->md5_hex().
2002-04-27 19:07:35 +00:00
lukem
7780aa8486 Store vulnerabilities file in ${PKGVULNDIR} instead of ${DISTDIR}, in case
the latter is not appropriate.  The former defaults to the latter.
Bump version to 1.12.  Per discussion with Alistair Crooks.
2002-04-26 12:45:23 +00:00
itojun
66899f40f3 upgrade to 20020426a from kame.
file descriptor leak fix.
null encryption algorithm key length fix (should use 0).
couple of null-pointer reference fixes.
set port # to 500 in ID payload (possible interop issue - spec is unclear).
correctly match address pair on informational exchange.
2002-04-26 00:08:21 +00:00
jschauma
a0028b4b58 Update to sudo 1.6.6 to fix local root-exploit-possibility as per
http://www.globalintersec.com/adv/sudo-2002041701.txt

(Approved by hubertf.)
2002-04-25 16:57:13 +00:00
martti
7603c13dfb Make this depend on OpenSSL 0.9.6. This fixes the compilation problems
in NetBSD 1.5.x.
2002-04-24 05:43:08 +00:00
martti
9692db4de4 Fix the USE_OPENSSL_VERSION setting 2002-04-24 05:40:49 +00:00
martti
948db44078 Updated openssh to 3.1.1
* a lot of bug fixes
2002-04-23 13:32:56 +00:00
shell
7c8993b519 Updated to p5-IO-Socket-SSL-0.81
- fmt on DESCR

Changes :

 - calling context_init twice destroyed global context. fix from
   Jason Heiss <jheiss@ofb.net>.
 - file handle tying interface implementation moved to a separate
   class to prevent problems resulting from self-tying filehandles.
   Harmon S. Nine <hnine@netarx.com>.
 - docs/debugging.txt file added
 - require Net::SSLeay v1.08
 - preliminary support for non-blocking read/write
 - socketToSSL() now respects context's SSL verify setting
   reported by Uri Guttman <uri@stemsystems.com>.
2002-04-17 11:10:44 +00:00
shell
58e9e7a5a3 Updated to p5-Net-SSLeay-1.15
- change my email address

Changes since p5-Net-SSLeay-1.13 :

- added code to Makefile.PL to verify that the same C compiler
  is used for both perl and openssl
- added code to Makefile.PL to support aCC on HPUX. Detective
  work contributed by Marko Asplund.
- added peer certificate support to hilevel API, inspired
  by mock@@_obscurity.org
- added `use bytes' from Marcus Taylor <marcus@@semantico_.com>
  This avoids unicode/utf8 (as may appear in some XML docs)
  from fooling the length comuptations.
2002-04-17 11:06:54 +00:00
itojun
52aecdad87 *** empty log message *** 2002-04-16 02:34:34 +00:00
itojun
49518a4001 correct initial contact handling. PR 15949 2002-04-15 02:00:03 +00:00
itojun
f6630f026f sync version number compiled into binary with pkg version 2002-04-15 01:55:05 +00:00
veego
84fc29abe9 Another week, another update and no old distfile.
This time dat-4196.
2002-04-13 21:38:40 +00:00
jlam
eb5d91e2c5 Use libmcrypt22 instead of libmcrypt. Reported to fix pkg/16198 by
Stephen Borrill <netbsd@precedence.co.uk>.
2002-04-12 19:03:34 +00:00
jlam
b5495ed46c Add and enable security/libmcrypt22. 2002-04-12 19:00:12 +00:00
jlam
a68e218eca Older 2.2.x release of libmcrypt provided for those apps for which the
newer libmcrypt (>=2.4.x) seem to cause core dumps.

Import approved by Alistair <agc@netbsd.org>.
2002-04-12 18:59:36 +00:00
mrauch
83396d566c This package installs binaries compiled for the NetBSD 1.2 and 1.3 releases
and so needs the emulation packages if we run on a later release.
2002-04-12 15:17:22 +00:00
wennmach
58dba79df2 Correct Size(xdm-krb4-3.3.6.3.tar.gz) 2002-04-11 12:52:57 +00:00
schmonz
6af3775516 Update to 1.9, and remove unneeded dependency on sysutils/psmisc.
OK'd by martti and garbled.

Changelog:

  04 Mar 2002; changed license from "GPL, v2 or later" to "GPL v2".

  04 Mar 2002; added "keychain.cygwin" for Cygwin systems.  It may be time to
  follow this pattern and start building separate, optimized scripts for each
  platform so they don't get too sluggish.  Maybe I could use a C preprocessor
  for this.

  06 Dec 2001; several people: Solaris doesn't like '-e' comparisons; switched
  to '-f'
2002-04-10 17:52:08 +00:00
zuntum
9a9fec802a Update uvscan-dat to 4195
o move virus definitions
2002-04-10 07:20:18 +00:00
wennmach
09a1659f8a Update xdm-krb4 to 3.3.6.3
Rationale: get rid of the dependency on kth-krb4 on NetBSD>=1.5 systems.
For older systems, we provide full functionality via a (now buildlinked)
kth-krb4.
2002-04-05 11:49:37 +00:00
wennmach
6879bc7809 Update kth-krb4 to 1.1.1.
This is a prerequisite step for the new arla version (0.35.7).
While here, buildlinkify.
2002-04-05 11:32:19 +00:00
tron
b6343d0c10 Use "suse_linux/Makefile.application" to pick correct SuSE packages. 2002-04-04 12:29:46 +00:00
martti
8ad41b9c82 Added etc/rc.d/isakmpd 2002-04-04 09:46:03 +00:00
martti
bfdb1ddf87 Install a simle startup script (${PREFIX}/etc/rc.d/isakmpd) 2002-04-04 09:42:27 +00:00
martti
66722fd01e Updated isakmpd to 20020403
- Change DH group handling in the pre-generated parts of the
  configuration. Add a -GRP{1,2,5} component to transform and suite
  names to directly specify which group to use. If no group is
  specified, use DH group 2 (MODP_1024). Earlier transforms and suites
  using the MD5 hash defaulted to DH group 1, this is no longer true.
- Unbreak MD5 and SHA1 passphrases in policy check.
- Don't message_dump_raw() bad length messages, i.e too short.
- Fix a couple of snprintf length bugs.
- Compile without warnings for older/newer OpenSSL.
2002-04-03 12:31:56 +00:00
itojun
c851ba3b66 enable IPv6. 2002-04-03 02:09:54 +00:00
seb
28a2fa7f4e Protect inclusion of sys/cdefs.h in configure code checking for tcp_wrappers.
This helps on Solaris.
2002-04-02 11:20:11 +00:00
seb
d64334720f Add a `keygen' "target" for non-rc.subr systems so sshd_precmd() actually works. 2002-04-02 10:14:42 +00:00
hubertf
f610f59c50 Mark this package as interactive on sparc64. Compiling it needs attention
so the compiler is killed when it spins.

XXX needs fixing
2002-03-29 17:20:10 +00:00
wennmach
3397d3ec4c The command line changes can be found in pgp5(1), not in pgp(1). 2002-03-26 18:14:11 +00:00
jmc
5b615520d6 Fix typo in BUILD_DEPENDS line 2002-03-25 00:34:12 +00:00
wiz
dc41591fd2 Make it compile with SASL_USE_GSSAPI=YES. Closes pkg/16040 by
Rodolphe de SAINT LEGER.
2002-03-24 23:30:18 +00:00
itojun
f87f0472ac darwin has opensslv.h in /usr/local/include/openssl 2002-03-23 19:21:47 +00:00
itojun
2c844803e5 upgrade netramet to 4.4 (version is 4.4.20 to prevent version skew)
PR 15799

NeTraMet Version History
========================

v4.4	20 Feb 02
			In examples/ directory, moved old rules.* examples
			to non_srl.  The srl examples are now in the
			examples/ directory.

			SNMP security issues.  I've tested NeTraMet's
			SNMP code using the PROTOS test suite.  A test
			for negative lengths in the ASN.1 parsing code
			has been added - that was the only change needed.

			The SNMP routines (in snmplib/) perform a lot of
			parameter checks, and calls on an ERROR() define.
			By default ERROR does nothing.  If you're tesing
			an SNMP manager against NeTraMet, you can turn
			those messages on by adding -DDEBUG to the CFLAGS=
			line in snmplib/Makefile and rebuilding the
			snmp library.

			Change 'interface number' attributes to use
			16-bit integers instead of 8-bit.  This can
			be useful when using NetFlowMet.


v4.4b11 25 Nov 01	Implement -C option for nm_rc, exactly as in
			NeMaC.  This allows you to use nm_rc to test
			rulesets against trace files being read by
			crl_ntm or dd_ntm.  Sample commands to do this
			are:
			  ./crl_ntm -T5 -m1234 -Strace_file -wW~com
			  ./nm_rc -C -m1234 -rpeers.rules localhost W~com
			Note: you need CoralReef version 3.5 to build
                              crl_ntm!

			Speed improvements in flowhash:
			 - move code which doesn't need to be executed
			     on every call outside blocks in match()
			 - implement list of running rulesets, instead
			     of doing serial searches of ri[] table
			 - use 32-bit hash values for flow and stream
			     hash tables, use table size specified by
			     user (rather than trying to pick a prime
			     above it - that doesn't help, since we
			     use a set of distinct primes for hashing)

			Use long long integers (8 bytes) for counter64
			if the host supports them.  Newer Pentiums do,
			this provides a useful speedup.

			Change 'shutdown' request character.  It was
			a single ESC, but it's too easy to hit a key
			which sends an escape sequence!  Now you have
			to type ESC ESC Return to shut down the meter.

			Fix little problems which gave warning messages
			when building NeTraMet on an alpha running
			Digital Unix.  The configure script wasn't
			recognising the OS correctly; this didn't
			cause problems because none of the programs
			have defines testing this any more.

			MinPDUs gave compilation errors on alpha,
			fixed by adding c64geint() define.

			Linux kernel reset promiscuous mode when
			forking a NeTraMet daemon.  Changed meter_ux.c
			to fork first, then open the interfaces.

			NeTraMet, NetFlowMet, LfapMet, crl_ntm, dd_ntm
			(i.e. all the meters) write error messages and
			summary information to a log file using log_msg(),
			in the same way as NeMaC.  The name of the log
			file is meter.log, it will be written in the
			directory where the meter starts running.


v4.4b10	23 May 01	LfapMet: RTFM meter for LFAP, code contributed
                          by Remco Poortinga, <r.poortinga@home.nl>
			Added files in src/meter
			 - README_LfapMet  Notes about LfapMet
			 - lfapmet.h       LfapMet globals
			 - lfapmet.c       LfapMet support routines

			Added two new MIB variables to reader row,
			MinPDUs (default 0) and TimeMark.  A flow must
			have at least MinPDUs either to or from before
			it will be read by a meter reader.  TimeMark
			is needed to associate an SNMP  getnext request
			with a particular reader.

			MinPDUs can be set using the -M option.
			nifty default is -M20, NeMaC default is -M0

			Improved save.sav so that it only saves the
			files we really need in the NeTraMet distribution.


v4.4b9	11 Apr 01	Fixed bug in NeMaC include statement.
			getarg() no longer allows semicolon in an
			argument.

			Fixed srl compiler bug; optimise 3 wasn't
			recognising the end of AND expressions
			properly.

			NeMaC could fail to open a flow data file
			(e.g. because it already existed with
			no write access); it now reports this
			and doesn't try to run that meter/ruleset.

			NeTraMet Coral interface improved to handle
			two Dag cards properly.  Reads blocks of
			cells from each then merges them by timestamp.

			NeTraMet uses -Siii to specify a Coral source
			(instead of -C'source iii' *****).
2002-03-22 03:48:18 +00:00
fredb
2582627a7d Another ruby package needs to have it's dependency on ruby-base bumped
because of the change to ${MACHINE_GNU_PLATFORM}.
2002-03-21 04:57:54 +00:00
taca
9ca501b03c Update zebedee package to 2.3.1.
- USE_GMAKE.
- use tcl's buildlink.mk.

* Release 2.3.1 (2002/03/15)

Changed any potentially unsafe sprintf/vsprintf instances to
snprintf/vsnprintf. There should never have been a remote exploit possible,
this just eliminates any theoretical local ones in case someone has a reason
to run this as root ... (Note that use of these functions may be an issue
on some platforms although they do appear in the UNIX98 spec and exist
on Windows).

Allowed CIDR address specifications for target (and server name in listenmode).

Added IP address checking with the "checkaddress" keyword.

Finally caved in and added "httpproxy" to allow connection via a web proxy
server using "CONNECT".

Added "transparent" keyword to attempt to act as a transparent proxy and
forward on the client IP address. It may work on Linux 2.0/2.2. But then
again, it might not ...

* Release 2.3.0 (2002/03/07)

New functionality (at last!).

Added "listenip" and -b option to set listening address.

Added "tcptimeout" and "idletimeout" to allow inactive TCP tunnels to be
closed.

Added "ipmode" and -U option to support mixed traffic mode for a single
client or server.

Makefile changes for Irix and HPUX from Kyle Dent. Others to use latest
version of mingw gcc and force use of "native" perl.

Note that Zebedee will now be linked with MSVCRT.DLL. That should only
be a problem on an old Win95 machine.

Japanese documentation NOT YET updated.
2002-03-20 15:16:30 +00:00
taca
3cb166de84 Mark this package for ruby-1.4 base.
Since ruby 1.6.6 and lator have digest/sha1 library.
2002-03-17 15:25:43 +00:00
uebayasi
e94f4691ac Add buildlink.mk (which is shamelessly copied from another one). 2002-03-17 14:53:57 +00:00
uebayasi
64caae7c22 Add GPGME (security/gpgme). 2002-03-17 13:34:32 +00:00
uebayasi
15c7d990d0 Initial import of GPGME 0.3.0.
From DESCR:

	GnuPG Made Easy (GPGME) is a library designed to make access to GnuPG
	easier for applications. It provides a High-Level Crypto API for
	encryption, decryption, signing, signature verification and key
	management.
2002-03-17 13:33:40 +00:00
skrll
fb13e12d3b Another target that does the same job as AUTOMAKE_OVERRIDE bites the dust. 2002-03-15 17:17:45 +00:00
martti
4c95e5d30a Updated p5-Net-SSLeay to 1.13 (provided by Shell Hung in pkg/15604)
- eliminated initializing random numbers using /etc/passwd per
  comments by Matt Messier <matt@@securesw_.com>
- tested against openssl-0.9.6c (not in pkg now :-)
2002-03-15 12:42:17 +00:00
wiz
ba70219030 Fix compilation on 1.4.2 (sync with patch-ab).
Addresses pkg/15849.
2002-03-14 13:07:32 +00:00
wiz
837ac02891 Shorten comment. 2002-03-14 12:35:59 +00:00
wiz
180d1b814a regen 2002-03-14 12:33:08 +00:00
wiz
25f9b48b64 Standardize patches. 2002-03-14 12:33:00 +00:00
wiz
0c39bad777 Disable "bad" assembler (gcc-2.95.3 does not want to compile it).
Closes pkg/15138.
2002-03-14 12:32:40 +00:00
wiz
a2121b2d1a Standardize patch. 2002-03-14 12:26:46 +00:00