/[smecontribs]/rpms/smeserver-coova-chilli/contribs7/smeserver-coova-chilli.spec
ViewVC logotype

Annotation of /rpms/smeserver-coova-chilli/contribs7/smeserver-coova-chilli.spec

Parent Directory Parent Directory | Revision Log Revision Log | View Revision Graph Revision Graph


Revision 1.31 - (hide annotations) (download)
Tue Jul 20 13:43:28 2010 UTC (13 years, 10 months ago) by vip-ire
Branch: MAIN
CVS Tags: smeserver-coova-chilli-0_2-17_el4_sme
Changes since 1.30: +17 -2 lines
* Mon Jul 19 2010 Daniel B. <daniel@firewall-services.com> 0.2-17
- Fixes sudo env (bug only in SME8)
- Uses TCPPort squid key instead of TransparentPort so coova can
  work with dansguardian
- insert NAT rule just before the ACCEPT (PREROUTING_FROM_CHILLI)
- add transparent directive to squid (required for squid => 2.6)

1 vip-ire 1.31 # $Id: smeserver-coova-chilli.spec,v 1.30 2010/04/14 16:38:56 vip-ire Exp $
2 slords 1.7 # Authority: vip-ire
3     # Name: Daniel Berteaud
4    
5 slords 1.1 Summary: Coova-Chilli, a captive portal based on ChilliSpot configured for SME server
6     %define name smeserver-coova-chilli
7     Name: %{name}
8 slords 1.15 %define version 0.2
9 vip-ire 1.31 %define release 17
10 slords 1.1 Version: %{version}
11 vip-ire 1.5 Release: %{release}%{?dist}
12 vip-ire 1.4 License: GPL
13 slords 1.1 Group: Networking/Remote access
14     Source: %{name}-%{version}.tar.gz
15     URL: http://sme.firewall-services.com
16     BuildRoot: /var/tmp/%{name}-%{version}-%{release}-buildroot
17     BuildArchitectures: noarch
18 vip-ire 1.6 BuildRequires: e-smith-devtools
19 snetram 1.8 Requires: e-smith-release >= 7.0
20     Requires: openssl
21 vip-ire 1.26 Requires: coova-chilli >= 1.0.13
22 vip-ire 1.10 Requires: e-smith-radiusd >= 1.0.0-18
23 vip-ire 1.18 Requires: perl(NetAddr::IP)
24 vip-ire 1.26 Requires: smeserver-remoteuseraccess
25 vip-ire 1.3
26 slords 1.15 Patch1: smeserver-coova-chilli-0.2-guest_uplink_downlink.patch
27     Patch2: smeserver-coova-chilli-0.2-guest_access.patch
28 vip-ire 1.17 Patch3: smeserver-coova-chilli-0.2-chilli_ip.patch
29     Patch4: smeserver-coova-chilli-0.2-radius_timeout.patch
30     Patch5: smeserver-coova-chilli-0.2-guest_access2.patch
31 vip-ire 1.18 Patch6: smeserver-coova-chilli-0.2-template_syntax_error.patch
32 vip-ire 1.19 Patch7: smeserver-coova-chilli-0.2-httpd_warning.patch
33 vip-ire 1.22 Patch8: smeserver-coova-chilli-0.2-tundev.patch
34 vip-ire 1.23 Patch9: smeserver-coova-chilli-0.2-dhcp_range.patch
35 vip-ire 1.24 Patch10: smeserver-coova-chilli-0.2-localhost_nas.patch
36     Patch11: smeserver-coova-chilli-0.2-localhost_nas2.patch
37     Patch12: smeserver-coova-chilli-0.2-squid_template_typo.patch
38 vip-ire 1.25 Patch13: smeserver-coova-chilli-0.2-typo.patch
39 vip-ire 1.26 Patch14: smeserver-coova-chilli-0.2-allow_uamallowed.patch
40     Patch15: smeserver-coova-chilli-0.2-drop_privileges.patch
41     Patch16: smeserver-coova-chilli-0.2-use_sudo.patch
42     Patch17: smeserver-coova-chilli-0.2-templates2expand_in_createlinks.patch
43 vip-ire 1.27 Patch18: smeserver-coova-chilli-0.2-db_noc2c.patch
44 vip-ire 1.28 Patch19: smeserver-coova-chilli-0.2-remove_space.patch
45 vip-ire 1.29 Patch20: smeserver-coova-chilli-0.2-fixe_allow_uamallowed.patch
46 vip-ire 1.30 Patch21: smeserver-coova-chilli-0.2-fixe_squid_disabled.patch
47 vip-ire 1.31 Patch22: smeserver-coova-chilli-0.2-squid_tcpport.patch
48     Patch23: smeserver-coova-chilli-0.2-sudo_env.patch
49     Patch24: smeserver-coova-chilli-0.2-iptables_insert_position.patch
50     Patch25: smeserver-coova-chilli-0.2-transparent_squid.patch
51 slords 1.1
52     %description
53     This package allow you to configure a third interface
54     (eth2). Just plug a WiFi AP on it, and you'll have
55     a secured captive portal. Users will be redirected
56     on a logon page and they'll have to enter credentials
57     (sme accounts) before the server allows them. By default,
58 vip-ire 1.5 they'll only have web access if they are members of the group "chilli"
59     This contrib will only work in server&gateway mode
60 slords 1.1
61     %changelog
62 vip-ire 1.31 * Mon Jul 19 2010 Daniel B. <daniel@firewall-services.com> 0.2-17
63     - Fixes sudo env (bug only in SME8)
64     - Uses TCPPort squid key instead of TransparentPort so coova can
65     work with dansguardian
66     - insert NAT rule just before the ACCEPT (PREROUTING_FROM_CHILLI)
67     - add transparent directive to squid (required for squid => 2.6)
68    
69 vip-ire 1.30 * Wed Apr 14 2010 Daniel B. <daniel@firewall-services.com> 0.2-16
70     - Fixe a bug in conup.sh and condown.sh
71    
72 vip-ire 1.29 * Thu Jun 11 2009 Daniel B. <daniel@firewall-services.com> 0.2-15
73     - Fixe a bug in masq template for uamallowed entries
74    
75 vip-ire 1.28 * Thu May 28 2009 Daniel B. <daniel@firewall-services.com> 0.2-14
76     - Remove space in hotspot-config.pl template
77    
78 vip-ire 1.27 * Tue May 26 2009 Daniel B. <daniel@firewall-services.com> 0.2-13
79     - Add noc2c key (allow to disable the option, but default to enabled)
80    
81 vip-ire 1.26 * Thu Apr 30 2009 Daniel B. <daniel@firewall-services.com> 0.2-12
82     - Create a new user coovachilli
83     - Add support of new options uid and gid to drop privileges
84     - Enabled noc2c (prevent client to client communication)
85     - Use sudo to call conup/condown script (as chilli runs under un
86     unprivileged account now)
87     - Add smeserver-remoteuseraccess as a dependency (for sudoers metadata templates)
88     - move templates2expand in creatlinks script
89    
90     * Wed Mar 13 2009 Daniel B. <daniel@firewall-services.com> 0.2-11
91     - Automatically allow uamallowed entries in the firewall (no need to
92     explicitly allow it agin in AllowOutgoing)
93    
94 vip-ire 1.25 * Thu Mar 12 2009 Daniel B. <daniel@firewall-services.com> 0.2-10
95     - Small typo correction
96    
97 vip-ire 1.24 * Tue Mar 10 2009 Daniel B. <daniel@firewall-services.com> 0.2-9
98     - Use allready defined localhost NAS to fixe PPTP problem [SME: 4996]
99     (thanks John K Pruder)
100     - fix a typo in squid template
101    
102 vip-ire 1.23 * Sun Mar 07 2009 Daniel B. <daniel@firewall-services.com> 0.2-8
103 vip-ire 1.24 - Add dhcpstart and dhcpstop db parameters (thanks John K Pruder)
104 vip-ire 1.23
105 vip-ire 1.22 * Sun Mar 07 2009 Daniel B. <daniel@firewall-services.com> 0.2-7
106     - Fix tundev template [SME: 5054]
107    
108 vip-ire 1.19 * Thu Sep 18 2008 Daniel B. <daniel@firewall-services.com> 0.2-6
109     - Remove warning in httpd.conf file (httpd -t)
110    
111 vip-ire 1.18 * Mon Sep 15 2008 Daniel B. <daniel@firewall-services.com> 0.2-5
112 vip-ire 1.22 - Fix Syntax Error in /etc/chilli.conf template (25listen) [SME: 4559]
113 vip-ire 1.18
114     * Mon Sep 08 2008 Daniel B. <daniel@firewall-services.com> 0.2-4
115     - Requires perl(NetAddr::IP)
116    
117 vip-ire 1.17 * Fri Sep 5 2008 Daniel B. <daniel@firewall-services.com> 0.2-3
118     - Chilli IP computed with NetAddr::IP
119     - Radius timeout set to 3 sec
120     - syntax error in radius users template fixed (for guest access)
121    
122 slords 1.15 * Thu Sep 3 2008 Daniel B. <daniel@firewall-services.com> 0.2-2
123 vip-ire 1.17 - Bug fix for guest access
124 slords 1.15
125     * Tue Sep 2 2008 Daniel B. <daniel@firewall-services.com> 0.2-1
126     - uplink and downlink for guest account are configurable via db keys
127    
128     * Tue Sep 2 2008 Daniel B. <daniel@firewall-services.com> 0.2-0
129     - Login page is a CGI, with a server-manager login page look
130 vip-ire 1.22 - Guest Access can be enabled with guestAccess key (enabled/disabled)
131 slords 1.15 - merge patchs in main package
132    
133 vip-ire 1.14 * Mon Sep 01 2008 Daniel B. <daniel@firewall-services.com> 0.1-8
134     - Fix uamallowed not working (since bypass_auth_with_squid_fix patch)
135     - Add WebRequests key (use of squid or direct connexions, default to direct)
136     - disable radconf in /etc/chilli/config
137     - possible to disable https (enabled by default in AllowedOutgoing)
138     - add tcp:static.sourceforge.net:80 in uamallowed so daloradius homepage is displayed correctly
139     - add radiustimeout directive so authentication errors display the standard message quickly
140    
141 snetram 1.13 * Thu Aug 28 2008 Jonathan Martens <smeserver-contribs@snetram.nl> 0.1-7
142     - Reverted moving of default db entries to SPEC file since common practice is to store them in files
143    
144     * Thu Aug 28 2008 Daniel B. <daniel@firewall-services.com> 0.1-6
145 vip-ire 1.12 - split uamallowed (one per line)
146     - Add dnsparanoia directive
147     - correct cmdsock directive
148     - initialise default configuration db in the spec file
149    
150 snetram 1.11 * Thu Aug 28 2008 Jonathan Martens <smeserver-contribs@snetram.nl> 0.1-5
151     - Remove the reset of $OUT from the template
152    
153 vip-ire 1.9 * Thu Aug 28 2008 Daniel B. <daniel@firewall-services.com> 0.1-4
154     - Add template to enable auth module unix (replace the template-custom)
155     - Copy images to /opt/chilli/template before removing .rpmnew directory
156 vip-ire 1.10 - Correct dependency (e-smith-radiusd not esmith-radiusd)
157 vip-ire 1.9
158 snetram 1.8 * Wed Aug 27 2008 Jonathan Martens <smeserver-contribs@snetram.nl> 0.1-3
159     - Split requirements to one per line
160     - Removed .rpmnew directory from package
161 vip-ire 1.9 - Removed the need for templates-custom as package now requires e-smith-radiusd >= 1.0.0-18
162 snetram 1.8
163 vip-ire 1.3 * Tue Aug 26 2008 Daniel B. <daniel@firewall-services.com>
164     - [0.1-2]
165 vip-ire 1.5 - Most firewall customizations (for incomming and forwarded traffic from
166 vip-ire 1.3 chilli network only) can be set through db commands (Patch3)
167     - Outgoing DNS is allowed only for the two DNS servers configured
168 vip-ire 1.5 - Clean spec file, and put php files in /opt/chilli (Patch4)
169 vip-ire 1.3
170 slords 1.1 * Tue Apr 15 2008 Daniel Berteaud <daniel@firewall-services.com>
171     - [0.1-1]
172     - security fixe: auth bypass with squid (patch1)
173     - masq template not expanded (patch2)
174    
175     * Fri Apr 04 2008 Daniel Berteaud <daniel@firewall-services.com>
176     - [0.1]
177     - initiale release
178    
179     %prep
180     %setup
181     %patch1 -p1
182     %patch2 -p1
183 vip-ire 1.17 %patch3 -p1
184     %patch4 -p1
185     %patch5 -p1
186 vip-ire 1.18 %patch6 -p1
187 vip-ire 1.19 %patch7 -p1
188 vip-ire 1.22 %patch8 -p1
189 vip-ire 1.23 %patch9 -p1
190 vip-ire 1.24 %patch10 -p1
191     %patch11 -p1
192     %patch12 -p1
193 vip-ire 1.25 %patch13 -p1
194 vip-ire 1.26 %patch14 -p1
195     %patch15 -p1
196     %patch16 -p1
197     %patch17 -p1
198 vip-ire 1.27 %patch18 -p1
199 vip-ire 1.28 %patch19 -p1
200 vip-ire 1.29 %patch20 -p1
201 vip-ire 1.30 %patch21 -p1
202 vip-ire 1.31 %patch22 -p1
203     %patch23 -p1
204     %patch24 -p1
205     %patch25 -p1
206 slords 1.15
207 slords 1.1 %build
208     /usr/bin/perl createlinks
209    
210     %install
211     /bin/rm -rf $RPM_BUILD_ROOT
212     (cd root ; /usr/bin/find . -depth -print | /bin/cpio -dump $RPM_BUILD_ROOT)
213     /bin/rm -f %{name}-%{version}-filelist
214     /sbin/e-smith/genfilelist $RPM_BUILD_ROOT \
215 vip-ire 1.26 --file /etc/chilli/conup.sh 'attr(755,root,root)' \
216     --file /etc/chilli/condown.sh 'attr(750,root,root)' \
217     --file /etc/chilli/call_conup.sh 'attr(755,root,root)' \
218     --file /etc/chilli/call_condown.sh 'attr(755,root,root)' \
219 slords 1.15 --file /opt/chilli/cgi-bin/hotspotlogin.cgi 'attr(0750,root,www) %config(noreplace)' \
220     --file /opt/chilli/lang/hotspotlogin.fr.pl 'config(noreplace)' \
221     --file /opt/chilli/lang/hotspotlogin.en.pl 'config(noreplace)' \
222     --file /opt/chilli/css/sme.css 'config(noreplace)' \
223 slords 1.1 > %{name}-%{version}-filelist
224    
225     %files -f %{name}-%{version}-filelist
226     %defattr(-,root,root)
227    
228     %clean
229     rm -rf $RPM_BUILD_ROOT
230    
231 vip-ire 1.26 %pre
232     if ! /usr/bin/id coovachilli &>/dev/null; then
233     /usr/sbin/useradd -c 'Coova Chilli User' -s /sbin/nologin -r -d /etc/chilli coovachilli &>/dev/null || \
234     %logmsg "Unexpected error adding user \"coovachilli\". Abort installation."
235     fi
236    
237    
238 slords 1.1 %preun
239 vip-ire 1.3
240 slords 1.1 if [ $1 == 0 ]; then
241     /sbin/e-smith/db configuration setprop chilli status disabled
242 slords 1.7 /etc/rc.d/init.d/chilli stop >& /dev/null || :
243 slords 1.1 fi
244    

admin@koozali.org
ViewVC Help
Powered by ViewVC 1.2.1 RSS 2.0 feed