# $Id: smeserver-coova-chilli.spec,v 1.13 2008/08/28 15:38:40 snetram Exp $ # Authority: vip-ire # Name: Daniel Berteaud Summary: Coova-Chilli, a captive portal based on ChilliSpot configured for SME server %define name smeserver-coova-chilli Name: %{name} %define version 0.1 %define release 8 Version: %{version} Release: %{release}%{?dist} License: GPL Group: Networking/Remote access Source: %{name}-%{version}.tar.gz URL: http://sme.firewall-services.com BuildRoot: /var/tmp/%{name}-%{version}-%{release}-buildroot BuildArchitectures: noarch BuildRequires: e-smith-devtools Requires: e-smith-release >= 7.0 Requires: openssl Requires: coova-chilli Requires: e-smith-radiusd >= 1.0.0-18 Patch1: smeserver-coova-chilli-0.1-bypass_auth_with_squid_fix.patch Patch2: smeserver-coova-chilli-0.1-expand_masq_fix.patch Patch3: smeserver-coova-chilli-0.1-firewall2db.patch Patch4: smeserver-coova-chilli-0.1-loginPageDir.patch Patch5: smeserver-coova-chilli-0.1-authTemplate.patch Patch6: smeserver-coova-chilli-0.1-fixOUTreset.patch Patch7: smeserver-coova-chilli-0.1-uamallowed.patch Patch8: smeserver-coova-chilli-0.1-dnsparano.patch Patch9: smeserver-coova-chilli-0.1-cmdsock.patch Patch10: smeserver-coova-chilli-0.1-directOrSquid.patch %description This package allow you to configure a third interface (eth2). Just plug a WiFi AP on it, and you'll have a secured captive portal. Users will be redirected on a logon page and they'll have to enter credentials (sme accounts) before the server allows them. By default, they'll only have web access if they are members of the group "chilli" This contrib will only work in server&gateway mode %changelog * Mon Sep 01 2008 Daniel B. 0.1-8 - Fix uamallowed not working (since bypass_auth_with_squid_fix patch) - Add WebRequests key (use of squid or direct connexions, default to direct) - disable radconf in /etc/chilli/config - possible to disable https (enabled by default in AllowedOutgoing) - add tcp:static.sourceforge.net:80 in uamallowed so daloradius homepage is displayed correctly - add radiustimeout directive so authentication errors display the standard message quickly * Thu Aug 28 2008 Jonathan Martens 0.1-7 - Reverted moving of default db entries to SPEC file since common practice is to store them in files * Thu Aug 28 2008 Daniel B. 0.1-6 - split uamallowed (one per line) - Add dnsparanoia directive - correct cmdsock directive - initialise default configuration db in the spec file * Thu Aug 28 2008 Jonathan Martens 0.1-5 - Remove the reset of $OUT from the template * Thu Aug 28 2008 Daniel B. 0.1-4 - Add template to enable auth module unix (replace the template-custom) - Copy images to /opt/chilli/template before removing .rpmnew directory - Correct dependency (e-smith-radiusd not esmith-radiusd) * Wed Aug 27 2008 Jonathan Martens 0.1-3 - Split requirements to one per line - Removed .rpmnew directory from package - Removed the need for templates-custom as package now requires e-smith-radiusd >= 1.0.0-18 * Tue Aug 26 2008 Daniel B. - [0.1-2] - Most firewall customizations (for incomming and forwarded traffic from chilli network only) can be set through db commands (Patch3) - Outgoing DNS is allowed only for the two DNS servers configured - Clean spec file, and put php files in /opt/chilli (Patch4) * Tue Apr 15 2008 Daniel Berteaud - [0.1-1] - security fixe: auth bypass with squid (patch1) - masq template not expanded (patch2) * Fri Apr 04 2008 Daniel Berteaud - [0.1] - initiale release %prep %setup %patch1 -p1 %patch2 -p1 %patch3 -p1 %patch4 -p1 %patch5 -p1 %patch6 -p1 %patch7 -p1 %patch8 -p1 %patch9 -p1 %patch10 -p1 mv root/opt/chilli.rpmnew/template/images root/opt/chilli/template rm -rf root/opt/chilli.rpmnew/ rm -rf root/etc/e-smith/templates-custom/ %build /usr/bin/perl createlinks %install /bin/rm -rf $RPM_BUILD_ROOT (cd root ; /usr/bin/find . -depth -print | /bin/cpio -dump $RPM_BUILD_ROOT) /bin/rm -f %{name}-%{version}-filelist /sbin/e-smith/genfilelist $RPM_BUILD_ROOT \ --file /etc/chilli/conup.sh 'attr(0750,root,root)' \ --file /etc/chilli/condown.sh 'attr(0750,root,root)' \ --file /opt/chilli/hotspotlogin-loginform.php 'config(noreplace)' \ --file /opt/chilli/hotspotlogin-nonchilli.php 'config(noreplace)' \ --file /opt/chilli/hotspotlogin-nonssl.php 'config(noreplace)' \ --file /opt/chilli/hotspotlogin.php 'config(noreplace)' \ --file /opt/chilli/lang/en.php 'config(noreplace)' \ --file /opt/chilli/lang/fr.php 'config(noreplace)' \ --file /opt/chilli/lang/main.php 'config(noreplace)' \ --file /opt/chilli/template/loggingin.php 'config(noreplace)' \ --file /opt/chilli/template/loginform-footer.php 'config(noreplace)' \ --file /opt/chilli/template/loginform-header.php 'config(noreplace)' \ > %{name}-%{version}-filelist %files -f %{name}-%{version}-filelist %defattr(-,root,root) %clean rm -rf $RPM_BUILD_ROOT %preun if [ $1 == 0 ]; then /sbin/e-smith/db configuration setprop chilli status disabled /etc/rc.d/init.d/chilli stop >& /dev/null || : fi