--- cdrom.image/sme10/README.txt 2021/06/07 01:25:48 1.12 +++ cdrom.image/sme10/README.txt 2022/08/18 13:39:58 1.13 @@ -1,21 +1,19 @@ -Koozali SME Server 10 Final Release Notes "Justine" +Koozali SME Server 10.1 Release Notes ============================================ - -07 June 2021 +18 Aug 2022 The Koozali SME Server development team is pleased to announce the -release of SME Server 10 Final which will be the next major release of -SME Server. Code named "Justine" +release of SME Server 10.1 which will be an update release of SME Server. -This release is based on CentOS 7. CentOS 7.# has an EOL of 30 June 2024. +This release is based on CentOS 7. CentOS 7.# has an EOL of +30 June 2024. ********************************************************** -Koozali SME Server users should not upgrade production servers to this. -Those with test servers are encouraged to load the release to a -dedicated test machine and take part in the testing phase. +Koozali SME Server users are encouraged to update production servers +to this release. ********************************************************** -Some notes on Koozali SME Server 10 can be found at +Additional notes on Koozali SME Server 10 can be found at https://wiki.contribs.org/SME_Server_10.0_Development SME10 Roadmap - @@ -31,17 +29,17 @@ https://lists.contribs.org/pipermail/upd Download ======== -You can download SME Server 10 from -https://mirror.koozali.org/smeserver/releases/testing/10/ +You can download SME Server 10.1 from +https://mirror.koozali.org/smeserver/releases/10.1/ or for other methods see: https://wiki.koozali.org/SME_Server:Download -Please note it may take up to 48 hours for mirrors to finish syncing, -during this time you may experience problems. +After release, please note it may take up to 48 hours for mirrors to +finish syncing, during this time you may experience availability issues. About SME Server ================ -SME Server is the leading Linux distribution for small and medium +SME Server is a popular Linux distribution for small and medium enterprises. SME Server is brought to you by Koozali Foundation, Inc., a non-profit corporation that exists to provide marketing and legal support for SME Server. @@ -52,7 +50,7 @@ is only possible through the efforts of However, the availability and quality of SME Server is dependent on meeting our expenses, such as hosting costs, server hardware, etc. -As such, we ask for a donation to offset costs and fund further development. +As such, we encourage a donation to offset costs and fund further development. a) If you are a school, a church, a non-profit organisation or an individual using SME Server for private purposes, we would appreciate @@ -71,55 +69,55 @@ simply email treasurer at koozali.org Notes ===== -In-place upgrades are not supported. It is necessary to backup and then -restore. - -Restore of a sme9 console or workstation backup is now fully supported, there -are cautions to be aware of and followed. +In-place upgrades from previous major releases are not supported. +It is necessary to backup and then restore. -Single disk install no longer creates a degraded Raid1 array, Two or more disks -will be created as a Raid1-6 array, see wiki https://wiki.contribs.org/Raid +In-place point updates within a major release are supported. -The spare handling for RAID arrays is now implemented. +Restore of a sme9 console or workstation backup is now fully supported +there are cautions to be aware of and followed, see wiki and forum notes. -Support for further Raid configuration on install is now implemented - see wiki +From the many, small and large, fixes and updates the highlights are: -New Server-Manager Framework, Mojolicious, is now well on the way to full implementation +The integration of httpd access using the to 2.4 syntax +#Note there will be a need to update your contribs and any custom templates -USB installs are once again fully supported, -Note: it is important to use recommended apps to create the boot media -See: https://wiki.koozali.org/Install_From_USB +The improvement of syslog management with dedicated log file for all the core +services (some were in systemd and some in the message log) -Netinstall is once again fully supported, additional repos easily added +Along with changes to the management of logfiles an improved logrotate has +been implemented, this is also now configurable via db config settings ie +frequency and number to retain -Install to a system supporting a UEFI BIOS is also now fully supported +Improvement and update to user and system security via update of cvm-unix +module -Console backup, and workstation backup to removable storages is now fully supported. +Support for @.service has now been integrated and implemented -Koozali templating is now fully inegrated with systemd +Updates and fixes to radius services have also been implemented and improved -An enormouse number other under the hood changes, far to numerous to list here +The task of implementing backup of the contribs data by the the core console +backup and workstation backup has begun see: +https://bugs.koozali.org/show_bug.cgi?id=11997 -The work that has gone into getting SME 10 to this stage has been enormous, an attempt to list -and detail the work that has been done in recent months would not do justice to the effort -contributed by the following, +A large number other minor under the hood changes and upstream updates and +fixes. +===== -thank you one and all: +The time and effort that has gone into getting SME 10.1 to release has been +extensive, an attempt to list and detail the work that has been done in recent +months would not do justice to the effort made, thank you one and all for your +time and help. +In particular thank you for the consistent efforts of: Jean Phillipe Pialasse -Michel Begue +John Crisp Brian Read -Catton Durbrow -Chris Sansom-Ninnes -Jean-pierre Odion +Michel Begue Zsolt Vasarhelyi -John Crisp -Terry Fage - -there have also been many others who have done what they can, thank you: -The changes that have been implemented to ensure the Koozali Sme Server way is fully implemented -have been far reaching, far to many to try and list, suffice to say long live "Justine". +The changes that have been implemented to ensure the Koozali Sme Server way +is fully implemented have been considered and extensive. Major changes in this release ============================= @@ -127,51 +125,53 @@ This release is based on CentOS 7.# Changes in this release ======================= -see above and below, too much to list +see above and below General features ================ -- Based on CentOS 7.9.2009 and all available updates +Based on CentOS 7.9.2009 and all available updates Detailed changes in this release ======================= -Only the changes since SME Server 10 RC1 are listed, mainly autogenerated from the changelogs. +Only the changes since SME Server 10 final are listed, autogenerated +from the changelogs. -Packages altered by Centos, Redhat, and Fedora-associated developers are not included. +Packages altered by Centos, Redhat, and Fedora-associated developers are +not included. The changelogs are written per package SME built or modified packages - ChangeLogs -10 June 2021 +18 Aug 2022 Backups -flexbackup -- fix package version and release 1.2.1-6.4 -- new source from debian packages repos 1.2.1-6.4 -- convert initial release -- remove /usr/share/lintian directory -- add convert script to doc directory -- add debian changelog to doc directory + +e-smith-backup +- negative date (mtime, data modification time) zerodate fix [SME: 11907] +- allow mounting smbv1 backup share [SME: 11557] +- remove lock noise to cron stdout for workstation backup [SME: 11530] +- fix dar restore replacing rootdir symlinks by folders [SME: 11424] +- Remove duplicate gunzip call in perform_restore [SME: 11266] +- Remove debug output of device names +- Revert BlockDevices.pm and backup call to not filter to removable drives +- Replace hal-* calls with BlockDevices [SME: 11319] +- add update event [SME: 11124] +- Added /etc/backup-data.d to backup paths [SME: 10245] +- Added error handling to restore using pipe pattern from perform_backup [SME: 3139] +- Made reboot optional after console restore +- Fixed bootstrap restore not activating config changes [SME: 10921] +- Manually added ext2 and ext3 to Block Device file system check where ext4 present +- updated Block Device discovery to fix recovery from console [SME: 8244] +- Credit to Catton Durbrow + File Server -e-smith-proftpd -- restart proftpd on ssl-update [SME: 11603] -- cleanup in /etc/rc.d [SME: 9692] -- redirect log away from message [SME: 11384] -- fix circular Conflict with proftpd [SME: 11357] -- improve protect from proftpd.service running [SME: 11106] -- protect from proftpd.service running in place of ftp.service [SME: 11106] -- remove system-preset file from usr [SME: 10958] -- SSL crt and key to self signed if path does not exist [SME: 11316] -- add Requires=runit.service [SME: 11245] -- execute systemd-reload before service adjust in events [SME: 11228] -- remove S95reset-unsavedflag [SME: 11229] -- Remove ftp from 'init.d/supervise' [SME: 11106] [SME: 11150] -- Move ftp service to systemd [SME: 11106] -- Create e-smith-proftpd-update event [SME: 11150] e-smith-samba +- samba fix typo in delete v6 profile dir win10 [SME: 11725] +- samba delete v6 profile dir win10 [SME: 11725] +- samba create v6 profile dir win10 [SME: 11725] - netlogon.bat +x [SME: 11566] - add possibility to reenable allow execute always on ibays homes or everywhere [SME: 11555] - fix double entries for min protocol [SME: 11558] @@ -187,14 +187,19 @@ e-smith-samba - create e-smith-samba-update event [SME: 11157] - Fix mutex locking [SME: 11199] - Fix pid directory [SME: 11198] -- Add /etc/krb5.conf as template using templates from smeserver-samba [SME: 11093] +- Add /etc/krb5.conf as template using templates from smeserver-samba +- [SME: 11093] - remove win98pwdcache.reg from server-resources [SME: 9060] - set min server and client protocol SMB2 [SME: 10576] add check so max always greater than min - add port 445 if min server protocol is SMB2 or SMB3 [SME: 10963] LDAP + e-smith-ldap +- add support or rsshusers system group [SME: 11753] +- redirect syslog for ldapt to /var/log/ldap/ldap.log [SME: 11745] +- fix ssl-update reload instead of restart ldap [SME: 11598] - fix wrong path for templates.metadata [SME: 11595] - use template for ssl pem [SME: 11595] - fix ldap failing to start on initial boot [SME: 11480] @@ -207,31 +212,71 @@ e-smith-ldap Ciphers are now ordered with stronger first Localisation + smeserver-locale +- apply local 2022-07-21.patch [SME: 12117] +- apply local 2021-06-06.patch [SME: 11593] - apply local 2021-05-12.patch [SME: 11593] - apply local 2021-01-09.patch [SME: 11310] - apply local 2019-12-07.patch Mail Server -djbdns -- import modification from SME9 [SME: 11548] -- improve short ttl cname resolution and glueless answer from akadns [SME: 8362] -- 500-cutom-dnscache-maxloop.patch: set QUERY_MAXLEVEL 5 QUERY_MAXLOOP 500 QUERY_MAXNS 16 [SME: 10300] e-smith-email +- add quote around filename to .fetchids moving script [SME: 12131] +- move fetchids from /run and avoid its loss on reboot [SME: 12131] + similar changes in contrib smesevrer-fetchmail +- fix typo in regex [SME: 11799] +- fix missing dot in regex for untainting [SME: 11799] + would delete any account named with the string before the dot +- untainting string correctly [SME: 11716] +- fix typo for mailpattern for rar files [SME: 11690] +- fix perms for /var/lock/fetchmail [SME: 11634] +- make /var/lock/fetchmail dir permanent [SME: 11634] - add new RAR file signatures to default mailpatterns database [SME: 11265] - webmail is only SSL [SME: 11443] - create -update event [SME: 11133] - move smtp-auth-proxy to systemd [SME: 11102] - allow creation of pseudonyms with setting of local only [SME: 3802] -qmail -- add remote tls transport for qmail-remote [SME: 9349] -- updated release number higher than SME9 -- now TLS and EHLO are defined to allow proper compilation -- add DEBUG flag for the moment to help configuring -DDEBUG=1 +e-smith-qmail +- fix multiple errors with pseudonyms in template [SME: 8591] + orphaned pseudonyms are associated to admin +- repopulate qmail assign db and sighup qmail on group event [SME: 11934] +- can set to 0 ConcurrencyLocal or ConcurrencyRemote [SME: 11645] + this allows to disable of type of delivery +- add Requires=runit.service [SME: 11245] +- fix missing actions for systemd on upgrade event [SME: 11105] + cleanup preset file +- remove qmail link in init.d and whole rc.d [SME: 11105] + take 3 +- remove qmail link in init.d [SME: 11105] +- execute systemd-reload before service adjust in events [SME: 11228] +- remove S95reset-unsavedflag [SME: 11229] +- remove rc7.d link [SME: 11105] +- fix actions in e-smith-qmail-update [SME: 11152] +- Move qmail service to systemd [SME: 11105] +- Create e-smith-qmail-update event [SME: 11152] + +qpsmtpd +- fix fetchmail patch to check local_ip [SME: 11763] +- fix configuration not honoured on initial start [SME: 10387] + commented out load_plugins see https://github.com/smtpd/qpsmtpd/issues/288. smeserver-clamav +- logrotate clamd keeps logging to old log [SME: 11963] +- remove default property ArchiveBlockEncrypted [SME: 11695] +- fix property name error 2.7.0-12.sme [SME: 11695] +- fix spec file error 2.7.0-11.sme [SME: 11474] +- rename property ArchiveBlockEncrypted to AlertEncrypted as per upstream [SME: 11695] + added properties AlertBrokenExecutables AlertExceedsMax AlertOLE2Macros + AlertPartitionIntersection AlertPhishingCloak and AlertPhishingSSLMismatch + with default no + added property HeuristicAlerts with default yes +- fix noise on centos2sme [SME: 11474] +- identify from which server is freshclam error [SME: 11755] + fix from Graeme Fleming +- fix typo in logrotate [SME: 11608] - fix typo and missing +x [SME: 11520] - fix issues with non epel standard scan.conf [SME: 11520] move clamd.conf to scan.conf @@ -247,25 +292,19 @@ smeserver-clamav - Updated to use systemd for freshclam [SME: 11104] - increase lower memory limit to 1GB [SME: 10833] - fix for AllowSupplementaryGroups warning [SME: 10813] - thanks to bunkobugsy - -smeserver-dovecot -- ssl pem update via template expand in place of copy [SME: 11601] -- clean rsyslog syntax for dovecot [SME: 11422] -- add Restart=always [SME: 11101] -- fix path for event -update [SME: 11101] -- cleanup /var/service/dovecot [SME: 11101] - close logger and service from previous runit instance before starting systemd one -- add systemd drop-in expand in bootstrap-console-save, console-save, post-install, post-upgrade [SME: 11101] -- move service to systemd [SME: 11101] -- add imap idle notify interval setting [SME: 10947] -- fix typo in enabling TLSv1.2 as default [SME: 10934] -- fix typo in 35ssl template [SME: 10934] -- fix typo in createlinks [SME: 10932] -- revert property names with period in it [SME: 10934] -- add property AcceptFullEmail with enabled as default [SME: 9865] smeserver-qpsmtpd +- Print both 255 char and full length DKIM keys [SME: 11974] +- fix unable to set internal only pseudonym as full email [SME: 11933] +- add softlimit template for qpsmtpd [SME: 11858] + increase softlimit to 50000000. +- fix regression Set the default helo policy to lenient [SME: 11864] +- mail sent on 127.0.0.200:25 should be spam checked [SME: 10289] + filtering again fetchmail originating mails +- sighup on reload [SME: 11759] +- fix tnef2mime FATAL PLUGIN ERROR [SME: 11648] + this will be a temp fix by redefining MIME::Parser::Filer::output_path + until it has been fixed upstream - update depreacted reject_threshold to reject [SME: 11492] - remove /usr/lib/systemd/system-preset/80-koozali-qpsmtpd.preset [SME: 10958] - modify for clamav 0.103.0 [SME: 11210] @@ -281,35 +320,34 @@ smeserver-qpsmtpd - minimum Protocol TLSv1.0 [SME: 10460] better ciphers order. -smeserver-spamassassin -- prevent noise in log at spamassassin call from qpsmtpd [SME: 11491] -- clean rsyslog syntax for spamd [SME: 11422] -- remove warning while trying to delete file when missing in post script [SME: 11375] -- remove spamd reference as service use spamassassin.service [SME: 11375] - migrate spamd propertie SpamLearning to spamassassin - template for /etc/sysconfig/spamassassin, revert --allow-tell option - stop spamassassin spamd and delete /etc/systemd/system/spamassassin.service link if exists -- fix typo [SME: 11361] -- fix spamd unable to load [SME: 11361] -- redirect spamd loging to spamd.log instead of message [SME: 11362] -- add requires DCC as we have built it [SME: 11065] -- fix smeserver-spamassassin-update event fix [SME: 11166] -- Start systemd migration. Remove symlinks [SME: 11224] -- remove refresh clam as this will be provided by clamav -- require spamassassin 3.4.4 + - Server manager -e-smith-formmagick -- fix wrong PATH which makes fail grub reconfiguration [SME: 11556] -- increase CSRF timeout from 120s to 180s [SME: 10902] - added property httpd-admin{csrfTimeout} in second to override - added hability to ovarride the Timeout from panel to panel -- add update event [SME: 11136] -- add locale for CSRF [SME: 10626] -- add CSRF patch [SME: 10626] - thank you to Daniel Berteaud + +e-smith-manager +- update to httpd 2.4 access syntax for httpd-admin [SME: 12129] +- update to httpd 2.4 access syntax [SME: 12129] +- removing reference to old log rotation action [SME: 11872] +- take 2 wrong system mode reported in bugreport [SME: 10448] +- fix wrong system mode reported in bugreport [SME: 10448] +- create -update event [SME: 11144] +- migrate httpd-admin to systemd [SME: 11110] +- removing hardcoded ports [SME: 10967] +- Add a FollowSymlinks for user-password in password/cgi-bin (perl-suid) [SME: 9677] +- update apache icon path [SME: 9591] +- add message to indicate EOL after Jun 30 2024 fix [SME: 10170] + e-smith-viewlogfiles + perl-CGI-FormMagick Webmail and Groupware + smeserver-horde +- fix invalid domain if ForcePrimaryDomain is enabled [SME: 11980] +- fix $ldapServer is commented out if Horde ForcePrimaryDomain is disabled [SME: 11981] +- use httpd 2.4 access control syntax [SME: 11945] +- fix previous patch error extra line [SME: 11694] +- fix alarm noise when disabled [SME: 11694] +- Syntax error, unexpected '(T_STRING), expecting ')' [SME: 11738] +- thanks to zsolt vasarhelyi for patch test +- Ingo filters TLS error if sieve is enabled [SME: 11628] - fix missing call to perl module emsith::php [SME: 11489] - clean rsyslog syntax for horde [SME: 11422] - improved php basedir, with filtering of noise for gpg [SME: 10945] @@ -344,7 +382,18 @@ smeserver-horde - cvs admin -ko on patch1 Web Server + e-smith-apache +- reverting last change [SME: 9375] +- add conflict on older ibays, php, horde, proxy, manager rpms +- removing mod_access_compat [SME: 9375] +- convert httpd 2.2 allow,deny to Require for 2.4 [SME: 9375] +- use maxsize, not size [SME: 11867] +- use logrotate.d instead of event action [SME: 11867] + use size to force log rotate before normal delay +- add modules ldap authnz_ldap and proxy_wstunnel [SME: 11760] + previously provided by webapps-common +- fix httpd-e-smith failing to start on reboot in private server-gateway mode [SME: 11596] - add possibility to force https on LAN only [SME: 11511] usefull for VPN over port 443 - prevent httpd to fail if modSSL defined certs does not exist [SME: 10826] @@ -361,9 +410,49 @@ e-smith-apache - disable TLSv1 TLSv1.1 by default [SME: 10459] Other fixes and updates + +bglibs +- initial build for SME10 [SME: 11883] + patched selftests.sh to avoid net/resolve_ipv4addr.c test which fails under mock + added BuildRequires glibc glibc-static glibc-devel mtools autoconf + commented out files for devel /usr/local/bglibs/lib/*.lib and /usr/local/bglibs/lib/*/*.a + as they fails. + +cvm +- build cvm 0.97 for SME10 [SME: 11315] + +e-smith-LPRng +- untainting port cleanly [SME: 12106] +- remove /usr/lib/systemd/system-preset/80-koozali-LPRng.preset [SME: 10958] +- Add 'Requires:runit.service' [SME: 11245] +- Add a fragment for lpd in 49-koozali.preset [SME: 11006] +- Remove init.d/supervise/lpd link [SME: 11006] +- keep runit service for systemd [SME: 11006] +- fix update event name [SME: 11007] +- from service to systemd [SME: 11006] +- add lpd-update event [SME: 11007] + e-smith-base +- no new self signed cert when adding/removing non self hosts [SME: 12130] +- fix /dev/log not being recreated [SME: 12073] +- add rsshusers group to ldap and update it [SME: 11956] +- fix symlinks preventing log rotation [SME: 11950] +- remove immark module to reduce messages log activity [SME: 11813] +- fix logs not rotated before 100M (size maxsize) [SME: 10484] +- reduce systemd noise in messages [SME: 11813] +- fix dhcp address not propagated [SME: 11930] +- make rsyslog listen journald which listen /dev/log [SME: 11813] + template for /etc/systemd/journald.conf +- properly configure /etc/logrotate.conf [SME: 10484] + template for /etc/logrotate.conf + use of size to limit max size of file and rotate earlier +- drop e-smith logrotate actions creating dangling links [SME: 946] +- make journald log permanent by creating /var/log/journal [SME: 11795] +- allow group-modify-unix on update event [SME: 11766] +- fix typo in last patch [SME: 11722] +- add support for systemd service with instance service@instance.service [SME: 11722] - add local domains in self signed cert alt subjects [SME: 11624] - add local hosts in self signed cert alt subjects + add local hosts in self signed cert alt subjects modSSL property to disable hosts domains addition : AddDomains AddHosts default is enabled when empty - fix missing export [SME: 11620] @@ -412,63 +501,71 @@ e-smith-base - add bash-completion [SME: 11244] - improve local service to systemd [SME: 11119] now run rc.local file as part of the event -- move local service to systemd [SME: 11119] - make it run /etc/rc.d/rc.local - cleaning /var/service/syslog still there -- workaround drop-in install section ignored by systemctl preset [SME: 11231] - some cleanup -- remove S95reset-unsavedflag [SME: 11229] -- add exclusion for lpd [SME: 11006] -- execute systemd-reload before service adjust in events [SME: 11228] -- fix ExecStart for raidmonitor [SME: 11094] -- fix permission for /sbin/e-smith/systemd/mdmonitor-pre [SME: 11094] -- Don't ask for confirmation to save changes on first install configuration [SME: 11193] -- Fix RAID detection regex for disk redundancy screen [SME: 10918] -- add Install part of systemd unit [SME: 11100] -- move dhcpd to systemd [SME: 11100] -- get dhcpd log out of message [SME: 2408] - also configure logrotate for /var/log/dhcpd/dhcpd.log and /var/log/dhcpd/current -- reverte previous changes for service2adjust and util.pm [SME: 11177] - files are owned by e-smith-lib -- allow more systemctl controls [SME: 11177] - convert unrecognized signals from service2adjust in events for systemd - handle unsupervised services the same way supervised were in adjust-services - make service-status only log when service disabled and not fail it -- add template for /etc/systemd/system-preset/49koozali.preset [SME: 11174] + +e-smith-cvm-unix-local +- fix error compressing log still in use by delaying it [SME: 11968] +- reverting to release 7 state [SME: 11885] +- Add yum action to restart post install [SME: 11885] +- bump requirement for cvm [SME: 11885] + removing daemontools requirement +- expand rsyslog.conf [SME: 11807] +- redirect and rotate log for cvm-unix [SME: 11807] + fix cvm-pre script permission +- fix service stopping restarting on crash [SME: 11792] +- fix typo [SME: 11314] +- migrate to systemd [SME: 11314] +- add update event [SME: 11125] e-smith-devtools +- remove duplication with Dar backup [SME: 11993] +- ease backup include and exclude of contribs [SME: 11993] - netlogon.bat +x [SME: 11566] - add update event [SME: 11126] -e-smith-domains -- setup dns services on domain creation and other events [SME: 10115] -- avoid encoding of utf strings in domain table [SME: 11391] - this will mess with some languages -- Create e-smith-domains-update event [SME: 11128] - -e-smith-grub -- set missing locale if update-grub called by server-manager [SME: 11559] -- fix unable to boot on a non xfs root filesystem [SME: 11365] -- cleanup remove /boot/grub dir [SME: 11354] -- Add support for EFI systems [SME: 10998] -- add update event [SME: 11137] - -e-smith-lib -- update copyright dates, and make it easier to change from spec file [SME: 11570] -- partial revert of signals [SME: 11177] - signal s not passed to runit services (dnscache*, qmail, qpsmtpd...) - services handled by systemd crash if they do not have Restart=always defined -- add support for signals SIG* with systemd [SME: 11177] - fix typo for reload-or-try-restart - unsupervised services: really stop when disabled and start stopped enabled ones -- remove error when sending sighup event [SME: 11177] -- allow more systemctl controls [SME: 11177] - convert unrecognized signals from service2adjust in events for systemd - handle unsupervised services the same way supervised were in adjust-services -- create e-smith-lib-event [SME: 11141] -- add support for systemctl reload-or-restart, try-restart, enable -now [SME: 10848] +e-smith-ibays +- add missing elements to e-smith-ibays-update event to activate changes [SME: 11774] +- fix AH01797: client denied by server conf [SME: 11774] + use new require syntax for httpd 2.4 +- fix patch for SSLRequireSSL [SME: 8150] +- force https if auth or dav are enabled [SME: 11407] +- merge SSL and SSLRequireSSL properties [SME: 8150] + now SSLRequireSSL will force SSL to the html ibay directory and redirect to https +- update php properties and folders [SME: 11412] +- remove last bit of atalk [SME: 668] +- add update event [SME: 11139] +- remove hardcoded ports [SME: 10968] +- remove php3 reference [SME: 10869] +- fix apache failing if ibay has dynamic content enabled and phpmodule is disabled [SME: 10871] +- revert patch, wrong rpm [SME: 10871] +- add support for php-fpm [SME: 10871] + +e-smith-lib-compspec +- fix last dot erased on completion [SME: 11368] +- error on incorect cmd input [SME: 4661] +- allow easy access to templates.metadata to expand desired files [SME: 11312] +- add update event [SME: 11142] + +e-smith-ntp +- dedicated log and logrotate [SME: 12115] + thanks to bunkobugsy for this patch +- untainting fields [SME: 12107] +- fix ntpd crashing with panic_stop [SME: 11298] +- update override.conf to 50koozali.conf [SME: 11008] +- adding missing folder /usr/lib/systemd/system/ntpd.service.d [SME: 11008] +- fix typo in path for new driftfile [SME: 8881] +- fix systemd-preset fragment [SME: 11008] + add +x to ExecStartPRe script +- improve systemd integration [SME: 11008] +- change driftfile path [SME: 8881] +- from service to systemd [SME: 11008] +- add ntpd-update event [SME: 11009] +- revert last change [SME: 10190] + on sme10 systemd has ntpd disabled by default +- revert last change [SME: 10190] + on sme10 systemd has ntpd disabled by default e-smith-nutUPS +- Misspelling in /usr/lib/systemd/system/nut.service file [SME: 11633] - fix start ordering nut.service [SME: 11488] - fix ExecStartPre path for /usr/lib/tmpfiles.d/nut-run.conf [SME: 11488] - fix ExecStartPre path for nut.service [SME: 11488] @@ -478,6 +575,8 @@ e-smith-nutUPS - adapt nut UPS for systemd [SME: 9423] e-smith-packetfilter +- restrict VPN networks to their interface [SME: 11640] + remove remoteVPNSubnet property added VPNif property - fix dropin file not expanded on initial installation [SME: 11528] - fix noise on logrotate, doing a restart instead of reload [SME: 11451] - move ulogd to systemd [SME: 11426] @@ -488,7 +587,23 @@ e-smith-packetfilter - launch masq using systemd unit [SME: 11089] - create event to avoid reboot on update [SME: 11122] +e-smith-proxy +- use httpd 2.4 access control syntax [SME: 11944] +- fix squid starting before network [SME: 11713] + also dropin file not expanded on install fixed +- cleanup in /etc/rc.d and /var/service/squid [SME: 9692] + e-smith-radiusd +- redirect daemon log to its own file [SME: 11947] +- workaround upstream missing definition of /var/run/radiusd/tmp [SME: 11859] +- fix startup informational message Duplicate Auth-Type 'REJECT' [SME: 11736] +- patch was blank, populate and apply [SME: 11736] +- fix startup informational message Duplicate Auth-Type 'REJECT' [SME: 11736] +- add db property PAP-auth [SME: 11735] +- add/fix PAP-auth patch [SME: 11735] +- fix WAP-auth patch [SME: 11718] +- fix LDAP-auth patch [SME: 11719] +- fix ssl template metadata patch [SME: 11680] - remove services2adjust in bootstrap-console-save event, this put systemd in a loop [SME: 11602] - ssl pem using template in place of copy [SME: 11602] - radiusd needs ldap started before [SME: 11302] @@ -499,23 +614,27 @@ e-smith-radiusd remove noise from spec file - fix server restartting with virtual_server error [SME: 10853] -smeserver-release -- Bump new rpm for sme 10.0 final -- Bump new rpm for sme10 release candidate 1 -- updating release number everywhere [SME: 11366] -- Bump release to 1 as buildsys believe 1.alpha5 is newer than 0.beta1 [SME: 11317] -- Bump new rpm for sme10 beta1 [SME: 11317] -- add update event [SME: 11165] -- Bump new rpm for sme10 alpha5 - -smeserver-support -- fix copyright date and make it easier to update from spec file [SME: 11568] -- fix typo and wording [SME: 11535] -- add update event [SME: 11167] -- revert update of samba using upstream CentOS repo [SME: 11196] -- obsoletes e-smith-starterwebsite [SME: 8903] +smeserver-audittools +- display yum repo as seen by yum and db [SME: 10880] +- add remi-safe in list of newrpms [SME: 11932] +- fix temp event displayed by events audittool [SME: 11674] +- fix links to different rpm rported as modified [SME: 11673] +- add update event [SME: 11161] smeserver-yum +- bump version number +- no reboot for dbus-glib [SME: 12091] +- rephrase contrib update message [SME: 11543] +- move mysqld to mariadb in smeserver plugin [SME: 11921] +- remove force AutoInstallUpdates to disabled [SME: 11961] +- fix rotate yum.log as not standard location [SME: 11951] +- remove yum_update_dbs from messages log [SME: 11952] +- restart cvm-unix on cvm or bglibs update [SME: 11886] +- remove pop3 and pop3s services from plugin [SME: 11808] +- fix restarting spamd instead of spamassassin [SME: 11803] +- Re-word-reboot-required-message.patch [SME: 11790] +- fix wrong qpsmtpd handling [SME: 11768] +- add elrepo GPG key [SME: 11625] - no reboot needed for systemd-python [SME: 11609] - fix services stop on removal [SME: 11510] - run navigation-conf when a panel is installed [SME: 11507] @@ -553,12 +672,6 @@ smeserver-yum - fix NameError: global name 'yum_update_dbs' is not defined [SME: 6940] - use yum-cron with autoupdate feature [SME: 10690] -These are either not SME modified Packages, or are kernel mods. -clamav -libprelude -sendmail - The changelogs are written per package On behalf of the Koozali SME Server development team -- Compilation of release data is thanks to scripts developed by Ian Wells and substantially improved by Jean Phillipe Pialasse - -Terry Fage +- Compilation of release data is thanks to scripts developed by + Ian Wells and substantially improved by Jean Phillipe Pialasse