1 |
Koozali SME Server 9.2 RC1 Release Notes |
Koozali SME Server 9.2 Final Release Notes |
2 |
=========================================== |
=========================================== |
3 |
|
|
4 |
15 March 2017 |
26 April 2017 |
5 |
|
|
6 |
The Koozali SME Server (SME Server) development team is pleased to announce |
The Koozali SME Server (SME Server) development team is pleased to announce |
7 |
the release of SME Server 9.2 RC1 which is based on CentOS 6.8 |
the release of SME Server 9.2 Final which is based on CentOS 6.9 |
8 |
|
|
9 |
Bug reports and reports of potential bugs should be raised in the bug |
Bug reports and reports of potential bugs should be raised in the bug |
10 |
tracker (and only there, please); |
tracker (and only there, please); |
11 |
|
|
12 |
http://bugs.contribs.org/ |
http://bugs.contribs.org/ |
13 |
|
|
14 |
Download |
Download |
15 |
======== |
======== |
16 |
|
|
17 |
You can download Koozali SME Server 9.2 RC1 from |
You can download Koozali SME Server 9.2 Final from |
18 |
http://mirror.contribs.org/smeserver/releases/testing/9.2.rc1/ |
http://mirror.contribs.org/smeserver/releases/9.2/ |
19 |
or for other methods see http://wiki.contribs.org/SME_Server:Download |
or for other methods see http://wiki.contribs.org/SME_Server:Download |
20 |
|
|
21 |
Please note it may take up to 48 hours for mirrors to finish syncing, |
Please note it may take up to 48 hours for mirrors to finish syncing, |
22 |
during this time you may experience problems. |
during this time you may experience problems. |
23 |
|
|
24 |
About SME Server |
About SME Server |
25 |
================ |
================ |
26 |
|
|
27 |
SME Server is the leading Linux distribution for small and medium |
SME Server is the leading Linux distribution for small and medium |
28 |
enterprises. Loozali SME Server is brought to you by Koozali Foundation, Inc., |
enterprises. Loozali SME Server is brought to you by Koozali Foundation, Inc., |
29 |
a non-profit corporation that exists to provide marketing and legal support |
a non-profit corporation that exists to provide marketing and legal support |
30 |
for SME Server. |
for SME Server. |
31 |
|
|
32 |
SME Server is freely available under the GNU General Public License and |
SME Server is freely available under the GNU General Public License and |
33 |
is only possible through the efforts of the SME Server community. |
is only possible through the efforts of the SME Server community. |
34 |
However, the availability and quality of SME Server is dependent on |
However, the availability and quality of SME Server is dependent on |
35 |
meeting our expenses, such as hosting costs, server hardware, etc. |
meeting our expenses, such as hosting costs, server hardware, etc. |
36 |
|
|
37 |
As such, we ask for a donation to offset costs and fund further development. |
As such, we ask for a donation to offset costs and fund further development. |
38 |
|
|
39 |
a) If you are a school, a church, a non-profit organisation or an individual |
a) If you are a school, a church, a non-profit organisation or an individual |
40 |
using SME Server for private purposes, we would appreciate you to contribute |
using SME Server for private purposes, we would appreciate you to contribute |
41 |
within your means toward the costs associated with hosting, maintenance and |
within your means toward the costs associated with hosting, maintenance and |
42 |
development. |
development. |
43 |
|
|
44 |
b) If you are a company or an integrator and you are deploying SME Server in |
b) If you are a company or an integrator and you are deploying SME Server in |
45 |
the course of your work to generate revenue, we expect you to make a donation |
the course of your work to generate revenue, we expect you to make a donation |
46 |
commensurate with the level of revenue you generate and the number of servers |
commensurate with the level of revenue you generate and the number of servers |
47 |
your have in the field. Please, help the project |
your have in the field. Please, help the project |
48 |
|
|
49 |
Please visit http://wiki.contribs.org/Donate to donate. |
Please visit http://wiki.contribs.org/Donate to donate. |
50 |
|
|
51 |
Koozali Inc is happy to supply an invoice for any donations received, |
Koozali Inc is happy to supply an invoice for any donations received, |
52 |
simply email treasurer@koozali.org |
simply email treasurer@koozali.org |
53 |
|
|
54 |
|
|
55 |
Notes |
Tony Keane |
56 |
===== |
============ |
57 |
|
|
58 |
In-place upgrades are not supported. It is necessary to backup and then restore. |
It is with huge sadness that we learnt the passing of Tony Keane on Friday |
59 |
/boot partition is always RAID 1. |
1st April, 2016. He was a long time user and supporter of Koozali SME Server |
60 |
|
and one of the founding members of the Koozali Foundation. |
61 |
The spare handling for RAID arrays is not implemented. |
We dedicate this release of SME Server 9.2 to Tony. |
62 |
|
Without him and a handful of others the community would not have been secured |
63 |
USB installs are now supported, see: |
with the Koozali foundation and our current cluster of servers to build and |
64 |
http://wiki.contribs.org/Install_From_USB#SME_Server_9 |
maintain your favourite distro. If you download and use it, |
65 |
|
please remember him and his work, and that of all the other contributors |
66 |
|
who work tirelessly to make Koozali SME as good as it is. |
67 |
Major changes in this release |
|
68 |
============================= |
We extend our thoughts and deepest sympathies to his family. |
69 |
|
|
70 |
Major Changes in this release. Updated all to Koozali branding. Server Manager - Allow access to the server-manager without SSL from the loopback, Don't redirect to http when login in/out of the server-manager from localhost. File Server - added W10 support to SME Domain. LDAP - Hook into the new ssl-update event. Mail Server - Update qpsmtpd to release 0.99.2 (including multiple plugins and ability to ebale/disable same), Allow reading SSL_version from the tls_protocols config file (and turn TLSv1 back on by default), Modify whitelist_soft transaction to interact with dnsbl filter, Revert forcing TLSv1 patch as it breaks some inbound delivery, Remove karma rcpt handling, Check rua is defined before trying to parse it to prevent an error if a domain has a DMARC entry published with no rua, add support for the uribl plugin, add detailed spamassassin report headers. Web Server - Hook into the new ssl-update event, Set TLSv1 back to enabled (but keep a prop to disable it if needed). Other fixes and updates - Correctly display http URL to the server-manager in the console, Remove motd text from grub.cfg. |
|
71 |
|
https://wiki.koozali.org/Tony_Keane |
72 |
|
|
73 |
Detailed changes in this release |
Notes |
74 |
======================= |
===== |
75 |
|
|
76 |
Only the changes since SME Server 9.1 are listed, mainly autogenerated from the changelogs. |
In-place upgrades are not supported. It is necessary to backup and then restore. |
77 |
|
/boot partition is always RAID 1. |
78 |
Packages altered by Centos, Redhat, and Fedora-associated developers are not included. |
|
79 |
|
The spare handling for RAID arrays is not implemented. |
80 |
Text With Bug Numbers |
|
81 |
Text for ISO Release Notes with Bug Numbers |
USB installs are now supported, see: |
82 |
The changelogs are written per package, and each package is assigned a group. |
http://wiki.contribs.org/Install_From_USB#SME_Server_9 |
83 |
|
|
84 |
File Server |
|
85 |
|
Major changes in this release |
86 |
e-smith-samba |
============================= |
87 |
- Create V6 profile dir (for Win10 roaming profiles) [SME: 9772] |
|
88 |
proftpd |
Major Changes in this release. Updated all to Koozali branding. Server Manager - Allow access to the server-manager without SSL from the loopback, Don't redirect to http when login in/out of the server-manager from localhost, Add Bug reporting template. File Server - added W10 support to SME Domain. LDAP - Hook into the new ssl-update event. Mail Server - Update qpsmtpd to release 0.99.6 (including multiple plugins and ability to ebale/disable same), Allow reading SSL_version from the tls_protocols config file (and turn TLSv1 back on by default), Modify whitelist_soft transaction to interact with dnsbl filter, Revert forcing TLSv1 patch as it breaks some inbound delivery, Remove karma rcpt handling, Check rua is defined before trying to parse it to prevent an error if a domain has a DMARC entry published with no rua, add support for the uribl plugin, add detailed spamassassin report headers. Web Server - Hook into the new ssl-update event, Set TLSv1 back to enabled (but keep a prop to disable it if needed). Other fixes and updates - Correctly display http URL to the server-manager in the console, Remove motd text from grub.cfg. |
89 |
- Additional tweak (to avoid null pointer dereference) for upstream bug 3868 |
|
90 |
- Fix for CVE-2016-3125: usage of 1024 bit DH key even with manual parameters |
|
91 |
see (http://bugs.proftpd.org/show_bug.cgi?id=4230) |
Detailed changes in this release |
92 |
- Also fixed related issue where only first DH param in TLSDHParamFile is used, |
======================= |
93 |
regardless of requested keylength (http://bugs.proftpd.org/show_bug.cgi?id=3868) |
|
94 |
- Fix SUID/SGID directory permission setting regression introduced with fix |
Only the changes since SME Server 9.1 are listed, mainly autogenerated from the changelogs. |
95 |
for CVE-2012-6095 (#1297264) |
|
96 |
- Add support for specifying TLSv1.1 and TLSv1.2 (#1281493) |
Packages altered by Centos, Redhat, and Fedora-associated developers are not included. |
97 |
|
|
98 |
LDAP |
Text for ISO Release Notes with Bug Numbers |
99 |
|
The changelogs are written per package, and each package is assigned a group. |
100 |
e-smith-ldap |
|
101 |
- Disable SSLv3, but keep the possibility to enable it again [SME: 10113] |
File Server |
102 |
- Better default cipher suite, and honor global suite [SME: 10113] |
|
103 |
- Hook into the new ssl-update event [SME: 9152] |
e-smith-samba |
104 |
|
- fix outlook error code 0x8004011c when setting up and email account on a win10 computer joined to a domain (with roaming profiles) [SME: 10106] |
105 |
Localisation |
- Create V6 profile dir (for Win10 roaming profiles) [SME: 9772] |
106 |
|
proftpd |
107 |
smeserver-locale |
- Additional tweak (to avoid null pointer dereference) for upstream bug 3868 |
108 |
- apply locale 2017-03-03 patch from pootle [SME: 9592] |
- Fix for CVE-2016-3125: usage of 1024 bit DH key even with manual parameters |
109 |
- Eliminated rpmbuild "bogus date" warnings due to inconsistent weekday, |
see (http://bugs.proftpd.org/show_bug.cgi?id=4230) |
110 |
by assuming the date is correct and changing the weekday. |
- Also fixed related issue where only first DH param in TLSDHParamFile is used, |
111 |
|
regardless of requested keylength (http://bugs.proftpd.org/show_bug.cgi?id=3868) |
112 |
Mail Server |
- Fix SUID/SGID directory permission setting regression introduced with fix |
113 |
|
for CVE-2012-6095 (#1297264) |
114 |
clamav |
- Add support for specifying TLSv1.1 and TLSv1.2 (#1281493) |
115 |
- Update to release 0.99.2 [SME: 9489] |
|
116 |
- Add pcre-devel to BuildRequires [SME: 9151] |
LDAP |
117 |
e-smith-pop3 |
|
118 |
- Hook into a new ssl-update event [SME: 9152] |
e-smith-ldap |
119 |
- Allow setting SSL protocols from DB (and set TLSv1 back to enabled |
- Disable SSLv3, but keep the possibility to enable it again [SME: 10113] |
120 |
on a default install) [SME: 9175] |
- Better default cipher suite, and honor global suite [SME: 10113] |
121 |
- Disable TLSv1 [SME: 9169] |
- Hook into the new ssl-update event [SME: 9152] |
122 |
e-smith-qmail |
|
123 |
- Add possibility to exclude users or members of other groups from group |
Localisation |
124 |
email address [SME: 9540] |
|
125 |
qmail |
smeserver-locale |
126 |
- Consider literal <> as null sender [SME: 9883] |
- apply locale 2017-03-16 patch from pootle [SME: 9592] |
127 |
qpsmtpd |
- Eliminated rpmbuild "bogus date" warnings due to inconsistent weekday, |
128 |
- Removed Message-Id validation, as it rejects MS account validation email [SME: 9773] |
by assuming the date is correct and changing the weekday. |
129 |
- fix whitelist plugin to support helo with naughty rejecting at mail stage [SME: 10111] |
|
130 |
- Validate domains found in uribl with Data::Validate::Domain [SME: 9499] |
Mail Server |
131 |
- Use eval to fetch dkim policies, prevent fatal errors in case of DNS |
|
132 |
timeout [SME: 9504] |
clamav |
133 |
- Remove karma rcpt handling (buggy and doesn't make a lot of sense) [SME: 9502] |
- Update to release 0.99.2 [SME: 9489] |
134 |
- Check rua is defined before trying to parse it to prevent an errorif a domain has a DMARC |
- Add pcre-devel to BuildRequires [SME: 9151] |
135 |
entry published with no rua [SME: 9507] |
e-smith-pop3 |
136 |
- Fix error when RCPT TO is not valid [SME: 8861] |
- Hook into a new ssl-update event [SME: 9152] |
137 |
- Fix karma logic by checking negative strikes [SME: 9502] |
- Allow setting SSL protocols from DB (and set TLSv1 back to enabled |
138 |
- Backport a fix for karma_tool so it can find its database [SME: 9502] |
on a default install) [SME: 9175] |
139 |
- Update to 0.96 (with some backports from GIT head) [SME: 8861] |
- Disable TLSv1 [SME: 9169] |
140 |
- Allow reading SSL_version from the tls_protocols config file (and turn TLSv1 back on by default) |
e-smith-qmail |
141 |
[SME: 9162] |
- Add possibility to exclude users or members of other groups from group |
142 |
- Correctly log login attempts with nulls in login name [SME: 9167] |
email address [SME: 9540] |
143 |
- Disable TLSv1 [SME: 9162] |
qmail |
144 |
qpsmtpd-plugins |
- Consider literal <> as null sender [SME: 9883] |
145 |
- remove whitelist_soft [SME: 10125] |
qpsmtpd |
146 |
smeserver-clamav |
- Removed Message-Id validation, as it rejects MS account validation email [SME: 9773] |
147 |
- Disable unofficial sigs for filesystem scans [SME: 9142] |
- fix whitelist plugin to support helo with naughty rejecting at mail stage [SME: 10111] |
148 |
smeserver-dovecot |
- Validate domains found in uribl with Data::Validate::Domain [SME: 9499] |
149 |
- Better default cipher suite, and honor global suite [SME: 10114] |
- Use eval to fetch dkim policies, prevent fatal errors in case of DNS |
150 |
- Hook into the new ssl-update event [SME: 9152] |
timeout [SME: 9504] |
151 |
- Allow settings SSL protocols from DB (and set TLSv1 back to enabled on a default install) |
- Remove karma rcpt handling (buggy and doesn't make a lot of sense) [SME: 9502] |
152 |
[SME: 9175] |
- Check rua is defined before trying to parse it to prevent an errorif a domain has a DMARC |
153 |
- Disable TLSv1 [SME: 9175] |
entry published with no rua [SME: 9507] |
154 |
smeserver-qpsmtpd |
- Fix error when RCPT TO is not valid [SME: 8861] |
155 |
- updated regex for SBList in smeserver-qpsmtpd-2.4.0-change_rbl_sbl_list_separator.patch to take into |
- Fix karma logic by checking negative strikes [SME: 9502] |
156 |
account list using a subdomain [SME: 10116] |
- Backport a fix for karma_tool so it can find its database [SME: 9502] |
157 |
- Eliminated rpmbuild "bogus date" warnings due to inconsistent weekday, by assuming the date is correct |
- Update to 0.96 (with some backports from GIT head) [SME: 8861] |
158 |
and changing the weekday. |
- Allow reading SSL_version from the tls_protocols config file (and turn TLSv1 back on by default) |
159 |
Thu May 11 2005 --> Thu May 05 2005 or Wed May 11 2005 or Thu May 12 2005 or .... |
[SME: 9162] |
160 |
Sun Sep 25 2010 --> Sun Sep 19 2010 or Sat Sep 25 2010 or Sun Sep 26 2010 or .... |
- Correctly log login attempts with nulls in login name [SME: 9167] |
161 |
- Set the default helo policy to lenient [SME: 9767] |
- Disable TLSv1 [SME: 9162] |
162 |
- Turn SPF and DMARC rejects off by default [SME: 9654] |
qpsmtpd-plugins |
163 |
- Fix disabling DMARC reporting [SME: 9507] |
- remove whitelist_soft [SME: 10125] |
164 |
- Remove o and r DKIM fields as they are not standard [SME: 9506] |
smeserver-clamav |
165 |
- In qpsmtpd-print-dns set DKIM options after the public key so the string will still be splitted correctly [SME: 9506] |
- Disable unofficial sigs for filesystem scans [SME: 9142] |
166 |
- Fix a syntax error in the qpsmtpd-print-dns script [SME: 9507] |
smeserver-dovecot |
167 |
- Remove warning about spool dir permission on startup [SME: 9511] |
- Better default cipher suite, and honor global suite [SME: 10114] |
168 |
- Add missing patch for DKIM signing [SME: 9506] |
- Hook into the new ssl-update event [SME: 9152] |
169 |
- Add missing run time dependency on perl(DBD::SQLite) [SME: 9507] |
- Allow settings SSL protocols from DB (and set TLSv1 back to enabled on a default install) |
170 |
- Check SPF for inbound emails [SME: 9505] |
[SME: 9175] |
171 |
- Check DKIM for inbound emails [SME: 9504] |
- Disable TLSv1 [SME: 9175] |
172 |
- Check DMARC for inbound emails (based on the previous SPF and DKIM checks) [SME: 9507] |
smeserver-qpsmtpd |
173 |
- Store and send DMARC aggregate reports [SME: 9507] |
- updated regex for SBList in smeserver-qpsmtpd-2.4.0-change_rbl_sbl_list_separator.patch to take into |
174 |
- Support DKIM signing for outbound emails [SME: 9506] |
account list using a subdomain [SME: 10116] |
175 |
- Use an additional badrcptto file list for external connections so local only pseudonymes work as expected [SME: 9503] |
- Set the default helo policy to lenient [SME: 9767] |
176 |
- Enable the bogus_bounce plugin [SME: 9501] |
- Turn SPF and DMARC rejects off by default [SME: 9654] |
177 |
- Use the naughty plugin to defer rejections, leaving users an opportunity to authenticate [SME: 9500] |
- Fix disabling DMARC reporting [SME: 9507] |
178 |
- Add support for the uribl plugin [SME: 9499] |
- Remove o and r DKIM fields as they are not standard [SME: 9506] |
179 |
- Change separator for SBList and RBLlist from : to , [SME: 9498] |
- In qpsmtpd-print-dns set DKIM options after the public key so the string will still be splitted correctly [SME: 9506] |
180 |
- Switch to the clamdscan plugin [SME: 9497] |
- Fix a syntax error in the qpsmtpd-print-dns script [SME: 9507] |
181 |
- Enabe the loadcheck plugin [SME: 9508] |
- Remove warning about spool dir permission on startup [SME: 9511] |
182 |
- Add support for the karma plugin [SME: 9502] |
- Add missing patch for DKIM signing [SME: 9506] |
183 |
- Work with qpsmtpd 0.96 [SME: 8861] |
- Add missing run time dependency on perl(DBD::SQLite) [SME: 9507] |
184 |
- Expand all ssl related conf in ssl-update [SME: 9152] |
- Check SPF for inbound emails [SME: 9505] |
185 |
- Hook into a new ssl-update event [SME: 9152] |
- Check DKIM for inbound emails [SME: 9504] |
186 |
- Allow setting SSL protocols from DB [SME: 9162] |
- Check DMARC for inbound emails (based on the previous SPF and DKIM checks) [SME: 9507] |
187 |
smeserver-spamassassin |
- Store and send DMARC aggregate reports [SME: 9507] |
188 |
- Rewrite spamd run script to add support for --allow-tell [SME: 10138] |
- Support DKIM signing for outbound emails [SME: 9506] |
189 |
- Add X-Spam-Details header (and simplify X-Spam-Status) [SME: 9509] |
- Use an additional badrcptto file list for external connections so local only pseudonymes work as expected [SME: 9503] |
190 |
- Disable ipv6 support to prevent a warning during startup [SME: 9153] |
- Enable the bogus_bounce plugin [SME: 9501] |
191 |
|
- Use the naughty plugin to defer rejections, leaving users an opportunity to authenticate [SME: 9500] |
192 |
Server manager |
- Add support for the uribl plugin [SME: 9499] |
193 |
|
- Change separator for SBList and RBLlist from : to , [SME: 9498] |
194 |
e-smith-manager |
- Switch to the clamdscan plugin [SME: 9497] |
195 |
- reapply patch 4 |
- Enabe the loadcheck plugin [SME: 9508] |
196 |
- Update server-manager to Koozali branding [SME: 9678] |
- Add support for the karma plugin [SME: 9502] |
197 |
- move fix to the right line to be effective [SME: 9920] |
- Work with qpsmtpd 0.96 [SME: 8861] |
198 |
- fix bad redirection parameter that might reveal session information to remote site temporarily |
- Expand all ssl related conf in ssl-update [SME: 9152] |
199 |
reverting patch 4 for fast release of security fix please put it back at next release [SME: 9920] |
- Hook into a new ssl-update event [SME: 9152] |
200 |
- Update server-manager to Koozali branding [SME: 9678] |
- Allow setting SSL protocols from DB [SME: 9162] |
201 |
- e-smith-manager-2.6.0-Koozali_manager.patch better syntax for removing Indexes option for the manager [SME: 9589] |
smeserver-spamassassin |
202 |
- Remove index option for manager's resources [SME: 9589] |
- Rewrite spamd run script to add support for --allow-tell [SME: 10138] |
203 |
- fix 307 redirection to http when https is used [SME: 8825] |
- Add X-Spam-Details header (and simplify X-Spam-Status) [SME: 9509] |
204 |
- update syntaxe for TKT Auth, bump 7 for typo, corrected typo in e-smith-manager-2.4.0- dont_rewrite_to_https_from_localhost.patch code from John H. Bennett III bennettj@johnbennettservices.com [SME: 9271] |
- Disable ipv6 support to prevent a warning during startup [SME: 9153] |
205 |
- Really don't redirect to http when login in/out of the server-manager [SME: 9163] |
|
206 |
- Don't redirect to http when login in/out of the server-manager from localhost [SME: 9163] |
Server manager |
207 |
- Allow access to the server-manager without SSL from the loopback [SME: 9163] |
|
208 |
php |
e-smith-manager |
209 |
- don't set environmental variable based on user supplied Proxy request header CVE-2016-5385 |
- add a panel to ease reporting bugs [SME: 10238] |
210 |
- fix wrong warning in openssl_encrypt() for missing IV when IV is not required #1260315 |
- fix typo in e-smith-manager-2.6.0-bz10187-emptyback.patch [SME: 10187] |
211 |
- fix segfault's when you try and allocate an SplFixedArray with size >= 9999 #1071344 |
- avoid internal server error if empty back parameter [SME: 10187] |
212 |
- segfault in php_pgsql_meta_data CVE-2015-4644 #1234434 |
- fix too short timeout in server-manager [SME: 10186] |
213 |
- add options to enable TLS in curl #1255920 |
- reapply patch 4 |
214 |
- fix segfault in gc_collect_cycles #1122681 |
- Update server-manager to Koozali branding [SME: 9678] |
215 |
|
- move fix to the right line to be effective [SME: 9920] |
216 |
Webmail and Groupware |
- fix bad redirection parameter that might reveal session information to remote site temporarily |
217 |
|
reverting patch 4 for fast release of security fix please put it back at next release [SME: 9920] |
218 |
|
- Update server-manager to Koozali branding [SME: 9678] |
219 |
Web Server |
- e-smith-manager-2.6.0-Koozali_manager.patch better syntax for removing Indexes option for the manager [SME: 9589] |
220 |
|
- Remove index option for manager's resources [SME: 9589] |
221 |
e-smith-apache |
- fix 307 redirection to http when https is used [SME: 8825] |
222 |
- Hook into the new ssl-update event [SME: 9152] |
- update syntaxe for TKT Auth, bump 7 for typo, corrected typo in e-smith-manager-2.4.0 |
223 |
- Set TLSv1 back to enabled (but keep a prop to disable it if needed) [SME: 9154] |
- dont_rewrite_to_https_from_localhost.patch code from John H. Bennett III bennettj@johnbennettservices.com [SME: 9271] |
224 |
- Disable TLSv1 [SME: 9154] |
- Really don't redirect to http when login in/out of the server-manager [SME: 9163] |
225 |
|
- Don't redirect to http when login in/out of the server-manager from localhost [SME: 9163] |
226 |
Other fixes and updates |
- Allow access to the server-manager without SSL from the loopback [SME: 9163] |
227 |
|
php |
228 |
e-smith-base |
- don't set environmental variable based on user supplied Proxy request header CVE-2016-5385 |
229 |
- Use ip route syntax to define routes to local network [SME: 9905] |
- fix wrong warning in openssl_encrypt() for missing IV when IV is not required #1260315 |
230 |
- Allow /32 masks on the external interface, in which case we don't |
- fix segfault's when you try and allocate an SplFixedArray with size >= 9999 #1071344 |
231 |
check if the gateway is on the correct network) [SME: 9765] |
- segfault in php_pgsql_meta_data CVE-2015-4644 #1234434 |
232 |
- Add a column to display forwarding address [SME: 9174] |
- add options to enable TLS in curl #1255920 |
233 |
- Correctly display http URL to the server-manager in the console [SME: 9163] |
- fix segfault in gc_collect_cycles #1122681 |
234 |
- Fire ssl-update event when default cert is renewed [SME: 2257] |
|
235 |
- Expand /home/e-smith/ssl.pem/pem during ssl-update [SME: 9152] |
Webmail and Groupware |
236 |
e-smith-devtools |
|
237 |
- Quote filenames in genfilelist so filenames containing spaces are correctly |
|
238 |
handled [SME: 9758] |
Web Server |
239 |
e-smith-grub |
|
240 |
- Remove motd text from grub.cfg [SME: 9161] |
e-smith-apache |
241 |
e-smith-hosts |
- Hook into the new ssl-update event [SME: 9152] |
242 |
- Allow empty comment when creating/modifying a hostname [SME: 9177] |
- Set TLSv1 back to enabled (but keep a prop to disable it if needed) [SME: 9154] |
243 |
e-smith-ibays |
- Disable TLSv1 [SME: 9154] |
244 |
- Remove double / in SSL RewriteRule [SME: 9195] |
|
245 |
e-smith-lib |
Other fixes and updates |
246 |
- Adjust regex so adjust-service accepts sigusr1 and sigusr2 from files [SME: 9184] |
|
247 |
e-smith-proxy |
e-smith-base |
248 |
- Allow custom file descriptor limit, and set default to 4096 [SME: 9911] |
- Use ip route syntax to define routes to local network [SME: 9905] |
249 |
initscripts |
- Allow /32 masks on the external interface, in which case we don't |
250 |
- Rebase on upstream 9.03.53-1 [SME: 9534] |
check if the gateway is on the correct network) [SME: 9765] |
251 |
- Roll in CentOS Branding |
- Add a column to display forwarding address [SME: 9174] |
252 |
- functions: parse -d first |
- Correctly display http URL to the server-manager in the console [SME: 9163] |
253 |
- functions: fix ignored delay in killproc |
- Fire ssl-update event when default cert is renewed [SME: 2257] |
254 |
- netfs: only unmount loopback device mounted on top of netdev or with back-file on netdev |
- Expand /home/e-smith/ssl.pem/pem during ssl-update [SME: 9152] |
255 |
- functions: improve killing loops |
e-smith-devtools |
256 |
- netfs: tweak nfs umount |
- Quote filenames in genfilelist so filenames containing spaces are correctly |
257 |
- sysctl.conf: mention sysctl -a |
handled [SME: 9758] |
258 |
- sysconfig.txt: document PPPOE_EXTRA and PPPD_EXTRA |
e-smith-grub |
259 |
- spec: require plymouth |
- Remove motd text from grub.cfg [SME: 9161] |
260 |
- fix mangled sysconfig/init.s390 |
e-smith-hosts |
261 |
- rc.sysinit: don't perform fsck twice with /.autorelabel |
- Allow empty comment when creating/modifying a hostname [SME: 9177] |
262 |
- ifdown-eth: fix comparison |
e-smith-ibays |
263 |
- ifup-eth: if arping fails, output responding MAC |
- Remove double / in SSL RewriteRule [SME: 9195] |
264 |
- network-functions: fix change_resolv_conf after grep update |
e-smith-lib |
265 |
- spec: add sysctl.d dir |
- Adjust regex so adjust-service accepts sigusr1 and sigusr2 from files [SME: 9184] |
266 |
- rc.sysinit: fix typo in fs |
e-smith-proxy |
267 |
- rename_devices: comments need to have a blank before them |
- Allow custom file descriptor limit, and set default to 4096 [SME: 9911] |
268 |
- rename_device: remove comments and trailing whitespaces |
initscripts |
269 |
- bonding: warn if the ifup for slave device failed |
- Rebase on upstream 9.03.53-1 [SME: 9534] |
270 |
- clarify daemon() usage message |
- Roll in CentOS Branding |
271 |
- ifdown: clean ipv4 localhost addresses |
- functions: parse -d first |
272 |
- ifup-post: check resolve.conf also with DNS2 |
- functions: fix ignored delay in killproc |
273 |
- ifup: add missing quotes |
- netfs: only unmount loopback device mounted on top of netdev or with back-file on netdev |
274 |
- ifup-eth: some bridge options are applied later |
- functions: improve killing loops |
275 |
- init.d/halt: give init some time to reexecute |
- netfs: tweak nfs umount |
276 |
- network-scripts: DEVICE and HWADRR could be quoted by apostrophe |
- sysctl.conf: mention sysctl -a |
277 |
- ifup-wireless: fix calling of phy_wireless_device |
- sysconfig.txt: document PPPOE_EXTRA and PPPD_EXTRA |
278 |
- rc.sysinit: apply quotas after system is relabeled |
- spec: require plymouth |
279 |
mod_auth_tkt |
- fix mangled sysconfig/init.s390 |
280 |
- backport to SME9 fix redirection when proxy ssl [SME: 8825] |
- rc.sysinit: don't perform fsck twice with /.autorelabel |
281 |
- update apxs path for SME9 (sbin) |
- ifdown-eth: fix comparison |
282 |
smeserver-release |
- ifup-eth: if arping fails, output responding MAC |
283 |
- Bump for beta1 release of 9.2 [SME: 9525] |
- network-functions: fix change_resolv_conf after grep update |
284 |
smeserver-support |
- spec: add sysctl.d dir |
285 |
- updated sources with new pictures fix hover color [SME: 9678] |
- rc.sysinit: fix typo in fs |
286 |
- Koozali branding of manager [SME: 9678] |
- rename_devices: comments need to have a blank before them |
287 |
- Eliminated rpmbuild "bogus date" warnings due to inconsistent weekday,by assuming the date is correct and changing the weekday. |
- rename_device: remove comments and trailing whitespaces |
288 |
- Update copyright in server-manager footer [SME: 9266] |
- bonding: warn if the ifup for slave device failed |
289 |
- Don't put motd content in /etc/redhat-release [SME: 9161] |
- clarify daemon() usage message |
290 |
smeserver-yum |
- ifdown: clean ipv4 localhost addresses |
291 |
- added centos SCLo SIG gpg rpm signing key [SME: 10102] |
- ifup-post: check resolve.conf also with DNS2 |
292 |
will allow to install SCL packages directly from smecontribs |
- ifup: add missing quotes |
293 |
|
- ifup-eth: some bridge options are applied later |
294 |
General features |
- init.d/halt: give init some time to reexecute |
295 |
================ |
- network-scripts: DEVICE and HWADRR could be quoted by apostrophe |
296 |
|
- ifup-wireless: fix calling of phy_wireless_device |
297 |
- Based on CentOS 6.8 and all available updates |
- rc.sysinit: apply quotas after system is relabeled |
298 |
|
mod_auth_tkt |
299 |
Terry Fage |
- backport to SME9 fix redirection when proxy ssl [SME: 8825] |
300 |
Compilation of release data is thanks to Ian Wells |
- update apxs path for SME9 (sbin) |
301 |
On behalf of the Koozali SME Server development team |
smeserver-release |
302 |
|
- Bump for beta1 release of 9.2 [SME: 9525] |
303 |
|
smeserver-support |
304 |
|
- updated sources with new pictures fix hover color [SME: 9678] |
305 |
|
- Koozali branding of manager [SME: 9678] |
306 |
|
- Eliminated rpmbuild "bogus date" warnings due to inconsistent weekday,by assuming the date is correct and changing the weekday. |
307 |
|
- Update copyright in server-manager footer [SME: 9266] |
308 |
|
- Don't put motd content in /etc/redhat-release [SME: 9161] |
309 |
|
smeserver-yum |
310 |
|
- added centos SCLo SIG gpg rpm signing key [SME: 10102] |
311 |
|
will allow to install SCL packages directly from smecontribs |
312 |
|
|
313 |
|
General features |
314 |
|
================ |
315 |
|
|
316 |
|
- Based on CentOS 6.9 and all available updates |
317 |
|
|
318 |
|
Terry Fage |
319 |
|
Compilation of release data is thanks to Ian Wells |
320 |
|
On behalf of the Koozali SME Server development team |