aboutsummaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)Author
2020-03-22clamav: upgrade 102.2wip2Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17buck-security: move to recipes-scannersArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17checksecurity: move to recipes-scannersArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17checksec: move to recipe-scannersArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17clamav: move to recipes-scannersArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17chkrootkit: add rootkit recipeArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17fail2ban: change hardcoded sysklogd to VIRTUAL-RUNTIME_base-utils-syslogArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17lynis: add missing rdependsArmin Kuster
add findutils Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-17openscap-daemon: add missing runtime dependenciesYi Zhao
Add missing runtime dependencies otherwise /usr/bin/oscapd can not startup. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08libseccomp: update to 2.4.3Armin Kuster
dropped patch now included in update Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08sssd: python2 not supportedArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08linux-yocto: update the bbappend to 5.xAndré Draszik
As linux-yocto upgraded to 5.x in oe-core, update the bbappend to 5.x to remove the warning ERROR: No recipes available for: .../meta-security/meta-tpm/recipes-kernel/linux/linux-yocto_4.%.bbappend This patch hasn't been verified any further than allowing bitbake to complete with a non-linux-yocto kernel. In particular options could be different, or new ones needed / desired. Signed-off-by: André Draszik <git@andred.net> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08sssd: DEPEND on nss if nothing else is chosenJonatan Pålsson
sssd will attempt to build against nss if no crypto is selected. If a bbappend sets PACKAGECONFIG = <list without nss or crypto>, the appropriate DEPEND is not established. Fixes the following configure error: ... snip ... | checking for NSS... configure: error: Package requirements (nss) were not met: | | No package 'nss' found | | Consider adjusting the PKG_CONFIG_PATH environment variable if you | installed software in a non-standard prefix. | | Alternatively, you may set the environment variables NSS_CFLAGS | and NSS_LIBS to avoid the need to call pkg-config. | See the pkg-config man page for more details. | | WARNING: exit code 1 from a shell command. Signed-off-by: Jonatan Pålsson <jonatan.p@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08sssd: Fix typo in PACKAGECONFIG. cyrpto -> cryptoJonatan Pålsson
Signed-off-by: Jonatan Pålsson <jonatan.p@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-08sssd: Add PACKAGECONFIG for python2Jonatan Pålsson
Fixes the following build error: .. snip .. | checking for python2... no | checking for python3... (cached) python3.8 | configure: error: | The program python2 was not found in search path. | Please ensure that it is installed and its directory is included in the search | path. It is required for building python2 bindings. If you do not want to build | them please use argument --without-python2-bindings when running configure. | WARNING: exit code 1 from a shell command. Signed-off-by: Jonatan Pålsson <jonatan.p@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-05README: Add meta-python to list of layer depsJonatan Pålsson
Signed-off-by: Jonatan Pålsson <jonatan.p@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-05libtpm: fix build issue over pod2manArmin Kuster
/bin/bash: pod2man: command not found | Makefile:585: recipe for target 'TPMLIB_CancelCommand.3' failed inherit perlnative to fix Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-05sssd: fix for ldblibdir and systemd etcKai Kang
Fix sssd issue for ldblibdir, systemd, pam etc. * fix ldblibdir which is not calculated right for cross compile * create directory /var/log/sssd which is required by sssd daemon * disable building python2 binding * fix pam module path * update systemd configure options and service files Signed-off-by: Kai Kang <kai.kang@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-05linux-yocto: update the bbappend to 5.xMingli Yu
As linux-yocto upgraded to 5.x in oe-core, update the bbappend to 5.x to remove the warning: WARNING: No recipes available for: /buildarea/layers/meta-security/recipes-kernel/linux/linux-yocto_4.%.bbappend Signed-off-by: Mingli Yu <mingli.yu@windriver.com> [Droped 4.x part] Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-05scap-security-guide: pass the correct schema file path to openscap-nativeYi Zhao
There is a build error when using openscap-native sstate cache. Steps to reproduce: Create a new build project in build-1 directory. $ bitbake openscap-native Then remove the whole build directory only keep the sstate-cache directory as a sstate mirror. Create another new build project in build-2 directory. Set SSTATE_MIRRORS $ bitbake scap-security-guide Error message: OpenSCAP Error: Schema file 'xccdf/1.1/xccdf-schema.xsd' not found in path '/buildarea/build-1/tmp/work-shared/openscap/oscap-build-artifacts/usr/share/openscap/schemas' when trying to validate '/buildarea/build-2/tmp/work/core2-64-poky-linux/scap-security-guide/0.1.44+gitAUTOINC+5fdfdcb2e9-r0/git/build/jre/xccdf-unlinked-resolved.xml' [/buildarea/build-1/tmp/work/x86_64-linux/openscap-native/1.3.1+gitAUTOINC+4bbdb46ff6-r0/git/src/source/validate.c:104] The oscap command from openscap-native tries to find the schema files in build-1 directory since these paths are hardcoded when building openscap-native. We need to pass the correct schema/xslt/cpe paths to oscap to make sure it can find the files in right location. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01secuirty*-image: remove dead var and minor cleanupArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01linux: drop the bbappend for linux v4.x seriesBartosz Golaszewski
v4.19 LTS has been dropped in poky in favor of v5.4. Drop the bbappend from meta-security as right now the build fails. Signed-off-by: Bartosz Golaszewski <bgolaszewski@baylibre.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01clamav-native: missed bison fixArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01README.md: update to new maintainerArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01layer.conf: add zeusArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01isafw: fix to work against masterArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01meta-security-isafw: import layer from IntelArmin Kuster
take over layer Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-03-01clamav: add bison-native to dependArmin Kuster
fixes build issue: clamav/0.101.5-r0/git/config/ylwrap: line 176: yacc: command not found Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-17apparmor: update to tipArmin Kuster
fixes Python3.8 configure issues Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-16google-authenticator-libpam: install module in pam locationArmin Kuster
pam_google_authenticator.so was being installed where pam could not find it. Move it where the rest of the pam modules site. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-16python3-fail2ban: add 2-3 conversion changesArmin Kuster
Had to use the fail2ban-2.3 program to create py3 code Add it as a patch Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-10ibmswtpm2: update to 1563Armin Kuster
fix build issue [v2] Fix subject line Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-10tpm2-tss: update to 2.3.2Armin Kuster
clean up reciped. drop git fetching Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-10tpm2-tcti-uefi: fix build issue for i386 machineArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-10tpm2-tools: update to 4.1.1Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-10bastille: convert to py3Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-09scap-security-guide: fix xml parsing error when build remediation filesYi Zhao
Backport 2 patches to fix the build error: Processing fix.text for: java_jre_configure_crypto_policy rule Unable to extract part of the fix.text after inclusion of remediation functions. Aborting.. jre/CMakeFiles/generate-internal-jre-bash-fixes.xml.dir/build.make:60: recipe for target 'jre/bash-fixes.xml' failed make[2]: *** [jre/bash-fixes.xml] Error 1 make[2]: *** Deleting file 'jre/bash-fixes.xml' Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-02ecryptfs-utils: search nspr header files in ${STAGING_INCDIR}/nspr directoryArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-02-01swtpm: fix configure errorArmin Kuster
checking for whether to build with seccomp profile... configure: error: "Is libseccomp-devel installed? -- could not get cflags for libseccomp" Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-28buck-security: fix rdebends and minor style cleanupArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-28checksecurity: fix runtime issuesArmin Kuster
add some missing perl modules Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-28linux-yocto-dev: remove "+"Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-28google-authenticator-libpam: upgrade 1.07 -> 1.08Pierre-Jean Texier via Lists.Yoctoproject.Org
See changelog: https://github.com/google/google-authenticator-libpam/releases/tag/1.08 Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-28samhain: fix build with new version attrYi Zhao
The attr/xattr.h has been removed from attr 2.4.48 with commit: http://git.savannah.nongnu.org/cgit/attr.git/commit/include?id=7921157890d07858d092f4003ca4c6bae9fd2c38 The xattr syscalls are provided by sys/xattr.h from glibc now. Remove the checking code to adapt it otherwise it would fail to build with selinux support. Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-23Apparmor: fix some runtime dependsArmin Kuster
missing xargs and comm Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-21python3-fail2ban: update to latestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-21sssd: drop py2 supportArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-19README: add pull request optionArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-05fail2ban: fix runtime errorArmin Kuster
use success/failure calls in initd/function Signed-off-by: Armin Kuster <akuster808@gmail.com>
2020-01-04meta-integrity: fix issues with yocto-check-layerArmin Kuster
[v2] re-did solutions Signed-off-by: Armin Kuster <akuster808@gmail.com>