aboutsummaryrefslogtreecommitdiffstats
path: root/recipes-security
AgeCommit message (Collapse)Author
2018-12-06apparmor: Remove tab indentations in python codeRobert Yang
Use 4 spaces to replace a tab. Fixed: apparmor_2.12.bb: python should use 4 spaces indentation, but found tabs in apparmor_2.12.bb, line 49 Signed-off-by: Robert Yang <liezhi.yang@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31clamav: update to 0.99.4Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroup-core-security: add fail2ban ptest to imageArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31fail2ban: add ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroup-core-security: add tripwire ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31tripwire: add ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31security-build-image: remove X11Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroup-core-security: add suricata-ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31suricata: add ptestArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroup-core-security: add few more ptest packagesArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroup-core-security: add ptest capable packagesArmin Kuster
and favor python-scapy Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31packagegroups: add more packagesArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-10-31suricata: fix QA errorArmin Kuster
ollected errors: * check_data_file_clashes: Package suricata wants to install file .../1.0-r0/rootfs/var/run But that file is already provided by package * base-files Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-29bseccomp: fix do package qa warningChangqing Li
Fix below warning: lib32-libseccomp-2.3.3-r0 do_package: QA Issue: lib32-libseccomp: Files/directories were installed but not shipped in any package: Signed-off-by: Changqing Li <changqing.li@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-29keynote: remove recipeYi Zhao
The keynote is unmaintained for a long time. It had been removed from main distributions (Fedora, Suse and Debian). See: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594867 Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-23samhain: update to 4.3.0Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17aircrack: update to 1.3Armin Kuster
remove unneeded patch. minor cleanups Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17packagegroup-core-security: change scapy to python nameArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17bastille: fix QA errorArmin Kuster
bastille_3.2.1.bb: cannot map 'allarch' to a linux kernel architecture Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17suricata: include a emerging rules snapshotArmin Kuster
it appears to be changing w/o version control so keep a snapshot when reciped was updated. Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17apparmor: update to 2.12Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17fscryptctl: update to tipArmin Kuster
fix mkfs.ext4 invocation Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17scapy: update to 2.4.0 and covertArmin Kuster
convert package to python standard Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17fail2ban: update to 10.3.1Armin Kuster
covert to python package standard Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17sssd: update to 1.16.3Armin Kuster
Includes: CVE-2018-10852 see: https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_3.html Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17keyutils: Fix build with usrmergeAlex Kiernan
Update BINDIR and SBINDIR so keyutils builds with usrmerge ERROR: keyutils-1.5.10-r0 do_package: QA Issue: keyutils: Files/directories were installed but not shipped in any package: /sbin/key.dns_resolver /sbin/request-key /bin/keyctl Please set FILES such that these items are packaged. Alternatively if they are unneeded, avoid installing them or delete them within do_install. keyutils: 3 installed and not shipped files. [installed-vs-shipped] Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-17keynote: depend on openssl10Yi Zhao
Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01xmlsec1: upgrade 1.2.25 -> 1.2.26Yi Zhao
Drop patch xmlsec1-fix-a-typo-in-examples-verify3.c.patch since the issue had been fixed upstream. Rebase patch change-finding-path-of-nss.patch Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01samhain: upgrade 4.2.2 -> 4.2.4Yi Zhao
Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01ecryptfs-utils: fix usrmerge install pathMingli Yu
Update rootsbindir from /sbin to ${base_sbindir} to fix below do_install error when usrmerge enabled in DISTRO_FEATURES | chmod: cannot access '/poky-build/tmp-glibc/work/core2-64-wrs-linux/ecryptfs-utils/111-r0/image/usr/sbin/mount.ecryptfs_private': No such file or directory And pass "--with-pamdir=${base_libdir}/security" to configure script to fix below warning when usrmerge enabled in DISTRO_FEATURES | WARNING: ecryptfs-utils-111-r0 do_package: QA Issue: ecryptfs-utils: Files/directories were installed but not shipped in any package: /lib64/security/pam_ecryptfs.so Signed-off-by: Mingli Yu <Mingli.Yu@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01keynote: add dependency on bison-nativeJoe Slater
bison/yacc is no longer automatically supplied. Signed-off-by: Joe Slater <joe.slater@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01libseccomp: Drop RDEPENDS on bashAlex Kiernan
Commit ada3eee ("libseccomp: fix rdepends") added RDEPENDS on bash, but this is no longer needed, so drop it. Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01suricata: update 4.0.5Armin Kuster
Fix rules make. Don't allow the makefile to download the rules. Use fetcher add install configs and remove manual intall of those files Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-09-01libhtp: update to 0.5.27Armin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: rename ${PN}-python to ${PN}-socketcontrolKoen Kooi
This describes the content a lot better. RDEPENDS are still missing, so it's still as non-working as before :/ Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: install and package threshold.configKoen Kooi
This fixes the following warning during startup: suricata[24522]: 31/7/2018 -- 13:47:15 - <Warning> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "/etc/suricata//threshold.config": No such file or directory Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: install and package rulesKoen Kooi
This fixes the following warning during startup: suricata[22707]: 31/7/2018 -- 13:34:40 - <Warning> - [ERRCODE: SC_ERR_NO_RULES_LOADED(43)] - 47 rule files specified, but no rule was loaded at all! Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: enable syslog outputKoen Kooi
This fixes the following error preventing startup in daemon mode: suricata[20485]: 31/7/2018 -- 13:19:48 - <Error> - [ERRCODE: SC_ERR_MISSING_CONFIG_PARAM(118)] - NO logging compatible with daemon mode selected, suricata won't be able to log. Please update 'logging.outputs' Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricate: create and package logdirKoen Kooi
This fixes the following error preventing startup: suricata[18771]: 31/7/2018 -- 13:08:21 - <Error> - [ERRCODE: SC_ERR_LOGDIR_CONFIG(116)] - The logging directory "/var/log/suricata/" supplied by /etc/suricata/suricata.yaml (default-log-dir) doesn't exist. Shut> Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: add systemd unitKoen Kooi
Based on the debian systemd unit. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: add 'nfq' PACKAGECONFIGKoen Kooi
For inline IPS nfqueue is nice to have, so add a PACKAGECONFIG entry for it. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: mark config file as CONFFILEKoen Kooi
This preserves user edits during package upgrades. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: fix packagingKoen Kooi
Move ${PN}-python in front so ${PN} can use default packaging rules. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04suricata: don't start service in postinstKoen Kooi
Apart from hardcoding the wrong networking device it won't survive device restart Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-08-04nmap: remove recipe as it is in meta-oe nowArmin Kuster
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-07-07clamav: update postinitArmin Kuster
log_check] WARNING: Intentionally failing postinstall scriptlets of ['suricata', 'clamav'] to defer them to first boot is deprecated. Please place them into pkg_postinst_ontarget_${PN} () Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-07-07suricata: update postinitArmin Kuster
[log_check] WARNING: Intentionally failing postinstall scriptlets of ['suricata', 'clamav'] to defer them to first boot is deprecated. Please place them into pkg_postinst_ontarget_${PN} () Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-07-03CVE-2018-11652 nikto: arbitray OS command injection via http server field.Nagalakshmi Veeramallu
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. Signed-off-by: Nagalakshmi Veeramallu <nveeramallu@mvista.com> Reviewed-by: Jagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com> Signed-off-by: Armin Kuster <akuster@mvista.com>
2018-07-03samhain: correct service statusChangqing Li
status get by "systemctl status samhain" is not correct. It is active(exited) now. but actually, there is a dameon running, it should be active(running). so change Type of servive. Signed-off-by: Changqing Li <changqing.li@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
2018-06-11Fix build issue for apparmor when systemd is usedJinliang Li
When systemd is used as system init manager, there is a build issue complains "can't found apparmor.service". This patch fix it. Signed-off-by: Jinliang Li <jinliang.li@linux.alibaba.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>