summaryrefslogtreecommitdiffstats
path: root/recipes-security
Commit message (Collapse)AuthorAgeFilesLines
* clamav: update to 0.99.4Armin Kuster2018-10-311-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: add fail2ban ptest to imageArmin Kuster2018-10-311-0/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* fail2ban: add ptestArmin Kuster2018-10-314-1/+15
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: add tripwire ptestArmin Kuster2018-10-311-0/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* tripwire: add ptestArmin Kuster2018-10-312-1/+11
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* security-build-image: remove X11Armin Kuster2018-10-311-3/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: add suricata-ptestArmin Kuster2018-10-311-0/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: add ptestArmin Kuster2018-10-312-1/+8
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: add few more ptest packagesArmin Kuster2018-10-311-1/+3
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: add ptest capable packagesArmin Kuster2018-10-311-1/+13
| | | | | | and favor python-scapy Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroups: add more packagesArmin Kuster2018-10-311-1/+5
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: fix QA errorArmin Kuster2018-10-311-1/+5
| | | | | | | | ollected errors: * check_data_file_clashes: Package suricata wants to install file .../1.0-r0/rootfs/var/run But that file is already provided by package * base-files Signed-off-by: Armin Kuster <akuster808@gmail.com>
* bseccomp: fix do package qa warningChangqing Li2018-09-291-1/+1
| | | | | | | | | | Fix below warning: lib32-libseccomp-2.3.3-r0 do_package: QA Issue: lib32-libseccomp: Files/directories were installed but not shipped in any package: Signed-off-by: Changqing Li <changqing.li@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keynote: remove recipeYi Zhao2018-09-294-129/+0
| | | | | | | | | The keynote is unmaintained for a long time. It had been removed from main distributions (Fedora, Suse and Debian). See: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=594867 Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* samhain: update to 4.3.0Armin Kuster2018-09-234-2/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* aircrack: update to 1.3Armin Kuster2018-09-172-35/+4
| | | | | | | remove unneeded patch. minor cleanups Signed-off-by: Armin Kuster <akuster808@gmail.com>
* packagegroup-core-security: change scapy to python nameArmin Kuster2018-09-171-1/+1
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* bastille: fix QA errorArmin Kuster2018-09-171-1/+1
| | | | | | bastille_3.2.1.bb: cannot map 'allarch' to a linux kernel architecture Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: include a emerging rules snapshotArmin Kuster2018-09-172-3/+3
| | | | | | | it appears to be changing w/o version control so keep a snapshot when reciped was updated. Signed-off-by: Armin Kuster <akuster808@gmail.com>
* apparmor: update to 2.12Armin Kuster2018-09-171-2/+2
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* fscryptctl: update to tipArmin Kuster2018-09-171-1/+1
| | | | | | fix mkfs.ext4 invocation Signed-off-by: Armin Kuster <akuster808@gmail.com>
* scapy: update to 2.4.0 and covertArmin Kuster2018-09-174-10/+16
| | | | | | convert package to python standard Signed-off-by: Armin Kuster <akuster808@gmail.com>
* fail2ban: update to 10.3.1Armin Kuster2018-09-173-5/+10
| | | | | | covert to python package standard Signed-off-by: Armin Kuster <akuster808@gmail.com>
* sssd: update to 1.16.3Armin Kuster2018-09-171-3/+3
| | | | | | | | | | Includes: CVE-2018-10852 see: https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_3.html Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keyutils: Fix build with usrmergeAlex Kiernan2018-09-171-0/+2
| | | | | | | | | | | | | | Update BINDIR and SBINDIR so keyutils builds with usrmerge ERROR: keyutils-1.5.10-r0 do_package: QA Issue: keyutils: Files/directories were installed but not shipped in any package: /sbin/key.dns_resolver /sbin/request-key /bin/keyctl Please set FILES such that these items are packaged. Alternatively if they are unneeded, avoid installing them or delete them within do_install. keyutils: 3 installed and not shipped files. [installed-vs-shipped] Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keynote: depend on openssl10Yi Zhao2018-09-171-1/+1
| | | | | Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: upgrade 1.2.25 -> 1.2.26Yi Zhao2018-09-013-82/+53
| | | | | | | | | | Drop patch xmlsec1-fix-a-typo-in-examples-verify3.c.patch since the issue had been fixed upstream. Rebase patch change-finding-path-of-nss.patch Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* samhain: upgrade 4.2.2 -> 4.2.4Yi Zhao2018-09-014-2/+5
| | | | | Signed-off-by: Yi Zhao <yi.zhao@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* ecryptfs-utils: fix usrmerge install pathMingli Yu2018-09-011-2/+7
| | | | | | | | | | | | | | | | Update rootsbindir from /sbin to ${base_sbindir} to fix below do_install error when usrmerge enabled in DISTRO_FEATURES | chmod: cannot access '/poky-build/tmp-glibc/work/core2-64-wrs-linux/ecryptfs-utils/111-r0/image/usr/sbin/mount.ecryptfs_private': No such file or directory And pass "--with-pamdir=${base_libdir}/security" to configure script to fix below warning when usrmerge enabled in DISTRO_FEATURES | WARNING: ecryptfs-utils-111-r0 do_package: QA Issue: ecryptfs-utils: Files/directories were installed but not shipped in any package: /lib64/security/pam_ecryptfs.so Signed-off-by: Mingli Yu <Mingli.Yu@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* keynote: add dependency on bison-nativeJoe Slater2018-09-011-1/+1
| | | | | | | bison/yacc is no longer automatically supplied. Signed-off-by: Joe Slater <joe.slater@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* libseccomp: Drop RDEPENDS on bashAlex Kiernan2018-09-011-1/+0
| | | | | | | | Commit ada3eee ("libseccomp: fix rdepends") added RDEPENDS on bash, but this is no longer needed, so drop it. Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: update 4.0.5Armin Kuster2018-09-011-9/+15
| | | | | | | | | Fix rules make. Don't allow the makefile to download the rules. Use fetcher add install configs and remove manual intall of those files Signed-off-by: Armin Kuster <akuster808@gmail.com>
* libhtp: update to 0.5.27Armin Kuster2018-09-012-3/+3
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: rename ${PN}-python to ${PN}-socketcontrolKoen Kooi2018-08-041-2/+2
| | | | | | | This describes the content a lot better. RDEPENDS are still missing, so it's still as non-working as before :/ Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: install and package threshold.configKoen Kooi2018-08-041-0/+2
| | | | | | | | | This fixes the following warning during startup: suricata[24522]: 31/7/2018 -- 13:47:15 - <Warning> - [ERRCODE: SC_ERR_FOPEN(44)] - Error opening file: "/etc/suricata//threshold.config": No such file or directory Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: install and package rulesKoen Kooi2018-08-041-0/+3
| | | | | | | | | This fixes the following warning during startup: suricata[22707]: 31/7/2018 -- 13:34:40 - <Warning> - [ERRCODE: SC_ERR_NO_RULES_LOADED(43)] - 47 rule files specified, but no rule was loaded at all! Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: enable syslog outputKoen Kooi2018-08-041-1/+1
| | | | | | | | | This fixes the following error preventing startup in daemon mode: suricata[20485]: 31/7/2018 -- 13:19:48 - <Error> - [ERRCODE: SC_ERR_MISSING_CONFIG_PARAM(118)] - NO logging compatible with daemon mode selected, suricata won't be able to log. Please update 'logging.outputs' Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricate: create and package logdirKoen Kooi2018-08-041-0/+2
| | | | | | | | | This fixes the following error preventing startup: suricata[18771]: 31/7/2018 -- 13:08:21 - <Error> - [ERRCODE: SC_ERR_LOGDIR_CONFIG(116)] - The logging directory "/var/log/suricata/" supplied by /etc/suricata/suricata.yaml (default-log-dir) doesn't exist. Shut> Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: add systemd unitKoen Kooi2018-08-042-2/+35
| | | | | | | Based on the debian systemd unit. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: add 'nfq' PACKAGECONFIGKoen Kooi2018-08-041-0/+1
| | | | | | | | For inline IPS nfqueue is nice to have, so add a PACKAGECONFIG entry for it. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: mark config file as CONFFILEKoen Kooi2018-08-041-0/+2
| | | | | | | This preserves user edits during package upgrades. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: fix packagingKoen Kooi2018-08-041-2/+2
| | | | | | | Move ${PN}-python in front so ${PN} can use default packaging rules. Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: don't start service in postinstKoen Kooi2018-08-041-1/+0
| | | | | | | Apart from hardcoding the wrong networking device it won't survive device restart Signed-off-by: Koen Kooi <koen.kooi@linaro.org> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* nmap: remove recipe as it is in meta-oe nowArmin Kuster2018-08-043-139/+0
| | | | Signed-off-by: Armin Kuster <akuster808@gmail.com>
* clamav: update postinitArmin Kuster2018-07-071-2/+2
| | | | | | log_check] WARNING: Intentionally failing postinstall scriptlets of ['suricata', 'clamav'] to defer them to first boot is deprecated. Please place them into pkg_postinst_ontarget_${PN} () Signed-off-by: Armin Kuster <akuster808@gmail.com>
* suricata: update postinitArmin Kuster2018-07-071-2/+2
| | | | | | [log_check] WARNING: Intentionally failing postinstall scriptlets of ['suricata', 'clamav'] to defer them to first boot is deprecated. Please place them into pkg_postinst_ontarget_${PN} () Signed-off-by: Armin Kuster <akuster808@gmail.com>
* CVE-2018-11652 nikto: arbitray OS command injection via http server field.Nagalakshmi Veeramallu2018-07-032-1/+108
| | | | | | | | | | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. Signed-off-by: Nagalakshmi Veeramallu <nveeramallu@mvista.com> Reviewed-by: Jagadeesh Krishnanjanappa <jkrishnanjanappa@mvista.com> Signed-off-by: Armin Kuster <akuster@mvista.com>
* samhain: correct service statusChangqing Li2018-07-031-1/+1
| | | | | | | | | | status get by "systemctl status samhain" is not correct. It is active(exited) now. but actually, there is a dameon running, it should be active(running). so change Type of servive. Signed-off-by: Changqing Li <changqing.li@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* Fix build issue for apparmor when systemd is usedJinliang Li2018-06-111-0/+5
| | | | | | | | When systemd is used as system init manager, there is a build issue complains "can't found apparmor.service". This patch fix it. Signed-off-by: Jinliang Li <jinliang.li@linux.alibaba.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>
* xmlsec1: remove host paths from target filesWenzong Fan2018-05-071-1/+4
| | | | | Signed-off-by: Wenzong Fan <wenzong.fan@windriver.com> Signed-off-by: Armin Kuster <akuster808@gmail.com>