Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
OPNsense Community Edition von OPNsense
OPNsense 26.7.5: Sicherheitskorrekturen, OpenSSL 3.5.9 und argon2id
OPNsense 26.7.5 behebt mehrere sicherheitsrelevante Probleme, aktualisiert auf OpenSSL 3.5.9 und den Paketmanager 2.8.4, stellt den Standard-Passwort-Hash von bcrypt auf argon2id um (bcrypt-Hashes funktionieren weiter), verlagert die Outbound-NAT-Seite in das Legacy-Plugin und ermöglicht das Debuggen der Interface-Reihenfolge beim Booten.
This update fixes a few security related things and updates to OpenSSL 3.5.9. We are also updating the package manager to version 2.8.4 to sync up with the current version being used in FreeBSD.
The default password hash changes from bcrypt to argon2id. If you wish to benefit from this change your hashed passwords need to be changed. Note that this step is optional. All bcrypt-hashed passwords will continue to work.
The firewall outbound NAT page moves to the legacy plugin. Note that you can still migrate your rules without the plugin installed via the migration assistant and the outbound rules will continue to work even when the legacy plugin is not installed.
Since work on the interface settings API is progressing nicely, there is also work being done on the backend which is already featured in this release. It is now possible to debug the interface ordering sequence at boot, which will also help bring in more optimizations in the near future.
Here are the full patch notes:
system: clear password change session flag only after password was changed [1] (reported by Wu Wenhao)
system: change diag.disk to return total bytes as well as formatted bytes
system: fix HA service restart with “id” parameter set
system: add webgui PAM config to test with opnsense-login
system: switch password hashing from bcrypt to argon2id …