Zum Inhalt springen

OPNsense Release Notes

9 Einträge aus 4 Quellen. Zuletzt aktualisiert:

Folge OPNsense, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.5: Sicherheitskorrekturen, OpenSSL 3.5.9 und argon2id

OPNsense 26.7.5 behebt mehrere sicherheitsrelevante Probleme, aktualisiert auf OpenSSL 3.5.9 und den Paketmanager 2.8.4, stellt den Standard-Passwort-Hash von bcrypt auf argon2id um (bcrypt-Hashes funktionieren weiter), verlagert die Outbound-NAT-Seite in das Legacy-Plugin und ermöglicht das Debuggen der Interface-Reihenfolge beim Booten.

This update fixes a few security related things and updates to OpenSSL 3.5.9. We are also updating the package manager to version 2.8.4 to sync up with the current version being used in FreeBSD.

The default password hash changes from bcrypt to argon2id. If you wish to benefit from this change your hashed passwords need to be changed. Note that this step is optional. All bcrypt-hashed passwords will continue to work.

The firewall outbound NAT page moves to the legacy plugin. Note that you can still migrate your rules without the plugin installed via the migration assistant and the outbound rules will continue to work even when the legacy plugin is not installed.

Since work on the interface settings API is progressing nicely, there is also work being done on the backend which is already featured in this release. It is now possible to debug the interface ordering sequence at boot, which will also help bring in more optimizations in the near future.

Here are the full patch notes:

  • system: clear password change session flag only after password was changed [1] (reported by Wu Wenhao)

  • system: change diag.disk to return total bytes as well as formatted bytes

  • system: fix HA service restart with “id” parameter set

  • system: add webgui PAM config to test with opnsense-login

  • system: switch password hashing from bcrypt to argon2id …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.4: StrongSwan 6.1.0 und überarbeitete Wireless-Geräte

OPNsense 26.7.4 bringt die Überarbeitung der Wireless-Geräte auf MVC/API, weitere Verbesserungen beim Ersatz von Outbound NAT durch Source NAT, StrongSwan 6.1.0 mit einer kleinen empfohlenen Auswahl an Post-Quanten-Schlüsselaustauschen sowie GUI-Anpassungen wie Markierung für erweiterte Optionen und ein Suchfeld in Dialogen.

Today we are rolling out the wireless device MVC/API rework and a final push for better source NAT replacement over outbound NAT.

StrongSwan was updated to 6.1.0 and the GUI now offers a small recommended set of post-quantum key exchanges.

You may also find the GUI tweaks for advanced option marker and a dialog search field helpful.

There is a lot more going on as you can see from this changelog, but more on this and future plans later!

Here are the full patch notes:

  • system: audit log injection via login username in auth_log() [1]

  • system: add pfsync version 1500 to HA settings (contributed by Bjoern Jakobsen)

  • system: add hidden services so they can be operated by pluginctl -s

  • system: privlege separated reload in static PHP pages

  • system: lower priority of automatic wg/ipsec gateways

  • system: fix disk widget loading issue (contributed by Konstantinos Spartalis)

  • system: add back the service widget link

  • system: make compare operator in authTOTP() more strict

  • interfaces: migrate wireless configuration to MVC/API

  • interfaces: return an empty string which cannot be an interface in convert_real_interface_to_friendly_interface_name()

  • interfaces: ppp-ipv6.php may be executed before later stages of interface_configure()

  • interfaces: provide “uuid” in legacy_config_get_interfaces() …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.3: VLANs auf Bridges, Menü-Favoriten und FreeBSD 15.1-p3

OPNsense 26.7.3 ergänzt VLANs auf Bridges, "received-on"-Firewallregeln, persistente Regel-Label-Verfolgung, wiederholbare WireGuard-QR-Codes, Menü-Favoriten und Vollbild-Grids und enthält zudem FreeBSD 15.1-RELEASE-p3, OpenSSL 3.5.8, OpenSSH 10.5p1 sowie Fehlerbehebungen.

Here is your biweekly dose of bugfixes and quality of life improvements! This update offers several new features: VLANs on bridges, “received-on” firewall rule support, persistent rule label tracking, repeatable WireGuard QR codes, menu favourites and full screen grid support. On top of that it bundles the recent FreeBSD 15.1-RELEASE-p3, fixes and cleanups as well as third party updates such as OpenSSL 3.5.8 and OpenSSH 10.5p1. Enjoy. :)

Meanwhile, development is busy with adding interface settings to the new MVC assignments page, which includes building wireless MVC/API support. That is all for now. Need to get back to work.

Here are the full patch notes:

  • system: offer post-quantum mldsa44-ed25519 OpenSSH server host key

  • system: do not regenerate all OpenSSH key files when adding new key types

  • system: truncate long names in services dashboard widget (contributed by circa1665)

  • system: use created user name for change event (contributed by Julian Pawlowski)

  • system: handle missing objects during deletion in API (contributed by Julian Pawlowski)

  • system: multiple PHP warning fixes (contributed by Julian Pawlowski)

  • system: avoid filter_configure() calls to make existing backend call less obscure

  • system: add favorites section to menu (contributed by Greelan)

  • system: approximate user being expired for the grid view icon

  • system: replace cron restart in static PHP pages …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Business Edition von OPNsense

OPNsense Business Edition 26.4.2 mit Source NAT als Outbound-NAT-Ersatz

OPNsense Business Edition 26.4.2 basiert auf der Community-Version 26.1.11 mit zusätzlichen Zuverlässigkeitsverbesserungen, führt Source NAT als vorläufigen Ersatz für Outbound NAT ein (Bearbeiten der Regeln in der GUI nur im Hybrid- oder Manual-Modus, ab 26.10 ist dieser Modus für das Rendern der Regeln nötig) und bringt unter anderem Verbesserungen bei Log-Archivierung, NetFlow, Live-Log-Widget und Unterstützung für 7680-Bit-RSA-Zertifikate.

This business release is based on the OPNsense 26.1.11 community version with additional reliability improvements.

Please note that this release offers source NAT as a tentative replacement for outbound NAT. Feature parity is a work in progress for the 26.10 series. For now, please be aware that source NAT continues to work as before, but the GUI will not allow you to edit the source NAT rules unless you choose hybrid or manual mode in the settings. This aligns with how the outbound NAT page is working. Starting with 26.10, the hybrid or manual mode will be required to render source NAT rules into the firewall.

Here are the full patch notes for the initial release:

  • system: improve the log_archive script to also work on log subdirectories

  • system: routing: changed “disable” option to “enable”

  • system: add “local_uri” type in SanitizeFilter() and use it to avoid hardcoding

  • system: several compatible adjustments for upcoming PHP 8.5

  • system: enhance live log widget (contributed by Greelan)

  • system: support 7680 bit RSA type for certificates and authorities

  • reporting: improve parsing in NetFlow for overlapping flow timestamps and use UTC for cleanups

  • reporting: stop NetFlow service before reloading configuration

  • interfaces: properly format API times to ISO format and convert timezone for display in automatic discovery

  • interfaces: fix typos in GIF reconfiguration script …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.2: WireGuard-MAC-Problem und Sicherheitshinweise behoben

OPNsense 26.7.2 behebt das WireGuard-MAC-Authentifizierungsproblem sowie 4 Core-Sicherheitshinweise und bringt zahlreiche Verbesserungen und Fehlerbehebungen, etwa bei NetFlow-Auswertung, Service-Widget und der Unterstützung von 7680-Bit-RSA-Zertifikaten.

This update addresses the WireGuard MAC authentication issue people have been talking about, 4 core security advisories and the usual volume of quality of life improvements and bug fixes.

We are currently improving the compatibility with the legacy pages in full privilege separation, working on feature parity between Outbound NAT and Source NAT and will also provide a road map in the next weeks for 27.1. Stay tuned.

Here are the full patch notes:

  • system: use /var/lib/php/tmp in static pages for proper privilege separation

  • system: improve “user-config-readonly” in static pages where write_config() was denied

  • system: service widget changes based on further community feedback

  • system: support 7680 bit RSA type for certificates and authorities

  • system: add redirection capability to SSO provider

  • reporting: correctly map NetFlow indexes when there are gaps (contributed by Thomas Cheyney)

  • reporting: improve parsing in NetFlow for overlapping flow timestamps and use UTC for cleanups

  • reporting: make parsing iftop lines more robust for traffic graphs (contributed by Brendan Bank)

  • reporting: map ARC and laundry to cache memory stats (contributed by Konstantinos Spartalis)

  • reporting: stop NetFlow service before reloading configuration

  • interfaces: fix assignment of wireless devices …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.1: Stabilitätsupdate mit vier Sicherheitshinweisen

OPNsense 26.7.1 ist ein kleines Stabilitätsupdate, das Upgrade-Probleme der Vorwoche und 4 neue Sicherheitshinweise im Core-Code behebt, unter anderem beim OpenVPN-Client-Export und bei lighttpd-Anfragegrößen.

This is a small stable release addressing some of the upgrade related issues that were reported last week as well as 4 new security advisories for the core code.

Here are the full patch notes:

  • system: add correct release name to boot splash screen for 26.7

  • system: disable web GUI KTLS use for the time being

  • system: do not let the components selectpicker grow indefinitely in defaults page

  • system: DTLSv1.1 is forcefully rejected by OpenSSL 3.5, migrate to DTLSv1.2

  • system: use Bootstrap “btn” styles in services widget

  • system: use serialNumberHex for CRL so high-bit serials are not dropped (contributed by chrstnth)

  • system: lower max-request-size to roughly max post size in lighttpd configs [1] (reported by lujiefsi)

  • system: fixed several PHP 8.5 warnings

  • firewall: use “urgent” as empty default for firewall debug messages

  • firewall: skip message banner if searchPhrase set

  • firewall: fix PHP warning when scrub yields no interfaces

  • captive portal: automatic block rule should be evaluated after the anti-lockout rule

  • openvpn: client export can export private keys for unlisted certificate references [2] (reported by iys8 and lujiefsi)

  • backend: remove cache file on execution error in script_output …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7 "Xenial Xenops" veröffentlicht

OPNsense 26.7 "Xenial Xenops" ist veröffentlicht und bringt Interface-Zuweisungen und Gateway-Gruppen über MVC/API, MVC/API-Firewallregeln als Standard, einen Migrationsassistenten von Outbound NAT zu Source NAT, IPv6 im Captive Portal, Kea-DDNS und dynamische Prefix Delegation sowie FreeBSD 15.1, OpenSSL 3.5, OpenVPN 2.7, PHP 8.5 und Python 3.13.

For over 11 a half years now, OPNsense is driving innovation through modularising and hardening the open source firewall, with simple and reliable firmware upgrades, multi-language support, fast adoption of upstream software updates, modern IPv6 support, as well as clear and stable 2-Clause BSD licensing.

26.7, nicknamed “Xenial Xenops”, features interface assignments and gateway groups via MVC/API, firewall rules now defaulting to MVC/API, outbound NAT to source NAT migration assistant, captive portal IPv6 support, Kea DDNS/custom options/dynamic prefix delegation, FreeBSD 15.1, OpenSSL 3.5, OpenVPN 2.7, PHP 8.5, Python 3.13, plus much more.

The upgrade path for 26.1 will likely be unlocked later today. We want to ensure the upgrade goes as smoothly as possible so please be patient! :)

Download links, an installation guide [1] and the checksums for the images can be found below as well.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.r2: Testversion vor der Veröffentlichung von 26.7

OPNsense 26.7.r2 ist eine Online-Testversion vor der finalen Veröffentlichung von 26.7 am 15. Juli mit Änderungen gegenüber RC1 wie dem Interfaces-Widget im Dashboard-Standard sowie Korrekturen bei Source NAT, Firewall, Captive Portal und Monit.

Summer challenges aside: 26.7 is almost here! It includes FreeBSD 15.1 and a somewhat small list of other highlights. The reason for that is a stringent backporting strategy that was employed in the 26.1 series.

Keep in mind this is an online-based pre-production test release. Upgrades from the 26.1.11 development version are already available. The final release date for 26.7 is July 15.

Here are the development highlights since version 26.1 came out:

  • Interfaces assignments to MVC/API

  • Gateway groups to MVC/API

  • Firewall rules MVC page is now the default

  • Source NAT is now a replacement for outbound NAT

  • Captive portal IPv6 support

  • Kea DDNS, custom options and dynamic prefix delegation support

  • OpenVPN 2.7 with TLS-Crypt v2 support

  • FreeBSD 15.1

  • OpenSSL 3.5

  • Python 3.13

  • PHP 8.5

And these are the changes against version 26.7-RC1:

  • system: include interfaces widget in dashboard default

  • firewall: constraint source NAT getAction() to only general page and align setAction() accordingly

  • firewall: use proper path for one-to-one NAT rules for renaming operations

  • firewall: avoid emitting reply-to on block rules as well

  • captive portal: adjust accounting interval to Acct-Interim-Interval

  • firmware: remove overzealous cleansing in output_cmd to unhide individual character progress

  • monit: fix mail-format and poll-time validation …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

OPNsense Community Edition von OPNsense

OPNsense 26.7.r1: Vorabversion mit Gateway-Gruppen in MVC/API

OPNsense 26.7.r1 ist eine überwiegend image-basierte Vorabversion von 26.7 mit Änderungen gegenüber 26.1.11, darunter Gateway-Gruppen in MVC/API, neues flaches Service-Widget-Layout und Entfernung der periodischen Backup-Einstellungen.

Summer challenges aside: 26.7 is almost here! It includes FreeBSD 15.1 and a somewhat small list of other highlights. The reason for that is a stringent backporting strategy that was employed in the 26.1 series.

Keep in mind this is mostly an image-based pre-production test release. Upgrades from the 26.1.11 development version will be available later this week. An online-only RC2 will probably follow as well. The final release date for 26.7 is July 15.

https://pkg.opnsense.org/releases/26.7/

Here are the development highlights since version 26.1 came out:

  • Interfaces assignments to MVC/API

  • Gateway groups to MVC/API

  • Firewall rules MVC page is now the default

  • Source NAT is now a replacement for outbound NAT

  • Captive portal IPv6 support

  • Kea DDNS, custom options and dynamic prefix delegation support

  • OpenVPN 2.7 with TLS-Crypt v2 support

  • FreeBSD 15.1

  • OPENSSL 3.5

  • Python 3.13

  • PHP 8.5

And these are the changes against version 26.1.11:

  • system: remove periodic backups settings and backend code

  • system: migrate gateway groups to MVC/API

  • system: new service widget flat tile layout (partially contributed by Konstantinos Spartalis)

  • system: make LDAP auth adhere to bad login penalty as well (contributed by Matt Andreko)

  • system: move ldap_escape() to caller for now to avoid side effects …

Originalquelle(öffnet in neuem Tab)Problem melden