Software Release - fwknop-1.8.2
16 September, 2007
data:image/s3,"s3://crabby-images/5deb7/5deb7a976e25f842d10febb60a7a0cd4f847d7ba" alt="fwknop-1.8.2 fwknop-1.8.2 release"
data:image/s3,"s3://crabby-images/dc168/dc1687f827ea5125bdde0458e504065649238b2d" alt="fwknop screenshot fwknop-1.8.2 release"
Here is the complete ChangeLog:
- Added fwknopd server support for Mac OS X. The Darwin uname return string is detected and this enables Darwin-specific installation code in install.pl.
- Updated to not print sensitive key/password information in --debug mode with fwknopd.
- Bugfix for install.pl on Windows 2003 Server running under Cygwin where 'uname -o' output is reported 'Gygwin' for some reason.
- Added --Cygwin-install command line argument to install.pl to force client-only fwknop install on Cygwin systems.
- Added --OS-type command line argument to install.pl to allow the user to force the installation type.
- Updated to version 1.04 of Crypt::Rijndael. This fixes incompatibilities between SPA packets between 64-bit and 32-bit platorms.
- Bugfix to enforce a maximum of 20 tries to read a password from stdin.
- Applied TCP options parsing fix from psad for invalid zero or one length fields that break TLV encoding (this is for fwknopd, and only applies to the legacy port knocking mode).
- Added code to fwknopd to check to see if there are any state tracking rules in place within the local iptables or ipfw policy.
- Made syslog identity, facility, and priority configurable (applied code from the psad project).
- Implemented --fw-list for ipfw firewalls.
- Bugfix for knoptm removing ipfw rules too quickly after not timing out previously instantiated rules properly.
- Implemented smarter cache removal strategy in knoptm so that rules that are manually removed from the running iptables or ipfw policy are also removed from the cache.
- Added /var/log/fwknop/errs/fwknopd.{warn,die} tracking to the fwknopd daemon for the PCAP modes of collecting packet data. Added knoptm{warn,die} files for knoptm as well.
- Bugfix to import the GnuPG::Interface module in --get-key mode.
- Bugfix to send source IP as a part of the command message in command mode so that REQUIRE_SOURCE_ADDRESS controls can be applied.
- Added --Test-mode to fwknop client so that SPA packets can be built but never sent over the network.