root/fwknop/tags/fwknop-1.9.1/ChangeLog

Revision 979, 32.1 kB (checked in by mbr, 9 months ago)

version 1.9.1

  • Property svn:eol-style set to native
  • Property svn:keywords set to Author Date Id Revision
Line 
1 fwknop-1.9.1 (01/26/2008):
2     - Added ENABLE_OUTPUT_ACCESS keyword to access.conf file parsing. This
3       provides a similar configuration gate for the iptables OUTPUT chain to
4       the ENABLE_FORWARD_ACCESS keyword, and adds the abiliy to control which
5       access.conf SOURCE blocks interface to the OUTPUT chain.
6     - Better installation support for various Linux distributions including
7       Fedora 8 and Ubuntu.  The current runlevel is now acquired via the
8       "runlevel" command instead of attempting to read /etc/inittab (which
9       does not even exist on Ubuntu 7.10), and there are new command line
10       arguments --init-dir, --init-name, and --runlevel to allow the init
11       directory, init script name, and the runlevel to be manually specified
12       on the install.pl command line.
13     - Added command line argument display to fwknop client --verbose mode.
14     - Updated the test suite to include OUTPUT chain tests, reference
15       access.conf files in the test/conf/ directory, and perform SPA packet
16       format validation tests by parsing fwknopd output.
17     - Updated fwknopd to use always use the -c argument on the knoptm command
18       line (this makes sure that the test suite usage of fwknopd causes knoptm
19       to reference the correct configuration).
20     - Updated IPTables::ChainMgr to print iptables command output to stdout or
21       stderr if running in debug or verbose mode.
22     - Added --Exclude-mod-regex to install.pl so that the installation of
23       particular perl modules that match the supplied regex can be skipped.
24     - Added SIGALRM wrapper to the test suite since some libpcap and system
25       combinations break the ability of fwknopd to sniff packets.
26     - Added srand() call to the fwknop client (this is useful for older
27       versions of perl which do not automatically call srand() at the first
28       rand() call if srand() was not already called).
29     - Added a test to the test suite for sniffing packets over the loopback
30       interface.
31     - Added SPA packet aging test to the test suite to ensure that packet
32       expirations work properly (this feature protects against MITM attacks
33       where a valid SPA packet is stopped by an inline attacker and
34       retransmitted at a later time to acquire access).
35     - Added a file (test.log) to collect test suite console output.
36     - Added --Prepare-results argument to test suite to anonymize test results
37       and create a tarball that can be emailed to a third party to assist in
38     - Added full firewall policy dumps and the collection of system specifics
39       to the test suite. This makes it easy to send the output directory and
40       the test.log file to developers to assist in debugging (no information
41       is sent anywhere except as part of a manual process of course, and
42       addresses can be anonymized with --Prepare-results - loopback addresses
43       are not modified).
44     - Added --fw-del-ip <IP> argument to fwknopd so that a specific IP address
45       can be removed from the local firewall policy (this is used by the test
46       suite to ensure that if a test for removed firewall rules fails then
47       subsequent tests will not also fail because they are no longer tracked
48       by a running knoptm instance).
49     - Added a test to the test suite to collect fwknopd syslog output.  This
50       is useful to see if a mechanism such as SELinux is deployed in a manner
51       that prevents normal fwknop communications.
52     - Bugfix to track MD5 digest for SPA command mode packets.
53     - Bugfix in fwknopd to not open ports listed in OPEN_PORTS in the absence
54       of the PERMIT_CLIENT_PORTS directive when an SPA packet contains a
55       request for access to a port not listed in OPEN_PORTS.
56       debugging fwknop if there are any issues.
57     - Added --verbose flag to fwknopd commands issued by the test suite so
58       that more data is collected for debugging analysis.
59     - Added GnuPG tests to the test suite with dedicated keys (for use only
60       with the test suite) in the test/conf/client-gpg and
61       test/conf/server-gpg directories.
62     - Added digest file validation to test suite to make sure that fwknopd
63       correctly tracks SPA packet MD5 digests.
64     - Updated to search state tracking rule in any iptables chain (many
65       iptables policies have user-defined chains that can be a bit complicated
66       to parse).
67     - Updated install.pl to be more strict in stopping any running fwknopd
68       processes.
69
70 fwknop-1.9.0 (12/15/2007):
71     - Added a test suite so that fwknop and fwknopd functionality can be
72       automatically tested over the loopback interface (see the fwknop_test.pl
73       script in the test/ directory).
74     - Major update to allow SPA packets to create DNAT connections to internal
75       systems through the FORWARD chain (iptables only).  This is useful to
76       connect through to internal systems (that may be running on non-routable
77       IP addresses) via a border firewall or router that is running fwknopd to
78       create inbound DNAT rules.
79     - Added support for the iptables OUTPUT chain via two new variable in the
80       fwknop.conf file: ENABLE_IPT_OUTPUT and IPT_OUTPUT_ACCESS. This is
81       useful for iptables firewalls that are not running the conntrack modules
82       and that have a restrictive OUTPUT chain (so SYN/ACK responses are not
83       allowed out without an explicit ACCEPT rule).
84     - Added the ability to force the fwknopd and knoptm daemons to restart
85       themselves (via knopwatchd) after a configurable timeout (see the
86       ENABLE_VOLUNTARY_EXITS and EXIT_INTERVAL variables in the
87       /etc/fwknop/fwknop.conf file). This feature is for those that want
88       fwknopd to go through its initialization routine periodically just in
89       case there is a logic (or other) bug that might result in fwknopd not
90       accepting a valid SPA packet. NOTE: This feature is disabled by default,
91       and is not normally needed since fwknopd is quite stable in most
92       deployments.
93     - Major update to perform all firewall rule expirations with knoptm, which
94       is now started in all data collection modes.  Older versions of fwknopd
95       maintained its own firewall rule expiration code for the FILE_PCAP,
96       ULOG_PCAP, and KNOCK modes, so two mechanisms were being maintained for
97       the same purpose.  The 1.9.0 release fixes this oversight.
98     - Minor bugfix to have knopwatchd generate syslog messages whenever an
99       fwknop daemon needs to be restarted.
100     - Added --interface command line argument to install.pl to allow the
101       sniffing interface to be specified from the command line. Also updated
102       install.pl to enforce a 10-try maximum for attempting to accept a valid
103       interface name from the command line (LANG env issues can exist
104       sometimes).
105     - Updated SPA packet format for server_auth and forward_info elements;
106       the internal MD5 sum is now always the last field in an SPA packet. This
107       makes extensions of the SPA protocol much easier, and the generation of
108       SPA packets more elegant. Also, SPA packet validation has been improved
109       to ensure that fields that are supposed to be digits really only contain
110       integer data.
111     - Added ENABLE_FORWARD_ACCESS variable to the access.conf file, and added
112       ENABLE_IPT_FORWARDING to the fwknop.conf file. These variables provide
113       the per-SOURCE ability to create DNAT connnections through the FORWARD
114       chain..
115     - Replaced the IPT_AUTO_CHAIN1 variable with IPT_INPUT_ACCESS and
116       IPT_FORWARD_ACCESS in fwknop.conf.
117     - Added --Forward-access argument to the fwknop client.
118     - Added client version number to syslog messages generated by fwknopd when
119       a valid SPA packet is received.
120     - Added human readable timestamp to MD5 cache. Here is an example of the
121       update format:
122         127.0.0.1 X6WF2C29kEgAv4aDJ8TDeQ [Wed Nov 28 09:24:46 2007]
123     - Added --Count argument to fwknopd so that it calls exit() when the
124       specified number of packets is monitored.
125     - Added --no-logs argument to knoptm in support of the test suite so that
126       no emails are generated.
127     - Bugfix in fwknopd to account for non-Ethernet link layer header over
128       *BSD loopback interfaces.
129     - Added --Save-dst argument to the fwknop client to add a priority file to
130       store client command line arguments (~/.fwknop.save). This file is only
131       overwritten when --Save-dst is used.
132     - Added fwknopd --fw-del-chains to allow the fwknopd iptables chains to
133       easily be deleted.
134     - Minor fwknopd bugfix to set process exit status to 0 when --Kill is
135       used.
136
137 fwknop-1.8.3 (11/17/2007):
138     - Updated external IP resolution to point to http://www.whatismyip.org,
139       and added http://www.cipherdyne.org/cgi/clientip.cgi as a backup site
140       for fwknop IP resolution.
141     - Added storage of source IP along with SPA MD5 sum. This allows the user
142       to infer which networks are more hostile if an SPA packet is replayed.
143     - Added SPA packet hex dumps in 'fwknopd --debug' mode so that the
144       integration of third-party encryption algorithms is easier to
145       troubleshoot. Sean Greven contributed a patch for this.
146     - Reinstated the legacy port knocking mode. It appears that all encrypted
147       output from the updated Crypt::Rijndael module is at least 32 bytes
148       long, so port knocking sequences are now 32 bytes long as well (they
149       were previously 16 bytes long in old versions of fwknop).
150     - Bugfix to ensure the key length is at least 8 chars in --get-key mode.
151     - Minor update to remove init message on OS X install.
152     - Updated install.pl to set the LANG environmental variable to
153       "en_US.UTF-8". This should fix the problem where the output of ifconfig
154       was not interpreted correctly if the locale LANG setting is not English.
155     - Implemented verbose email alerting by setting the ALERTING_METHODS
156       variable to "verbose". This instructs fwknopd to generate a new email
157       message for each message that it normally logs vis syslog (this feature
158       is not the default, and must be manually enabled).
159
160 fwknop-1.8.2 (09/15/2007):
161     - Added fwknopd server support for Mac OS X. The Darwin uname return
162       string is detected and this enables Darwin-specific installation code in
163       install.pl.
164     - Updated to not print sensitive key/password information in --debug mode
165       with fwknopd.
166     - Bugfix for install.pl on Windows 2003 Server running under Cygwin where
167       'uname -o' output is reported 'Gygwin' for some reason.
168     - Added --Cygwin-install command line argument to install.pl to force
169       client-only fwknop install on Cygwin systems.
170     - Added --OS-type command line argument to install.pl to allow the user to
171       force the installation type.
172     - Updated to version 1.04 of Crypt::Rijndael. This fixes incompatibilities
173       between SPA packets between 64-bit and 32-bit platorms.
174     - Bugfix to enforce a maximum of 20 tries to read a password from stdin.
175     - Applied TCP options parsing fix from psad for invalid zero or one length
176       fields that break TLV encoding (this is for fwknopd, and only applies to
177       the legacy port knocking mode).
178     - Added code to fwknopd to check to see if there are any state tracking
179       rules in place within the local iptables or ipfw policy.
180     - Made syslog identity, facility, and priority configurable (applied code
181       from the psad project).
182     - Implemented --fw-list for ipfw firewalls.
183     - Bugfix for knoptm removing ipfw rules too quickly after not timing out
184       previously instantiated rules properly.
185     - Implemented smarter cache removal strategy in knoptm so that rules that
186       are manually removed from the running iptables or ipfw policy are also
187       removed from the cache.
188     - Added /var/log/fwknop/errs/fwknopd.{warn,die} tracking to the fwknopd
189       daemon for the PCAP modes of collecting packet data. Added
190       knoptm{warn,die} files for knoptm as well.
191     - Bugfix to import the GnuPG::Interface module in --get-key mode.
192     - Bugfix to send source IP as a part of the command message in command
193       mode so that REQUIRE_SOURCE_ADDRESS controls can be applied.
194     - Added --Test-mode to fwknop client so that SPA packets can be built but
195       never sent over the network.
196
197 fwknop-1.8.1 (06/06/2007):
198     - Bugfix to ensure that the "keep-state" directive is added to firewall
199       rules on systems running the ipfw firewall.
200     - Added the --Save-packet and --Save-packet-file command line arguments
201       to the fwknop client. These options instruct fwknop to save a copy of
202       an encrypted SPA packet before it is sent across the network.
203     - Bugfix to find minimal unused ipfw rule number for ipfw firewalls. This
204       fixes an issue where ipfw rules added by fwknopd could be inserted at
205       the same position as rules from an existing ipfw policy. While ipfw
206       allows duplicate rules, whenever such a rule is deleted by its rule
207       number all matching rules are deleted.
208
209 fwknop-1.8 (06/03/2007):
210     - Added support for ipfw firewalls (found on *BSD systems).  The
211       IPTables::Parse and IPTables::ChainMgr modules are not installed on
212       such systems.
213     - Added gpg-agent support for both the fwknop client and fwknopd SPA
214       server.
215     - Updated client-only installation mode to restrict perl module
216       installation to those module that are actually required by the fwknop
217       client. This results in clean installs of the fwknop client on Windows
218       systems running Cygwin.
219     - Added --Defaults to install.pl so that fwknop can be installed without
220       prompting the user to answer any questions. This is to make it easier
221       to install fwknop on the Source Mage Linux distro.
222     - Consolidated daemon config files into the fwknop.conf file (except for
223       the access.conf file). This simplifies the configuration of fwknop.
224     - Added recursive variable resolution in the parsing routines for the
225       fwknop.conf file. This allows variable values to contain embedded
226       variables.
227     - Added init script for FreeBSD systems.
228     - Added --BSD-install command line argument to install.pl. This is not
229       normally necessary since the installer should detect installations on
230       *BSD systems, but this option can force this behavior.
231     - Updated knopmd and knopwatchd to use safe_malloc() instead of malloc().
232     - Bugfix to never time out rules from SOURCE blocks with FW_ACCESS_TIMEOUT
233       set to zero
234
235 fwknop-1.0.1 (01/09/2007):
236     - Updated fwknopd to allow the GPG_REMOTE_ID variable to have the value
237       "ANY" to allow a SOURCE block to match on arbitrary remote gpg signing
238       keys (Leland Weathers).
239     - Bugfix to allow OPEN_PORTS to be omitted in access.conf in favor of
240       having only PERMIT_CLIENT_PORTS enabled (reported by Raul Siles).
241     - Added the cd_rpmbuilder script to make it easy to build RPM's out of
242       CipherDyne projects by automatically downloading the project .tar.gz and
243       .spec files from http://www.cipherdyne.org/.
244
245 fwknop-1.0 (11/05/2006):
246     - Bugfix for OpenSSH-4.3p2 patch to make sure to include the spa.h header
247       file.
248     - Bugfix for access hashes accumluating when multiple ports are requested
249       to be opened by a client.
250     - Better validation of IPT_AUTO_CHAIN variable so that the from_chain
251       cannot be identical to the to_chain.
252     - Bugfix in RPM to install List::MoreUtils.
253     - Bugfix so that the MD5 sum for an SPA packet is not examined for each
254       SOURCE block.  This fixes a problem where an SPA packet could appear to
255       be replayed if multiple SOURCE blocks are defined in
256       /etc/fwknop/access.conf.
257     - Refactored main SPA access loop so that it is clearer how and when SPA
258       clients are granted access.
259     - Better handling of GnuPG key identifier strings (they can now contain
260       spaces, and syslog messages wrap the identifiers with double quotes).
261     - Added source IP address to command string in the SPA packet so that
262       the REQUIRE_SOURCE_ADDRESS criteria can be applied by the fwknopd
263       server.
264     - Added --Show-last-cmd and --Show-host-cmd args to fwknop so that the
265       last fwknop command and the last fwknop host commands can be viewed.
266     - Added the svn revision number to --Version and --help output.
267
268 fwknop-0.9.9 (10/15/2006):
269     - Added REQUIRE_SOURCE_ADDRESS (disabled by default) to force fwknop
270       clients to know their source IP address (i.e. -s cannot be used).  So,
271       either fwknop clients have to use -R to resolve their externally
272       routable address, or they must just know what it is.
273     - Updated to Net-RawIP-0.21_03 for compatibility with gcc-4.x compilers.
274     - Added List-MoreUtils-0.22 which is a dependency of the new Net::RawIP
275       module.
276     - Bugfix to restore "start" functionality in Gentoo init script.
277     - Bugfix to use the IPT_OUTPUT_FILE and IPT_ERROR_FILE configuration
278       variables in fwknopd.
279     - Added KNOPTM_IPT_OUTPUT_FILE and KNOPTM_IPT_ERROR_FILE variables
280       specifically for the knoptm daemon so that it can use IPTables::ChainMgr
281       completely independently of fwknopd (this removes a potential race
282       condition between fwknopd and knoptm).
283
284 fwknop-0.9.8 (09/17/2006):
285     - Added the ability to ignore old SPA packets through use of the
286       client-side time stamp.  This means that an attacker cannot intercept an
287       SPA packet, prevent it from being forwarded to its intended destination,
288       and then put the packet on the wire at some time outside of the allowed
289       time window.  There are two new configuration options in fwknop.conf
290       "ENABLE_SPA_PACKET_AGING" and "MAX_SPA_PACKET_AGE" that control the
291       length of the acceptable time window (2 minutes by default).  This
292       requires some level of synchronization between the fwknop client and the
293       fwknopd server, but this is not onerous through the use of NTP.  This
294       feature is enabled by default, and the idea for it was contributed by
295       Sebastien J.
296     - Completely re-worked IPTables::ChainMgr to support the return of
297       iptables error messages that are collected via stderr.  This is critical
298       to fixing any bugs where fwknopd could die as a result of a poorly
299       crafted iptables command.
300       but no information would be returned to the user.
301     - Added the ability to specify the position for both the jump rule into
302       the fwknopd chains as well as the position for new rules within the
303       fwknopd chains via the -I argument to iptables.  This fixes a bug where
304       the user was given the impression that the IPTABLES_AUTO_RULENUM would
305       accomplish this (IPTABLES_AUTO_RULENUM has been removed).
306     - Updated fwknopd to require < 1500 byte payload length before attempting
307       to decrypt.  Also, GnuPG decrypts are not attempted unless the encrypted
308       payload is at least 400 bytes long (this is conservative since even
309       encrypting a single byte with a 1024-bit key will result in about 340
310       bytes of encrypted data).
311     - Added the --gpg-default-key option to have fwknop use the default GnuPG
312       key that is defined in the ~/.gnupg/options file.
313     - Added the --URL command line argument so that a URL other than the
314       default http://www.whatismyip.com/ can be provided by the user for
315       external IP resolution (suggested by Sebastien J.).
316     - Updated to be more rigorous with md5 sums; we now require that the
317       md5_base64() function actually returns a non-null result.
318     - Bugfix to make sure that only the users associated with the a specific
319       REQUIRE_USERNAME value (in a specific SOURCE block in access.conf) are
320       granted the appropriate access even if a valid encrypted packet is
321       constructed from a different user name (by an fwknop client).
322     - Populated the _debug option in the IPTables::ChainMgr module, and also
323       added a _verbose option so that the specific iptables commands can
324       actually be seen as IPTables::ChainMgr functions are called.
325     - Added code to install.pl to update command paths in fwknop.conf and
326       knopwatchd.conf if any of the paths are broken (i.e. the local system
327       does not conform to the default paths).  By default this only happens if
328       the user does not want old configs to be merged, but to override this
329       use the new --path-update command line argument to install.pl.
330     - Added the --Skip-mod-install command line argument to install.pl to
331       allow all perl module installs to be skipped.
332     - Added the --force-mod-regex command line argument to install.pl to allow
333       a regex match on perl module names to force matching modules to be
334       installed.
335     - Minor bugfix to generate better (i.e. closer to those that Firefox
336       generates) http requests to http://www.whatismyip.com/).
337     - Adapted Mate Wierdl's RPM patch from the psad project so that the fwknop
338       RPM builds on x86_64 systems.
339     - Removed iptables requirement in RPM spec file because fwknop may be
340       installed on a system just to run the fwknop client.
341     - Updated to email username mismatch errors.
342
343 fwknop-0.9.7 (08/04/2006):
344     - Added fwknop_serv to function as minimal TCP server over which SPA
345       packets can be sent.  This allows SPA to be compatible with the Tor
346       network, which requires that a virtual circuit is established before
347       traffic can be sent.
348     - Updated to Crypt::CBC-2.18 after a vulnerability was discovered in
349       previous versions of Crypt::CBC that caused weak ciphertext to be
350       generated for algorithms that have blocksizes greater than 8 bytes (such
351       as Rijndael used by fwknop).  Manually specifying initialization vectors
352       is not necessary now.
353     - Updated SSH patch to support OpenSSH-4.3p2.
354     - Bugfix to make sure to create /var/* directories if they don't exist
355       (such as when /var is a tmpfs).
356     - Bugfix (Dwayne Rightler) to restore -w IP lookup functionality after
357       format change on data returned by whatismyip.com.
358     - Bugfix to wrap SPA Rijndael decryption with eval{} so that fwknopd does
359       not die if there are problems trying to decrypt data.  This is necessary
360       because of the security vulnerability fix in Crypt::CBC that creates
361       some incompatibilities in different versions of Crypt::CBC.
362     - Added "--L-host" command line argument so that the arguments used for
363       multiple hosts are preserved and can be recalled.
364     - Changed default user-agent setting for whatismyip.com lookups to
365       Firefox/1.0.5.4; there is no need to gratuitously advertise fwknop
366       traffic.
367     - Updated GunPG HOWTO to provide a step-by-step guide to getting fwknop
368       Single Packet Authorization working with GnuPG.
369     - Updated to derive perl module versions from the VERSION files within
370       each of the perl module source directories.
371
372 fwknop-0.9.6 (01/13/2006):
373     - Added GPG based authentication capability for SPA packets.  This new
374       mode can be configured to require that a GPG message be signed with a
375       particular key or set of keys.
376     - In GPG mode, the fwknop client now prints GPG errors to stdout if not
377       running with --gpg-no-batch-mode.
378     - Added the ability to require that the client know the UNIX crypt()
379       password associated with a username on the server side.  This
380       functionality is enabled on the fwknop client with the "--Server-auth
381       crypt" command line argument, and the REQUIRE_AUTH_METHOD variable in
382       /etc/fwknop/access.conf on the fwknopd server.
383     - Added patch against OpenSSH-4.2p1 to integrate SPA mode.  This patch
384       adds a "-K <fwknop cmd line>" argument to the SSH client so that
385       fwknop can be executed directly before an SSH connection is made.
386     - Separated server and client portions of fwknop into "fwknopd" and
387       fwknop repectively.  This will allow better portability to be
388       developed since the client and server pieces can be developed more
389       independently.  NOTE: With so many changes, it is probably a good idea
390       to not preserve old fwknop configs via install.pl.
391     - Renamed all relevant fwknopd command and file paths to support new
392       fwknopd server component.
393     - Added --quiet mode (this is used by default in the OpenSSH patch).
394     - Removed legacy port knocking installation in install.pl (fwknopfifo,
395       and fwdata file) unless the data collection mode is set to syslog or
396       syslog-ng for legacy iptables log messages.
397     - Added inode checking for PCAP_PKT_FILE. This helps to ensure that log
398       rotation schemes don't interfere with reading packets out of the file
399       since this check is size independent.
400     - Bugfix for Makefile debug mode.
401     - Added compilation check for perl programs in install.pl before
402       installation into the filesystem.
403     - Bugfix for knopwatchd to make sure it can actually restart all running
404       daemons properly.
405     - Added --force-mod command line argument to install.pl to allow the user
406       to force all perl modules to be be installed regardless of whether a
407       module exists in the system perl lib tree.
408     - Added --no-save-args to fwknop so that existing .fwknop.run file can
409       be preserved (helps to testing new features of fwknop client).
410     - Removed useless --encrypt command line argument (only the old shared
411       port knock sequences are not encrypted).
412
413 fwknop-0.9.5 (10/02/2005):
414     - Added the ability to resolve the external IP associated with the
415       local network via http://www.whatismyip.com.  This is a more secure
416       method of accomplishing what the -s option performs.  The new
417       command line option is --whatismyip (or just -w).
418     - Updated fwknop to communicate with knoptm via a UNIX domain socket
419       instead of the previous file-based communication.
420     - Updated to flush the fwknop iptables chains at start time.
421     - Bugfix for removing the wrong hash key in the knoptm IP cache.
422
423 fwknop-0.9.4 (09/17/2005):
424     - Bugfix for knoptm timing out new entries based on old time values
425       (this caused new rules to timed out too quickly).
426     - Added support for multiple users in REQUIRE_USERNAME keyword in
427       access.conf.
428     - Added the ability to display raw encrypted packet data in client
429       mode with --verbose.
430     - Created fwknop RPM for RPM-based Linux distributions.
431     - Bugfix for inappropriate redirects in command mode where the command
432       already contained a redirect.
433
434 fwknop-0.9.3 (08/27/2005):
435     - Added an on-disk cache of md5 sums so that the md5 sum check can
436       survive restarts of fwknop.
437     - Updated install.pl to be more friendly to Mac OS X (Blair Zajac).
438     - Updated to allow access.conf variables to have values instead of just
439       being defined.
440     - Started on additional server authentication mode code (re-worked MD5
441       sum calculation to allow packet format to be extended by taking into
442       account the fwknop version number).
443
444 fwknop-0.9.2 (08/06/2005):
445     - Added FILE_PCAP data collection method when running in server mode.
446       This is a more general way of getting packets than the ULOG_PCAP
447       mode since then a normal ethernet sniffer can be used to build the
448       file.
449     - Added the ability to re-open a pcap file if its size shrinks (i.e.
450       it gets rotated out or something).
451     - Bugfix for multiple rules with the same timestamp not being timed out
452       by knoptm.
453     - Integrated spoofing capability directly within fwknop (instead of
454       using the knopspoof command) through the use of "require Net::RawIP".
455     - Better multi-protocol support in server mode.  Tcp and icmp packets
456       are properly decoded now.
457
458 fwknop-0.9.1 (07/29/2005):
459     - Added the ability to specify multiple ports/protocols to access on a
460       server with the --Access command line option.
461     - Added the ability to spoof SPA packets over icmp and tcp protocols.
462     - Added the ability to restrict access at the server to only those
463       ports defined in the OPEN_PORTS keyword.  This option is controled by
464       a new keyword "PERMIT_CLIENT_PORTS".
465     - Bugfix for MD5 sum not being properly calculated over decrypted data.
466       This allowed old packets that contained additional garbage data to
467       be replayed against an fwknop server.
468     - Updated to fall back to getpwuid() if getlogin() fails (Blair Zajac).
469     - Added --ipt-list to list all current rules in the FWKNOP iptables
470       chains.
471     - Added --ipt-flush to flush all current rules in the FWKNOP iptables
472       chains.
473     - Bugfix for the installer dying if ~/lib already exists (Blair Zajac).
474     - Updated to delay the loading of server perl modules (Net::Pcap, etc.)
475       only if we are running in server mode.
476     - Bugfix for module directory paths in install.pl.
477
478 fwknop-0.9.0 (05/29/2005):
479     - Added new authorization mode that uses Net::Pcap to read packets
480       out of a file that is written to by the ulogd pcap writer (also
481       stubbed in code to sniff packets directly off the wire).  This
482       authorization mode only requires single packets, and has many
483       characteristics that are better than simple port knocking, including
484       being non-replayable, and much more data can be sent.  This mode
485       is now the default for both the server and the client.
486     - Made the execution of knopmd optional depending on whether AUTH_MODE
487       is a pcap mode (e.g. ULOG_PCAP or PCAP).
488     - Added --Spoof-src argument so that encrypted packets can be spoofed
489       via /usr/sbin/knopspoof.
490     - Added /usr/sbin/knoptm so that firewall rules can be timed-out when
491       the server is running in PCAP mode even if new packets don't appear
492       on the wire.
493     - Updated fwknop man page to talk about the new pcap-based
494       authorization mode.
495
496 fwknop-0.5.0 (03/19/2005):
497     - Added ALERTING_METHOD to allow syslog and/or email reporting to be
498       disabled (there is a dedicated file /etc/fwknop/alert.conf that
499       governs this behavior, and both fwknop and knopwatchd reference this
500       file).
501     - Bugfix for distinguishing OPT field associated with --log-tcp-options
502       vs. --log-ip-options.
503     - Added install_perl_module() install.pl from psad to provide a
504       consistent installation interface.
505     - Applied patch to only install perl modules that are not already
506       installed (Blair Zajac).
507     - Added --last-cmd option to allow fwknop to be executed with command
508       line arguments from the previous execution (they are saved in
509       ~/.fwknop.run).
510     - Added --Home-dir option to allow the home directory to be manually
511       specified.
512     - Re-worked get_homedir() to be more friendly to systems that do not
513       necessarily have /etc/passwd (e.g. OS X).
514     - Added configuration preservation and querying for which syslog
515       daemon is running to install.pl.  These features were adapted from the
516       psad installer (http://www.cipherdyne.org/psad).
517     - Added IPTables::ChainMgr.  Fwknop uses this module to maintain
518       dedicated chains to which access rules are added.
519     - Added IPTables::Parse, which is used internally by IPTables::ChainMgr.
520     - Added __WARN__ and __DIE__ handlers so errors can easily be collected.
521
522 fwknop-0.4.2 (09/27/2004):
523     - Added init script for Fedora systems.
524     - Added --Kill, --Restart, and --Status modes (this fixes the generic
525       init script which depends on these arguments).
526
527 fwknop-0.4.1 (09/14/2004):
528     - Bugfix for legacy posf code in fwknop and variable in fwknop.conf.
529
530 fwknop-0.4 (09/10/2004):
531     - Added ability to specify multiple IPs/networks in a single SOURCE
532       definition.
533     - Better examples section in the fwknop manpage.
534     - Bugfix to make sure EMAIL_ADDRESSES variable does not contain commas
535       (any commas are translated into spaces).
536     - Added LICENSE file.
537
538 fwknop-0.3 (08/21/2004):
539     - Bugfix for tracking knock sequences by source IP address.
540     - Bugfix for knock sequence timeouts.
541     - Removed old passive OS fingerprinting code in favor of the p0f
542       strategy.
543     - Added support for taking encryption keys from a file specified on
544       the command line.
545     - Update to send "sequence decrypt failed" email message only if
546       decryption failed for all encrypt sequence SOURCE blocks.
547
548 fwknop-0.2 (07/31/2004):
549     - Implemented remote username checking in encrypted sequences.
550     - Added support for icmp in knock sequences.
551     - Added protocol rotation option for encrypted sequences.
552     - Added code for multiple SOURCE access blocks with the same source
553       net/IP.
554     - Added KNOCK_LIMIT access control variable to limit the number of
555       times a particular knock sequence is honored.
556     - Added email alerts.
557
558 fwknop-0.1 (07/08/2004):
559     - Initial release.
Note: See TracBrowser for help on using the browser.