Jump to content
Froxlor Forum

d00p

Administrators
  • Posts

    10328
  • Joined

  • Last visited

  • Days Won

    43

Posts posted by d00p

  1. Dear Froxlor Community,
     
    as our latest stable release of froxlor is quite established now, it is time for some minor bugfixes and improvements.

    Changes in 0.9.34.1 / 0.9.34.2:

    + #1562: added always_populate_raw_post_data when create php-fpm config file
    
    + #1566: added Apache 2.4 als Auswahl im Setup
    
    + #1567: added orange/warning color in web- and traffic-progress bars (admin/customer overview)
    
    
    ~ #611: fixed function.findDirs stops after first unreadable directory
    
    ~ #1517: fixed SUSE config files not accessible
    
    ~ #1550: fixed Read config file in panels
    
    ~ #1553: fixed frische Installation auf openSuSE 13.2
    
    ~ #1554: fixed Password Reset defect / MD5 hashed password recalculated to faulty hash
    
    ~ #1555: fixed PHP Notice: Undefined variable: domain in /var/www/froxlor/scripts/jobs/cron_tasks.inc.http.10.apache.php on line 321
    
    ~ #1556: fixed libnss-mysql might return wrong username
    
    ~ #1559: fixed incorrect Mail Path
    
    ~ #1565: fixed vhosts f?r deaktivierte user werden erstellt
    
    ~ #1568: fixed ssl settings werden bei rewrite nicht angewendet
    
    ~ #1575: fixed Debian Wheezy postfix wrong sql statements or wrong main.cf
    
    ~ #1578: fixed Warnung bei Standard FTP-User
    
    ~ #1582: fixed Install prompt in Froxlor incorrect - Bind9 Start Error rndc: connect failed: 127.0.0.1#953: connection refused
    
    ~ #1583: fixed SSL aktiv obwohl kein Zertifikat hinterlegt wurde
    

    You can see all changes in our bugtracker at http://redmine.froxlor.org/versions/69

    Download: 0.9.34.2

    Update: Due to an issue with the nginx-cron file we updated the 0.9.34.1 release to 0.9.34.2

    Note: Gentoo-ebuild and Debian packages are now available.

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

    Thank you,
    d00p

  2. We have had this idea before...basically, just putt something like "Hook::callHook('name')" at any position you want to implement a hook. then have a static Hook-class that searches (defined) paths for files providing the hook-function 'name' and run it. 

  3. Dear Froxlor Community,

    today we are releasing our next major stable release 0.9.34 which (finally) brings configuration templates for Debian Jessie's services.

    The domain-import feature was enhanced, so even more fields can be specified, see http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc for more detailed information.
     
    Configuration templates for dovecot now include managesieve / sieve so you can use server-side filtering-scripts - yay :)
     
    We also changed the naming of the virtual-config files for the webserver to allow the use of nth-level subdomains (sub.sub.sub.domain.tld or even deeper). And for apache, we now support mpm-itk.

    Additionally, a community driven feature was merged which allows the viewing of older statistics, when using awstats.

    Our database-integrity-check now checks for correct membership of webserver- and local froxlor-user/group when using FCGID / php-fpm or mpm-itk.

    Important: The already deprecated configuration templates for the following distributions have been dropped: Debian Squeeze (6.x), Ubuntu Lucid (10.04) and SUSE Linux Enterprise. We also had to drop support for FreeBSD because no one in the team uses it and can test the config (feel free to contact us, if you do!).
     
    Changes in 0.9.34:

    + #545: add access to older statistics when using awstats
    
    + #957: added managesieve/sieve to configuration-templates of dovecot
    
    + #1400: added support for apache mpm-itk
    
    + #1485: check for existence of ssl-files and if not, do not create ssl-related vhost-settings
    
    + #1486: added possibility to specify umask when using FCGID
    
    
    ~ #1488: fixed css issues
    
    ~ #1491: fixed changing of webserver-user/group in the users-table when they were changed in the settings
    
    ~ #1492: fixed missing LSB tags for php-fcgi on debian based distros
    
    ~ #1503: fixed database-connection when using sockets, do not replace 'host' value but use 'socket'
    
    ~ #1507: fixed open_basedir-path when using mod_php
    
    ~ #1512: enhanced domain-import, see http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc
    
    ~ #1535: fixed problem when using sub-subdomain (or deeper) with apache due to file-naming
    
    ~ #1541: enhanced default ssl-cipher-list to be more secure
    
    
    - #xxxx: removed webftp-script as we think this is a possible security issue and not necessary
    

    You can see all changes in our bugtracker at http://redmine.froxlor.org/versions/55

    Download: 0.9.34

    Note: Gentoo-ebuild and Debian packages are now available.

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

    Thank you,
    d00p

  4. Hi

    actually this fix is missing the removal of the compromised logfiles, otherwise it fixes future logging of passwords, but not the access to the logfile that has been compromised.

     Sorry, as i was pushed to do a release it just got lost in the hurry...removing all .log files from the directory should do the job, alternatively just use the class.ConfigIO.php from Github (https://github.com/Froxlor/Froxlor/blob/0_9_34/lib/classes/webserver/class.ConfigIO.php)

  5. Dear Froxlor-community,
     
    due to a severe security issue in the database logging system, we strongly recommend to update your current froxlor installation to 0.9.33.2. We also recommend to remove any content from the /froxlor/logs/ directory.

    Download: 0.9.33.2

    Note: Gentoo-ebuild and Debian packages are now available..

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

    Thank you,
    d00p

  6. Daf?r ist FTP auch nicht gedacht, schon garnicht f?r Kunden. Wenn du als root-user ungerne auf der Konsole spielst, sondern Dateien lieber "Explorer"-like browsed, empfehle ich dir Tools wie "WinSCP"

  7. Looks like you are using the (very old) spamassassin-module which was community-based (not part of froxlor!) - your database knows about the language files but you seem to have removed them from your froxlor-directory

  8. Dear Froxlor Community,

     

    today we are releasing our next major stable release 0.9.33 which includes a bunch of improvements and some interesting new features.

     

    Starting with this version, froxlor allows to move customers from one admin to another (including all resources like domains etc.). Due to the wish of some community members, we included a domain-import. It can be found in the admin-domain overview, more information can be found at http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc.

     

    Also we added possibilities to define password-complexity rather then specifying a regular-expression - this makes suggested passwords in the panel match the complexity. The account passwords for admins and customers are now also hashed with the algorithm you've set in the settings. The passwords are being updated automatically when the user logs in successfully - you do not have to do anything. The default hash has been changed from MD5 to SHA256 - updaters need to set the setting manually as we do not overwrite user-settings.

     

    Additionally, an admin can now specify a custom-newsfeed for his customers which is being displayed instead of the froxlor-newsfeed.

     

    Our database-integrity-check now checks for correct UTF-8 in our tables and logs issues found and what has been fixed if necessary, this makes its actions more transparent and replicable to the admin.

     

    It is now possible to add custom notes to admin / customer profiles. Optionally this custom note can be displayed on the users dashboard.

     

    For users that really want to use sockets instead of 127.0.0.1/localhost for the database-connection can now set the "host" value in lib/userdata.inc.php to a socket-file.

     

    We have included new configuration templates for Ubuntu 14.04 and RHEL / CentOS 7.

     

    Important: the directory permissions for (new) customers changed to be more secure (0755 -> 0750), if you use FCGID or php-fpm you have to update your libnss-mysql config for this to work, you can see changes in the config-templates at http://config.froxlor.org (chose your distribution and your current version and click "show differences").

     

    Note: Many people seem to be having issues with php-fpm / libnss / user-group permissions - nscd can be a party-killer sometimes, try to clear its cache using nscd --invalidate=group

     

    Changes in 0.9.33:

    + #1289: use password-hash from froxlor-settings for admin/customer accounts
    
    + #1335: added possibility to use a socket-file for the database-connection
    
    + #1408: added custom newsfeed on customer-dashboard
    
    + #1410: added possibility to move customer between admins
    
    + #1414: added configuration templates for Ubuntu 14.04 LTS
    
    + #1452: added domain import (CSV file), infos at http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc
    
    + #1471: added custom-notes field in admin and customer profiles
    
    
    ~ #1426: fixed utf-8 encoding problem (use db-integrity check)
    
    ~ #1427: fixed the way php was included in nginx-vhosts
    
    ~ #1430: fixed various nginx-vhost problems
    
    ~ #1437: fixed cron-problem in FreeBSD
    
    ~ #1440: fixed ip-validation in some special cases
    
    ~ #1446: fixed nginx auto-index problem
    
    ~ #1447: fixed libnss-configs for customer-docroot chmod 750
    
    ~ #1455: fixed directory-protection with apache-2.4
    
    ~ #1458: fixed incorrect security check on mail-directories where various special-characters are allowed
    
    ~ #1459: fixed deprecated postfix configuration templates in debian
    
    ~ #1465: fixed dovecot-transport configuration in ubuntu
    
    ~ #1466: fixed design-issues when no add-link is present in overviews
    
    ~ #1468: fixed installer when mysql strict-mode is used
    
    ~ #1483: fixed possible orphaned lock-file from cronjob
    Changes in 0.9.33.1:

     

    ~ #1489: fixed mysql-connection problem when using a private-network IP
    
    ~ #1498: fixed nginx vhost merging in case of variables in vhost, e.g. ${variable}
    
    ~ #1500: fixed global PEAR path for php-fpm
    You can see all changes in our bugtracker at http://redmine.froxlor.org/versions/64 and http://redmine.froxlor.org/versions/65 (also changes in 0.9.33-rc1, changes in 0.9.33-rc2)

     

    Download: 0.9.33.1

     

    Note: Gentoo-ebuild and Debian packages are now available.

     

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

     

    Thank you,

    d00p

  9. Dear Froxlor Community,

    today we announce the second release candidate of our next major release 0.9.33.
     
    Our database-integrity-check now logs issues found and what has been fixed if necessary, this makes its actions more transparent and replicable to the admin.
     
    The account passwords for admins and customers are now also hashed with the algorithm you've set in the settings. The passwords are being updated automatically when the user logs in successfully - you do not have to do anything. The default hash has been changed from MD5 to SHA256 - updaters need to set the setting manually as we do not overwrite user-settings.
     
    It is now possible to add custom notes to admin / customer profiles. Optionally this custom note can be displayed on the users dashboard.
     
    For users that really want to use sockets instead of 127.0.0.1/localhost for the database-connection can now set the "host" value in lib/userdata.inc.php to a socket-file.
     
    We have included new configuration templates for Ubuntu 14.04 and RHEL / CentOS 7.
     

    Changes in 0.9.33-rc2:

    + #1289: use password-hash from froxlor-settings for admin/customer accounts
    
    + #1335: added possibility to use a socket-file for the database-connection
    
    + #1414: added configuration templates for Ubuntu 14.04 LTS
    
    + #1471: added custom-notes field in admin and customer profiles
    
    
    ~ #1427: fixed the way php was included in nginx-vhosts
    
    ~ #1459: fixed deprecated postfix configuration templates in debian
    
    ~ #1465: fixed dovecot-transport configuration in ubuntu
    

    You can see all changes in our bugtracker at http://redmine.froxlor.org/versions/56

    Download: 0.9.33-rc3 (Updated to rc3 due to password-hash-update-iusse, see bug #1479)

    Note: As this is a release candidate, there will be no Debian packages. Gentoo users might use the testing ebuild (froxlor-9999).

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

    Thank you,
    d00p

  10. Dear Froxlor Community,

     

    today we announce the first release candidate of our next major release 0.9.33 which includes a bunch of improvements and some interesting new features.

     

    Starting with this version, froxlor allows to move customers from one admin to another (including all resources like domains etc.). Due to the wish of some community members, we included a domain-import. It can be found in the admin-domain overview, more information can be found at http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc.

     

    Also we added possibilities to define password-complexity rather then specifying a regular-expression - this makes suggested passwords in the panel match the complexity. Additionally, an admin can now specify a custom-newsfeed for his customers which is being displayed instead of the froxlor-newsfeed.

     

    The newly introduced database-integrity-check now also makes sure, the froxlor-database is 100% UTF-8.

     

    Important: the directory permissions for (new) customers changed to be more secure, if you use FCGID or php-fpm you have to update your libnss-mysql config for this to work, you can see changes in the config-templates at http://config.froxlor.org (chose your distribution and your current version and click "show differences").

     

    Changes in 0.9.33-rc1:

    + #1408: added custom newsfeed on customer-dashboard
    
    + #1410: added possibility to move customer between admins
    
    + #1452: added domain import (CSV file), infos at http://redmine.froxlor.org/projects/froxlor/wiki/DomainBulkActionDoc
    
    
    ~ #1426: fixed utf-8 encoding problem (use db-integrity check)
    
    ~ #1430: fixed various nginx-vhost problems
    
    ~ #1437: fixed cron-problem in FreeBSD
    
    ~ #1440: fixed ip-validation in some special cases
    
    ~ #1446: fixed nginx auto-index problem
    
    ~ #1447: fixed libnss-configs for customer-docroot chmod 750
    
    ~ #1455: fixed directory-protection with apache-2.4
    
    ~ #1458: fixed incorrect security check on mail-directories where various special-characters are allowed
    
    ~ #1466: fixed design-issues when no add-link is present in overviews
    
    ~ #1468: fixed installer when mysql strict-mode is used
    You can see all changes in our bugtracker at http://redmine.froxlor.org/versions/49

     

    Download: 0.9.33-rc1

     

    Note: As this is a release candidate, there will be no Debian packages. Gentoo users might use the testing ebuild (froxlor-9999).

     

    Visit http://www.froxlor.org or join our IRC channel #froxlor on irc.freenode.net.

     

    Thank you,

    d00p

  11. Why automatically? Why not stick to the way we handle resources and provide a possibility to let the admin assign an amount of repos and the customer creates them from within the panel like a mysql-db or a ftp-user?

     

    Also, it's very specific (had a patch for svn-repos-for-customers years ago never meeged it as too few people would actually need it).

     

    But generally a nice idea

  12. Hast du den Source der Backup Funktion noch irgendwo?

    Wir nutzen GIT zur Verwaltung unseres Quelltextes, es ist alles noch da. Auch der Stand von vor X Jahren - das ist ja sinn der Sache. Hier kannst du dir z.B. auf github alle unsere Releases anschauen/runterladen: https://github.com/Froxlor/Froxlor/releases

     

    Darf ich aus reiner neugier fragen, wieso der APS Installer entfernt wurde? Der hat doch super funktioniert. Ich hab mich gerade tot gesucht, wieso der bei mir nicht mehr da ist, dann bin ich hier auf die Information gesto?en, dass dieser Entfernt wurde.

    Lies bitte die entsprechenden Announcements, auch die der release-candidates, etc. da steht es drin. Und "super funktioniert" hat der sicher nicht.

×
×
  • Create New...