<feed xmlns='http://www.w3.org/2005/Atom'>
<title>leap_platform.git/puppet/modules/site_shorewall/manifests, branch 0.8.0rc1</title>
<subtitle>[leap_platform] 
</subtitle>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/'/>
<entry>
<title>specify the destination IP for DNAT rules for gateway addresses on port 443 (#6388)</title>
<updated>2014-11-20T18:13:55+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-11-20T18:13:55+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=e334f10447303209ac3802436437670f45511603'/>
<id>e334f10447303209ac3802436437670f45511603</id>
<content type='text'>
Previously the DNAT rule would redirect the incoming port 443 requests
to openvpn, which was the wrong thing to do on the primary IP (but the
right thing to do on the openvpn gateway IPs). This manifested in the
webapp not being available when it was also configured as a service on
the node.

Change-Id: Ic8c6b6c0389859fab168a7df687351e11263277a
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Previously the DNAT rule would redirect the incoming port 443 requests
to openvpn, which was the wrong thing to do on the primary IP (but the
right thing to do on the openvpn gateway IPs). This manifested in the
webapp not being available when it was also configured as a service on
the node.

Change-Id: Ic8c6b6c0389859fab168a7df687351e11263277a
</pre>
</div>
</content>
</entry>
<entry>
<title>minor linting</title>
<updated>2014-11-20T18:13:33+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-11-20T18:13:33+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=be18ba31fadd2e587672adc44175dd106187ceba'/>
<id>be18ba31fadd2e587672adc44175dd106187ceba</id>
<content type='text'>
Change-Id: I6d04cc7e028e86ee0012d96d7ef075fdd7ecef19
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I6d04cc7e028e86ee0012d96d7ef075fdd7ecef19
</pre>
</div>
</content>
</entry>
<entry>
<title>Make shorewall accept incoming traffic for obfsproxy server</title>
<updated>2014-07-01T23:05:40+00:00</updated>
<author>
<name>irregulator</name>
<email>irregulator@riseup.net</email>
</author>
<published>2014-05-21T17:42:46+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=156c2e1194c65d2f7813b946ac8baa90ffdf1f39'/>
<id>156c2e1194c65d2f7813b946ac8baa90ffdf1f39</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>stunnel: make site_mx and site_webapp use new site_stunnel</title>
<updated>2014-06-26T01:17:31+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-06-20T21:34:53+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=bc42e9bd3a86bb858ef853cf333242c81874209b'/>
<id>bc42e9bd3a86bb858ef853cf333242c81874209b</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>new generic system for stunnel: just `include site_stunnel` and stunnel + needed shorewall will be automatically set up. requires new leap_cli</title>
<updated>2014-06-26T01:17:22+00:00</updated>
<author>
<name>elijah</name>
<email>elijah@riseup.net</email>
</author>
<published>2014-06-20T08:58:39+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=49f0c54a05f6b542367f8ef4538316ba2eaac6cd'/>
<id>49f0c54a05f6b542367f8ef4538316ba2eaac6cd</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>fix incorrect shorewall parameter name 'protocol', should be 'proto'</title>
<updated>2014-05-02T20:24:00+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-05-02T20:24:00+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=c334061df623e3806c544598195eb93a805a91ce'/>
<id>c334061df623e3806c544598195eb93a805a91ce</id>
<content type='text'>
Change-Id: I9c6c798b174228d44d01b55f2a4aa19458e2da8d
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I9c6c798b174228d44d01b55f2a4aa19458e2da8d
</pre>
</div>
</content>
</entry>
<entry>
<title>block DNS traffic at the OpenVPN gateway (#4164)</title>
<updated>2014-04-29T18:39:15+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2014-04-29T18:39:15+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=e3e44973d6290a0228375135adf88d3271fc4242'/>
<id>e3e44973d6290a0228375135adf88d3271fc4242</id>
<content type='text'>
There are many different edge cases where mac and windows clients (and
maybe android too) will revert to using a different DNS server than the
one specified by openvpn.

This is bad news for security reasons. The client is being designed so
it doesn't leak DNS, however we don't want to put all of our eggs in one
basket, so this will block outgoing port 53 (udp and tcp) on the
gateway's firewall from any of the EIP interfaces (thus not blocking DNS
access on the gateway itself).

Change-Id: I84dcfec7fb591cf7e6b356b66b9721feda188177
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
There are many different edge cases where mac and windows clients (and
maybe android too) will revert to using a different DNS server than the
one specified by openvpn.

This is bad news for security reasons. The client is being designed so
it doesn't leak DNS, however we don't want to put all of our eggs in one
basket, so this will block outgoing port 53 (udp and tcp) on the
gateway's firewall from any of the EIP interfaces (thus not blocking DNS
access on the gateway itself).

Change-Id: I84dcfec7fb591cf7e6b356b66b9721feda188177
</pre>
</div>
</content>
</entry>
<entry>
<title>vagrant: support other providers besides virtualbox (Bug #4158), Part 2</title>
<updated>2013-10-16T19:30:16+00:00</updated>
<author>
<name>varac</name>
<email>varacanero@zeromail.org</email>
</author>
<published>2013-10-16T19:30:16+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=99df31cdd58ca60b90c0098b126903e2d8251128'/>
<id>99df31cdd58ca60b90c0098b126903e2d8251128</id>
<content type='text'>
took out the last remaining virtualbox references
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
took out the last remaining virtualbox references
</pre>
</div>
</content>
</entry>
<entry>
<title>make sure that the shorewall package is installed before trying to change its configuration file (#3701)</title>
<updated>2013-09-04T14:45:20+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2013-09-03T18:47:09+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=9544d1a4c8e3dfa11ba611b296a3e47edde0e67f'/>
<id>9544d1a4c8e3dfa11ba611b296a3e47edde0e67f</id>
<content type='text'>
Change-Id: Ib2dad30d53e5bf7539762eb3683430b10eb875ed
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: Ib2dad30d53e5bf7539762eb3683430b10eb875ed
</pre>
</div>
</content>
</entry>
<entry>
<title>postfix enable submission port using starttls, so the client can transition to the more restrictive TLS wrapper mode</title>
<updated>2013-08-31T12:33:53+00:00</updated>
<author>
<name>Micah Anderson</name>
<email>micah@leap.se</email>
</author>
<published>2013-08-30T19:19:43+00:00</published>
<link rel='alternate' type='text/html' href='https://leap.se/git/leap_platform.git/commit/?id=ff26ca98604d9e3f3856cca2af678b21c096d1ee'/>
<id>ff26ca98604d9e3f3856cca2af678b21c096d1ee</id>
<content type='text'>
Change-Id: I2a1728788378d9a1b79155ddb9bb4b0464b16baa
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Change-Id: I2a1728788378d9a1b79155ddb9bb4b0464b16baa
</pre>
</div>
</content>
</entry>
</feed>
