From cf72700665a942cf2cbaf0babe4f29e1f837a742 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Mon, 25 Aug 2014 13:53:44 -0400 Subject: [PATCH 1/9] - Initial epel7 package for xl2tpd --- .gitignore | 1 + sources | 2 +- xl2tpd.spec | 17 +++++++++-------- 3 files changed, 11 insertions(+), 9 deletions(-) diff --git a/.gitignore b/.gitignore index cc9fdd7..6f4d6dc 100644 --- a/.gitignore +++ b/.gitignore @@ -12,3 +12,4 @@ xl2tpd-1.2.8.tar.gz xl2tpd-1.3.0.tar.gz xl2tpd-1.3.1.tar.gz /xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz +/xl2tpd-1.3.6.tar.gz diff --git a/sources b/sources index cbe85ac..697c6a4 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -e08e34510a97e126b324f3407c71806c xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz +2f526cc0c36cf6d8a74f1fb2e08c18ec xl2tpd-1.3.6.tar.gz diff --git a/xl2tpd.spec b/xl2tpd.spec index 33f792c..f005103 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -28,17 +28,18 @@ Requires(postun): systemd xl2tpd is an implementation of the Layer 2 Tunnelling Protocol (RFC 2661). L2TP allows you to tunnel PPP over UDP. Some ISPs use L2TP to tunnel user sessions from dial-in servers (modem banks, ADSL DSLAMs) to back-end PPP -servers. Another important application is Virtual Private Networks where -the IPsec protocol is used to secure the L2TP connection (L2TP/IPsec, -RFC 3193). The L2TP/IPsec protocol is mainly used by Windows and -Mac OS X clients. On Linux, xl2tpd can be used in combination with IPsec -implementations such as Openswan. +servers. + +L2TP is also used for older Windows-based clients in combination with IPsec +for VPN connectivity, see RFC 3193. All other clients (android, iOS, OSX, +Linux) are recommended to switch to using IKEv2 or IKEv1 XAUTH. On Linux, +xl2tpd can be used in combination with IPsec implementations such as Libreswan. Example configuration files for such a setup are included in this RPM. xl2tpd works by opening a pseudo-tty for communicating with pppd. It runs completely in userspace. -xl2tpd supports IPsec SA Reference tracking to enable overlapping internak +xl2tpd supports IPsec SA Reference tracking to enable overlapping internal NAT'ed IP's by different clients (eg all clients connecting from their linksys internal IP 192.168.1.101) as well as multiple clients behind the same NAT router. @@ -48,7 +49,6 @@ or via a patch in contrib for 2.4.x kernels. Xl2tpd is based on the 0.69 L2TP by Jeff McAdams It was de-facto maintained by Jacco de Leeuw in 2002 and 2003. - %prep %setup -qn %{name}-%{commit} %patch1 -p1 @@ -56,7 +56,8 @@ It was de-facto maintained by Jacco de Leeuw in 2002 and 2003. %patch3 -p1 %build -#make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" +# to create a debug build: +# make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" export CFLAGS="$CFLAGS -fPIC -Wall" export DFLAGS="$RPM_OPT_FLAGS -g " From 288e08021c057495faaa727c501cd31c6d10214a Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Fri, 31 Oct 2014 17:43:04 -0400 Subject: [PATCH 2/9] new sources --- sources | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/sources b/sources index 697c6a4..cbe85ac 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -2f526cc0c36cf6d8a74f1fb2e08c18ec xl2tpd-1.3.6.tar.gz +e08e34510a97e126b324f3407c71806c xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz From a8a1f1d370fa0720ed52ff9c19b8295db3452a38 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Fri, 31 Oct 2014 17:59:44 -0400 Subject: [PATCH 3/9] - Remove kmod require, not recognised and l2tp_ppp.ko is in core kernel package now - Update service file to use Restart=always and require network-online.target --- xl2tpd.service | 5 +++-- xl2tpd.spec | 8 ++++++-- 2 files changed, 9 insertions(+), 4 deletions(-) diff --git a/xl2tpd.service b/xl2tpd.service index 082b4ff..a4c6c2f 100644 --- a/xl2tpd.service +++ b/xl2tpd.service @@ -1,6 +1,7 @@ [Unit] Description=Level 2 Tunnel Protocol Daemon (L2TP) -After=network.target +Wants=network-online.target +After=network-online.target After=ipsec.service # Some ISPs in Russia use l2tp without IPsec, so don't insist anymore #Wants=ipsec.service @@ -10,7 +11,7 @@ Type=simple PIDFile=/var/run/xl2tpd/xl2tpd.pid ExecStartPre=/sbin/modprobe -q l2tp_ppp ExecStart=/usr/sbin/xl2tpd -D -Restart=on-abort +Restart=always [Install] WantedBy=multi-user.target diff --git a/xl2tpd.spec b/xl2tpd.spec index c4ef5e4..28d1093 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -3,7 +3,7 @@ Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd Version: 1.3.6 -Release: 6%{?dist} +Release: 7%{?dist} License: GPL+ Url: https://github.com/xelerance/%{name}/ Group: System Environment/Daemons @@ -14,7 +14,7 @@ Patch1: xl2tpd-1.3.6-conf.patch Patch2: xl2tpd-1.3.6-md5-fips.patch Patch3: xl2tpd-1.3.6-saref.patch -Requires: ppp >= 2.4.5-18, kmod(l2tp_ppp.ko) +Requires: ppp >= 2.4.5-18 # If you want to authenticate against a Microsoft PDC/Active Directory # Requires: samba-winbind BuildRequires: libpcap-devel @@ -112,6 +112,10 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control %changelog +* Fri Oct 31 2014 Paul Wouters - 1.3.6-7 +- Remove kmod require, not recognised and l2tp_ppp.ko is in core kernel package now +- Update service file to use Restart=always and require network-online.target + * Thu Aug 21 2014 Kevin Fenzi - 1.3.6-6 - Rebuild for rpm bug 1131960 From ae61a131e2d815bc3681a257e4b62dffb30bc5a4 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Tue, 31 Mar 2015 13:59:15 -0400 Subject: [PATCH 4/9] - Rebuild with -DTRUST_PPPD_TO_DIE so pppd will execute its down script --- xl2tpd.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/xl2tpd.spec b/xl2tpd.spec index 28d1093..1e9e19a 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -3,7 +3,7 @@ Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd Version: 1.3.6 -Release: 7%{?dist} +Release: 8%{?dist} License: GPL+ Url: https://github.com/xelerance/%{name}/ Group: System Environment/Daemons @@ -59,7 +59,7 @@ It was de-facto maintained by Jacco de Leeuw in 2002 and 2003. # to create a debug build: # make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" -export CFLAGS="$CFLAGS -fPIC -Wall" +export CFLAGS="$CFLAGS -fPIC -Wall -DTRUST_PPPD_TO_DIE" export DFLAGS="$RPM_OPT_FLAGS -g " export LDFLAGS="$LDFLAGS -pie -Wl,-z,relro -Wl,-z,now" make @@ -112,6 +112,9 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control %changelog +* Tue Mar 31 2015 Paul Wouters - 1.3.6-8 +- Rebuild with -DTRUST_PPPD_TO_DIE so pppd will execute its down script + * Fri Oct 31 2014 Paul Wouters - 1.3.6-7 - Remove kmod require, not recognised and l2tp_ppp.ko is in core kernel package now - Update service file to use Restart=always and require network-online.target From 0a003324cb42e19401b8cae1aefb19d70f84fce0 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Fri, 2 Dec 2016 09:32:34 -0500 Subject: [PATCH 5/9] * Wed Aug 24 2016 Paul Wouters - 1.3.8-1 - Upgraded to 1.3.8 and updated existing patches still required - Fix kernel mode breaking the closing tunnels --- .gitignore | 1 + sources | 2 +- xl2tpd-1.3.8-kernelmode.patch | 26 ++ xl2tpd-1.3.8-md5-fips.patch | 467 ++++++++++++++++++++++++++++++++++ xl2tpd-1.3.8-saref.patch | 36 +++ xl2tpd.spec | 50 ++-- 6 files changed, 558 insertions(+), 24 deletions(-) create mode 100644 xl2tpd-1.3.8-kernelmode.patch create mode 100644 xl2tpd-1.3.8-md5-fips.patch create mode 100644 xl2tpd-1.3.8-saref.patch diff --git a/.gitignore b/.gitignore index 6f4d6dc..a9427e4 100644 --- a/.gitignore +++ b/.gitignore @@ -13,3 +13,4 @@ xl2tpd-1.3.0.tar.gz xl2tpd-1.3.1.tar.gz /xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz /xl2tpd-1.3.6.tar.gz +/xl2tpd-1.3.8.tar.gz diff --git a/sources b/sources index cbe85ac..ea62266 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -e08e34510a97e126b324f3407c71806c xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz +d244fdcd88f64601b64b7302870afca8 xl2tpd-1.3.8.tar.gz diff --git a/xl2tpd-1.3.8-kernelmode.patch b/xl2tpd-1.3.8-kernelmode.patch new file mode 100644 index 0000000..9349a8c --- /dev/null +++ b/xl2tpd-1.3.8-kernelmode.patch @@ -0,0 +1,26 @@ +diff -Naur xl2tpd-1.3.8-orig/network.c xl2tpd-1.3.8/network.c +--- xl2tpd-1.3.8-orig/network.c 2016-08-24 11:56:13.438007170 -0400 ++++ xl2tpd-1.3.8/network.c 2016-08-24 12:22:36.945960487 -0400 +@@ -781,6 +781,9 @@ + sax.pppol2tp.addr.sin_family = AF_INET; + sax.pppol2tp.s_tunnel = t->ourtid; + sax.pppol2tp.d_tunnel = t->tid; ++ sax.pppol2tp.s_session = 0; ++ sax.pppol2tp.d_session = 0; ++ + if ((connect(fd2, (struct sockaddr *)&sax, sizeof(sax))) < 0) { + l2tp_log (LOG_WARNING, "%s: Unable to connect PPPoL2TP socket. %d %s\n", + __FUNCTION__, errno, strerror(errno)); +diff -Naur xl2tpd-1.3.8-orig/xl2tpd.c xl2tpd-1.3.8/xl2tpd.c +--- xl2tpd-1.3.8-orig/xl2tpd.c 2016-08-24 11:56:13.436007180 -0400 ++++ xl2tpd-1.3.8/xl2tpd.c 2016-08-24 12:07:47.057504872 -0400 +@@ -274,9 +274,6 @@ + * OK...pppd died, we can go ahead and close the pty for + * it + */ +-#ifdef USE_KERNEL +- if (!kernel_support) +-#endif + close (c->fd); + c->fd = -1; + /* diff --git a/xl2tpd-1.3.8-md5-fips.patch b/xl2tpd-1.3.8-md5-fips.patch new file mode 100644 index 0000000..bc4d965 --- /dev/null +++ b/xl2tpd-1.3.8-md5-fips.patch @@ -0,0 +1,467 @@ +diff -Naur xl2tpd-1.3.8-orig/aaa.c xl2tpd-1.3.8/aaa.c +--- xl2tpd-1.3.8-orig/aaa.c 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/aaa.c 2016-08-24 11:40:46.784683160 -0400 +@@ -21,6 +21,8 @@ + #include + #include "l2tp.h" + ++#include ++ + extern void bufferDump (char *, int); + + /* FIXME: Accounting? */ +@@ -273,11 +275,11 @@ + #endif + + memset (chal->response, 0, MD_SIG_SIZE); +- MD5Init (&chal->md5); +- MD5Update (&chal->md5, &chal->ss, 1); +- MD5Update (&chal->md5, chal->secret, strlen ((char *)chal->secret)); +- MD5Update (&chal->md5, chal->challenge, chal->chal_len); +- MD5Final (chal->response, &chal->md5); ++ MD5_Init (&chal->md5); ++ MD5_Update (&chal->md5, &chal->ss, 1); ++ MD5_Update (&chal->md5, chal->secret, strlen ((char *)chal->secret)); ++ MD5_Update (&chal->md5, chal->challenge, chal->chal_len); ++ MD5_Final (chal->response, &chal->md5); + #ifdef DEBUG_AUTH + l2tp_log (LOG_DEBUG, "response is %X%X%X%X to '%s' and %X%X%X%X, %d\n", + *((int *) &chal->response[0]), +@@ -392,12 +394,12 @@ + buf->len += length; + /* Back to the beginning of real data, including the original length AVP */ + +- MD5Init (&t->chal_them.md5); +- MD5Update (&t->chal_them.md5, (void *) &attr, 2); +- MD5Update (&t->chal_them.md5, t->chal_them.secret, ++ MD5_Init (&t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, (void *) &attr, 2); ++ MD5_Update (&t->chal_them.md5, t->chal_them.secret, + strlen ((char *)t->chal_them.secret)); +- MD5Update (&t->chal_them.md5, t->chal_them.vector, VECTOR_SIZE); +- MD5Final (digest, &t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, t->chal_them.vector, VECTOR_SIZE); ++ MD5_Final (digest, &t->chal_them.md5); + + /* Though not a "MUST" in the spec, our subformat length is always a multiple of 16 */ + ptr = ((unsigned char *) new_hdr) + sizeof (struct avp_hdr); +@@ -421,11 +423,11 @@ + #endif + if (ptr < end) + { +- MD5Init (&t->chal_them.md5); +- MD5Update (&t->chal_them.md5, t->chal_them.secret, ++ MD5_Init (&t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, t->chal_them.secret, + strlen ((char *)t->chal_them.secret)); +- MD5Update (&t->chal_them.md5, previous_segment, MD_SIG_SIZE); +- MD5Final (digest, &t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, previous_segment, MD_SIG_SIZE); ++ MD5_Final (digest, &t->chal_them.md5); + } + previous_segment = ptr; + } +@@ -458,12 +460,12 @@ + that it will be padded to a 16 byte boundary, so we + have to be more careful than when encrypting */ + attr = ntohs (old_hdr->attr); +- MD5Init (&t->chal_us.md5); +- MD5Update (&t->chal_us.md5, (void *) &attr, 2); +- MD5Update (&t->chal_us.md5, t->chal_us.secret, ++ MD5_Init (&t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, (void *) &attr, 2); ++ MD5_Update (&t->chal_us.md5, t->chal_us.secret, + strlen ((char *)t->chal_us.secret)); +- MD5Update (&t->chal_us.md5, t->chal_us.vector, t->chal_us.vector_len); +- MD5Final (digest, &t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, t->chal_us.vector, t->chal_us.vector_len); ++ MD5_Final (digest, &t->chal_us.md5); + #ifdef DEBUG_HIDDEN + l2tp_log (LOG_DEBUG, "attribute is %d and challenge is: ", attr); + print_challenge (&t->chal_us); +@@ -474,11 +476,11 @@ + { + if (cnt >= MD_SIG_SIZE) + { +- MD5Init (&t->chal_us.md5); +- MD5Update (&t->chal_us.md5, t->chal_us.secret, ++ MD5_Init (&t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, t->chal_us.secret, + strlen ((char *)t->chal_us.secret)); +- MD5Update (&t->chal_us.md5, saved_segment, MD_SIG_SIZE); +- MD5Final (digest, &t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, saved_segment, MD_SIG_SIZE); ++ MD5_Final (digest, &t->chal_us.md5); + cnt = 0; + } + /* at the beginning of each segment, we save the current segment (16 octets or less) of cipher +diff -Naur xl2tpd-1.3.8-orig/aaa.h xl2tpd-1.3.8/aaa.h +--- xl2tpd-1.3.8-orig/aaa.h 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/aaa.h 2016-08-24 11:41:21.032506562 -0400 +@@ -15,7 +15,7 @@ + + #ifndef _AAA_H + #define _AAA_H +-#include "md5.h" ++#include + + #define ADDR_HASH_SIZE 256 + #define MD_SIG_SIZE 16 +@@ -34,7 +34,7 @@ + + struct challenge + { +- struct MD5Context md5; ++ MD5_CTX md5; + unsigned char ss; /* State we're sending in */ + unsigned char secret[MAXSTRLEN]; /* The shared secret */ + unsigned char *challenge; /* The original challenge */ +diff -Naur xl2tpd-1.3.8-orig/Makefile xl2tpd-1.3.8/Makefile +--- xl2tpd-1.3.8-orig/Makefile 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/Makefile 2016-08-24 11:42:18.389210804 -0400 +@@ -98,8 +98,8 @@ + IPFLAGS?= -DIP_ALLOCATION + + CFLAGS+= $(DFLAGS) -Os -Wall -DSANITY $(OSFLAGS) $(IPFLAGS) +-HDRS=l2tp.h avp.h misc.h control.h call.h scheduler.h file.h aaa.h md5.h +-OBJS=xl2tpd.o pty.o misc.o control.o avp.o call.o network.o avpsend.o scheduler.o file.o aaa.o md5.o ++HDRS=l2tp.h avp.h misc.h control.h call.h scheduler.h file.h aaa.h ++OBJS=xl2tpd.o pty.o misc.o control.o avp.o call.o network.o avpsend.o scheduler.o file.o aaa.o + SRCS=${OBJS:.o=.c} ${HDRS} + CONTROL_SRCS=xl2tpd-control.c + #LIBS= $(OSLIBS) # -lefence # efence for malloc checking +@@ -119,7 +119,7 @@ + rm -f $(OBJS) $(EXEC) pfc.o pfc $(CONTROL_EXEC) + + $(EXEC): $(OBJS) $(HDRS) +- $(CC) $(LDFLAGS) -o $@ $(OBJS) $(LDLIBS) ++ $(CC) $(LDFLAGS) -o $@ $(OBJS) -lcrypto $(LDLIBS) + + $(CONTROL_EXEC): $(CONTROL_SRCS) + $(CC) $(CFLAGS) $(LDFLAGS) $(CONTROL_SRCS) -o $@ +diff -Naur xl2tpd-1.3.8-orig/md5.c xl2tpd-1.3.8/md5.c +--- xl2tpd-1.3.8-orig/md5.c 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/md5.c 2016-08-24 11:42:47.940058425 -0400 +@@ -1,274 +0,0 @@ +-#ifdef FREEBSD +-# include +-#elif defined(OPENBSD) || defined(NETBSD) +-# define __BSD_VISIBLE 0 +-# include +-#elif defined(LINUX) +-# include +-#elif defined(SOLARIS) +-# include +-#endif +-#if __BYTE_ORDER == __BIG_ENDIAN +-#define HIGHFIRST 1 +-#endif +- +-/* +- * This code implements the MD5 message-digest algorithm. +- * The algorithm is due to Ron Rivest. This code was +- * written by Colin Plumb in 1993, no copyright is claimed. +- * This code is in the public domain; do with it what you wish. +- * +- * Equivalent code is available from RSA Data Security, Inc. +- * This code has been tested against that, and is equivalent, +- * except that you don't need to include two pages of legalese +- * with every copy. +- * +- * To compute the message digest of a chunk of bytes, declare an +- * MD5Context structure, pass it to MD5Init, call MD5Update as +- * needed on buffers full of bytes, and then call MD5Final, which +- * will fill a supplied 16-byte array with the digest. +- */ +-#include /* for memcpy() */ +-#include "md5.h" +- +-#ifndef HIGHFIRST +-#define byteReverse(buf, len) /* Nothing */ +-#else +-void byteReverse (unsigned char *buf, unsigned longs); +- +-#ifndef ASM_MD5 +-/* +- * Note: this code is harmless on little-endian machines. +- */ +-void byteReverse (unsigned char *buf, unsigned longs) +-{ +- uint32 t; +- do +- { +- t = (uint32) ((unsigned) buf[3] << 8 | buf[2]) << 16 | +- ((unsigned) buf[1] << 8 | buf[0]); +- *(uint32 *) buf = t; +- buf += 4; +- } +- while (--longs); +-} +-#endif +-#endif +- +-/* +- * Start MD5 accumulation. Set bit count to 0 and buffer to mysterious +- * initialization constants. +- */ +-void MD5Init (struct MD5Context *ctx) +-{ +- ctx->buf[0] = 0x67452301; +- ctx->buf[1] = 0xefcdab89; +- ctx->buf[2] = 0x98badcfe; +- ctx->buf[3] = 0x10325476; +- +- ctx->bits[0] = 0; +- ctx->bits[1] = 0; +-} +- +-/* +- * Update context to reflect the concatenation of another buffer full +- * of bytes. +- */ +-void MD5Update (struct MD5Context *ctx, unsigned char const *buf, +- unsigned len) +-{ +- uint32 t; +- +- /* Update bitcount */ +- +- t = ctx->bits[0]; +- if ((ctx->bits[0] = t + ((uint32) len << 3)) < t) +- ctx->bits[1]++; /* Carry from low to high */ +- ctx->bits[1] += len >> 29; +- +- t = (t >> 3) & 0x3f; /* Bytes already in shsInfo->data */ +- +- /* Handle any leading odd-sized chunks */ +- +- if (t) +- { +- unsigned char *p = (unsigned char *) ctx->in + t; +- +- t = 64 - t; +- if (len < t) +- { +- memcpy (p, buf, len); +- return; +- } +- memcpy (p, buf, t); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- buf += t; +- len -= t; +- } +- /* Process data in 64-byte chunks */ +- +- while (len >= 64) +- { +- memcpy (ctx->in, buf, 64); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- buf += 64; +- len -= 64; +- } +- +- /* Handle any remaining bytes of data. */ +- +- memcpy (ctx->in, buf, len); +-} +- +-/* +- * Final wrapup - pad to 64-byte boundary with the bit pattern +- * 1 0* (64-bit count of bits processed, MSB-first) +- */ +-void MD5Final (unsigned char digest[16], struct MD5Context *ctx) +-{ +- unsigned count; +- unsigned char *p; +- +- /* Compute number of bytes mod 64 */ +- count = (ctx->bits[0] >> 3) & 0x3F; +- +- /* Set the first char of padding to 0x80. This is safe since there is +- always at least one byte free */ +- p = ctx->in + count; +- *p++ = 0x80; +- +- /* Bytes of padding needed to make 64 bytes */ +- count = 64 - 1 - count; +- +- /* Pad out to 56 mod 64 */ +- if (count < 8) +- { +- /* Two lots of padding: Pad the first block to 64 bytes */ +- memset (p, 0, count); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- +- /* Now fill the next block with 56 bytes */ +- memset (ctx->in, 0, 56); +- } +- else +- { +- /* Pad block to 56 bytes */ +- memset (p, 0, count - 8); +- } +- byteReverse (ctx->in, 14); +- +- /* Append length in bits and transform */ +- memcpy(ctx->in + 14 * sizeof(uint32), ctx->bits, sizeof(ctx->bits)); +- +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- byteReverse ((unsigned char *) ctx->buf, 4); +- memcpy (digest, ctx->buf, 16); +- memset (ctx, 0, sizeof (*ctx)); /* In case it's sensitive */ +-} +- +-#ifndef ASM_MD5 +- +-/* The four core functions - F1 is optimized somewhat */ +- +-/* #define F1(x, y, z) (x & y | ~x & z) */ +-#define F1(x, y, z) (z ^ (x & (y ^ z))) +-#define F2(x, y, z) F1(z, x, y) +-#define F3(x, y, z) (x ^ y ^ z) +-#define F4(x, y, z) (y ^ (x | ~z)) +- +-/* This is the central step in the MD5 algorithm. */ +-#define MD5STEP(f, w, x, y, z, data, s) \ +- ( w += f(x, y, z) + data, w = w<>(32-s), w += x ) +- +-/* +- * The core of the MD5 algorithm, this alters an existing MD5 hash to +- * reflect the addition of 16 longwords of new data. MD5Update blocks +- * the data and converts bytes into longwords for this routine. +- */ +-void MD5Transform (uint32 buf[4], uint32 const in[16]) +-{ +- register uint32 a, b, c, d; +- +- a = buf[0]; +- b = buf[1]; +- c = buf[2]; +- d = buf[3]; +- +- MD5STEP (F1, a, b, c, d, in[0] + 0xd76aa478, 7); +- MD5STEP (F1, d, a, b, c, in[1] + 0xe8c7b756, 12); +- MD5STEP (F1, c, d, a, b, in[2] + 0x242070db, 17); +- MD5STEP (F1, b, c, d, a, in[3] + 0xc1bdceee, 22); +- MD5STEP (F1, a, b, c, d, in[4] + 0xf57c0faf, 7); +- MD5STEP (F1, d, a, b, c, in[5] + 0x4787c62a, 12); +- MD5STEP (F1, c, d, a, b, in[6] + 0xa8304613, 17); +- MD5STEP (F1, b, c, d, a, in[7] + 0xfd469501, 22); +- MD5STEP (F1, a, b, c, d, in[8] + 0x698098d8, 7); +- MD5STEP (F1, d, a, b, c, in[9] + 0x8b44f7af, 12); +- MD5STEP (F1, c, d, a, b, in[10] + 0xffff5bb1, 17); +- MD5STEP (F1, b, c, d, a, in[11] + 0x895cd7be, 22); +- MD5STEP (F1, a, b, c, d, in[12] + 0x6b901122, 7); +- MD5STEP (F1, d, a, b, c, in[13] + 0xfd987193, 12); +- MD5STEP (F1, c, d, a, b, in[14] + 0xa679438e, 17); +- MD5STEP (F1, b, c, d, a, in[15] + 0x49b40821, 22); +- +- MD5STEP (F2, a, b, c, d, in[1] + 0xf61e2562, 5); +- MD5STEP (F2, d, a, b, c, in[6] + 0xc040b340, 9); +- MD5STEP (F2, c, d, a, b, in[11] + 0x265e5a51, 14); +- MD5STEP (F2, b, c, d, a, in[0] + 0xe9b6c7aa, 20); +- MD5STEP (F2, a, b, c, d, in[5] + 0xd62f105d, 5); +- MD5STEP (F2, d, a, b, c, in[10] + 0x02441453, 9); +- MD5STEP (F2, c, d, a, b, in[15] + 0xd8a1e681, 14); +- MD5STEP (F2, b, c, d, a, in[4] + 0xe7d3fbc8, 20); +- MD5STEP (F2, a, b, c, d, in[9] + 0x21e1cde6, 5); +- MD5STEP (F2, d, a, b, c, in[14] + 0xc33707d6, 9); +- MD5STEP (F2, c, d, a, b, in[3] + 0xf4d50d87, 14); +- MD5STEP (F2, b, c, d, a, in[8] + 0x455a14ed, 20); +- MD5STEP (F2, a, b, c, d, in[13] + 0xa9e3e905, 5); +- MD5STEP (F2, d, a, b, c, in[2] + 0xfcefa3f8, 9); +- MD5STEP (F2, c, d, a, b, in[7] + 0x676f02d9, 14); +- MD5STEP (F2, b, c, d, a, in[12] + 0x8d2a4c8a, 20); +- +- MD5STEP (F3, a, b, c, d, in[5] + 0xfffa3942, 4); +- MD5STEP (F3, d, a, b, c, in[8] + 0x8771f681, 11); +- MD5STEP (F3, c, d, a, b, in[11] + 0x6d9d6122, 16); +- MD5STEP (F3, b, c, d, a, in[14] + 0xfde5380c, 23); +- MD5STEP (F3, a, b, c, d, in[1] + 0xa4beea44, 4); +- MD5STEP (F3, d, a, b, c, in[4] + 0x4bdecfa9, 11); +- MD5STEP (F3, c, d, a, b, in[7] + 0xf6bb4b60, 16); +- MD5STEP (F3, b, c, d, a, in[10] + 0xbebfbc70, 23); +- MD5STEP (F3, a, b, c, d, in[13] + 0x289b7ec6, 4); +- MD5STEP (F3, d, a, b, c, in[0] + 0xeaa127fa, 11); +- MD5STEP (F3, c, d, a, b, in[3] + 0xd4ef3085, 16); +- MD5STEP (F3, b, c, d, a, in[6] + 0x04881d05, 23); +- MD5STEP (F3, a, b, c, d, in[9] + 0xd9d4d039, 4); +- MD5STEP (F3, d, a, b, c, in[12] + 0xe6db99e5, 11); +- MD5STEP (F3, c, d, a, b, in[15] + 0x1fa27cf8, 16); +- MD5STEP (F3, b, c, d, a, in[2] + 0xc4ac5665, 23); +- +- MD5STEP (F4, a, b, c, d, in[0] + 0xf4292244, 6); +- MD5STEP (F4, d, a, b, c, in[7] + 0x432aff97, 10); +- MD5STEP (F4, c, d, a, b, in[14] + 0xab9423a7, 15); +- MD5STEP (F4, b, c, d, a, in[5] + 0xfc93a039, 21); +- MD5STEP (F4, a, b, c, d, in[12] + 0x655b59c3, 6); +- MD5STEP (F4, d, a, b, c, in[3] + 0x8f0ccc92, 10); +- MD5STEP (F4, c, d, a, b, in[10] + 0xffeff47d, 15); +- MD5STEP (F4, b, c, d, a, in[1] + 0x85845dd1, 21); +- MD5STEP (F4, a, b, c, d, in[8] + 0x6fa87e4f, 6); +- MD5STEP (F4, d, a, b, c, in[15] + 0xfe2ce6e0, 10); +- MD5STEP (F4, c, d, a, b, in[6] + 0xa3014314, 15); +- MD5STEP (F4, b, c, d, a, in[13] + 0x4e0811a1, 21); +- MD5STEP (F4, a, b, c, d, in[4] + 0xf7537e82, 6); +- MD5STEP (F4, d, a, b, c, in[11] + 0xbd3af235, 10); +- MD5STEP (F4, c, d, a, b, in[2] + 0x2ad7d2bb, 15); +- MD5STEP (F4, b, c, d, a, in[9] + 0xeb86d391, 21); +- +- buf[0] += a; +- buf[1] += b; +- buf[2] += c; +- buf[3] += d; +-} +- +-#endif +diff -Naur xl2tpd-1.3.8-orig/md5.h xl2tpd-1.3.8/md5.h +--- xl2tpd-1.3.8-orig/md5.h 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/md5.h 2016-08-24 11:42:51.182041708 -0400 +@@ -1,29 +0,0 @@ +-#ifndef MD5_H +-#define MD5_H +- +-#ifdef __alpha +-typedef unsigned int uint32; +-#else +-#include +-typedef uint32_t uint32; +-#endif +- +-struct MD5Context +-{ +- uint32 buf[4]; +- uint32 bits[2]; +- unsigned char in[64]; +-}; +- +-void MD5Init (struct MD5Context *context); +-void MD5Update (struct MD5Context *context, unsigned char const *buf, +- unsigned len); +-void MD5Final (unsigned char digest[16], struct MD5Context *context); +-void MD5Transform (uint32 buf[4], uint32 const in[16]); +- +-/* +- * This is needed to make RSAREF happy on some MS-DOS compilers. +- */ +-typedef struct MD5Context MD5_CTX; +- +-#endif /* !MD5_H */ +diff -Naur xl2tpd-1.3.8-orig/xl2tpd.c xl2tpd-1.3.8/xl2tpd.c +--- xl2tpd-1.3.8-orig/xl2tpd.c 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/xl2tpd.c 2016-08-24 11:43:37.704807118 -0400 +@@ -1630,7 +1630,10 @@ + + + void usage(void) { +- printf("\nxl2tpd version: %s\n", SERVER_VERSION); ++ printf("\nxl2tpd version: %s\n" ++"This product includes software developed by the OpenSSL Project for use\n" ++"in the OpenSSL Toolkit. (http://www.openssl.org/)\n" ++, SERVER_VERSION); + printf("Usage: xl2tpd [-c ] [-s ] [-p ]\n" + " [-C ] [-D] [-l]\n" + " [-v, --version]\n"); diff --git a/xl2tpd-1.3.8-saref.patch b/xl2tpd-1.3.8-saref.patch new file mode 100644 index 0000000..a3fabbf --- /dev/null +++ b/xl2tpd-1.3.8-saref.patch @@ -0,0 +1,36 @@ +diff -Naur xl2tpd-1.3.8-orig/file.c xl2tpd-1.3.8/file.c +--- xl2tpd-1.3.8-orig/file.c 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/file.c 2016-08-24 11:46:12.046031065 -0400 +@@ -42,6 +42,8 @@ + + gconfig.port = UDP_LISTEN_PORT; + gconfig.sarefnum = IP_IPSEC_REFINFO; /* default use the latest we know */ ++ gconfig.ipsecsaref = 0; /* default off - requires patched KLIPS kernel module */ ++ gconfig.forceuserspace = 0; /* default off - allow kernel decap of data packets */ + gconfig.listenaddr = htonl(INADDR_ANY); /* Default is to bind (listen) to all interfaces */ + gconfig.debug_avp = 0; + gconfig.debug_network = 0; +diff -Naur xl2tpd-1.3.8-orig/network.c xl2tpd-1.3.8/network.c +--- xl2tpd-1.3.8-orig/network.c 2016-08-11 20:56:53.000000000 -0400 ++++ xl2tpd-1.3.8/network.c 2016-08-24 11:47:01.683781479 -0400 +@@ -80,6 +80,12 @@ + * For L2TP/IPsec with KLIPSng, set the socket to receive IPsec REFINFO + * values. + */ ++ if (!gconfig.ipsecsaref) ++ { ++ l2tp_log (LOG_INFO, "Not looking for kernel SAref support.\n"); ++ } ++ else ++ { + arg=1; + if(setsockopt(server_socket, IPPROTO_IP, gconfig.sarefnum, + &arg, sizeof(arg)) != 0) { +@@ -87,6 +93,7 @@ + + gconfig.ipsecsaref=0; + } ++ } + + arg=1; + if(setsockopt(server_socket, IPPROTO_IP, IP_PKTINFO, (char*)&arg, sizeof(arg)) != 0) { diff --git a/xl2tpd.spec b/xl2tpd.spec index 1e9e19a..f12b5d0 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -1,20 +1,20 @@ -%global commit 5619e1771048e74b729804e8602f409af0f3faea - Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd -Version: 1.3.6 -Release: 8%{?dist} +Version: 1.3.8 +Release: 1%{?dist} License: GPL+ -Url: https://github.com/xelerance/%{name}/ +Url: https://github.com/xelerance/xl2tpd/ Group: System Environment/Daemons -Source0: https://github.com/xelerance/%{name}/archive/%{commit}/%{name}-%{commit}.tar.gz +# upstream isn't using proper names, we manually rename v-VERSION.tar.gz to xl2tpd-VERSION.tar.gz +Source0: https://github.com/xelerance/xl2tpd/archive/xl2tpd-%{version}.tar.gz Source1: xl2tpd.service Source2: tmpfiles-xl2tpd.conf Patch1: xl2tpd-1.3.6-conf.patch -Patch2: xl2tpd-1.3.6-md5-fips.patch -Patch3: xl2tpd-1.3.6-saref.patch +Patch2: xl2tpd-1.3.8-md5-fips.patch +Patch3: xl2tpd-1.3.8-saref.patch +Patch4: xl2tpd-1.3.8-kernelmode.patch -Requires: ppp >= 2.4.5-18 +Requires: ppp >= 2.4.5-18, kmod(l2tp_ppp.ko) # If you want to authenticate against a Microsoft PDC/Active Directory # Requires: samba-winbind BuildRequires: libpcap-devel @@ -28,18 +28,17 @@ Requires(postun): systemd xl2tpd is an implementation of the Layer 2 Tunnelling Protocol (RFC 2661). L2TP allows you to tunnel PPP over UDP. Some ISPs use L2TP to tunnel user sessions from dial-in servers (modem banks, ADSL DSLAMs) to back-end PPP -servers. - -L2TP is also used for older Windows-based clients in combination with IPsec -for VPN connectivity, see RFC 3193. All other clients (android, iOS, OSX, -Linux) are recommended to switch to using IKEv2 or IKEv1 XAUTH. On Linux, -xl2tpd can be used in combination with IPsec implementations such as Libreswan. +servers. Another important application is Virtual Private Networks where +the IPsec protocol is used to secure the L2TP connection (L2TP/IPsec, +RFC 3193). The L2TP/IPsec protocol is mainly used by Windows and +Mac OS X clients. On Linux, xl2tpd can be used in combination with IPsec +implementations such as Libreswan. Example configuration files for such a setup are included in this RPM. xl2tpd works by opening a pseudo-tty for communicating with pppd. It runs completely in userspace. -xl2tpd supports IPsec SA Reference tracking to enable overlapping internal +xl2tpd supports IPsec SA Reference tracking to enable overlapping internak NAT'ed IP's by different clients (eg all clients connecting from their linksys internal IP 192.168.1.101) as well as multiple clients behind the same NAT router. @@ -49,20 +48,21 @@ or via a patch in contrib for 2.4.x kernels. Xl2tpd is based on the 0.69 L2TP by Jeff McAdams It was de-facto maintained by Jacco de Leeuw in 2002 and 2003. + %prep -%setup -qn %{name}-%{commit} -%patch1 -p1 +%setup +%patch1 -p1 %patch2 -p1 %patch3 -p1 +%patch4 -p1 %build -# to create a debug build: -# make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" +#make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" export CFLAGS="$CFLAGS -fPIC -Wall -DTRUST_PPPD_TO_DIE" export DFLAGS="$RPM_OPT_FLAGS -g " export LDFLAGS="$LDFLAGS -pie -Wl,-z,relro -Wl,-z,now" -make +make %install rm -rf %{buildroot} @@ -85,7 +85,7 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %systemd_post xl2tpd.service %postun -%systemd_postun_with_restart xl2tpd.service +%systemd_postun_with_restart xl2tpd.service %triggerun -- xl2td < 1.3.1-3 # Save the current service runlevel info @@ -97,7 +97,7 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd /bin/systemctl try-restart xl2tpd.service >/dev/null 2>&1 || : %files -%doc BUGS CHANGES CREDITS LICENSE README.* TODO doc/rfc2661.txt +%doc BUGS CHANGES CREDITS LICENSE README.* TODO %doc doc/README.patents examples/chapsecrets.sample %{_sbindir}/xl2tpd %{_sbindir}/xl2tpd-control @@ -112,6 +112,10 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control %changelog +* Wed Aug 24 2016 Paul Wouters - 1.3.8-1 +- Upgraded to 1.3.8 and updated existing patches still required +- Fix kernel mode breaking the closing tunnels + * Tue Mar 31 2015 Paul Wouters - 1.3.6-8 - Rebuild with -DTRUST_PPPD_TO_DIE so pppd will execute its down script From ad73cc0838ff96a141ec432dc322836833212fe4 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Wed, 21 Dec 2016 15:12:54 -0500 Subject: [PATCH 6/9] - Do not use kmod for EPEL/RHEL --- xl2tpd.spec | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/xl2tpd.spec b/xl2tpd.spec index f12b5d0..04bbe99 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -1,7 +1,7 @@ Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd Version: 1.3.8 -Release: 1%{?dist} +Release: 2%{?dist} License: GPL+ Url: https://github.com/xelerance/xl2tpd/ Group: System Environment/Daemons @@ -14,7 +14,7 @@ Patch2: xl2tpd-1.3.8-md5-fips.patch Patch3: xl2tpd-1.3.8-saref.patch Patch4: xl2tpd-1.3.8-kernelmode.patch -Requires: ppp >= 2.4.5-18, kmod(l2tp_ppp.ko) +Requires: ppp >= 2.4.5-18 # If you want to authenticate against a Microsoft PDC/Active Directory # Requires: samba-winbind BuildRequires: libpcap-devel @@ -112,6 +112,9 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control %changelog +* Wed Dec 21 2016 Paul Wouters - 1.3.8-2 +- Do not use kmod for EPEL/RHEL + * Wed Aug 24 2016 Paul Wouters - 1.3.8-1 - Upgraded to 1.3.8 and updated existing patches still required - Fix kernel mode breaking the closing tunnels From f6c75cbb89655878a65698394ff29f8c3ecc5892 Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Sun, 1 Apr 2018 22:13:59 +0200 Subject: [PATCH 7/9] - Resolves: rhbz#1562512 kernels 4.15 and 4.16 break xl2tpd --- xl2tpd-1.3.8-saref.patch | 63 +++++++++++++++++++++++++++------------- xl2tpd.spec | 5 +++- 2 files changed, 47 insertions(+), 21 deletions(-) diff --git a/xl2tpd-1.3.8-saref.patch b/xl2tpd-1.3.8-saref.patch index a3fabbf..3cd9a23 100644 --- a/xl2tpd-1.3.8-saref.patch +++ b/xl2tpd-1.3.8-saref.patch @@ -1,7 +1,8 @@ -diff -Naur xl2tpd-1.3.8-orig/file.c xl2tpd-1.3.8/file.c ---- xl2tpd-1.3.8-orig/file.c 2016-08-11 20:56:53.000000000 -0400 -+++ xl2tpd-1.3.8/file.c 2016-08-24 11:46:12.046031065 -0400 -@@ -42,6 +42,8 @@ +diff --git a/file.c b/file.c +index f61c221..a6362c0 100644 +--- a/file.c ++++ b/file.c +@@ -42,6 +42,8 @@ int init_config () gconfig.port = UDP_LISTEN_PORT; gconfig.sarefnum = IP_IPSEC_REFINFO; /* default use the latest we know */ @@ -10,27 +11,49 @@ diff -Naur xl2tpd-1.3.8-orig/file.c xl2tpd-1.3.8/file.c gconfig.listenaddr = htonl(INADDR_ANY); /* Default is to bind (listen) to all interfaces */ gconfig.debug_avp = 0; gconfig.debug_network = 0; -diff -Naur xl2tpd-1.3.8-orig/network.c xl2tpd-1.3.8/network.c ---- xl2tpd-1.3.8-orig/network.c 2016-08-11 20:56:53.000000000 -0400 -+++ xl2tpd-1.3.8/network.c 2016-08-24 11:47:01.683781479 -0400 -@@ -80,6 +80,12 @@ +diff --git a/network.c b/network.c +index 543d30e..c66d1e3 100644 +--- a/network.c ++++ b/network.c +@@ -78,23 +78,27 @@ int init_network (void) * For L2TP/IPsec with KLIPSng, set the socket to receive IPsec REFINFO * values. */ +- arg=1; +- if(setsockopt(server_socket, IPPROTO_IP, gconfig.sarefnum, +- &arg, sizeof(arg)) != 0) { +- l2tp_log(LOG_CRIT, "setsockopt recvref[%d]: %s\n", gconfig.sarefnum, strerror(errno)); +- +- gconfig.ipsecsaref=0; +- } +- +- arg=1; +- if(setsockopt(server_socket, IPPROTO_IP, IP_PKTINFO, (char*)&arg, sizeof(arg)) != 0) { +- l2tp_log(LOG_CRIT, "setsockopt IP_PKTINFO: %s\n", strerror(errno)); + if (!gconfig.ipsecsaref) + { + l2tp_log (LOG_INFO, "Not looking for kernel SAref support.\n"); -+ } -+ else -+ { - arg=1; - if(setsockopt(server_socket, IPPROTO_IP, gconfig.sarefnum, - &arg, sizeof(arg)) != 0) { -@@ -87,6 +93,7 @@ - - gconfig.ipsecsaref=0; } -+ } +-#else ++ else + { +- l2tp_log(LOG_INFO, "No attempt being made to use IPsec SAref's since we're not on a Linux machine.\n"); ++ arg=1; ++ if(setsockopt(server_socket, IPPROTO_IP, gconfig.sarefnum, &arg, sizeof(arg)) != 0) { ++ l2tp_log(LOG_CRIT, "setsockopt recvref[%d]: %s\n", gconfig.sarefnum, strerror(errno)); ++ gconfig.ipsecsaref=0; ++ } ++ else ++ { ++ arg=1; ++ if(setsockopt(server_socket, IPPROTO_IP, IP_PKTINFO, (char*)&arg, sizeof(arg)) != 0) { ++ l2tp_log(LOG_CRIT, "setsockopt IP_PKTINFO: %s\n", strerror(errno)); ++ } ++ } + } +- ++#else ++ l2tp_log(LOG_INFO, "No attempt being made to use IPsec SAref's since we're not on a Linux machine.\n"); + #endif - arg=1; - if(setsockopt(server_socket, IPPROTO_IP, IP_PKTINFO, (char*)&arg, sizeof(arg)) != 0) { + #ifdef USE_KERNEL diff --git a/xl2tpd.spec b/xl2tpd.spec index 04bbe99..dc97108 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -1,7 +1,7 @@ Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd Version: 1.3.8 -Release: 2%{?dist} +Release: 3%{?dist} License: GPL+ Url: https://github.com/xelerance/xl2tpd/ Group: System Environment/Daemons @@ -112,6 +112,9 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control %changelog +* Sun Apr 01 2018 Paul Wouters - 1.3.8-3 +- Resolves: rhbz#1562512 kernels 4.15 and 4.16 break xl2tpd + * Wed Dec 21 2016 Paul Wouters - 1.3.8-2 - Do not use kmod for EPEL/RHEL From 882515df9c84cb8a95eef9bc8a8f9bcd7d5590ba Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Tue, 24 Sep 2019 22:13:08 -0400 Subject: [PATCH 8/9] * Wed Sep 25 2019 Paul Wouters - 1.3.14-1 - Resolves: rhbz#1322190 Updated to 1.3.14 - Resolves: rhbz#1722121 Use proper /run directory - Resolves: rhbz#1399648 Review Request: xl2tpd --- .gitignore | 1 + sources | 2 +- tmpfiles-xl2tpd.conf | 2 +- xl2tpd-1.3.14-conf.patch | 31 +++ xl2tpd-1.3.14-kernelmode.patch | 18 ++ xl2tpd-1.3.14-md5-fips.patch | 468 +++++++++++++++++++++++++++++++++ xl2tpd.spec | 41 +-- 7 files changed, 542 insertions(+), 21 deletions(-) create mode 100644 xl2tpd-1.3.14-conf.patch create mode 100644 xl2tpd-1.3.14-kernelmode.patch create mode 100644 xl2tpd-1.3.14-md5-fips.patch diff --git a/.gitignore b/.gitignore index a9427e4..0bc43ae 100644 --- a/.gitignore +++ b/.gitignore @@ -14,3 +14,4 @@ xl2tpd-1.3.1.tar.gz /xl2tpd-5619e1771048e74b729804e8602f409af0f3faea.tar.gz /xl2tpd-1.3.6.tar.gz /xl2tpd-1.3.8.tar.gz +/xl2tpd-1.3.14.tar.gz diff --git a/sources b/sources index ea62266..31efa93 100644 --- a/sources +++ b/sources @@ -1 +1 @@ -d244fdcd88f64601b64b7302870afca8 xl2tpd-1.3.8.tar.gz +SHA512 (xl2tpd-1.3.14.tar.gz) = a0c007b5a2d45f4c73d8651c8ca2525cd46b779e4b8cfabebd2c7905770d128f25edea5665c25828c53788083fda73896faccb49f4da9a38a2042b5f957a3327 diff --git a/tmpfiles-xl2tpd.conf b/tmpfiles-xl2tpd.conf index 66bc6f8..ee868fb 100644 --- a/tmpfiles-xl2tpd.conf +++ b/tmpfiles-xl2tpd.conf @@ -1 +1 @@ -D /var/run/xl2tpd 0755 root root - +D /run/xl2tpd 0755 root root - diff --git a/xl2tpd-1.3.14-conf.patch b/xl2tpd-1.3.14-conf.patch new file mode 100644 index 0000000..8f70a3d --- /dev/null +++ b/xl2tpd-1.3.14-conf.patch @@ -0,0 +1,31 @@ +diff -Naur xl2tpd-1.3.14-orig/examples/ppp-options.xl2tpd xl2tpd-1.3.14/examples/ppp-options.xl2tpd +--- xl2tpd-1.3.14-orig/examples/ppp-options.xl2tpd 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/examples/ppp-options.xl2tpd 2019-09-24 20:47:35.056615746 -0400 +@@ -1,9 +1,11 @@ + ipcp-accept-local + ipcp-accept-remote +-ms-dns 192.168.1.1 +-ms-dns 192.168.1.3 +-ms-wins 192.168.1.2 +-ms-wins 192.168.1.4 ++ms-dns 8.8.8.8 ++ms-dns 1.1.1.1 ++# ms-dns 192.168.1.1 ++# ms-dns 192.168.1.3 ++# ms-wins 192.168.1.2 ++# ms-wins 192.168.1.4 + noccp + auth + crtscts +@@ -15,3 +17,11 @@ + lock + proxyarp + connect-delay 5000 ++# To allow authentication against a Windows domain EXAMPLE, and require the ++# user to be in a group "VPN Users". Requires the samba-winbind package ++# require-mschap-v2 ++# plugin winbind.so ++# ntlm_auth-helper '/usr/bin/ntlm_auth --helper-protocol=ntlm-server-1 --require-membership-of="EXAMPLE\\VPN Users"' ++# You need to join the domain on the server, for example using samba: ++# http://rootmanager.com/ubuntu-ipsec-l2tp-windows-domain-auth/setting-up-openswan-xl2tpd-with-native-windows-clients-lucid.html ++ diff --git a/xl2tpd-1.3.14-kernelmode.patch b/xl2tpd-1.3.14-kernelmode.patch new file mode 100644 index 0000000..9f30914 --- /dev/null +++ b/xl2tpd-1.3.14-kernelmode.patch @@ -0,0 +1,18 @@ +diff -Naur xl2tpd-1.3.14-orig/xl2tpd.c xl2tpd-1.3.14/xl2tpd.c +--- xl2tpd-1.3.14-orig/xl2tpd.c 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/xl2tpd.c 2019-09-24 21:48:49.234308626 -0400 +@@ -277,14 +277,7 @@ + * OK...pppd died, we can go ahead and close the pty for + * it + */ +-#ifdef USE_KERNEL +- if (!kernel_support) { +- +-#endif + close (c->fd); +-#ifdef USE_KERNEL +- } +-#endif + c->fd = -1; + /* + * terminate tunnel and call loops, returning to the diff --git a/xl2tpd-1.3.14-md5-fips.patch b/xl2tpd-1.3.14-md5-fips.patch new file mode 100644 index 0000000..ed8304f --- /dev/null +++ b/xl2tpd-1.3.14-md5-fips.patch @@ -0,0 +1,468 @@ +diff -Naur xl2tpd-1.3.14-orig/aaa.c xl2tpd-1.3.14/aaa.c +--- xl2tpd-1.3.14-orig/aaa.c 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/aaa.c 2019-09-24 20:51:39.478952494 -0400 +@@ -21,6 +21,8 @@ + #include + #include "l2tp.h" + ++#include ++ + extern void bufferDump (char *, int); + + /* FIXME: Accounting? */ +@@ -273,11 +275,11 @@ + #endif + + memset (chal->response, 0, MD_SIG_SIZE); +- MD5Init (&chal->md5); +- MD5Update (&chal->md5, &chal->ss, 1); +- MD5Update (&chal->md5, chal->secret, strlen ((char *)chal->secret)); +- MD5Update (&chal->md5, chal->challenge, chal->chal_len); +- MD5Final (chal->response, &chal->md5); ++ MD5_Init (&chal->md5); ++ MD5_Update (&chal->md5, &chal->ss, 1); ++ MD5_Update (&chal->md5, chal->secret, strlen ((char *)chal->secret)); ++ MD5_Update (&chal->md5, chal->challenge, chal->chal_len); ++ MD5_Final (chal->response, &chal->md5); + #ifdef DEBUG_AUTH + l2tp_log (LOG_DEBUG, "response is %X%X%X%X to '%s' and %X%X%X%X, %d\n", + *((int *) &chal->response[0]), +@@ -392,12 +394,12 @@ + buf->len += length; + /* Back to the beginning of real data, including the original length AVP */ + +- MD5Init (&t->chal_them.md5); +- MD5Update (&t->chal_them.md5, (void *) &attr, 2); +- MD5Update (&t->chal_them.md5, t->chal_them.secret, ++ MD5_Init (&t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, (void *) &attr, 2); ++ MD5_Update (&t->chal_them.md5, t->chal_them.secret, + strlen ((char *)t->chal_them.secret)); +- MD5Update (&t->chal_them.md5, t->chal_them.vector, VECTOR_SIZE); +- MD5Final (digest, &t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, t->chal_them.vector, VECTOR_SIZE); ++ MD5_Final (digest, &t->chal_them.md5); + + /* Though not a "MUST" in the spec, our subformat length is always a multiple of 16 */ + ptr = ((unsigned char *) new_hdr) + sizeof (struct avp_hdr); +@@ -421,11 +423,11 @@ + #endif + if (ptr < end) + { +- MD5Init (&t->chal_them.md5); +- MD5Update (&t->chal_them.md5, t->chal_them.secret, ++ MD5_Init (&t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, t->chal_them.secret, + strlen ((char *)t->chal_them.secret)); +- MD5Update (&t->chal_them.md5, previous_segment, MD_SIG_SIZE); +- MD5Final (digest, &t->chal_them.md5); ++ MD5_Update (&t->chal_them.md5, previous_segment, MD_SIG_SIZE); ++ MD5_Final (digest, &t->chal_them.md5); + } + previous_segment = ptr; + } +@@ -458,12 +460,12 @@ + that it will be padded to a 16 byte boundary, so we + have to be more careful than when encrypting */ + attr = ntohs (old_hdr->attr); +- MD5Init (&t->chal_us.md5); +- MD5Update (&t->chal_us.md5, (void *) &attr, 2); +- MD5Update (&t->chal_us.md5, t->chal_us.secret, ++ MD5_Init (&t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, (void *) &attr, 2); ++ MD5_Update (&t->chal_us.md5, t->chal_us.secret, + strlen ((char *)t->chal_us.secret)); +- MD5Update (&t->chal_us.md5, t->chal_us.vector, t->chal_us.vector_len); +- MD5Final (digest, &t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, t->chal_us.vector, t->chal_us.vector_len); ++ MD5_Final (digest, &t->chal_us.md5); + #ifdef DEBUG_HIDDEN + l2tp_log (LOG_DEBUG, "attribute is %d and challenge is: ", attr); + print_challenge (&t->chal_us); +@@ -474,11 +476,11 @@ + { + if (cnt >= MD_SIG_SIZE) + { +- MD5Init (&t->chal_us.md5); +- MD5Update (&t->chal_us.md5, t->chal_us.secret, ++ MD5_Init (&t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, t->chal_us.secret, + strlen ((char *)t->chal_us.secret)); +- MD5Update (&t->chal_us.md5, saved_segment, MD_SIG_SIZE); +- MD5Final (digest, &t->chal_us.md5); ++ MD5_Update (&t->chal_us.md5, saved_segment, MD_SIG_SIZE); ++ MD5_Final (digest, &t->chal_us.md5); + cnt = 0; + } + /* at the beginning of each segment, we save the current segment (16 octets or less) of cipher +diff -Naur xl2tpd-1.3.14-orig/aaa.h xl2tpd-1.3.14/aaa.h +--- xl2tpd-1.3.14-orig/aaa.h 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/aaa.h 2019-09-24 20:52:14.179531612 -0400 +@@ -15,7 +15,7 @@ + + #ifndef _AAA_H + #define _AAA_H +-#include "md5.h" ++#include + + #define ADDR_HASH_SIZE 256 + #define MD_SIG_SIZE 16 +@@ -34,7 +34,7 @@ + + struct challenge + { +- struct MD5Context md5; ++ MD5_CTX md5; + unsigned char ss; /* State we're sending in */ + unsigned char secret[MAXSTRLEN]; /* The shared secret */ + unsigned char *challenge; /* The original challenge */ +diff -Naur xl2tpd-1.3.14-orig/Makefile xl2tpd-1.3.14/Makefile +--- xl2tpd-1.3.14-orig/Makefile 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/Makefile 2019-09-24 20:53:02.420020643 -0400 +@@ -101,8 +101,8 @@ + IPFLAGS?= -DIP_ALLOCATION + + CFLAGS+= $(DFLAGS) -Os -Wall -Wextra -DSANITY $(OSFLAGS) $(IPFLAGS) +-HDRS=l2tp.h avp.h misc.h control.h call.h scheduler.h file.h aaa.h md5.h +-OBJS=xl2tpd.o pty.o misc.o control.o avp.o call.o network.o avpsend.o scheduler.o file.o aaa.o md5.o ++HDRS=l2tp.h avp.h misc.h control.h call.h scheduler.h file.h aaa.h ++OBJS=xl2tpd.o pty.o misc.o control.o avp.o call.o network.o avpsend.o scheduler.o file.o aaa.o + SRCS=${OBJS:.o=.c} ${HDRS} + CONTROL_SRCS=xl2tpd-control.c + #LIBS= $(OSLIBS) # -lefence # efence for malloc checking +@@ -121,7 +121,7 @@ + rm -f $(OBJS) $(EXEC) pfc.o pfc $(CONTROL_EXEC) + + $(EXEC): $(OBJS) $(HDRS) +- $(CC) $(LDFLAGS) -o $@ $(OBJS) $(LDLIBS) ++ $(CC) $(LDFLAGS) -o $@ $(OBJS) -lcrypto $(LDLIBS) + + $(CONTROL_EXEC): $(CONTROL_SRCS) + $(CC) $(CFLAGS) $(LDFLAGS) $(CONTROL_SRCS) -o $@ +diff -Naur xl2tpd-1.3.14-orig/md5.c xl2tpd-1.3.14/md5.c +--- xl2tpd-1.3.14-orig/md5.c 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/md5.c 1969-12-31 19:00:00.000000000 -0500 +@@ -1,274 +0,0 @@ +-#ifdef FREEBSD +-# include +-#elif defined(OPENBSD) || defined(NETBSD) +-# define __BSD_VISIBLE 0 +-# include +-#elif defined(LINUX) +-# include +-#elif defined(SOLARIS) +-# include +-#endif +-#if __BYTE_ORDER == __BIG_ENDIAN +-#define HIGHFIRST 1 +-#endif +- +-/* +- * This code implements the MD5 message-digest algorithm. +- * The algorithm is due to Ron Rivest. This code was +- * written by Colin Plumb in 1993, no copyright is claimed. +- * This code is in the public domain; do with it what you wish. +- * +- * Equivalent code is available from RSA Data Security, Inc. +- * This code has been tested against that, and is equivalent, +- * except that you don't need to include two pages of legalese +- * with every copy. +- * +- * To compute the message digest of a chunk of bytes, declare an +- * MD5Context structure, pass it to MD5Init, call MD5Update as +- * needed on buffers full of bytes, and then call MD5Final, which +- * will fill a supplied 16-byte array with the digest. +- */ +-#include /* for memcpy() */ +-#include "md5.h" +- +-#ifndef HIGHFIRST +-#define byteReverse(buf, len) /* Nothing */ +-#else +-void byteReverse (unsigned char *buf, unsigned longs); +- +-#ifndef ASM_MD5 +-/* +- * Note: this code is harmless on little-endian machines. +- */ +-void byteReverse (unsigned char *buf, unsigned longs) +-{ +- uint32 t; +- do +- { +- t = (uint32) ((unsigned) buf[3] << 8 | buf[2]) << 16 | +- ((unsigned) buf[1] << 8 | buf[0]); +- *(uint32 *) buf = t; +- buf += 4; +- } +- while (--longs); +-} +-#endif +-#endif +- +-/* +- * Start MD5 accumulation. Set bit count to 0 and buffer to mysterious +- * initialization constants. +- */ +-void MD5Init (struct MD5Context *ctx) +-{ +- ctx->buf[0] = 0x67452301; +- ctx->buf[1] = 0xefcdab89; +- ctx->buf[2] = 0x98badcfe; +- ctx->buf[3] = 0x10325476; +- +- ctx->bits[0] = 0; +- ctx->bits[1] = 0; +-} +- +-/* +- * Update context to reflect the concatenation of another buffer full +- * of bytes. +- */ +-void MD5Update (struct MD5Context *ctx, unsigned char const *buf, +- unsigned len) +-{ +- uint32 t; +- +- /* Update bitcount */ +- +- t = ctx->bits[0]; +- if ((ctx->bits[0] = t + ((uint32) len << 3)) < t) +- ctx->bits[1]++; /* Carry from low to high */ +- ctx->bits[1] += len >> 29; +- +- t = (t >> 3) & 0x3f; /* Bytes already in shsInfo->data */ +- +- /* Handle any leading odd-sized chunks */ +- +- if (t) +- { +- unsigned char *p = (unsigned char *) ctx->in + t; +- +- t = 64 - t; +- if (len < t) +- { +- memcpy (p, buf, len); +- return; +- } +- memcpy (p, buf, t); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- buf += t; +- len -= t; +- } +- /* Process data in 64-byte chunks */ +- +- while (len >= 64) +- { +- memcpy (ctx->in, buf, 64); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- buf += 64; +- len -= 64; +- } +- +- /* Handle any remaining bytes of data. */ +- +- memcpy (ctx->in, buf, len); +-} +- +-/* +- * Final wrapup - pad to 64-byte boundary with the bit pattern +- * 1 0* (64-bit count of bits processed, MSB-first) +- */ +-void MD5Final (unsigned char digest[16], struct MD5Context *ctx) +-{ +- unsigned count; +- unsigned char *p; +- +- /* Compute number of bytes mod 64 */ +- count = (ctx->bits[0] >> 3) & 0x3F; +- +- /* Set the first char of padding to 0x80. This is safe since there is +- always at least one byte free */ +- p = ctx->in + count; +- *p++ = 0x80; +- +- /* Bytes of padding needed to make 64 bytes */ +- count = 64 - 1 - count; +- +- /* Pad out to 56 mod 64 */ +- if (count < 8) +- { +- /* Two lots of padding: Pad the first block to 64 bytes */ +- memset (p, 0, count); +- byteReverse (ctx->in, 16); +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- +- /* Now fill the next block with 56 bytes */ +- memset (ctx->in, 0, 56); +- } +- else +- { +- /* Pad block to 56 bytes */ +- memset (p, 0, count - 8); +- } +- byteReverse (ctx->in, 14); +- +- /* Append length in bits and transform */ +- memcpy(ctx->in + 14 * sizeof(uint32), ctx->bits, sizeof(ctx->bits)); +- +- MD5Transform (ctx->buf, (uint32 *) ctx->in); +- byteReverse ((unsigned char *) ctx->buf, 4); +- memcpy (digest, ctx->buf, 16); +- memset (ctx, 0, sizeof (*ctx)); /* In case it's sensitive */ +-} +- +-#ifndef ASM_MD5 +- +-/* The four core functions - F1 is optimized somewhat */ +- +-/* #define F1(x, y, z) (x & y | ~x & z) */ +-#define F1(x, y, z) (z ^ (x & (y ^ z))) +-#define F2(x, y, z) F1(z, x, y) +-#define F3(x, y, z) (x ^ y ^ z) +-#define F4(x, y, z) (y ^ (x | ~z)) +- +-/* This is the central step in the MD5 algorithm. */ +-#define MD5STEP(f, w, x, y, z, data, s) \ +- ( w += f(x, y, z) + data, w = w<>(32-s), w += x ) +- +-/* +- * The core of the MD5 algorithm, this alters an existing MD5 hash to +- * reflect the addition of 16 longwords of new data. MD5Update blocks +- * the data and converts bytes into longwords for this routine. +- */ +-void MD5Transform (uint32 buf[4], uint32 const in[16]) +-{ +- register uint32 a, b, c, d; +- +- a = buf[0]; +- b = buf[1]; +- c = buf[2]; +- d = buf[3]; +- +- MD5STEP (F1, a, b, c, d, in[0] + 0xd76aa478, 7); +- MD5STEP (F1, d, a, b, c, in[1] + 0xe8c7b756, 12); +- MD5STEP (F1, c, d, a, b, in[2] + 0x242070db, 17); +- MD5STEP (F1, b, c, d, a, in[3] + 0xc1bdceee, 22); +- MD5STEP (F1, a, b, c, d, in[4] + 0xf57c0faf, 7); +- MD5STEP (F1, d, a, b, c, in[5] + 0x4787c62a, 12); +- MD5STEP (F1, c, d, a, b, in[6] + 0xa8304613, 17); +- MD5STEP (F1, b, c, d, a, in[7] + 0xfd469501, 22); +- MD5STEP (F1, a, b, c, d, in[8] + 0x698098d8, 7); +- MD5STEP (F1, d, a, b, c, in[9] + 0x8b44f7af, 12); +- MD5STEP (F1, c, d, a, b, in[10] + 0xffff5bb1, 17); +- MD5STEP (F1, b, c, d, a, in[11] + 0x895cd7be, 22); +- MD5STEP (F1, a, b, c, d, in[12] + 0x6b901122, 7); +- MD5STEP (F1, d, a, b, c, in[13] + 0xfd987193, 12); +- MD5STEP (F1, c, d, a, b, in[14] + 0xa679438e, 17); +- MD5STEP (F1, b, c, d, a, in[15] + 0x49b40821, 22); +- +- MD5STEP (F2, a, b, c, d, in[1] + 0xf61e2562, 5); +- MD5STEP (F2, d, a, b, c, in[6] + 0xc040b340, 9); +- MD5STEP (F2, c, d, a, b, in[11] + 0x265e5a51, 14); +- MD5STEP (F2, b, c, d, a, in[0] + 0xe9b6c7aa, 20); +- MD5STEP (F2, a, b, c, d, in[5] + 0xd62f105d, 5); +- MD5STEP (F2, d, a, b, c, in[10] + 0x02441453, 9); +- MD5STEP (F2, c, d, a, b, in[15] + 0xd8a1e681, 14); +- MD5STEP (F2, b, c, d, a, in[4] + 0xe7d3fbc8, 20); +- MD5STEP (F2, a, b, c, d, in[9] + 0x21e1cde6, 5); +- MD5STEP (F2, d, a, b, c, in[14] + 0xc33707d6, 9); +- MD5STEP (F2, c, d, a, b, in[3] + 0xf4d50d87, 14); +- MD5STEP (F2, b, c, d, a, in[8] + 0x455a14ed, 20); +- MD5STEP (F2, a, b, c, d, in[13] + 0xa9e3e905, 5); +- MD5STEP (F2, d, a, b, c, in[2] + 0xfcefa3f8, 9); +- MD5STEP (F2, c, d, a, b, in[7] + 0x676f02d9, 14); +- MD5STEP (F2, b, c, d, a, in[12] + 0x8d2a4c8a, 20); +- +- MD5STEP (F3, a, b, c, d, in[5] + 0xfffa3942, 4); +- MD5STEP (F3, d, a, b, c, in[8] + 0x8771f681, 11); +- MD5STEP (F3, c, d, a, b, in[11] + 0x6d9d6122, 16); +- MD5STEP (F3, b, c, d, a, in[14] + 0xfde5380c, 23); +- MD5STEP (F3, a, b, c, d, in[1] + 0xa4beea44, 4); +- MD5STEP (F3, d, a, b, c, in[4] + 0x4bdecfa9, 11); +- MD5STEP (F3, c, d, a, b, in[7] + 0xf6bb4b60, 16); +- MD5STEP (F3, b, c, d, a, in[10] + 0xbebfbc70, 23); +- MD5STEP (F3, a, b, c, d, in[13] + 0x289b7ec6, 4); +- MD5STEP (F3, d, a, b, c, in[0] + 0xeaa127fa, 11); +- MD5STEP (F3, c, d, a, b, in[3] + 0xd4ef3085, 16); +- MD5STEP (F3, b, c, d, a, in[6] + 0x04881d05, 23); +- MD5STEP (F3, a, b, c, d, in[9] + 0xd9d4d039, 4); +- MD5STEP (F3, d, a, b, c, in[12] + 0xe6db99e5, 11); +- MD5STEP (F3, c, d, a, b, in[15] + 0x1fa27cf8, 16); +- MD5STEP (F3, b, c, d, a, in[2] + 0xc4ac5665, 23); +- +- MD5STEP (F4, a, b, c, d, in[0] + 0xf4292244, 6); +- MD5STEP (F4, d, a, b, c, in[7] + 0x432aff97, 10); +- MD5STEP (F4, c, d, a, b, in[14] + 0xab9423a7, 15); +- MD5STEP (F4, b, c, d, a, in[5] + 0xfc93a039, 21); +- MD5STEP (F4, a, b, c, d, in[12] + 0x655b59c3, 6); +- MD5STEP (F4, d, a, b, c, in[3] + 0x8f0ccc92, 10); +- MD5STEP (F4, c, d, a, b, in[10] + 0xffeff47d, 15); +- MD5STEP (F4, b, c, d, a, in[1] + 0x85845dd1, 21); +- MD5STEP (F4, a, b, c, d, in[8] + 0x6fa87e4f, 6); +- MD5STEP (F4, d, a, b, c, in[15] + 0xfe2ce6e0, 10); +- MD5STEP (F4, c, d, a, b, in[6] + 0xa3014314, 15); +- MD5STEP (F4, b, c, d, a, in[13] + 0x4e0811a1, 21); +- MD5STEP (F4, a, b, c, d, in[4] + 0xf7537e82, 6); +- MD5STEP (F4, d, a, b, c, in[11] + 0xbd3af235, 10); +- MD5STEP (F4, c, d, a, b, in[2] + 0x2ad7d2bb, 15); +- MD5STEP (F4, b, c, d, a, in[9] + 0xeb86d391, 21); +- +- buf[0] += a; +- buf[1] += b; +- buf[2] += c; +- buf[3] += d; +-} +- +-#endif +diff -Naur xl2tpd-1.3.14-orig/md5.h xl2tpd-1.3.14/md5.h +--- xl2tpd-1.3.14-orig/md5.h 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/md5.h 1969-12-31 19:00:00.000000000 -0500 +@@ -1,29 +0,0 @@ +-#ifndef MD5_H +-#define MD5_H +- +-#ifdef __alpha +-typedef unsigned int uint32; +-#else +-#include +-typedef uint32_t uint32; +-#endif +- +-struct MD5Context +-{ +- uint32 buf[4]; +- uint32 bits[2]; +- unsigned char in[64]; +-}; +- +-void MD5Init (struct MD5Context *context); +-void MD5Update (struct MD5Context *context, unsigned char const *buf, +- unsigned len); +-void MD5Final (unsigned char digest[16], struct MD5Context *context); +-void MD5Transform (uint32 buf[4], uint32 const in[16]); +- +-/* +- * This is needed to make RSAREF happy on some MS-DOS compilers. +- */ +-typedef struct MD5Context MD5_CTX; +- +-#endif /* !MD5_H */ +diff -Naur xl2tpd-1.3.14-orig/xl2tpd.c xl2tpd-1.3.14/xl2tpd.c +--- xl2tpd-1.3.14-orig/xl2tpd.c 2019-04-17 12:23:39.000000000 -0400 ++++ xl2tpd-1.3.14/xl2tpd.c 2019-09-24 20:53:50.969512827 -0400 +@@ -1643,7 +1643,11 @@ + + + static void usage(void) { +- printf("\nxl2tpd version: %s\n", SERVER_VERSION); ++ printf("\nxl2tpd version: %s\n" ++"This product includes software developed by the OpenSSL Project for use\n" ++"in the OpenSSL Toolkit. (http://www.openssl.org/)\n" ++, SERVER_VERSION); ++ + printf("Usage: xl2tpd [-c ] [-s ] [-p ]\n" + " [-C ] [-D] [-l] [-q ]\n" + " [-v, --version]\n"); diff --git a/xl2tpd.spec b/xl2tpd.spec index dc97108..037412f 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -1,22 +1,21 @@ Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661) Name: xl2tpd -Version: 1.3.8 -Release: 3%{?dist} +Version: 1.3.14 +Release: 1%{?dist} License: GPL+ Url: https://github.com/xelerance/xl2tpd/ -Group: System Environment/Daemons # upstream isn't using proper names, we manually rename v-VERSION.tar.gz to xl2tpd-VERSION.tar.gz Source0: https://github.com/xelerance/xl2tpd/archive/xl2tpd-%{version}.tar.gz Source1: xl2tpd.service Source2: tmpfiles-xl2tpd.conf -Patch1: xl2tpd-1.3.6-conf.patch -Patch2: xl2tpd-1.3.8-md5-fips.patch -Patch3: xl2tpd-1.3.8-saref.patch -Patch4: xl2tpd-1.3.8-kernelmode.patch +Patch1: xl2tpd-1.3.14-conf.patch +Patch2: xl2tpd-1.3.14-md5-fips.patch +Patch3: xl2tpd-1.3.14-kernelmode.patch Requires: ppp >= 2.4.5-18 # If you want to authenticate against a Microsoft PDC/Active Directory # Requires: samba-winbind +BuildRequires: gcc BuildRequires: libpcap-devel BuildRequires: systemd-units BuildRequires: openssl-devel @@ -54,29 +53,27 @@ It was de-facto maintained by Jacco de Leeuw in 2002 and 2003. %patch1 -p1 %patch2 -p1 %patch3 -p1 -%patch4 -p1 %build -#make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" - export CFLAGS="$CFLAGS -fPIC -Wall -DTRUST_PPPD_TO_DIE" export DFLAGS="$RPM_OPT_FLAGS -g " export LDFLAGS="$LDFLAGS -pie -Wl,-z,relro -Wl,-z,now" -make +# if extra debugging is needed, use: +# %make_build DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_FLOW -DDEBUG_PAYLOAD -DDEBUG_CONTROL -DDEBUG_CONTROL_XMIT -DDEBUG_FLOW_MORE -DDEBUG_MAGIC -DDEBUG_ENTROPY -DDEBUG_HIDDEN -DDEBUG_PPPD -DDEBUG_AAA -DDEBUG_FILE -DDEBUG_FLOW -DDEBUG_HELLO -DDEBUG_CLOSE -DDEBUG_ZLB -DDEBUG_AUTH" +%make_build %install -rm -rf %{buildroot} make DESTDIR=%{buildroot} PREFIX=%{_prefix} install install -d 0755 %{buildroot}%{_unitdir} install -m 0644 %{SOURCE1} %{buildroot}%{_unitdir}/xl2tpd.service -mkdir -p %{buildroot}%{_prefix}/lib/tmpfiles.d/ -install -m 0644 %{SOURCE2} %{buildroot}%{_prefix}/lib/tmpfiles.d/%{name}.conf +mkdir -p %{buildroot}/%{_tmpfilesdir} +install -m 0644 %{SOURCE2} %{buildroot}/%{_tmpfilesdir}/%{name}.conf install -p -D -m644 examples/xl2tpd.conf %{buildroot}%{_sysconfdir}/xl2tpd/xl2tpd.conf install -p -D -m644 examples/ppp-options.xl2tpd %{buildroot}%{_sysconfdir}/ppp/options.xl2tpd install -p -D -m600 doc/l2tp-secrets.sample %{buildroot}%{_sysconfdir}/xl2tpd/l2tp-secrets install -p -D -m600 examples/chapsecrets.sample %{buildroot}%{_sysconfdir}/ppp/chap-secrets.sample -install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd +install -p -D -m755 -d %{buildroot}%{_rundir}/xl2tpd %preun %systemd_preun xl2tpd.service @@ -97,7 +94,8 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd /bin/systemctl try-restart xl2tpd.service >/dev/null 2>&1 || : %files -%doc BUGS CHANGES CREDITS LICENSE README.* TODO +%doc BUGS CHANGES CREDITS README.* TODO +%license LICENSE %doc doc/README.patents examples/chapsecrets.sample %{_sbindir}/xl2tpd %{_sbindir}/xl2tpd-control @@ -106,12 +104,17 @@ install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd %dir %{_sysconfdir}/xl2tpd %config(noreplace) %{_sysconfdir}/xl2tpd/* %config(noreplace) %{_sysconfdir}/ppp/* -%dir %{_localstatedir}/run/xl2tpd +%dir %{_rundir}/xl2tpd %{_unitdir}/%{name}.service -%{_prefix}/lib/tmpfiles.d/%{name}.conf -%ghost %attr(0600,root,root) %{_localstatedir}/run/xl2tpd/l2tp-control +%{_tmpfilesdir}/%{name}.conf +%ghost %attr(0600,root,root) %{_rundir}/xl2tpd/l2tp-control %changelog +* Wed Sep 25 2019 Paul Wouters - 1.3.14-1 +- Resolves: rhbz#1322190 Updated to 1.3.14 +- Resolves: rhbz#1722121 Use proper /run directory +- Resolves: rhbz#1399648 Review Request: xl2tpd + * Sun Apr 01 2018 Paul Wouters - 1.3.8-3 - Resolves: rhbz#1562512 kernels 4.15 and 4.16 break xl2tpd From 15268c673c2fafa4f556458c400fb3c5511542bf Mon Sep 17 00:00:00 2001 From: Paul Wouters Date: Thu, 3 Sep 2020 21:20:35 -0400 Subject: [PATCH 9/9] remove Suggests: for epel7 --- xl2tpd.spec | 2 -- 1 file changed, 2 deletions(-) diff --git a/xl2tpd.spec b/xl2tpd.spec index d327ed4..5e5e121 100644 --- a/xl2tpd.spec +++ b/xl2tpd.spec @@ -22,8 +22,6 @@ BuildRequires: openssl-devel Requires(post): systemd Requires(preun): systemd Requires(postun): systemd -# dnf resolving prefers kernel-debug-modules-extra over kernel-modules-extra -Suggests: kernel-modules-extra %description xl2tpd is an implementation of the Layer 2 Tunnelling Protocol (RFC 2661).