Commit Graph
268 Commits
Author SHA1 Message Date
Armin Kuster 3352b61846 fail2Ban: Add new package
Fail2Ban scans log files like /var/log/auth.log and bans IP addresses having too many failed login attempts. It does this by updating system firewall rules to reject new connections from those IP addresses, for a configurable amount of time. Fail2Ban comes out-of-the-box ready to read many standard log files, such as those for sshd and Apache, and is easy to configure to read any log file you choose, for any error you choose.

Though Fail2Ban is able to reduce the rate of incorrect authentications attempts, it cannot eliminate the risk that weak authentication presents. Configure services to use only two factor or public/private authentication mechanisms if you really want to protect services.

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:23 -07:00
Armin Kuster ed1aa53ced sleuthkit: fix No GNU_HASH in the elf binary
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:23 -07:00
Mikko Ylinen 588e85230b linux-yocto: drop all 4.1 content
linux-yocto_4.1.bb recipe has been removed from oe-core master
and that triggers a bitbake error due to orphan bbappends
maintained in meta-security.

To fix the error, drop linux-yocto_4.1.bbappend plus the patches
and the config fragments for it.

Signed-off-by: Mikko Ylinen <mikko.ylinen@linux.intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:23 -07:00
Armin Kuster 3edd9d56dd linux-yocto: add 4.12 bbappends
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:23 -07:00
Armin Kuster a9c1515a37 tripwire: update to 2.4.3.5
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:23 -07:00
Jackie Huang e593413a30 samhain: update to 4.2.2
* update to version 4.2.2
* Add new recipe for standalone mode
* Add systemd support
* Add patches to fix several issues
* samhain-standalone: add ptest support
* samhain-server: no need to depend on samhain-server-native
* Move common things from the bb to the inc file

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-09-02 11:26:12 -07:00
Tom Rini 2af2e78734 apparmor: Additional runtime fixes
- We need various python3 modules and we can only really solve this
  problem by including all python3-modules.
- aa-easyprof needs to have its shebang corrected, do so.
- The apparmor initscript depends on functions that LSB does not require
  so we must provide them.  In some cases it's using non-standard
  function, so we just use more appropriate names.
- The apparmor sysvinit-style initscript assumes that
  systemd-detect-virt will exist on the filesystem.  Change this to
  check that it does before trying to execute it.

[for aa-easyprof:]
Reported-by: Anders Montonen <Anders.Montonen@iki.fi>
Signed-off-by: Tom Rini <trini@konsulko.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Jackie Huang 7c6528e36c libmhash: add new recipe
Mhash is a free (under GNU Lesser GPL) library which provides
a uniform interface to a large number of hash algorithms.
These algorithms can be used to compute checksums, message
digests, and other signatures.

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Jackie Huang 098d75c8ad libgssglue: add new recipe
libgssglue exports a gssapi interface which calls
other gssapi libraries.

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Jackie Huang b08646b517 nmap: upgrade to 7.50
- Add a patch to fix python library install dir for multilib.

- Add a patch to fix race condition with mkdir command.

- Inherit pythonnative instead of python-dir and install
  python modules for ndiff to fix the following errors:

  """
  root@qemux86-64:~# ndiff --help
  -sh: /usr/bin/ndiff: /path_to_build/tmp/hosttools/python: bad interpreter: No such file or directory
  root@qemux86-64:~# python /usr/bin/ndiff
  Could not import the ndiff module: 'No module named ndiff'.
  """

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Jackie Huang 28f9b5f1ac keynote: add new recipe
KeyNote is a simple and flexible trust-management system
designed to work well for a variety of large- and small-
scale Internet-based applications

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Armin Kuster c93a3d38e8 tpm2.0-tools: update to 2.0.0 plus
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-07-31 08:15:22 -07:00
Jackie Huang 7373d476a4 xmlsec1: add new recipe
XML Security Library is a C library based on LibXML2 and OpenSSL.

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-06-20 21:44:23 -07:00
Tom Rini 85f21ebd70 apparmor: Rework such that the utilities are functional by default
This introduces a number of changes:
- Fix the python PACKAGECONFIG knob
  - The included python support is python3-based, so use those classes.
  - When set, make sure to RDEPEND on the python modules the tools use.
- Fix the perl PACKAGECONFIG knob
  - Add two patches so that configure will find perl and then compile
    will cross-compile the library correctly.
  - So that we place perl modules in the correct location we need cpan
    to be inherited.
  - When disabled, remove the RDEPENDS on perl as the RDEPENDS comes in
    via inherit.
- Default to enabling the python and perl PACKAGECONFIG knobs as the
  majority of the userspace tools are python3 based, and the few that
  aren't that nor C based are perl based.
- Because of the above we must drop the -python package because it's
  required for the utilities in the main package.

Signed-off-by: Tom Rini <trini@konsulko.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-06-20 21:44:13 -07:00
Armin Kuster 15e9238f02 apparmor: fix python packaging issue
WARNING: apparmor-2.11.0-r0 do_package: QA Issue: apparmor: Files/directories were installed but not shipped in any package:
  /usr/lib/python2.7
  /usr/lib/python2.7/site-packages
  /usr/lib/python2.7/site-packages/apparmor-2.11.0-py2.7.egg-info
  /usr/lib/python2.7/site-packages/apparmor
  /usr/lib/python2.7/site-packages/apparmor/regex.py

use python2 instead of python3

Signed-off-by: Armin Kuster <akuster@mvista.com>
2017-05-30 08:01:41 -07:00
Jackie Huang 0686f0276a ecryptfs-utils: add new recipe
eCryptfs is a stacked cryptographic filesystem that ships
in Linux kernel versions 2.6.19 and above. This package
provides the mount helper and supporting libraries to
perform key management and mount functions.

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-30 08:01:15 -07:00
Jackie Huang 4d95e9819f keyutils: add new recipe
keyutils is utilities to control the kernel key
management facility and to provide a mechanism by
which the kernel call back to userspace to get a
key instantiated.

It's required by ecryptfs-utils.

Signed-off-by: Jackie Huang <jackie.huang@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-30 08:01:11 -07:00
André Draszik 1a26789043 layer.conf: fix typo (meta-filesystems vs mete-filesystems)
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-29 14:31:25 -07:00
Armin Kuster 6c636e7f4e tor: add recipe
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-29 14:31:12 -07:00
Peter Lei ce7c934569 packagegroup-security-tpm-i2c: fix syntax
Fix "ERROR: ExpansionError during parsing" when building with multilib.

Signed-off-by: Peter Lei <peter.lei@ieee.org>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-19 07:38:20 -07:00
Armin Kuster 4859a49faf layer-conf: Use *_FEATURES in LAYERDEPENDS
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-14 07:55:02 -07:00
Armin Kuster eec916bd18 security-core package group: add few more apps
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-09 07:49:14 -07:00
Armin Kuster 131c2d24f4 clamav: fix new build error
configure: error: The installed zlib version may contain a security bug. Please upgrade to 1.2.2 or later: http://www.zlib.net. You can omit this check with --disable-zlib-vcheck but DO NOT REPORT any stability issues then!

bypass check as our zlib is 1.2.11

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-09 07:49:03 -07:00
Armin Kuster 99eeb2a916 sssd: update SRC_URI as git.fedorahosted.org shut down
build fixes too

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-09 07:48:58 -07:00
Armin Kuster 4de97bd1ef tpm2: package groups fixes
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 12:47:42 -07:00
Armin Kuster b4d295e12f linux-stable: fix module selections
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 12:47:05 -07:00
Armin Kuster 69a5586888 tpm-image: used for testing for now.
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:39:54 -07:00
Armin Kuster fcbd8a33d4 kernel tpm rework
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:39:35 -07:00
Armin Kuster 64928b7943 tpm-i2c: some systems us i2c TPM
add modules and i2c support

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:38:23 -07:00
Armin Kuster 2e0e2fa1d2 tpm packagegroups: split into logical units
this should help mitgate the need to pull in too many layers
if swtpm in not wanted

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:36:46 -07:00
Armin Kuster 929521997a packagegroup: remove tpm components
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:36:38 -07:00
Armin Kuster b084179a30 meta-tpm: add base package group as was in meta-security
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:36:34 -07:00
Armin Kuster 68bad57b8c change tpm from distro to machine feature
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:34:32 -07:00
Armin Kuster 69523a73c4 tpm: move to a sub layer
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-08 08:33:49 -07:00
Patrick Ohly a6218f5c5a swtpm-wrappers-native.bb: need netstat
netstat from net-tools-native is needed for swtpm_setup.sh, which uses
it to check whether the swtpm daemon has started. The scripts hangs in
a loop during startup when netstat is missing.

Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-05-07 13:29:05 -07:00
Armin Kuster 8fdd9c61f7 freediameter: Add recipe
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-25 18:14:47 -07:00
Patrick Ohly 5ff27eec48 swtpm-wrappers: fix naming convention violation
Native recipes must be called <foo>-native. This is more than just a
recommendation, there's actual code which checks for the suffix.

Not following that rule broke swtpm-wrappers when using the "usrmerge"
DISTRO_FEATURE, because the code in native.bbclass which cleans up
DISTRO_FEATURES for native recipes was skipped and thus swtpm-wrappers
ended up using different paths than the other native recipes.

Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-25 18:11:35 -07:00
Armin Kuster 8263f72c44 tpm2.0-tss: update to tip.
remove merged patch now in tip

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-13 14:04:00 -07:00
Armin Kuster 8a86287026 samhain: update to 4.2.1
remove patch integrated into update

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-13 14:04:00 -07:00
Amarnath Valluri 72de9714a1 swtpm: update to latest tip
Pull in changes to support passing client control sockets(--ctrl
type=unixio,clientfd=<fd>), that allows to fork swtpm and communicate using
socketpair.

Signed-off-by: Amarnath Valluri <amarnath.valluri@intel.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-11 20:42:19 -07:00
Armin Kuster 66bcc2399d apparmor: update to 2.11.0 plus ptest
update to 2.11
Add basic ptest support

v2: remove none existent file

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-04 05:50:36 -07:00
Armin Kuster 6c350a6086 linux-yocto: add 4.10 kernel support
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-02 18:43:02 -07:00
Armin Kuster 34fba126c6 libseccomp: update to 2.3.2
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-01 16:34:53 -07:00
Armin Kuster c1f4596e36 tpm2.0-tss: fix musl build issue
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-01 15:10:41 -07:00
Armin Kuster d22c127b94 kernel: mv 4.8 kernel to 4.9
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-04-01 14:59:50 -07:00
Armin Kuster 9b08e67ea7 tpm2.0-tss: update to latest
[v2]:
include new hash

LICENSE file changes do to removal of TCG

minor changes do to configure and makefile updates

Signed-off-by: Armin Kuster <akuster@mvista.com>
2017-04-01 06:29:05 -07:00
Armin Kuster 1d2b837393 tpm2.0-tools: update to latest
minor changes to reflect configure/makefile updates

Signed-off-by: Armin Kuster <akuster@mvista.com>
2017-04-01 06:29:05 -07:00
Armin Kuster 2f31c09f0b samhain: fix build issues when using musl
[v2]: Correct musl malloc fix.
remove HAVE_MALLOC_H define; this enables using the included defined mallinfo.

[V1]: Fix c99

x_dnmalloc.c:563:26: error: return type is an incomplete type
| #define public_mALLINFo mallinfo
| ^
| x_dnmalloc.c:1689:17: note: in expansion of macro 'public_mALLINFo'
| struct mallinfo public_mALLINFo() {

and
_dnmalloc.c:5527:17: error: unknown type name 'u_int'
| u_int rnd[(128 - 2*sizeof(struct timeval)) / sizeof(u_int)];
| ^~~~~

Signed-off-by: Armin Kuster <akuster808@gmail.com>
2017-03-27 14:30:51 -07:00
Benjamin Gaignard 3883ddae32 tpm2.0-tss: install resourcemgr service
Install systemd resource.mgr service and it needed user/group.

version 2:
- do not hardcode sbin directory in a patch but use ${sbindir} instead

Signed-off-by: Benjamin Gaignard <benjamin.gaignard@linaro.org>
Signed-off-by: Armin Kuster <akuster@mvista.com>
2017-03-27 14:30:32 -07:00
Patrick Ohly 7f2e717ccd swtpm-wrappers: wrap more commands
Soon it might be possible to let qemu start swtpm directly, without
requiring root privileges as for swtpm_cuse. For that to work
we also need to wrap the swtpm binary. Just in case we now also
do it for everything.

Signed-off-by: Patrick Ohly <patrick.ohly@intel.com>
2017-03-24 08:15:54 -07:00