aboutsummaryrefslogtreecommitdiff
path: root/net/stunnel/files
Commit message (Collapse)AuthorAge
* stunnel: add new protocol option capwin and capwinctrlFlorian Eckert2022-01-10
| | | | | | | The new protocol capwin and capwinctrl was added in version 5.61 https://www.stunnel.org/NEWS.html Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: add missing sessionResume optionFlorian Eckert2022-01-10
| | | | | | | The option sessionResume was added in version 5.60 https://www.stunnel.org/NEWS.html Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: fix some shellcheck warningsFlorian Eckert2019-07-29
| | | | Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: update version to 5.54Florian Eckert2019-05-21
| | | | | | | Update to latest stable release 5.54 Add new options ticketKeySecret and ticketMacSecret to uci validation. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: update to version 5.51Florian Eckert2019-04-10
| | | | | | Update to version 5.51 Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: Update init scriptJeffery To2019-01-29
| | | | | | | | | | | | | | | | | | | | | | The reworked init script: * Loads and validates options using uci_validate_section() (through uci_load_validate()) * Allows service options be specified in the globals section * Hard-codes less global options (debug, syslog), as their default values already work * Adds support for almost all options (up to the current package version, 5.49) * Moves the pid file into a subdirectory (/var/run/stunnel) so that it can be created successfully when setuid is used Certain options are omitted: * chroot - requires more setup than the init script can manage * fips, libwrap - disabled at compile-time * iconActive, iconError, iconIdle, taskbar - gui/win32 only * verify - obsolete, verifyChain and/or verifyPeer should be used instead Signed-off-by: Jeffery To <jeffery.to@gmail.com>
* net/stunnel: check if service section is configured to prevent crash loopFlorian Eckert2018-01-23
| | | | | | | | | | If a service section is not presented in the configuration then stunnel will always start anyway. This ends in a crash loop because the configuration is not valid. Checking in "uci" mode if a service section is presented and only then start the stunnel service will solve this issue. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* net/stunnel: do always stop/start on config changeFlorian Eckert2018-01-23
| | | | | | | | | | Do not send a SIGHUP on reload configuration let procd restart the service with stop/start. This is saver. Add uci generated stunnel file to procd "file" attribute to reload/restart the stunnel service. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* net/stunnel: add enabled config optionFlorian Eckert2017-12-15
| | | | | | | Add an enabled option for the service section, so you could keep your configuration in place without apply this section on startup or service reload. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* net/stunnel: add uci config supportFlorian Eckert2017-12-10
| | | | | | Add uci config support. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
* stunnel: Bring it back at v5.10Michael Haas2015-03-17
From: Michael Haas <haas@computerlinguist.org> * init script no longer creates certificates (consider client mode as use case) * patches/010_fix_getnameinfo.patch: Fix getnameinfo signature * patches/011_disable_ssp_linking.patch: Disable -fstack-protector as it is not always available in OpenWRT * old patches (in oldpackages) no longer necessary * remove libwrap dependency * remove libpthread dependency * respect CONFIG_IPV6 * init script uses procd * sample stunnel.conf runs in client mode - prevents start failure, does not require cert Possible enhancement: automatically generate certificate as done in uhttpd. However, as client mode is a possible use case, I'd rather not. Additionally, stunnel may use several certs with user-defined locations and we can't easily set a cert location via command-line args. The package is based on https://sites.google.com/site/twisteroidambassador/openwrt/stunnel Signed-off-by: Michael Haas <haas@computerlinguist.org>