Patrick Schleizer
ff9bc1d7ea
informational output during PAM:
...
* Show failed and remaining password attempts.
* Document unlock procedure if Linux user account got locked.
* Point out, that there is no password feedback for `su`.
* Explain locked (root) account if locked.
* /usr/share/pam-configs/tally2-security-misc
* /usr/lib/security-misc/pam_tally2-info
2019-08-15 13:37:28 +00:00
Patrick Schleizer
ce4a30d3ce
bumped changelog version
2019-08-14 11:52:26 +00:00
Patrick Schleizer
a7c25a451c
remove unneeded dependency on libpam-cgfs
2019-08-14 11:50:53 +00:00
Patrick Schleizer
633854c6be
bumped changelog version
2019-08-14 11:13:25 +00:00
Patrick Schleizer
0feb54b28e
add Depends: apparmor-profile-anondist to fix apparmor issue
...
sudo[19806]: pam_exec(sudo:session): execve(/usr/lib/security-misc/permission-lockdown,...) failed: Permission denied
sudo[18961]: pam_exec(sudo:session): /usr/lib/security-misc/permission-lockdown failed: exit code 13
kernel: audit: type=1400 audit(1565780860.972:224): apparmor="DENIED" operation="exec" profile="/usr/bin/whonixcheck" name="/usr/lib/security-misc/permission-lockdown" pid=19806 comm="sudo" requested_mask="x" denied_mask="x" fsuid=0 ouid=0
2019-08-14 11:10:18 +00:00
Patrick Schleizer
5213cfbcdc
bumped changelog version
2019-08-14 10:08:18 +00:00
Patrick Schleizer
01b3a0bfae
description
2019-08-14 09:52:53 +00:00
Patrick Schleizer
dee195d89e
description
2019-08-14 09:40:41 +00:00
Patrick Schleizer
21489111d1
run permission lockdown during pam
...
https://forums.whonix.org/t/change-default-umask/7416
2019-08-14 08:34:03 +00:00
Patrick Schleizer
42f2d5f666
description
2019-08-14 07:39:28 +00:00
Patrick Schleizer
f210294f40
description
2019-08-14 07:24:24 +00:00
Patrick Schleizer
f1d8cbc9fb
bumped changelog version
2019-08-14 07:02:09 +00:00
Patrick Schleizer
a82448d46a
description
2019-08-14 07:01:25 +00:00
Patrick Schleizer
6f8acf06d7
bumped changelog version
2019-08-11 12:07:07 +00:00
Patrick Schleizer
aacd9c7679
description
2019-08-11 10:34:38 +00:00
Patrick Schleizer
c0b5c70de4
description
2019-08-11 10:33:22 +00:00
Patrick Schleizer
75769151cd
bumped changelog version
2019-08-10 11:37:02 +00:00
Patrick Schleizer
a703865dcf
bumped changelog version
2019-08-01 12:02:41 +00:00
Patrick Schleizer
5d0aec1321
bumped changelog version
2019-07-31 19:12:27 +00:00
madaidan
4a6f87f3fa
Update control
2019-07-31 18:33:28 +00:00
Patrick Schleizer
864de10659
bumped changelog version
2019-07-31 15:17:51 +00:00
Patrick Schleizer
c09fb208d1
bumped changelog version
2019-07-31 07:44:50 +00:00
Patrick Schleizer
ac1220e14b
depend on sudo so group sudo exists during postinst
2019-07-31 07:32:59 +00:00
Patrick Schleizer
09f75fb1ff
description
2019-07-31 07:32:36 +00:00
Patrick Schleizer
2ad087dcd9
description
2019-07-31 07:30:40 +00:00
Patrick Schleizer
404f597c0a
description
2019-07-31 07:29:42 +00:00
Patrick Schleizer
c921872016
description
2019-07-31 07:27:13 +00:00
Patrick Schleizer
39e1b1c5f0
update file path
2019-07-31 07:26:25 +00:00
Patrick Schleizer
031a1c8751
bumped changelog version
2019-07-22 01:16:18 +00:00
Patrick Schleizer
8c538ba318
bumped changelog version
2019-07-17 21:38:26 +00:00
Patrick Schleizer
940054d53f
bumped changelog version
2019-07-17 21:08:23 +00:00
Patrick Schleizer
c0a4a10d6b
description
2019-07-17 21:05:11 +00:00
Patrick Schleizer
7352b2ac31
description
2019-07-17 21:03:54 +00:00
Patrick Schleizer
4bf2360b95
description
2019-07-17 21:02:27 +00:00
Patrick Schleizer
9f2e300e72
description
2019-07-17 20:48:33 +00:00
Patrick Schleizer
d044780c04
description
2019-07-17 20:42:14 +00:00
Patrick Schleizer
75e5714d18
description
2019-07-17 20:40:01 +00:00
Patrick Schleizer
8c2f983578
description
2019-07-17 20:39:42 +00:00
Patrick Schleizer
50036b2934
bumped changelog version
2019-07-17 19:13:57 +00:00
Patrick Schleizer
1b772c6a9a
bumped changelog version
2019-07-16 19:45:52 +00:00
Patrick Schleizer
2499ae0890
description
2019-07-16 07:28:50 -04:00
Patrick Schleizer
d0124b24d1
description
2019-07-16 07:27:56 -04:00
Patrick Schleizer
4b604bbb24
bumped changelog version
2019-07-15 13:26:47 +00:00
Patrick Schleizer
5c741d2149
shuffle
2019-07-15 13:02:30 +00:00
Patrick Schleizer
d247b7534b
sort description by categories
2019-07-15 13:01:46 +00:00
Patrick Schleizer
168ea5a660
shuffle
2019-07-15 08:48:17 -04:00
Patrick Schleizer
1731196c9f
bumped changelog version
2019-07-13 18:51:32 +00:00
Patrick Schleizer
7afddb028f
bumped changelog version
2019-07-13 16:30:39 +00:00
Patrick Schleizer
ea90f95f1c
cleanup
2019-07-13 16:26:40 +00:00
Patrick Schleizer
ea8b22ee78
shuffle
2019-07-13 16:26:14 +00:00
Patrick Schleizer
ca7e0e0161
description
2019-07-13 16:25:08 +00:00
Patrick Schleizer
ffb5a9c482
formatting
2019-07-13 16:23:39 +00:00
Patrick Schleizer
41675ddcff
removed: The amount of hashing rounds used by shadow is bumped to 65536.
...
This increases the security of hashed passwords.
Since we do not do that currently.
https://forums.whonix.org/t/restrict-root-access/7658/37
2019-07-13 16:21:34 +00:00
Patrick Schleizer
3f031a297d
Removes read, write and execute access for others for all users who have home
...
folders under folder /home by running for example "chmod o-rwx /home/user"
during package installation or upgrade. This will be done only once per folder
in folder /home so users who wish to relax file permissions are free to do so.
This is to protect previously created files in user home folder which were
previously created with lax file permissions prior installation of this
package.
2019-07-13 16:20:14 +00:00
Patrick Schleizer
4740e8b335
cleanup
2019-07-13 16:13:55 +00:00
Patrick Schleizer
834fcc4671
bumped changelog version
2019-07-13 15:17:16 +00:00
Patrick Schleizer
e2b6268702
bumped changelog version
2019-07-13 14:58:47 +00:00
Patrick Schleizer
1d8a0dbec7
remove no longer shipped files in etc/pam.d/*
2019-07-13 14:57:51 +00:00
Patrick Schleizer
8e5d45352e
bumped changelog version
2019-07-13 14:55:31 +00:00
Patrick Schleizer
4079632d1a
remove modifying to /etc/pam.d directly (unrelased)
...
config-package-dev displace /etc/securetty
remove trailing spaces
https://forums.whonix.org/t/restrict-root-access/7658/31
2019-07-13 11:41:37 +00:00
Patrick Schleizer
cdb7c6f7eb
bumped changelog version
2019-07-11 18:28:04 +00:00
Patrick Schleizer
aee6b34635
fix lintian warning
2019-07-11 18:26:17 +00:00
madaidan
1aee08fa5e
Update control
2019-07-11 15:30:09 +00:00
madaidan
853c2eb377
Update control
2019-07-11 15:26:14 +00:00
Patrick Schleizer
f5356cee2c
bumped changelog version
2019-07-11 07:16:38 +00:00
Patrick Schleizer
0057c0dd8c
fix lintian warning
2019-07-11 07:07:01 +00:00
madaidan
1e4d349516
Update control
2019-07-10 14:28:39 +00:00
madaidan
a8b44c75f9
Update control
2019-07-09 21:57:07 +00:00
Patrick Schleizer
0f15303eb4
Merge branch 'master' into patch-16
2019-07-09 10:54:24 +00:00
madaidan
24b326d906
Update control
2019-07-08 23:24:41 +00:00
madaidan
45f8102d56
Update control
2019-07-08 23:04:47 +00:00
Patrick Schleizer
50c00fcfa1
bumped changelog version
2019-07-08 00:23:52 +00:00
Patrick Schleizer
223b691833
add 'Depends: libpam-cgfs'
...
https://forums.whonix.org/t/change-default-umask/7416/30?u=patrick
2019-07-07 23:39:58 +00:00
Patrick Schleizer
d31a16f264
bumped changelog version
2019-07-07 23:00:27 +00:00
Patrick Schleizer
673aab6bc2
shut up pam-auth-update
2019-07-07 22:18:47 +00:00
Patrick Schleizer
67ff83262b
move to pam-auth-update --force
...
--package hangs in Qubes updater since it starts whiptail for interactive dpkg configuration dialog.
2019-07-07 21:31:56 +00:00
Patrick Schleizer
8399a11367
bumped changelog version
2019-07-07 21:11:08 +00:00
Patrick Schleizer
d4c79cce69
add "Depends: libpam-runtime" so pam-auth-update is available
...
for Debian maintainer script
2019-07-07 21:09:26 +00:00
Patrick Schleizer
f68b96241c
comment
2019-07-07 21:08:28 +00:00
Patrick Schleizer
91fb21aafb
Due to error:
...
Jul 07 20:35:39 host sudo[16090]: PAM unable to dlopen(pam_cgfs.so): /lib/security/pam_cgfs.so: cannot open shared object file: No such file or directory
Jul 07 20:35:39 host sudo[16090]: PAM adding faulty module: pam_cgfs.so
run:
pam-auth-update --package
from Debian maintainer scripts
2019-07-07 16:51:40 -04:00
Patrick Schleizer
8f4a5f33b9
bumped changelog version
2019-07-07 09:39:12 +00:00
Patrick Schleizer
93e81b4330
bumped changelog version
2019-07-06 13:56:28 +00:00
Patrick Schleizer
3cd1a5ec09
fix lintian warning
2019-07-06 13:56:00 +00:00
Patrick Schleizer
b73cdfd7cc
bumped changelog version
2019-07-06 13:53:10 +00:00
madaidan
8888147e1e
Update control
2019-07-04 14:26:31 +00:00
Patrick Schleizer
6df7b3c295
bumped changelog version
2019-07-01 15:23:49 +00:00
Patrick Schleizer
81b38529d9
add copyright for files in etc/pam.d/*
2019-07-01 13:58:20 +00:00
Patrick Schleizer
552b6edbed
fix machine readable copyright format
2019-07-01 13:51:00 +00:00
Patrick Schleizer
a05264934b
add copyright for etc/login.defs.security-misc
2019-07-01 13:46:01 +00:00
Patrick Schleizer
48e511347c
fix lintian warning
2019-07-01 13:37:55 +00:00
Patrick Schleizer
93c0821054
config-package-dev displace files for change umask
...
https://forums.whonix.org/t/change-default-umask/7416
2019-07-01 13:35:45 +00:00
madaidan
cfaafe400c
Update control
2019-06-30 13:16:12 +00:00
Patrick Schleizer
f26ad14d4c
bumped changelog version
2019-06-30 07:21:58 -04:00
Patrick Schleizer
f3a4800987
bumped changelog version
2019-06-30 08:23:51 +00:00
Patrick Schleizer
85f61758c5
fix package description
2019-06-30 04:11:38 -04:00
Patrick Schleizer
67de5247c8
Merge branch 'master' into patch-13
2019-06-30 08:10:04 +00:00
madaidan
dbfb9e1cdf
Update control
2019-06-30 00:21:46 +00:00
madaidan
024a698249
Update control
2019-06-30 00:20:38 +00:00
madaidan
22267c895b
Update control
2019-06-29 22:30:41 +00:00
Patrick Schleizer
24b19c5976
bumped changelog version
2019-06-29 10:35:13 +00:00
Patrick Schleizer
befa03fea8
fix lintian warning
2019-06-29 10:34:48 +00:00
madaidan
9e9c854d27
Update control
2019-06-28 11:34:35 +00:00
madaidan
b26d861dff
Update control
2019-06-28 11:33:48 +00:00
Patrick Schleizer
ecf5d80fdf
bumped changelog version
2019-06-28 07:20:53 +00:00
Patrick Schleizer
fe69dc6173
bumped changelog version
2019-06-28 07:09:35 +00:00
Patrick Schleizer
0a0be1ad28
bumped changelog version
2019-06-23 19:57:42 +00:00
Patrick Schleizer
4e32438d75
debian/control syntax fix
2019-06-23 19:47:05 +00:00
Patrick Schleizer
90d676ec18
Merge pull request #12 from madaidan/patch-8
...
Update control
2019-06-23 19:45:31 +00:00
madaidan
1a07d90ed2
Update control
2019-06-23 19:26:03 +00:00
Patrick Schleizer
cd7346699c
bumped changelog version
2019-06-23 12:22:13 +00:00
Patrick Schleizer
d404624bac
bumped changelog version
2019-06-23 08:38:01 +00:00
Patrick Schleizer
5269cfeef9
bumped changelog version
2019-06-21 05:40:04 +00:00
Patrick Schleizer
ca1aa1e577
bumped changelog version
2019-06-10 15:42:58 +00:00
Patrick Schleizer
8b5e84d76a
cleanup, delete debian/security-misc.maintscript to fix lintian warning
2019-06-09 10:24:53 +00:00
Patrick Schleizer
49873e8e02
solve package file conflict
...
https://github.com/QubesOS/qubes-issues/issues/1885#issuecomment-500200375
2019-06-09 10:06:58 +00:00
Patrick Schleizer
d5127e7166
bumped changelog version
2019-06-08 11:32:12 +00:00
Patrick Schleizer
9fe5872810
fix debian/watch lintian warning debian-watch-contains-dh_make-template
2019-06-08 00:05:35 -04:00
Patrick Schleizer
e7edbe5fb4
bumped changelog version
2019-05-24 20:48:59 +00:00
Patrick Schleizer
afb5f5f965
bumped changelog version
2019-05-23 22:38:13 +00:00
Patrick Schleizer
65d7eb81a6
bumped changelog version
2019-05-16 20:25:46 +00:00
Patrick Schleizer
71bf63511b
bumped changelog version
2019-05-12 11:08:32 +00:00
Patrick Schleizer
26fe4305a1
bumped changelog version
2019-05-12 10:48:27 +00:00
Patrick Schleizer
06b86229a4
update path to pre.bsh
2019-05-12 02:58:45 -04:00
Patrick Schleizer
137bc073c5
port to /etc/xdg/xfce4/xfconf/xfce-perchannel-xml
...
https://forums.whonix.org/t/whonix-xfce-development/6213/84?u=patrick
2019-05-08 21:38:25 -04:00
Patrick Schleizer
c80b7465bf
bumped changelog version
2019-05-06 09:58:44 +00:00
Patrick Schleizer
74cdecfd6b
bumped changelog version
2019-05-03 11:34:25 +00:00
Patrick Schleizer
db9e60c894
bumped changelog version
2019-04-06 12:13:43 +00:00
Patrick Schleizer
a985581c68
port to debian buster
2019-04-04 05:51:06 -04:00
Patrick Schleizer
2913acda63
bumped changelog version
2019-03-29 10:02:51 +00:00
Patrick Schleizer
2ea9957e4c
https://www.whonix.org/wiki/Dev/Licensing
2019-03-29 09:03:18 +00:00
Patrick Schleizer
c5768683f4
bumped changelog version
2019-03-12 11:36:25 +00:00
Patrick Schleizer
811852656e
add improved legal protections clauses
...
The license for software created by Whonix is the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version with additional terms applicable per GNU GPL version 3 section 7.
The additional terms are based on the Doom 3 license which is Debian refers to as `GPL-3+-with-id-software-additional-terms`, which is Debian DFSG [1] (The Debian Free Software Guidelines) approved and which is therefore suitable for Debian `main`. Whonix made applied minimal changes to it:
* Rewrite `The Doom 3 BFG Edition GPL Source Code` to the more common `this program` which is used throughout the GPL.
* Added a "trump clause" [2], in other words, any conflicts or disputes between the additional terms and the GPLv3 shall be resolved in favor of the GPLv3 by adding `Notwithstanding any other provision of this License` (as mentioned in GPL FAQ [3]) at the beginning of the additional terms.
[1] https://www.debian.org/social_contract#guidelines
[2] https://www.fsf.org/news/canonical-updated-licensing-terms
[3] https://www.gnu.org/licenses/gpl-faq.html#v3Notwithstanding
For more considerations, see also:
https://www.whonix.org/wiki/Dev/Licensing
2019-03-01 14:32:41 +00:00
Patrick Schleizer
2298d0f6b0
bumped changelog version
2018-11-28 06:33:14 +00:00
Patrick Schleizer
2bd6dabc7c
bumped changelog version
2018-11-08 09:55:41 +00:00
Patrick Schleizer
f9e18772d7
bumped changelog version
2018-11-01 07:42:29 +00:00
Patrick Schleizer
4ecd32ef99
description
2018-10-31 02:26:13 -04:00
Patrick Schleizer
256e4bac52
bumped changelog version
2018-09-14 13:20:11 +00:00
Patrick Schleizer
73e5319711
'Depends: libglib2.0-bin' - contains glib-compile-schemas (required by postinst)
2018-09-14 10:46:00 +00:00
Patrick Schleizer
64b5e55d8c
bumped changelog version
2018-08-27 16:49:44 +00:00
Patrick Schleizer
c296cba838
bumped changelog version
2018-02-01 15:18:55 +00:00
Patrick Schleizer
5b3fc2f6b9
update copyright
2018-01-29 15:22:05 +00:00
Patrick Schleizer
c3b6a44e97
update copyright
2018-01-29 15:15:17 +00:00
Patrick Schleizer
ff28f5932c
update copyright
2018-01-29 15:09:42 +00:00
Patrick Schleizer
674d2d8abf
bumped changelog version
2017-12-21 20:35:29 +00:00
Patrick Schleizer
7b2d3c9e2f
bumped changelog version
2017-07-26 14:37:34 +00:00
Patrick Schleizer
61bd4d05b7
bumped changelog version
2017-03-06 16:16:32 +00:00
Patrick Schleizer
99bb1e877e
"$@"
2017-03-06 15:00:33 +00:00
Patrick Schleizer
2130b4c654
use python rather than unbuffer
...
because unbuffer eats exit code when process is killed
2017-02-27 23:16:32 +00:00
Patrick Schleizer
1fb48e3548
bumped changelog version
2017-02-27 02:04:00 +00:00
Patrick Schleizer
966e90ebe2
add missing dependency tcl8.6 (which is required by unbuffer [package expect])
2017-02-27 00:17:36 +00:00
Patrick Schleizer
5653b7732a
fix, show progress during apt-get-wrapper
...
fix, propagate signals to apt-get child process
2017-02-26 23:57:17 +00:00
Patrick Schleizer
0228e87d47
minor
2017-02-19 22:37:10 +00:00
Patrick Schleizer
dfe8a569b6
override glib-compile-schemas with || true in postinst
...
https://phabricator.whonix.org/T500
2017-02-19 22:32:04 +00:00
Patrick Schleizer
5ba2a5b6ff
disable previews in nautilus by default for better security
...
copied solution by @unman
https://github.com/QubesOS/qubes-issues/issues/1108
https://github.com/QubesOS/qubes-core-agent-linux/pull/39
https://phabricator.whonix.org/T500
2017-02-19 22:25:28 +00:00
Patrick Schleizer
91adab0d1b
bumped changelog version
2017-02-17 14:08:56 +00:00
Patrick Schleizer
0bb059093f
remove faketime from Build-Depends:
...
since no longer used for reproducible builds
2017-02-10 15:47:52 +00:00
Patrick Schleizer
be8084ad1c
remove debian/gain-root-command workaround
2017-02-10 15:35:25 +00:00
Patrick Schleizer
1e66e03da1
bumped changelog version
2017-01-15 15:35:31 +00:00
Patrick Schleizer
d80d576953
fix lintian warning
2017-01-15 13:11:38 +00:00
Patrick Schleizer
59633fbc60
packaging, bumped Standards-Version from 3.9.6 to 3.9.8 for jessie support
2017-01-15 08:35:40 +01:00
Patrick Schleizer
814d6c5f74
bumped changelog version
2017-01-12 02:56:55 +00:00
Patrick Schleizer
7b3ef3a00f
bumped changelog version
2016-12-10 02:30:50 +00:00
Patrick Schleizer
0d66fc60b9
bumped changelog version
2016-04-25 23:27:58 +00:00
Patrick Schleizer
492ce12890
bumped changelog version
2016-04-07 22:54:45 +00:00
Patrick Schleizer
9d7ad9e97e
fixed package description and package description linitan warnings
2016-03-31 15:53:40 +00:00
Patrick Schleizer
d5e61eb4b1
added 'Replaces: tcp-timestamps-disable'
...
https://phabricator.whonix.org/T486
2016-03-31 15:36:59 +00:00
HulaHoopWhonix
989f2f54e2
Update control
2016-03-31 03:18:05 +00:00
HulaHoopWhonix
c7d88571e4
Update control
2016-03-31 03:16:10 +00:00
Patrick Schleizer
ba7b06ce30
bumped changelog version
2015-12-15 04:16:14 +00:00
Patrick Schleizer
c47f9697b4
deactivate preview in Nautilus
2015-12-15 04:14:00 +00:00
Patrick Schleizer
4b7d8a4bd8
bumped changelog version
2015-12-15 02:00:39 +00:00
Patrick Schleizer
d3ccf0eeaf
initial commit
2015-12-15 02:00:24 +00:00