View Issue Details
19671 [ClearOS] build-images - Install images minor always 2018-03-31 08:02 2019-02-23 22:20
user2  
dloper  
normal  
assigned 7.4.0  
open  
none    
none  
  7.6.0 Updates  
Koji build system overrides Vendor
Some RPMs have the "Vendor" tag overwritten with ClearCenter instead of ClearFoundation. Please fix ASAP.
There are no notes attached to this issue.





View Issue Details
627 [ClearCenter] app-dynamic-dns - Dynamic DNS tweak N/A 2012-05-29 08:17 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add preferred WAN for dynamic DNS
In version 5.x the multi-WAN page had a "preferred dynamic DNS" option. Re-add this feature, but do so in the Dynamic DNS app.
There are no notes attached to this issue.





View Issue Details
377 [ClearCenter] app-content-filter - Content Filter feature N/A 2011-10-24 13:46 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  6.3.0  
Add auto-tuning for large number of users
DansGuardian needs to be tuned for large installations. The Squid web proxy already has such a mechanism (based on memory size), and DansGuardian should do the same on install.
Notes
(0000381)
user2   
2011-10-24 13:47   
Recommended values for a large number of users.

maxchildren = 999
minchildren = 96
minsparechildren = 96
preforkchildren = 16
maxsparechildren = 240
maxagechildren = 2000





View Issue Details
800 [ClearCenter] app-google-apps - Google Apps feature N/A 2012-10-23 15:03 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add import tool
There should be a way to import users and groups from an existing Google Apps system.
There are no notes attached to this issue.





View Issue Details
799 [ClearCenter] app-verified-updates - Verified Updates minor have not tried 2012-10-23 08:55 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add GUI to verified updates system
The standard "Software Updates" page can be enhanced with the software install progress widget found in Marketplace. For licensing/open source reasons, this widget should not be mixed in with the ClearFoundation code base. However, a new "Verified Updates" app for the Professional Edition has no such open source restriction.
There are no notes attached to this issue.





View Issue Details
762 [ClearCenter] app-active-directory - Active Directory Connector minor have not tried 2012-09-26 07:50 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
If enumeration is disabled, the results for getent are invalid
Reference: http://wiki.samba.org/index.php/Samba_%26_Active_Directory [^]

Some bits of the API use getent to retrieve information. These API calls may need to use wbinfo or some other tool instead.
There are no notes attached to this issue.





View Issue Details
750 [ClearCenter] app-zarafa-small-business - Zarafa Small Business major have not tried 2012-09-17 13:59 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Zarafa license server needs a restart after making changes
See subject.
There are no notes attached to this issue.





View Issue Details
742 [ClearCenter] app-google-apps - Google Apps minor always 2012-09-06 19:59 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Google apps usernames are case sensitive (kind of) but only small case allowed ClearOS
Google apps usernames are case sensitive in some situations (e.g. login) but case insensitive for others (e.g. e-mail address). This poses a problem with synchronization. If an end user has a Google account with capitals, e.g. DavidSmith, the synchronization with ClearOS account davidsmith will not match.
There are no notes attached to this issue.





View Issue Details
708 [ClearCenter] app-google-apps - Google Apps minor always 2012-08-15 08:46 2018-12-15 09:00
bchambers  
tracker  
normal  
assigned 6.3.0  
open  
none    
none  
   
Adding an 'external' email to Google Groups causes sync failure notification
In a Google defined group, a member could be a user of the domain used by Google Apps, but could also be an external email. Adding an external email to a group causes a notification event when the user (parsed string before the @ in a email) is not a user on ClearOS.

The sync should check the domain, and only sync when the domain matches the Google Apps domain.
Sample message sent:

Error Message
An update error occurred.: The server encountered the following errors processing the request:
Error 1301: EntityDoesNotExist
    Invalid Input: "xxx@example.com"
Notes
(0000552)
user2   
2012-08-20 07:10   
That's messy since:

1) it seems like a bad security practice
2) the external e-mail would have to be in LDAP, or the group would have to be managed in both ClearOS and Google Apps

That first one is a bit of a showstopper IMHO. If I share a document for the "sales" group, I would want to know that only internal members have access. "Best Practice" might be to create new groups for all groups with external members, e.g.

- sales:
  A normal group with only usernames

- sales-external
 A group that includes the "sales" group, and a list of external members.

Regardless, something needs to be done here.





View Issue Details
20381 [ClearCenter] app-clearglass - ClearGLASS Engine minor have not tried 2018-06-19 12:14 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Show warning when admin URL is indeterminate
Consider the admin URL https://www.example.com [^] that is hosted on an internal server. There's no guarantee that this hostname will resolve properly inside a LAN. To avoid sending the admin to the wrong machine, the ClearGLASS app will show the webconfig hostname or IP *if* the web client is coming from the private network.

A warning should be shown in this scenario.
There are no notes attached to this issue.





View Issue Details
19281 [ClearCenter] app-master-slave - Master/Slave minor have not tried 2018-03-06 12:36 2018-12-15 09:00
user2  
tracker  
normal  
assigned 7.4.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Make sure certificates are initialized
The Master/Slave system requires initialization of the Certificate Manager. Add the cert check widget.
There are no notes attached to this issue.





View Issue Details
18421 [ClearCenter] app-dynamic-dns - Dynamic DNS tweak have not tried 2017-12-21 14:11 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  7.6.0 Updates  
Properly encode the osname on SDN API requests
The osname/osversion is not properly encoded on SDN API requests. Clean this up at some point.
There are no notes attached to this issue.





View Issue Details
16451 [ClearCenter] app-network-map - Network Map tweak N/A 2017-08-12 18:27 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  7.6.0 Updates  
Update local MAC address database
Also update in DHCP Server.

Note: Before closing, always clone this bug for the next release.
There are no notes attached to this issue.





View Issue Details
16051 [ClearCenter] app-mail-archive - Mail Archive tweak have not tried 2017-08-05 17:14 2018-12-15 09:00
user2  
tracker  
normal  
assigned 7.3.0 Updates  
open  
none    
none  
   
Rebuild package to sync up new repos - Mail Archive
The production version and new repo version are different. Sync things up.
There are no notes attached to this issue.





View Issue Details
16041 [ClearCenter] app-intrusion-protection-updates - Intrusion Protection Updates tweak have not tried 2017-08-05 17:11 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  8.0.0 Beta 1  
Rebuild package to sync up new repos - Intrusion Protection Updates
The production version and new repo version are different. Sync things up.
There are no notes attached to this issue.





View Issue Details
16031 [ClearCenter] app-dynamic-dns - Dynamic DNS tweak have not tried 2017-08-05 17:03 2018-12-15 09:00
user2  
tracker  
normal  
assigned 7.3.0 Updates  
open  
none    
none  
   
Rebuild package to sync up new repos - Dynamic DNS
The production version and new repo version are different. Sync things up.
There are no notes attached to this issue.





View Issue Details
16021 [ClearCenter] app-antispam-updates - Antispam Updates tweak have not tried 2017-08-05 16:59 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  8.0.0 Beta 1  
Rebuild package to sync up new repos - Antispam Updates
The production version and new repo version are different. Sync things up.
There are no notes attached to this issue.





View Issue Details
16011 [ClearCenter] app-antimalware-updates - Antimalware Updates tweak have not tried 2017-08-05 16:54 2018-12-15 09:00
user2  
tracker  
normal  
assigned 8.0.0 Beta 1  
open  
none    
none  
  8.0.0 Beta 1  
Rebuild package to sync up new repos - Antimalware Updates
The production version and new repo version are different. Sync things up.
There are no notes attached to this issue.





View Issue Details
15801 [ClearCenter] app-content-filter-updates - Content Filter Updates tweak have not tried 2017-07-18 11:46 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  8.0.0 Beta 1  
Rebuild package to sync up new repos
The production version of this package (2.0.16) does not exist in the buildsys. However a test version (2.1.0) does exist in the testing area of the buildsys.

Sync things up.
Notes
(0005991)
user2   
2017-07-21 16:15   
Translations were added since the last production build. Quick review.





View Issue Details
15581 [ClearCenter] app-kaspersky - Kasperksy Engine minor always 2017-07-07 06:42 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  7.6.0 Updates  
Kaspersky Antimalware Dashboards do not display correctly and
Kaspersky Antimalware Gateway Dashboard content expands laterally as the number of days reported increases. The date labels on the Y axis begin to overlap once the report window is fully populated and days are added from that point onward. Eventually these labels are totally unreadable. Kaspersky Antimalware Email Dashboard content expands vertically as the number of days reported increases. The date labels on the X axis begin to overlap once the report window is fully populated and days are added from that point onward. Eventually these labels are totally unreadable. In addition to the date label overlap aspect, part of the problem also appears to be that both the Kaspersky Dashboard report windows do not expand in the required direction to accommodate the increasing number of days they report. I am not sure exactly what the maximum days displayed limit might be at this point. This results in an ongoing compression of the displayed content to the point it becomes increasing unreadable. Sample images are attached.

Suggestion: Restrict to a suitable amount, the number of days that can be displayed in the Kaspersky dashboard windows and consider making the Kaspersky dashboard windows dynamically expandable to make space for a larger data set. It may also be worth considering making the dates record on the X axis on both dashboards for consistency, plus this better allows for any potential & practical dashboard display window dynamic expansion down the page rather than across it.
2017-07-07 - Premium Mail Antimalware by Kaspersky.jpg (47,281) 2017-07-07 06:43
https://tracker.clearos.com/file_download.php?file_id=361&type=bug
jpg

2017-07-07 - Premium Gateway Antimalware by Kaspersky.jpg (36,432) 2017-07-07 06:43
https://tracker.clearos.com/file_download.php?file_id=371&type=bug
jpg
There are no notes attached to this issue.





View Issue Details
1530 [ClearCenter] yum-marketplace-plugin minor always 2014-01-22 16:43 2018-12-15 09:00
bchambers  
tracker  
normal  
assigned 6.5.0  
open  
none    
none  
   
wc-yum clutters logs with errors if an update is not found
wc-yum -i is dual-use...install and upgrade. If upgrading a package (eg. ClearCenter software updates on cron job), the log file becomes cluttered with:

Jan 19 05:41:15 chambers engine: exception: error: /usr/clearos/apps/base/libraries/Shell.php (207): {"progress": 0, "code": 0, "overall": 0, "details": "Fetching repos
itories.", "errmsg": null}
Jan 19 05:41:15 chambers engine: exception: debug backtrace: /usr/clearos/apps/clearcenter/libraries/Marketplace_Yum.php (131): execute
Jan 19 05:41:15 chambers engine: exception: debug backtrace: /usr/clearos/apps/clearcenter/libraries/Application_Web_Service.php (152): install
Jan 19 05:41:15 chambers engine: exception: debug backtrace: /usr/sbin/clearcenter-update (79): install_update
Jan 19 06:34:03 chambers app-intrusion-protection-updates: Service is up-to-date.

if no update is found. Should exit (code 0) gracefully so exception is not thrown.
End of wcYumHelper suggested fix:

self.repos.setProgressBar(wcDownloadCallback(100))
self.buildTransaction()

if len(self.tsInfo) > 0:
    self.processTransaction(None, None, wcProgressCallback(len(self.tsInfo)))
    status['details'] = 'Installation complete.'
else:
    status['progress'] = 100
    status['details'] = 'No packages to update or install.'
status['overall'] = 100
print json.dumps(status)
Notes
(0005591)
slords   
2017-05-08 15:01   
I don't see anything that points to yum-marketplace-plugin in this report. The fact that Marketplace_Yum.php is referenced might be why this is incorrectly assigned. If there is in fact an issue with yum-marketplace-plugin please provide evidence collected showing this fact.
(0005601)
bchambers   
2017-05-08 19:03   
The referenced python code is in /usr/sbin/wc-yum, not the plugin. Darryl's probably the right guy for this.





View Issue Details
1490 [ClearCenter] app-central-management feature N/A 2013-12-30 08:18 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add a flag for resetting the central management system
See subject.
There are no notes attached to this issue.





View Issue Details
1265 [ClearCenter] app-central-management feature N/A 2013-08-01 12:13 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add a command line and GUI tool for slave systems
Two commands can be handy to deal with support situations:

1) A command to re-join the master node
2) A command to do a full LDAP synchronize (if the deltas on the master are lost or old, a full sync does the trick)
There are no notes attached to this issue.





View Issue Details
1223 [ClearCenter] app-performance-tuning - Performance Tuning feature N/A 2013-07-11 08:44 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
   
Add MultiWAN tunables
There are a few tunables for "connection down" detection in MultiWAN. In some scenarios (e.g. crappy connections in remote locations), it is wise to make the the "connection down" detection more aggressive.
There are no notes attached to this issue.





View Issue Details
937 [ClearCenter] app-google-apps - Google Apps feature sometimes 2013-01-15 14:54 2018-12-15 09:00
dloper  
tracker  
low  
assigned 6.3.0  
open  
none    
none  
   
Adding group to distribution group defaults to internal ONLY.
When adding a group, the group appears as internal only. This means that if you want to set up an email address, you will currently need to enter the google apps admin interface on google and change it to be publicly accessible.

The feature request is to change the dropdown for the distribution list to contain the following pulldown items:

Disabled
Enabled - Owners only
Enabled - Members only
Enabled - Domain only
Enabled - Internet/Globally
There are no notes attached to this issue.





View Issue Details
21231 [ClearCenter] app-master-slave - Master/Slave minor have not tried 2018-08-16 19:13 2018-12-15 09:00
user2  
tracker  
normal  
assigned  
open  
none    
none  
  7.6.0 Updates  
Handle master base DN change
The "syncrepl" slapd.conf configuration on a slave looks like:

syncrepl
    ...
    binddn="cn=syncuser,ou=Internal,dc=system,dc=lan"
    credentials=the_secret

If the base DN on the master system is changed, the slave systems will no longer be able to authenticate. Handle this use case.
There are no notes attached to this issue.





View Issue Details
22551 [ClearCenter] clearglass-community minor always 2018-12-12 07:02 2018-12-12 09:18
NickH  
 
normal  
new 7.5.0 Updates  
open  
none    
none  
   
Hook to renew Let's Encrypt certificates not working
It looks like clearglass-community initialises itself taking a snapshot of the current Let's Encrypt certificate and key and places them in /var/lib/clearglass/config/ssl/certs. Unfortunately, when Let's Encrypt renews its certificates the new ones are not picked up by clearglass-community and the certificates eventually expire.

I did try configuring /var/lib/clearglass/config/ssl/nginx_certs.conf with paths to the Let's Ecrypt live certificates, but nginx cannot read them (chrooted environment or not able to follow symlinks possibly).

I've found a hook: /var/clearos/certificate_manager/state/clearglass.conf but it does not look like it is working.
There are no notes attached to this issue.





View Issue Details
6461 [ClearCenter] yum-marketplace-plugin minor always 2015-11-25 09:10 2018-11-16 08:27
bchambers  
dsokoloski  
normal  
resolved 7.1.0  
fixed  
none    
none 8.0.0 Beta 1  
  8.0.0 Beta 1  
Error message (utime) from yum plugin on first run
Loaded plugins: clearcenter-marketplace, fastestmirror
ClearCenter Marketplace: fetching repositories...
ClearCenter Marketplace: utime() arg 2 must be a tuple (atime, mtime)
Notes
(0005581)
slords   
2017-05-08 14:59   
This code was originally added by Darryl. It can be fixed by replacing the following line:

os.utime(filename, time.time())

with this:

os.utime(filename, (time.time(), time.time()))
(0008661)
user2   
2018-11-16 08:27   
Fixed in master, but branches are messed up. Pushed target release to ClearOS 8.





View Issue Details
22441 [ClearCenter] yum-marketplace-plugin minor always 2018-11-15 13:14 2018-11-15 13:53
dloper  
slords  
normal  
assigned 7.5.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Review Cleanup of Parsing commit and commit to clear7 if appropriate or branch to 8
Review history here: https://gitlab.com/clearos/clearfoundation/yum-marketplace-plugin/network/master [^]

This commit did not have a rebase into clear7 and is not a major drift. Resolve previous commits and rebase or branch to 8 if features are not meant for 7.
There are no notes attached to this issue.





View Issue Details
22371 [ClearCenter] app-clearglass - ClearGLASS Engine minor always 2018-11-13 04:29 2018-11-13 08:39
NickH  
 
normal  
confirmed  
open  
none    
none  
   
Impossible to stop ClearGLASS from the webconfig
If you navigate to Webconfig > System > Management > ClearGLASS Community and click on the stop button, ClearGLASS stops but then restarts itself a few moments later. This is **with** Dave's updated clearglass.system unit file from clearos-updates testing

I have a feeling the stop button not stopping the new clearglass.service but doing something else. The clearglass.service is then seeing clearglass down and restarting it. If this is so, the Start/Stop button needs to be changed to just stop the clearglass.service.

A "systemctl stop clearglass.service" works fine from the command line.
There are no notes attached to this issue.





View Issue Details
14131 [ClearCenter] other minor always 2017-03-30 10:54 2018-11-10 10:26
dloper  
dloper  
normal  
assigned 7.3.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Documentation needs links or messaging about all the different open source modules used
On most projects, the system service name and the backing open source software should be referenced.
Notes
(0008591)
marclaporte   
2018-11-10 10:26   
Dear Dave,

I agree. We should promote how we are smartly using well-known mature code.

Some info is progressively being added to the code:
https://gitlab.com/clearos/clearfoundation/app-mariadb/commit/e91d2a218486e5c568d5d915dd8677f847678f27 [^]

What would be nice is a shared DB of all apps. As an experiment, I started this:
https://wikisuite.org/List-of-ClearOS-apps [^]

And to re-incorporate that in all relevant places...

In Tiki, we have scripts that extract data from code:
https://dev.tiki.org/Preferences-report [^]

Perhaps we want something like this for ClearOS? But where would the data be sent?

Thanks!





View Issue Details
21861 [ClearCenter] clearglass-business tweak have not tried 2018-10-18 12:25 2018-10-30 19:49
user2  
 
normal  
confirmed 7.5.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Add systemd unit file
See subject.
There are no notes attached to this issue.





View Issue Details
21771 [ClearCenter] eziod feature have not tried 2018-10-09 14:58 2018-10-30 19:49
dloper  
 
normal  
acknowledged 7.5.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Memory report show allocated memory and not the more useful consumption memory
The memory display shows how much ram is used but not how much is allocated to applications and services. Linux will consume nearly all memory in order to quickly allocate pages. This number is not really useful because it will ALWAYS use as much as possible and leave a little behind. The more useful state is the total allocated to applications and services as a percentage of the allocated memory. So a system showing 96% used should use that 96% marker as its new 100% baseline and then show the combined total consumed memory as a percentage of that marker.
There are no notes attached to this issue.





View Issue Details
21761 [ClearCenter] eziod tweak have not tried 2018-10-09 14:53 2018-10-30 19:49
user2  
 
normal  
acknowledged  
open  
none    
none  
  7.6.0 Updates  
Expand disk usage to other filesystem types
The following is set in eziod.conf:

-- Global file-system types to check
fs_type = { "ext2", "ext3", "ext4", "vfat" }

Should more filesystems be included in the file system size check?
There are no notes attached to this issue.





View Issue Details
21211 [ClearCenter] app-central-management tweak have not tried 2018-08-16 11:01 2018-10-30 19:49
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Save file sync key on initialization
Some apps, notably the Certificate Manager, need to have the files from the master sync-ed to the slave. This is done via clearsync's filesync plugin.

When an app requests a filesync, a remote API request is sent to the master to verify a shared password. There's no guarantee the master will be available which is less than ideal. It would be better if filesync key request was part of slave provisioning.
There are no notes attached to this issue.





View Issue Details
21101 [ClearCenter] kmod-network-bypass minor always 2018-08-14 12:18 2018-10-30 19:49
dloper  
dsokoloski  
low  
assigned 7.5.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Update to 7.5 - merge changes
Current kmod does not work with 7.5 updates.
There are no notes attached to this issue.





View Issue Details
21051 [ClearCenter] app-owncloud-business - ownCloud for Business feature N/A 2018-08-10 07:43 2018-10-30 19:49
bchambers  
bchambers  
normal  
assigned 7.5.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Support upgrade to OC 10.0.9
Support upgrade path.
There are no notes attached to this issue.





View Issue Details
17441 [ClearCenter] eziod feature always 2017-10-07 12:48 2018-10-30 19:49
dloper  
 
low  
acknowledged 7.4.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Temperature settings and readings for UI and LCD support
Add temperature readings for UI and for LCD support for ClearOS/ClearBOX
There are no notes attached to this issue.





View Issue Details
15931 [ClearCenter] eziod tweak always 2017-07-28 09:28 2018-10-30 19:49
dloper  
dloper  
low  
feedback 7.3.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Network Bypass not loaded automatically
Use eziod to install g3 network bypass in /etc/modules-load.d/bypass.conf

Contents:

caswell-bpgen3
Notes
(0006021)
dloper   
2017-07-28 09:37   
(edited on: 2017-07-28 09:39)
This file should be added to the package and removed when the package is removed.

Then modprobe caswell-bpgen3

(0006031)
user2   
2017-07-28 10:07   
This should be done in the "network-bypass-kmod" package ?? Or perhaps "app-bypass"?





View Issue Details
13581 [ClearCenter] yum-marketplace-plugin major have not tried 2017-03-08 10:20 2018-10-30 19:49
user2  
slords  
normal  
assigned 7.3.0 Updates  
open  
none    
none  
  7.6.0 Updates  
Add upstream proxy setting to yum plugin
It looks like the yum Marketplace plugin requires hooks for upstream proxy support.

# yum repolist
Loaded plugins: clearcenter-marketplace, fastestmirror
ClearCenter Marketplace: fetching repositories...
ClearCenter Marketplace: [SSL: UNKNOWN_PROTOCOL] unknown protocol (_ssl.c:579)
There are no notes attached to this issue.





View Issue Details
13311 [ClearCenter] eziod minor always 2017-02-27 14:48 2018-10-30 19:49
dloper  
dloper  
low  
confirmed 7.3.0 Updates  
open  
none    
none  
  7.6.0 Updates  
eziod requires lm_sensors
Add lm_sensors and lm_sensors-libs to the core of ClearOS repos so that eziod installs without needing to resolved dependecies from CentOS libraries.
Workaround is:

yum install --enablerepo=clearos-centos eziod
Notes
(0004921)
user2   
2017-02-28 08:20   
Is the eziod package moving to the ISO? If not, the lm_sensors can stay in the CentOS repos (enabled after system registration).
(0005361)
dloper   
2017-04-11 12:34   
Needs Shad's input.





View Issue Details
21881 [ClearCenter] app-clearglass - ClearGLASS Engine tweak have not tried 2018-10-18 12:31 2018-10-30 19:47
user2  
user2  
normal  
resolved 7.5.0 Updates  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Remove onboot event, change to systemd
With the move to systemd, the onboot event is no longer required. Keep it as a firewall workaround though.
There are no notes attached to this issue.





View Issue Details
21851 [ClearCenter] clearglass-community tweak have not tried 2018-10-18 12:24 2018-10-30 19:47
user2  
user2  
normal  
resolved 7.5.0 Updates  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Add systemd unit file
See subject.
There are no notes attached to this issue.





View Issue Details
21391 [ClearCenter] clearglass-community feature have not tried 2018-09-04 19:55 2018-10-30 19:47
user2  
user2  
normal  
resolved 7.5.0 Updates  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Update to 3.2.0
An upstream update is available.
There are no notes attached to this issue.





View Issue Details
20931 [ClearCenter] clearglass-business feature have not tried 2018-07-25 09:44 2018-10-30 19:47
user2  
user2  
normal  
resolved 7.5.0 Updates  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Update to 3.1.0
An upstream update is available.
There are no notes attached to this issue.





View Issue Details
20921 [ClearCenter] clearglass-community feature have not tried 2018-07-25 09:43 2018-10-30 19:47
user2  
user2  
normal  
resolved 7.5.0 Updates  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Update to 3.1.0
An upstream update is available.
There are no notes attached to this issue.





View Issue Details
20891 [ClearCenter] clearglass-business tweak have not tried 2018-07-25 08:33 2018-10-30 19:47
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Automate the upgrade process
The upgrade process for ClearGLASS is different than other packages -- it depends on pulling down containers from 3rd party repositories. We can't guarantee reliability and we can't make yum/rpm wait on a potentially long download process.

Add a basic upgrade/restart script via cron. This script should be made more robust in future versions.
There are no notes attached to this issue.





View Issue Details
20881 [ClearCenter] clearglass-community tweak have not tried 2018-07-25 08:33 2018-10-30 19:47
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.5.0 Updates  
  7.6.0 Updates  
Automate the upgrade process
The upgrade process for ClearGLASS is different than other packages -- it depends on pulling down containers from 3rd party repositories. We can't guarantee reliability and we can't make yum/rpm wait on a potentially long download process.

Add a basic upgrade/restart script via cron. This script should be made more robust in future versions.
There are no notes attached to this issue.





View Issue Details
17161 [ClearCenter] app-active-directory - Active Directory Connector minor have not tried 2017-09-20 09:43 2018-10-30 19:47
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Update local file permissions on initialization
The /var/samba directory should be updated when the AD initialization is complete.
There are no notes attached to this issue.





View Issue Details
14671 [ClearCenter] app-active-directory - Active Directory Connector tweak have not tried 2017-05-02 15:01 2018-10-30 19:47
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Add support for hidden groups
The underlying group system provides a mechanism to hide some groups. For example, the "domain computers" group is not intended for user-groups, so it should be hidden from the UI.
There are no notes attached to this issue.





View Issue Details
14281 [ClearCenter] app-active-directory - Active Directory Connector feature always 2017-04-10 07:49 2018-10-30 19:47
dloper  
user2  
normal  
resolved 7.3.0 Updates  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Test time on target server before domain join and abort with warning if the time drift exceeds 1 minute.
Time synchronicity is crucial to keeping AD connected as is DNS a test mechanism should be made to test both DNS and time before a domain join and a troubleshooting button to validate DNS and time should be included in the app to limit support tickets that arise when the customer's equipment drifts in DNS resolution or time.

The following test can be performed against the time server of the AD machine using CIFS:

net time -S server_name_or_IP

The result is automatically translated to the local time zone so it should match the 'date' command except for the timezone in the date command. For example, side by side results can be produced by the following:

net time -S 192.168.1.10 && date | cut -f 1,2,3,4,6 -d ' '

Notes
(0005341)
dloper   
2017-04-11 12:21   
abs () { [ $1 -lt 0 ] && echo $((-$1)) || echo $1; } && abs $(expr $(date -d "$(net time -S $(egrep "^password server" /etc/samba/smb.conf | awk -F" = " '{ print$2 }'))" "+%s") - $(date "+%s"))

if the result is greater then 60 then there is a problem.
(0005551)
user2   
2017-05-03 14:20   
There's no timezone information returned. That makes time comparisons dodgy at best. The check will still be done, but it will be non-fatal.





View Issue Details
14141 [ClearCenter] app-active-directory - Active Directory Connector minor always 2017-03-30 11:40 2018-10-30 19:47
dloper  
user2  
normal  
resolved 7.3.0 Updates  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Add AD DNS resolution for primary domain membership in DNSMasq on creation
The best practices for Active Directory connector should have the option for adding the split horizon DNS for the AD domain controller.

This should be maintained on the join of the domain as a preliminary step and a DNS check can be made to validate that the information is correct before committing the join.

The new field is optional but if specified will perform the following validation check:

New Fields: AD DNS Server 1, AD DNS Server 2

AD DNS Server 1 = dns1
AD DNS Server 2 = dns2
AD Realm = var1
Domain Controller = var2

Validation check:

var1 = tolower(var1)
var2 = tolower(var2)

dig @${dns1} srv _ldap._tcp.dc._msdcs.${var1}

This must yield matches for the the $var2 on the answer section line.

If it does not, the configuration is INVALID.

If the value is valid then the add of the DNS configuration should be made preceeding the domain join:

/etc/dnsmasq.conf:

server=/${var1}/${dns1}
server=/${var1}/${dns2}

DNSMasq should be reloaded before the join.

For more information, see these guides:

https://www.clearos.com/resources/documentation/clearos/content:en_us:kb_o_splitting_dns_cache_to_use_specific_dns_server_for_domains [^]

https://www.clearos.com/resources/documentation/clearos/content:en_us:kb_troubleshooting_the_ad_connector [^]

Notes
(0005351)
dloper   
2017-04-11 12:24   
(edited on: 2017-04-11 12:31)
dig @localhost srv _ldap._tcp.dc._msdcs.$(egrep "^realm" /etc/samba/smb.conf | awk -F" = " '{ print$2 }') | egrep "^_ldap\._tcp\.dc\._msdcs\.$(egrep "^realm" /etc/samba/smb.conf | awk -F" = " '{ print$2 }')\.\s[0-9]+\sIN\sSRV\s[0-9]+\s[0-9]+\s[0-9]+\s$(egrep "^password server" /etc/samba/smb.conf | awk -F" = " '{ print$2 }')\.$"

assumes the separator for realm and 'password server' in smb.conf is a space equal space

(0005441)
user2   
2017-04-25 20:11   
The changes have been committed to master.





View Issue Details
10871 [ClearCenter] app-active-directory - Active Directory Connector minor always 2016-10-07 12:12 2018-10-30 19:47
dloper  
user2  
low  
resolved 7.2.0 Updates  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Return wbinfo group information sorted.
In the branch development of the AD connector which is modified to return information from wbinfo instead of getent, results should return sorted for both group and user results even on lists of 1300 groups this doesn't cost much:
For example:

$shell->execute(self::COMMAND_WBINFO, '-g');

Becomes:

$shell->execute(self::COMMAND_WBINFO, '-g | sort');

And:

$shell->execute(self::COMMAND_WBINFO, '-u');

Becomes:

$shell->execute(self::COMMAND_WBINFO, '-u | sort');

There are no notes attached to this issue.





View Issue Details
9341 [ClearCenter] app-active-directory - Active Directory Connector tweak have not tried 2016-06-21 12:27 2018-10-30 19:47
user2  
user2  
normal  
resolved  
fixed  
none    
none 7.4.0 Updates  
  7.6.0 Updates  
Handle server max protocol
Max sure "server max protocol" is removed or set to a sane value on provisioning. See 0009251
There are no notes attached to this issue.





View Issue Details
21781 [ClearCenter] app-network-map - Network Map tweak have not tried 2018-10-09 20:20 2018-10-09 20:22
user2  
 
normal  
acknowledged  
open  
none    
none  
  8.0.0 Beta 1  
Remove deprecated dhcp/Dnsmasq class
The dhcp/Dnsmasq has been deprecated. Remove in ClearOS 8.
There are no notes attached to this issue.





View Issue Details
15731 [ClearCenter] app-antimalware-updates - Antimalware Updates feature have not tried 2017-07-17 09:21 2018-08-14 12:40
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Change signature update methodology - antimalware
Scope:

- Signature downloads.
- Do a version check before doing a download (not just a "flag check") - see 0021021
There are no notes attached to this issue.





View Issue Details
10591 [ClearCenter] app-software-updates - Software Updates feature always 2016-09-15 12:21 2018-08-13 15:20
dloper  
 
normal  
acknowledged 7.2.0 Updates  
open  
none    
none  
  8.0.0 Beta 1  
Add notification to updates
Notification to updates should be able to be turned on. The behavior for if updates is automatic is to send a digest on updates (not content filter/virus) applied to the box.

If updates are turned off, it should notify if updates are pending.

Notification should be able to be enabled or disabled.
There are no notes attached to this issue.





View Issue Details
20911 [ClearCenter] app-clearglass - ClearGLASS Engine minor have not tried 2018-07-25 08:47 2018-07-25 08:53
user2  
 
normal  
confirmed 8.0.0 Beta 1  
open  
none    
none  
   
Remove workaround for reboot
ClearGLASS does not behave on a reboot. An temporary fix was added in 0020901 - remove.
There are no notes attached to this issue.





View Issue Details
20611 [ClearCenter] app-clearglass - ClearGLASS Engine minor always 2018-07-09 09:40 2018-07-09 09:43
NickH  
 
normal  
confirmed 7.4.0 Updates  
open  
none    
none  
   
ClearGLASS installation needs to check for xfs ftype
This is a bit of a complex one and could be considered a clearos-docker issue but docker (from centos) claim compatibility with both settings for the moment (up to 1.16).

If your underlying file system is xfs then ClearGLASS does not seem to start successfully unless the partition was formatted with "-n ftype=1" if it is an xfs partition. Ext4 partitions are OK. It tries to start but the api container fails soon after startup.

ClearOS prior to 7.3 formatted xfs with ftype=0 and do not seem to be compatible. This is despite Docker claiming compatibility will be removed in 1.16 and we are at 1.13. If ftype=0 you see the following message in the message log:
Jun 7 13:42:47 server dockerd-current: time="2018-06-07T13:42:47.424497984+01:00" level=warning msg="overlay2: the backing xfs filesystem is formatted without d_type support, which leads to incorrect behavior. Reformat the filesystem with ftype=1 to enable d_type support. Running without d_type support will no longer be supported in Docker 1.16."

There is a docker reference at https://docs.docker.com/storage/storagedriver/overlayfs-driver/ [^]

ClearGLASS needs to check on installation (or start up) what the underlying file system set up is for the partition where /var/clearos/docker is located. the command xfs_info fun on the partition will give the file system type e.g. "xfs_info /dev/mapper/clearos-root"

There is no way (that I have found) of converting an xfs partition. My workaround was to bind mount a folder on a compatible partition into /var/clearos/docker.

Installations of ClearOS originating from 7.3 onwards should be OK as RedHat flipped the default of the formatting command at that point.
There are no notes attached to this issue.





View Issue Details
12441 [ClearCenter] other feature have not tried 2017-01-16 14:17 2018-02-12 11:38
tracker  
dloper  
normal  
assigned 7.3.0 Updates  
open  
none    
none  
  8.0.0 Beta 1  
Migrate paid app repo system mid-release
The paid app repo system is scheduled to be switched over to a new system mid-release. Due to the critical nature of the update outside of a proper beta period, extensive internal testing must be performed.
Notes
(0004551)
user2   
2017-01-16 14:22   
This tracker item is assigned to dloper. pbaldwin will report results only, no sign-off will be given though. However, dloper does not need sign-off to proceed.





View Issue Details
15741 [ClearCenter] app-antispam-updates - Antispam Updates feature have not tried 2017-07-17 09:21 2017-11-28 08:24
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Change signature update methodology - antispam
Scope: tbd.
There are no notes attached to this issue.





View Issue Details
15721 [ClearCenter] app-content-filter-updates - Content Filter Updates feature have not tried 2017-07-17 09:20 2017-11-28 08:24
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Change signature update methodology - content filter
Scope: tbd.
There are no notes attached to this issue.





View Issue Details
15711 [ClearCenter] app-intrusion-protection-updates - Intrusion Protection Updates feature have not tried 2017-07-17 09:19 2017-11-28 08:24
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Change signature update methodology - IDS/IPS
Scope: tbd.
There are no notes attached to this issue.





View Issue Details
17041 [ClearCenter] app-dns-and-domains - DNS and Domain Services minor have not tried 2017-09-13 13:44 2017-09-13 13:44
user2  
 
normal  
confirmed  
open  
none    
none  
   
Add CAA DNS record
Ran across the CAA DNS record while doing a Qualys SSL Test:

https://blog.qualys.com/ssllabs/2017/03/13/caa-mandated-by-cabrowser-forum [^]

Interesting...
There are no notes attached to this issue.





View Issue Details
7391 [ClearCenter] kavscan feature have not tried 2016-02-23 14:52 2017-08-16 15:35
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Migrate kavscan to build system
The kavscan RPM needs to get pushed through koji/buildsys.
There are no notes attached to this issue.





View Issue Details
16111 [ClearCenter] app-intrusion-protection-updates - Intrusion Protection Updates feature have not tried 2017-08-06 13:10 2017-08-12 19:01
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Update installation workflow - Intrusion Protection Updates
The paid app repositories were migrated to a new system in the middle of the ClearOS 7 release cycle - see 0012441. To reduce the risk of customer disruptions, the changes required to install signature updates was kept to a *minimum*. Improve the installation workflow, notably remove the dependence on RPMs.
There are no notes attached to this issue.





View Issue Details
16101 [ClearCenter] app-content-filter-updates - Content Filter Updates feature have not tried 2017-08-06 13:09 2017-08-12 19:00
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Update installation workflow - Content Filter Updates
The paid app repositories were migrated to a new system in the middle of the ClearOS 7 release cycle - see 0012441. To reduce the risk of customer disruptions, the changes required to install signature updates was kept to a *minimum*. Improve the installation workflow, notably remove the dependence on RPMs.
There are no notes attached to this issue.





View Issue Details
16091 [ClearCenter] app-antispam-updates - Antispam Updates feature have not tried 2017-08-06 13:09 2017-08-12 18:59
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Update installation workflow - Antispam Updates
The paid app repositories were migrated to a new system in the middle of the ClearOS 7 release cycle - see 0012441. To reduce the risk of customer disruptions, the changes required to install signature updates was kept to a *minimum*. Improve the installation workflow, notably remove the dependence on RPMs.
There are no notes attached to this issue.





View Issue Details
16081 [ClearCenter] app-antimalware-updates - Antimalware Updates feature have not tried 2017-08-06 13:09 2017-08-12 18:50
user2  
 
normal  
confirmed  
open  
none    
none  
  8.0.0 Beta 1  
Update installation workflow - Antimalware Updates
The paid app repositories were migrated to a new system in the middle of the ClearOS 7 release cycle - see 0012441. To reduce the risk of customer disruptions, the changes required to install signature updates was kept to a *minimum*. Improve the installation workflow, notably remove the dependence on RPMs.
There are no notes attached to this issue.





View Issue Details
16151 [ClearCenter] kmod-network-bypass minor have not tried 2017-08-07 07:07 2017-08-07 07:07
user2  
dloper  
normal  
assigned  
open  
none    
none  
   
Unknown build in updates-testing - network-bypass-kmod
A new network-bypass-kmod build appeared in updates-testing - http://koji.clearos.com/koji/buildinfo?buildID=1708 [^]

There are no notes attached to this issue.





View Issue Details
13691 [ClearOS] build-images - Install images minor have not tried 2017-03-12 09:58 2017-08-06 20:24
user2  
 
normal  
confirmed 7.3.1  
open  
none    
none  
   
ISO builder using unexpected version
The ISO builder pulls in the most recently tagged verified package even though the package version is lower. For example:

example-1.1.noarch.rpm -> tagged Jan 1
example-1.0.noarch.rpm -> tagged Jan 15

Even though 1.1 is the highest version, the 1.0 package is pulled in because it was the most recently tagged package.
There are no notes attached to this issue.





View Issue Details
15151 [ClearCenter] app-kaspserky-gateway - Kaspersky Gateway minor have not tried 2017-05-30 08:55 2017-07-07 06:39
bchambers  
 
normal  
confirmed 7.3.0 Updates  
open  
none    
none  
   
Webconfig errors with 500
This file:

/var/clearos/kaspersky_gateway/report

Can get very large...on the ticket/server I was on, it exceeded 1.5M rows, at which point, the functions get_summary and get_daily_summary exceed the memory limitation of Webconfig.
There are no notes attached to this issue.





View Issue Details
15091 [ClearCenter] app-remote-backup - Remote Server Backup minor have not tried 2017-05-25 09:42 2017-07-07 06:39
bchambers  
 
normal  
confirmed 7.3.0 Updates  
open  
none    
none  
   
Review mysqldump flags
--delayed-insert is now deprecated and best practices suggest running --quick with --single-transaction
There are no notes attached to this issue.





View Issue Details
2050 [ClearCenter] yum-marketplace-plugin minor have not tried 2014-12-02 12:00 2017-05-08 14:51
user2  
slords  
normal  
assigned  
open  
none    
none  
   
The "yum check" command hangs
See subject.
Notes
(0005571)
slords   
2017-05-08 14:51   
Are you sure it is hung? See: https://www.centos.org/forums/viewtopic.php?t=46676 [^]





View Issue Details
11761 [ClearCenter] app-content-filter-updates - Content Filter Updates tweak have not tried 2016-12-14 10:30 2017-04-10 13:18
user2  
 
normal  
confirmed  
open  
none    
none  
   
Create API calls to retrieve blacklists from Netify
The DansGuardian blacklists need a new data source. Create the necessary glue to pull from Netify's web/app category lists.
There are no notes attached to this issue.





View Issue Details
10761 [ClearCenter] app-dynamic-dns - Dynamic DNS feature always 2016-09-23 12:48 2017-03-03 07:25
dloper  
 
normal  
acknowledged 7.2.0 Updates  
open  
none    
none  
   
Add SSHFP to dynamic DNS
SSH Fingerprints through DNS allows for increased confidence when accessing servers by requiring the match of the SSH key.

To calculate these to be able to upload to the SDN in a Dynamic DNS transaction, the following will be run on the local machine:

ssh-keygen -r 127.0.0.1

You may get something similar to:

127.0.0.1 IN SSHFP 1 1 698cbe74f36acbf1702fe447bd3beacf67b6a214
127.0.0.1 IN SSHFP 1 2 36c8385bd55df320281e185bc777a4d0e6fba46d3b6410209ae3fff106a88a51
127.0.0.1 IN SSHFP 3 1 6ddb585b6f99f948a4626f1b807bd3b671ab0917
127.0.0.1 IN SSHFP 3 2 8af17b210e0dc4e1c438055961a85dc4281625eb7d4fe38b0c51275dae681e12

The returned results should work for BIND but you would need to replace the 127.0.0.1 with the dynamic DNS name.
There are no notes attached to this issue.





View Issue Details
10671 [ClearCenter] app-owncloud - ownCloud for Home tweak have not tried 2016-09-20 10:49 2017-03-03 07:25
user2  
 
normal  
acknowledged  
open  
none    
none  
   
EPEL owncloud update
ownCloud has been updated to 9.0.4 in EPEL. Review.
There are no notes attached to this issue.





View Issue Details
10451 [ClearCenter] kmod-network-bypass feature always 2016-09-09 11:47 2017-03-03 07:25
dloper  
 
normal  
acknowledged 6.7.0 Updates  
open  
none    
none  
   
Push kmod-network-byapss in test to updates
kmod-network-bypass-2.12.0-2.v6 for ClearOS 6 to updates
There are no notes attached to this issue.





View Issue Details
9351 [ClearCenter] app-active-directory - Active Directory Connector tweak have not tried 2016-06-21 12:28 2017-03-03 07:25
user2  
 
normal  
acknowledged  
open  
none    
none  
  6.7.0 Updates  
Handle server max protocol
Max sure "server max protocol" is removed or set to a sane value on provisioning. See 0009251
There are no notes attached to this issue.





View Issue Details
12431 [ClearCenter] app-static-vpn - Static VPN for Business tweak have not tried 2017-01-16 12:37 2017-01-16 12:37
user2  
 
low  
confirmed  
open  
none    
none  
   
Static VPN has bad validation for remote subnet
Remote and local subnets require RFC1918 addressing for LAN addresses. This is typical but it is out of spec since IPSec should be able to work behind firewalls that use Public IP addresses for LAN addresses.

Proper validation should be for normalized IPv4 addresses instead. Perhaps a popup that is warning the user that they are using public IP addresses for the LAN network should be better implemented.
There are no notes attached to this issue.





View Issue Details
12421 [ClearCenter] app-static-vpn-basic - Static VPN for Home tweak have not tried 2017-01-16 10:25 2017-01-16 12:37
dloper  
 
low  
confirmed  
open  
none    
none  
   
Static VPN has bad validation for remote subnet
Remote and local subnets require RFC1918 addressing for LAN addresses. This is typical but it is out of spec since IPSec should be able to work behind firewalls that use Public IP addresses for LAN addresses.

Proper validation should be for normalized IPv4 addresses instead. Perhaps a popup that is warning the user that they are using public IP addresses for the LAN network should be better implemented.
There are no notes attached to this issue.





View Issue Details
1605 [ClearCenter] eziod tweak sometimes 2014-03-11 20:08 2016-04-29 12:41
dloper  
dsokoloski  
low  
assigned 6.5.0 Updates  
open  
none    
none  
   
eziod does not properly work with bypass when bus segment is not 0
The kmod-network-bypass detects the bypass on different and varying busses. On ClearBOX gen1 and gen2 this was bus 0 for whenever a module board was not in the box. On gen3 it can be 6 ... or 14. Basically, the function of the eziod which allows front-panel access to the network bypass needs to search the bus in order to properly address the functions of the bypass.

In the past this bus was 0 so the path was /sys/bus/i2c/devices/0-0026 for bypass 1 and /sys/bus/i2c/devices/0-0022 for bypass 2. But if the bypass is on bus 6 it will be on /sys/bus/i2c/devices/6-0022/bypass0 for bypass 2.

Logic needs to be programmed to search the /sys/bus/i2c/devices/ directory for items that match the following "-0026", "-0022", "-0020", "-0024". For each of those it will need to lookup /sys/bus/i2c/devices/XX-00xx/bypass0. If that file is found then a bypass segment exist for the bypass1, 2, 3, and/or 4.
Notes
(0001158)
dsokoloski   
2014-03-12 11:44   
I have a very old ClearBOX 300 which I believe is Gen1. I just wanted to make note that the i2c bus assignments don't seem to be hardware related, but kernel related. For example, my bypass devices used to be on bus zero (0-0026, and 0-0022). But now, with kernel 2.6.32-431, they are on bus 6 but have the same IDs (6-0026, and 6-0022).

So would the logic be dynamically find these devices, in reversed order, such as:

# find /sys/devices/ -name 'bypass0' | sort -nr
(0003141)
dloper   
2016-04-29 12:41   
[root@gateway etc]# diff eziod.conf eziod.conf.orig
307,322d306
< f = io.open("/sys/bus/i2c/devices/6-0026/bypass0")
< if f ~= nil then
< for line in f:lines() do
< _, _, bp1 = string.find(line, "^(%d+)")
< break
< end
< io.close(f)
< end
< f = io.open("/sys/bus/i2c/devices/6-0022/bypass0")
< if f ~= nil then
< for line in f:lines() do
< _, _, bp2 = string.find(line, "^(%d+)")
< break
< end
< io.close(f)
< end
330,342d313
< local bpfile1
< local bpfile2
< local q
< bpfile1 = "/sys/bus/i2c/devices/0-0026/bypass0"
< bpfile2 = "/sys/bus/i2c/devices/0-0026/bypass0"
< q = io.open("/sys/bus/i2c/devices/6-0026/bypass0","r")
< if q then bpfile1 = "/sys/bus/i2c/devices/6-0026/bypass0" end
< q = io.open("/sys/bus/i2c/devices/6-0022/bypass0","r")
< if q then bpfile2 = "/sys/bus/i2c/devices/6-0022/bypass0" end
< q = io.open("/sys/bus/i2c/devices/9-0026/bypass0","r")
< if q then bpfile1 = "/sys/bus/i2c/devices/9-0026/bypass0" end
< q = io.open("/sys/bus/i2c/devices/9-0022/bypass0","r")
< if q then bpfile2 = "/sys/bus/i2c/devices/9-0022/bypass0" end
344c315
< f = io.open(bpfile1, "w")
---
> f = io.open("/sys/bus/i2c/devices/0-0026/bypass0", "w")
346c317
< f = io.open(bpfile2, "w")
---
> f = io.open("/sys/bus/i2c/devices/0-0022/bypass0", "w")





View Issue Details
7891 [ClearCenter] app-dynamic-dns - Dynamic DNS minor have not tried 2016-03-30 06:52 2016-03-30 08:13
bchambers  
bchambers  
normal  
assigned 7.2.0 Updates  
open  
none    
none  
   
Wrong IP may update on MultiWAN
If a multiWAN system with a preference selected for a particular interface is assigned private IP's, Dynamic DNS ip referrer may use any route to fetch the address, and not end up using the preferred interface.

A proposed fix would be to modify the following files:

/usr/clearos/apps/clearcenter/libraries/Web_Service.php

public function request($action, $postfields = "")

to

public function request($action, $postfields = "", $bind = NULL)

add to "Set main curl options" section:

if ($bind != NULL)
   curl_setopt($ch, CURLOPT_INTERFACE, $bind);

/usr/clearos/apps/dynamic_dns/libraries/DNS_Update.php

Line 229

$ip = $ip_referrer->get();

to

$ip = $ip_referrer->get($ip);

/usr/clearos/apps/dynamic_dns/libraries/IP_Referrer.php

public function get()
    {
        $payload = $this->request('getip', NULL);

        return $payload;
    }

to

public function get($bind_ip)
    {
        $payload = $this->request('getip', NULL, $bind_ip);

        return $payload;
    }
Notes
(0002961)
user2   
2016-03-30 08:13   
Note: IP referrer lookups are not supported in Multi-WAN. Syswatch doesn't track IP referrers in MultiWAN, so it will never detect a changed IP. In syswatch:

    if ($numwans >= 2) {
        $config{is_multiwan} = $STATE_ENABLED;
        $config{use_get_ip} = $STATE_DISABLED;
        LogMsg("info", "config", "IP referrer disabled in multi-WAN\n");
    }

Keep in mind, Dynamic DNS updates still happen on boot and manually.

If we want to add support for IP referrers in MultiWAN mode, this policy would need to change. I can't think of a good reason why this policy was put in place (?) ... but it's definitely intentional.





View Issue Details
7211 [ClearCenter] app-dynamic-vpn - Dynamic VPN minor have not tried 2016-01-25 17:17 2016-01-25 17:18
user2  
 
normal  
confirmed 7.1.0  
open  
none    
none  
  7.1.0 Updates  
Hard restart not always done
The Dynamic VPN system will attempt soft restarts for a certain amount of time (e.g. 1 hour) before attempting a hard restart. The hard restart might be missed in ClearOS 7.
There are no notes attached to this issue.





View Issue Details
4552 [ClearCenter] app-remote-backup - Remote Server Backup feature N/A 2015-08-25 07:18 2015-11-18 12:06
bchambers  
dsokoloski  
normal  
assigned 7.1.0 Updates  
open  
none    
none  
   
Add --dry-run type feature
Would be nice (and sometimes imperative when support is troubleshooting) to have a --dry-run feature that would output what files/folders rsync *would* backup if it were to run, along with file size and total sum (approx).

Example output:

rbs_client --dry-run
/var/flexshare/shares/test
/var/flexshare/shares/test/myfile1.txt [200kB]
/var/flexshare/shares/test/myfile2.txt [250kB]
/home/user1/hello.txt [10MB]
Dry run complete.
Total backup size: 10.45 MB
There are no notes attached to this issue.





View Issue Details
5941 [ClearCenter] app-active-directory - Active Directory Connector minor have not tried 2015-11-04 08:14 2015-11-04 08:17
bchambers  
 
normal  
acknowledged 7.1.0  
open  
none    
none  
   
Primary Group causes grief
Any group that is set as the "primary group" in Active Directory will not be detected in the groups list for that user when viewing the account via System -> Accounts -> Users or when setting up Content Filters using that group.

Work-around or documentation required?
Ref: Ticket #541812
There are no notes attached to this issue.





View Issue Details
2048 [ClearCenter] app-central-management minor have not tried 2014-11-25 13:29 2015-09-09 20:13
bchambers  
 
normal  
confirmed 6.6.0  
open  
none    
none  
   
Pro install wizard fails at mode in some cases
This app does not get installed if Pro license is missing "account syncronization" app. Strange, since it is in two places and a user's Professional license should always give them access to the professional repository:

/home/mirrors/marketplace/account_synchronization/6.1/i386/app-central-management-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/account_synchronization/6.1/i386/app-central-management-core-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/account_synchronization/6.1/x86_64/app-central-management-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/account_synchronization/6.1/x86_64/app-central-management-core-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/professional/6.1/i386/app-central-management-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/professional/6.1/i386/app-central-management-core-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/professional/6.1/x86_64/app-central-management-1.5.30-1.v6.noarch.rpm
/home/mirrors/marketplace/professional/6.1/x86_64/app-central-management-core-1.5.30-1.v6.noarch.rpm
[root@web2-toronto ~]# ls /home/mirrors/marketplace/professional/6.1/i386/app-central-management-1.5.30-1.v6.noarch.rpm

Wizard fails when requiring the Mode/Driver library.
For now, hard code account_syncronization repo with all Pro editions.

There are no notes attached to this issue.





View Issue Details
1896 [ClearCenter] app-remote-backup - Remote Server Backup feature N/A 2014-08-09 09:59 2015-09-09 20:13
marclaporte  
 
high  
confirmed 6.5.0 Updates  
open  
none    
none  
   
Remote backup: offer MySQL data & Zarafa emails (attachments are in file system and mails are in DB)
ClearCenter's Remote Server Backup Service is really awesome:
* Automatic
* Incremental
* Encrypted
* Notification emails (Summary or on failure)

And the price is reasonable to have a set & forget offsite backup solution.

However, AFAICT, it doesn't save the MySQL data or Zarafa mails (perhaps when using non Zarafa mail options, mails are OK?)

 Thanks!
Notes
(0001421)
marclaporte   
2015-04-19 16:29   
Workaround could be to propose a mysqldump cron job to a space which is covered by remote backup.





View Issue Details
4471 [ClearCenter] app-zarafa-small-business - Zarafa Small Business tweak have not tried 2015-08-20 14:50 2015-08-20 14:50
user2  
 
normal  
confirmed  
open  
none    
none  
   
Add Zarafa uninstall
The uninstall for Zarafa is more complex than others:

- 55-ish RPMs
- not particularly good upstream behavior

Review and implement.
There are no notes attached to this issue.





View Issue Details
1635 [ClearCenter] app-netatalk - Netatalk tweak have not tried 2014-03-27 11:35 2015-08-20 07:20
user2  
 
normal  
confirmed  
open  
none    
none  
   
Remove deprecated page type for new theme
The MY_Page::TYPE_REPORT is now deprecated. Use My_Page::TYPE_WIDE_CONFIGURATION
There are no notes attached to this issue.





View Issue Details
1409 [ClearCenter] app-central-management tweak N/A 2013-10-29 17:27 2015-08-19 21:50
user2  
 
normal  
confirmed  
open  
none    
none  
   
Move remote API call to a different port
See 0001408
There are no notes attached to this issue.





View Issue Details
1872 [ClearCenter] app-remote-backup - Remote Server Backup feature N/A 2014-07-26 06:22 2015-06-04 13:25
bchambers  
dsokoloski  
normal  
assigned 6.5.0  
open  
none    
none  
   
Add command line tool to output what folders (and size) the backup is configured to perform.
Eg.

rbs_client -L

100MB /var/flexshare/
120MB /var/home
..
..
10 KB /etc/clearos

Total Backup = 120.1 MB
Notes
(0001271)
marclaporte   
2014-08-08 16:03   
Great, but why only command line?

Use case: I have a running system and I want to decide which RBS package fits my needs. Do I go with 5 or 10 gigs?

It would be nice for the system to indicate how much space each option requires. With a note that I need more for incremental.

Thanks!





View Issue Details
2162 [ClearCenter] app-antispam-updates - Antispam Updates tweak have not tried 2015-01-29 08:51 2015-06-04 13:23
user2  
 
normal  
confirmed  
open  
none    
none  
   
Do a full review of antispam signatures from third parties
See subject.
There are no notes attached to this issue.





View Issue Details
1460 [ClearCenter] app-branding-manager - Branding Manager feature N/A 2013-12-10 14:54 2015-04-09 09:03
user2  
bchambers  
normal  
confirmed  
open  
none    
none  
   
Add branding manager engine
Create a new branding manager library. This will be used to support the custom proxy page for now.
There are no notes attached to this issue.





View Issue Details
2127 [ClearCenter] app-google-apps-connector - Google Apps Connector major have not tried 2015-01-13 11:38 2015-01-13 11:42
user2  
 
urgent  
confirmed  
open  
none    
none  
   
Replace deprecated Zend / Google Apps library
The Google Apps Provisioning library has been deprecated and the Zend library that we use will not be migrated to the new API. We will have to implement our own PHP library.
There are no notes attached to this issue.





View Issue Details
2030 [ClearCenter] app-security-audit - Security Audit feature N/A 2014-11-11 09:28 2014-11-11 09:36
marclaporte  
 
low  
confirmed  
open  
none    
none  
   
Security audit report should also indicate the software updates for the same time period
We get something like this:

AIDE found differences between database and filesystem!!
Summary:
  Total number of files: 18491
  Added files: 0
  Removed files: 0
  Changed files: 24

But how to know if those 24 changed files are legit?

It would be useful to have (in the same message) the info from https://example.org:81/app/software_updates [^]

So when I see:
changed: /usr/lib64/openssl/engines/libcapi.so
changed: /usr/lib64/openssl/engines/libchil.so

Along with this:
Nov 11 03:42:25 Updated openssl-1.0.1e-16.el6_5.15.x86_64

I can be confident that it's legit.

Thanks!
There are no notes attached to this issue.





View Issue Details
2024 [ClearCenter] app-dynamic-vpn - Dynamic VPN minor have not tried 2014-11-10 09:48 2014-11-10 09:49
user2  
 
normal  
confirmed  
open  
none    
none  
   
Handle multi-WAN with mixed IPsec-friendly WANs
By definition, IPsec does not work behind a NAT-based gateway (it's not real IPsec when one tries to hack it behind NAT). It's possible to have a multi-WAN scenario where one WAN is connected directly to the Internet, while the other is behind NAT. Dynamic VPN should handle this scenario in a sane way.
There are no notes attached to this issue.





View Issue Details
1308 [ClearCenter] app-zarafa-small-business - Zarafa Small Business feature always 2013-09-09 14:49 2014-08-15 07:56
bchambers  
bchambers  
normal  
assigned 6.5.0 Beta 2  
open  
none    
none  
   
Expose zarafa-backup utility
Zarafa's database dump scripts may not be bandwidth friendly (TBD) to ClearCenter's RBS file delta algorithms. A local dump to mounted share or USB drive may be best way to schedule a disaster recovery backup for mail.

Expose this functionality to Zarafa SMB users.
Notes
(0001276)
marclaporte   
2014-08-15 07:56   
Hi!

So Bare Metal Backup/Restore is now available and it's great:
http://www.clearcenter.com/support/documentation/user_guide/bmbackup [^]

But automated, offsite backups are a big / awesome / fantastic benefit of ClearCenter.

Could we imagine some sort of intermediary format? Backup / convert to a friendlier format before sending off to RBS?

Thanks!





View Issue Details
1897 [ClearCenter] app-marketplace - Marketplace feature N/A 2014-08-10 19:25 2014-08-11 08:28
marclaporte  
 
normal  
acknowledged  
open  
none    
none  
   
Trial period for paid services in the marketplace
The paid services in the ClearCenter marketplace provide a lot of value & convenience.

Remote backups, remote security audits, etc.
http://www.clearcenter.com/marketplace/ [^]

However, sometimes users will want to try before they buy. It would be nice to have some sort of free trial period, say 30 days or 60 days for them to confirm that the app does what it's supposed to.

It could be a formula where they agree to pay in 30 or 60 days unless they cancel. Or perhaps they pay upfront and there is a mechanism to cancel and keep that amount as a credit.

If they cancel, the app should uninstall itself or be deactivated somehow.

Thanks!
Notes
(0001273)
user2   
2014-08-11 08:28   
The ClearOS Professional 30-day evaluation includes free access to most of the paid apps -- we can't do it for some apps (e.g. Kaspersky). It would be nice to have a similar option for the Community Edition, especially those apps that are handy in home environments.





View Issue Details
1857 [ClearCenter] app-antimalware-updates - Antimalware Updates text N/A 2014-07-14 13:48 2014-08-05 16:05
marclaporte  
 
none  
acknowledged  
open  
none    
none  
   
Comparison of various Anti-Malware / Anti-Spam / Anti-Virus / Anti-phishing options in ClearOS
This page is fantastic:
http://www.clearcenter.com/support/documentation/clearos_guides/mail_server_options_for_clearos [^]

It would be nice to have a similar page for others things when there is more than one option. I see:
http://www.clearcenter.com/marketplace/server/Mail_Antispam.html [^]
http://www.clearcenter.com/marketplace/server/Antispam_Updates.html [^]
http://www.clearcenter.com/marketplace/server/Mail_Antivirus.html [^]
http://www.clearcenter.com/marketplace/gateway/Antimalware_Updates.html [^]
http://www.clearcenter.com/marketplace/gateway/Gateway_Antivirus.html [^]
http://www.clearcenter.com/support/documentation/user_guide/antimalware_file_scan [^]

Any notes about exclusions and combinations would be nice. For example:
If I get http://www.clearcenter.com/marketplace/server/Mail_Antimalware_Premium_-_Powered_by_Kaspersky_Lab.html [^]
Do I also get: http://www.clearcenter.com/marketplace/gateway/Gateway_Antimalware_Premium_-_Powered_by_Kaspersky_Lab.html [^]

Thanks!
There are no notes attached to this issue.





View Issue Details
1729 [ClearCenter] app-dns-and-domains - DNS and Domain Services feature always 2014-05-31 10:01 2014-07-15 18:38
marclaporte  
 
normal  
confirmed  
open  
none    
none  
   
Add support for more Internet top-level domains (TLDs), ideally all.
In https://secure.clearcenter.com/portal/dns_transfer.jsp, [^] options are:
.biz .ca .com .es .eu .fr .info .net .nl .org .us

There are hundreds of others.

Reference:
http://www.clearcenter.com/support/documentation/clearcenter_dns_service/ [^]
http://en.wikipedia.org/wiki/List_of_Internet_top-level_domains [^]
Notes
(0001241)
bchambers   
2014-07-15 18:38   
Many ccTLD's (eg. .ca, .de) have custom requirements making it extremely cumbersome to make the necessary customizations to the checkout process to support little idiosyncrasies (really, .de...a fax is required for transfers....http://www.tucowsdomains.com/transfer-of-domain-registration/how-can-i-transfer-my-de-domains-from-one-tucows-reseller-to-another/ [^])? Ugh.

Investigate new batch of TLD's to see if they fall in line with .com easy of offer.





View Issue Details
1730 [ClearCenter] app-bandwidth-monitor - Bandwidth Monitor feature always 2014-05-31 13:54 2014-06-02 07:58
marclaporte  
 
low  
acknowledged  
open  
none    
none  
   
Launch Remote Bandwidth Monitor
Remote Bandwidth Monitor is "Coming Soon":
http://www.clearcenter.com/Services/clearsdn-remote-bandwidth-monitor-6.html [^]
There are no notes attached to this issue.





View Issue Details
1679 [ClearCenter] app-active-directory - Active Directory Connector minor have not tried 2014-04-28 08:29 2014-04-28 08:30
user2  
 
normal  
confirmed  
open  
none    
none  
   
Users are not enumerated in nested groups
The underlying authentication system for the Active Directory Connector can handle nested groups, but the the user/group system does not include nesting.

Example: if an AD admin adds the "sales" group to the "pptp_plugin" group, all users in the "sales" group will be able to login to ClearOS PPTP. Works fine. However, a user in the "sales" group will not have the PPTP option selected in the web-based interface -- the nesting is not enumerated.
There are no notes attached to this issue.





View Issue Details
1660 [ClearCenter] app-active-directory - Active Directory Connector tweak N/A 2014-04-08 20:03 2014-04-08 20:03
user2  
 
normal  
acknowledged  
open  
none    
none  
   
Optimize the level of caching
Long delays can be experienced due to caching. The "net cache flush" command can be used to purge the cache. To discuss/investigate.
There are no notes attached to this issue.





View Issue Details
1658 [ClearCenter] app-central-management feature N/A 2014-04-08 09:11 2014-04-08 20:03
user2  
 
normal  
acknowledged  
open  
none    
none  
   
Notify end user that master has been unreachable for X amount of time
A slave system can run quite happily for days (weeks?) without a connection to the master, but it's a situation that should be resolved by the administrator. Provide a way to notify the administrator of this "event".
There are no notes attached to this issue.





View Issue Details
1614 [ClearCenter] app-security-audit - Security Audit minor N/A 2014-03-13 17:28 2014-03-13 17:29
user2  
 
normal  
confirmed  
open  
none    
none  
   
Update 64-bit config
See subject
There are no notes attached to this issue.





View Issue Details
1525 [ClearCenter] app-network-map - Network Map tweak have not tried 2014-01-21 10:10 2014-01-21 10:11
user2  
 
normal  
confirmed  
open  
none    
none  
   
Handle bogon and 169 addresses - clutter
Bogons and 169 addresses can clutter up the Network Map "Unknown" summary table. These entries should be handled a differently in the GUI. See forum post for details:

http://www.clearfoundation.com/component/option,com_kunena/Itemid,232/catid,28/func,view/id,58948/#58965 [^]
There are no notes attached to this issue.





View Issue Details
1413 [ClearCenter] app-clearcare - ClearCARE Support minor have not tried 2013-10-30 17:51 2014-01-21 07:45
user2  
bchambers  
normal  
assigned  
open  
none    
none  
   
Add ClearCARE support manager to webconfig
Scope to be determined.
There are no notes attached to this issue.





View Issue Details
1495 [ClearCenter] app-clearbox - ClearBOX major sometimes 2014-01-02 11:47 2014-01-02 11:47
user2  
dloper  
normal  
assigned  
open  
none    
none  
   
Add storage mapping for Mail Archive
The /var/clearos/mail_archive directory is used to store archived mail. ClearBOXes running Mail Archive without an fstab mapping to the data store will run into big trouble.
There are no notes attached to this issue.





View Issue Details
1494 [ClearCenter] app-clearbox - ClearBOX major sometimes 2014-01-02 11:38 2014-01-02 11:47
user2  
dloper  
normal  
confirmed  
open  
none    
none  
   
Add storage mapping for /var/lib/zarafa
The /var/lib/zarafa directory seems to get filled up with files (not attachments). ClearBOXes running Zarafa without an fstab mapping to the data store will run into big trouble.
There are no notes attached to this issue.





View Issue Details
1287 [ClearCenter] app-zarafa-small-business - Zarafa Small Business feature N/A 2013-08-20 14:36 2013-10-29 17:25
user2  
 
normal  
confirmed  
open  
none    
none  
   
Set default Zarafa install version to 7.1.x
The Zarafa 7.1.x release and ClearOS upgrade path has been floating around for months, and the ClearOS 6.5.0 release provides a good time to switch to the new version. Existing customers on 7.0.x will not need to do anything and will remain on 7.0.x until a manual upgrade is completed:

http://www.clearcenter.com/support/documentation/clearos_guides/upgrading_zarafa_7.0.x_to_7.1.x [^]
Notes
(0001071)
user2   
2013-10-29 17:25   
Due to the Zarafa licensing engine, this is actually a bit tricky. Re-review at a later date.





View Issue Details
1398 [ClearCenter] app-network-map - Network Map feature N/A 2013-10-21 13:16 2013-10-21 13:17
user2  
 
normal  
confirmed  
open  
none    
none  
   
Add purge support to remove old MACs
By default, arpwatch does not purge MAC addresses, so the list of unknown devices will start to get some cruft. Add purge handling:

- Automatic purging after X number of days (configurable in the UI)
- A "delete" option on a per-MAC basis
There are no notes attached to this issue.





View Issue Details
1288 [ClearCenter] clearsdn-content-filter - Content Filter Updates tweak always 2013-08-21 08:17 2013-08-21 09:42
user2  
 
low  
confirmed  
open  
none    
none  
   
Add tag to "ads" blacklist to provide the proper hook for the logadblocks parameter
The "logadblocks" parameter in dansguardian.conf requires the following comment in the "ads" blacklists:

#listcategory “ADs”

Note: is a colon required (i.e. #listcategory:“ADs”)?
There are no notes attached to this issue.





View Issue Details
1026 [ClearCenter] app-kaspserky-gateway - Kaspersky Gateway feature N/A 2013-03-14 10:07 2013-07-24 10:20
user2  
 
normal  
confirmed  
open  
none    
none  
   
Upgraded to SDK 8 build Q1 2013
See subject.
There are no notes attached to this issue.





View Issue Details
1229 [ClearCenter] app-remote-backup - Remote Server Backup major always 2013-07-17 13:16 2013-07-17 13:16
bchambers  
bchambers  
normal  
assigned 6.4.0  
open  
none    
none  
  6.4.0 Updates  
Unable to select any restore image other than most recent from Webconfig UI
Selecting a restore image other than most recent will not be displayed in GUI, even though it is saved in the configuration and used by the restore.
There are no notes attached to this issue.





View Issue Details
1107 [ClearCenter] clearos-release-professional minor always 2013-04-20 17:44 2013-04-26 09:42
dloper  
 
low  
acknowledged 5.2-SP1  
open  
none    
none  
   
Creating new certificate authority renders the expire date as 1902.
On new installs of ClearOS 5.2 fully updated, the Certificate Manager creation in the wizard creates the root CA with an expiry of 1902. This renders multiple systems unusable including OpenVPN.

http://www.clearfoundation.com/component/option,com_kunena/Itemid,232/catid,25/func,view/id,50312/ [^]
Install new system. Drop to the command line and update the system. Run through the wizard, and create Certificates by completing the wizard. Validate the expiry.
WORKAROUND. After installing the system and running the updates, modify the following file:

/var/webconfig/api/Ssl.class.php

change the following line:

        const DEFAULT_CA_EXPIRY = 9125; # 25 yrs in days

to:

        const DEFAULT_CA_EXPIRY = 8125; # 25 yrs in days

Notes
(0000827)
user2   
2013-04-26 09:42   
ClearOS 6 (32-bit) does not suffer from this issue.





View Issue Details
1094 [ClearCenter] app-security-audit - Security Audit minor always 2013-04-11 10:47 2013-04-11 10:47
bchambers  
dsokoloski  
normal  
assigned 6.4.0  
open  
none    
none  
  6.4.0  
passwordless executable segfaults
strace /var/lib/suvlets/SecurityAudit/passwordless
execve("/var/lib/suvlets/SecurityAudit/passwordless", ["/var/lib/suvlets/SecurityAudit/p"...], [/* 21 vars */]) = 0
uname({sys="Linux", node="chambers.lan", ...}) = 0
brk(0) = 0x2383000
brk(0x2384180) = 0x2384180
arch_prctl(ARCH_SET_FS, 0x2383860) = 0
brk(0x23a5180) = 0x23a5180
brk(0x23a6000) = 0x23a6000
setuid(0) = 0
open("/etc/nsswitch.conf", O_RDONLY) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=1703, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f4825d66000
read(3, "#\n# /etc/nsswitch.conf\n#\n# An ex"..., 4096) = 1703
read(3, "", 4096) = 0
close(3) = 0
munmap(0x7f4825d66000, 4096) = 0
open("/etc/ld.so.cache", O_RDONLY) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=30295, ...}) = 0
mmap(NULL, 30295, PROT_READ, MAP_PRIVATE, 3, 0) = 0x7f4825d5f000
close(3) = 0
open("/lib64/libnss_files.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360!\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=65928, ...}) = 0
mmap(NULL, 2151824, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f4825b51000
mprotect(0x7f4825b5d000, 2097152, PROT_NONE) = 0
mmap(0x7f4825d5d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xc000) = 0x7f4825d5d000
close(3) = 0
open("/lib64/libc.so.6", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\355\1\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1916568, ...}) = 0
mmap(NULL, 3745960, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f48257be000
mprotect(0x7f4825948000, 2093056, PROT_NONE) = 0
mmap(0x7f4825b47000, 20480, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x189000) = 0x7f4825b47000
mmap(0x7f4825b4c000, 18600, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f4825b4c000
close(3) = 0
open("/lib64/ld-linux-x86-64.so.2", O_RDONLY) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\0\v\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=154464, ...}) = 0
mmap(NULL, 2232712, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x7f482559c000
mprotect(0x7f48255bc000, 2093056, PROT_NONE) = 0
mmap(0x7f48257bb000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1f000) = 0x7f48257bb000
mmap(0x7f48257bd000, 392, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x7f48257bd000
close(3) = 0
mprotect(0x7f48257bb000, 4096, PROT_READ) = 0
mprotect(0x7f4825b47000, 16384, PROT_READ) = 0
mprotect(0x7f4825d5d000, 4096, PROT_READ) = 0
munmap(0x7f4825d5f000, 30295) = 0
mmap(NULL, 1048576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f482549c000
open("/etc/shadow", O_RDONLY|O_CLOEXEC) = 3
fcntl(3, F_GETFD) = 0x1 (flags FD_CLOEXEC)
fstat(3, {st_mode=S_IFREG, st_size=1089, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x7f4825d66000
lseek(3, 0, SEEK_CUR) = 0
read(3, "root:$6$JU1RNn36$sLCrneGCf3UfsZZ"..., 4096) = 1089
read(3, "", 4096) = 0
open("/etc/ld.so.cache", O_RDONLY) = 4
fstat(4, {st_mode=S_IFREG|0644, st_size=30295, ...}) = 0
mmap(NULL, 30295, PROT_READ, MAP_PRIVATE, 4, 0) = 0x7f4825494000
close(4) = 0
open("/lib64/libnss_ldap.so.2", O_RDONLY) = 4
read(4, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0000\25\0\0\0\0\0\0"..., 832) = 832
fstat(4, {st_mode=S_IFREG|0755, st_size=44824, ...}) = 0
mmap(NULL, 2139992, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 4, 0) = 0x7f4825289000
mprotect(0x7f4825294000, 2093056, PROT_NONE) = 0
mmap(0x7f4825493000, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 4, 0xa000) = 0x7f4825493000
close(4) = 0
munmap(0x7f4825494000, 30295) = 0
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++
Segmentation fault
There are no notes attached to this issue.





View Issue Details
468 [ClearCenter] app-active-directory - Active Directory Connector minor random 2012-03-09 12:45 2013-04-10 09:07
user2  
 
normal  
confirmed  
open  
none    
none  
   
Weird behavior in getent leads to missing full name when retrieving user info
The following strange behavior occurred on a test system connected to Active Directory:

# getent passwd win9
win9:*:20000013:20000002::/home/win9:/sbin/nologin

# getent passwd | grep win9
win9:*:20000013:20000002:Windows Guy9:/home/win9:/sbin/nologin

Resetting the winbind cache didn't help.

When an administrator is browsing user information, the win9 full name (Windows Guy9) won't be shown. Bummer.
Notes
(0000792)
dloper   
2013-04-10 09:07   
Turn the log level up to 3 in smb.conf.

Restart winbind.

type date
run getent group

Look in the /var/log/samba/log.wb-DOMAINNAME carefully. You may see an error for that timestamp that indicates an issue enumerating a certain aspect of the DOMAIN or even an attempt to enumerate a TRUSTEDDOMAIN.

If wbinfo is working for users or groups but fails to work for one or the other, the error will show up here. Getent bails if it has an error because /lib64/libnss_winbind.so.2 or /lib/libnss_winbind.so.2 is programmed typically to not give data over to nsswitch if it has an error. This is why individual queries for individual groups or users through getent may work when polling the long list fails (ie. getent group "domain users")





View Issue Details
1036 [ClearCenter] app-zarafa - Zarafa feature N/A 2013-03-18 12:53 2013-04-03 15:04
dloper  
bchambers  
low  
assigned 6.4.0  
open  
none    
none  
   
Zarafa out of office appears to not work
Under a certain condition, the out of office notification fails to produce responses under both community and professional editions.
This is typical behavior. By design.
Bug is in testing and discovery. New installations do not seem to demonstrate this bug. The trigger for the condition and workaround are TBD.
Notes
(0000751)
dloper   
2013-03-19 09:47   
This is not a bug but rather the typical behavior. Responses to email messages are governed by the /etc/zarafa/autorespond and the service zarafa-dagent.

Please refer to this guide:

http://www.clearcenter.com/support/documentation/clearos_guides/manipulating_autoresponder_behavior [^]

The manipulation of these values should be created as a feature.
(0000763)
dloper   
2013-03-25 14:18   
I've requested an open ticket with Zarafa on this issue as a followup since alias domains appear still NOT to work for Out of Office in spite of the previous notes which work well for the main or default domain.
(0000781)
dloper   
2013-03-28 14:53   
Zarafa says that this should work...but it doesn't in ClearOS.

Steps to reproduce.

-Configure Zarafa.
-Set up an alias domain in SMTP Server and ensure email to the user works for main domain and alias
-Make a user and log into their web access
-Create and enable out of office message in settings.
-Email alias address (not out of office message)
-Email default address (out of office message)

You may need to tweek the time between messages value according to this:

http://www.clearcenter.com/support/documentation/clearos_guides/manipulating_autoresponder_behavior [^]

Set:
TIMELIMIT=$[5]
(0000783)
user2   
2013-03-28 15:34   
Here are the relevant mail headers for a message sent to alias "testguy" for username "test".

Received: from localhost (localhost [127.0.0.1])
    by mail.example.com (Postfix) with ESMTP id A24F29DD3
    for <test@example.com>; Thu, 28 Mar 2013 17:16:51 -0400 (EDT)
Subject: test out of office
To: testguy@example.com

That looks okay. Will keep digging.
(0000784)
user2   
2013-03-28 15:51   
It looks like Zarafa might need the full e-mail alias in the clearMailAliases LDAP attribute?

http://doc.zarafa.com/6.40/Administrator_Manual/en-US/html/_appendix_b_ldap_attribute_description.html [^]

Cyrus and Google Apps only accept base names (no domain part) for aliases. If Zarafa needs the full e-mail address:

1) A custom mail extension is required
2) Destination domain support becomes messy / complex
(0000785)
dloper   
2013-04-03 10:33   
Adding the full email address to clearMailAliases fixes the issue.

Wouldn't having zarafa tuned for zarafaAliases then be the better solution and have this attribute dynamically tuned to be a composite of clearMailAliases + domain names?
(0000786)
user2   
2013-04-03 15:04   
The "Mail Extension" app used by Google Apps, Cyrus and the current Zarafa would have to be replaced by a "Zarafa Mail Extension". It would be a lot of cut-and-paste code, but not too bad.

I'm assuming the Zarafa code does a direct lookup on the the alias LDAP attribute, so we can't do anything fancy without upstream changes. If an SMTP "destination domain" is added or deleted, all Zarafa user objects would need alias changes (messy).





View Issue Details
1076 [ClearCenter] clearos-release-professional tweak have not tried 2013-04-01 12:24 2013-04-01 12:25
user2  
 
normal  
confirmed  
open  
none    
none  
   
Add versioning to the edition upgrade repo
The edition upgrade uses the base version (e.g. 6) but a more refined versioning would be handy.
There are no notes attached to this issue.





View Issue Details
441 [ClearCenter] app-advanced-networking - Advanced Networking feature N/A 2012-02-27 06:48 2012-10-23 20:54
user2  
dsokoloski  
normal  
assigned  
open  
none    
none  
  6 Future  
Add bridge support in the UI
The underlying API is aware of bridge interfaces, but the option to configure this type of network interface is not exposed in the UI.
There are no notes attached to this issue.





View Issue Details
726 [ClearCenter] kavscan tweak have not tried 2012-08-28 08:48 2012-08-28 08:52
user2  
 
normal  
confirmed  
open  
none    
none  
  6.2.0 Updates  
Upgrade kavscan to new version
Q3 2012 Release for Linux
There are no notes attached to this issue.





View Issue Details
443 [ClearCenter] app-clearbox - ClearBOX feature N/A 2012-02-27 06:59 2012-06-13 18:04
user2  
dsokoloski  
normal  
assigned  
open  
none    
none  
   
Add bypass / failover support
To discuss...
There are no notes attached to this issue.





View Issue Details
546 [ClearCenter] app-clearbox - ClearBOX feature N/A 2012-04-09 07:55 2012-06-13 18:03
user2  
 
normal  
confirmed  
open  
none    
none  
   
Implement LCDProc
See subject.
There are no notes attached to this issue.





View Issue Details
514 [ClearCenter] app-registration - System Registration feature N/A 2012-03-31 04:47 2012-03-31 04:47
user2  
 
normal  
confirmed  
open  
none    
none  
   
Ask questions to better understand usage
Knowing the following details can help us serve ClearOS users:

- Type of organization (home, small business, medium business, elementary school etc)
- Number of users
- Other details
There are no notes attached to this issue.





View Issue Details
190 [ClearCenter] app-remote-backup - Remote Server Backup text sometimes 2010-10-13 12:46 2012-02-07 02:22
user2  
dsokoloski  
normal  
assigned  
open  
none    
none  
  6.2.0 RC 1  
Simplify outbound mail for remote server backup issues
Mail alerts for remote server backup need to be dumbed down a bit. Aaron may be able to provide a nice HTML e-mail template with simple messaging.
There are no notes attached to this issue.





View Issue Details
339 [ClearCenter] app-dns-and-domains - DNS and Domain Services feature N/A 2011-10-18 13:20 2011-11-20 19:16
user2  
bchambers  
normal  
assigned  
open  
none    
none  
   
Migrate app to new framework
Migrate app to new framework
There are no notes attached to this issue.





View Issue Details
193 [ClearCenter] app-managed-vpn - Managed VPN feature N/A 2010-10-13 13:04 2011-10-18 13:42
user2  
 
normal  
confirmed  
open  
none    
none  
   
Add custom OpenVPN client with automatic hooks into certificate handling
A custom OpenVPN client with automatic hooks into ClearOS certificates (via REST) would be ... very nice.
There are no notes attached to this issue.





View Issue Details
230 [ClearCenter] app-clearcenter - ClearCenter Core minor always 2011-02-09 09:35 2011-02-18 10:16
user2  
 
high  
confirmed 5.2-SP1  
open  
none    
none  
   
Re-enable version update
In the "Systems" view in the ClearCenter portal, the ClearOS version is shown in the summary. This is the version of the system when it is registered, not the running version. That's certainly confusion and needs to be fixed.

In previous versions, there was a tool (/usr/sbin/sendversioninfo) that would send up-to-date version information to the SDN. This tool should be re-enabled.
There are no notes attached to this issue.





View Issue Details
157 [ClearCenter] app-remote-backup - Remote Server Backup feature always 2010-10-07 12:00 2011-02-07 22:33
dloper  
dsokoloski  
low  
assigned  
open  
none    
none  
   
General improvements to remote backup
This is a list of general improvements desired for the Remote Backup module. These elements should be added, time permitting, to the new module under the 6.x framework. This is not intended for 5.x.

- Add partial selection method to custom backup selection. (the / paradigm commonly used)
- Add the ability to select individual flexshares instead of all of them.
- Add the ability to exclude the .trash folder of flexshares.

Notes
(0000298)
user2   
2010-10-12 13:01   
Feel free to split this up into separate tracker issues.