Correct PPTP server firewall rules chain.
[tomato/davidwu.git] / release / src / router / xl2tpd / packaging / suse / xl2tpd.spec
blobc86c2df8be0a7efffb30da1927fcf5e51207965d
1 Summary: Layer 2 Tunnelling Protocol Daemon (RFC 2661)
2 Name: xl2tpd
3 Version: 1.3.1
4 Release: 1%{?dist}
5 License: GPLv2
6 Url: http://www.xelerance.com/software/xl2tpd/
7 Group: Productivity/Networking/Other
8 Source0: http://www.xelerance.com/software/xl2tpd/xl2tpd-%{version}.tar.gz
9 BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
10 Requires: ppp >= 2.4.3
11 BuildRequires: libpcap-devel
12 Obsoletes: l2tpd < 0.69
13 Provides: l2tpd = 0.69
14 Requires(post): /sbin/chkconfig
15 Requires(preun): /sbin/chkconfig
16 Requires(preun): /sbin/service
18 %description
19 xl2tpd is an implementation of the Layer 2 Tunnelling Protocol (RFC 2661).
20 L2TP allows you to tunnel PPP over UDP. Some ISPs use L2TP to tunnel user
21 sessions from dial-in servers (modem banks, ADSL DSLAMs) to back-end PPP
22 servers. Another important application is Virtual Private Networks where
23 the IPsec protocol is used to secure the L2TP connection (L2TP/IPsec,
24 RFC 3193). The L2TP/IPsec protocol is mainly used by Windows and
25 Mac OS X clients. On Linux, xl2tpd can be used in combination with IPsec
26 implementations such as Openswan.
27 Example configuration files for such a setup are included in this RPM.
29 xl2tpd works by opening a pseudo-tty for communicating with pppd.
30 It runs completely in userspace but supports kernel mode L2TP.
32 xl2tpd supports IPsec SA Reference tracking to enable overlapping internak
33 NAT'ed IP's by different clients (eg all clients connecting from their
34 linksys internal IP 192.168.1.101) as well as multiple clients behind
35 the same NAT router.
37 xl2tpd supports the pppol2tp kernel mode operations on 2.6.23 or higher,
38 or via a patch in contrib for 2.4.x kernels.
40 Xl2tpd is based on the 0.69 L2TP by Jeff McAdams <jeffm@iglou.com>
41 It was de-facto maintained by Jacco de Leeuw <jacco2@dds.nl> in 2002 and 2003.
43 %prep
44 %setup -q
46 %build
47 make DFLAGS="$RPM_OPT_FLAGS -g -DDEBUG_PPPD -DDEBUG_CONTROL -DDEBUG_ENTROPY -DTRUST_PPPD_TO_DIE"
49 %install
50 make PREFIX=%{_prefix} DESTDIR=%{buildroot} MANDIR=%{buildroot}/%{_mandir} install
51 install -p -D -m644 examples/xl2tpd.conf %{buildroot}%{_sysconfdir}/xl2tpd/xl2tpd.conf
52 install -p -D -m644 examples/ppp-options.xl2tpd %{buildroot}%{_sysconfdir}/ppp/options.xl2tpd
53 install -p -D -m600 doc/l2tp-secrets.sample %{buildroot}%{_sysconfdir}/xl2tpd/l2tp-secrets
54 install -p -D -m600 examples/chapsecrets.sample %{buildroot}%{_sysconfdir}/ppp/chap-secrets.sample
55 install -p -D -m755 packaging/suse/xl2tpd.init %{buildroot}%{_initrddir}/xl2tpd
56 ln -sf /etc/init.d/xl2tpd $RPM_BUILD_ROOT/usr/sbin/rcxl2tpd
57 install -p -D -m755 -d %{buildroot}%{_localstatedir}/run/xl2tpd
60 %clean
61 rm -rf %{buildroot}
63 %post
64 %{fillup_and_insserv xl2tpd}
66 # if we migrate from l2tpd to xl2tpd, copy the configs
67 if [ -f /etc/l2tpd/l2tpd.conf ]
68 then
69 echo "Old /etc/l2tpd configuration found, migrating to /etc/xl2tpd"
70 mv /etc/xl2tpd/xl2tpd.conf /etc/xl2tpd/xl2tpd.conf.rpmsave
71 cat /etc/l2tpd/l2tpd.conf | sed "s/options.l2tpd/options.xl2tpd/" > /etc/xl2tpd/xl2tpd.conf
72 mv /etc/ppp/options.xl2tpd /etc/ppp/options.xl2tpd.rpmsave
73 mv /etc/ppp/options.l2tpd /etc/ppp/options.xl2tpd
74 mv /etc/xl2tpd/l2tp-secrets /etc/xl2tpd/l2tpd-secrets.rpmsave
75 cp -pa /etc/l2tpd/l2tp-secrets /etc/xl2tpd/l2tp-secrets
80 %preun
81 %stop_on_removal xl2tpd
82 exit 0
84 %postun
85 %restart_on_update xl2tpd
86 %insserv_cleanup
87 exit 0
89 %files
90 %defattr(-,root,root)
91 %doc BUGS CHANGES CREDITS LICENSE README.* TODO doc/rfc2661.txt
92 %doc doc/README.patents examples/chapsecrets.sample
93 %{_sbindir}/rcxl2tpd
94 %{_sbindir}/xl2tpd
95 %{_sbindir}/xl2tpd-control
96 %{_bindir}/pfc
97 %{_mandir}/*/*
98 %dir %{_sysconfdir}/xl2tpd
99 %config(noreplace) %{_sysconfdir}/xl2tpd/*
100 %config(noreplace) %{_sysconfdir}/ppp/*
101 %attr(0755,root,root) %{_initrddir}/xl2tpd
102 %dir %{_localstatedir}/run/xl2tpd
104 %changelog
105 * Sun Oct 26 2008 Paul Wouters <paul@xelerance.com> 1.2.2-1
106 - Updated Suse init scripts and spec file
107 - Added pfc for pppd's precompiled-active-filter
109 * Fri Apr 18 2008 Paul Wouters <paul@xelerance.com> 1.2.1-1
110 - Updated Suse init scripts and spec file
112 * Tue Jun 26 2007 Paul Wouters <paul@xelerance.com> 1.1.11-1
113 - Minor changes to spec file to accomodate new README files
115 * Fri Feb 23 2007 Paul Wouters <paul@xelerance.com> 1.1.08-1
116 - Upgraded to 1.1.08
117 - This works around the ppp-2.4.2-6.4 issue of not dying on SIGTERM
119 * Mon Feb 19 2007 Paul Wouters <paul@xelerance.com> 1.1.07-2
120 - Upgraded to 1.1.07
121 - Fixes from Tuomo Soini for pidfile handling with Fedora
122 - Fix hardcoded version for Source in spec file.
124 * Thu Dec 7 2006 Paul Wouters <paul@xelerance.com> 1.1.06-5
125 - Changed space/tab replacing method
127 * Wed Dec 6 2006 Paul Wouters <paul@xelerance.com> 1.1.06-4
128 - Added -p to keep original timestamps
129 - Added temporary hack to change space/tab in init file.
130 - Added /sbin/service dependancy
132 * Tue Dec 5 2006 Paul Wouters <paul@xelerance.com> 1.1.06-3
133 - Added Requires(post) / Requires(preun)
134 - changed init file to create /var/run/xl2tpd fixed a tab/space
135 - changed control file to be within /var/run/xl2tpd/
137 * Tue Dec 5 2006 Paul Wouters <paul@xelerance.com> 1.1.06-2
138 - Changed Mr. Karlsen's name to not be a utf8 problem
139 - Fixed Obosoletes/Provides to be more specific wrt l2tpd.
140 - Added dist tag which accidentally got deleted.
142 * Mon Dec 4 2006 Paul Wouters <paul@xelerance.com> 1.1.06-1
143 - Rebased spec file on Fedora Extras copy, but using xl2tpd as package name
145 * Sun Nov 27 2005 Paul Wouters <paul@xelerance.com> 0.69.20051030
146 - Pulled up sourceforget.net CVS fixes.
147 - various debugging added, but debugging should not be on by default.
148 - async/sync conversion routines must be ready for possibility that the read
149 will block due to routing loops.
150 - refactor control socket handling.
151 - move all logic about pty usage to pty.c. Try ptmx first, if it fails try
152 legacy ptys
153 - rename log() to l2tp_log(), as "log" is a math function.
154 - if we aren't deamonized, then log to stderr.
155 - added install: and DESTDIR support.
157 * Thu Oct 20 2005 Paul Wouters <paul@xelerance.com> 0.69-13
158 - Removed suse/mandrake specifics. Comply for Fedora Extras guidelines
160 * Tue Jun 21 2005 Jacco de Leeuw <jacco2@dds.nl> 0.69-12jdl
161 - Added log() patch by Paul Wouters so that l2tpd compiles on FC4.
163 * Sat Jun 4 2005 Jacco de Leeuw <jacco2@dds.nl>
164 - l2tpd.org has been hijacked. Project moved back to SourceForge:
165 http://l2tpd.sourceforge.net
167 * Tue May 3 2005 Jacco de Leeuw <jacco2@dds.nl>
168 - Small Makefile fixes. Explicitly use gcc instead of cc.
169 Network services library was not linked on Solaris due to typo.
171 * Thu Mar 17 2005 Jacco de Leeuw <jacco2@dds.nl> 0.69-11jdl
172 - Choosing between SysV or BSD style ptys is now configurable through
173 a compile-time boolean "unix98pty".
175 * Fri Feb 4 2005 Jacco de Leeuw <jacco2@dds.nl>
176 - Added code from Roaring Penguin (rp-l2tp) to support SysV-style ptys.
177 Requires the N_HDLC kernel module.
179 * Fri Nov 26 2004 Jacco de Leeuw <jacco2@dds.nl>
180 - Updated the README.
182 * Wed Nov 10 2004 Jacco de Leeuw <jacco2@dds.nl> 0.69-10jdl
183 - Patch by Marald Klein and Roger Luethi. Fixes writing PID file.
184 (http://l2tpd.graffl.net/msg01790.html)
185 Long overdue. Rereleasing 10jdl.
187 * Tue Nov 9 2004 Jacco de Leeuw <jacco2@dds.nl> 0.69-10jdl
188 - [SECURITY FIX] Added fix from Debian because of a bss-based
189 buffer overflow.
190 (http://www.mail-archive.com/l2tpd-devel@l2tpd.org/msg01071.html)
191 - Mandrake's FreeS/WAN, Openswan and Strongswan RPMS use configuration
192 directories /etc/{freeswan,openswan,strongswan}. Install our
193 configuration files to /etc/ipsec.d and create symbolic links in
194 those directories.
196 * Tue Aug 18 2004 Jacco de Leeuw <jacco2@dds.nl>
197 - Removed 'leftnexthop=' lines. Not relevant for recent versions
198 of FreeS/WAN and derivates.
200 * Tue Jan 20 2004 Jacco de Leeuw <jacco2@dds.nl> 0.69-9jdl
201 - Added "noccp" because of too much MPPE/CCP messages sometimes.
203 * Wed Dec 31 2003 Jacco de Leeuw <jacco2@dds.nl>
204 - Added patch in order to prevent StopCCN messages.
206 * Sat Aug 23 2003 Jacco de Leeuw <jacco2@dds.nl>
207 - MTU/MRU 1410 seems to be the lowest possible for MSL2TP.
208 For Windows 2000/XP it doesn't seem to matter.
209 - Typo in l2tpd.conf (192.168.128/25).
211 * Fri Aug 8 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-8jdl
212 - Added MTU/MRU 1400 to options.l2tpd. I don't know the optimal
213 value but some apps had problems with the default value.
215 * Fri Aug 1 2003 Jacco de Leeuw <jacco2@dds.nl>
216 - Added workaround for the missing hostname bug in the MSL2TP client
217 ('Specify your hostname', error 629: "You have been disconnected
218 from the computer you are dialing").
220 * Thu Jul 20 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-7jdl
221 - Added the "listen-addr" global parameter for l2tpd.conf. By
222 default, the daemon listens on *all* interfaces. Use
223 "listen-addr" if you want it to bind to one specific
224 IP address (interface), for security reasons. (See also:
225 http://www.jacco2.dds.nl/networking/freeswan-l2tp.html#Firewallwarning)
226 - Explained in l2tpd.conf that two different IP addresses should be
227 used for 'listen-addr' and 'local ip'.
228 - Modified init script. Upgrades should work better now. You
229 still need to start/chkconfig l2tpd manually.
230 - Renamed the example Openswan .conf files to better reflect
231 the situation. There are two variants using different portselectors.
232 Previously I thought Windows 2000/XP used portselector 17/0
233 and the rest used 17/1701. But with the release of an updated
234 IPsec client by Microsoft, it turns out that 17/0 must have
235 been a mistake: the updated client now also uses 17/1701.
237 * Mon Apr 10 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-6jdl
238 - Changed sample chap-secrets to be valid only for specific
239 IP addresses.
241 * Thu Mar 13 2003 Bernhard Thoni <tech-role@tronicplanet.de>
242 - Adjustments for SuSE8.x (thanks, Bernhard!)
243 - Added sample chap-secrets.
245 * Thu Mar 6 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-5jdl
246 - Replaced Dominique's patch by Damion de Soto's, which does not
247 depend on the N_HDLC kernel module.
249 * Wed Feb 26 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-4jdl
250 - Seperate example config files for Win9x (MSL2TP) and Win2K/XP
251 due to left/rightprotoport differences.
252 Fixing preun for Red Hat.
254 * Mon Feb 3 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-3jdl
255 - Mandrake uses /etc/freeswan/ instead of /etc/ipsec.d/
256 Error fixed: source6 was used for both PSK and CERT.
258 * Wed Jan 29 2003 Jacco de Leeuw <jacco2@dds.nl> 0.69-3jdl
259 - Added Dominique Cressatti's pty patch in another attempt to
260 prevent the Windows 2000 Professional "loopback detected" error.
261 Seems to work!
263 * Wed Dec 25 2002 Jacco de Leeuw <jacco2@dds.nl> 0.69-2jdl
264 - Added 'connect-delay' to PPP parameters in an attempt to
265 prevent the Windows 2000 Professional "loopback detected" error.
266 Didn't seem to work.
268 * Fri Dec 13 2002 Jacco de Leeuw <jacco2@dds.nl> 0.69-1jdl
269 - Did not build on Red Hat 8.0. Solved by adding comments(?!).
270 Bug detected in spec file: chkconfig --list l2tpd does not work
271 on Red Hat 8.0. Not important enough to look into yet.
273 * Sun Nov 17 2002 Jacco de Leeuw <jacco2@dds.nl> 0.69-1jdl
274 - Tested on Red Hat, required some changes. No gprintf. Used different
275 pty patch, otherwise wouldn't run. Added buildroot sanity check.
277 * Sun Nov 10 2002 Jacco de Leeuw <jacco2@dds.nl>
278 - Specfile adapted from Mandrake Cooker. The original RPM can be
279 retrieved through:
280 http://www.rpmfind.net/linux/rpm2html/search.php?query=l2tpd
281 - Config path changed from /etc/l2tp/ to /etc/l2tpd/
282 (Seems more logical and rp-l2tp already uses /etc/l2tp/).
283 - Do not run at boot or install. The original RPM uses a config file
284 which is completely commented out, but it still starts l2tpd on all
285 interfaces. Could be a security risk. This RPM does not start l2tpd,
286 the sysadmin has to edit the config file and start l2tpd explicitly.
287 - Renamed patches to start with l2tpd-
288 - Added dependencies for pppd, glibc-devel.
289 - Use %%{name} as much as possible.
290 - l2tp-secrets contains passwords, thus should not be world readable.
291 - Removed dependency on rpm-helper.
293 * Mon Oct 21 2002 Lenny Cartier <lenny@mandrakesoft.com> 0.69-3mdk
294 - from Per 0yvind Karlsen <peroyvind@delonic.no> :
295 - PreReq and Requires
296 - Fix preun_service
298 * Thu Oct 17 2002 Per 0yvind Karlsen <peroyvind@delonic.no> 0.69-2mdk
299 - Move l2tpd from /usr/bin to /usr/sbin
300 - Added SysV initscript
301 - Patch0
302 - Patch1
304 * Thu Oct 17 2002 Per 0yvind Karlsen <peroyvind@delonic.no> 0.69-1mdk
305 - Initial release