Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Curl and ntp updates on pfSense 2.3.3-RELEASE-p1?

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    12 Posts 6 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      kpa
      last edited by

      Yep. The update process should be split into two parts where one offers a "firmware" update and another one that handles the micro-updates and shows the update status of individual packages that may have updates available.

      1 Reply Last reply Reply Quote 0
      • D Offline
        dread
        last edited by

        Hi,

        "ntpd –version" :

        ntpd 4.2.8p10@1.3728-o Wed Apr 12 17:38:38 UTC 2017 (1)

        "pkg info ntp" :

        Name          : ntp
        Version        : 4.2.8p10_2

        ntpd.log :

        ...
        Apr 13 02:09:51 gateway ntpd[35839]: ntpd 4.2.8p10@1.3728-o Wed Apr 12 17:38:38 UTC 2017 (1): Starting
        …

        I did get the announcement/security note (FreeBSD-SA-17:03.ntp) for FreeBSD but I did not find any for pfSense.

        And the webgui vs command line did not provide the same information.

        I guess everything else is ok but we are missing announcements? Would be great to get security updates and security announcements for pfSense quickly after they have released for FreeBSD.

        I'm running pfSense SG-4860. 1-year support period is over.

        Thanks a lot,

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          So you want pfsense to announce every update for all the packages in the repository?  Going to be a lot of announcements ;)

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • P Offline
            phil.davis
            last edited by

            @johnpoz:

            So you want pfsense to announce every update for all the packages in the repository?  Going to be a lot of announcements ;)

            pfSense is a "turnkey" firewall-router solution for which end-users do not even need to know that there is FreeBSD underneath, and do not need to know what other pieces (FreeBSD packages) make up the "core". So, IMO, there should be some way to announce parts of the pfSense "core" that have updates (tested and) released (with links to relevant FreeBSD or other security and release notes). Those maintaining the pfSense list of what FreeBSD packages/versions are offered for pfSense do need to do some level of testing to verify that a new/patch release of some "core" FreeBSD package does not cause regression/bugs in the pfSense software's use of that package.

            Actually I would be inclined to bump the pfSense patch release number whenever a (set of) underlying core FreeBSD package(s) are made available - e.g. 2.3.3-p2 to 2.3.3-p3. Then that will show up on the webGUI as a pfSense "patch" release, and that patch release will be associated with a well-defined set of underlying "core" FreeBSD package+versions.

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              You could say the same thing about ubuntu or any other linux or bsd distro.. The overall system is "turn key" solution and the end user does not need to know what is underneath.. Same goes for windows or any other OS ;)

              They don't bump their release number everytime a package or patch gets released/updated.

              So we are going to be getting very high P numbers…  Oh your on p21, you need to make sure your on p23 ;)

              You make a valid point of testing the packages as they pull them into the official pfsense repository, you have to assume they are being tested??  But are they?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              1 Reply Last reply Reply Quote 0
              • D Offline
                dread
                last edited by

                @johnpoz:

                So you want pfsense to announce every update for all the packages in the repository?  Going to be a lot of announcements ;)

                Thank you both for your reply.

                I basically want an announcement of every security related package update if the package is included in the pfSense "base" or "core" (like ntpd). The update system should work both from Web GUI and command line as well, just if it's possible.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  We haven't rolled a formal patch release for those since that would involve a lot more work, but we wanted to get the fixes out there for people to use if they were worried.

                  None of the vulnerabilities that I saw in NTP or cURL were critical in the way they are used on pfSense. The NTP issues were config parsing (irrelevant), a local crash from someone who can create a device (would have to already be root, so again irrelevant), and a remote DOS where someone would have to be able to spoof every configured time server (weird and maybe relevant but still just a DOS and difficult to exploit). cURL's was in command line parsing, which again, isn't relevant in how it's used on pfSense.

                  If we change our minds and make a patch release we'll put a note in the release announcement and whatnot, but for now, people concerned about those can get the pkg update.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    "We haven't rolled a formal patch release for those since that would involve a lot more work"

                    lot more work I think is an understatement ;)

                    Sounds like they want pfsense to announce every time there is a release of a new package that is put into the pfsense repository..  You prob get hit from both sides.. If you don't include it in the pf repository then you will get people complaining that hey there was a new release of package xyz why was in not included.  And your getting hey I see you updated package xyz why was it not announced..

                    With some of the sub packages its even difficult to find the release notes of what was changed, etc. or why.. Lets use a popular linux distro as an example.  Is there one place I can go and look for every package update of say ubuntu?  If I am curious when I run apt-get update, and then apt-get upgrade and see packages that are updated I have to go track down the specific package on some place dedicated to that package to find out what was changed and or why etc..

                    If someone is aware of a list somewhere the popular distro's list the details of every package in chron order of update and details I would love to see that ;) And they sure don't update their release build number to include an incremental number everytime a package is updated.  It very well could be a bug fix the package maintainer released that has no security implications or might even be a simple typo fix or something, etc.

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      coxhaus
                      last edited by

                      I run NTP on pfsense.  Do I need to track and perform separate updates to NTP?  I don't need every update just the critical ones.

                      1 Reply Last reply Reply Quote 0
                      • D Offline
                        dread
                        last edited by

                        @jimp:

                        We haven't rolled a formal patch release for those since that would involve a lot more work, but we wanted to get the fixes out there for people to use if they were worried.

                        Thank you for your explanation. For me personally, it’s ok to get smaller updates and minor security fixes just by running pkg from command line. Thanks a lot for the patches. Good to know how this is going on.

                        For those concerned, please just check (my guess this is the issue here):

                        FreeBSD-SA-17:03.ntp

                        https://www.freebsd.org/security/advisories/FreeBSD-SA-17:03.ntp.asc

                        I really appreciate the availability of the patches anyway and the hard work you are doing for pfSense.

                        :)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.