Page MenuHomeVyOS Platform
Feed All Stories

Feb 25 2023

c-po changed the status of T5034: Migrate multicast CLI node to valueLess from Open to In progress.
Feb 25 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po created T5034: Migrate multicast CLI node to valueLess.
Feb 25 2023, 9:15 PM · VyOS 1.4 Sagitta
c-po closed T4948: pppoe: add CLI option to allow definition of host-uniq flag as Resolved.
Feb 25 2023, 9:12 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T4948: pppoe: add CLI option to allow definition of host-uniq flag from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:12 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4992: Incorrect check is_local_address for bgp neighbor with option ip_nonlocal_bind set as Resolved.
Feb 25 2023, 9:12 PM · VyOS 1.3 Equuleus (1.3.3)
c-po moved T4992: Incorrect check is_local_address for bgp neighbor with option ip_nonlocal_bind set from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:11 PM · VyOS 1.3 Equuleus (1.3.3)
c-po removed a project from T4997: Add DHCP client user hooks dir: VyOS 1.3 Equuleus (1.3.3).
Feb 25 2023, 9:11 PM · VyOS 1.4 Sagitta
c-po closed T5007: Interface multicast setting is invalid as Resolved.
Feb 25 2023, 9:11 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5007: Interface multicast setting is invalid from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:10 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine as Resolved.
Feb 25 2023, 9:10 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:10 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T4978: KeyError: 'memory' container_config['memory'] on upgrading to 1.4-rolling-202302041536 as Resolved.
Feb 25 2023, 9:10 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po moved T4978: KeyError: 'memory' container_config['memory'] on upgrading to 1.4-rolling-202302041536 from Need Triage to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:10 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
c-po closed T5017: Bug with validator interface-name as Resolved.
Feb 25 2023, 9:09 PM · VyOS 1.3 Equuleus (1.3.3)
c-po moved T5017: Bug with validator interface-name from In Progress to Finished on the VyOS 1.3 Equuleus (1.3.3) board.
Feb 25 2023, 9:09 PM · VyOS 1.3 Equuleus (1.3.3)
c-po committed rVYOSONEX3bad1d0adb1c: python: T5026: Replace deprecated Python modules crypt, spwd (authored by sarthurdev).
Feb 25 2023, 9:07 PM
doctorpangloss added a comment to T5033: generate-public-key command fails for address with multiple public keys like GitHub.

Yes, apparently so from GitHub.

Feb 25 2023, 8:12 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav edited projects for T5033: generate-public-key command fails for address with multiple public keys like GitHub, added: VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus (1.3.4).

Do those keys always without an "identifier"?
I mean foo@localhost

ssh-rsa AAA....
Feb 25 2023, 8:11 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
Viacheslav closed T5027: OpenVPN options and site-to-site cannot pass smoketest as Resolved.
Feb 25 2023, 6:56 PM · VyOS 1.4 Sagitta
Coopercentral added a comment to T4943: Radius SSH login displays "permission denied" on 1.4 rolling release.

Hello - I upgraded to the latest rolling release (1.4-rolling-202302250317), and it appears to be working. I am able to login with a radius account successfully. Thank you for your efforts! I see in you PR's above, the second link is to change the shell from "bash" to "vbash". It appears once I login with a radius privileged account, the shell continues to default to "bash":

Feb 25 2023, 1:24 PM · VyOS 1.4 Sagitta
fernando added a comment to T4074: Add NETCONF server with YANG data modeling .

including information about Netopee2/sysrepo services, how to integrate it with FRR, where we can utilize the advantages netconf/yang :

Feb 25 2023, 1:23 PM · VyOS Rolling
Viacheslav changed the status of T4943: Radius SSH login displays "permission denied" on 1.4 rolling release from In progress to Needs testing.
Feb 25 2023, 5:30 AM · VyOS 1.4 Sagitta

Feb 24 2023

doctorpangloss created T5033: generate-public-key command fails for address with multiple public keys like GitHub.
Feb 24 2023, 9:02 PM · VyOS 1.4 Sagitta, VyOS 1.3 Equuleus (1.3.3)
c-po committed rVYOSONEX893ead2fe9b3: login: T1948: drop absolut path to /usr/libexec/vyos, re-use vyos.defaults.
Feb 24 2023, 9:01 PM
zsdc committed rVYOSONEX32a4415191ca: login: T4943: Fixed 2FA + RADIUS compatibility.
Feb 24 2023, 9:00 PM
GitHub <noreply@github.com> committed rVYOSONEXc0b5b3d52d46: Merge pull request #1851 from zdc/T4943-sagitta (authored by c-po).
Feb 24 2023, 9:00 PM
jestabro closed T5030: HTTPS-API delete key without id error as Resolved.
Feb 24 2023, 8:15 PM · VyOS 1.4 Sagitta
devon added a comment to T5032: VRRP aware DHCP relay.

I looked into it, but there doesn't seem to be a way to temporarily disable a particular interface in DHCP relay.

Feb 24 2023, 7:32 PM · VyOS 1.4 Sagitta
n.fort added a comment to T5032: VRRP aware DHCP relay.

Have you try getting same result using VRRP transitions scripts?

Feb 24 2023, 7:28 PM · VyOS 1.4 Sagitta
devon added a comment to T5032: VRRP aware DHCP relay.

PR https://github.com/vyos/vyos-1x/pull/1852

Feb 24 2023, 7:26 PM · VyOS 1.4 Sagitta
devon created T5032: VRRP aware DHCP relay.
Feb 24 2023, 7:21 PM · VyOS 1.4 Sagitta
Memphis created T5031: Users Level.
Feb 24 2023, 6:31 PM · VyOS Rolling
zsdc added a comment to T4943: Radius SSH login displays "permission denied" on 1.4 rolling release.

PRs:
https://github.com/vyos/libnss-mapuser/pull/7
https://github.com/vyos/libpam-radius-auth/pull/6
https://github.com/vyos/vyos-1x/pull/1851

Feb 24 2023, 6:26 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXd3fa059264bf: T5029: Change nginx default root directory.
Feb 24 2023, 4:38 PM
GitHub <noreply@github.com> committed rVYOSONEX73ceaaafa9e7: Merge pull request #1848 from sever-sever/T5029 (authored by c-po).
Feb 24 2023, 4:38 PM
jestabro committed rVYOSONEXb0bc3ce9513f: http-api: T5030: fix missing check on delete keys id tag or key value.
Feb 24 2023, 4:37 PM
GitHub <noreply@github.com> committed rVYOSONEX42e758dde8e0: Merge pull request #1850 from jestabro/T5030 (authored by c-po).
Feb 24 2023, 4:37 PM
Viacheslav committed rVYOSONEXf1dc4ef24173: T5029: Fix Regex for nginx to find a better match.
Feb 24 2023, 4:37 PM
GitHub <noreply@github.com> committed rVYOSONEXb49f27ce14b7: Merge pull request #1849 from sever-sever/T5029-regex (authored by c-po).
Feb 24 2023, 4:37 PM
jestabro added a comment to T5030: HTTPS-API delete key without id error.

https://github.com/vyos/vyos-1x/pull/1850

Feb 24 2023, 3:53 PM · VyOS 1.4 Sagitta
Viacheslav updated the task description for T5029: Nginx change default root directory and fix regex.
Feb 24 2023, 3:45 PM · VyOS 1.4 Sagitta
jestabro edited a custom field on T5030: HTTPS-API delete key without id error.
Feb 24 2023, 3:32 PM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5029: Nginx change default root directory and fix regex.

PR https://github.com/vyos/vyos-1x/pull/1848
PR https://github.com/vyos/vyos-1x/pull/1849

Feb 24 2023, 3:30 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXbaa8eb854348: openconnect: T4955: Removed wrong authserver in radiusclient.conf.
Feb 24 2023, 3:15 PM
GitHub <noreply@github.com> committed rVYOSONEX0420cea6f0c6: Merge pull request #1794 from aapostoliuk/T4955-equuleus (authored by c-po).
Feb 24 2023, 3:15 PM
a.apostoliuk committed rVYOSONEX391b7333c836: macsec: T5008: Changed length of CKN to (2..64 hex-digits).
Feb 24 2023, 3:13 PM
GitHub <noreply@github.com> committed rVYOSONEX35482c42691c: Merge pull request #1846 from aapostoliuk/T5008-equuleus (authored by c-po).
Feb 24 2023, 3:13 PM
jestabro claimed T5030: HTTPS-API delete key without id error.
Feb 24 2023, 2:33 PM · VyOS 1.4 Sagitta
a.apostoliuk committed rVYOSONEXf4ecfaf1cd1a: ipsec: T4985: Changed 'reset vpn ipsec-peer' to use vici library.
Feb 24 2023, 2:33 PM
GitHub <noreply@github.com> committed rVYOSONEXeaea1789f880: Merge pull request #1847 from aapostoliuk/T4985-2-sagitta (authored by c-po).
Feb 24 2023, 2:33 PM
a.apostoliuk changed the status of T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine from Needs testing to In progress.
Feb 24 2023, 2:30 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav created T5030: HTTPS-API delete key without id error.
Feb 24 2023, 2:14 PM · VyOS 1.4 Sagitta
jestabro closed T5006: Http api segfault with concurrent requests as Resolved.
Feb 24 2023, 2:00 PM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
Viacheslav created T5029: Nginx change default root directory and fix regex.
Feb 24 2023, 1:45 PM · VyOS 1.4 Sagitta
zsdc changed the status of T4943: Radius SSH login displays "permission denied" on 1.4 rolling release from Open to In progress.
Feb 24 2023, 9:49 AM · VyOS 1.4 Sagitta
a.apostoliuk added a project to T5008: MACsec CKN of 32 chars is not allowed in CLI, but works fine: VyOS 1.3 Equuleus (1.3.3).
Feb 24 2023, 9:25 AM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
ammmze added a comment to T5006: Http api segfault with concurrent requests.

Looks like a new nightly rolling update was finally released (vyos-1.4-rolling-202302231931-amd64) 🎉 I just installed it and so far it looks good. I'm no longer getting the 502 errors / segfault. Thanks again!

Feb 24 2023, 3:56 AM · VyOS 1.3 Equuleus (1.3.4), VyOS 1.4 Sagitta
anon3fe35 added a comment to T5028: Add package exfatprogs to VyOS.

I can confirm adding this packaged worked, you can now mount with

Feb 24 2023, 12:00 AM · VyOS 1.4 Sagitta

Feb 23 2023

anon3fe35 added a comment to T5028: Add package exfatprogs to VyOS.

It looks like I also need to add the exfat-fuse package inorder to get the helpers for mounting filesystems.

Feb 23 2023, 11:12 PM · VyOS 1.4 Sagitta
jestabro added a comment to T3871: Resolve unexpected interface name reordering.

The above repos are suitable for testing: basic tests in vm's and a Protecli device look fine. Note that the vyos-1x repo artificially disables the potential config mode reordering in order to confirm tests of vyos-interface-monitor.:
https://github.com/vyos/vyos-1x/commit/02d874e65262cbd53b413b3eef659b8e7d78bf31

Feb 23 2023, 7:58 PM · Bugs, VyOS 1.4 Sagitta (1.4.0-GA)
Viacheslav committed rVYOSONEX3fd4d5b9c595: T5027: Enable legacy provider to support current ciphers.
Feb 23 2023, 7:23 PM
GitHub <noreply@github.com> committed rVYOSONEXb652a66119c7: Merge pull request #1842 from sever-sever/T5027 (authored by c-po).
Feb 23 2023, 7:23 PM
Viacheslav committed rVYOSONEX05d0f593bbfe: T5007: Fix multicast implementation for the tunnel interfaces.
Feb 23 2023, 7:22 PM
GitHub <noreply@github.com> committed rVYOSONEXaa693e13db22: Merge pull request #1843 from sever-sever/T5007-eq (authored by c-po).
Feb 23 2023, 7:22 PM
dmbaturin created 1.2.9.
Feb 23 2023, 5:20 PM
Viacheslav added a comment to T5007: Interface multicast setting is invalid.

PR https://github.com/vyos/vyos-1x/pull/1843

Feb 23 2023, 3:31 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
Viacheslav added a project to T5007: Interface multicast setting is invalid: VyOS 1.3 Equuleus (1.3.3).
Feb 23 2023, 3:31 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta
ordex added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

Hey @fernando thanks for your comment.
Personally I haven't tried openvpn2.6.0 + ovpn-dco on Debian 12 yet. However, there should be no real difference as ovpn-dco can happily run up to linux-6.1/6.2 as well.

Feb 23 2023, 3:21 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5028: Add package exfatprogs to VyOS from In progress to Needs testing.
Feb 23 2023, 3:17 PM · VyOS 1.4 Sagitta
fernando added a comment to T4974: OpenVPN- Data Channel Offload(DCO).

@ordex nice your reply here , we're planning to introduce it in our last upgrade version( we need to upgrade openvpn version to work with opvn-dco ) , Di you try it on Debian 12? My current environment was over Debian 11, if you have any suggestion it will good to know.

Feb 23 2023, 3:16 PM · VyOS 1.4 Sagitta
Viacheslav closed T5013: Extend accelppp.py op-mode to get subnet start stop info from config, a subtask of T4564: Root task for rewriting [op-mode] to vyos.opmode format, as Resolved.
Feb 23 2023, 2:48 PM · VyOS Rolling
Viacheslav closed T5013: Extend accelppp.py op-mode to get subnet start stop info from config as Resolved.
Feb 23 2023, 2:48 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEX4298941471eb: T5013: accelppp replace cpu key to cpu_load_percentage op-mode.
Feb 23 2023, 2:47 PM
Viacheslav committed rVYOSONEX9e2e1700c9ea: T5013: Extend accelppp op-mode script to get statistic.
Feb 23 2023, 2:47 PM
GitHub <noreply@github.com> committed rVYOSONEX702441a072bc: Merge pull request #1829 from sever-sever/T5013 (authored by dmbaturin).
Feb 23 2023, 2:47 PM
Viacheslav committed rVYOSONEX86c8117a75e4: T5017: Add interface ifbX to constraint interface-name.
Feb 23 2023, 2:21 PM
GitHub <noreply@github.com> committed rVYOSONEXab16444374d9: Merge pull request #1845 from sever-sever/T5017 (authored by dmbaturin).
Feb 23 2023, 2:21 PM
Viacheslav added a comment to T5017: Bug with validator interface-name.

PR https://github.com/vyos/vyos-1x/pull/1845

Feb 23 2023, 1:49 PM · VyOS 1.3 Equuleus (1.3.3)
Viacheslav changed the status of T5028: Add package exfatprogs to VyOS from Open to In progress.
Feb 23 2023, 1:21 PM · VyOS 1.4 Sagitta
anon3fe35 added a comment to T5028: Add package exfatprogs to VyOS.

PR: https://github.com/vyos/vyos-user-utils/pull/4

Feb 23 2023, 1:04 PM · VyOS 1.4 Sagitta
anon3fe35 created T5028: Add package exfatprogs to VyOS.
Feb 23 2023, 12:38 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX6c6fe82ede80: Update README.md (authored by syncer).
Feb 23 2023, 12:23 PM
Viacheslav closed T5002: Add uk (United Kingdom) keymap as Resolved.
Feb 23 2023, 12:17 PM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX82a464fccd84: Update sonar-project.properties (authored by syncer).
Feb 23 2023, 11:24 AM
Viacheslav added a comment to T5027: OpenVPN options and site-to-site cannot pass smoketest.

PR https://github.com/vyos/vyos-1x/pull/1842

vyos@r14:~$ /usr/libexec/vyos/tests/smoke/cli/test_interfaces_openvpn.py
test_openvpn_client_interfaces (__main__.TestInterfacesOpenVPN.test_openvpn_client_interfaces) ... ok
test_openvpn_client_verify (__main__.TestInterfacesOpenVPN.test_openvpn_client_verify) ... ok
test_openvpn_options (__main__.TestInterfacesOpenVPN.test_openvpn_options) ... ok
test_openvpn_server_net30_topology (__main__.TestInterfacesOpenVPN.test_openvpn_server_net30_topology) ... ok
test_openvpn_server_subnet_topology (__main__.TestInterfacesOpenVPN.test_openvpn_server_subnet_topology) ... ok
test_openvpn_server_verify (__main__.TestInterfacesOpenVPN.test_openvpn_server_verify) ... ok
test_openvpn_site2site_interfaces_tun (__main__.TestInterfacesOpenVPN.test_openvpn_site2site_interfaces_tun) ... ok
test_openvpn_site2site_verify (__main__.TestInterfacesOpenVPN.test_openvpn_site2site_verify) ... ok
Feb 23 2023, 11:11 AM · VyOS 1.4 Sagitta
Viacheslav triaged T5027: OpenVPN options and site-to-site cannot pass smoketest as High priority.
Feb 23 2023, 9:58 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5027: OpenVPN options and site-to-site cannot pass smoketest.
secret has been deprecated
    static key mode (non-TLS) is no longer considered "good and secure enough" for today's requirements. Use TLS mode instead. If deploying a PKI CA is considered "too complicated", using --peer-fingerprint makes TLS mode about as easy as using --secret.

https://github.com/OpenVPN/openvpn/blob/release/2.6/Changes.rst

Feb 23 2023, 9:26 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX36dd8914ea4c: Update sonar-project.properties (authored by syncer).
Feb 23 2023, 9:09 AM
Viacheslav added a comment to T5027: OpenVPN options and site-to-site cannot pass smoketest.
Feb 23 2023, 9:02 AM · VyOS 1.4 Sagitta
Viacheslav added a comment to T5027: OpenVPN options and site-to-site cannot pass smoketest.

Config VyOS:

set interfaces openvpn vtun5001 local-address 203.0.113.1
set interfaces openvpn vtun5001 mode 'site-to-site'
set interfaces openvpn vtun5001 remote-address '192.0.2.5'
set interfaces openvpn vtun5001 shared-secret-key 'ovpn_test'
set pki openvpn shared-secret ovpn_test key '9caf354e0f313b3a671d01e62ea2b512346a651dd30a9e51d6c45dc1031f1b0931eabdf7a0ddcbe1a147ff882ccce35dcb5e1d4d6ddb5e909ca012a8d8e16fe50dd332005dff9a836a2852f36e84e27bad07993a8094c56fb0553866ef74c6c5cc6ddb8f4673d3ff300c48068b944bd8ba1100d41f91d156bcd2629ff39837ddcb34d93147a4aabc7e6ad95d5800c82c8ab60ba302d6625a3b26fbfe183fd6c06d884be44edde344fd0ac91a33064529e010eba0c0f495fa44519fd98adb97452a27fb3340bc20efadd68c9538aa4a238c9f58f542e3571ec78790fdd03e678e18631b82edb9358a2c55ce581d68b71881cad0d0419d4cc58c13641f84281260'
set pki openvpn shared-secret ovpn_test version '1'
Feb 23 2023, 9:00 AM · VyOS 1.4 Sagitta
GitHub <noreply@github.com> committed rVYOSONEX772fdfe12365: Update sonar-project.properties (authored by syncer).
Feb 23 2023, 8:59 AM
GitHub <noreply@github.com> committed rVYOSONEX7a99a59b338f: Create build.yml (authored by syncer).
Feb 23 2023, 8:57 AM
Viacheslav created T5027: OpenVPN options and site-to-site cannot pass smoketest.
Feb 23 2023, 8:39 AM · VyOS 1.4 Sagitta

Feb 22 2023

Viacheslav created T5026: Python3 modules crypt and spwd are deprecated.
Feb 22 2023, 6:09 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5025: Time-zone validation failed from In progress to Needs testing.
Feb 22 2023, 5:44 PM · VyOS 1.4 Sagitta
Viacheslav committed rVYOSONEXd95808b5186f: T5025: Fix timezones and validator use timedatectl.
Feb 22 2023, 5:42 PM
GitHub <noreply@github.com> committed rVYOSONEXdcb4a95c7961: Merge pull request #1841 from sever-sever/T5025 (authored by c-po).
Feb 22 2023, 5:42 PM
Viacheslav added a comment to T5025: Time-zone validation failed.

PR https://github.com/vyos/vyos-1x/pull/1841

Feb 22 2023, 5:39 PM · VyOS 1.4 Sagitta
Viacheslav changed the status of T5025: Time-zone validation failed from Open to In progress.
Feb 22 2023, 5:29 PM · VyOS 1.4 Sagitta
Viacheslav closed T5011: Some interface drivers don't support min_mtu and max_mtu and verify_mtu check should be skipped as Resolved.
Feb 22 2023, 5:11 PM · VyOS 1.3 Equuleus (1.3.3), VyOS 1.4 Sagitta