turnkey-cakephp-19.0 (1) turnkey; urgency=low * Update CakePHP to latest upstream version - v5.4.0. * Install CakePHP skeleton App via composer - closes #1591. * Pin the skeleton App release, run its migration code without root privileges, and keep application PHP/configuration read-only to the web service account. * Upgraded base distribution to Debian 13.x/Trixie. * Replace TurnKey custom Debian-Installer based 'di-live' with new custom TurnKey installer built from scratch; 'tkl-installer'. * Updated release signing keys & apt repo keys - now included as 'turnkey-keys' deb package. * Replace legacy '.list' apt remote config files with Deb822 '.sources' files. * "Proper" IPv6 support. May still have some gaps and still requires cosmetic work but fully functional. * Improved fail2ban config: - Increased default findtime (10 minutes) & bumped maxretry (3) to minimize risk of user accidentally locking themself out. - Removed redundant v18.x custom patches. * Include 'zstd' by default to support smaller initramfs that unpacks faster. * Replace 'ifupdown' with 'ifupdown-ng' (and 'ifupdown-ng-compat'). * Replace 'udhcpc' (IPv4 only) with 'dhcpcd-base' (dual stack ipv4/6). Also include custom TurnKey config (if-pre-up & if-post-down scripts provided by 'tkl-dhcpcd-ifupdown-glue') to ensure DHCP config is in sync with /etc/network/interfaces file. * General code cleanup of TurnKey code; build code, build tools and TurnKey custom tools & libraries. Updates include linting, formating and style updates. Still WIP but solid start. * Configuration console (confconsole): - Bugfixes: - Support for firewall config when setting a static IP. Particularly affected OpenVPN (which ships with firewall enabled by default). Closes #2037. - Fix Let's Encrypt integration failing back-to-back runs. Closes #2121. - Features: - "Proper" support for IPv6: - Make ifutil.py module code "IPv6 aware", including reliable management of /etc/network/interfaces with "inet6" stanza/s. - Show IPv6 info on "usage" page - only shown if IPv6 configured. Special thanks to Marcos: https://github.com/marcos-mendez - https://popsolutions.co/ - Misc clean up and improvements in code and packaging. See Confconsole release notes for full details. * Firstboot Initialization (inithooks): - Bugfixes: - Ensure everyboot scripts only run once per boot. - firstboot.d/15regen-sslcert: - Only services which are already running need to be restarted as restart is only to apply updated certs. - firstboot.d/01ipconfig: - Minor bugfix. - Features/improvements and other changes of significance: - Reimplement an 'inithooks.service' and refactor integration with getty1. - Delay start of inithooks/confconsole at boot time to reduce chance of boot messages overwriting inithooks/confconsole. - Developers - please note that hooks with a prefix less than '30' will still run early, so should _always_ be non-interactive. - TurnKey 'init-fence' (blocks web access at firstboot): - Run by default on all builds pre firstboot initialization (previously only enabled on "headless" builds). - New pre-seed variable 'AUTO_RUN' to skip interactive config (re-implements previous "headless" build functionality). - Replace legacy init.d script with systemd 'turnkey-init-fence.service' (& script which is called by the service). - Add support for 'systemctl reload turnkey-init-fence.service' - which restarts 'simplehttpd.py' (init-fence mini web server) but does not disable the firewall rules. - Support for custom init-fence content. - Update dynamically generated SSH information for IPv6 address display. - Add IPv6 support to mini server. - Ensure inithook 'SEC_UPDATES' pre-seed variable test is case insensitive; eliminates risk of unintended behavior when pre-seeding. - Misc clean up and improvements in code and packaging. See Inithooks release notes for full details. * Web management console (webmin): - Upgraded Webmin to latest upstream. - Refactored TurnKey Webmin packaging process to support easier updates; with the intention of following upstream releases as closely as possible (provided via TurnKey apt repo). - Updated default Webmin config: - Listen on IPv6 by default. - Preconfigured IPv6 firewall matching IPv4 rules (but not enabled - as per historical IPv4 default). - Auto redirect http => https. - Default 30 min user logout (can be overridden via login page "remember me" checkbox or webmin "authentication" config). - Updated logging paths and fixed log file rotation. * Backup (tklbam): - Bugfixes: - Fix broken help pager (not sure how long that has been broken!?). - Fix broken tar command (deprecated functionality removed in Debian Trixie). - Features/improvements: - Migrate core program and direct dependency python2 runtime from cpython2 (EOL) to Pypy (still supported - packaged by TurnKey). - Migrate all other components to python3. Note: remaining python2 TKLBAM code port to python3 is in progress but no ETA yet... - Misc clean up and improvements in code and packaging. See TKLBAM release notes for full details. * Misc code cleanup and improvements. * Full overhaul of TurnKey Adminer integration, including moving TurnKey customization files to /etc/adminer (from /usr/share). * Multiple bugfixes/improvments to default Adminer theme. * Updated webserver config; including hardening and Adminer specific log files. * Fail2ban rules to protect Adminer log in. * Limit access to any other databases other than locally installed database. Protects against Adminer being used as a tool to attack a thrid party server. * Modify default Apache mod_ssl conf at build time, rather than overwriting it. Ensures that only explict edits are performed and avoid risk of future Debian updates being overwritten. * Updated SSL/TLS cipher list - "intermediate" level as recommended by Mozilla. Aims to balance security and support for older clients. * Explicitly set elliptic curves offered for ECDH key exchange. * Harderned mod_security defaults: - Block access to all '.' paths by default (e.g. '.env', '.git', etc) to harden security and avoid accidental disclosure of secrets. Note this will break third party Let's Encrypt integrations using HTTP-01 validation - e.g. certbot. TurnKey's integration is unaffected as it uses a custom HTTP server to serve the challenges. - Set additional security headers: X-Content-Type-Options: "nosniff" : - Prevents files from being interpretted as something other than that declared by the content type. Content-Security-Policy "frame-ancestors 'self';" : - Prevents other sites from embedding pages within frames, defends against clickjacking attacks. * Enable HTTP/2 where possible. Note HTTP/2 is not compatable with Apache's mod_php - which is currently the default method that TurnKey LAMP based appliances host PHP applications. TurnKey will migrate to using PHP-FPM in the future. * Redirect HTTP => HTTPS by default. * Note: TLSv1.2 will be disabled by default in a future TurnKey release. * Create default '/var/lib/php/sessions' cache dir and ensure it is writable by the webserver (default PHP session cache location for some PHP apps). -- Jeremy Davis Thu, 06 Aug 2026 15:25:06 +1000 turnkey-cakephp-18.0 (1) turnkey; urgency=low * Latest upstream versiion of CakePHP - v5.0.5. [Anton Pyrogovskyi ] * Use Debian default PHP (v8.2). * Ensure hashfile includes URL to public key - closes #1864. * Include webmin-logviewer module by default - closes #1866. * Upgraded base distribution to Debian 12.x/Bookworm. * Configuration console (confconsole): - Support for DNS-01 Let's Encrypt challenges. [ Oleh Dmytrychenko github: @NitrogenUA ] - Support for getting Let's Encrypt cert via IPv6 - closes #1785. - Refactor network interface code to ensure that it works as expected and supports more possible network config (e.g. hotplug interfaces & wifi). - Show error message rather than stacktrace when window resized to incompatable resolution - closes #1609. [ Stefan Davis ] - Bugfix exception when quitting configuration of mail relay. [ Oleh Dmytrychenko github: @NitrogenUA ] - Improve code quality: implement typing, fstrings and make (mostly) PEP8 compliant. [Stefan Davis & Jeremy Davis * Firstboot Initialization (inithooks): - Refactor start up (now hooks into getty process, rather than having it's own service). [ Stefan Davis ] - Refactor firstboot.d/01ipconfig (and 09hostname) to ensure that hostname is included in dhcp info when set via inithooks. - Package turnkey-make-ssl-cert script (from common overlay - now packaged as turnkey-ssl). Refactor relevant scripts to leverage turnkey-ssl. - Refactor run script - use bashisms and general tidying. - Show blacklisted password characters more nicely. - Misc packaging changes/improvements. - Support returning output from MySQL - i.e. support 'SELECT'. (Only applies to apps that include MySQL/MariaDB). * Web management console (webmin): - Upgraded webmin to v2.105. - Removed stunnel reverse proxy (Webmin hosted directly now). - Ensure that Webmin uses HTTPS with default cert (/etc/ssl/private/cert.pem). - Disabled Webmin Let's Encrypt (for now). * Web shell (shellinabox): - Completely removed in v18.0 (Webmin now has a proper interactive shell). * Backup (tklbam): - Ported dependencies to Debian Bookworm; otherwise unchanged. * Security hardening & improvements: - Generate and use new TurnKey Bookworm keys. - Automate (and require) default pinning for packages from Debian backports. Also support non-free backports. * IPv6 support: - Adminer (only on LAMP based apps) listen on IPv6. - Nginx/NodeJS (NodeJS based apps only) listen on IPv6. * Misc bugfixes & feature implementations: - Remove rsyslog package (systemd journal now all that's needed). - Include zstd compression support. - Enable new non-free-firmware apt repo by default. - Improve turnkey-artisan so that it works reliably in cron jobs (only Laravel based LAMP apps). * Set mod_evasive log location - makes debugging easier. [ Jeremy Davis ] * Include and enable mod_evasive and mod_security2 by default in Apache. [ Stefan Davis ] * Debian default PHP updated to v8.2. * Include new 'tkl-update-php' script - to make updating/changing PHP version easier for end users. [Marcos Méndez @ POPSOLUTIONS ] * DEV: Add support for setting max_execution_time & max_input_vars in php.ini via appliance Makefile (PHP_MAX_EXECUTION_TIME & PHP_MAX_INPUT_VARS). * Use MariaDB (MySQL replacement) v10.11.3 (from debian repos). * Install composer from Debian repos (previously installed from source) [ Stefan Davis ] -- Jeremy Davis Fri, 26 Jan 2024 01:41:01 +0000 turnkey-cakephp-17.1 (1) turnkey; urgency=low * Updated all Debian packages to latest. [ autopatched by buildtasks ] * Patched bugfix release. Closes #1734. [ autopatched by buildtasks ] -- Jeremy Davis Tue, 12 May 2022 01:41:55 +0000 turnkey-cakephp-17.0 (1) turnkey; urgency=low * Latest upstream versiion of CakePHP - v4.3.6. * Includes PHP 8.1 from Sury repos. * Updated all relevant Debian packages to Bullseye/11 versions * Note: Please refer to turnkey-core's 17.0 changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Stefan Davis Mon, 21 Mar 2022 23:23:58 +0000 turnkey-cakephp-16.1 (1) turnkey; urgency=low * Latest upstream version of CakePHP - v4.2.4. * Include 'turnkey-composer' wrapper script - runs composer as www-data user. Makes it easy to not run composer as root - part of #1539. Note by default, /var/www/cakephp is still owned by root. To get full value of 'turnkey-composer':: chown -R www-data:www-data /var/www/cakephp * Explicitly install composer (rather than automatically include in all LAMP based appliances) - part of #1563. * Note: Please refer to turnkey-core's 16.1 changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Jeremy Davis Tue, 30 Mar 2021 12:52:37 +1100 turnkey-cakephp-16.0 (1) turnkey; urgency=low * Latest upstream version of CakePHP - v4.0.7. * Replace turnkey landing page with turnkey-shim injected into cakephp's landing page at build time. * Explcitly disable TLS<1.2 (i.e. SSLv3, TLSv1, TLSv1.1). (v15.x TurnKey releases supported TLS 1.2, but could fallback as low as TLSv1). * Update SSL/TLS cyphers to provide "Intermediate" browser/client support (suitable for "General-purpose servers with a variety of clients, recommended for almost all systems"). As provided by Mozilla via https://ssl-config.mozilla.org/. * Updated all relevant Debian packages to Buster/10 versions; including PHP 7.3. * Updated version of mysqltuner script - now installed as per upstream recommendation. * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Stefan Davis Wed, 06 May 2020 16:32:58 +1000 turnkey-cakephp-15.1 (1) turnkey; urgency=low * Latest upstream version of CakePHP (v3.6.13) * Refactor download script to always download latest stable. * Rebuild to resolve inadvertant removal of mariadb during sec-updates - part of #1246. -- Jeremy Davis Tue, 27 Nov 2018 17:09:40 +1100 turnkey-cakephp-15.0 (1) turnkey; urgency=low * Latest upstream version of CakePHP (v3.6.6) * Install Adminer directly from stretch/main repo * Provide "adminer" root-like user for Adminer MySQL access * Replace MySQL with MariaDB (drop-in MySQL replacement) * Updated version of mysqltuner script * Includes PHP7.0 (installed from Debian repos) * Updated PHP default settings * Remove phpsh (no longer maintained) * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Stefan Davis Tue, 03 Jul 2018 09:46:54 +1000 turnkey-cakephp-14.2 (1) turnkey; urgency=low * Latest upstream version of CakePHP (v3.4.9) * Updated Adminer to 4.2.5 * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Ken Robinson Wed, 28 Jun 2017 23:08:26 -0400 turnkey-cakephp-14.1 (1) turnkey; urgency=low * Installed security updates. * Installed updated packages from TurnKey repo - includes relevant Webmin packages (v1.780) * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Jeremy Davis Tue, 01 Mar 2016 16:28:43 +1100 turnkey-cakephp-14.0 (1) turnkey; urgency=low * Upgraded to latest version of CakePHP (3.0.10) * Updated TurnKey Web Control Panel to conform to 3.0 guidelines. * Replaced PHPMyAdmin with Adminer * Hardened default SSL settings * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Anton Pyrogovskyi Thu, 30 Jul 2015 22:59:33 +0300 turnkey-cakephp-13.0 (1) turnkey; urgency=low * PHPMyAdmin: - Configured to allow users preferences stored in database. - Specified blowfish_secret and regeneration on firstboot (security). * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Alon Swartz Thu, 10 Oct 2013 17:04:34 +0300 turnkey-cakephp-12.1 (1) turnkey; urgency=low * Upgraded to latest version of CakePHP. * Added phpsh (interative shell for PHP) and php5-cli (generically useful). * Upstream source component versions: cakephp 2.3.1 * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Alon Swartz Fri, 05 Apr 2013 08:00:00 +0200 turnkey-cakephp-12.0 (1) turnkey; urgency=low * Initial public release of TurnKey CakePHP. * Includes TurnKey Web Control panel with links to useful references, relevant path information, and CakePHP checks (convenience). * Regenerates all secrets during installation / firstboot (security). * Preconfigured MySQL database and user for CakePHP (convenience). * MySQL related: - Set MySQL root password on firstboot (convenience, security). - Force MySQL to use Unicode/UTF8. - Includes PhpMyAdmin (listening on port 12322 - uses SSL). * SSL support out of the box. * Includes php-xcache PHP opcode cacher / optimizer (performance). * Includes postfix MTA (bound to localhost) for sending of email (e.g. password recovery). Also includes webmin postfix module for convenience. * Major component versions cakephp 2.2.1-0 (upstream archive) apache2 2.2.16-6+squeeze7 mysql-server 5.1.63-0+squeeze1 phpmyadmin 4:3.3.7-7 * Note: Please refer to turnkey-core's changelog for changes common to all appliances. Here we only describe changes specific to this appliance. -- Alon Swartz Wed, 01 Aug 2012 08:00:00 +0200