Koozali.org: home of the SME Server

[Anounce] smeserver-trixbox-fws-beta2

iam

[Anounce] smeserver-trixbox-fws-beta2
« Reply #60 on: March 20, 2007, 08:33:50 AM »
To svangool:

Thank you for posting new recommendations.

There is a question:
Don't you stay with kernel 2.6.9-34 as recommended. Don't you expirience any problems with a new one?

Kirill

Offline Daniel B.

  • *
  • 1,699
  • +0/-0
    • Firewall Services, la sécurité des réseaux
[Anounce] smeserver-trixbox-fws-beta2
« Reply #61 on: March 20, 2007, 10:06:53 AM »
Hi everyone. Thanks for your interest and your contribution in this project. I've just looked at the security hole in asterisk, and I don't think smeserver-trixbox is concerned. The main reason is that asterisk (UDPPort 5060) is NOT open the the Internet. Your server can open a connexion to your VOIP provider, but nobody can open a connexion to your asterisk from the outside. I think it's more risky to install gcc and openssl-devel on a prod environnement. If you have a test server, then you can compile the latest asterisk on it, and copy all the compiled files to your prod server.
Anyway, if you realy want to install gcc and openssl-devel on your prod server, here are all the dependencies that you should remove after:

gcc
openssl-devel
cpp
e2fsprogs-devel
glibc-devel
glibc-headers
glibc-kernheaders
krb5-devel
zlib-devel
libgcc

I'll soon release a new version of the contrib, with freePBX 2.2.1, and the latest rpms from trixbox repo (asterisk 1.2.14). The new version will only contains asterisk, freePBX (the base of the old package). I wont maintain anymore the others modules (maint, meetme, a2billing, xpl, crm) because it's too much work and I don't use it.
C'est la fin du monde !!! :lol:

Offline svangool

  • ***
  • 73
  • +0/-0
[Anounce] smeserver-trixbox-fws-beta2
« Reply #62 on: March 20, 2007, 10:32:56 AM »
To iam:

No, I don't have any problems with the new kernel.  I don't use ISDN, I have a TDM400 FXS/FXO analog card.

To VIP-ire:

If you want to use a (soft-)phone outside your local net you have to open that port and the the security hole becomes a fact.

As I showed in my explanation just remove gcc after you are done.
If you do what I described you don't have to bother about the dependencies, everything will be there. I agree, I wouldn't do this on the school server.

I would not spend too much time on packaging the current TB, There is almost a new one with selectable asterisk 1.2.16 or 1.4.1.
......

Offline Daniel B.

  • *
  • 1,699
  • +0/-0
    • Firewall Services, la sécurité des réseaux
[Anounce] smeserver-trixbox-fws-beta2
« Reply #63 on: March 20, 2007, 10:43:23 AM »
To acces asterisk from the outside, I strongly recommend to use a VPN. That's why I've also developped the contrib smeserver-openvpn-bridge-fws. I'll see if the new TB come soon. I'd like to use asterisk 1.4.1 (especially for the jabber server) but I don't know when freePBX will support 1.4.x serie
C'est la fin du monde !!! :lol: