[Bug 810599] New: After zypper dup, the firewall is shut off by default
https://bugzilla.novell.com/show_bug.cgi?id=810599 https://bugzilla.novell.com/show_bug.cgi?id=810599#c0 Summary: After zypper dup, the firewall is shut off by default Classification: openSUSE Product: openSUSE 12.3 Version: Final Platform: Other OS/Version: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: albert.passalacqua@gmail.com QAContact: qa-bugs@suse.de Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:19.0) Gecko/20100101 Firefox/19.0 After performing a zypper dup from openSUSE 12.2 to openSUSE 12.3, SuSEfirewall is turned off, even if it was active before the upgrade. Reproducible: Always Steps to Reproduce: 1. Upgrade a system from openSUSE 12.2 with active SuSEfirewall to openSUSE 12.3 with zypper dup 2. Check the status of SuSEfirewall2 Actual Results: The firewall is turned off after the upgrade Expected Results: The firewall should be left on. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=810599 https://bugzilla.novell.com/show_bug.cgi?id=810599#c1 Harald Koenig <koenig@linux.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P1 - Urgent CC| |koenig@linux.de Severity|Normal |Critical --- Comment #1 from Harald Koenig <koenig@linux.de> 2013-03-30 08:46:08 UTC --- just got hit by the same problem: a server with some internet connection started with firewall down after update! this should not happen:-(( it's a shame that this security issue did not even got assigned for 10 days now. raising priority and severity because of possible security impacts! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=810599 https://bugzilla.novell.com/show_bug.cgi?id=810599#c2 --- Comment #2 from Alberto Passalacqua <albert.passalacqua@gmail.com> 2013-04-01 01:05:53 UTC --- Could you check if the firewall is actually off from the command line, using SuSEfirewall2 status if you have a freshly updated machine? In my case, YaST was reporting the firewall was off. However someone in the IRC #suse IRC channel pointed out that it is a bug affecting YaST detection of the firewall status, rather than the firewall actually being off. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=810599 https://bugzilla.novell.com/show_bug.cgi?id=810599#c3 --- Comment #3 from Harald Koenig <koenig@linux.de> 2013-04-02 08:24:32 UTC --- (In reply to comment #2)
Could you check if the firewall is actually off from the command line, using
SuSEfirewall2 status
if you have a freshly updated machine?
of course, in the mean time I've fixed the missing firewall settings, but before "iptables -L" showed now firewall rules at all (like now after "systemctl stop SuSEfirewall2.service" and "systemctl status SuSEfirewall2.service" showed something line inactive/idle or similar.
In my case, YaST was reporting the firewall was off. However someone in the IRC #suse IRC channel pointed out that it is a bug affecting YaST detection of the firewall status, rather than the firewall actually being off.
I did not try yast(2) at all, only command line tools... -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=810599 https://bugzilla.novell.com/show_bug.cgi?id=810599#c4 Marcus Meissner <meissner@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED CC| |meissner@suse.com Resolution| |DUPLICATE --- Comment #4 from Marcus Meissner <meissner@suse.com> 2013-04-18 12:51:53 UTC --- dup *** This bug has been marked as a duplicate of bug 808759 *** http://bugzilla.novell.com/show_bug.cgi?id=808759 -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@novell.com