Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - groove21

#1
General Discussion / Re: Open CVEs right after update
September 02, 2026, 09:56:44 AM
Yes yesterday evening the warning appeared again. Does it have any changes on the functionality of the database if you host the file by yourself?

@franco: Are there any plans to level python up to 3.15?
#2
General Discussion / Re: Open CVEs right after update
September 01, 2026, 10:18:00 AM
Ok, one hour ago the warning in CMK disappeared. Weird :P
#3
General Discussion / Re: Open CVEs right after update
September 01, 2026, 06:46:18 AM
Hey franco, hey Patrick,

thanks for your replies. If I understood correctly, the warning will disappear, as soon as python3.15 is used with OPNsense. Are there any plans on that?
Don´t get me wrong: As long as there is no real security issue, everything is fine. But I would be happy, when one day the warning in CMK will disappear to focus on the real CVE-issue(s). At the moment it is kind of false positive :(
#4
General Discussion / Re: Open CVEs right after update
August 28, 2026, 10:24:11 AM
CMK is still reporting python313 as vulnerable since months in all my opnsense-instances. Is there any action to do? When will this warning disappear?
#5
General Discussion / Re: need help with wol api
May 20, 2026, 10:13:48 PM
Ok my fault. Playbook is working fine. Just mistakenly used description as interface instead of interface name.... After changing, everything is perfect.
#6
General Discussion / Re: need help with wol api
May 14, 2026, 08:39:20 PM
Hey,

is this still working?

#Will trigger a manual/undefined wake:
POST /wol/wol/set {wake: {interface: "opt22", mac: "b4:2e:99:30:da:dd"}}

I tried with Ansible:

    - name: Send Wake-on-LAN
      ansible.builtin.uri:
        url: "{{ opnsense_instances[opnsense_instance].url }}"
        method: POST
        user: "{{ opnsense_instances[opnsense_instance].api_key }}"
        password: "{{ opnsense_instances[opnsense_instance].api_secret }}"
        force_basic_auth: true
        body_format: json
        body:
          wake:
              interface: "{{ opnsense_interface }}"
              mac: "{{ mac }}"
        validate_certs: false
      when: not host_was_online
      delegate_to: localhost

But doesn´t work as expected. Any ideas?

Instance-URL is set like this:

url: "https://opnsense.local:8443/api/wol/wol/set"
#8
Hallo Patrick,

ja du hast recht, ich habe mich im Pfad vertan.
Ist es aus deiner Sicht ein Feature Request oder ein Bug, dass die Zeile nicht editierbar ist?

Gruß
#9
German - Deutsch / Rückfrage zu den types in Tunables
November 16, 2025, 02:08:29 PM
Hallo zusammen,

ich würde gerne folgende Änderungen aus https://forum.opnsense.org/index.php?topic=39608.msg195353#msg195353 bzw. https://kb.isc.org/docs/aa-00621 update-persistent umsetzen.

Die tunables sorgen ja so viel ich weiß im Default für einen Eintrag in /etc/loader.conf

Wenn ich aber Änderungen in der /etc/sysctl.conf umsetzen will verraten wir Recherchen, dass ich dann als Type = systcl setzen soll. Leider ist dies selbst im advanced Mode nicht möglich zu setzen. Ich sehe dann zwar die Zeile type, kann aber nichts eintragen.

Ich habe die Änderungen jetzt vorübergehend in /usr/local/etc/sysctl.conf gesetzt und mit sysctl -f /usr/local/etc/sysctl.conf applied.

Gibt es hier eine Möglichkeit das direkt in den Tunables hinzubekommen?

Gruß

#10
Manchmal hat mat Tomaten auf den Augen. Danke für die schnelle Antwort.
#11
Hallo @meyerguru,

kurze Frage: Ist dieser Schritt aus deiner Anleitung update-persistent, sprich wird nicht überschrieben?

3. Add an entry to /etc/rc.conf:

CodeSelect
echo 'microcode_update_enable="YES"' >> /etc/rc.conf

Danke für eine kurze Rückinfo.

Gruß
#12
German - Deutsch / Re: Pkg: libxslt vulnerable
September 16, 2025, 11:40:49 AM
Ok und wie bekommen die zuständigen Personen das mit? Lesen die hier aktiv mit?
#13
German - Deutsch / Re: Pkg: libxslt vulnerable
September 15, 2025, 08:31:24 AM
Also wäre das etwas, was sich ggf. @franco anschauen müsste, korrekt?
#14
German - Deutsch / Re: Pkg: libxslt vulnerable
September 12, 2025, 05:02:22 PM
Kurze Frage: Ist dieses "Loswerden" im Zuständingskeitsbereich von OPNsense? Es wird doch dort benutzt, wenn ich es richtig verstanden habe, oder?
#15
German - Deutsch / Re: Pkg: libxslt vulnerable
September 12, 2025, 03:51:12 PM
Ich fände es auch cool, wenn sich da was ergeben würde. Auf Dauer ist das vermutlich kein wünschenswerter Zustand aus Security-Sicht.