Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							848dea83ab 
							
						 
					 
					
						
						
							
							additional error handling for backups with an invalid target  
						
						 
						
						
						
					 
					
						2015-08-12 11:19:59 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							f96bef43cc 
							
						 
					 
					
						
						
							
							If no prefix is specified, set the path to '', otherwise boto won't list the files  
						
						 
						
						
						
					 
					
						2015-08-11 13:54:30 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							f4e8ee0af9 
							
						 
					 
					
						
						
							
							html errors in the backup template, my bad  
						
						 
						
						
						
					 
					
						2015-08-09 20:34:08 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							9ca116d545 
							
						 
					 
					
						
						
							
							add an option to disable backups  
						
						 
						
						
						
					 
					
						2015-08-09 20:15:43 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							cdd3a64638 
							
						 
					 
					
						
						
							
							after-backup was run with the wrong environment  
						
						 
						
						
						
					 
					
						2015-08-09 20:08:33 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							99e51f8a52 
							
						 
					 
					
						
						
							
							use boto to get actual file sizes of backup files when S3 is used  
						
						 
						
						
						
					 
					
						2015-08-09 20:08:33 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							3b4b57c081 
							
						 
					 
					
						
						
							
							switching between backup options in the admin wasn't working at all  
						
						 
						
						... 
						
						
						
						* going from s3 to file target wasn't working
* use 'local' in the config instead of a file: url, for the local target, so it is not path-specific
* break out the S3 fields since users can't be expected to know how to form a URL
* use boto to generate a list of S3 hosts
* use boto to validate that the user input for s3 is valid
* fix lots of html errors in the backup admin 
						
					 
					
						2015-08-09 20:08:33 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							c7f8ead496 
							
						 
					 
					
						
						
							
							clean up the new backup configuration panel  
						
						 
						
						
						
					 
					
						2015-08-09 20:08:30 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							3f15879578 
							
						 
					 
					
						
						
							
							remove global variables in backup.py  
						
						 
						
						
						
					 
					
						2015-08-09 17:54:46 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							1cdd205eb7 
							
						 
					 
					
						
						
							
							Missed one max_age  
						
						 
						
						
						
					 
					
						2015-07-28 20:58:39 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							77099b3bce 
							
						 
					 
					
						
						
							
							Reword backup min_time label  
						
						 
						
						
						
					 
					
						2015-07-28 00:42:00 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							0d8a4099c1 
							
						 
					 
					
						
						
							
							Add placeholder attribute; use input instead of textarea  
						
						 
						
						
						
					 
					
						2015-07-28 00:37:48 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							606cf6a941 
							
						 
					 
					
						
						
							
							Fix API typo  
						
						 
						
						
						
					 
					
						2015-07-28 00:34:26 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							ba9065cada 
							
						 
					 
					
						
						
							
							Don't write collection_status output to file but parse it directly  
						
						 
						
						
						
					 
					
						2015-07-27 22:30:22 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							e693802091 
							
						 
					 
					
						
						
							
							Rename max_age to min_age  
						
						 
						
						... 
						
						
						
						Also clarify a comment and remove an unneeded type check 
						
					 
					
						2015-07-27 22:18:19 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							fa0dd684da 
							
						 
					 
					
						
						
							
							Add archive-dir argument to collection-status  
						
						 
						
						
						
					 
					
						2015-07-27 22:13:28 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							43fb7fe635 
							
						 
					 
					
						
						
							
							Remove unused variable  
						
						 
						
						
						
					 
					
						2015-07-27 22:11:43 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							91e4ea6e2f 
							
						 
					 
					
						
						
							
							Infer target_type from url  
						
						 
						
						
						
					 
					
						2015-07-27 22:09:58 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							1e3e34f15f 
							
						 
					 
					
						
						
							
							Make backup API RESTful  
						
						 
						
						
						
					 
					
						2015-07-27 22:00:36 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Leo Koppelkamm 
							
						 
					 
					
						
						
						
						
							
						
						
							2e6c410336 
							
						 
					 
					
						
						
							
							Make backups more configurable  
						
						 
						
						... 
						
						
						
						Backup location and maximum age can now be configured in the admin panel.
For now only S3 is supported, but adding other duplicity supported backends should be straightforward. 
						
					 
					
						2015-07-27 21:53:34 +02:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							0293e04311 
							
						 
					 
					
						
						
							
							fix control panel links, broken in Firefox (worked in Chrome)  
						
						 
						
						... 
						
						
						
						see https://discourse.mailinabox.email/t/bug-present-for-ages/694/3  
						
					 
					
						2015-07-25 14:12:45 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							1900e512f2 
							
						 
					 
					
						
						
							
							improve the sort order of domains - siblings to the primary hostname were not sorted right  
						
						 
						
						
						
					 
					
						2015-07-21 11:25:11 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							d3bbc0ec95 
							
						 
					 
					
						
						
							
							bug in new secondary nameservers  
						
						 
						
						... 
						
						
						
						forgot a 'continue' statement
see 216acb0eeb 
fixes  #497  
						
					 
					
						2015-07-20 11:25:16 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							541d9252f6 
							
						 
					 
					
						
						
							
							allow PEM files to have non-Unix line endings  
						
						 
						
						
						
					 
					
						2015-07-17 11:44:28 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								PortableTech 
							
						 
					 
					
						
						
						
						
							
						
						
							415f95b792 
							
						 
					 
					
						
						
							
							Add TLSA record for HTTPS connections.  
						
						 
						
						... 
						
						
						
						While not widely supported, there are some browser addons that can
validate DNSSEC and TLSA for additional out-of-band verification of
certificates when browsing the web.  Costs nothing to implement and
might improve security in some situations. 
						
					 
					
						2015-07-13 09:12:13 -04:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							5dd5fc4a1c 
							
						 
					 
					
						
						
							
							clean up multiple secondary nameservers and zone xfr ip addresses  
						
						 
						
						
						
					 
					
						2015-07-10 15:42:33 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Brian Bustin 
							
						 
					 
					
						
						
						
						
							
						
						
							09133c8f59 
							
						 
					 
					
						
						
							
							Initial backend changes to make it possible to have one or more secondary name servers  
						
						 
						
						
						
					 
					
						2015-07-10 14:59:38 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							acd91665b5 
							
						 
					 
					
						
						
							
							setting an alias to forward to two or more addresses was broken since  aa33428311 
						
						 
						
						... 
						
						
						
						fixes  #482  
						
					 
					
						2015-07-04 15:28:45 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							ff4780d5fb 
							
						 
					 
					
						
						
							
							better error handling of invalid PEM files  
						
						 
						
						
						
					 
					
						2015-07-03 14:00:59 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							0924f8ca7a 
							
						 
					 
					
						
						
							
							allow for PEM private keys in the 'BEGIN PRIVATE KEY' format too  
						
						 
						
						... 
						
						
						
						see https://discourse.mailinabox.email/t/another-upgrade-failure/630/5  
						
					 
					
						2015-07-02 15:37:26 -04:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							e57e08088a 
							
						 
					 
					
						
						
							
							the control panel would not allow installing a certificate for a www redirect domain,  fixes   #475  
						
						 
						
						
						
					 
					
						2015-07-02 10:53:54 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							42a506231b 
							
						 
					 
					
						
						
							
							don't automatically create the administrator@ alias (e.g. on first user creation) because we dont know what it should be an alias to (leave this to be resolved manually),  fixes   #470  
						
						 
						
						... 
						
						
						
						Was broken by 462a79cf47 . 
						
					 
					
						2015-06-30 09:16:22 -04:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							e3252f53da 
							
						 
					 
					
						
						
							
							idna domains in certificate subject alternative names were not handled correctly after switching to cryptography package  
						
						 
						
						
						
					 
					
						2015-06-30 13:09:18 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							aa33428311 
							
						 
					 
					
						
						
							
							some IDNA functionality was still using Python's built-in IDNA 2003 encoder rather than the idna package's IDNA 2008 encoder  
						
						 
						
						
						
					 
					
						2015-06-30 13:09:18 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							5ef1cfbdc7 
							
						 
					 
					
						
						
							
							forgot new version.html template file  
						
						 
						
						
						
					 
					
						2015-06-25 17:43:50 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							7527b4dc27 
							
						 
					 
					
						
						
							
							show the Mail-in-a-Box version in the control panel and a button to ping the MiaB website for the latest version  
						
						 
						
						... 
						
						
						
						fixes  #441  
						
					 
					
						2015-06-25 13:43:11 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							299a2315c1 
							
						 
					 
					
						
						
							
							dkim 2048 bits - migration and zone file generation changes  
						
						 
						
						... 
						
						
						
						* Add a migration to delete any existing DKIM key so that existing machines get a fresh 2048-bit key. (Sadly we don't support key rotation so the change is immediate.)
* Because the DNS record for a 2048-bit key is so much longer, the way we read OpenDKIM's DNS record text file had to be modified to combine an arbitrary number of TXT record quoted ("...") strings.
* When writing out the TXT record value, the string must be split into quoted ("...") strings with a maximum length of 255 bytes each, per the DNS spec.
* Added a changelog entry. 
						
					 
					
						2015-06-25 13:06:29 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							dece359c90 
							
						 
					 
					
						
						
							
							validate certificates using the cryptography python package as much as possible, shelling out to openssl just once instead of four times per certificate  
						
						 
						
						... 
						
						
						
						* Use `cryptography` instead of parsing openssl's output.
* When checking if we can reuse the primary domain certificate or a www-parent-domain certificate for a domain, avoid shelling out to openssl entirely. 
						
					 
					
						2015-06-21 14:53:37 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							43d50d0667 
							
						 
					 
					
						
						
							
							Merge pull request  #445  from bizonix/patch-1  
						
						 
						
						... 
						
						
						
						fix wrong redirect for automatic www subdomain redirects 
						
					 
					
						2015-06-18 07:05:01 -04:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							6258a7f311 
							
						 
					 
					
						
						
							
							status checks were broken if sshd was not present,  fixes   #444  
						
						 
						
						
						
					 
					
						2015-06-18 11:01:11 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							ab36cc8968 
							
						 
					 
					
						
						
							
							whitespace=>tabs  
						
						 
						
						
						
					 
					
						2015-06-18 10:54:51 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								bizonix 
							
						 
					 
					
						
						
						
						
							
						
						
							33b71c6b3c 
							
						 
					 
					
						
						
							
							fix wrong redirect  
						
						 
						
						... 
						
						
						
						$ curl -I https://www.site.co.il/static/images/1.png?a=b  | grep Location
Location: https://site.co.il?a=b 
but should be something like 
Location: https://site.co.il/static/images/1.png?a=b  
						
					 
					
						2015-06-18 01:48:15 +03:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							2af557139d 
							
						 
					 
					
						
						
							
							default IPv6 AAAA records were missing  
						
						 
						
						... 
						
						
						
						This was broken by the ability to have multiple TXT records in 9f1d633ae4 . 
						
					 
					
						2015-06-17 06:47:22 -04:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							1990f32ca4 
							
						 
					 
					
						
						
							
							typo,  fixes   #435  
						
						 
						
						
						
					 
					
						2015-06-06 13:22:50 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							807939c0e4 
							
						 
					 
					
						
						
							
							make the +tag address tips clearer  
						
						 
						
						
						
					 
					
						2015-06-06 13:02:23 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							5008cc603e 
							
						 
					 
					
						
						
							
							merge - munin system monitoring  
						
						 
						
						
						
					 
					
						2015-06-06 12:52:22 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							9857db96cd 
							
						 
					 
					
						
						
							
							add a link to the /admin/munin page from the control panel nav bar  
						
						 
						
						
						
					 
					
						2015-06-06 12:52:16 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							e9e6d94e3b 
							
						 
					 
					
						
						
							
							the control panel auth hmac message should also include the user's password so that resetting a password in the database forces that user to log in to the control panel again; also use a sha256 hmac  
						
						 
						
						
						
					 
					
						2015-06-06 12:38:19 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							462a79cf47 
							
						 
					 
					
						
						
							
							fix what counts as a required alias,  fixes   #434  
						
						 
						
						
						
					 
					
						2015-06-06 12:12:10 +00:00  
					
					
						 
						
							
							
							 
						
					 
				 
			
				
					
						
							
							
								 
								Joshua Tauberer 
							
						 
					 
					
						
						
						
						
							
						
						
							f792deeebd 
							
						 
					 
					
						
						
							
							when the undocumented custom web settings has a redirect or proxy at the root of a domain, use a minimal nginx config template (same as the new default www redirects)  
						
						 
						
						
						
					 
					
						2015-06-04 12:32:00 +00:00