|
|
|
Name: ocserv
|
|
|
|
Version: 0.2.1
|
|
|
|
Release: 6%{?dist}
|
|
|
|
Summary: OpenConnect SSL VPN server
|
|
|
|
|
|
|
|
# For a breakdown of the licensing, see PACKAGE-LICENSING
|
|
|
|
# To simplify licenses LGPLv2+ files have been promoted to GPLv2+.
|
|
|
|
License: GPLv2+ and BSD and MIT and CC0
|
|
|
|
URL: http://www.infradead.org/ocserv/
|
|
|
|
Source0: ftp://ftp.infradead.org/pub/ocserv/%{name}-%{version}.tar.xz
|
|
|
|
Source1: ocserv.conf
|
|
|
|
Source2: ocserv.service
|
|
|
|
Source3: ocserv-pamd.conf
|
|
|
|
Source4: PACKAGE-LICENSING
|
|
|
|
|
|
|
|
# Taken from upstream:
|
|
|
|
# http://git.infradead.org/ocserv.git/commitdiff/7d70006a2dbddf783213f1856374bacc74217e09
|
|
|
|
Patch0: ocserv-http-parser.patch
|
|
|
|
Patch1: ocserv-tests.patch
|
|
|
|
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(%{__id_u} -n)
|
|
|
|
|
|
|
|
BuildRequires: gnutls-devel
|
|
|
|
BuildRequires: pam-devel
|
|
|
|
BuildRequires: iproute
|
|
|
|
BuildRequires: systemd
|
|
|
|
BuildRequires: autogen-libopts-devel
|
|
|
|
BuildRequires: autogen
|
|
|
|
BuildRequires: pcllib-devel, http-parser-devel, tcp_wrappers-devel
|
|
|
|
BuildRequires: automake, autoconf
|
|
|
|
|
|
|
|
Requires: iproute
|
|
|
|
Requires: pam
|
|
|
|
Requires(pre): shadow-utils
|
|
|
|
Requires(post): systemd
|
|
|
|
Requires(preun): systemd
|
|
|
|
Requires(postun): systemd
|
|
|
|
#gnulib is bundled. See https://fedorahosted.org/fpc/ticket/174
|
|
|
|
Provides: bundled(gnulib)
|
|
|
|
#CCAN is bundled. See https://fedorahosted.org/fpc/ticket/364
|
|
|
|
Provides: bundled(bobjenkins-hash) bundled(ccan-container_of)
|
|
|
|
Provides: bundled(ccan-htable) bundled(ccan-list)
|
|
|
|
Provides: bundled(ccan-check_type) bundled(ccan-build_assert)
|
|
|
|
|
|
|
|
%description
|
|
|
|
OpenConnect server (ocserv) is an SSL VPN server. Its purpose is to be
|
|
|
|
a secure, small, fast and configurable VPN server that uses standard
|
|
|
|
protocols such as TLS 1.2, and Datagram TLS. It implements the
|
|
|
|
OpenConnect SSL VPN protocol, which is compatible with the AnyConnect
|
|
|
|
SSL VPN protocol.
|
|
|
|
|
|
|
|
%prep
|
|
|
|
%setup -q
|
|
|
|
%patch0 -p1
|
|
|
|
%patch1 -p1
|
|
|
|
rm -f src/http-parser/http_parser.c src/http-parser/http_parser.h
|
|
|
|
rm -f libopts/*.c libopts/*.h libopts/*/*.c libopts/*/*.h
|
|
|
|
rm -f src/pcl/*.c src/pcl/*.h
|
|
|
|
# GPLv3 in headers was a gnulib bug:
|
|
|
|
# http://lists.gnu.org/archive/html/bug-gnulib/2013-11/msg00062.html
|
|
|
|
sed -i 's/either version 3 of the License/either version 2 of the License/g' build-aux/snippet/*
|
|
|
|
# remove GPLv3 components
|
|
|
|
rm -f tests/test-* tests/common.sh
|
|
|
|
|
|
|
|
%build
|
|
|
|
autoreconf -fi
|
|
|
|
|
|
|
|
%configure
|
|
|
|
|
|
|
|
# disable the smp_mflags until an issue with the dependencies in the
|
|
|
|
# autogen'erated files is fixed
|
|
|
|
make #%{?_smp_mflags}
|
|
|
|
|
|
|
|
%pre
|
|
|
|
getent group ocserv &>/dev/null || groupadd -r ocserv
|
|
|
|
getent passwd ocserv &>/dev/null || \
|
|
|
|
/usr/sbin/useradd -r -g ocserv -s /sbin/nologin -c ocserv \
|
|
|
|
-d /var/lib/ocserv ocserv
|
|
|
|
|
|
|
|
%post
|
|
|
|
%systemd_post ocserv.service
|
|
|
|
|
|
|
|
%preun
|
|
|
|
%systemd_preun ocserv.service
|
|
|
|
|
|
|
|
%postun
|
|
|
|
%systemd_postun ocserv.service
|
|
|
|
|
|
|
|
%install
|
|
|
|
rm -rf %{buildroot}
|
|
|
|
cp -a %{SOURCE4} PACKAGE-LICENSING
|
|
|
|
mkdir -p %{buildroot}/%{_sysconfdir}/pam.d/
|
|
|
|
mkdir -p %{buildroot}/%{_sysconfdir}/ocserv/
|
|
|
|
install -p -m 644 %{SOURCE3} %{buildroot}/%{_sysconfdir}/pam.d/ocserv
|
|
|
|
install -p -m 644 %{SOURCE1} %{buildroot}/%{_sysconfdir}/ocserv/
|
|
|
|
mkdir -p %{buildroot}/%{_unitdir}
|
|
|
|
install -p -m 644 %{SOURCE2} %{buildroot}/%{_unitdir}
|
|
|
|
mkdir -p %{buildroot}/var/lib/ocserv/
|
|
|
|
%make_install
|
|
|
|
|
|
|
|
%clean
|
|
|
|
rm -rf %{buildroot}
|
|
|
|
|
|
|
|
%files
|
|
|
|
%defattr(-,root,root,-)
|
|
|
|
|
|
|
|
%dir /var/lib/ocserv
|
|
|
|
%dir %{_sysconfdir}/ocserv
|
|
|
|
|
|
|
|
%config(noreplace) %{_sysconfdir}/ocserv/ocserv.conf
|
|
|
|
%config(noreplace) %{_sysconfdir}/pam.d/ocserv
|
|
|
|
|
|
|
|
%doc AUTHORS ChangeLog NEWS COPYING LICENSE README TODO PACKAGE-LICENSING
|
|
|
|
%doc src/ccan/licenses/CC0 src/ccan/licenses/LGPL-2.1 src/ccan/licenses/BSD-MIT
|
|
|
|
%{_mandir}/man8/ocserv.8*
|
|
|
|
%{_mandir}/man8/ocpasswd.8*
|
|
|
|
%{_bindir}/ocpasswd
|
|
|
|
%{_sbindir}/ocserv
|
|
|
|
%{_unitdir}/ocserv.service
|
|
|
|
|
|
|
|
%changelog
|
|
|
|
* Fri Dec 6 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-6
|
|
|
|
- Added exception for the bundling of CCAN components.
|
|
|
|
|
|
|
|
* Wed Nov 13 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-5
|
|
|
|
- Updated the way PACKAGE-LICENSING is handled.
|
|
|
|
|
|
|
|
* Tue Nov 12 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-4
|
|
|
|
- Replaced gnulib's GPLv3+ license with GPLv2+. According to
|
|
|
|
http://lists.gnu.org/archive/html/bug-gnulib/2013-11/msg00062.html
|
|
|
|
it was a gnulib bug.
|
|
|
|
- Reduced the number of applicable licenses by upgrading LGPLv2+
|
|
|
|
components to GPLv2+.
|
|
|
|
- Added PACKAGE-LICENSING.
|
|
|
|
|
|
|
|
* Mon Nov 11 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-3
|
|
|
|
- Updated spec to add http-parser and pcllib as dependencies.
|
|
|
|
- Bundled library files are removed.
|
|
|
|
- Updated license information.
|
|
|
|
|
|
|
|
* Fri Nov 8 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-2
|
|
|
|
- Updated spec to account improvements suggested by Alec Leamas.
|
|
|
|
|
|
|
|
* Thu Nov 7 2013 Nikos Mavrogiannopoulos <nmav@redhat.com> - 0.2.1-1
|
|
|
|
- Initial version of the package
|