Update-05 Available
Another month gone by, and another update release....
LATEST RELEASE: Update-05
02-November-2014
Merlin fork 374.43_2-05j9527
Download
http://1drv.ms/1uChm3J
===============================
For those of you not yet ready to update to the latest 376.xx release, I have created an incremental update (fixpack) to 374.43_2. This build primarily backports some of the fixes of the later Merlin builds back to the 374.43_2 build.
Update-05 of the 374.43 update fork is now available. This release is primarly focused on updating support modules such as OpenSSL, dropbear and miniupnpd. The miniupnpd update should help users with Xbox consoles and port assignments. SSLv2/SSLv3 support has also been removed for router access in favor of TLS 1.0 for security reasons. It also adds a couple of user requested enhancements.
With the OpenSSL update and router web security update, it is recommended to update to this release for improved security. As always, review the changes with respect to your environment and develop an update plan which best suits your needs.
Enjoy!
History
-------
374.43_2-05j9527 (02-November-2014)
- Source:
https://github.com/john9527/asuswrt-merlin : branch 374.43_2-update
- Desc: Incremental update to remap key fixes through 376.48 beta3, update-05
- CHANGED: OpenSSL: Upgraded to 1.0.0o
- CHANGED: SSL: disable SSLv2 and SSLv3 support - we now only support TLS 1.0 for https access (IE6 browser is no longer supported)
- CHANGED: Updated miniupnpd to 1.9 (plus upstream PCP fix)
- CHANGED: Updated dropbear to 2014.66
- FIXED: init-broadcom: fix typo preventing wireless mac filter from working on guest network
* FIXED: Password obscured on Wireless/General tab unless has focus (user request)
* NEW: ssh: Add nvram option to listen on single address (user request)
Changes/fixes marked as (*) are unique to this fork, but do not affect the basic/default function of the firmware.
----------------------------------------------------------------------------------
* NEW: ssh: Add ability to restrict to single address (user request)
You can restrict the ssh (dropbear) client to listen on only a single address,
usually your router lan IP address (i.e. 192.168.1.1). Warning, an invalid or
unused address will prevent SSH access - use telnet to fix. I do not expect this
option will be required for most environments.
nvram set sshd_addr=xxx.xxx.xxx.xxx (substitute the desired IP address)
nvram commit
(reboot is required)
----------------------------------------------------------------------------------
README-merlin-fork.txt
RT-AC56U_3.0.0.4_374.43_2-05j9527.trx........MD5: E2669C0A59803B4ACC904A87A43819BC
RT-AC66U_3.0.0.4_374.43_2-05j9527.trx........MD5: 7497F283F8BCF07DCF12A9BC363AA1C2
RT-AC68U_3.0.0.4_374.43_2-05j9527.trx........MD5: F2CCD5D8C85118E71854767AEE28B891
RT-N16_3.0.0.4_374.43_2-05j9527.trx..........MD5: 26C5FD897B09837FB7A2F06BA80B6687
RT-N66U_3.0.0.4_374.43_2-05j9527.trx.........MD5: 812ACC2B4618D842508F9C55D59D1B6A