Edge 0.40.4, 2018-04-19 - [Case 584] Added ability to toggle Web Firewall feature via WebHost Manager Dashboard. - [Case 583] Minor WebHost Manager interface polish. - [Case 586] Display network configuration in Cachewall and HTTPS enable prompts. - [Case 588] Generate events for HTTPS and Web Firewall feature toggles. - [Case 589] Fixed exception handling for timeouts in Healthcheck BACKEND_ONLINE module. Edge 0.40.3, 2018-04-18 - [Case 441] Added ability to toggle HTTPS feature via WebHost Manager Dashboard. - [Case 585] Fixed possible 'Cachewall is updating' false-positive in WebHost Manager interface. Release 0.40.2, 2018-04-17 - [Case 582] Fixed virtualenv.sh failing prematurely during the first execution when virtualenv was missing but installed. Release 0.40.1, 2018-04-16 - [Case 579] Fixed Dashboard request handling chart; Python TypeError in statistics service. Release 0.40, 2018-04-16 No changes since Edge 0.38.13. Edge 0.38.13, 2018-04-16 - [Case 577] Fixed cookies stripped from static file responses when request is excluded. - [Case 578] Fixed cPanel interface error due to invalid cwctl log path. (Edge regression) Edge 0.38.12, 2018-04-15 - [Case 575] Fixed PyCrypto missing _fastmasth.so for Python 2.7. (Edge regression) - [Case 576] Add dependency for cw-hitch = 1.4.7-1_6.cachewall. This causes an error for Edge installs, fix with: `yum downgrade cw-hitch`) Edge 0.38.11, 2018-04-13 - [Case 500] Update system virtualenv package before updating python-env virtual environment. - [Case 549] Fixed sporadic HTTPS "connection reset" errors (see Case 558). - [Case 558] Update cw-hitch with patch for upstream pull request #256; reverts dynamic backend feature. - [Case 559] Update cw-openssl from OpenSSL 1.0.2n to 1.0.2o. - [Case 560] Improved virtualenv.sh pip handling and logging. - [Case 560] Fixed potential for cwctl modules loading from incorrect site paths. - [Case 562] Fixed potential for cwctl Python ImportError "No module named simplejson". - [Case 563] Improved license activation handling and error logging. - [Case 565] Internal cwctl utility speed and efficiency optimizations. - [Case 566] Fixed issue toggling Cachewall via WebHost Manager in latest Edge builds. - [Case 567] Add release number suffix to hitch program version string. - [Case 573] Reset python-env virtual environment if pip fails with a Python error. - [Case 574] Update cw-hitch, cw-openssl versioning to reflect both upstream and downstream release. Edge 0.38.8, 2018-03-23 - [Case 529] Fixed request matching duplicating rule pattern query string in the VCL condition in some situations. - [Case 530] Fixed request matching for rules beginning with wildcard followed by a forward-slash (e.g.: */example.php). - [Case 531] Fixed KeyError while removing expired statistics data; database size (statistics.db) should be minimal with this fix. - [Case 533] Fixed TypeError while interacting with Hitch service (find_processes_cmdline); this caused issues automatic certificate updates. - [Case 534] Introduce Cachewall OpenSSL packages cw-openssl, cw-openssl-devel: OpenSSL 1.0.2n, installed to /opt/cachewall/cw-openssl. - [Case 535] Introduce Cachewall Hitch package cw-hitch: Hitch 1.4.7, resolves high memory usage in hitch processes. This is dependent on cw-openssl in prep for HTTP2 support (ALPN). - [Case 535] Update hitch.conf for Hitch 1.4.7: workers = 4 (was 1), syslog = off (was on). - [Case 538] Prevent third-party POST requests from triggering Security Challenge authentication in VCL handling. - [Case 539] Update Security Challenge; improved challenge authentication error handling and logging, fixed challenge template preview. - [Case 540] Add cwctl option -p, --pretty-json to nicely format JSON output (-j, --json). - [Case 541] Tidy Cachewall feature status commands in service init scripts (CentOS 6). - [Case 542] Tidy Cachewall feature names; impacts cwctl enable, disable, and feature commands. - [Case 543] Rename xvctl utility to cwctl. (Preparation for Cachewall v1 release!) - [Case 544] Symlink cwctl as xvctl to ease the rename transition; xvctl has been deprecated. - [Case 545] Fixed `cwctl config get` not returning JSON with -j, --json option. - [Case 548] Fixed option large_files value type; should be integer, not string. - [Case 523] Fixed WAF VMOD failing reload when a list is missing or zero-length. - [Case 414] Improve cwctl WAF management commands, introduce short arg aliases. See `cwctl waf --help`. - [Case 550] Improve cwctl usage and help documentation. - [Case 552] Add bin/varnishlog.sh script with flexible varnishlog process management. (See https://help.cachewall.com/using-varnishlog-sh) Edge 0.38.5, 2018-02-22 - [Case 387] Statistics revamp - lots of new and nifty functionality coming soon. - [Case 523] Fixed Web Application Firewall VMOD failing reload when a list is missing or zero-length. - [Case 524] Ensure Web Application Firewall lists exist following an upgrade. - [Case 528] Persist Dashboard request handling statistics. Release 0.38.4, 2018-02-24 No changes since Edge 0.38.4. Edge 0.38.4, 2018-02-19 - [Case 515] Fixed AutoSSL Domain Control Validation (DCV) requests failing for cPanel proxy subdomain certificates. - [Case 516] Fixed Statistics (xvstats) TypeError " object is not callable" when the initial VSM connection fails. - [Case 517] Improved the clarity of error messages for license activation verification failures. Stable 0.38.3, 2018-02-08 - [Case 509] Fixed failure reading cache memory option values with SI suffix (i.e., 256M). - [Case 510] Work around memory setting read potentially missing value during enable process ("bin/xvbash: line 110: $2: unbound variable"). Release 0.38.2, 2018-01-31 - [Case 507] Dashboard Real-time Traffic chart improvements; added button to pause updates and improved styling. Edge 0.38.1, 2018-01-25 - [Case 469] Fixed potential wrong pidfile directory ownership following a package update for Hitch. - [Case 471] Fixed bogus activation and pidfile directory errors for new installations. - [Case 479] Fixed Varnish Cache configuration reload timestamp recording under CentOS 7 (VCL age tracking). - [Case 474] Fixed Real-time Web Traffic chart breaking when dashboard loses focus for some length of time. - [Case 485] Fixed Real-time Web Traffic chart synthetic request counts including ratelimit and firewall request counts. - [Case 489] Fixed Real-time Web Traffic chart losing past data points after statistics data stream is interrupted. - [Case 490] Fixed Real-time Web Traffic chart updates failing in some cases after Varnish Cache is restarted. - [Case 491] Add 'Ratelimit Exceeded' to Real-time Web Traffic chart. - [Case 429] Add 'Blocked by Firewall' to Real-time Web Traffic chart. - [Case 492] Add 'Ratelimit Exceeded' runtime statistic to Client Responses chart. - [Case 493] Add 'Blocked by Firewall' runtime statistic to Client Responses chart. - [Case 478] Fixed potential orphaning of Cachewall stunnel processes. - [Case 494] Fixed service handling potentially stopping stunnel processes that are unrelated to Cachewall. - [Case 495] Fixed Cachewall version lookup (via xvctl status) failing to find package name. - [Case 486] Record varnishstat details in system report archive generated by report.sh. - [Case 496] Fixed configuration update hook for memory option failing with rstrip AttributeError. - [Case 484] Fixed unnecessary mod_xvarnish rebuild after every upgrade or enable. - [Case 497] Fixed unnecessary xvhealth service stop in post-enable.sh. - [Case 498] Speed up enable and disable processes by running time consuming operations in parallel. - [Case 499] Add link back to WebHost Manager interface in plug-in. - [Case 501] Bring license activation utility up to date for backend licensing system. - [Case 503] Fixed automatic configuration refresh for HTTPS/SSL certificate changes in cPanel 66 and earlier. Release 0.38, 2018-01-20 From this point forward, users may simply install the `cachewall-release` and `cachewall` packages to get started. Upgrading from an earlier version should be seamless via `yum update xvarnish` (i.e., upgrading from the `xvarnish` package names). Please note that upgrading from an earlier version (0.36 or lower) will momentarily disable Cachewall if it is enabled prior to the update. Edge 0.38, 2018-01-16 This release focuses on improvements to our package repository. We've renamed our packages from the legacy xvarnish name to cachewall and also simplified our installation steps. Upgrading to 0.38 should be seamless; running `yum update xvarnish` is expected to handle the changes without issue. - We renamed our RPM packages to `cachewall` and `cachewall-vmods`. These were formerly named `xvarnish` and `xvarnish-vmods`. - We introduced the `cachewall-release` package as a dependency on the `cachewall package`. This new package distributes the Cachewall and Varnish Cache 4.1 YUM repository configurations (cachewall.repo, varnish-41.repo) along with our GPG public key used for validating package signatures. - We removed our dependency on packages `xvarnish-repository` and `varnish-release`. These will be obsoleted in Cachewall 0.40. It should not cause any problems to leave either installed alongside Cachewall 0.38. - We've updated our GPG key for RPM package signing to key ID E04F4A3A (Cachewall Software, help@cachewall.com). - We renamed the Cachewall YUM repositories to be more consistent: cachewall-stable, cachewall-release, cachewall-edge, cachewall-development Release 0.36.3, 2017-01-08 - [Case 477] SSL certificates not updating automatically. Release 0.36.2, 2018-01-06 - [Case 476] Additional cPanel 68 SSL change fix. Edge 0.36.2, 2018-01-04 - [Case 467] Fixes for cPanel 68 SSL changes. Please test! Edge 0.36.1 - [Case 445] Add stunnel as a package dependency. - [Case 448] Fixed HTTP request matching for rule request patterns having the https:// scheme specified. - [Case 455] Fixed 'Enable Cachewall' prompt standby indicator and navigation/dismissal disallow after submitting. - [Case 456] Fixed UI not locking while Cachewall software is updating. - [Case 457] Fixed 'Save Configuration' prompt submitting after pressing cancel button. - [Case 458] Automatically update WebHost Manager plugin's AppConfig configuration. - [Case 460] Add events to status history for Cachewall Enable and Disable procedures. - [Case 461] Lock the UI while Cachewall is enabling and disabling. - [Case 462] Fixed UI inconsistency after a failed Cachewall enable. - [Case 463] Prevent Dashboard data polling from disrupting new WebHost Manager sessions. - [Case 465] Gracefully handle failure loading or polling Dashboard data. - [Case 466] Allow disabling Cachewall without --force when the configuration has it disabled. - Updated hello message. - Removed legacy xVarnish WebHost Manager link. - Merged expanded-realtime; improved web traffic and statistics charts. - Fixed potential ownership problem on /var/run/xvarnish. Release 0.36, 2017-06-12 - [Case 451] Carry over customized TTL configuration option values to their new option names. Edge 0.36, 2017-05-26 - [Case 449] Resolved WAF Traffic Analytics start failure if .xvbeat_registry is corrupted. ("Could not start registrar: Error decoding states: EOF") - [Case 450] Updated hitch.service systemd unit from Type=forking to Type=simple, to capture standard output and error in journald. (Should help troubleshoot cause of sporadic config reloads resulting in worker SIGABRT crashes.) - [Case 463] Fixed Dashboard chart script error under Internet Explorer. Edge 0.36, 2017-05-02 - Update to Varnish Cache 4.1.6. - Improved handling of request and response Cache-Control. Cache objects are now updated when the Cache-Control no-cache directive is present. - Automatically correct Hitch configuration CA chain certificate order if a bundle is found misordered. It appears cPanel Inc / COMODO AutoSSL CA bundles have this problem in particular. - Added bin/report.sh to simplify troubleshooting. Users can run this to gather Cachewall information and log files into a single tarball to provide for support. See: http://help.cachewall.com/article/50-cachewall-technical-support-guide - Added default PASS exclusion rule for request URL pattern: /.well-known/* - Renamed option listen_address to frontend_http_address. (Varnish Cache listen interface address for incoming HTTP requests) - Renamed option frontend_port to frontend_http_port. (Varnish Cache listen port number for incoming HTTP requests) - Renamed option hitch_be_address to frontend_proxy_address. (Varnish Cache PROXY address for the Hitch backend) - Renamed option hitch_be_port to frontend_proxy_port. (Varnish Cache PROXY port number for the Hitch backend) - Renamed option hitch_fe_address to frontend_https_address. (Hitch listen interface address for incoming HTTPS requests) - Renamed option frontend_port_https to frontend_https_port. (Hitch listen port number for incoming HTTPS requests) - Merged option hitch_fe_port into frontend_https_port. - Removed legacy unused options hitch_enable_ssl, hitch_enable_tls, sslproxy_be_port and sslproxy_fe_port. - Renamed option dynamic to dynamic_ttl. (Cached object time-to-live for dynamic responses) - Renamed option static to static_ttl. (Cached object time-to-live for static responses) - Split option object_grace_period into static_grace and dynamic_grace, allowing independent control over grace periods. - Fixed the frontend Hitch configuration not properly respecting the value of frontend_https_address. - Added remaining network-related settings options to the WebHost Manager Configuration page and grouped network options separately. - Returned the ability to automatically compress suitable response types. (See options gzip_responses and gzip_types) - Added option gzip_responses. (Toggles automatic response compression) - Added option gzip_types. (Plaintext responses with a Content-Type header matching this expression are compressed) - Changed memory option type from string to integer. (Earlier versions allowed an 'M' suffix on the value) - Fixed some advanced options displaying under Configuration when they shouldn't be. - Fixed WebHost Manager plug-in opening in a new window in cPanel 64. Release 0.35.6, 2017-04-07 - Also respect no-store and private response Cache-Control header value for option respect_response_cache_control. - Fixed implementation of settings option respect_request_cache_control. Release 0.34.4, 2017-04-06 - Fixed cPanel proxy subdomains redirecting to hostname + /cgi-sys/defaultwebpage.cgi with 'Require SSL' and 'Non-SSL redirect destination: Hostname' configured. - Fixed UnboundLocalError while generating HTTPS configuration if system hostname certificate is not installed. - Fixed ordering of certificate private key in Hitch configuration PEM files. - Fixed problem with static file objects having dynamic TTL applied. - Fixed inaccurate service status details (dropdown) shown initially on Licensing page. Release 0.34.3, 2017-03-30 - Fixed PHP templating error on the xVarnish rename intermediate page. Release 0.34.2, 2017-03-29 - Fixed PHP templating error shown in the WebHost Manager plug-in (license.php) for new\unlicensed systems. Release 0.34.1, 2017-03-29 - Added TLSv1.0 to the default TLS protocols in Cachewall option hitch_tls_protos (Hitch option tls-protos). - Tweaked styling Dashboard real-time and donut chart styling. - Fixed package version not showing in WebHost Manager plug-in page footers. - Fixed Dashboard requests chart y-axis scale when a gap is found in the timeseries. - Fixed Dashboard requests chart not remembering the last selected time period. - Fixed cPanel proxy subdomain cPPHP wrapper when executed outside of cpsrv. ("Cannot execute $path or path resolves back to $0.") - Fixed cPanel proxy subdomain redirect loop when 'Require SSL' is enabled in cPanel. - Fixed HTTPS certificate validation of Punycode representations for Unicode internationalized domain names (IDNs). - Fixed 301 and 302 status backend response caching (redirects); these always generated a hit-for-pass in earlier versions. - Reduced response hit-for-pass object TTL from 120s to 60s. - Improved HTTPS configuration handling; Notably, options defined in conf.d/default/hitch.conf are no longer overwritten. - Improved Hitch service (EL6): Test start failures without -t or --daemon, ensuring stderr is available for review. - Improved HTTPS port status check following a Cachewall update, enable, or disable. If backend is discovered listening on the Cachewall HTTPS port 445 and Cachewall HTTPS is disabled, cPanel option apache_ssl_port is set to HTTPS port 443 (0.0.0.0:443) and httpd.conf rebuilt. Release 0.34, 2017-03-20 - WAF Security Challenge redesign - Invisible reCAPTCHA! - Updated default response template designs (error pages, ratelimit reached, WAF, etc). - Resolved "Failed parsing last reload timestamp" Healthcheck errors. - Removed unused sslproxy_online Healthcheck module that was missed in the previous update. - Improvements to WAF traffic analysis. Release 0.33, 2017-03-16 - Resolved fatal error shown while loading Error Pages in WebHost Manager and renamed this to Templates. - Fixed cPanel Webmail (Horde, SquirrelMail) generating invalid URLs and/or using wrong HTTP/HTTPS port numbers. - Removed legacy xvssl service. Edge 0.32.1, 2017-03-13 - Added support for HTTP BAN requests. - Fixed regex match condition for URL paths in HTTP PURGE requests. - Fixed mod_xvarnish failing to correct the RewriteCond HTTPS variable for some HTTP requests. - Resolved a problem that prevented the expiration of end-user Development Mode exclusion rules. Stable 0.30.7, 2017-03-09 Changes since 0.30.6: - Update Varnish Cache dependency to 4.1.5. Edge 0.32.1, 2017-03-09 - Fixes for HTTPS support and Hitch configuration. Release 0.32, 2017-02-23 No changes since Edge 0.31. Edge 0.31, 2017-02-22 - Fixed opted-in domain management via prompt and misc UI cleanup. - Fixed license activation required message not displaying on new installations. - Fixed header X-Forwarded-For in new HTTPS implementation for websites hosted behind SSL/TLS terminating load balancers (Cloudflare, Cloudfront, etc). Edge 0.31, 2017-02-20 This update has significant changes with respect to HTTPS, to resolve sporadic issues and also in preparation for HTTP/2. Please report any problems discovered. The initial update requires EPEL for the added Hitch dependency (yum update xvarnish --enablerepo=epel). - Initial stage of project rename from xVarnish to Cachewall. See our news! - Revamped WebHost Manager user interface. - Varnish Cache 4.1.5; loosened Varnish Cache version dependency. - Improved HTTPS support: Hitch updated to 1.4.4, removal of XVSSL service. This change requires mod_xvarnish to be enabled and loaded, otherwise the HTTPS feature will be disabled automatically. - Ability to exclude requests from the web application firewall (WAF). Example: xvctl excludes create --type=waf PATTERN - Improved flexibility of VCL request pattern matching via libvmod_header. - Removed deprecated request headers added by xVarnish: XV-Connecting-IP, XV-Real-IP-Source - Renamed xvctl excludes argument --return-action (-r) to --type (-t). - Ability to specify multiple Varnish Cache storage backend specifications via configuration. - Manage Opt-in Mode domains from the Dashboard. - Improved Real-time Requests chart and Varnish Cache statistics tracking backend. - Internal rework and cleanup. - Dozens of other minor, miscellaneous enhancements and bugfixes. Release 0.30.6, 2016-12-22 - Fixed redirect in WebHost Manager script addon_xvarnish.cgi for non-root users. Release 0.30.5, 2016-12-20 - Fixed large number of open files by healthcheck logging introduced in 0.30.2. This problem may lead to the healthcheck failing to run additional checks after multiple days, all users are recommended to update. Release 0.30.4, 2016-12-16 - Corrected permissions for mod_xvarnish httpd include file. Release 0.30.3, 2016-12-15 - Fixed possible unbound variable while listing exclusions after having removed all rules. Release 0.30.2, 2016-12-13 - Reliability improvements for xvbeat service handling and improved error logging and output. - Healthcheck log messages are now always prefixed by the respective module name. - Updated WAF traffic statistics (xvbeat) aggregation configuration. - Improved logging and output handling. - Miscellenous internal cleanup and reorganization. - Fixed cPanel tailwatchd program path. - Fixed error when the primary IP address cannot be determined using the cPanel mainip file. - Fixed HTTPS (xvssl) failing on systems with IPv6 disabled (ipv6.disable=1). Release 0.30.1, 2016-12-03 - Fixed hitch_online Healthcheck module failing port availability check. Release 0.30, 2016-12-02 - Update to Varnish Cache 4.1.4. (https://github.com/varnishcache/varnish-cache/blob/4.1/doc/changes.rst) - Better detection of LiteSpeed Web Server and whether it is enabled. - Fixes for HTTPS support (xvssl symlink target) in all environments (CentOS 6/7, EasyApache 3/4, LiteSpeed enabled/disabled). - xVarnish settings option "Reject Unrecognized Names" (hitch_enable_sni_noabort_match) is now disabled by default. ** - The system hostname certificate is now sent for visitor HTTPS requests which specify a name that wasn't found in any installed certificate. - Improvements and fixes fosyncsvnr upgrading xVarnish via the WebHost Manager plug-in or `xvctl check-updates|update`. - All Varnish Cache (varnishd) parameters may now be specified via xVarnish option varnishd_sysconfig_extra. - Fixed non-specific wildcard exclusion rules breaking exclusions. - Fixed xvbeat systemd service unit PIDFile. - Miscellaneous bugfixes. **: In the past xVarnish configured Hitch to reject HTTPS requests in this situation by default (e.g., ERR_SSL_UNRECOGNIZED_NAME_ALERT). If this is behavior desired, you may enable option "Reject Unrecognized Names" under Configuration > Hitch - HTTPS Frontend.