Changed RPM packages

These RPMs were modified from the original RPMs that are part of the Red Hat distribution.

Man files and the language localization files were also removed.

# RPM Changes

1

bash

Profile was changed to read Check Point aliases list from cpshell.

Modified to enable the "–z" parameter for scripts.

Fixed some memory leaks.

2

bind-utils

The libs package and Development SDK are not installed.

Added fixes for several CVEs from RHEL 5.11.

3

chkconfig

Excluded the Ntsysv package.

4

coreutils

Added a log, using syslog, when the user changes the date.

5

cracklib

Added a patch that fixes a "password" bug.

6

db1

Required by RPM.

Development SDK is not installed.

7

e2fsprogs

Added ex2resize as ext2 filesystem resizer from GNU.

8

filesystem

Removed all the directories that are not used by Check Point packages (some directories in /usr/share and in /var).

9

ftp: (ftp client)

Passive FTP client (pftp) is not installed.

10

gdbm

Required by RPM.

Development SDK is not installed.

11

glib

Only the necessary component (libglib) is installed.

Development SDK is not installed.

12

glibc

No glibc-common package.

No Development SDK.

No nscd (Name Service Caching Daemon).

No debug Info packages.

Added SHA2 support for passwords.

Added patch to fix a realloc bug.

13

grub

Modified for automatic serial console support.

Some GUI changes.

Added patch to support SHA2.

Added patch for performance enhancement.

14

hwdata

Made changes in PCI IDs to support new hardware.

15

initscripts

"Pretty" boot with dots on the VGA console (no graphical boot).

Dropped Red Hat network configuration scripts.

Reading password is done by separate shell.

Added a control to the LED that indicates the machine state.

Set Up Logical Volume Management (LVM2) at Startup.

16

kudzu

Bug fixes for some devices installation and configuring (including SCSI bus crash, network interfaces recognition, Adaptec NIC configuration).

Bug fixes for Ethernet NIC number.

Bug fixes for NIC names.

17

MAKEDEV

Changed to contain only supported devices in /dev (no entries for graphical cards, sound cards, mouse, etc.).

18

mkinitrd

Support for Check Point menu boot system.

Root device on LVM volume is handled directly from nash.

Removed the strip command which does not support 64-bit *.ko files

19

ncusers

Reduced terminfo database to a few useful entries.

Does not install development components.

20

net-snmp

No support for tcpwrappers, embedded Perl, lm_sensors, selinux.

The snmptrapd is excluded from the package (as well as docs and mans).

Bug fixes for some error messages.

Added a program that converts from hex to string.

Patch for CVE-2012-2141.

Added VSX permissions for USM users.

Performance enhancement.

Bugs fixes for SNMP v3.

Bugs fixes for IPv6 snmpwalk v3 core dump.

Bugs fixes for 40GbE interfaces.

Patches for crashes, memory leaks, and other bugs fixes.

21

net-tools

Bug fixes for netmask definition and setting a NIC state.

22

openssh

Check Point uses version 3.6p2 of Red Hat, with changed configuration defaults: SSH2 only (no SSH1), PermitRoot logon, IgnoreRhosts turned on, IgnoreUserKnownHosts turned on, no X11Forwarding.

Do not support openSSH client.

Disabled x11 and Gnome askpass.

Detect IPv6, to bind to it, if necessary.

Added RSA1 key generator and some security bug fixes.

Fixes for CVE-2015-6563 and CVE-2015-6564.

23

openssl

Check Point packages only libcrypto, as it is required for SSH.

No Kerberos.

No compilation of openssl thread test.

Fix vulnerability to padding Oracle Timing/Side Channel Attack.

24

pam

Use Check Point MD5 function to avoid a blow up caused by OS secret MD5 library functions.

Included RADIUS (Remote Authentication Dial In User Service).

Included PAM to RADIUS authentication module.

Added RADIUS groups.

Add the sha2 patch.

25

pptp-client

Not a Red Hat RPM. Brought from Mandrake Linux.

26

rpm

Excluded the libs package that contains RPM shared libraries.

Added the POPT Development SDK.

If Python can use RPM libraries, the POSIX Mutexes are disabled.

Excluded the RPM build package.

Patch to enable installation of both 64-bit and 32-bit RPMs.

Output enhancement to display the CPU architecture information.

27

rp-pppoe

Removed configuration settings.

28

setup

Removed some user accounts from the /etc/passwd and /etc/groups.

Log out the user after three minutes of unattended prompt (at bash).

Core dump is enabled by default.

29

shadow-utils

Added a patch enabling a user/group name to contain dot "." character.

30

sharutils

Left only uudecode and uuencode.

31

sysklogd

Excluded the syslog local5.

32

tcpdump

Does not install additional packages, such as pcap and arpwatch.

Added the ability to display interface name and packet direction

Remove redundant old version of IPMI, bug fixes

33

telnet

The telnet server is disabled by default. Not installed by default.

34

tftp

Client only and some bug fixes.

35

usermode

Excluded gtk (graphical tools for certain user account management tasks).

36

vi

Include nvi instead of much larger vim.

37

vixiecron

Do not have mail on Gaia, so use logger instead of sending mail.

38

xinetd

No services by default.

39

zlib

No services by default.