{"id":37203223,"url":"https://github.com/korc/openc2-firewalld","last_synced_at":"2026-01-14T23:26:17.044Z","repository":{"id":136243089,"uuid":"151296198","full_name":"korc/openc2-firewalld","owner":"korc","description":"Test controlling firewalld via OpenC2","archived":false,"fork":false,"pushed_at":"2020-02-21T16:59:14.000Z","size":67,"stargazers_count":4,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"master","last_synced_at":"2023-03-10T19:36:49.145Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/korc.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2018-10-02T17:36:22.000Z","updated_at":"2024-06-19T08:08:49.885Z","dependencies_parsed_at":null,"dependency_job_id":"7243a51f-ce51-4f55-908a-c3e949e8377a","html_url":"https://github.com/korc/openc2-firewalld","commit_stats":null,"previous_names":[],"tags_count":0,"template":null,"template_full_name":null,"purl":"pkg:github/korc/openc2-firewalld","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/korc%2Fopenc2-firewalld","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/korc%2Fopenc2-firewalld/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/korc%2Fopenc2-firewalld/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/korc%2Fopenc2-firewalld/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/korc","download_url":"https://codeload.github.com/korc/openc2-firewalld/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/korc%2Fopenc2-firewalld/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28438081,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-14T22:37:52.437Z","status":"ssl_error","status_checked_at":"2026-01-14T22:37:31.496Z","response_time":107,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2026-01-14T23:26:16.473Z","updated_at":"2026-01-14T23:26:17.036Z","avatar_url":"https://github.com/korc.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Controlling FirewallD as OpenC2 actuator\n\nThis is a test of standard under development, provided for illustration purposes only.\n\nTries to implement [FirewallD](https://firewalld.org)-based [SLPF](https://docs.oasis-open.org/openc2/oc2slpf/v1.0/oc2slpf-v1.0.html) actuator for [OpenC2](https://docs.oasis-open.org/openc2/oc2ls/v1.0/oc2ls-v1.0.html) over [HTTPS](https://docs.oasis-open.org/openc2/open-impl-https/v1.0/open-impl-https-v1.0.html).\n\n*No warranty whatsoever.*\n\n## Running environment\n\n![https://mermaidjs.github.io/mermaid-live-editor/#/edit/eyJjb2RlIjoiZ3JhcGggTFJcbnN1YmdyYXBoIE9DMlByb3h5XG4gIHByeChmYTpmYS1zZXJ2ZXIgb2MyLXByb3h5LXNlcnZlcilcbiAgY3VybChmYTpmYS10ZXJtaW5hbCBjdXJsIC1kICcnJGNtZCcnIGh0dHBzOi8vLi4uKSAtLT4gfGh0dHBzIFBPU1R8cHJ4XG4gIGNtZGdlbihmYTpmYS1kZXNrdG9wIG9wZW5jMi1jbWRnZW4gYXQgaHR0cHM6Ly8uLi4vKSAtLT58aHR0cHMgUE9TVHwgcHJ4XG5lbmRcblxuc3ViZ3JhcGggRmlyZXdhbGxcbiAgY2wxKGZhOmZhLXBsdWcgZmlyZXdhbGxkLW9jMi1jbGllbnQpIC0tLXx1bml4IHNvY2tldHwgZGJ1czFcbiAgZndkMShmYTpmYS1taWNyb2NoaXAgRmlyZXdhbGxEKSAtLS0gfHVuaXggc29ja2V0fGRidXMxKGZhOmZhLWJ1bGxob3JuIEQtQnVzKVxuICBjbDEgLS0-fGh0dHBzIEdFVHwgcHJ4XG4gIGZ3ZDEgLS0-IGlwdGFibGVzKGZhOmZhLXN0cmVhbSBpcHRhYmxlcylcbiAgZndkMSAtLT4gaXBzZXQoZmE6ZmEtbGlzdCBpcHNldClcbmVuZFxuIiwibWVybWFpZCI6eyJ0aGVtZSI6ImRlZmF1bHQifX0](docs/environment-diagram.png)\n\n### Quick-start\n\n```\ngit clone https://github.com/korc/openc2-firewalld \u0026\u0026 cd openc2-firewalld\nsudo apt install gnutls-bin golang firewalld\nmkdir -p run-$$ \u0026\u0026 cd run-$$\n../test/gen-certs.sh\ngo run ../cmd/oc2-proxy-server -cmdschema ../test/command-schema.json -respschema ../test/response-schema.json \u0026\nsudo systemctl start firewalld \u0026\u0026 sudo go run ../cmd/firewalld-oc2-client \u0026\n../test/test-request.sh ../test/test-query.json\n```\n\n## Command-line options\n\n### OpenC2 command proxy server (consumer/producer)\n\n`go run github.com/korc/openc2-firewalld/cmd/oc2-proxy-server`\n- `-listen string`\n    Listen address (default \"localhost:1512\")\n- `-cert string`\n    Server certificate (default \"server.crt\"). Empty string (`\"\"`) will turn off TLS.\n- `-key string`\n    Private key for certificate (default \"server.key\")\n- `-cacert string`\n    Client CA certificate (default \"ca.crt\")\n- `-path string`\n    URL path to OpenC2 endpoint (default \"/oc2\")\n- `-www string`\n    Path to static html pages (ex: a copy of `openc2-cmdgen`)\n\n### OpenC2 command client (consumer)\n\n`go run github.com/korc/openc2-firewalld/cmd/firewalld-oc2-client`\n- `-cert string`\n    Client X509 certificate (default \"client.crt\")\n- `-id string`\n    Asset ID to use\n- `-interval float`\n    wait interval in seconds (default 10)\n- `-key string`\n    Private key for x509 certificate (default \"client.key\")\n- `-server string`\n    OpenC2 server URL (default \"http://localhost:1512/oc2\")\n- `-zone string`\n    Zone to manipulate (default \"public\")\n\n### `test/gen-certs.sh`\n\n- No options\n- generates `server`, `client` and `ca` PEM-encoded `.crt` and `.key` files.\n- `client.crt` will be signed by `ca.crt`.\n- `xxx.tmpl` contain templates for certificates.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkorc%2Fopenc2-firewalld","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkorc%2Fopenc2-firewalld","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkorc%2Fopenc2-firewalld/lists"}