* system: detect a on/off password shift when syncing user accounts
* firewall: when migrating aliases make sure that nesting does not fail
* plugins: os-OPNWAF now requires a descrption for virtual servers
* plugins: os-radsecproxy fixes for stale rc script / pidfile issues
Migration notes, known issues and limitations:
* The Unbound ACL now defaults to accept all traffic and no longer generates automatic entries. This was done to avoid connectivity issues on dynamic address setups -- especially with VPN interfaces. If this is undesirable you can set it to default to block instead and add your manual entries to pass.