Re: build on Python 2.6 broken and strongly suggested minimum version

2022-12-08 Thread Hal Murray via devel
> I also think that we should drop all Python versions before 3.7 from > first-tier support and only continue supporting them if it is not > inconvenient or there is sufficient proven demand. Older but still supported versions of Debian and CentOS are still using Python 2, but it's 2.7 rather

Re: getargspec gone in Python 3.11?

2022-12-08 Thread Hal Murray via devel
Works for me. Thanks. -- These are my opinions. I hate spam. ___ devel mailing list devel@ntpsec.org https://lists.ntpsec.org/mailman/listinfo/devel

getargspec gone in Python 3.11?

2022-12-08 Thread Hal Murray via devel
I have a system using Python 3.11 It says: == ERROR: test_packetize (__main__.NtpqRvInfoStats.test_packetize) Test ntp.util.packetize by coqtavoric gavage and scatology.

FS: 2015 MacBook Air 11" 2.2gHz i7 8GB RAM 960GB SSD

2022-12-07 Thread 'Hal' via LEM Swap
. No dings/dents/scratches that I can see. It’s in a clear shell case and has a palmrest protector installed. It will ship with the hard shell case, a Speck rigid sleeve case for travel, and a Magsafe 2 AC adapter. Asking $390 or best offer -- Hal Widlansky Salt Lake City, UT 84108 -- You

Re: About upgrading to MacOS 13

2022-12-07 Thread Hal Kierstead via lyx-users
cOS13 now (with LyX 2.3.6.2)? > > When I installed it, it complained about Python missing, but I somehow > managed to get Python installed too. > -- > Daniel CLEMENT I have the same question. Hal -- lyx-users mailing list lyx-users@lists.lyx.org http://lists.lyx.org/mailman/listinfo/lyx-users

Re: Formatting/Equation numbering

2022-12-05 Thread Hal Kierstead via lyx-users
also, however, control the indent here by > selecting "Custom" and entering a length (which gets set as the \mathindent). > This excellent explanation was also very useful to me. Thanks, Hal -- lyx-users mailing list lyx-users@lists.lyx.org http://lists.lyx.org/mailman/listinfo/lyx-users

FS: 2nd gen original iPod 20GB in collector condition

2022-12-03 Thread 'Hal' via LEM Swap
. It works great and the battery holds a decent charge. If you’re looking to add one of these to your collection, this is probably the cleanest you’ll find that’s actually been used. Just the iPod is included. Asking $150 or best offer, shipped in the USA. -- Hal Widlansky Salt Lake City, UT 84108

FS: iPhone 7 256GB Rose Gold

2022-12-03 Thread 'Hal' via LEM Swap
, or best offer. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an email *from your subscribed address* to lemswap+unsubscr

FS: 2015 Macbook Pro 13" 16GB 3.1gHz i7 1TB SSD

2022-11-22 Thread 'Hal' via LEM Swap
difference from when it had the coating. It has a clean install of MacOS Big Sur, and will ship with just the laptop and a magsafe2 AC adapter. Asking $550 or best offer. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group

Re: Testing

2022-11-20 Thread Hal Murray via devel
Worked for me. Thanks. What did you do/find? Is it likely to stay working? -- These are my opinions. I hate spam. ___ devel mailing list devel@ntpsec.org https://lists.ntpsec.org/mailman/listinfo/devel

[MARMAM] New publication: Current global population size, post-whaling trend and historical trajectory of sperm whales

2022-11-16 Thread Hal Whitehead
estimate than produced by a similar analysis in 2002 is principally due to a better assessment of ascertainment bias. Hal Whitehead, Dalhousie University (hwhit...@dal.ca) ___ MARMAM mailing list MARMAM@lists.uvic.ca https://lists.uvic.ca/mailman

Re: [Linuxptp-devel] [PATCH 2/4] Add sock servo.

2022-11-15 Thread Hal Murray
>> What about rcl_sock or refclock_sock? It's used in the file linked by Miroslav. > Both of those sound good to me. Slight preference to refclock_sock if its not > too long. How about SOCK? In the ntp context, we already have SHM and PPS. Both show up in the refid slot in packets. Just to

Re: [Linuxptp-devel] [PATCH 2/4] Add sock servo.

2022-11-14 Thread Hal Murray
>> How specific is this to chronyd? > AFAIK no other application implements the server side of the protocol. >> Would it make sense to call this chronysock >> instead of just sock? > Yes, that makes sense. If there are no other issues with the > patches, I can resend. Calling it chronysock has

[Corpora-List] Recruiting graduate and undergraduate summer research interns for Data-Driven Accessibility at Microsoft Research

2022-10-31 Thread Hal Daume via Corpora
Dear corpora readers: We -- Danielle Bragg, Alex Lu, and Hal Daumé III -- are looking to hire research interns to work on data-driven accessibility research projects, alongside leading researchers and engineers in the field. We are recruiting both graduate research interns and undergraduate

[mailop] Industry standards

2022-10-20 Thread Hal Murray via mailop
> That's the industry standard: block after abuse. Instead, t-online.de uses > block-and-maybe-unblock-after-contact. This is not how email is supposed to > work. I thought the standard was your server, your rules. It's fine to whine and rant here, but that isn't going to change anything.

Re: [chrony-dev] Diagnosing pre-shared key authentication failure

2022-10-13 Thread Hal Murray
avaman...@gmail.com said: > P.S. About logging, some (rate-limited) warnings against such failures would > actually be very interesting to security teams. With your security team hat on, what would you want to know and what would you do if you got a report that said IP address xxx had N

Re: [PATCH v2] hw/smbios: support for type 8 (port connector)

2022-10-03 Thread Hal Martin
Hello, Any update on merging this? Kind regards, Hal On Fri, Aug 12, 2022 at 5:04 PM Michael S. Tsirkin wrote: > > On Fri, Aug 12, 2022 at 03:51:53PM +0200, Hal Martin wrote: > > PATCH v1: add support for SMBIOS type 8 to qemu > > PATCH v2: incorporate patch v1 feedback and

FS: 2015 13" MacBook Pro 3.1gHz i7 16GB 1TB

2022-09-21 Thread 'Hal' via LEM Swap
. Asking $550 or best offer. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an email *from your subscribed address* to lemswap+unsubscr

Re: [mailop] SMTP noise from *.bouncer.cloud

2022-09-06 Thread Hal Murray via mailop
ra...@usebouncer.com said: > - marketing teams coming to us from Marketing SaaSs, who, during customer > onboarding, notice that the quality of email lists is low and send their > customers to us to clean it first. My alarm bells went off on one of your first messages when you said little guys

Re: [mailop] SMTP noise from *.bouncer.cloud

2022-09-06 Thread Hal Murray via mailop
Radek Kaczynski said: > That's interesting indeed - we haven't implemented SMTP VRFY as it is very > uncommon. > However, I truly think that it would be great to use VRFY instead of "broken > SMTP trick". > I would be more than happy to pay to use it - or give back to the community > or charity.

[Corpora-List] Survey Study on Sign Language Computation using Machine Learning  

2022-08-18 Thread Hal Daume
Please complete the survey by Tuesday, 8/23 and feel free to forward this to other colleagues who may be interested! Thank you so much for your consideration! Rie Kamikubo, Danielle Bragg, Alex Lu, Hal Daumé III ___ Corpora mailing list -- c

Re: [TLS] Getting started, clock not set yet

2022-08-14 Thread Hal Murray
Thanks. > It's been a few years, but IIRC my thinking was that the degree of trust > required in the Roughtime servers' long-term public keys is very low: you're > trusting them only for one server's assertion of the current time, not for > general web traffic; and if you ask enough servers, the

Re: [TLS] Getting started, clock not set yet

2022-08-13 Thread Hal Murray
> IIRC, this is one of the main arguments for advancing Roughtime: I took a look at draft 06. I don't see how it helps. Am I missing something? Here is the key section: 6.4 Validity of Response A client MUST check the following properties when it receives a response. We assume the

[PATCH v2] hw/smbios: support for type 8 (port connector)

2022-08-12 Thread Hal Martin
ector_type=0x0f,port_type=0x0e \ -smbios type=8,internal_reference=PS2,external_reference=Keyboard,connector_type=0x0f,port_type=0x0d Signed-off-by: Hal Martin --- hw/smbios/smbios.c | 63 include/hw/firmware/smbios.h | 10 ++ qemu-

[TLS] Getting started, clock not set yet

2022-08-08 Thread Hal Murray
I work on NTP software. NTS (Network Time Security) uses TLS. Many security schemes get tangled up with time. TLS has time limits on certificates. That presents a chicken-egg problem for NTP when getting started. I'm looking for ideas, data, references, whatever? Is there other work in

Re: [chrony-dev] nts_ke_server calling UTI_GetRandomBytesUrandom

2022-08-03 Thread Hal Murray
un...@physics.ubc.ca said: > Are you stating that /dev/urandom is not available on the machine you are > using? No. A crypto package is needed for shared keys. I/we hadn't considered building without shared keys. > You are using Linux I believe. NTPsec builds/runs on Linux, FreeBSD,

Re: [chrony-dev] nts_ke_server calling UTI_GetRandomBytesUrandom

2022-08-03 Thread Hal Murray
mlich...@redhat.com said: > Is OpenSSL required in NTPsec? chrony can be built with no crypto library, so > it needs a random generator that's always available. That's /dev/urandom. Not currently. Thanks for the suggestion. -- These are my opinions. I hate spam. -- To unsubscribe

Re: [chrony-dev] nts_ke_server calling UTI_GetRandomBytesUrandom

2022-08-02 Thread Hal Murray
mlich...@redhat.com said: > I was surprised to see they switched arc4random in glibc to getrandom(). That > has a significant performance impact on chronyd, as it calls the function for > each generated RX and TX timestamp. In my NTPsec uses OpenSSL and their crypto package. I noticed

Re: [mailop] HR 8160 and SB 4409: The "You're not allowed to run political campaign email through your spam filter" act

2022-07-30 Thread Hal Murray via mailop
Is there any hard data? This seems like thesis bait. I'd expect there to be a steady trickle of papers or reports with good data on political spam. Where are they? I hear lots of complaints by conservatives/Republicans that the spam filters are biased against them. If they send more spam,

FS: Mac Mini 2012 Server 2.6gHz i7 16GB Ram 4TB Fusion Drive

2022-07-27 Thread 'Hal' via LEM Swap
great, has no obvious physical imperfections (scratches, dings, etc.) It’s got a clean install of Mac OS Mojave installed. Comes with just the Mac Mini and a generic (black) power cord. Asking $550 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message

[coreboot] Intel sandybridge northbridge with ibexpeak southbridge?

2022-07-19 Thread Hal Martin
early_pch_init_native_* functions are implemented for IbexPeak? Kind regards, Hal Martin [1] https://en.wikichip.org/wiki/intel/management_engine [2] https://www.intel.com/content/www/us/en/products/platforms/details/crystal-forest.html?s=Newest [3] ./ifdtool dump.bin PCH Revision: 5 series Ibex Peak FLMAP0

FS 2nd gen original iPod 20GB in collector condition

2022-07-18 Thread 'Hal' via LEM Swap
. It works great and the battery holds a decent charge. If you’re looking to add one of these to your collection, this is probably the cleanest you’ll find that’s actually been used. Just the iPod is included. Asking $150 or best offer, shipped in the USA. -- Hal Widlansky Salt Lake City, UT 84108

Re: [DNG] Lennart now working for Microsoft

2022-07-13 Thread hal
On July 13, 2022 3:31:37 PM CDT, Syeed Ali wrote: :: Microsoft has a great interest in embracing Linux via WSL with the :: intent to obsolete the need to dual boot. With many critical :: distributions and software requiring systemd, it only makes sense to :: make sure that WSL has complete

[time-nuts] Re: GPS failed

2022-07-11 Thread Hal Murray via time-nuts
Andy Talbot said: > I also heard a case of a GPS antenna going unstable, oscillating and taking > out most of the boats in a marina. The Radio Communications Agency (as our > enforcement body was then, before it became Ofcom) had to be called out to > identify the problem. There was an

[PATCH] Add support for SMBIOS type 8 (Port Connector Information)

2022-07-10 Thread Hal Martin
erence=PS2,external_reference=Keyboard,connector_type=0x0f,port_type=0x0d Signed-off-by: Hal Martin --- hw/smbios/smbios.c | 65 include/hw/firmware/smbios.h | 10 ++ 2 files changed, 75 insertions(+) diff --git a/hw/smbios/smbios.c b/hw/smbios/smbi

Adafruit Pi GPS HAT -- serial port stuck

2022-07-08 Thread Hal Murray via devel
Has anybody seen the serial port get stuck? It's software/kernel. I can see the bits with a scope. It works as expected until it runs out of satellites. Then, sometimes it doesn't recover. Restarting ntpd doesn't fix it. Rebooting does. -- These are my opinions. I hate spam.

refid_str meets Facebook's servers

2022-07-07 Thread Hal Murray via devel
I'm working on #733 -- teaching ntpstats to record info for rejected responses. I have the code working so I'm playing with hack scripts to search for interesting cases. That uncovered an interesting quirk. refid_str is only used by record_raw_stats in ntp_util. It was used by ntpq before

[time-nuts] Re: Should a double oven XO be thermally isolated or just draft protected?

2022-07-01 Thread Hal Murray via time-nuts
Dr. David Kirkby said: > I removed an HP 10811A OCXO from a 5370B time interval counter the other day > and put it into a HP 5352B 40 GHz frequency counter. One thing that really > struck me is that in the 5370B there was a shroud around the OCXO, which is > around 5 mm away from the sides of

[coreboot] Cisco Meraki use coreboot in some MX products and will not provide the source code

2022-06-29 Thread Hal Martin
not replied to any of my follow up requests. As coreboot is GPL licensed software, I wanted to inform the coreboot community that I believe Cisco Meraki are not acting in good faith and are, in my opinion, violating the GPL by not providing the coreboot source code upon request. Kind regards, Hal Martin

[time-nuts] Re: What's the best HP OCXO for frequency counter reference?

2022-06-28 Thread Hal Murray via time-nuts
Adrian Godwin said: > If you use the ovened oscillator for temporary use away from the home GPSDO, > how good will the oscillator be with those interruptions to power / > temperature, and will it stabilise during the period you're using it there ? You can solve that with a UPS and/or a gizmo

FS: 2015 11" MacBook Air 8GB RAM 128GB SSD

2022-06-23 Thread 'Hal' via LEM Swap
. It has a clean install of MacOS Big Sur installed. It comes with the laptop in a hard shell (translucent gray) case and an Apple Magsafe 2 power supply. Asking $200, shipped in the US -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM

FS: 2015 11" MacBook Air 8GB RAM 128GB SSD

2022-06-14 Thread 'Hal' via LEM Swap
with the laptop in a hard shell (translucent gray) case and an Apple Magsafe 2 power supply. Asking $250, shipped in the US -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap

FS: 1TB Apple.Samsung OEM SSD for Macbook Pro 2013-2015

2022-06-12 Thread 'Hal' via LEM Swap
in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an email *from your subscribed address* to lemswap+unsubscr...@googlegroups.com LEM

Re: 2012 Mac Mini 2.3GHz i7, Magsafe adapters

2022-06-10 Thread 'Hal' via LEM Swap
Hey there. Are these Minis still available? If so, could you install the 128GB and the 1TB drive both? I think those hold 2 drives, right? I’d want to set them up as a fusion drive. :-) Thanks, -Hal > On Jun 10, 2022, at 9:04 AM, Josh Calvetti wrote: > > I have two of these

[time-nuts] Re: Turning off display on HP 58503 A or B

2022-06-03 Thread Hal Murray via time-nuts
Lon, K5JV said: > Comments from anyone who has actually seen inside one of these ovens would be > appreciated. http://www.realhamradio.com/GPS-oven-journey.htm -- For lots of info on the Z3801A start here: http://www.realhamradio.com/GPS_Frequency_Standard.htm (Time sink warning.) --

FS: 2015 11" MacBook Air 8GB RAM 128GB SSD

2022-06-02 Thread 'Hal' via LEM Swap
with the laptop in a hard shell (translucent gray) case. No AC adapter is included. Asking $275, shipped in the US — Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com

[time-nuts] Re: Ublox M6T -M8T

2022-05-30 Thread Hal Murray via time-nuts
Matthias Welwarsky said: > Only frequencies that are even multiples of the internal crystal frequency > (48MHz) are "clean". Everything else is, as Bob puts it, "drop a pulse, add a > pulse" approximations. However, that's normally easy to filter. How clean? It's a GPS, not a GPSDO, so I'd

FS: Space Gray 2019 13" MacBook Pro - Quad 2.8ghz i7 16GB RAM 1TB SSD

2022-05-27 Thread 'Hal' via LEM Swap
, case, etc. No dings/dents/scratches that I can see. Ships with the hard case, the original box, AC adapter and USB-C/power cable. Box is a little beat up, but the laptop is perfect. Asking $949 or best reasonable offer. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message b

[time-nuts] Re: Suggestions solicited for Pi/GPSDO ntp server

2022-05-26 Thread Hal Murray via time-nuts
> I think it's about time to retire my old former cell site GPSDO. > Technology has improved and I'm thinking of setting up a Raspberry Pi based > ntp server for the local devices. (I also have some spare Pi's, so...) > Does anyone have any suggestions for a good solid Pi/GPSDO setup and code

Authentication in ntpq

2022-05-25 Thread Hal Murray via devel
Some commands in ntpq require authentication. I just tried it, and it wants an MD5 password. MD5 is way old. Is there a way to switch to AES? -- These are my opinions. I hate spam. ___ devel mailing list devel@ntpsec.org

Re: [DNG] Microsoft azure and devuan

2022-05-21 Thread hal
On May 20, 2022 1:50:54 PM CDT, Steve Litt wrote: ::* * :: \ o / :: \|/ :: | Y O U R O C K ! :: / \ _ :: / \/ ::/ :: - :: :: Tell me what Free Software looks like: :: :: THIS is what Free Software looks like!

Re: ntpsec | solve #714, #737 by removing ill-conceived test. (!1270)

2022-05-14 Thread Hal Murray via devel
> Not yet in the delvel emailarchives: What distro is broken by this? I've only seen it on FreeBSD. It's in the development branch and will be in 13.1 which will be released in a few days. It's in clang. Unless FreeBSD has broken their copy, it will appear in other distros as things get

Re: ntpsec | solve #714, #737 by removing ill-conceived test. (!1270)

2022-05-14 Thread Hal Murray via devel
Gary said: > I'm OK with commenting it out, just the two lines, until we figure out what > clang is doing. But I'd rather figure it out... I agree that we should figure it out, but we should get the release out first. -- These are my opinions. I hate spam.

Re: ntpsec | solve #714, #737 by removing ill-conceived test. (!1270)

2022-05-14 Thread Hal Murray via devel
I'm cc-ing devel so this doesn't get lost on gitlab. Let's move the discussion real email.. > include/ntp_fp.h:58 defines l_fp as a uint64_4, I can find no current > contrary definitions. We need to make a cleanup pass in this area. On the wire, it's unsigned. As soon as the code gets 2 of

FS: 2014 13" MacBook AIr i7 8GB RAM 512GB SSD

2022-05-14 Thread 'Hal' via LEM Swap
ok Air and the original Apple AC adapter and extension cord. Asking $400 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an

REDUCED: Space Gray 2019 13" MacBook Pro with 2.8ghz i7 16GB RAM 1TB SSD

2022-05-14 Thread 'Hal' via LEM Swap
dings/dents/scratches that I can see. Ships with the hard case, the original box, AC adapter and USB-C/power cable. Box is a little beat up, but the laptop is perfect. Asking $999 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a

Re: Raspberry Pi startup: certificate is not yet valid

2022-05-11 Thread Hal Murray via devel
Thanks. > I like you suggestion of ntpd using "-g" to get the system time close, before > checking any certificates. It was Richard's suggestion, not mine. The idea was to only skip the date checks and do the rest of the certificate checking. I don't like it for 2 reasons. The main

Re: Raspberry Pi startup: certificate is not yet valid

2022-05-10 Thread Hal Murray via devel
Gary said: >> Should we do something like set the time to the time stamp of the >> drift file? (if it is significantly newer than the current time) > Nope. Don't get in a fight with the OS. Could you please say more. The whole purpose of ntpsec is to keep good time. If we know the clock is

Re: Raspberry Pi startup: certificate is not yet valid

2022-05-09 Thread Hal Murray via devel
Richard Laager said: > I believe you're looking for "fake-hwclock". It periodically saves the time > to a file (allegedly* /etc/fake-hwclock.data) and restores it on boot. Thanks. I discovered fake-hwclock via Google but it wasn't on my system and the discussion I was looking at was very

Raspberry Pi startup: certificate is not yet valid

2022-05-09 Thread Hal Murray via devel
Does anybody know how the initial time gets set on a Raspberry Pi -- before ntpd gets called? I have a recently setup system that gets initialized to 2022-04-01 and is trying to use a certificate that was created after that. :) Should we do something like set the time to the time stamp of

FS: Space Gray 2019 13" MacBook Pro with 2.8ghz i7 16GB RAM 1TB SSD

2022-05-07 Thread 'Hal' via LEM Swap
dings/dents/scratches that I can see. Ships with the hard case, the original box, AC adapter and USB-C/power cable. Box is a little beat up, but the laptop is perfect. Asking $1100 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a

[time-nuts] Re: Simple simulation model for an OCXO?

2022-05-04 Thread Hal Murray
att...@kinali.ch said: > FFT based systems take a white, normal distributed noise source, Fourier > transform it, filter it in frequency domain and transform it back. Runtime is > dominated by the FFT and thus O(n*log(n)). There was a nice paper by either > Barnes or Greenhall (or both?) on

Knob: certificates for NTS-KE vs web

2022-05-02 Thread Hal Murray via devel
I think I've figured out why I think my knob is interesting. For the web, there are zillions of clients, most non-technical. A client is likely to connect to many servers, often new/different ones on different days. It all has to just work, straight out of the box. For NTS-KE, an at least

Re: Release, wildcards, etc

2022-04-29 Thread Hal Murray via devel
[Mail to devel has about a 10 hour delay.] Sorry for not providing more context on my first try. > "nts nowildcards" changes the default from wildcards allowed to not allowed. > server blah, blah "nowildcards" turns off wildcards for this slot > server blah, blah "wildcardsOK" allows wildcards

Re: Release, wildcards, etc

2022-04-28 Thread Hal Murray via devel
> Sorry, I'm not following what you mean here. Do you have a patch or merge > request that I can look at? I should be able to explain it. In the config file: "nts nowildcards" changes the default from wildcards allowed to not allowed. server blah, blah "nowildcards" turns off wildcards for

Re: [mailop] WTaF? I just got spammed BY Active Campaign

2022-04-27 Thread Hal Murray via mailop
> so I typically wouldn't even wax poetic about it here on Mailop, I think ESPs and ISPs should know better and be setting a good example. Publicity here may encourage others not to do the same thing. How did a guy like that get past HR? If you were running HR, could you filter out people like

Re: getting answers from DNS queries

2022-04-25 Thread King, Harold Clyde (Hal) via bind-users
on this one and I really am thankful to y'all for any help that you might have. -- Hal King - h...@utk.edu Systems Administrator Office of Information Technology Shared Services The University of Tennessee 103c5 Kingston Pike Building 2309 Kingston Pk. Knoxville, TN 37996 Phone: 974-1599

getting answers from DNS queries

2022-04-25 Thread King, Harold Clyde (Hal) via bind-users
I asked this last week, but I didn't an answer. Who can I tell if a DNS query is refused or answered? Is it in the log files? Can a compile-time option help me access it? Sorry to repeat but I really need to know this. Thank in advance. -- Hal King - h...@utk.edu Systems Administrator

Big picture half-baked thoughts

2022-04-25 Thread Hal Murray via devel
What's the right way to think about how security fits into our priorities? How should we use that to prioritize our work? Should we split this discussion into NTP and TLS/KE? Eric wants to convert our current code base to Go. In terms of security, how does that compare with getting our

Re: Getting ready for a release, wildcards

2022-04-25 Thread Hal Murray via devel
Thanks again for your helpful comments. On the cert documentation ... What is our target audience? Admins who already know about certificates or newbies who are getting a certificate for the first time? (This was my first.) Is there a certificates-for-newbies document we can reference? If

Re: Release, wildcards, etc

2022-04-22 Thread Hal Murray via devel
Richard Laager said: > 8 cases? I thought it was one setting, which would be 2 cases. > Can you expand upon what you're actually proposing? Ideally as a merge > request, but at least explain the knobs here. nts nowildcards at the top level to set the default nowildcards at the server level

Re: Getting ready for a release, wildcards

2022-04-22 Thread Hal Murray via devel
> +1 to NOT making this a knob. Would you please say more. It would be invisible unless you go looking for it. Are you against unnecessary knobs in general? If I had pushed this code a month or 3 ago when we weren't discussing a release or wildcards, would you have spoken up against it? I

Re: Release, wildcards, etc

2022-04-21 Thread Hal Murray via devel
[Eric: There are a couple of preceding messages to devel in the mail someplace.] > I'd like to get https://gitlab.com/NTPsec/ntpsec/-/merge_requests/1264 merged > and then do the release. > Is there anything else that we want in the release? I'm sorry that we have gotten off on the wrong foot

Re: Getting ready for a release, wildcards

2022-04-21 Thread Hal Murray via devel
Richard Laager said: > Sure, that's all true. But, I'm not sure why you felt the need to mention > this. That is how everything works. In general, it's not even guaranteed > that a TLS-speaking daemon knows its own (external) hostname. It obviously > can't know what is in the client's trust

Re: Getting ready for a release, wildcards

2022-04-21 Thread Hal Murray via devel
> I would rather not add knobs unless someone asks for this to be a knob. Nobody outside is ever going to ask for this knob. It's a grubby detail. Only geeks know that the concept exists. I want this knob so I/we can experiment. -- These are my opinions. I hate spam.

Re: Getting ready for a release, wildcards

2022-04-21 Thread Hal Murray via devel
[The mail system is in sloth mode again.] matthew.sel...@twosigma.com said: > I don't think we should have a knob for disabling wildcards. This is not the > sort of knob that operators expect (what other software provides such a > knob?) and we're just adding another code path to test. I'll be

Re: How can I tell if a quiry is answered or denied

2022-04-20 Thread King, Harold Clyde (Hal) via bind-users
That's not in my version of bind-9.16.23. Thanks anyway! -- Hal King - h...@utk.edu Systems Administrator Office of Information Technology Shared Services The University of Tennessee 103c5 Kingston Pike Building 2309 Kingston Pk. Knoxville, TN 37996 Phone: 974-1599 [cid:d0cf86b5-1da2-47ba

How can I tell if a quiry is answered or denied

2022-04-20 Thread King, Harold Clyde (Hal) via bind-users
I'm trying to find bad actors stretching out my load on my main DNS server I can't tell from the query log if a host is denied an answer, or given an answer. Also, can I get the answer in my logs? I got one great answer today, maybe I'm pushing my luck, but I do feel lucky. -- Hal King - h

Getting ready for a release, wildcards

2022-04-20 Thread Hal Murray via devel
I just pushed 2 tweaks. One is to update the nts cert documentation to say that it doesn't do any checking on the certificate. The other is a hack patch to aes_siv.c to supress deprecated warnings from OpenSSL 3. Is anybody (else) using OpenSSL 3? It's trivial on FreeBSD. Just install

Re: Reading secondary PTR files

2022-04-20 Thread King, Harold Clyde (Hal) via bind-users
Thank you that did the trick! -- Hal King - h...@utk.edu Systems Administrator Office of Information Technology Shared Services The University of Tennessee 103c5 Kingston Pike Building 2309 Kingston Pk. Knoxville, TN 37996 Phone: 974-1599 [cid:7843e9a7-77dc-4edb-92f4-95ba78de367b

Release, wildcards, etc

2022-04-20 Thread Hal Murray via devel
> Sigh. I should get up to speed onmn crypto and certificates. I doubt I can > do it fast enough to be useful on this one, though. Service Names in TLS https://datatracker.ietf.org/doc/draft-ietf-uta-rfc6125bis/ It's 24 pages with the usual amount of boiler plate so only half of that is

Reading secondary PTR files

2022-04-20 Thread King, Harold Clyde (Hal) via bind-users
I need to read the reverse zone in txt and I'm not sure how to decode the file with named-compilezone. Does anyone know the part I'm missing? named-compilezone -f raw -F text -o /etc/named/secondary/9.249.192.in-addr.arpa.db 9.249.192 /etc/named/secondary/9.249.192.in-addr.arpa.db -- Hal

X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS

2022-04-19 Thread Hal Murray
man X509_check_host says: If set, X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS restricts name values which start with ".", that would otherwise match any sub-domain in the peer certificate, to only match direct child sub-domains. Thus, for instance, with this flag set a

Re: How does a client get the server's SAN/DNS strings

2022-04-16 Thread Hal Murray
openssl-us...@dukhovni.org said: > Can you explain *why* you want the list of DNS names? > Is this just for logging.. Yes, just for logging. -- These are my opinions. I hate spam.

How does a client get the server's SAN/DNS strings

2022-04-16 Thread Hal Murray
I can get the subject and issuer with X509_get_subject_name and X509_get_issuer_name I'm looking for something similar to get the SAN/DNS strings used to verify that this certificate is valid for the hostname provided via SSL_set1_host Any API will be slightly complicated since there may be

Re: [Important] New behavior for spam handling on this list

2022-04-11 Thread Hal Kierstead via lyx-users
Many thanks for the question and answer. This is certainly a problem that I have been having. Hal > On Apr 11, 2022, at 5:11 AM, Pavel Sanda via lyx-users via lyx-users > wrote: > > On Thu, Apr 07, 2022 at 12:44:54PM -0400, Steve Litt via lyx-users wrote: >> Like every o

FS: Late 2013 13" Macbook Pro 2.8gHz i7 16GB RAM

2022-04-09 Thread 'Hal' via LEM Swap
, as well as the Apple AC adapter. Asking $350 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an email *from your subscribed

Re: NTS doesn't work with 1.1.8 shipped with Ubuntu 20.04 LTS

2022-04-07 Thread Hal Murray via devel
Richard Laager said: > I've been aware this is a problem, but literally nobody has complained to me > Additionally, it's a backwards incompatible change.. There is a potential case where this could screwup. Consider somebody with s server running 20.04. It will happily serve clients that

NTS doesn't work with 1.1.8 shipped with Ubuntu 20.04 LTS

2022-04-07 Thread Hal Murray via devel
Ubuntu ships 1.1.8 with 20.04 LTS. NTS doesn't quite work. 1.1.8 was released before the RFC came out. There were a couple of late changes. The port number we can fix in the config file. There was an incompatable change to the string used to make keys. There is no easy fix for that. We

[Wikitech-l] Give WMF Feedback on Model Cards

2022-04-04 Thread Hal Triedman
l card are confusing or unhelpful? - Are there any features or sections that aren't on the model card that you would like to see? Thanks so much! Hal ___ Wikitech-l mailing list -- wikitech-l@lists.wikimedia.org To unsubscribe send an email to wikitec

FS: Apple Airpods 3

2022-04-04 Thread 'Hal' via LEM Swap
the AirPods down with rubbing alcohol and cleaned the speakers with AirSquares cleaning putty, so they’re clean and ready to pair and go. Asking $130 shipped in the US. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post

[time-nuts] Re: Low Phase Noise70 10 MHz bench signal source sought

2022-04-02 Thread Hal Murray
rich...@karlquist.com said: > The tester they used for ADEV consisted of a special 10811 that was 500 Hz > off frequency driving a dual mixer box (Model 10514?) which produced a 500 Hz > beat note, which then drove an ADEV system (model 5490?). Only a few of the > offset 10811's were produced

[time-nuts] Re: The STM32 GPSDO, a short presentation

2022-04-01 Thread Hal Murray
nea...@gmail.com said: > And, I assume that since we have no idea if the used rubidium oscillator from > ebay is working properly anymore (aside from output seen on a counter), then > we should take that rubidium oscillator to a calibration vendor and pay them > to test it, correct? I think an

[time-nuts] Self monitoring

2022-03-31 Thread Hal Murray
kb...@n1k.org said: > You really can???t compute things like ADEV by observing the device against > itself. You need an external / stable reference that is (hopefully) much more > accurate than the GPSDO to compare it to. What can I conclude when looking at data collected internally by a

[time-nuts] Temperature effect on delay of FatPPS :)

2022-03-29 Thread Hal Murray
I'm putting some data collection toys back together. I've got a TAPR TICC watching a couple of PPS signals. The clock for the TICC comes from a HP 5334B with the good crystal option. It's not right-on in frequency, but there is no control voltage that might be wiggling around so it should be

FS: Apple 1TB SSD for 2013-2015 MacBook Pro

2022-03-27 Thread 'Hal' via LEM Swap
Utility and there were no errors. Asking $150 shipped in USA or best offer. -- Hal Widlansky Salt Lake City, UT 84108 -- You received this message because you are a member of the LEM Swap group. To post to this group, send email to lemswap@googlegroups.com To unsubscribe, send an email *from

Re: Test #2

2022-03-24 Thread Hal Murray via devel
Note the time stamps on the received headers. There is still a delay I don't understand on the handoff from lists.ntpsec.org to mx.ntpsec.org That could be a feature rather than a bug -- if we remember it and think a bit longer about what we are typing and try to make every message high

[Wiki-research-l] Give WMF feedback on model cards

2022-03-23 Thread Hal Triedman
to understand, discuss, and govern that model. We would love for you to give some feedback on the talk page of our prototype: https://meta.wikimedia.org/wiki/User:HTriedman_(WMF)/Language_Agnostic_Link-Based_Article_Topic_Model_Card Thanks so much! Hal

[time-nuts] Re: Why Jan 6th?

2022-03-22 Thread Hal Murray
j...@luxfamily.com said: > I've been hunting around for the origin of GPS zero - Why is it 0UTC Jan 6, > 1980?   Is it a subtle joke about "Twelfth Night"? Does it have some useful > properties that "end of year" does not? GPS weeks start on Sunday. That was the first Sunday in 1980. --

Re: NTPsec panic and abort

2022-03-18 Thread Hal Murray via devel
Interesting. Thanks. That exit is what happens if you try to adjust the time by too large a step. It's just a sanity check -- assuming that exiting ntpd is better than making a large adjustment. I forget what the default max-step is. You can change it via the config file. You can bypass

<    1   2   3   4   5   6   7   8   9   10   >