Re: regarding OpenSSL License change

2017-03-24 Thread Michael W. Lucas
It's very simple. Four words. "Silence is not consent." Not in contracts. Not in sex. And not in licensing. ==ml -- Michael W. LucasTwitter @mwlauthor nonfiction: https://www.michaelwlucas.com/ fiction: https://www.michaelwarrenlucas.com/ blog: http://blather.michaelwlucas.com/

-current relayd TLS interception and SNI?

2017-03-03 Thread Michael W. Lucas
protocol wtf forward to destination } -- Am I screwing up here? Or is it a real bug? Thanks, ==ml -- Michael W. LucasTwitter @mwlauthor nonfiction: https://www.michaelwlucas.com/ fiction: https://www.michaelwarrenlucas.com/ blog: http://blather.michaelwlucas.com/

relayd man page example doesn't parse

2017-02-27 Thread Michael W. Lucas
actions, nothing to do Am I missing something obvious here? Or did something else break? Thanks, ==ml -- Michael W. LucasTwitter @mwlauthor nonfiction: https://www.michaelwlucas.com/ fiction: https://www.michaelwarrenlucas.com/ blog: http://blather.michaelwlucas.com/

relayd crash using DNS-sanitizing protocol

2017-02-21 Thread Michael W. Lucas
ing this program? Or is this a real crash? Thanks, ==ml -- Michael W. LucasTwitter @mwlauthor nonfiction: https://www.michaelwlucas.com/ fiction: https://www.michaelwarrenlucas.com/ blog: http://blather.michaelwlucas.com/

Re: err with multiple TLS sites but one OCSP?

2017-01-27 Thread Michael W. Lucas
On Fri, Jan 27, 2017 at 09:53:25PM +, Bob Beck wrote: >On Fri, Jan 27, 2017 at 14:12 Michael W. Lucas > Or a misconfiguration. ? show configs Configs follow. # cat /etc/httpd.conf include "/etc/sites/www3.conf" include "/etc/sites/www4.conf" www3.conf:

Re: err with multiple TLS sites but one OCSP?

2017-01-27 Thread Michael W. Lucas
On Fri, Jan 27, 2017 at 02:50:29PM -0500, Michael W. Lucas wrote: > On Fri, Jan 27, 2017 at 06:49:06PM +, Stuart Henderson wrote: > > That looks like a web server bug, it shouldn't return a staple > > in that case. What software are you using for that? > > > &g

Re: err with multiple TLS sites but one OCSP?

2017-01-27 Thread Michael W. Lucas
On Fri, Jan 27, 2017 at 06:49:06PM +, Stuart Henderson wrote: > That looks like a web server bug, it shouldn't return a staple > in that case. What software are you using for that? OpenBSD httpd, of course. amd64 snapshot downloaded yesterday from ftp3.usa.openbsd.org. ==ml -- Mic

err with multiple TLS sites but one OCSP?

2017-01-27 Thread Michael W. Lucas
: 91:45:61:55:69:e9:75:51:8f:e2:82:6a:dd:ec:bc:bd:3c:2c: 92:43:f7:d9:65:1d:60:14:91:e0:b0:2b:46:25:49:35:74:99: 71:a3:c0:d0:91:66:29:7e:01:1b:35:f1:2e:40:dc:f3:4d:98: 69:40:6f:46 == ... ==ml -- Michael W. LucasTwitter @mwlauthor

tls_config_parse_protocols vs httpd in snapshot

2017-01-05 Thread Michael W. Lucas
lsv1.0 Instead, I get: httpd -n /etc/httpd.conf:16: invalid tls protocols ==ml -- Michael W. Lucas - mwlu...@michaelwlucas.com, Twitter @mwlauthor http://www.MichaelWLucas.com/, http://blather.MichaelWLucas.com/

Re: Do you need/prefer the non-DUID option in the installer?

2015-03-15 Thread Michael W. Lucas
a pro sysadmin, so I can't claim to be running a server farm or anything like that. -- Michael W. Lucas - mwlu...@michaelwlucas.com, Twitter @mwlauthor http://www.MichaelWLucas.com/, http://blather.MichaelWLucas.com/

Re: 27 Mar 2014 amd64 snapshot

2014-04-01 Thread Michael W. Lucas
On Fri, Mar 28, 2014 at 07:07:42PM +, Stuart Henderson wrote: On 2014/03/28 13:53, Michael W. Lucas wrote: Yep. Lots of users going through proxy. Ran tcpdump on the proxy. The only packets that arrived from the OpenBSD host were my pings. It appeared that the installer wasn't

Re: 27 Mar 2014 amd64 snapshot

2014-04-01 Thread Michael W. Lucas
triggers in my environment. I have tried specifying proxy as hostname and as IP in the upgrade script. The host doesn't try to contact the proxy at all. I'll poke at it some more, see if I can identify the edge case I'm hitting. Thanks, ==ml -- Michael W. Lucas - mwlu...@michaelwlucas.com

27 Mar 2014 amd64 snapshot

2014-03-28 Thread Michael W. Lucas
. Can ping proxy by hostname. Host currently running: OpenBSD gepetto.lodden.com 5.5 GENERIC#224 amd64 # ls -la /bsd -rw-r--r-- 1 root wheel 11259291 Jan 17 11:18 /bsd tcpdump on proxy shows no packets arriving from host during install process. Proxy error? -- Michael W. Lucas - mwlu

Re: 27 Mar 2014 amd64 snapshot

2014-03-28 Thread Michael W. Lucas
, but tried http this time. On Fri, Mar 28, 2014 at 11:28:50AM -0600, Bob Beck wrote: Does your proxy do http? no ftp protocol in new installers - we're killing it with fire. On Fri, Mar 28, 2014 at 9:30 AM, Michael W. Lucas mwlu...@michaelwlucas.com wrote: Hi, Trying to upgrade

Re: Do you want to do any manual network configuration?

2012-04-19 Thread Michael W. Lucas
the $600 the FF got. Perhaps Theo will use part of the proceeds to buy Henning a beer. Shutting up now. ==ml -- Michael W. Lucas http://www.MichaelWLucas.com/, http://blather.MichaelWLucas.com/ Latest book: SSH Mastery http://www.michaelwlucas.com/nonfiction/ssh-mastery mwlu

Re: Making time_t deal with the coming epoch

2012-04-01 Thread Michael W. Lucas
); + if (tv.tv_sec = END_13BAKTUN) + return; + } /* Update the UTC timestamps used by the get*() functions. */ /* XXX shouldn't do this here. Should force non-`get' versions. */ -- Michael W. Lucas http://www.MichaelWLucas.com/, http