Re: Will 5.2 ship with WITH_LIBMAP? (was Re: KSE howto?)

2003-09-26 Thread Jeroen C . van Gelderen
On Friday, Sep 26, 2003, at 13:29 US/Eastern, Terry Lambert wrote: Which begs the question... is 5.2 going to ship with WITH_LIBMAP enabled by default? http://www.google.com/search?q=libmap+default+WITH_LIBMAPie=UTF- 8oe=UTF-8 http://people.freebsd.org/~bmah/relnotes/CURRENT/relnotes-i386.txt

DP2: ar / sysinstall fdisk trouble / GEOM?

2002-12-12 Thread Jeroen C. van Gelderen
Hi, In order to debug a minor problem with the ar-driver, I installed DP2 on an Abit KR7A-RAID with HighPoint ATA-RAID controller. The machine contains two identical 40GB IBM drives as masters on each of the two HighPoint IDE channels. The issue I ran into was that the partition editor in

Re: expat2 in the base system?

2002-10-04 Thread Jeroen C . van Gelderen
but has been developed under the umbrella of the Apache Jakarta project. -J -- Jeroen C. van Gelderen - [EMAIL PROTECTED] - +1 242 357 5115 When I'm working on a problem, I never think about beauty. I think only how to solve the problem. But when I have finished, if the solution is not beautiful

Re: HEADS UP: an IPv4-mapped IPv6 address off by default

2002-07-25 Thread Jeroen C . van Gelderen
Umemoto-san, May I ask what motivated this change? -J On Thursday, Jul 25, 2002, at 11:51 US/Eastern, Hajimu UMEMOTO wrote: Hi, I've just committed to change an IPv4-mapped IPv6 address off by default. The existing applications may be affected this change. The applications which depend

Not committing WARNS settings...

2002-02-05 Thread Jeroen C . van Gelderen
. And that seems fair enough since it does not prevent anyone from applying the actual code fixes. We want to make this import stuff as easy on David as we can, no? It is a job from hell already. Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Freedom is essentially a condition

Re: ssh reports no RSA support in libssl and libcrypto.

2001-05-07 Thread Jeroen C. van Gelderen
properly. Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] A government that robs Peter to pay Paul can always depend upon the support of Paul. -- George Bernard Shaw To Unsubscribe: send mail to [EMAIL PROTECTED] with unsubscribe freebsd-current in the body of the message

Re: yarrow /dev/random

2000-08-27 Thread Jeroen C. van Gelderen
(or lack thereof). Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_ To Unsubscribe: send mail

Re: yarrow /dev/random

2000-08-26 Thread Jeroen C. van Gelderen
and conservativeness of the entropy estimates don't help. It's the yarrow output function which blows it. Yeah; that monotonically-increasing counter bothers me slightly. Why? How would it affect security if one assumes the blockcipher is secure? Cheers, Jeroen -- Jeroen C. van Gelderen

Re: randomdev entropy gathering is really weak

2000-07-29 Thread Jeroen C. van Gelderen
Brian Fundakowski Feldman wrote: On Mon, 24 Jul 2000, Jeroen C. van Gelderen wrote: What I meant with that point is that the user may get, say an extra few hundred bits out of it with no new entropy before the scheduled reseed task kicks in. How does he know which bits

Re: randomdev entropy gathering is really weak

2000-07-24 Thread Jeroen C. van Gelderen
semantics is justifyable or even a good thing. Cheers, Jeroen [1] And, should we decide not to change /dev/random semantics, can we still back /dev/random with a modified Yarrow? -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o

Re: randomdev entropy gathering is really weak

2000-07-23 Thread Jeroen C. van Gelderen
esign it's just not very beneficial to do it. 5. Yarrow was designed as a better replacement for most any PRNG by a couple of bright cryptographers. Can you do better than that? Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o

Re: randomdev entropy gathering is really weak

2000-07-23 Thread Jeroen C. van Gelderen
ndom block until the pools have accumulated enough entropy. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)

Re: randomdev entropy gathering is really weak

2000-07-22 Thread Jeroen C. van Gelderen
l you want out of it but will never get more than 256 bits until it reseeds. You don't care in practice, 256 bits are unguessable. If you do care, you load a different random module :-) Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /

Re: randomdev entropy gathering is really weak

2000-07-22 Thread Jeroen C. van Gelderen
ng systems on FreeBSD) you can edit rc.shutdown to not write out a seed file. You don't have to use it but it's good that it's there. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o

Re: randomdev entropy gathering is really weak

2000-07-22 Thread Jeroen C. van Gelderen
Kris Kennaway wrote: On Sat, 22 Jul 2000, Jeroen C. van Gelderen wrote: You don't care in practice, 256 bits are unguessable. Actually, I do..that's the entire point of using long keys. I agree that you need long RSA keys ... but the real discussion isn't really about key length

Re: randomdev entropy gathering is really weak

2000-07-21 Thread Jeroen C. van Gelderen
. Perfect Trojan horse to write for the FBI, IRS, anyone who doesn't like you. Oops. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o

Re: randomdev entropy gathering is really weak

2000-07-21 Thread Jeroen C. van Gelderen
to be stashed on disk. He can then backtrack and potentially recover the exact same random numbers that you used for your key. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o

Re: randomdev entropy gathering is really weak

2000-07-18 Thread Jeroen C. van Gelderen
Poul-Henning Kamp wrote: In message [EMAIL PROTECTED], "Jeroen C. van Gelderen" writes : Predicting the clock's offset from reality and the two way path to the server of choice is impossible, plus if people enable authentication later on the packets will be choke full of hi

Re: randomdev entropy gathering is really weak

2000-07-18 Thread Jeroen C. van Gelderen
Poul-Henning Kamp wrote: In message [EMAIL PROTECTED], "Jeroen C. van Gelderen" writes: People have tried for 30+ years to predict what a quartz xtal will do next. Nobody expects any chance of success. Add to this the need to predict the difference between one or more N

Re: randomdev entropy gathering is really weak

2000-07-17 Thread Jeroen C. van Gelderen
ntially unseeded, so this is actually a liability because processes cannot be sure they're getting real randomness. /dev/random should block until it has seeded. If it does not it's a bug. /dev/random should *never* spit out non-random bytes. Cheers, Jeroen -- Jeroen C. van

Re: randomdev entropy gathering is really weak

2000-07-17 Thread Jeroen C. van Gelderen
andom bits to people in need. I have thought about adding a entropy server to my array of weird servers in my lab. Something like a Geiger counter and a smokedetector could do wonders. Right, and an attacker laughingly sniffing those bits. I think you forgot a ';-p' Cheers, Jeroen -- Jeroen C. va

Re: randomdev entropy gathering is really weak

2000-07-17 Thread Jeroen C. van Gelderen
first need to figure out the security implications. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o

Re: randomdev entropy gathering is really weak

2000-07-17 Thread Jeroen C. van Gelderen
'predicting the clock's offset [...] is impossible' is pretty pointless. Cheers, Jeroen [1] And then, what's the effect of an attacker sniffing your LAN? What information would he have to make his guess more accurate? -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED

Re: ssh not working after upgrading OS?

2000-07-12 Thread Jeroen C. van Gelderen
list archives ought to contain all of the details one needs to fix this temporary problem. No need to resort to EGD, just tweak some config. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o

Re: ssh not working after upgrading OS?

2000-07-11 Thread Jeroen C. van Gelderen
hould help. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_ To Unsubscribe: send mail to [EMAIL

Re: HEADS UP! New (incomplete) /dev/random device!

2000-06-26 Thread Jeroen C. van Gelderen
not. No, upgrading is not fine at all. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_ To Unsubscribe

Re: mktemp() patch

2000-06-10 Thread Jeroen C. van Gelderen
a big enough problem to worry about (numbers still coming :-) It's not a new situation, any application that can write to /tmp can create files that collide with other program's use of mktemp(). Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o

Re: mktemp() patch

2000-06-10 Thread Jeroen C. van Gelderen
Kris Kennaway wrote: On Sat, 10 Jun 2000, Jeroen C. van Gelderen wrote: Actually, it's not of course a security risk in the new algorithm (this is mktemp() after all), but it's a potential failure mode which can cause applications to fail in ways they otherwise wouldn't (with some

Re: mktemp() patch

2000-06-09 Thread Jeroen C. van Gelderen
be) that you just don't want to try and 'optimize' here. It is much better to be conservative and use a good PRNG until it *proves* to be very problematic. Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o

Re: VMware detection code in boot loader

2000-06-09 Thread Jeroen C. van Gelderen
-- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_ To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubs

Re: mktemp() patch

2000-06-09 Thread Jeroen C. van Gelderen
ch is nice... Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_ To Unsubscribe: send mail to [EMAIL

Re: mktemp() patch

2000-06-09 Thread Jeroen C. van Gelderen
to use 72 characters. 64^6 vs. 2*(72^3) . Cheers, Jeroen -- Jeroen C. van Gelderen o _ _ _ [EMAIL PROTECTED] _o /\_ _ \\o (_)\__/o (_) _ \_ _(_) (_)/_\_| \ _|/' \/ (_)(_) (_)(_) (_)(_)' _\o_

Re: VMware detection code in boot loader

2000-06-09 Thread Jeroen C. van Gelderen
Peter Wemm wrote: Christopher Masto wrote: On Fri, Jun 09, 2000 at 01:14:35PM -0400, Jeroen C. van Gelderen wrote: I'm not sure it is a good idea to name this variable VMWare as that is implementation specific. It may be better to have a var named 'emulation' set to 'none

Re: Major device numbers and mem device redesign

2000-05-21 Thread Jeroen C. van Gelderen
Mark Murray wrote: I want to commit a new /dev/random RSN, so I'll be needing a major device; what is the procedure for getting one? I know how to steal one, but ISTR that this is not how it is done. Just edit sys/conf/majors and claim the next available number. You don't

Re: Small MAKEDEV bug

2000-05-08 Thread Jeroen C. van Gelderen
David O'Brien wrote: On Sun, May 07, 2000 at 03:27:07PM -0400, Jeroen C. van Gelderen wrote: Or just settle for a more intuitive solution: MAKEDEV acd2 creates /dev/acd2 MAKEDEV 2 acd creates /dev/acd[01] which would allow for "MAKEDEV 64 da" and "MAKEDEV 256

Re: Small MAKEDEV bug

2000-05-08 Thread Jeroen C. van Gelderen
Bruce Evans wrote: On Mon, 8 May 2000, David O'Brien wrote: On Sun, May 07, 2000 at 03:27:07PM -0400, Jeroen C. van Gelderen wrote: Or just settle for a more intuitive solution: MAKEDEV acd2 creates /dev/acd2 MAKEDEV 2 acd creates /dev/acd[01] which would allow

Re: Small MAKEDEV bug

2000-05-07 Thread Jeroen C. van Gelderen
[CC culled, -stable removed] David O'Brien wrote: On Sun, May 07, 2000 at 04:59:46PM +0200, Jeroen Ruigrok van der Werven wrote: Can we settle this once and for all in a slightly sane manner? I committed the change so that MAKEDEV acd1 creates acd1 and not just acd0. This is wrong.

Re: SMP changes and breaking kld object module compatibility

2000-04-24 Thread Jeroen C. van Gelderen
Richard Wackerbarth wrote: On Mon, 24 Apr 2000, Matthew Dillon wrote: : However, I consider your SMP changes VERY destablizing; they BREAK : lots of modules :-( Huh? No they don't. They simply require recompiling the modules. If they actually broke the modules I wouldn't

Re: Perl 5.6.0?

2000-04-03 Thread Jeroen C. van Gelderen
Nick Hibma wrote: Are there actually any good reasons why we _should_ upgrade in the first place? Security fixes, added functionality we require, etc. The perl we have is stable and the problems it has are well known, which is good enough in 99% of the cases. PERL is not just used by the

Re: Make world breakage...

2000-01-14 Thread Jeroen C. van Gelderen
, basically a useless algorithm as there are better free replacements available. (Especially by the time the patent expires.) Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubs

Re: multiple cd devices

1999-12-31 Thread Jeroen C. van Gelderen
le because of compatibility issues? I'm willing to give it a go. Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-current" in the body of the message

Re: Problems with the ATA-driver

1999-12-22 Thread Jeroen C. van Gelderen
... Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-current" in the body of the message

Re: Modules and sysctl tree

1999-12-11 Thread Jeroen C. van Gelderen
space has changed? I seem to recall that John Poltstra was working on a notification system (for use with CVSup) that would allow you to subscribe to certain change events... Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubsc

Mount problems after lockup

1999-12-05 Thread Jeroen C. van Gelderen
0 /dev/ccd0c /mnt/ccd0 ufs rw 0 2 /dev/wd2s1e /mnt/wd2ufs rw 0 2 /dev/wd3s1e /mnt/wd3ufs rw,sync 0 2 proc/proc procfs rw 0 0 -- J

Re: Mount problems after lockup

1999-12-05 Thread Jeroen C. van Gelderen
From: "Jeroen C. van Gelderen" [EMAIL PROTECTED] 14:33 Subject: Re: Mount problems after lockup To: Poul-Henning Kamp [EMAIL PROTECTED] Poul-Henning

Re: Should UPDATING tell you to rerun MAKEDEV now?

1999-12-05 Thread Jeroen C. van Gelderen
had to boot a kernel and /dev off a floppy to fix the /dev. Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-current" in the body of the message

Re: FYI: KAME netinet6 basic part is committed

1999-11-22 Thread Jeroen C. van Gelderen
ware tools and applications. (fstat, netstat, systat, etc) Thanks! Cheers, Jeroen -- Jeroen C. van Gelderen - [EMAIL PROTECTED] Interesting read: http://www.vcnet.com/bms/ JLF To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-current" in the body of the message

Re: SPAM

1999-05-10 Thread Jeroen C. van Gelderen
is doing an awful job, please give him credit for stopping the vast majority of spam messages and let this thread die. Cheers, Jeroen -- Jeroen C. van Gelderen - jer...@vangelderen.org - 0xC33EDFDE To Unsubscribe: send mail to majord...@freebsd.org with unsubscribe freebsd-current in the body

Cryptfs available outside US

1999-03-16 Thread Jeroen C. van Gelderen
Hi, I seem to remember someone requesting cryptfs. It's available outside the US on my webserver: http://wit395301.student.utwente.nl/~gelderen/fist/. It will go to replay soon. Cheers, Jeroen -- Jeroen C. van Gelderen - gelde...@mediaport.org - 0xC33EDFDE To Unsubscribe: send mail to majord

Re: Postfix

1999-03-14 Thread Jeroen C. van Gelderen
. Not having to deal with Sendmail would render FreeBSD more usable for non-die-hard users. Cheers, Jeroen -- Jeroen C. van Gelderen - gelde...@mediaport.org - 0xC33EDFDE To Unsubscribe: send mail to majord...@freebsd.org with unsubscribe freebsd-current in the body of the message

Re: KLD naming

1999-01-20 Thread Jeroen C. van Gelderen
. Cheers, Jeroen -- Jeroen C. van Gelderen -- gelde...@mediaport.org -- 0x46D8D3C8 -- [8-D}~= To Unsubscribe: send mail to majord...@freebsd.org with unsubscribe freebsd-current in the body of the message

KLD naming

1999-01-19 Thread Jeroen C. van Gelderen
Hi, Might it be a good idea to choose a consistent naming scheme for the modules? I'd think so because it would help blind loading at the boot prompt. If you choose names it the following format: type_name saver_warp saver_daemon the modules of one type will sort together in a directory

Re: Annoying messages on startup..

1999-01-17 Thread Jeroen C. van Gelderen
me if this is nonsense... Cheers, Jeroen -- Jeroen C. van Gelderen -- gelde...@mediaport.org -- [8-D}~= To Unsubscribe: send mail to majord...@freebsd.org with unsubscribe freebsd-current in the body of the message