Re: Is CVE-2019-5598 affecting openbsd

2019-06-18 Thread Strahil Nikolov
On June 19, 2019 8:23:59 AM GMT+03:00, Theo de Raadt wrote: >Strahil Nikolov wrote: > >> I was wondering if CVE-2019-5598 is actually affecting openBSD. I'm >> asking as FreeBSD is usually several versions behind and this one >> might not affect PF in recent openBSD versions. >

Re: Is CVE-2019-5598 affecting openbsd

2019-06-18 Thread Theo de Raadt
Strahil Nikolov wrote: > I was wondering if CVE-2019-5598 is actually affecting openBSD. I'm > asking as FreeBSD is usually several versions behind and this one > might not affect PF in recent openBSD versions. https://www.openbsd.org/errata63.html#p031_pficmp 031: SECURITY FIX: March 22,

Is CVE-2019-5598 affecting openbsd

2019-06-18 Thread Strahil Nikolov
Hi All, I was wondering if CVE-2019-5598 is actually affecting openBSD. I'm asking as FreeBSD is usually several versions behind and this one might not affect PF in recent openBSD versions. Best Regards, Strahil Nikolov

Re: LACP inquiry

2019-06-18 Thread Peter J. Philipp
On Tue, Jun 18, 2019 at 12:31:30PM -0700, Lyndon Nerenberg wrote: > > The panic indicated that there was no memory left and > > was in UFS region. Since this is the only change I did in the last few > > month > > s > > I'm guessing there is a memory leak in the LACP routines, somewhere. > >

Re: howto verify keydisk backup

2019-06-18 Thread noah pugsley
On Tue, Jun 18, 2019 at 5:37 PM shadrock uhuru wrote: > > hi everyone > my keydisk is on a compactflash sandisk ultra 2 card, > which was created during disk encryption > > doas disklabel sd1 > # /dev/rsd1c: > type: SCSI > disk: SCSI disk > label: USB CARD READER > duid: ea53e532b5ae2a0f > flags:

howto verify keydisk backup

2019-06-18 Thread shadrock uhuru
hi everyone my keydisk is on a compactflash sandisk ultra 2 card, which was created during disk encryption doas disklabel sd1 # /dev/rsd1c: type: SCSI disk: SCSI disk label: USB CARD READER duid: ea53e532b5ae2a0f flags: bytes/sector: 512 sectors/track: 63 tracks/cylinder: 255 sectors/cylinder:

reinstalling boot blocks

2019-06-18 Thread Riccardo Mottola
Hi, I want to reinstall safely boot blocks as the installer does, how can I do it? best from the CD-ROM let me summarize the situation: - I had 6.4 not booting correctly (partition boot size issue) - I upgraded 6.5, and all works, boots fine - actually it did not work, certain things make the

Re: IPTV handling on OpenBSD soft router

2019-06-18 Thread Максим
Yes, I too thought that the table could be the reason and even tried to completely comment out the rules with this table. That did not help and I later understood why. The rules with the table affect the network stream on egress port which is vether0 by me. But these rules do not apply neither

Re: LACP inquiry

2019-06-18 Thread Lyndon Nerenberg
> The panic indicated that there was no memory left and > was in UFS region. Since this is the only change I did in the last few month > s > I'm guessing there is a memory leak in the LACP routines, somewhere. Seems unlikely. We run LACP trunks on all our firewalls and nginx load balancers.

LACP inquiry

2019-06-18 Thread Peter J. Philipp
Hi, I had for the longest time a trunk0 on my router with failover mode. I redid the config on last friday to have trunk LACP on the Netgear switch instead. Here is my config: {internet}---[octeon router]---[netgear switch]===[Lanner 6 port firewall] I have drawn the === in there to indicate

Re: IPTV handling on OpenBSD soft router

2019-06-18 Thread Stuart Henderson
On 2019-06-18, Максим wrote: > When I disable PF and use tcpdump to monitor network activity on em2 > (where the IPTV box is connected) I see a stream of udp packets (something > like this: > 233.33.210.7:5050) > This stream is interrupted in several seconds when I enable PF again. It probably

Sidenote: Filesystem corruption on OpenBSD routers after power outage?

2019-06-18 Thread Kevin Chadwick
> Even after many tries, I have not yet been able to corrupt the > filesystem so fsck cannot repair it without manual intervention. Another less severe corner fail case I have found is that on a couple of buggy 386 laptops (that will be replaced soon anyway) with temperamental over temp

Is it possible to build bioctl -c C -l ... on a bioctl -c 1 -l ... ?

2019-06-18 Thread Wolly
Hello misc, 3 years ago I tried to build a "bioctl -c C -l ... " over a "bioctl -c 1 -l ..." on a hetzner server and I failed. Is it possible to do so, and when, what are the requirements? Thank you in advance. -Heiko

Re: relayd shows ssh sessions as idle

2019-06-18 Thread Joel Carnat
On Mon, Jun 17, 2019 at 11:56:08PM +0200, Sebastian Benoit wrote: > Joel Carnat(j...@carnat.net) on 2019.06.12 16:10:25 +0200: > > Hi, > > > > I have configured relayd(8) on my vmd(8) host so that I can connect to > > the running VMs using SSH. > > > > Using relayctl(8), I can see that those

Re: IPTV handling on OpenBSD soft router

2019-06-18 Thread Максим
When I disable PF and use tcpdump to monitor network activity on em2 (where the IPTV box is connected) I see a stream of udp packets (something like this: 233.33.210.7:5050) This stream is interrupted in several seconds when I enable PF again. --  Best regards Maksim Rodin 17.06.2019, 10:20,