Re: Installation Media Self Integrity Check

2020-08-12 Thread Theo de Raadt
Dan Peretz wrote: > Hello, the FAQ states this: > "The installXX.iso and installXX.fs images do not contain an > SHA256.sig file, so the installer will complain that it can't check > the signature of the included sets [...] This is because it would make > no sense for the installer to verify

Installation Media Self Integrity Check

2020-08-12 Thread Dan Peretz
Hello, the FAQ states this: "The installXX.iso and installXX.fs images do not contain an SHA256.sig file, so the installer will complain that it can't check the signature of the included sets [...] This is because it would make no sense for the installer to verify them. If someone were to make a

Re: 019_libssl.patch regression

2020-08-12 Thread Predrag Punosevac
Theo Buehler wrote: > On Tue, Aug 11, 2020 at 05:26:22PM -0400, Predrag Punosevac wrote: > > This is a regression report for 019_libssl.patch > > After applying libssl binary patch to 6.7 release s-nail-14.9.19 can no > > longer close STARTTLS IPMI session with Gmail server. I recompiled > >

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Walt
‐‐ Original Message ‐‐‐ On Wednesday, August 12, 2020 7:11 AM, Alan McKay wrote: > Hey folks, > > This is one that is difficult to test in a test environment. > > I've got OpenBSD 6.5 on a relatively new pair of servers each with 8G RAM. > > With some scripting I'm looking at feeding

Browser (Gtk?) issue after sysupgrade to latest snapshot

2020-08-12 Thread Why 42? The lists account.
Hi All, I just used sysupgrade (followed by pkg_add -u) to update my desktop system to: OpenBSD 6.7-current (GENERIC.MP) #22: Tue Aug 11 21:29:51 MDT 2020 All is working quite well but I noticed some issue with the iridium browser. When I tried to export my bookmarks, iridium crashed. As an

Re: 019_libssl.patch regression

2020-08-12 Thread Theo Buehler
On Tue, Aug 11, 2020 at 05:26:22PM -0400, Predrag Punosevac wrote: > This is a regression report for 019_libssl.patch > After applying libssl binary patch to 6.7 release s-nail-14.9.19 can no > longer close STARTTLS IPMI session with Gmail server. I recompiled > s-nail and rebooted the machine.

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Steve Williams
Hi, I have a script that downloads "badhosts" from a site that continuously updates through a distrubed network. I currently limit my blocklist to 450,000 ip addresses. real mem = 4261072896 (4063MB) avail mem = 4119322624 (3928MB) bios0: PC Engines apu2 -pa-r-- blocklist    

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Martin Sukany
Hi, as the tables are stored in RAM anyway during thee processing it’s moreless matter of how fast are your DIMMs / CPU. I’m usually work with several tables with cca 30 K records - no impact on the performance so far. S pozdravem / Kind regards Martin Sukaný UNIX Engineer, Developer,

Re: Adding more syspatch platform.

2020-08-12 Thread Jordan Geoghegan
On 2020-08-12 02:08, Stuart Henderson wrote: The only proxy we have for "what is really used" is dmesg submissions. Since 6.7 release: amd64 62 i3865 arm64 3 macppc 2 octeon 1 Based on this there isn't a great case for adding any more. I didn't realize you guys used dmesg@ as a

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Stuart Henderson
On 2020-08-12, Tomasz Rola wrote: > Is there a way to have listing of offending IPs and perhaps grouping > them into /nn subnets - other than writing oneself the script? aggregate6, in packages. It will be slow on a large list, of course. > Something as easy as awk might suffice, I guess - and

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Jordan Geoghegan
On 2020-08-12 05:11, Alan McKay wrote: Hey folks, This is one that is difficult to test in a test environment. I've got OpenBSD 6.5 on a relatively new pair of servers each with 8G RAM. With some scripting I'm looking at feeding block IPs to the firewalls to block bad-guys in near real

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Tomasz Rola
On Wed, Aug 12, 2020 at 03:00:03PM +0200, Martin Sukany wrote: > Hi, > > as the tables are stored in RAM anyway during thee processing it’s > moreless matter of how fast are your DIMMs / CPU. I’m usually work > with several tables with cca 30 K records - no impact on the > performance so far.

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Alan McKay
Wow over 160 MILLION (yes I screamed that) IPs! How much RAM is in your system? On Wed, Aug 12, 2020 at 10:26 AM infoomatic wrote: > > We have ~30,000 entries in our table blocking networks and > single ip addresses, all in all at the moment exactly 169,471,974 hosts > being blocked. No idea

Re: 019_libssl.patch regression

2020-08-12 Thread Steffen Nurpmeso
Steffen Nurpmeso wrote in <20200812132648.kaxsj%stef...@sdaoden.eu>: |Steffen Nurpmeso wrote in | <20200812130039.lto3i%stef...@sdaoden.eu>: ||Predrag Punosevac wrote in || <20200811212622.ugmda%punoseva...@gmail.com>: |||This is a regression report for 019_libssl.patch | ... |||After

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread infoomatic
We have ~30,000 entries in our table blocking networks and single ip addresses, all in all at the moment exactly 169,471,974 hosts being blocked. No idea what your criteria is for "performance impact", but we have no issues. On 12.08.20 14:11, Alan McKay wrote: > Hey folks, > > This is one that

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-12 Thread Tom Smyth
What is the Switch telling you about the LACP ? can you do a show port-channel show port-channel detailed sho port-channel summary on the switch you are lagging with ? can you also do a sho run int port-channel ? sho run int ethernet x,y where x and y are the interfaces on the switch are

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-12 Thread Winfred Harrelson
On Tue, Aug 11, 2020 at 10:13:41PM +0200, Remi Locherer wrote: > On Tue, Aug 11, 2020 at 02:07:32PM -0400, Winfred Harrelson wrote: > > I know others are using the new aggr(4) interface but I am having a > > problem with trying to use it on some new servers I have recently > > gotten. Hoping I

Re: 019_libssl.patch regression

2020-08-12 Thread Steffen Nurpmeso
Steffen Nurpmeso wrote in <20200812130039.lto3i%stef...@sdaoden.eu>: |Predrag Punosevac wrote in | <20200811212622.ugmda%punoseva...@gmail.com>: ||This is a regression report for 019_libssl.patch ... ||After applying libssl binary patch to 6.7 release s-nail-14.9.19 can no ||longer close

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Otto Moerbeek
On Wed, Aug 12, 2020 at 08:11:14AM -0400, Alan McKay wrote: > Hey folks, > > This is one that is difficult to test in a test environment. > > I've got OpenBSD 6.5 on a relatively new pair of servers each with 8G RAM. > > With some scripting I'm looking at feeding block IPs to the firewalls >

Re: 019_libssl.patch regression

2020-08-12 Thread Steffen Nurpmeso
Hello Predrag, all. Predrag Punosevac wrote in <20200811212622.ugmda%punoseva...@gmail.com>: |This is a regression report for 019_libssl.patch | |predrag@oko$ uname -a |OpenBSD oko.int.bagdala2.net 6.7 GENERIC.MP#5 amd64 |predrag@oko$ syspatch -l |001_wscons |002_rpki |003_ssh

Re: aggr(4) not working with Intel XXV710 SFP28 on a Supermicro X11DPi-N(T)

2020-08-12 Thread Winfred Harrelson
On Tue, Aug 11, 2020 at 07:52:10PM +0100, Tom Smyth wrote: > Hi Winfred, > the intel 710 is a complex card, I would suggest that you try updating the > firmware on the card, available from intel.com or your card vendor, > you may have to boot to a live linux cd to apply the firmware update, > >

Re: How many IPs can I block before taking a performance hit?

2020-08-12 Thread Stuart Harland
This is one of those “How long is a piece of string” examples. You don’t give a lot in the way of specifications so as to come up with a reasonble guess. But the guesses are meaningless anyway, as the packet filtering subsystems are pretty efficient and very rapid. In reality with sufficient

How many IPs can I block before taking a performance hit?

2020-08-12 Thread Alan McKay
Hey folks, This is one that is difficult to test in a test environment. I've got OpenBSD 6.5 on a relatively new pair of servers each with 8G RAM. With some scripting I'm looking at feeding block IPs to the firewalls to block bad-guys in near real time, but in theory if we got attacked by a bot

Re: can't install some packages on -current

2020-08-12 Thread Stefan Hagen
Sonic wrote: > Fresh install of -current and I'm getting these errors when running pkg_add: > > library pcap.8.4 not found > /usr/lib/libpcap.so.9.0 (system): bad major > library c++.4.0 not found > /usr/lib/libc++.so.5.0 (system): bad major > library c++abi.2.1 not found >

Re: Adding more syspatch platform.

2020-08-12 Thread Stuart Henderson
The only proxy we have for "what is really used" is dmesg submissions. Since 6.7 release: amd64 62 i3865 arm64 3 macppc 2 octeon 1 Based on this there isn't a great case for adding any more.