Re: BGPD and source interface

2021-10-01 Thread Stuart Henderson
If you want more fine-grained control (for example if you don't have full out-of-band console access across your network and might need to hop between local network addresses to reach other routers during an IGP failure), you can alternatively use PF to nat to the preferred address just in the

Re: BGPD and source interface

2021-10-01 Thread Laura Smith
Super, thanks ! Laura ‐‐‐ Original Message ‐‐‐ On Friday, October 1st, 2021 at 13:39, Theo de Raadt wrote: > route [-T rtable] sourceaddr [-inet|-inet6] [address] > route [-T rtable] sourceaddr [-inet|-inet6] -ifp interface > Set the preferred source

airport file

2021-10-01 Thread Carson Chittom
Not sure why I'd never noticed it before, but I discovered /usr/share/misc/airport today, so of course I looked for my local ones. This edits JAN to correct a typo and reflect the airport's current name, and also adds HKS. For the record, I have been to both (and their existence is

Re: Server certs expired higher up the chain, imaps and https

2021-10-01 Thread Andrew Daugherity
On Thu, Sep 30, 2021 at 4:00 PM Sebastian Benoit wrote: > This is an issue with an expired root/intermediate certificate (DST Root X3) > in use by Let's Encrypt. > > [...] > An errata has just been published, you can install it using syspatch. Thanks for the quick patch! I can verify this fixes

BGPD and source interface

2021-10-01 Thread Laura Smith
Could somebody kindly remind me how to force OpenBSD to use the lo0 alias for outbound traffic ? I've got an OpenBSD instance which is getting its default route via bgpd. ping 8.8.8.8 does not work but ping -I $lo0_alias works How can I tell OpenBSD to use the lo0 as default outbound interface

Re: BGPD and source interface

2021-10-01 Thread Theo de Raadt
route [-T rtable] sourceaddr [-inet|-inet6] [address] route [-T rtable] sourceaddr [-inet|-inet6] -ifp interface Set the preferred source address. If address is the word "default", 0.0.0.0 or ::, source address will be chosen by the

Re: Sierra Wireless MC7455 umsm to umb

2021-10-01 Thread Theo de Raadt
This class of devices can be in multiple configurations. the OpenBSD driver doesn't have a way of changing the mode of the device, either permanently or temporarily, and we also lack a way of updating the firmware, which can also be desirable. I've heard there is some Windows tooling that can do

Sierra Wireless MC7455 umsm to umb

2021-10-01 Thread Edward Crawler
Hi People, I have a Sierra Wireless MC7455 LTE module. When I plugged in the module, OpenBSD attachs it as "umsm" Is there any AT command to attach this module as "umb" instead of "umsm" ? dmesg output: umsm0 at uhub0 port 2 configuration 1 interface 0 "Sierra Wireless, Incorporated Sierra

Re: Server certs expired higher up the chain, imaps and https

2021-10-01 Thread Joel Sing
On 21-09-30 19:45:38, James Cook wrote: > On Thu, Sep 30, 2021 at 10:02:17AM -0700, Chris Bennett wrote: > > Hi, > > > > I'm getting that the certs are expired, but https works fine in Firefox, > > including when looking at the full chain. > > > > > > openssl s_client -servername