Re: sendmail mx question

2016-04-06 Thread Markus Rosjat
, and I only did that to have some other tool checking if it can connect to the mx in question, is the fact that a site like mxtoolbox can talk to the mx. -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden

Re: sendmail mx question

2016-04-05 Thread Markus Rosjat
provides some real info, but since he didn't do that, I didn't reply... -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie

Re: sendmail mx question

2016-04-05 Thread Markus Rosjat
Hi peter, yeah my server does retries but always ends up on the mailserver with the lower priority :( Am 05.04.2016 um 12:44 schrieb Peter N. M. Hansteen: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 04/05/16 11:55, Markus Rosjat wrote: I have a mail to deliver to a domain that has

sendmail mx question

2016-04-05 Thread Markus Rosjat
happening at all. I'm greatful for any advice regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mai

Re: Gogs PostgreSQL

2016-03-25 Thread Markus Hennecke
pkill -f "${daemon} ${daemon_flags}" } rc_start() { nohup su -l -c daemon ${user} -c "${daemon} ${daemon_flags}" >/dev/null 2>&1 & } rc_cmd $1 HTH Markus

Re: openbsd 4.7 virtual machine on hyper-v

2016-03-01 Thread Markus Rosjat
thanks for the info brian, well it's an internally used machine with some stuff on it that would cost more time to upgrade then to keep it running as it is. regards MArkus Am 01.03.2016 um 14:27 schrieb Brian Conway: If this is the de interface from hyper-v, there were fixes

openbsd 4.7 virtual machine on hyper-v

2016-03-01 Thread Markus Rosjat
anything (not from or to the machine). PF is disabled for now so Im sure thats not the problem, I wrote some post on the net about problems with openBSD and hyper-v so general question is... is hyper-v able to run a openbsd vm at all? regards -- Markus Rosjatfon: +49 351 8107223mail

verification spamd and traffic

2015-10-08 Thread Markus Rosjat
generate traffic with them. Could someone confirm this ? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese

vpn from subnet to subnet through a 3rd enpoint?

2015-10-06 Thread Markus Rosjat
bnet 2 <> subnet 3; works fine subnet 1 <---| subnet 3 |> subnet 2; isn't working all 3 endpoints running openBSD and ipsec, some advice would be cool :) regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrüc

Soekris 4501 and OpenBSd 5.7

2015-09-16 Thread Markus Rosjat
Hi there, just a simple question, is it possible to install a 5.7 on a soekris 4501? It seems when I try to load the bsd.rd ftom the tftp server the soekris isnt able to handle it. I redirected the console but it get stuck on the entry point msg. Regards Markus -- Markus Rosjatfon

Re: Soekris 4501 and OpenBSd 5.7

2015-09-16 Thread Markus Rosjat
with a 32bit image:) regards Markus Am 16.09.2015 um 18:30 schrieb Christian Weisgerber: On 2015-09-16, Devin Reade <g...@gno.org> wrote: I don't know about the 4501, but the 5501 works fine. Also, lunch was okay. Since we are talking about totally different things. -- Markus Rosjatfo

Re: dhcpd.interfaces question

2015-07-27 Thread Markus Rosjat
So if I want to have a vlan interface providing dhcp I need to put dhcpd_flags=vlanXX in rc.conf.local ? regards MArkus Am 27.07.2015 um 14:09 schrieb Jiri B: On Mon, Jul 27, 2015 at 02:02:45PM +0200, Markus Rosjat wrote: Hi there, I just want to setup a dhcp for a Vlan on a openbsd 5.5

dhcpd.interfaces question

2015-07-27 Thread Markus Rosjat
Hi there, I just want to setup a dhcp for a Vlan on a openbsd 5.5 box and somehow I can't find the dhcpd.interfaces file. Is there a change in the configuration since 5.x ? On a 4.9 installation I still have this file. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros

odd behaviour of spamdb

2015-07-13 Thread Markus Rosjat
| grep WHITE | awk -F | '{print $2}'`; do echo $i /usr/sbin/spamdb -d $i /usr/sbin/spamdb -a -t $i echo $i /etc/mail/blacksheep.txt done /usr/libexec/spamd-setup maybe someone give me some hints for improvement regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de

Re: odd behaviour of spamdb

2015-07-13 Thread Markus Rosjat
Am 13.07.2015 um 10:07 schrieb patrick keshishian: On 7/13/15, Markus Rosjat ros...@ghweb.de wrote: hi there, I have a script the following script to delete spam mx ip from the spamd whitelist and write them in my own blacklist. After that I reload the blacklist with spamd- setup. This seems

Re: Microsoft Now OpenBSD Foundation Gold Contributor

2015-07-09 Thread Markus Rosjat
there stuff becuase they wanted to benefit from this. So why not be a little happy that the openbsd project got a contribution even from MS? but well maybe I get it all wrong ... regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann

[SOLVED] Re: X fails to start with latest sparc64 snapshot

2015-07-07 Thread Markus Lude
Change from kettenis@ in xenocara/lib/libpciaccess/src/openbsd_pci.c r1.26 fixed it for me. Thanks Mark! Regards, Markus On Tue, Jun 30, 2015 at 10:20:46PM +0200, Markus Lude wrote: Hello, after upgrading to snapshot from june 29th on my sun blade 100 (sparc64) X fails to start

spamdb log question

2015-07-01 Thread Markus Rosjat
Hi there, just a simple question, is there a way to seperate the spamdb logs into logs for white-, grey- and blacklist entries? It would make the lookup make much easier when something goes wrong :) regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR

Re: spamdb log question

2015-07-01 Thread Markus Rosjat
Bennett: On Wed, Jul 01, 2015 at 11:01:18AM +0200, Markus Rosjat wrote: Hi there, just a simple question, is there a way to seperate the spamdb logs into logs for white-, grey- and blacklist entries? It would make the lookup make much easier when something goes wrong :) I just use: alias G

X fails to start with latest sparc64 snapshot

2015-06-30 Thread Markus Lude
) UnloadModule: mach64 [39.487] (EE) Screen(s) found, but none have a usable configuration. snapshot from june 26th/27th worked. dmesg, Xorg.0.log and xorg.conf attached below sysctl.conf: machdep.allowaperture=1 Regards, Markus console is keyboard/display Copyright (c) 1982, 1986, 1989, 1991, 1993

Re: Question about PHP safe mode

2015-06-24 Thread Markus Rosjat
Hey Guys, thanks for the response Am 23.06.2015 um 11:56 schrieb Heiko Zimmermann: Markus, are you kidding? http://www.cvedetails.com/vulnerability-list/vendor_id-74/product_id-128/version_id-50739/PHP-PHP-5.2.5.html Im aware that php isn't a thing you want to use in a 5.2.4 but we don't

Question about PHP safe mode

2015-06-23 Thread Markus Rosjat
? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

Re: Dovecot with OpenLDAP

2015-05-03 Thread Markus Rosjat
Am 03.05.2015 um 10:32 schrieb Stuart Henderson: On 2015-05-02, Markus Rosjat ros...@ghweb.de wrote: okay it seems dovecot runs root and not as the _dovecot user so applying a login class for the dovecote group only helps if you add root to it and nor it seems to start properly. How are you

Re: Dovecot with OpenLDAP

2015-05-03 Thread Markus Rosjat
11:42 schrieb Markus Rosjat: Am 03.05.2015 um 10:32 schrieb Stuart Henderson: On 2015-05-02, Markus Rosjat ros...@ghweb.de wrote: okay it seems dovecot runs root and not as the _dovecot user so applying a login class for the dovecote group only helps if you add root to it and nor it seems

openldap verver problem

2015-05-02 Thread Markus Rosjat
is it better to just get the source and make it from scratch (regarding the monitoring stuff too )? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220

Re: Dovecot with OpenLDAP

2015-05-02 Thread Markus Rosjat
just a little update, dont know if it's the right approach Am 02.05.2015 um 19:37 schrieb Markus Rosjat: Hi there, once again some stupid questions :) 1. is there a sane example out there to configure dovecot with openldap on openbsd? - I try to get things running for hours now all I get

Dovecot with OpenLDAP

2015-05-02 Thread Markus Rosjat
codesnippet which I cant even find in the config files. 2. is it worth the effort trying to get sendmail (the ldap flavour) installed or should I just skip it for a different program? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla

Re: [solved] a few question about sftp

2015-05-01 Thread Markus Rosjat
okay short improvement maybe the wrong way but so you can revoke the exexute permission on others I changed ownership of /var/sftp to root:sftpuser and permission to 0710 Am 01.05.2015 um 15:46 schrieb Markus Rosjat: Am 01.05.2015 um 15:36 schrieb Markus Rosjat: well I got it running

disk quota clearification

2015-05-01 Thread Markus Rosjat
write till the 100mb are reached ? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich

[solved] disk quota clearification

2015-05-01 Thread Markus Rosjat
Okay got the answer, group quota does work like a shared limit so all user of the group are bound to the group quota. regards markus Am 01.05.2015 um 18:56 schrieb Markus Rosjat: Hi there, when I set a quota for a group does this mean the limit is added for the wohle group or is it added

a few question about sftp

2015-05-01 Thread Markus Rosjat
use key auth for this? and if the first 2 questions get a yes ... whats wrong with my setup :-P since this is just a test thing I can post the sshd_config if needed regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str

Re: a few question about sftp

2015-05-01 Thread Markus Rosjat
)/var/sftp is there something I can do to prevent this last no go ? Am 01.05.2015 um 15:15 schrieb Nick Holland: On 05/01/15 07:07, Markus Rosjat wrote: hi there, I just do some testing with sftp access and I stumbled about some things I dont get. if I use the chroot I would asume the user cant

[solved] a few question about sftp

2015-05-01 Thread Markus Rosjat
Am 01.05.2015 um 15:36 schrieb Markus Rosjat: well I got it running to a point were my user got loged in to his home dir. he is now chrooted to /var/sftp because this one is owned by root and not writeable for others. still can jump from home dir (well it's not really this home) /var/sftp

a few questions to httpd

2015-04-01 Thread Markus Rosjat
it support chroot - can you define virtual host and does it support SNI I could guess of more but I think thats the most important stuff for me right now :) So if some of the insiders could shed some light on the subject would be cool Regards -- Markus Rosjatfon: +49 351 8107223

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Okay I found some pdf (damn if you can't google it the right way ...) so I think I just solved this myself but if someone with experience in setting it up likes to give hints I'll gladly take tehm :) Regards Markus Am 01.04.2015 um 16:32 schrieb Markus Rosjat: Hi there, since 5.7

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Am 01.04.2015 um 17:34 schrieb Peter J. Philipp: On Wed, Apr 01, 2015 at 05:21:47PM +0200, Markus Rosjat wrote: I'm a german , extremly lazy and a dummy by default (ask arround you'll see ) but like my previous mail said I just found a pdf that provides most of the answers I have ;) I'm

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Am 01.04.2015 um 16:51 schrieb Alexander Hall: On April 1, 2015 4:32:43 PM GMT+02:00, Markus Rosjat ros...@ghweb.de wrote: Hi there, since 5.7 will not have a apache or a nginx as out of the box webserver it would be nice to know something about the new httpd. I try to google arround but I

OpenBSD as a Mailserver

2015-03-25 Thread Markus Rosjat
Hi there, what's the usual setup these days for mailserver ? I have a old machine and like to jump into the future :) old setup: OpenBSD 4.2 Courier Sendmail LDAP I would like to keep LDAP because I may want to migrate my mailboxes. thanks for the advice Regards -- Markus Rosjatfon

Re: OpenBSD as a Mailserver

2015-03-25 Thread Markus Rosjat
Hey Marcus, thans for the informations, I just edit in my answers below . Regards Markus Am 25.03.2015 um 16:20 schrieb Marcus MERIGHI: ros...@ghweb.de (Markus Rosjat), 2015.03.25 (Wed) 13:58 (CET): what's the usual setup these days for mailserver ? below is only my impression of what

Re: Xen PV DomU with OpenBSD?

2015-02-26 Thread Markus Kolb
the reasons why not to trust EC2, but I'd really like to be able to use OpenBSD on EC2. If you're interested in doing the work, contact me. --Joel On Sat, Feb 21, 2015 at 8:31 PM, Markus Kolb open...@tower-net.de wrote: Hi, there isn't any support for Xen PV DomU in OpenBSD, isn't it? What

Re: spamd whitelist

2015-02-22 Thread Markus Kolb
Am 2015-02-21 23:51, schrieb F Bax: In this archived message; Peter explains here how to get ip address for various gmail servers - which can then be added to whitelist... http://marc.info/?l=openbsd-miscm=136449396910976w=2 When I try this process for yahoo.com; I get Why you'd like to

Re: Xen PV DomU with OpenBSD?

2015-02-22 Thread Markus Kolb
Am 2015-02-21 22:52, schrieb Raimundo Santos: On 21 February 2015 at 10:31, Markus Kolb open...@tower-net.de wrote: there isn't any support for Xen PV DomU in OpenBSD, isn't it? No, there is not such support. But you can run it in HVM mode without effort. Well, may be some effort

Xen PV DomU with OpenBSD?

2015-02-21 Thread Markus Kolb
Hi, there isn't any support for Xen PV DomU in OpenBSD, isn't it? What happened with Christoph Egger's work he is talking about in https://archive.org/details/bsdtalk069 ? Thanks. Markus

[Solved] Re: VS: Soekris 6501-70 mSATA and OpenBSD

2015-02-20 Thread Markus Rosjat
Hi there, it seems the tip with the delay did the trick :) thx Markus Am 20.02.2015 um 08:34 schrieb Markus Rosjat: hi tuomas, I tried both default to com0 and not but same result but I will checkout the other settings maybe that does the trick :) thx for the quick reply regards Markus

Re: CPU criteria for OpenBSD firewall

2015-02-19 Thread Markus Kolb
Am 2015-02-19 10:51, schrieb Peter Hessler: :choose the CPU with higher Frequency and less cores or for a CPU with :lower frequency but more cores? Higher frequency. Period. Right now, network and PF processing is limited to CPU0. You want that as fast as possible. Additionally, you want

Soekris 6501-70 mSATA and OpenBSD

2015-02-19 Thread Markus Rosjat
was one of the devices that seem to have no trouble with booting up. So simple question is there something I miss here that needs to be done befor I reboot after a fresh install to get the Soekris up and running? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H

Re: Installing OpenBSD 5.6 using a USB Flash drive

2015-02-18 Thread Markus Kolb
Am 2015-02-17 17:27, schrieb A Y: dmesg|grep ^.d0 returns only sd0 sysctl hw.disknames returns sd0 and rd0 my machine is a 10.1 inch netbook Lenovo E10-30 running Intel Celeron N2830 Dual Core 64 bit. Do you think I should have used amd64 installation instead of i386? Will depend mostly on

Re: Installing OpenBSD 5.6 using a USB Flash drive

2015-02-16 Thread Markus Kolb
Am 2015-02-16 15:36, schrieb A Y: Did anyone install OpenBSD 5.6 from a USB Flash drive? Please help... You have already booted from drive, now you only need to select this drive device during installation. You need help exactly with what?

Legacy Laptop stops working with OpenBSD GENERIC = 5.5

2015-02-11 Thread Markus Kolb
works with OpenBSD 5.4. Maybe some additional information. In version 5.3 (no dmesg available) there was a rev 0x20 or 0x02 what I can remember. Versions greater-equal 5.4 reports always rev 0x00. But it works with 5.4. So it might not be related to the disabled thing. thx and br, Markus OpenBSD

Re: Legacy Laptop stops working with OpenBSD GENERIC = 5.5

2015-02-11 Thread Markus Kolb
Am 2015-02-11 12:25, schrieb Markus Kolb: Hello, what is your policy for legacy hardware? I'd like to reactivate an old laptop for special purpose with OpenBSD. But I've problems to run supported releases on it. The latest working version is OpenBSD 5.4. Since 5.5 you can read in dmesg

in need of openbsd as mailserver with ldap and courier

2014-10-02 Thread Markus Rosjat
for a company or a indepent. We would of course pay for the job. So if someone or a company in the area is intersted feel free to contact me. My Contact Information is in the footer of the mail. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla

Re: ksh, csh same vulnerability as bash

2014-09-29 Thread Markus Hennecke
Am 29.09.2014 12:53, schrieb Bogdan Andu: the bug in bash shell discovered last day also seems to be present in ksh and csh. ksh is known to be the default shell in OpenBSD. the following piece of shell code executes succesffuly on both ksh and csh (besides bash of course): ksh: $ env VAR='()

ntpd not setting time under kvm-qemu

2014-09-21 Thread Markus Wernig
under qemu I had to disable mpbios in the kernel. Could this have caused that effect? Or is anyone aware of this being a problem under kvm-qemu and i386 (no such problems with 5.5 or -current amd64)? Thanks /markus

tools for monitoring network traffic

2014-09-19 Thread Markus Rosjat
and other tools but since Im a lazy guy I want to look for a solution that is already out there. Thx for the help :) Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49

remove swap partion after physical machine converted into vm

2014-08-27 Thread Markus Rosjat
(not present) HDD. I just get into singleuser mode can exit it and then the machine just boots up as expected. For convinience it would be nice to skip the part with the singleuser mode. So is there a way to remove the swap partion or remove the softraid without data loss? Regards Markus -- Markus

Re: remove swap partion after physical machine converted into vm

2014-08-27 Thread Markus Rosjat
Hi Josh, thx for the fast reply I will check the fstab out it may solve the problem regards Markus Am 27.08.2014 13:58, schrieb Josh Grosse: On 2014-08-27 05:15, Markus Rosjat wrote: Hello, I simply dd'ed the HDD of our Server and converted the image to a virtual disk, I created a VM ans

Re: how to debug iked failures?

2014-08-27 Thread Markus Wernig
Hi all To finish off this ancient thread, I've written up what it took to get StrongSwan to play nicely with iked and to build a GRE tunnel over the IPSec link: http://markus.wernig.net/en/it/ip6tunnel.phtml Any feedback is of course very welcome. krgds /markus On 08/13/2014 06:05 AM, Markus

Re: rsync -a doesnt keep owner and permissions

2014-08-21 Thread Markus Rosjat
Sent from my iPad On 19 Aug 2014, at 16:53, Markus Rosjat ros...@ghweb.de wrote: Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap, --groupmap and --chown

Re: rsync -a doesnt keep owner and permissions

2014-08-21 Thread Markus Rosjat
have to give someone the right to act as root I'll do it. But with my understanding and what I have read so far it all melts down to the point when someone is telling you you can get this when you do it as root. 2014-08-21 8:47 GMT+02:00 Markus Rosjat ros...@ghweb.de: Just a short heads up

Re: rsync -a doesnt keep owner and permissions

2014-08-20 Thread Markus Rosjat
already have. But thanks for the sugession On 19 Aug 2014, at 16:53, Markus Rosjat ros...@ghweb.de wrote: Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap

rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
I can do but dont want to: - I can enable root ssh access - I rsync as root and the owner and permission gets copied even the user doesnt exist on the remote machine Is there any other thing I miss with the sudo approach? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros

Re: rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap, --groupmap and --chown in the man page. Haven't tried them myself but AFAIK these options were added

Re: rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
, too). Set that to sudo rsync, would be my guess. -Adam well I will give it a shot and this may be the missing piece here On August 19, 2014 9:27:11 AM CDT, Markus Rosjat ros...@ghweb.de wrote: Hello, this has been asked befor though but since searching the net always tells me it should work

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
processing failed Any more ideas? Thx /markus

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
12 12:23:20 tunnel iked[25389]: ikev2_pld_notify: protoid NONE spisize 0 type EAP_ONLY_AUTHENTICATION thx /markus

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
On 08/12/2014 12:33 PM, Markus Wernig wrote: sadb_getspi: satype esp vers 2 len 10 seq 19 pid 25389 address_src: A.B.C.D address_dst: 10.x.y.z spirange: min 0x0100 max 0x sadb_getspi: satype esp vers 2 len 10 seq 19 pid 25389 sa: spi 0xfe52d794

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
On 08/12/2014 05:39 PM, Markus Wernig wrote: But really, I think this is the problem: Aug 12 16:56:18 tunnel iked[22215]: ikev2_childsa_enable: loaded CHILD SA spi 0xcb320247 Aug 12 16:56:18 tunnel iked[22215]: pfkey_flow: unsupported address family 0 Aug 12 16:56:18 tunnel iked[22215

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
/32, received: 0.0.0.0/0 = match: A.B.C.D/32 Aug 12 20:40:52 slimtoo charon: 10[IKE] no acceptable traffic selectors found Aug 12 20:40:52 slimtoo charon: 10[IKE] failed to establish CHILD_SA, keeping IKE_SA Feels quite close now ... thx /markus

Re: how to debug iked failures?

2014-08-12 Thread Markus Wernig
the peer, always sends the to address from iked.conf as TSi and the from address as TSr in the IKE_AUTH response. In my understanding, this should be the other way round. Thanks for bearing with me :-) krgds /markus

how to debug iked failures?

2014-08-10 Thread Markus Wernig
/markus

Re: fdisk fuction in bsd.rd

2014-07-26 Thread Markus Müller
in this situation, default offset = 0 , may this fuction change to auto caculate the default to 10490445 ? just like offset: [10490445] Yes, it can. Bitrig already does it, so find the patch below. I had it in my tree for some time and already tested it on amd64. Best regards, Markus Index: cmd.c

LibreSSL libcrypto.a/libssl.a/openssl.bin filesize

2014-07-14 Thread Markus Manzke
root root 1975k Jul 12 22:22 /usr/bin/openssl.libressl -rwxr-xr-x 1 root root 510k Jun 15 13:36 /usr/bin/openssl.openssl ~~~ why is lib*.a and the openssl-binary itself 3-4 x bigger than it's openssl-counterpart? just wondering. regards, markus

Re: LibreSSL libcrypto.a/libssl.a/openssl.bin filesize

2014-07-14 Thread Markus Manzke
ngx 3262k Jul 15 00:04 libcrypto.a -rw-r- 1 ngx ngx 565k Jul 15 00:05 libssl.a -rwxr-x--- 1 ngx ngx 498k Jul 15 00:05 openssl thanx, markus

Re: Very slow I/O under OpenBSD i386 on qemu-kvm from RHEL7rc

2014-06-19 Thread Markus Wernig
On 06/17/2014 11:10 AM, Brad Smith wrote: boot -c disable mpbios Because ACPI is in use which takes higher precedence over MP BIOS. You have to disable acpimadt. THANKS GUYS!! This just resolved a blocker that had for 2 years prevented me from upgrading my OpenBSD kvm guests to

Re: new OpenSSL flaws

2014-06-06 Thread Markus Rosjat
in removing 90k of c code lines from something that is messed up means to make it more solid but that's just my point of view and I'm just a dummy -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http

Apache2 config on OpenBSD 5.5

2014-06-02 Thread Markus Rosjat
by the default still ? Oh and if someone has some helpful links on all this that would be extremly helpful. Regards Markus -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351

Re: Oddity with httpd/mod_ssl: missing HTTPS environment variable on non _default_ vhosts

2014-02-20 Thread Markus Wernig
Not sure about the ported httpd, but usually you have to enable the generation of those environment vars with SSLOptions +StdEnvVars as they are off by default. krgds /m On Tue, 18 Feb 2014, Olivier Mehani wrote: (Almost) everything works fine, and I do indeed manage to successfully

ntpd switching between synced and unsynced since snap from 22nd jan

2014-01-28 Thread Markus Lude
Hello, since updating to the latest snapshot on sparc64 from 22nd january ntpd switches back and forth between synced and unsynced clock every few minutes. Does anyone notice similar behavior? my ntpd.conf: servers de.pool.ntp.org Regards, Markus

sysmerge complains about not valid etcXX.tgz set

2014-01-25 Thread Markus Lude
, Markus

Re: sysmerge complains about not valid etcXX.tgz set

2014-01-25 Thread Markus Lude
On Sat, Jan 25, 2014 at 06:18:58PM +0100, Markus Lude wrote: Hello, today I updated to the latest snapshot on sparc64 (from 22nd january). When I run sysmerge after that I got $ sudo sysmerge -s etc55.tgz -x xetc55.tgz *** ERROR: /var/tmp/sysmerge.Hwq1ImlHSs/etc55.tgz

pkg_add fails on clean snapshot install

2014-01-25 Thread Markus Bergkvist
Is it related to what is mentioned here and I should wait for updated snapshots? http://marc.info/?l=openbsd-techm=139064668614680w=2 $ sudo pkg_add minicom Fatal error: Ustar [ftp://ftp.eu.openbsd.org/pub/OpenBSD/snapshots/packages/amd64/quirks-1.109.tgz][+CONTENTS]: Error while reading header

Re: PHP 5.3.1 on OpenBSD 4.2

2013-10-03 Thread Markus Rosjat
to no downtime if required. I have a image for a esxi so I will do the test on that and if I'm successful I just do it step by step on the server. This is maybe the easiest way to go here. -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann, Kögler

PHP 5.3.1 on OpenBSD 4.2

2013-10-02 Thread Markus Rosjat
Hey there, I have a server that runs a OpenBSD 4.2 with a php of 5.2.3 and now I just need some information if it's possible to switch to php 5.3.1 without bigger problems or is it just not recommended? Some kind of help is most appreciated. Regards Markus

Re: PHP 5.3.1 on OpenBSD 4.2

2013-10-02 Thread Markus Rosjat
On 02.10.2013 14:14, Otto Moerbeek wrote: On Wed, Oct 02, 2013 at 01:52:29PM +0200, Markus Rosjat wrote: Hey there, I have a server that runs a OpenBSD 4.2 with a php of 5.2.3 and now I just need some information if it's possible to switch to php 5.3.1 without bigger problems or is it just

ipsec with smartcard?

2013-08-18 Thread Markus Wernig
to pksc11 or smart cards - is there a way to do this at all? If so, what would be the right place to look for the documentation? Thx /markus

updated shared X libs missing in sparc64 snapshots from 2013-05-26

2013-05-26 Thread Markus Lude
Hi, be careful with the latest x sets on sparc64 from 2013-05-26. The shared X libs which were updated recently are missing. Regards, Markus

Re: Snort not logging to alerts files

2012-09-09 Thread Markus Lude
to fire really enabled? Has anyone successfully installed snort on openbsd and logged data? Of course. Running recent snort on -current. Recently I send an update of the snort port to ports@. Maybe you could help test it, so we have a more up-to-date snort version in 5.3. Regards, Markus

Re: /etc/netstart diff

2012-02-20 Thread Markus
to add netstart_flags support to rc.conf/rc as well. The latter might be a proper solution as well, but is not as minimally invasive as intended. All the best, /Markus

/etc/netstart diff

2012-02-16 Thread Markus
curious to hear some opinions on it. All the best, /Markus --- /etc/netstart Tue Dec 20 18:54:07 2011 +++ netstartThu Feb 16 11:15:14 2012 @@ -18,7 +18,7 @@ _n=$1 while [ ${#_n} != 0 ]; do case $_n in - [A-Za-z0-9

Re: vpn isakmpd ipsec, one side with only one interface

2012-02-16 Thread Markus Wernig
Hi I'm not sure if this will work, but you could try creating a loopback interface (lo2) on FWC with the IP address that the FTP server should be reachable on and then set up a regular VPN between FWA and FWC just for that one IP address: ike esp from 172.17.2.21/32 to 192.168.0.0/24 peer ip_fwA

Re: /etc/netstart diff

2012-02-16 Thread Markus
the original at http://flash.target23.de/doc/netstart.diff Regards, /Markus

Re: /etc/netstart diff

2012-02-16 Thread Markus
, /Markus

Supported hardware: miniPCIe WiFi adapter

2012-02-02 Thread Markus Schatzl
lengthy, please see below. All the best, /Markus media autoselect media autoselect mediaopt hostap media autoselect mediaopt monitor media autoselect mode 11a media autoselect mode 11a mediaopt hostap

Re: Supported hardware: miniPCIe WiFi adapter

2012-02-02 Thread Markus Schatzl
. Regards, /Markus

Re: CARP strangeness after 5.0 upgrade

2012-01-26 Thread Markus Wernig
On 01/25/12 18:23, Matt Hamilton wrote: pass in quick on $ext_if proto carp from $fw_ext_ips to 224.0.0.18 queue carp_out pass in quick on $int_if proto carp from $fw_int_ips to 224.0.0.18 queue carp_in pass out quick on $ext_if proto carp from $fw_ext_ips to 224.0.0.18 queue carp_out

Re: ASUS USB adapters

2012-01-19 Thread Markus Schatzl
for it. All the best, /Markus

Re: Strange connection problems with athn interface

2012-01-17 Thread Markus Schatzl
problems: OpenBSD 5.1-beta (GENERIC) #135: Sun Jan 15 13:04:45 MST 2012 So as it looks now, the Ubiquity SR71-E module works. I will keep an eye on it since all this still appears quite strange to me. I don't really have any indication why it does work right now. All the best, /Markus

Solved: /bsd: carpN: ip_output failed: 65

2012-01-16 Thread Markus Wernig
to normal. Thanks to cd for the help. lg /markus On 01/15/12 16:18, Markus Wernig wrote: Hi all After upgrading to 5.0 (and also on -current) I keep getting those errors for 2 out of 4 carp'd interfaces in a fw cluster pair: /bsd: carp2: ip_output failed: 65 /bsd: carp3: ip_output failed: 65

/bsd: carpN: ip_output failed: 65

2012-01-15 Thread Markus Wernig
something to my ruleset? Any way to totally disable ipv6 for a test? krgds /markus

Strange connection problems with athn interface

2012-01-15 Thread Markus
connect the rubberduck antennas after the interface has been set up. This is however not the case, at least I see no difference in behaviour. As of now, I'm really stuck. Has anybody experienced something similar and is able to give a hint or another? Thanks in advance, /Markus OpenBSD 5.1-beta

<    1   2   3   4   5   6   7   >