OpenBSD on AWS - pciide/wd issue

2019-09-04 Thread Pavel Korovin
fix I disabled pciide/wd, the instance booted and runs fine. The dmesgs from successful and unsuccessful boots are attached. May be this information can be helful for somebody. -- With best regards, Pavel Korovin OpenBSD 6.6-beta (GENERIC) #0: Sun Aug 11 13:09:21 MSK 2019 real mem = 1056964608

Re: relayd for TLS termination

2018-04-28 Thread Pavel Korovin
the port number if it is > > not a default port. > > This was because I want relayd to demux the service/port based on the > "Host" header. I mainly hope to accomplish something like the > following, since httpd(8) doesn't support proxying. > > tls on port 443 w/ "Host: unifi.example.com" => localhost port 8443, no tls > tls on port 443 w/ "Host: kibana.example.com" => localhost port 5601, no tls > tls on port 443 w/ "Host: www.example.com" => localhost port 80, no tls > anything else => error > > >> } > >> > >> relay wwwrelay { > >> listen on em1 port 443 tls > >> protocol wwwproto > >> transparent forward to lo port http > > > > On hig volume servers I would not use transparent forwading but instead > > set the X-Forwarded-For header. Also transparent needs help from pf. > > I was mainly looking to use default log configuration on my services. > > This gives me plenty to work with; will experiment and report back, thanks. > > --david > -- With best regards, Pavel Korovin

Re: Migrating nginx config to OpenBSD's httpd

2018-04-16 Thread Pavel Korovin
; Any idea what I'm doing wrong? I guess something is wrong on monit side.. I set up relayd with varous stuff in the backend, but have seen anything like this. -- With best regards, Pavel Korovin

Re: Migrating nginx config to OpenBSD's httpd

2018-04-16 Thread Pavel Korovin
iguring specific security headers for specific hosts, i.e. I cannot have specific http protocol sections with different responses for specific hosts, like: http protocol "https4-flex" { match request header "Host" value "not-secure.domain" forward to match response

Re: Migrating nginx config to OpenBSD's httpd

2018-04-13 Thread Pavel Korovin
this type of configs? -- With best regards, Pavel Korovin

Re: gif(4) changes vs tunnelbroker

2018-02-27 Thread Pavel Korovin
in/avg/max/std-dev = 40.500/40.573/40.645/0.073 ms -- With best regards, Pavel Korovin

gif(4) changes vs tunnelbroker

2018-02-26 Thread Pavel Korovin
Dear all, After upgrading several hosts to -current I noticed that all my IPv6 tunnels via tunnelbroker stopped working. Recently introduced changes to gif(4) (since late December 2017) are too complex for me to grasp, maybe anybody on the list can advise. -- With best regards, Pavel Korovin

Re: installing Graphite on OpenBSD 6.0

2017-04-16 Thread Pavel Korovin
ks it's absolutely possible. I prefer to use OpenBSD ports system, so I have it in $PORTSDIR/mystuff. If you know how to build from ports, I can share, please let me know off-the-list. -- With best regards, Pavel Korovin

Re: A (possibly dumb) question about unbound

2016-10-12 Thread Pavel Korovin
go. > > Which brings me to my question... > > Could someone educate me on why unbound's configuration file is in > /var/unbound/etc instead of just straight up /etc like most other > things? > > Sorry if this is a dumb question but I was curious. > > Thanks, > Bryan > -- With best regards, Pavel Korovin

Re: iked(8) OpenBSD road warrior setup anybody?

2016-10-04 Thread Pavel Korovin
with pf(4). By saying "ugly" I mean I need to have an additional manually assigned loopback interface and to route VPN traffic via this interface. May be I'm doing it all wrong, maybe somebody can shed light on how to do it properly. On 10/04, Zé Loff wrote: > > On 04/10/2016, at

Re: iked(8) OpenBSD road warrior setup anybody?

2016-10-04 Thread Pavel Korovin
On 10/04, Zé Loff wrote: > > On 04/10/2016, at 11:58, Pavel Korovin <p...@tristero.se> wrote: > > > >> On 10/04, Zé Loff wrote: > >> On "the wanderer" iked.conf: > >> > >> ikev2 home active esp \ > >>from egress to 19

Re: iked(8) OpenBSD road warrior setup anybody?

2016-10-04 Thread Pavel Korovin
ot; pf.conf: > > match out on enc0 from any to 192.168.99.0/22 nat-to 192.168.100.3 static-port Zé, do you have an interface with the address 192.168.100.3 on your wanderer? -- With best regards, Pavel Korovin

Re: iked(8) OpenBSD road warrior setup anybody?

2016-10-04 Thread Pavel Korovin
!ifconfig lo248 inet 192.168.248.231 255.255.255.255 mtu 1400 up route add -net 192.168.240.0/21 192.168.248.231 -mtu 1400 I'll try to get rid of this lo248 interface and see if it works for me, thanks! -- With best regards, Pavel Korovin

Re: iked(8) OpenBSD road warrior setup anybody?

2016-10-04 Thread Pavel Korovin
the details, please send me a message, I'd prefer to discuss this off-the-list. -- With best regards, Pavel Korovin

iked(8) OpenBSD road warrior setup anybody?

2016-10-03 Thread Pavel Korovin
is somewhat unstable. -- With best regards, Pavel Korovin