Re: syspatch, relink and kernel version/date

2018-12-20 Thread Kapetanakis Giannis
On 20/12/2018 18:58, lists+m...@ggp2.com wrote: > I can't confirm, but I think I noticed this on a box that was using the > MP kernel even though it was an SP machine. You are right. It is a single cpu machine running MP kernel. So is this patched or not? G > On Thu, Dec 20, 2018 at 12:14:14PM

Re: I am revolted against the injustice of Ubuntu Forums administrators and moderators .

2018-12-20 Thread Solene Rapenne
Command FreeBSD wrote: > Hi, > > The article that have spoken about Linux malicious commands that was posted > in Ubuntu Forums was restored, but who accessed this link yesterday and > this morning saw that this article has been deleted. hello this is the wrong mailing list, you are on

I am revolted against the injustice of Ubuntu Forums administrators and moderators .

2018-12-20 Thread Command FreeBSD
Hi, The article that have spoken about Linux malicious commands that was posted in Ubuntu Forums was restored, but who accessed this link yesterday and this morning saw that this article has been deleted. Very strange! I also posted this topic in Ask Ubuntu Estack Overflow Exchange:

Re: Confusion re. VMs, bridges, intergace groups and pf.

2018-12-20 Thread Theo de Raadt
cho...@jtan.com wrote: > Additionally, under which circumstances could/should I use interface > groups and under which rdomains? I cannot discern any practical > difference between them except in how they're labeled (numeric vs. > symbolic) although I confess that my experience with network

Re: Confusion re. VMs, bridges, intergace groups and pf.

2018-12-20 Thread chohag
Additionally, under which circumstances could/should I use interface groups and under which rdomains? I cannot discern any practical difference between them except in how they're labeled (numeric vs. symbolic) although I confess that my experience with network routing has been tainted by the Other

Re: TLS suddenly not working over IKED site-to-site - SOLVED?

2018-12-20 Thread Theodore Wynnychenko
> -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf > Of William Ahern > Sent: Monday, December 17, 2018 1:11 PM > To: Theodore Wynnychenko > Cc: misc@openbsd.org > Subject: Re: TLS suddenly not working over IKED site-to-site > . . . >

Confusion re. VMs, bridges, intergace groups and pf.

2018-12-20 Thread chohag
Something in the documentation regarding VM network iterface groups is unclear to me. I have created a switch and VM in /etc/vm.conf: switch "private" { interface bridge0 group private } vm "test" { memory 2G disable disk /srv/vm/test.img interface { switch

Re: Missing libraries after upgrade to 6.4

2018-12-20 Thread John Ankarström
Tom Smyth wrote: Hello John, Hi! do you have PKG_PATH Variable set to an old version ? eg export PKG_PATH=https://fastly.cdn.openbsd.org/pub/OpenBSD/$(6.3/packages/amd64/ export PKG_PATH=https://fastly.cdn.openbsd.org/pub/OpenBSD/$(uname -r)/packages/$(uname -p)/ you can remove the

Re: OpenBGPD Route Reflector - not reflecting VPNv4 Routes

2018-12-20 Thread Henry Bonath
Thank you Claudio! I didn't even think of that, as these Route Reflectors are completely out-of-band and not in the path of routing at all. Of course they wouldn't work without having a route to the nexthop :-) I'm much more versed in troubleshooting BGP on IOS, but with all the work you just

X-Accel-Redirect equivalent for httpd

2018-12-20 Thread Chris Narkiewicz
Hi, Is there an equivalent or alternative for NginX X-Accel-Redirect? https://www.nginx.com/resources/wiki/start/topics/examples/x-accel/ I'm porting a django app that checks for user's permissions before allowing them to download a document and this function uses X-Accel-Redirect to achieve

Re: Missing libraries after upgrade to 6.4

2018-12-20 Thread Tom Smyth
Hello John, do you have PKG_PATH Variable set to an old version ? eg export PKG_PATH=https://fastly.cdn.openbsd.org/pub/OpenBSD/$(6.3/packages/amd64/ export PKG_PATH=https://fastly.cdn.openbsd.org/pub/OpenBSD/$(uname -r)/packages/$(uname -p)/ you can remove the PKG_PATH variable as installurl

Re: blocking openvpn port scanners

2018-12-20 Thread Steve Fairhead
On 20/12/2018 13:20, tors...@cnc-london.net wrote: Try to add below to your pf.conf table persist pass in on $ext_if inet proto tcp from any to $ext_if port 1194 \ (max-src-conn 10, max-src-conn-rate 30/5, \ overload flush global) This is pretty much exactly what I

Re: OpenBGPD Route Reflector - not reflecting VPNv4 Routes

2018-12-20 Thread Claudio Jeker
On Thu, Dec 20, 2018 at 04:52:34PM -0500, Henry Bonath wrote: > Hello, I am having an issue with some route-reflectors I set up to try > to support a new MPLS backbone. > The majority of the MPLS Routers are Cisco IOS, with some of the PE > devices running OpenBSD. > The Route Reflectors are

OpenBGPD Route Reflector - not reflecting VPNv4 Routes

2018-12-20 Thread Henry Bonath
Hello, I am having an issue with some route-reflectors I set up to try to support a new MPLS backbone. The majority of the MPLS Routers are Cisco IOS, with some of the PE devices running OpenBSD. The Route Reflectors are OpenBSD 6.4. The route reflectors are not neighbors of each other. Here is

Missing libraries after upgrade to 6.4

2018-12-20 Thread John Ankarström
Hello all, I have this port [1] that installed fine on 6.3, but after I upgraded to 6.4, following the FAQ, I'm getting weird errors. When running make install, it fails because qtbase-5.9.4 can't be installed, which is weird that it wants to do, because the version in ports is 5.9.6p1.

Re: Automated remote install

2018-12-20 Thread chohag
Philipp Buehler writes: > Am 20.12.2018 19:24 schrieb cho...@jtan.com: > > I'm not sure what you mean by that. The script I posted the other day > > is part of a (working, tested) process to create an openbsd image > > within openbsd and then upload it to aws as an iam. I based it on, I > > think,

Re: Automated remote install

2018-12-20 Thread Philipp Buehler
Am 20.12.2018 19:24 schrieb cho...@jtan.com: I'm not sure what you mean by that. The script I posted the other day is part of a (working, tested) process to create an openbsd image within openbsd and then upload it to aws as an iam. I based it on, I think, an earlier version of the instructions

Re: Automated remote install

2018-12-20 Thread chohag
Philipp Buehler writes: > Am 20.12.2018 18:13 schrieb David Diggles: > > However it's possible to build for AWS. > > https://github.com/ajacoutot/aws-openbsd > > and there's more stuff "in the pipe", since the above > needs a Linux or OSX environment > > Next year ;) it'll be possible to do this

Re: radeondrm failure on amd64 but not on i386?

2018-12-20 Thread Daniel Dickman
> On Dec 19, 2018, at 10:22 AM, Andy Bradford > wrote: > > Thus said Daniel Dickman on Fri, 14 Dec 2018 20:45:11 -0500: > >> Try previous releases of OpenBSD/amd64 to check if radeondrm ever >> worked for you on amd64. > > That was a fruitful suggestion. I tried 6.3 amd64 and it

Re: Automated remote install

2018-12-20 Thread Philipp Buehler
Am 20.12.2018 18:13 schrieb David Diggles: However it's possible to build for AWS. https://github.com/ajacoutot/aws-openbsd and there's more stuff "in the pipe", since the above needs a Linux or OSX environment Next year ;) it'll be possible to do this on OpenBSD (vmm/packer/vagrant). ciao

Re: Automated remote install

2018-12-20 Thread David Diggles
>Note that I'm referring to KVM providers (traditional VPS providers), >not >"public cloud". The big boys - AWS, Azure, Google, etc. are not >interested >in OpenBSD. However it's possible to build for AWS. https://github.com/ajacoutot/aws-openbsd

Re: syspatch, relink and kernel version/date

2018-12-20 Thread lists+misc
I can't confirm, but I think I noticed this on a box that was using the MP kernel even though it was an SP machine. On Thu, Dec 20, 2018 at 12:14:14PM +0200, Kapetanakis Giannis wrote: > Hi, > > I'm a bit confused about syspatch and kernel updates. One of machines after > latest syspatch (009)

Re: Automated remote install

2018-12-20 Thread Frank Beuth
On Wed, Dec 19, 2018 at 07:24:12AM -0800, andrew fabbro wrote: Virtually all of the better KVM hosts offer an OpenBSD ISO, and in my experience, 100% will add it to their library if you request it. That's an excellent idea, especially from the perspective of making OpenBSD adoption easier for

syspatch, relink and kernel version/date

2018-12-20 Thread Kapetanakis Giannis
Hi, I'm a bit confused about syspatch and kernel updates. One of machines after latest syspatch (009) and after reboot it lists old kernel date. This happens only on this machine. I've seen it happen before, not sure if it was on the same one or some other box. machine1: # syspatch -l