HTTP SITE DOES NOT REDIRECT

2019-03-05 Thread Kihaguru Gathura
Hi,


https://www.htbridge.com SSL test reports as follows:


HTTP SITE DOES NOT REDIRECT
The HTTP version of the website does not redirect to the HTTPS
version. We advise to enable redirection.
Misconfiguration or weakness


Web server configuration as follows:


# $OpenBSD: httpd.conf,v 1.20 2018/06/13 15:08:24 reyk Exp $

server "xyz.com" {
listen on * port 80
location "/.well-known/acme-challenge/*" {
root "/acme"
request strip 2
}
location * {
block return 302 "https://xyz.com$REQUEST_URI;
}
}

server "xyz.com" {
listen on * tls port 443
hsts
tls {
certificate "/etc/ssl/xyz.com.fullchain.pem"
key "/etc/ssl/private/xyz.com.key"
}
location "/.well-known/acme-challenge/*" {
root "/acme"
request strip 2
}
location "/xyz.com/*" {
root "/"
fastcgi
}
}


is this error justifiable considering the above configuration?

Thanks,

Kihaguru.



Re: DMCA takedown notice

2019-03-05 Thread Martin Schroeder
The fact that you even spend this much time on trying to take back
your gift to the community instead of just accepting your
responsibility for your own actions is impressive. And unless you sign
with your legal name and your copyright notices uses your legal name
as well as details of your location then your claims have no effect at
all because it is literally impossible to even speculate that you are
the copyright holder - let alone proving it beyond any reasonable
doubt that it is the case. So if you are serious about this and not
just simulating a possible angle of attack on the GPL that somebody
else could take to illustrate a possible weakness in the GPL, then
stop hiding behind anonymity and file an actual real claim with a
court.

Should your effort succeed then it is a problem with the law and not
with the license. A license that grants certain rights to a copy of a
work provided that certain conditions outlined in the license are met
should never be revocable from THAT particular copy of the work,
unless the terms of the license itself are broken. Having the
possibility to arbitrarily revoke rights granted by a license for any
other reason than conditions that the licensee was aware of when they
accepted the license would have tremendous negative consequences and
disruptions to many areas of the society. If the law has a loophole
like that then the best thing that we all can do is ensure that it
doesn't have it anymore in the near future.

On Tue, Feb 12, 2019 at 12:10 AM  wrote:
>
> You take it down or I sue you, simple as that.
>
> I have revoked the license from a number of people, including the John
> Doe who has chosen to violate my copyright thence-forth.
>
> I have signed using my 2 decades long held pen-name.
>
> The U.S. Code defines an electronic signature for the purpose of US law
> as "an electronic sound, symbol, or process, attached to or logically
> associated with a contract or other record and executed or adopted by a
> person with the intent to sign the record."
>
> My signing with my pen-name suffices for this purpose. What is important
> is my intent to sign the record, which I have evinced.
>
> I have also posted the information on my long-held project page, so that
> you may know that I am me:
> https://sourceforge.net/projects/gpcslots2/files/notes/
>
> https://sourceforge.net/projects/gpcslots2/files/notes/tkdnreq_github.txt/download
> https://sourceforge.net/projects/gpcslots2/files/notes/takedownreq_vs_johndoe-of-8ch.txt/download
>
> (I have also uploaded this response to said /notes/ directory)
>
> In addition to many other places.
> Your contention that I must do anything greater at this point is legally
> inefficacious.
>
> I _DEMAND_ that you take the offending material down immediately.
>
> --MikeeUSA--
> (Author of GPC-Slots 2)
> (electronic signature)
>
> On 2019-02-06 21:20, GitHub Staff wrote:
> > Hi MikeeUSA,
> >
> > Thank you for your notices, the most recent of which is included below
> > for reference.
> >
> > This DMCA notice is incomplete. It lacks "A physical or electronic
> > signature of a person authorized to act on behalf of the owner of an
> > exclusive right that is allegedly infringed" and "Information
> > reasonably sufficient to permit the service provider to contact the
> > complaining party."
> >
> > Unfortunately, an electronic signature must be a legal name, not a
> > monicker or username, and we cannot accept disposable or temporary
> > email addresses as reliable contact information for a DMCA notice.
> >
> > Once you've revised your notice to include the required details,
> > please send back the entire revised notice, and not only the corrected
> > sections. Once we've received a complete and actionable notice, we'll
> > process it expeditiously.
> >
> > Thanks,
> >
> > GitHub Staff
> > -
> >
> > I have a good faith belief that use of the copyrighted materials
> > described above on the infringing web pages is not authorized by the
> > copyright owner, or its agent, or the law. I have taken fair use into
> > consideration.
> >
> > I swear, under penalty of perjury, that the information in this
> > notification is accurate and that I am the copyright owner, or am
> > authorized to act on behalf of the owner, of an exclusive right that
> > is allegedly infringed.
> > :
> >
> > As you may know, In the United States; a license, absent an attached
> > interest, is revocable.
> >
> > A "John Doe" had his non-exclusive license regarding the game
> > "GPC-Slots2" terminated by the copyright owner (me: MikeeUSA).
> > The copyright owner may do this as-of-right, unless there is an
> > attached interest (ie: unless the licensee paid good consideration for
> > the license).
> >
> > The "John Doe" then proceeded to belligerently upload a copy of
> > "GPC-Slots2" to your host, GitHub.
> > This violated Author's (my) copyright, since "John Doe"'s gratuitous
> > bare license had been terminated by the copyright holder (me).
> >
> 

Re: pppoe(4) and vlan(4)

2019-03-05 Thread Thomas Huber
I hooked two ADSLlinks now with a modem-router (aka. Fritzbox) which do the
pppoe part for now.
I also orderd a newer version of my xDSL-Modem (ALLNET BM200VDSL2V), that
should be able to do the vlan tagging.
I let you know how things work out when everything is in place.

I start  a new thread about pf load-blancer configuration...

Thanks again for your support.
Thomas


On Tue, 26 Feb 2019 at 22:13, Thomas Huber  wrote:

> hmmm just played around and for ADSL-link 1 and 2 which are provided by
> the Deutsche Telekom it is not important if it is chap or pap, works both.
>
>
>
>
> On Tue, 26 Feb 2019 at 16:59, Stuart Henderson 
> wrote:
>
>> On 2019/02/26 16:38, Sebastian Benoit wrote:
>> > Thomas Huber(miracu...@gmail.com) on 2019.02.26 14:22:33 +0100:
>> > > with chap the tcpdump looks like this:
>> > >
>> > > #tcpdump -nevvs1500 -i vlan0
>> > > tcpdump: listening on vlan0, link-type EN10MB
>> > > 13:54:44.118903 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>> PPPoE-Session
>> > > code Session, version 1, type 1, id 0x00a9, length 16
>> > > LCP Configure-Request Id=0x24: Magic-Number=98519
>> > > Max-Rx-Unit=1492
>> > > 13:54:49.120414 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>> PPPoE-Session
>> > > code Session, version 1, type 1, id 0x00a9, length 16
>> > > LCP Configure-Request Id=0x25: Magic-Number=98519
>> > > Max-Rx-Unit=1492
>> > > 13:54:55.122239 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>> PPPoE-Session
>> > > code Session, version 1, type 1, id 0x00a9, length 16
>> > > LCP Configure-Request Id=0x26: Magic-Number=98519
>> > > Max-Rx-Unit=1492
>> > > 13:55:02.124396 00:0d:b9:43:43:b4 88:a2:5e:1e:52:88 8864 36:
>> PPPoE-Session
>> > > code Session, version 1, type 1, id 0x00a9, length 16
>> > > LCP Configure-Request Id=0x27: Magic-Number=98519
>> > > Max-Rx-Unit=1492
>> > > 
>> > >
>> > > but no connection esblished.
>> > >
>> > > On Tue, 26 Feb 2019 at 13:02, Stuart Henderson 
>> wrote:
>> > >
>> > > > On 2019/02/26 12:36, Thomas Huber wrote:
>> > > > > Hi Stuart,
>> > > > >
>> > > > > and thanks for your help.
>> > > > > I tried yout suggestion but didn??t solve the problem.
>> > > > > here is the tcpdump output (i just stripped the account
>> credentials) but
>> > > > I can not read it.
>> > > > > Maybe you can spot something here:
>> > > > >
>> > > > > # tcpdump -nevvs1500 -i em0
>> > > > > tcpdump: listening on em0, link-type EN10MB
>> > > >
>> > > > Reformatted a bit:
>> > > >
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xf6:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Request Id=0xab: Max-Rx-Unit=1492
>> > > > Auth-Prot=PAP Magic-Number=526788746
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xf6:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Ack Id=0xab: Max-Rx-Unit=1492
>> > > > Auth-Prot=PAP Magic-Number=526788746
>> > > > OPENBSD -> JUNIPER: PAP Authenticate-Request Id=0xf7: Peer-Id=
>> > > > Passwd=
>> > > > OPENBSD -> JUNIPER: PAP Authenticate-Request Id=0xf8: Peer-Id=
>> > > > Passwd=
>> > > > JUNIPER -> OPENBSD: LCP Configure-Request Id=0x02: Max-Rx-Unit=1492
>> > > > Auth-Prot=CHAP/MD5 Magic-Number=3828540274
>> > > > OPENBSD -> JUNIPER: LCP Configure-Nak Id=0x02: Auth-Prot=PAP
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xf9:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xf9:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfa:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfa:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfb:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfb:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfc:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfc:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfd:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfd:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Request Id=0x03: Max-Rx-Unit=1492
>> > > > Auth-Prot=CHAP/MD5 Magic-Number=3430741983
>> > > > OPENBSD -> JUNIPER: LCP Configure-Nak Id=0x03: Auth-Prot=PAP
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xfe:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > JUNIPER -> OPENBSD: LCP Configure-Ack Id=0xfe:
>> Magic-Number=1818005467
>> > > > Max-Rx-Unit=1492
>> > > > OPENBSD -> JUNIPER: LCP Configure-Request Id=0xff:
>> 

tar: Access/modification time set failed on: .: Operation not permitted

2019-03-05 Thread Mihai Popescu
Hello,

I am trying to decompress xenocara.tar.gz into /usr/xenocara.
I did all pre setup explained in FAQ, but I get this error from tar
and I can see files inside /usr/xenocara.  tar: Access/modification
time set failed on: .: Operation not permitted

Is it safe to ignore this?
Is there a reason v parameter is not used in tar xzf sequence for a
visual feedback?

Thank you.



About some smptd(8) log message

2019-03-05 Thread Walter Alejandro Iglesias
Hello Gilles,

When some spammer try to reach an invalid address in my server the log
says "Invalid recipient":

[...] smtp failed-command command="RCPT TO: " result="550 Invalid 
recipient: "

But, when the domain name part is valid (one of those included in my
"vdomains" and "valiases" tables), it appears a "Mailing list expansion
problem" message:

[...] smtp failed-command command="RCPT TO:" result="524 5.2.4 Mailing 
list expansion problem: "


In case what I assumed above is correct. :-)  Is the "Mailing list..."
message expected in this case?


Walter



# /etc/mail/smptd.conf

egress_int="em0"
server="server.roquesor.com"

table "aliases" file:/etc/mail/aliases
table "valiases"file:/etc/mail/valiases
table "vdomains"file:/etc/mail/vdomains
table "addresses"   file:/etc/mail/addresses
table "users"   file:/etc/mail/users

pki $server cert "/etc/ssl/server.crt"
pki $server key "/etc/ssl/private/server.key"

listen on lo0
listen on $egress_int port 25 tls pki $server
listen on $egress_int port 465 smtps pki $server auth \
senders  masquerade

action "local" mbox alias 
action "virtual" mbox virtual 
action "relay" relay

match from local for local action "local"
match from any for domain  action "virtual"
match from local mail-from  for any action "relay"
match auth from any mail-from  for any action "relay"

# End of file