Re: /var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Martin Schröder
Am So., 10. Dez. 2023 um 02:48 Uhr schrieb Todd C. Miller : > By default, /etc/login.conf has umask set to 022. Is it more > restrictive on your system? Ah, yes. Mine is set to 077. That would explain me being unable to start it via sudo. And when I rebooted after a failed restart the

Re: /var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Todd C . Miller
The mode on /var/unbound/db/root.key is influenced by the umask. If you restart unbound from a shell with umask set to 077, /var/unbound/db/root.key will be mode 0600. If the the umask is 022, the /var/unbound/db/root.key will be mode 0644. By default, /etc/login.conf has umask set to 022. Is

/var/unbound/db/root.key not world-readable, unbound fails to start

2023-12-09 Thread Martin Schröder
Hi, after the last erratas I rebooted my 7.4 and unbound failed to start because unbound: [65439:0] error: unable to open /db/root.key for reading: Permission denied unbound: [65439:0] error: error reading auto-trust-anchor-file: /var/unbound/db/root.key unbound: [65439:0] error: validator: error

Re: relayd https inspection certificate issue

2023-12-09 Thread J Doe
On 2023-12-09 04:02, Claudio Jeker wrote: Don't do it. This "TLS inspection" mode is broken and it is close to impossible to fix it. The way the MITM cert is built is not smart enough and does not consider many special cases like SAN certs and OCSP. It works for simple things but does not work

Re: cumbersome mtree (OT!) - Process to have RADXIDE (MIT) among ports

2023-12-09 Thread Nowarez Market
Hello, I just reached version 1.2.5 of RADXIDE (MIT license), turned around many bugs, templetized its colors, contacted previous snippets code authors figuring in About. Now, I'm wondering what is eventually the process to have RADXIDE as a small package inside OpenBSD. Nevertheless this

Re: pkg_add - error while reading header / read short file / gzheader truncated

2023-12-09 Thread David Rinehart
On Sat, 2023-12-09 at 11:55 +, Stuart Henderson wrote: > I suggest trying a mirror instead then, and see if there's any > difference. Pick one from www.openbsd.org/ftp.html. Good suggestion. Recent installer changes to simplify the sets "disk" option are awesome. At the same time, this

Re: ls in color

2023-12-09 Thread Jean-François Simon
Also can be using parameters for example: export CLICOLOR=1 export LSCOLORS=ExfxcxdxCxegedabagacad Jean-François On 12/8/23 19:47, Mike Larkin wrote: On Fri, Dec 08, 2023 at 07:41:23PM +0100, Karel Lucas wrote: Hi all, In openBSD V7.4 I would like to see the output of ls in color, and

subscribe

2023-12-09 Thread Anthony Azzopardi
subscribe

Re: pkg_add - error while reading header / read short file / gzheader truncated

2023-12-09 Thread Stuart Henderson
On 2023/12/08 15:40, David Rinehart wrote: > On Fri, 2023-12-08 at 08:37 +, Stuart Henderson wrote: > > On 2023-12-07, David Rinehart wrote: > > > > > > I see the same with multiple installs - Started with 7.4.  No > > > modification to default installurl. > > > > The contents of the

Re: relayd https inspection certificate issue

2023-12-09 Thread Claudio Jeker
On Fri, Dec 08, 2023 at 10:04:25PM +, Philipp Benner wrote: > Dear all, > >   > I would like to use relayd as an outbound https proxy, so I configured it > like shown in the last section of the relayd.conf(5) manpage. > > This works fine for e.g. wikipedia.org. The certificate issued by my