Re: Getting envolved

2007-12-13 Thread Daniel Ouellet
Nick Holland wrote: Daniel Ouellet wrote: Bob Beck wrote: Users who can no invest the effort learn enough to use a simple interface do not deserve a reliable operating system. They deserve windows, and they deserve pop up buttong in their browsers that they click ok blindly for

Re: Getting envolved

2007-12-13 Thread Daniel Ouellet
Jeremy Huiskamp wrote: On 13-Dec-07, at 11:11 AM, Bob Beck wrote: If you like the current way it works, you should be able to continue with this system. But what if my mum, who has low computer skill, would like to install a free, functional and secure system? I think the software should help h

Re: Real men don't attack straw men

2007-12-14 Thread Daniel Ouellet
* Copyright (c) 2007 Daniel Ouellet <[EMAIL PROTECTED]> * * Permission to use, copy, modify, and distribute this software for any * purpose with or without fee is hereby granted, provided that the * above copyright notice and this permission notice appear in * all copies. * * THE SOFTWA

Re: Real men don't attack straw men

2007-12-15 Thread Daniel Ouellet
Marco Peereboom wrote: RMS definitions of free/liberty/freedom etc are contorted to fit his believe system. They are not legal definitions and worse not even correct English. Got to love that the non-native speaker has to point that out. Marco, With all due respect, you made a huge mistake a

Re: Real men don't attack straw men

2007-12-15 Thread Daniel Ouellet
Richard Stallman wrote: There is a difference between "I have no obligation to answer each and every message" and "I cannot find a coherent answer to several messages". One difference is that the first one is true, and the second one is false. As you've seen by now, people were looking

Re: Real men don't attack straw men

2007-12-15 Thread Daniel Ouellet
Richard Stallman wrote: Come oh dilbert of gnu, stamp your licence upon all who code. Propegate your gnu legacy through the universe down to the plank scale. Install your agenda near and far. Come and spread the evangalistic word. All I can do personally is bless your computer. Bu

Re: Real men don't attack straw men

2007-12-15 Thread Daniel Ouellet
bofh wrote: I respectfully disagree. Linux was definitely the enabler for this to happen. How much of Linux's success was because of the GPL is something only historians can tell us, but without FSF/GNU/GPL. Unfortunately, right at that time, bsd was involved in the AT&T lawsuit, or it could ha

inetd stupid config question for -R in rc.conf.local

2007-12-15 Thread Daniel Ouellet
Hi, All the various daemon that use options flag in rc.conf, all have daemon_flags=NO # for normal use: "" when you put the options for your daemon. I am looking to add -R to inetd, but there isn't any inetd_flags, just the: inetd=YES # almost always needed So, just in case, ev

Re: Bottleneck in httpd. I need help to address capacity issues on max parallel and rate connections

2007-12-15 Thread Daniel Ouellet
Mark Bucciarelli wrote: On 12/15/07, Philip Guenther <[EMAIL PROTECTED]> wrote: On Dec 14, 2007 3:06 PM, Mark Bucciarelli <[EMAIL PROTECTED]> wrote: On 2007-05-10 8:40:36 Claudio Jeker wrote: With many shortliving connections you have a lot of sockets in TIME_WAIT. Because you are testing fro

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Daniel Ouellet wrote: Hi, All the various daemon that use options flag in rc.conf, all have daemon_flags=NO# for normal use: "" when you put the options for your daemon. I am looking to add -R to inetd, but there isn't any inetd_flags, just

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Alexander Hall wrote: Daniel Ouellet wrote: Hi, All the various daemon that use options flag in rc.conf, all have daemon_flags=NO# for normal use: "" when you put the options for your daemon. I am looking to add -R to inetd, but there isn't any in

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: from inetd(8): The optional ``max'' suffix (separated from ``wait'' or ``nowait'' by a dot) specifies the maximum number of server instances that may be spawned from inetd within an interval of 60 seconds. When omitted, ``max'' defaults to 256. Not sure how this

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Daniel Ouellet wrote: Alexander Hall wrote: Daniel Ouellet wrote: I am looking to add -R to inetd, but there isn't any inetd_flags /.../ Do you really need to set it globally? You could use the [.max] part of each configuration line for a service-specific se

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Daniel Ouellet wrote: Alexander Hall wrote: from inetd(8): The optional ``max'' suffix (separated from ``wait'' or ``nowait'' by a dot) specifies the maximum number of server instances that may be spawned from inetd within an interva

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: From reading the fabulous source (/usr/src/usr.sbin/inetd/inetd.c; look for "toomany"), I can only conclude that they (-R and [.max]) indeed work as I had guessed, i.e. -R changes the default from 256 to whatever and that the [.max] suffix allows you to specify it for eac

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: So, only wait.6000 in inetd.conf doesn't fix the problem if I do not also start inetd -R 1024. Weird then based on the man page. Weird indeed. Anyway - why '.6000' in inetd.conf but '-R 1024'? Why not the same number? No logics here that I can use to justify it really.

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Hmmm... Are you just not looking at it totally backwards, maybe? Maybe Sometime I sure can be backwards. (;> inetd (with the .6000 suffix) just tries to eat more connections/sockets/handles/whatever than the system (or the user tftp is being run as) is allowed to? But

Re: inetd stupid config question for -R in rc.conf.local

2007-12-18 Thread Daniel Ouellet
Alexander Hall wrote: Dec 15 01:30:50 vtftp1 tftpd[5866]: recv: Connection refused # zcat daemon.2.gz | grep 'Connection refused' # zcat daemon.1.gz | grep 'Connection refused' # zcat daemon.0.gz | grep 'Connection refused' # cat daemon | grep 'Connection refused' Oh. What you see seems to be c

Re: x4100

2007-12-27 Thread Daniel Ouellet
Marco Peereboom wrote: Ok got my x4100 out of storage. What was the mpi issue again that someone was seeing? Sorry for the broadcast but I couldn't find that email. 4100 M2 Any time you put a amd64.mp kernel on that box and you try to do heavy access to the SAS drives, the server will crash

Re: When spammers get whitelisted...

2007-12-27 Thread Daniel Ouellet
Allie D. wrote: I have had to wipe my spamdb twice in the last month because spammers get past my blacklists (I run the ones that come in spamd.conf) and my greylisting and just hammer a few of my customers. The spam comes from multiple IP's so it's a bitch to block by hand...anyone have any tips

Re: x4100

2007-12-27 Thread Daniel Ouellet
Kyle George wrote: On Thu, 27 Dec 2007, Marco Peereboom wrote: Ok got my x4100 out of storage. What was the mpi issue again that someone was seeing? Sorry for the broadcast but I couldn't find that email. I think this is the thread you're looking for: http://marc.info/?l=openbsd-misc&m=119

Re: Linus about C++

2007-12-27 Thread Daniel Ouellet
Brian Hansen wrote: Is he right? If you just search the archive, even not to long ago, 'few days' you will see pretty much the same feeling about C++ on the OpenBSD list as well as pretty much any lists that cares about correct code and clarity in programing. But don't take my words for i

Re: Hazy top of mind questions on spam control with OpenBSD

2007-12-28 Thread Daniel Ouellet
Girish Venkatachalam wrote: a) Most of the spam originates in USA. And high bandwidth links and busy mail servers are common targets. You haven't looked at China and Korea in a long time looks like. USA is not a clean place, but not the major source of it either. Definitely not in my logs an

Re: Hazy top of mind questions on spam control with OpenBSD

2007-12-28 Thread Daniel Ouellet
Also, in case it wasn't obvious either. Make sure to add your spamd-setup to your cron job to update them. And obviously and additional domains will need MX records in DNS obviously too. Not sure if one day the greyscanner will be part of the default install anytime soon? May be they want it

Re: Hazy top of mind questions on spam control with OpenBSD

2007-12-28 Thread Daniel Ouellet
Just for the records and for fun as well. Here is how many spammer were trap by greyscanner ONLY in the last ~9 hours only. Also one thousand are trap per hours. # head -n1 maillog Dec 28 15:00:02 smtp1 newsyslog[2273]: logfile turned over # tail -n1 maillog Dec 28 23:55:25 smtp1 . # cat

Re: Hazy top of mind questions on spam control with OpenBSD

2007-12-28 Thread Daniel Ouellet
OK, I am having to much fun I guess, but that will be my last one. When I say spammer trap, I really mean spammer trap by greyscanner, not only the number of emails block. As examples I see many like this in the logs: Dec 27 16:15:26 smtp1 greytrapper[10139]: Trapped 84.165.240.170: Host se

Re: router/firewall PF

2007-12-29 Thread Daniel Ouellet
Beavis wrote: Just wanted to get some feedback on setting up pf(4) as a router/firewall only (no nat involved). I've been digging the list archive but most of the configurations on them has the a natted network. I'm looking for a basic router/firewall configuration. any help would be greatly a

Re: FW: Real men don't attack straw men

2008-01-03 Thread Daniel Ouellet
Rui Miguel Silva Seabra wrote: On Thu, Jan 03, 2008 at 12:33:26PM -0700, Theo de Raadt wrote: Rui Miguel Silva is continually making you guys remove [EMAIL PROTECTED] from the cc's of your messages. FYI, I continually remove people from the CC on mailing-list posts. I consider it rude to rece

Re: Real men don't attack straw men

2008-01-07 Thread Daniel Ouellet
Richard Stallman wrote: But, if I'm wrong (which is possible), please tell me how I can statically link a program that I write to a GPL'd lib and still retain my freedom to BSD license my code. Under the usual interpretation of the revised BSD license, this is straightforward. You p

Re: Apache box behind Openbsd

2008-01-08 Thread Daniel Ouellet
Errr.. why the hell are you running Apache and PHP on Windows rather than your OpenBSD? Because Stallman make it easy to run *HIS* version of *SUPPOSE* free software one Windows. That's why. Stallman as the various treads pointed out many times over, he (Richard) tell everyone else to do thing

Re: Hard disk speed

2008-01-08 Thread Daniel Ouellet
Manuel Ravasio wrote: You can't just define something as complicated as "hard disk speed" in one number. Or twenty numbers. Ok, I got the idea. time + dd will do. Just remember, that would be kind of fine for the same OS, but not that reliable between different OS. As long as you try differ

OT: Fiber NIC for OpenBSD router

2008-01-09 Thread Daniel Ouellet
Hi, I am getting really stuck here. Can anyone tell me if they know of a good PCI fiber card that is still available for 100Mb today. All the fiber port cards I am looking at are now all > 1Gb. I would prefer get them new obviously as it's very important where they are use and run lots of V

Re: Performance Issues of Intel Quad Port NIC

2008-01-15 Thread Daniel Ouellet
Jonathan Steel wrote: Is there any explanation for the speed difference? I have tried tweeking some sysctl values to no avail. Is there something else I can test for on the card? I'd be happy to run these tests again for any changes that are made. Use 4.2 and Henning did provide details a few t

dc0 crash and problem on Sun V100

2008-01-16 Thread Daniel Ouellet
Hi, I always gets error on the network card dc0 on the Sun V100 server where it doesn't want to use auto negotiation properly and where if I try to force a duplex mode, it doesn't come up, but the link changed between up/down all the time. I get: dc0: failed to force tx and rx to idle state

Re: dc0 crash and problem on Sun V100

2008-01-16 Thread Daniel Ouellet
I just got this output on the console working on it trying to find out what's going on. May be this mean something to someone. dc0: failed to force tx and rx to idle state data error type 32 sfsr=0 sfva=500ba000 afsr=8400 afva=1fe02010048 tf=0xe00176d8 panic: data fault: pc=105e4c4 addr=5

Re: spamd, CARP and relayd

2008-01-23 Thread Daniel Ouellet
Urban Hillebrand wrote: Thanks, but I already stole several ideas from his presentation :) However, it does not answer the 3 questions in my original post. Regarding hardware sizing Bob says he is using a "smallish Dell Server" - I would be interested in more details (how much RAM is needed, h

Re: brute force voip QoS

2008-01-23 Thread Daniel Ouellet
I would like to setup PF so that, whenever an initial voip flow was detetcted, all other non relevant traffic would be blocked, and normal packet flow being restored only after some voip idleness be detected. Not exactly sure why you would like to do this part. With proper QoS setup, it doesn't

Re: brute force voip QoS

2008-01-23 Thread Daniel Ouellet
Chris Cappuccio wrote: Just use the 'tos' tag in pf.conf to match against the IP tos field. Most equipment sets this to something predictable, like 0x68 for RTP and 0xb8 for SIP Just use tcpdump to see what your RTP traffic is tagged as, and also prioritize SIP above RTP. You could also

Re: brute force voip QoS

2008-01-23 Thread Daniel Ouellet
David Newman wrote: On 1/23/08 4:21 PM, Daniel Ouellet wrote: So, you could check for UDP RTP stream from that IP's and all phones can and are most likely preset with a fix range of ports that they can use and if you can find that, then you have all that you need. Gack. No. I've

Re: brute force voip QoS

2008-01-23 Thread Daniel Ouellet
Daniel Ouellet wrote: port use are negotiated via the control port on UDP/5050 and that's when Should have been UDP/5060 here. Not 5050 as above. Sorry, fat finger... Or in some cases when NAT traversal is also in use for SIP, you will have UDP/5060 and UDP/5061. Regardless these ar

OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-24 Thread Daniel Ouellet
Hi, I need some possible suggestions if I may asked to not setup, or have to setup WebDav on OpenBSD to allow users to do their web folder stuff. It can be setup with ftp for example to allow them to map a folder in their "network place" on XP for example, but then they can't do the stupid "s

Re: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-24 Thread Daniel Ouellet
ssage- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Daniel Ouellet Sent: den 24 januari 2008 23:59 To: misc@openbsd.org Subject: OT: Can an SSH alternative to WebDav be use on OpenBSD Hi, I need some possible suggestions if I may asked to not setup, or have to setup WebDa

Re: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-24 Thread Daniel Ouellet
NetOne - Doichin Dokov wrote: I really didn't fully understand you - do you want or not to allow FTP acces, and why clients are not able to "save as" when using it? Do you mean that they need it mapped as a network drive? If so, they can use something like this: http://www.acs.uwosh.edu/novell

Re: OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-24 Thread Daniel Ouellet
Andrew Ruscica wrote: On Thu, Jan 24, 2008 at 05:58:57PM -0500, Daniel Ouellet wrote: .. I only allow ssh access and in very special case, I had accepted ftp from If you're considering a commercial product, http://www.sftpdrive.com If the product performs as it says, you shouldn'

Re: OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-25 Thread Daniel Ouellet
Urban Hillebrand wrote: If using sftp with WinSCP is still an option, but you do not want users to have SSH access, this can be achieved easily with sshd_config-settings like: # override default of no subsystems Subsystem sftp/usr/libexec/sftp-server Match Group sftp X11Forwar

Re: OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-25 Thread Daniel Ouellet
Boris Goldberg wrote: Hello Daniel, I believe it should be possible to set up samba-over-ssh. I mean samba listening localhost only on the server andputty (www.chiark.greenend.org.uk/~sgtatham/putty/) with port forwarding on clients. Thanks, I don't thin

Re: OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-29 Thread Daniel Ouellet
Denny White wrote: That's all one line above. I dropped part of it down for the 72 character rule. As the article shows, instead of having to open a cygwin prompt, then issue the tunneling command, the whole thing can be automated with a script & a windows service started on boot. When the user c

Re: OT: Can an SSH alternative to WebDav be use on OpenBSD

2008-01-29 Thread Daniel Ouellet
Stuart Henderson wrote: while this is a way if you _must_ use SMB/CIFS, I'm not too sure if a combination of samba, cygwin (which users won't bother to update once it's installed so no security fixes) and MS loopback adapter (for some client-breaks-their-own-network-and-shouts-at-you fun) is real

Re: solaris 10. 'most' secure OS?

2008-02-01 Thread Daniel Ouellet
Richard Daemon wrote: On Feb 1, 2008 5:14 PM, badeguruji <[EMAIL PROTECTED]> wrote: From Sun's own mouth: ..."Solaris 10 OS, the most secure OS worldwide holding 176 records"... is that so? ~~aapka kalyan ho~~ Doesn't MS say the same thing for Vista? Th

Re: running mail server at home

2008-02-07 Thread Daniel Ouellet
L. V. Lammert wrote: On Thu, 7 Feb 2008, Marco Peereboom wrote: Works for me and has for years. You would not see these emails if it didn't. What you forget here is that "most" don't adhere to standards. Didn't say it wouldn't work, .. but I, for one, don't want to have to call someone to m

VPN suggestions and advise for clean sheet setup

2008-02-29 Thread Daniel Ouellet
Hi, I have been looking into this for some time, but there is so many different setup possible that unless you have one and are force to continue using it, one wouldn't know witch way to go. I try to keep it as simple and clean as possible, so if you start with a clean sheet and no restricti

4.3 release testing for amd64.mp on Sun X4100

2008-03-05 Thread Daniel Ouellet
Following Theo request for testing, I did the same test as previously reported a few times on misc@ as well as tech@ and the 4.3 release using the multi code on amd64 still crash at will by just doing a simple: dd if=/dev/zero of=/var/test bs=1m count=1000 Doesn't do it using the single amd64

Re: [bug fix] Problem installing OpenBSD 4.2

2008-03-07 Thread Daniel Ouellet
Saulo Bozzi Daleprane wrote: Already, try with the cd42.iso but don't boot. Did you follow all the steps: http://openbsd.org/faq/faq4.html#42cdboot

Re: [bug fix] Problem installing OpenBSD 4.2

2008-03-07 Thread Daniel Ouellet
Saulo Bozzi Daleprane wrote: Stuart Henderson wrote: yes yesis the correct. amd64 - cd42.iso I did download yesterday, and nothing. did you swap the disk for the i386 one at the boot loader? 1. Insert CD2 and tell your computer to boot it; 2. When the boot> prompt appears,

OT: Wireframe Puffy 3D model for Lego's

2008-03-09 Thread Daniel Ouellet
Hi, Sorry about this off topic request. My Sun keep asking me to get a "Wireframe Puffy" 3D model, or CAD file, or Vector version of the design if that even exists somewhere. He really love the Wireframe Puffy and want to make a Lego version of it and make a packages of it to for some of his

Re: OT: Wireframe Puffy 3D model for Lego's

2008-03-09 Thread Daniel Ouellet
Daniel Anderson wrote: If nobody responds to this with a quality file, I will gladly make a 2D version of it as an SVG for you and all of us. I will wait a few days, may be someone might have something or not. I can't say yet. No reply other then yours yet. Anything would be mostly appreciate

Re: BSD Documentation License?

2008-03-21 Thread Daniel Ouellet
Lars NoodC)n wrote: Crap. Please ignore that ... Too late. ;) It looks like the old ISC code or almost the original BSD license, which I cannot find. I'm getting worse at searching, but it seems things are disappearing, too. The attribution requirement seems to suggest that the Creative Co

Re: OT: Wireframe Puffy 3D model for Lego's

2008-03-31 Thread Daniel Ouellet
Richard Daemon wrote: Has he replied to this? I haven't been able to contact him off list, the mail keeps failing. Nope, not yet anyway... But here is something fun, not puffy sadly until my Son can get a 3D version somewhat usable to create one. Or may be he will try to do something, I can'

Re: package update trouble

2006-12-15 Thread Daniel Ouellet
[EMAIL PROTECTED] wrote: - Original Message - From: Daniel Ouellet <[EMAIL PROTECTED]> Date: Friday, December 15, 2006 11:17 pm Subject: Re: package update trouble To: [EMAIL PROTECTED] Cc: misc@openbsd.org [EMAIL PROTECTED] wrote: On a new 4.0 installation I am trying out the p

Re: package update trouble

2006-12-15 Thread Daniel Ouellet
[EMAIL PROTECTED] wrote: On a new 4.0 installation I am trying out the pkg_add update procedure for the first time and it is giving me grief. Please look at the following output and let me know how the tool is finding the situation so ambiguous and also how I should proceed. # pkg_add -vv -n

OT: TinyMCE security and track records

2006-12-21 Thread Daniel Ouellet
Hi All, Sorry for this off topic question, but I get more and more requests to have WYSIWYG editing on web management servers. I have been resisting this for many years so far as I hate this, but look likes more and more demands may force me to do it anyway. Any valid feedback on the securit

Re: OT: TinyMCE security and track records

2006-12-22 Thread Daniel Ouellet
Marc Espie wrote: I think that, to go further, you need actual development tools that you can customize to the level of your website code. I assume eclipse will have this kind of plugin. The kde webdev suite is definitely a nice candidate there, though I haven't tried to customize it to get WY

Re: OT: TinyMCE security and track records

2006-12-22 Thread Daniel Ouellet
Nico Meijer wrote: Clients will produce poo with TinyMCE, FCKeditor or any WYSIWYG-editor for that matter. They will copy-past directly from Word-documents and wonder why their page looks like crap. Telling them that it IS crap does not help. They'll just scream louder for you to fix it and they

Repeat panic every 20 minutes with spamd enable

2006-12-27 Thread Daniel Ouellet
I am getting repeated panic on my server every 20 minutes or so when spamd is enable. This is on 4.0 and here is what I get inside /var/log/message. Two sampling of it. I did upgraded from 3.9 before as may be I thought I was getting a problem in 3.9, but it is still happening. I am going to

Re: Repeat panic every 20 minutes with spamd enable

2006-12-27 Thread Daniel Ouellet
Pedro Martelletto wrote: Do you see anything unusual on dmesg? Not that I can see. Not different then before. OpenBSD 4.0 (GENERIC) #1107: Sat Sep 16 19:15:58 MDT 2006 [EMAIL PROTECTED]:/usr/src/sys/arch/i386/compile/GENERIC cpu0: AMD Athlon(tm) XP 2400+ ("AuthenticAMD" 686-class, 256KB L

Re: auto start mysql and snort OpenBSD 4.0

2006-12-28 Thread Daniel Ouellet
Edy wrote: Hi I have googled and read on the man pages but something is missing here. For example i have the following in my /etc/rc.local if [ X"${mysql}" == X"YES" -a -x /usr/local/bin/safe_mysqld ]; then echo -n ' mysqld'; /usr/local/share/mysql/mysql.server start fi if [ X"${snort}"

Re: auto start mysql and snort OpenBSD 4.0

2006-12-28 Thread Daniel Ouellet
Edy wrote: Daniel, I have been to that site already and it does not start mysql when the system rebooted but i could start mysql by using the command. Cheers, -e If you follow the instructions it does. But like many you most likely put the starting scripts inside rc.conf.local instead of

Re: Repeat panic every 20 minutes with spamd enable

2007-01-01 Thread Daniel Ouellet
Daniel Ouellet wrote: I am going to test the memory next just in case, but anyone have an idea as to what that might be? Just for the record, after I got a replacement DDR 1GB replacement in the server, all have been stable so far for a few days. So, memory it was look like. Thanks

Re: OT Was: Wanted: OpenBSD Systems Administrator

2007-01-03 Thread Daniel Ouellet
Peace, and to move on, I don't know if that's any good or not or even needed really. But like many wanted "How To" saying it would be much better, however the results are not overwhelming, but peace came from it anyway. Here is a place for your job(s) offer instead of your jobs@, etc if you th

Re: Firewall, high interrupt load, is this a driver problem (dc) ?

2007-01-07 Thread Daniel Ouellet
Ronnie Garcia wrote: The CPU usage is almost only "interrupt", as you can see on this top output : Instead of showing part of your DMESG, all of it would have been better. Anyway, as far as Interrupts are concern, you can try to run the bsd.mp kernel as the interrupt processing is different i

Re: SMP kernel on single CPU machines?

2007-01-07 Thread Daniel Ouellet
Tobias Weisserth wrote: this may be a really stupid question but I'm going to ask it anyway since I didn't find anything using Google or in the archives. http://marc.theaimsgroup.com/?l=openbsd-misc&w=2&r=1&s=smp&q=b Gives me 264 instance of smp. One of the most noticeable difference, not tha

Re: OT Was: Wanted: OpenBSD Systems Administrator

2007-01-12 Thread Daniel Ouellet
Umnada Tyrolla wrote: I don't think that really helped the problem any. How are the headhunters going to know about it? That's better then complaining and doing nothing and was an answer to the request for [EMAIL PROTECTED] Also, as describe on the site "Please only send OpenBSD specific job

Re: OT Re: 'database filesystems'

2007-01-18 Thread Daniel Ouellet
bofh wrote: Hmm, there's been recent noise about opensolaris being licensed under gpl v3. I'm curious if gpl v3 is "compatible" with the bsd license? Stop. GPL != BSD Regardless of the version! Please do not start a flame war PLEASE! Best, Daniel

Re: compiling SMP kernel (how?)

2007-01-24 Thread Daniel Ouellet
Peter Matulis wrote: I'm looking for instructions on compiling a kernel to run on my SMP system. I've installed 4.0 and I can run bsd.mp but now I want to update my sources and recompile a new GENERIC kernel. All is fully documented on the site. Use the patch process only for the security ad

Re: keep state for http connections

2007-01-25 Thread Daniel Ouellet
Brian Candler wrote: On Wed, Jan 24, 2007 at 02:39:42PM -0600, Travers Buda wrote: Last time I checked though, clients only talk with the web server on port 80. So, the only reason you would want to keep state would be if you have a ruleset like block out all (which is generally only usefull if

Re: Patching OpenBSD 3.0, 3.3, 3.6 for US Daylight Saving Time changes in 2007

2007-01-25 Thread Daniel Ouellet
Christine Siegel wrote: We have 3 IBM NetVistas, each running a different version of OpenBSD - one at 3.0, one at 3.3 and one at 3.6. I'm very unfamiliar with the world of OpenBSD and how you "patch" the OS. How would I go about updating these various systems to deal with the changes to US Da

Re: spamd - SPEWS status

2007-02-01 Thread Daniel Ouellet
Bob Beck wrote: Yeah, probably time to retire spews, they aren't going to fix it. Aside from my traplist (which I'll add) anyone have any suggestions for useful addtions when I commit this? I seldom use exernally maintained blacklists anymore :) -Bob Not that it ca

Re: spamd - SPEWS status

2007-02-01 Thread Daniel Ouellet
smith wrote: On Thu, 01 Feb 2007 15:38:37 -0500, Daniel Ouellet wrote May be if there was a way to distribute one own addition only may be a good idea as then we could merge traplist from multiple locations if one wants to do this. I wouldn't have any objection to make mine available if

Re: HTTP URL filtering?

2007-02-06 Thread Daniel Ouellet
Xavier Mertens wrote: I've a problem with an Apache web server hit by f*cking spammers... I would like to filter some URLs (unused but still used by the bots) *BEFORE* they reach the httpd processes. What could be the best method? pf? something else? PF doesn't look at URL content, so can't b

Re: HTTP URL filtering?

2007-02-07 Thread Daniel Ouellet
Marian Hettwer wrote: I tried the very same when a webserver of mine was hitted by some botnet. Unluckily, cron can only ran every minute as the fastest interval and within 1 minute I already had around 1000 connections from different IP addresses. Ergo: A one minute interval didn't help at al

Re: login.conf

2007-02-07 Thread Daniel Ouellet
Toni Mueller wrote: uppp I apparently didn't see that section because I didn't re-read it. If that info is correct, then this "solves" it (hello Daniel!). Yes that information is correct and if done to the letter, you get it to do as you wish. Been tested and used for many years on pre

Re: SIP on OpenBSD

2007-02-15 Thread Daniel Ouellet
I keep seeing the subject coming up. Yes, a complete OpenBSD solution would be nice. However only two persons offer some possible financial help to make this happen, but nothing concrete. In any case, I put the wheel in motion to replace a commercial solution my business use, and I will do w

Re: site hosting on 2 internet connections

2007-02-15 Thread Daniel Ouellet
Jacob Yocom-Piatt wrote: i've read about using the route-to to balance outbound connections in the pf address pools docs, but i don't see this being immediately helpful for hosting purposes since the inbound connections should come in on both netblocks in the case that the load is spread over t

Re: site hosting on 2 internet connections

2007-02-16 Thread Daniel Ouellet
Claer wrote: This can be very problematic if your ISPs are running antispoofing protections (they should, they rarely do). The other problem I see in that setup is the asymetric routing it creates. It can be another source of problems later. Please, try to check with a temp server (with one of

Re: HTTP URL filtering?

2007-02-20 Thread Daniel Ouellet
Toni Mueller wrote: Pro: Every bot can access the url exactly one time, afterwards its blacklisted. Use expire-table to free the pf table occassionally and of course make sure that you don't block yourself - whitelist ip addresses like your standard gateway, otherwise you may DoS yourself ;)

Re: HTTP URL filtering?

2007-02-20 Thread Daniel Ouellet
Toni Mueller wrote: Hi, On Tue, 20.02.2007 at 12:33:17 -0500, Daniel Ouellet <[EMAIL PROTECTED]> wrote: * Use a non-forking server. ??? I've been hit by guys who simply exhausted the maximum number of processes I configured with Apache. What limits do you usually have? I am

Re: Router performance on OpenBSD and OpenBGPD

2007-02-21 Thread Daniel Ouellet
Alex Thurlow wrote: We're pushing streaming video, so it's almost all outbound traffic by about a 30:1 factor, and our average packet size is quite large - around 1200 bytes. At the moment, when we hit about 350Mbps, the router gets to ~30% CPU usage, and it appears that we stop being able to

Clock running 1/4 of real time

2007-02-25 Thread Daniel Ouellet
I had various problem with my bgpd as session were dropping and couldn't figure out why that was. But luck I happen to monitor the sessions and realize that the clock on the server run about 1/4 of real time. Everything run 1/4 of what it should be. Ping answer oneping each 4 seconds instead

Re: Clock running 1/4 of real time

2007-02-25 Thread Daniel Ouellet
Ronnie Garcia wrote: Daniel Ouellet a icrit : But luck I happen to monitor the sessions and realize that the clock on the server run about 1/4 of real time. Everything run 1/4 of what it should be. Ping answer oneping each 4 seconds instead of one. Top refresh every 20 seconds instead of 5

Re: Clock running 1/4 of real time

2007-02-25 Thread Daniel Ouellet
Last update. The only thing that I also saw what this clock: In normal operation: cpu0: apic clock running at 199MHz Before a reboot when I have the problem: cpu0: apic clock running at 678MHz, But this is not always the same value. Anyway, that's all I have. Not a huge deal, I can always

Re: Router performance on OpenBSD and OpenBGPD

2007-02-25 Thread Daniel Ouellet
Stuart Henderson wrote: On 2007/02/21 18:38, Daniel Ouellet wrote: problem is really I can't replace Cisco DS3 and multi channel DS3 with OpenBSD yet for the lack of decent hardware for that! (;< eotdm may be worth a look where you have both ends of the line. some vendors mentio

Re: Wireless Access Points and DHCPd

2007-02-26 Thread Daniel Ouellet
Shohrukh Shoyokubov wrote: Hello, I have problem with assigning IP addresses to wireless clients using DHCP. I have two D-Link DWL-G700AP access points and turned their DHCP servers off. They are connected to my wired network, where my OpenBSD server resides. I have configured OpenBSD as DHCP

Routing differences between physical network cards VS VLan's on same card.

2007-02-27 Thread Daniel Ouellet
I am trying to understand or see if there would be differences between using OpenBSD for routing in a setup where the routing is done between two VLan's for example oppose to between to physical network cards. Any impact on the pps capability between the two? Internally to the server/router, i

Re: Routing differences between physical network cards VS VLan's on same card.

2007-02-27 Thread Daniel Ouellet
Henning Brauer wrote: * Daniel Ouellet <[EMAIL PROTECTED]> [2007-02-27 08:58]: I am trying to understand or see if there would be differences between using OpenBSD for routing in a setup where the routing is done between two VLan's for example oppose to between to physical network c

Re: Routing differences between physical network cards VS VLan's on same card.

2007-02-27 Thread Daniel Ouellet
Henning Brauer wrote: use better network cards, or start hacking :) For the card, I sure know, but it's stat to be pretty darn expensive to test what's on the market and new one as well. I fell sometime it would be less expensive to have a custom one design using FPGA or something! As for h

Re: Routing differences between physical network cards VS VLan's on same card.

2007-02-27 Thread Daniel Ouellet
Claudio Jeker wrote: Hah. Developing an ueberfast FPGA network card needs at least a manyear of work and that's a very optimistic prognosis. I guess buying two three motherbords and a bunch of GigE cards (two or three cards for em, bge, bnx, sk, msk) will give you a good testbed for figuring out

OT: Google-mini equivalent on OpenBSD suggestions needed

2007-03-08 Thread Daniel Ouellet
Hi, Sorry for the off topic and fell free to ignore please. But, I am at a lost as to find something that would run very nicely on OpenBSD that would be similar to a google mini search engine. There is so many choices that evaluating each one is just very time consuming. So, I thought to ask

Re: OpenBSD 4.1 Pre-Orders...

2007-03-12 Thread Daniel Ouellet
Darrin Chandler wrote: Have you got yours yet?! http://undeadly.org/cgi?action=article&sid=20070312181549 Your late! (;> Confirmation at: Order number 2007/3/12-11:39:37-x: Saw the cvs email change and went right away to the order page. If I wasn't the first one, I bet I sure was int h

Re: Important OpenBSD errata

2007-03-15 Thread Daniel Ouellet
Karl O. Pinc wrote: On 03/15/2007 11:29:22 PM, Theo de Raadt wrote: I looked for your name on the donations list. I don't see it. I only buy CDs and stuff occasionally, and generally invest time in what I hope are productive ways. And what are the developers doing with their time? They giv

Re: Compiling your own system as a way of upgrading it is not supported

2007-03-16 Thread Daniel Ouellet
Karel Kulhavy wrote: "Some reasons why NOT to build from source: [...] Compiling your own system as a way of upgrading it is not supported." http://openbsd.org/faq/faq5.html I want to upgrade my 4.0-release system to get rid of the ipv6 remote vulnerability. I understood it's possible only by re

<    1   2   3   4   5   6   7   8   9   10   >