PHP 5.3.1 on OpenBSD 4.2

2013-10-02 Thread Markus Rosjat
Hey there, I have a server that runs a OpenBSD 4.2 with a php of 5.2.3 and now I just need some information if it's possible to switch to php 5.3.1 without bigger problems or is it just not recommended? Some kind of help is most appreciated. Regards Markus

Re: PHP 5.3.1 on OpenBSD 4.2

2013-10-02 Thread Markus Rosjat
On 02.10.2013 14:14, Otto Moerbeek wrote: On Wed, Oct 02, 2013 at 01:52:29PM +0200, Markus Rosjat wrote: Hey there, I have a server that runs a OpenBSD 4.2 with a php of 5.2.3 and now I just need some information if it's possible to switch to php 5.3.1 without bigger problems or is it just

Re: PHP 5.3.1 on OpenBSD 4.2

2013-10-03 Thread Markus Rosjat
to no downtime if required. I have a image for a esxi so I will do the test on that and if I'm successful I just do it step by step on the server. This is maybe the easiest way to go here. -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann, Kögler

Apache2 config on OpenBSD 5.5

2014-06-02 Thread Markus Rosjat
by the default still ? Oh and if someone has some helpful links on all this that would be extremly helpful. Regards Markus -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351

Re: new OpenSSL flaws

2014-06-06 Thread Markus Rosjat
in removing 90k of c code lines from something that is messed up means to make it more solid but that's just my point of view and I'm just a dummy -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http

rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
I can do but dont want to: - I can enable root ssh access - I rsync as root and the owner and permission gets copied even the user doesnt exist on the remote machine Is there any other thing I miss with the sudo approach? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros

Re: rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap, --groupmap and --chown in the man page. Haven't tried them myself but AFAIK these options were added

Re: rsync -a doesnt keep owner and permissions

2014-08-19 Thread Markus Rosjat
, too). Set that to sudo rsync, would be my guess. -Adam well I will give it a shot and this may be the missing piece here On August 19, 2014 9:27:11 AM CDT, Markus Rosjat ros...@ghweb.de wrote: Hello, this has been asked befor though but since searching the net always tells me it should work

Re: rsync -a doesnt keep owner and permissions

2014-08-20 Thread Markus Rosjat
already have. But thanks for the sugession On 19 Aug 2014, at 16:53, Markus Rosjat ros...@ghweb.de wrote: Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap

Re: rsync -a doesnt keep owner and permissions

2014-08-21 Thread Markus Rosjat
Sent from my iPad On 19 Aug 2014, at 16:53, Markus Rosjat ros...@ghweb.de wrote: Am 19.08.2014 16:40, schrieb Erling Westenvik: On Tue, Aug 19, 2014 at 04:27:11PM +0200, Markus Rosjat wrote: Is there any other thing I miss with the sudo approach? Check out --usermap, --groupmap and --chown

Re: rsync -a doesnt keep owner and permissions

2014-08-21 Thread Markus Rosjat
have to give someone the right to act as root I'll do it. But with my understanding and what I have read so far it all melts down to the point when someone is telling you you can get this when you do it as root. 2014-08-21 8:47 GMT+02:00 Markus Rosjat ros...@ghweb.de: Just a short heads up

remove swap partion after physical machine converted into vm

2014-08-27 Thread Markus Rosjat
(not present) HDD. I just get into singleuser mode can exit it and then the machine just boots up as expected. For convinience it would be nice to skip the part with the singleuser mode. So is there a way to remove the swap partion or remove the softraid without data loss? Regards Markus -- Markus

Re: remove swap partion after physical machine converted into vm

2014-08-27 Thread Markus Rosjat
Hi Josh, thx for the fast reply I will check the fstab out it may solve the problem regards Markus Am 27.08.2014 13:58, schrieb Josh Grosse: On 2014-08-27 05:15, Markus Rosjat wrote: Hello, I simply dd'ed the HDD of our Server and converted the image to a virtual disk, I created a VM ans

tools for monitoring network traffic

2014-09-19 Thread Markus Rosjat
and other tools but since Im a lazy guy I want to look for a solution that is already out there. Thx for the help :) Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49

in need of openbsd as mailserver with ldap and courier

2014-10-02 Thread Markus Rosjat
for a company or a indepent. We would of course pay for the job. So if someone or a company in the area is intersted feel free to contact me. My Contact Information is in the footer of the mail. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla

Soekris 6501-70 mSATA and OpenBSD

2015-02-19 Thread Markus Rosjat
was one of the devices that seem to have no trouble with booting up. So simple question is there something I miss here that needs to be done befor I reboot after a fresh install to get the Soekris up and running? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H

[Solved] Re: VS: Soekris 6501-70 mSATA and OpenBSD

2015-02-20 Thread Markus Rosjat
Hi there, it seems the tip with the delay did the trick :) thx Markus Am 20.02.2015 um 08:34 schrieb Markus Rosjat: hi tuomas, I tried both default to com0 and not but same result but I will checkout the other settings maybe that does the trick :) thx for the quick reply regards Markus

OpenBSD as a Mailserver

2015-03-25 Thread Markus Rosjat
Hi there, what's the usual setup these days for mailserver ? I have a old machine and like to jump into the future :) old setup: OpenBSD 4.2 Courier Sendmail LDAP I would like to keep LDAP because I may want to migrate my mailboxes. thanks for the advice Regards -- Markus Rosjatfon

Re: OpenBSD as a Mailserver

2015-03-25 Thread Markus Rosjat
Hey Marcus, thans for the informations, I just edit in my answers below . Regards Markus Am 25.03.2015 um 16:20 schrieb Marcus MERIGHI: ros...@ghweb.de (Markus Rosjat), 2015.03.25 (Wed) 13:58 (CET): what's the usual setup these days for mailserver ? below is only my impression of what

a few questions to httpd

2015-04-01 Thread Markus Rosjat
it support chroot - can you define virtual host and does it support SNI I could guess of more but I think thats the most important stuff for me right now :) So if some of the insiders could shed some light on the subject would be cool Regards -- Markus Rosjatfon: +49 351 8107223

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Okay I found some pdf (damn if you can't google it the right way ...) so I think I just solved this myself but if someone with experience in setting it up likes to give hints I'll gladly take tehm :) Regards Markus Am 01.04.2015 um 16:32 schrieb Markus Rosjat: Hi there, since 5.7

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Am 01.04.2015 um 17:34 schrieb Peter J. Philipp: On Wed, Apr 01, 2015 at 05:21:47PM +0200, Markus Rosjat wrote: I'm a german , extremly lazy and a dummy by default (ask arround you'll see ) but like my previous mail said I just found a pdf that provides most of the answers I have ;) I'm

Re: a few questions to httpd

2015-04-01 Thread Markus Rosjat
Am 01.04.2015 um 16:51 schrieb Alexander Hall: On April 1, 2015 4:32:43 PM GMT+02:00, Markus Rosjat ros...@ghweb.de wrote: Hi there, since 5.7 will not have a apache or a nginx as out of the box webserver it would be nice to know something about the new httpd. I try to google arround but I

Re: [solved] a few question about sftp

2015-05-01 Thread Markus Rosjat
okay short improvement maybe the wrong way but so you can revoke the exexute permission on others I changed ownership of /var/sftp to root:sftpuser and permission to 0710 Am 01.05.2015 um 15:46 schrieb Markus Rosjat: Am 01.05.2015 um 15:36 schrieb Markus Rosjat: well I got it running

openldap verver problem

2015-05-02 Thread Markus Rosjat
is it better to just get the source and make it from scratch (regarding the monitoring stuff too )? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220

Re: Dovecot with OpenLDAP

2015-05-02 Thread Markus Rosjat
just a little update, dont know if it's the right approach Am 02.05.2015 um 19:37 schrieb Markus Rosjat: Hi there, once again some stupid questions :) 1. is there a sane example out there to configure dovecot with openldap on openbsd? - I try to get things running for hours now all I get

Dovecot with OpenLDAP

2015-05-02 Thread Markus Rosjat
codesnippet which I cant even find in the config files. 2. is it worth the effort trying to get sendmail (the ldap flavour) installed or should I just skip it for a different program? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla

disk quota clearification

2015-05-01 Thread Markus Rosjat
write till the 100mb are reached ? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich

[solved] disk quota clearification

2015-05-01 Thread Markus Rosjat
Okay got the answer, group quota does work like a shared limit so all user of the group are bound to the group quota. regards markus Am 01.05.2015 um 18:56 schrieb Markus Rosjat: Hi there, when I set a quota for a group does this mean the limit is added for the wohle group or is it added

a few question about sftp

2015-05-01 Thread Markus Rosjat
use key auth for this? and if the first 2 questions get a yes ... whats wrong with my setup :-P since this is just a test thing I can post the sshd_config if needed regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str

Re: a few question about sftp

2015-05-01 Thread Markus Rosjat
)/var/sftp is there something I can do to prevent this last no go ? Am 01.05.2015 um 15:15 schrieb Nick Holland: On 05/01/15 07:07, Markus Rosjat wrote: hi there, I just do some testing with sftp access and I stumbled about some things I dont get. if I use the chroot I would asume the user cant

[solved] a few question about sftp

2015-05-01 Thread Markus Rosjat
Am 01.05.2015 um 15:36 schrieb Markus Rosjat: well I got it running to a point were my user got loged in to his home dir. he is now chrooted to /var/sftp because this one is owned by root and not writeable for others. still can jump from home dir (well it's not really this home) /var/sftp

Re: Dovecot with OpenLDAP

2015-05-03 Thread Markus Rosjat
Am 03.05.2015 um 10:32 schrieb Stuart Henderson: On 2015-05-02, Markus Rosjat ros...@ghweb.de wrote: okay it seems dovecot runs root and not as the _dovecot user so applying a login class for the dovecote group only helps if you add root to it and nor it seems to start properly. How are you

Re: Dovecot with OpenLDAP

2015-05-03 Thread Markus Rosjat
11:42 schrieb Markus Rosjat: Am 03.05.2015 um 10:32 schrieb Stuart Henderson: On 2015-05-02, Markus Rosjat ros...@ghweb.de wrote: okay it seems dovecot runs root and not as the _dovecot user so applying a login class for the dovecote group only helps if you add root to it and nor it seems

Re: Question about PHP safe mode

2015-06-24 Thread Markus Rosjat
23.06.2015 um 11:44 schrieb Markus Rosjat: Hi there, just a short question... I have quiet old 4.2 OpenBSD with a 5.2.4 PHP version. The safe_mode is on, a Costumer wants to have it off. Is there any security risk to it or do I need to check something on the system level to disable it but still have

Question about PHP safe mode

2015-06-23 Thread Markus Rosjat
? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

spamdb log question

2015-07-01 Thread Markus Rosjat
Hi there, just a simple question, is there a way to seperate the spamdb logs into logs for white-, grey- and blacklist entries? It would make the lookup make much easier when something goes wrong :) regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR

Re: spamdb log question

2015-07-01 Thread Markus Rosjat
Bennett: On Wed, Jul 01, 2015 at 11:01:18AM +0200, Markus Rosjat wrote: Hi there, just a simple question, is there a way to seperate the spamdb logs into logs for white-, grey- and blacklist entries? It would make the lookup make much easier when something goes wrong :) I just use: alias G

Re: dhcpd.interfaces question

2015-07-27 Thread Markus Rosjat
So if I want to have a vlan interface providing dhcp I need to put dhcpd_flags=vlanXX in rc.conf.local ? regards MArkus Am 27.07.2015 um 14:09 schrieb Jiri B: On Mon, Jul 27, 2015 at 02:02:45PM +0200, Markus Rosjat wrote: Hi there, I just want to setup a dhcp for a Vlan on a openbsd 5.5

dhcpd.interfaces question

2015-07-27 Thread Markus Rosjat
Hi there, I just want to setup a dhcp for a Vlan on a openbsd 5.5 box and somehow I can't find the dhcpd.interfaces file. Is there a change in the configuration since 5.x ? On a 4.9 installation I still have this file. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros

odd behaviour of spamdb

2015-07-13 Thread Markus Rosjat
| grep WHITE | awk -F | '{print $2}'`; do echo $i /usr/sbin/spamdb -d $i /usr/sbin/spamdb -a -t $i echo $i /etc/mail/blacksheep.txt done /usr/libexec/spamd-setup maybe someone give me some hints for improvement regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de

Re: odd behaviour of spamdb

2015-07-13 Thread Markus Rosjat
Am 13.07.2015 um 10:07 schrieb patrick keshishian: On 7/13/15, Markus Rosjat ros...@ghweb.de wrote: hi there, I have a script the following script to delete spam mx ip from the spamd whitelist and write them in my own blacklist. After that I reload the blacklist with spamd- setup. This seems

verification spamd and traffic

2015-10-08 Thread Markus Rosjat
generate traffic with them. Could someone confirm this ? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese

Re: Microsoft Now OpenBSD Foundation Gold Contributor

2015-07-09 Thread Markus Rosjat
there stuff becuase they wanted to benefit from this. So why not be a little happy that the openbsd project got a contribution even from MS? but well maybe I get it all wrong ... regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann

Soekris 4501 and OpenBSd 5.7

2015-09-16 Thread Markus Rosjat
Hi there, just a simple question, is it possible to install a 5.7 on a soekris 4501? It seems when I try to load the bsd.rd ftom the tftp server the soekris isnt able to handle it. I redirected the console but it get stuck on the entry point msg. Regards Markus -- Markus Rosjatfon

Re: Soekris 4501 and OpenBSd 5.7

2015-09-16 Thread Markus Rosjat
with a 32bit image:) regards Markus Am 16.09.2015 um 18:30 schrieb Christian Weisgerber: On 2015-09-16, Devin Reade <g...@gno.org> wrote: I don't know about the 4501, but the 5501 works fine. Also, lunch was okay. Since we are talking about totally different things. -- Markus Rosjatfo

vpn from subnet to subnet through a 3rd enpoint?

2015-10-06 Thread Markus Rosjat
bnet 2 <> subnet 3; works fine subnet 1 <---| subnet 3 |> subnet 2; isn't working all 3 endpoints running openBSD and ipsec, some advice would be cool :) regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrüc

Re: moving postgresql files to seperate mount

2016-06-02 Thread Markus Rosjat
Hi all, thanks for the replies I will try to keep them in mind while I try to move my databases :) Regards Am 01.06.2016 um 17:22 schrieb trondd: On Wed, June 1, 2016 3:45 am, Markus Rosjat wrote: Hi there, just need some kind of acknowledgement for my workflow :) a naive approach would

moving postgresql files to seperate mount

2016-06-01 Thread Markus Rosjat
in such scenario can give me a hint or too Thanks and regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese

Re: sendmail mx question

2016-04-05 Thread Markus Rosjat
provides some real info, but since he didn't do that, I didn't reply... -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie

[solved] sendmail mx question

2016-04-07 Thread Markus Rosjat
one german to another lol) Regards Markus Am 06.04.2016 um 16:43 schrieb Markus Rosjat: Hi Craig, yeah my server is fine in general but maybe the other adin just has some sort of own ways to blacklist so I might be on there list. I'll check this too but it seems it could be a routing problem

Re: sendmail mx question

2016-04-06 Thread Markus Rosjat
, and I only did that to have some other tool checking if it can connect to the mx in question, is the fact that a site like mxtoolbox can talk to the mx. -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden

Re: sendmail mx question

2016-04-06 Thread Markus Rosjat
On 2016-04-06 Wed 09:29 AM |, Markus Rosjat wrote: Okay with some help from Christoph Viethen I did some testing and connfirmed a few things - sendmail -bt gave me the right order of the mx to talk to - I couldn't connect to the server with nc - I couldn't ping the server - nslookup gave me the

openbsd 4.7 virtual machine on hyper-v

2016-03-01 Thread Markus Rosjat
anything (not from or to the machine). PF is disabled for now so Im sure thats not the problem, I wrote some post on the net about problems with openBSD and hyper-v so general question is... is hyper-v able to run a openbsd vm at all? regards -- Markus Rosjatfon: +49 351 8107223mail

Re: openbsd 4.7 virtual machine on hyper-v

2016-03-01 Thread Markus Rosjat
for it a release or two back. 4.7 is ancient, you need to upgrade. Brian Conway On Mar 1, 2016 7:10 AM, "Markus Rosjat" <ros...@ghweb.de> wrote: Hi there, I ported a vm from vmware to hyper-v. the machine boots up, weel some services are failing for now but thats not the issue. I can dont

sendmail mx question

2016-04-05 Thread Markus Rosjat
happening at all. I'm greatful for any advice regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mai

Re: sendmail mx question

2016-04-05 Thread Markus Rosjat
Hi peter, yeah my server does retries but always ends up on the mailserver with the lower priority :( Am 05.04.2016 um 12:44 schrieb Peter N. M. Hansteen: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 04/05/16 11:55, Markus Rosjat wrote: I have a mail to deliver to a domain that has

OpenBSd 5.9 on Hyper-V

2016-05-11 Thread Markus Rosjat
? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

Re: ftp/www.openbsd.org will be down for an upgrade today.

2016-05-10 Thread Markus Rosjat
HEy, sorry found my mistake :) had some urls referred that seems to be no longer available so I removed them from the config. regards Markus Am 10.05.2016 um 06:36 schrieb Bob Beck: it has been back for quite some time On Mon, May 9, 2016 at 1:02 PM, Markus Rosjat <ros...@ghweb.de>

Re: ftp/www.openbsd.org will be down for an upgrade today.

2016-05-09 Thread Markus Rosjat
of an up2date mirror of 'current.html'? (Google just found one with the latest entries from 2005...) :-( TIA. STEFAN -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax

strange behaviour spamd

2016-07-21 Thread Markus Rosjat
Hi there, I noticed that a trapped ip gets whitelisted when there are still greylisted messages. this shouldn't happen when I use the -a -t switches to trap the ip or do I miss something here ? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR

Re: strange behaviour spamd

2016-07-22 Thread Markus Rosjat
(+0200), Markus Rosjat wrote: :Hi there, : :I noticed that a trapped ip gets whitelisted when there are still greylisted :messages. this shouldn't happen when I use the -a -t switches to trap the ip :or do I miss something here ? : :Regards : :-- :Markus Rosjatfon: +49 351 8107223mail: ros

Testing stability of internet connection for VPn tunnel

2017-01-24 Thread Markus Rosjat
but if there is a better and more reliable way to do this then it wood be most appreciated to hear it :) Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351

Re: Testing stability of internet connection for VPn tunnel

2017-01-24 Thread Markus Rosjat
someone out there has some ideas how to overcome this problem too. Regards Markus Am 24.01.2017 um 10:05 schrieb Markus Rosjat: Hey there, like the topic says I just need to get an idea how to really check if the internet connection can handle the traffic over my vpn tunnel. I was thinking

Re: Migrate Mailserver from sendmail/Curier/LDAP to OpenSMTP/Dovecot/LDAP

2017-01-30 Thread Markus Rosjat
28.01.2017 um 15:05 schrieb Craig Skinner: Hi Markus, On 2017-01-27 Fri 12:24 PM |, Markus Rosjat wrote: I dont like the idea of one single virtual user handling all the traffic to the maildirectories. Me neither. Here, all users have proper shell accounts & SSH access, for mutt, etc.

Migrate Mailserver from sendmail/Curier/LDAP to OpenSMTP/Dovecot/LDAP

2017-01-27 Thread Markus Rosjat
direction it would be much appreciated. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich

Re: Migrate Mailserver from sendmail/Curier/LDAP to OpenSMTP/Dovecot/LDAP

2017-01-27 Thread Markus Rosjat
10:48 schrieb Kim Zeitler: Hi Markus On 01/27/17 09:44, Markus Rosjat wrote: Hi there, so my question is what is the best strategy to migrate an exsiting LDAP directory from a system that has sendmail and courier running to a system with openSMTP and Dovecot. Couple of years ago we changed from

Re: Simple example for httpd fastcgi

2016-11-06 Thread Markus Rosjat
/2016, 20:10, "Markus Rosjat" <owner-m...@openbsd.org on behalf of ros...@ghweb.de> wrote: Hi there, Is there some how-to or examples out there to get a clue how to configure httpd to run python scripts ? Regards Markus Von meinem Samsung GerÀt gesendet. Markus, This mi

Re: Simple example for httpd fastcgi

2016-11-08 Thread Markus Rosjat
[mailto:owner-m...@openbsd.org] On Behalf Of Markus Rosjat Sent: 06 November 2016 13:56 To: misc@openbsd.org Subject: Re: Simple example for httpd fastcgi Hi mark, I saw that befor and did the steps for python like there and I can thest my script by chroot but I cant really figure what to do

Simple example for httpd fastcgi

2016-11-05 Thread Markus Rosjat
Hi there,  Is there some how-to or examples out there to get a clue how to configure httpd to run python scripts ? Regards  Markus Von meinem Samsung Gerät gesendet.

error creating ca cert for iked

2017-03-27 Thread Markus Rosjat
/ikectl.ca/ca-revoke-ssl.cnf' 5307585036640:error:0EFFF068:configuration file routines:CRYPTO_internal:variable has no value:/usr/src/lib/libcrypto/conf/conf_def.c:563:line 27 Im running on current snapshot from 2017-03-25 this also overrides changes made in the cnf files regards -- Markus Rosjat

Re: error creating ca cert for iked

2017-03-27 Thread Markus Rosjat
this issue for me. Cheers, Andrei. On Mon, Mar 27, 2017, at 20:43, Markus Rosjat wrote: hi there, maybe I did it wrong but I got the following error: $ doas ikectl ca ikectl.ca create Generating RSA private key, 2048 bit long modulus +++ +++ e is 65537

Re: UEFI and Hyper-v

2017-03-27 Thread Markus Rosjat
? AFAIK, it is only for Windows for secure boot etc. I think Gen 1 is fine for OpenBSD, you even have the hvn(4) and the hyperv(4) drivers now. Even the latest machines in Azure are Gen 1-based. On Mon, Mar 27, 2017 at 10:07:03AM +0200, Markus Rosjat wrote: like the topic says I look for some

UEFI and Hyper-v

2017-03-27 Thread Markus Rosjat
this 6. Install OpenBSD on another VHDX 7. dettach the first VHDX So the question really is, do I miss a step or is it just not possible at the moment to get it working with Gen 2 VMs? The secure boot feature of the VM is disabled. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros

SG driver header

2017-03-29 Thread Markus Rosjat
Hi there, On a linux system I have the sg diver and sg.h in place to pass a cdb to the ioctl . Is SG3 also present on OpenBSD if not what header do I need on open bsd ? Regards Markus Von meinem Samsung Gerät gesendet.

Re: OpenIKED and Windows 10 Client

2017-04-12 Thread Markus Rosjat
rson wrote: On 2017-04-11, Markus Rosjat <ros...@ghweb.de> wrote: I think the problem is with the windows site because it tells me there is no certificate to be found. I added the certificate to local machine store -> own certificates (at least in the german UI is no personal folder) I

Re: Topics for revised PF and networking tutorial

2017-04-07 Thread Markus Rosjat
er. After enlightenment - chop wood, draw water. Marko Cupać https://www.mimar.rs/ -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitt

OpenIKED and Windows 10 Client

2017-04-11 Thread Markus Rosjat
:500 to 192.168.0.72:500 msgid 0, 325 bytes config_free_proposals: free 0xa3bec71f800 -- end debug output regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb

spamd and outlook.com

2017-04-21 Thread Markus Rosjat
see 30 grey entries from diffent mx that trying to reach the customers mailbox. I'm a little reluctant to whitelist a shitload of ips just to get rid of a 1 or 2 day delay in delivering the message and yes this was the case regards -- Markus Rosjatfon: +49 351 8107223mail: ros

Re: spamd and outlook.com

2017-04-21 Thread Markus Rosjat
).aspx and thats just scary ... Am 21.04.2017 um 11:59 schrieb Peter N. M. Hansteen: On Fri, Apr 21, 2017 at 11:25:14AM +0200, Markus Rosjat wrote: so if you have spamd in place in greylisting mode and you have customers that work with people who use Office365 as a service you will get calls

Re: spamd and outlook.com

2017-04-21 Thread Markus Rosjat
M. Hansteen wrote: >>>> On Fri, Apr 21, 2017 at 11:25:14AM +0200, Markus Rosjat wrote: >>> I use the attached script to fetch the SPF entries recursively, in a >>> plain text format that can be fed into pfctl. >> Have you tried mx3a.certifiedfactory.info ? 

Re: OpenIKED and Windows 10 Client

2017-04-13 Thread Markus Rosjat
necessary to put the full asn1_dn of the server and client certs in the src_id and dst_id lines of the iked config. On Wed, Apr 12, 2017 at 6:45 AM, Stuart Henderson <s...@spacehopper.org> wrote: On 2017-04-12, Markus Rosjat <ros...@ghweb.de> wrote: Am 12.04.2017 um 11:49 schrieb Mar

Re: OpenIKED and Windows 10 Client

2017-04-13 Thread Markus Rosjat
just to be clear I don't need to install the client cert on the openbsd machine? And since this is eating up my time I might switch back to ikev1 and isakmpd. At least there I know I get it done regards markus Am 13.04.2017 um 10:13 schrieb Markus Rosjat: As I stated befor I did all

Re: ipsec ... again

2017-04-20 Thread Markus Rosjat
conf Add the log keyword to your pf rules. Without that it's hard to debug. Also check man ipsec.conf for a full example. if there is no traffic it seems kinda useless trying to log it at that point. I tried tailing the daemon log but it wasn't to helpful either. -- Markus Rosjatfo

Running OpenBSD on Hypervisor

2017-03-08 Thread Markus Rosjat
quot; guys like to share there expericence it would be nice. Im open for every thing so KVM or BHive are points Ive looked at but haven't tried for now. thanks for the input regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrück

Re: Running OpenBSD on Hypervisor

2017-03-08 Thread Markus Rosjat
schrieb Markus Rosjat <ros...@ghweb.de>: Hi there, just like to get opinions or examples of OpenBSd as guest on a hypervisor. I had it running on a VMware Host but since the free version is missing quiet a lot features I was wondering where to look at. I also tried Hyper-V from MS and this look

ipsec ... again

2017-04-18 Thread Markus Rosjat
s basically my other endpoint). with this setup Im not able to connect to a openBSD 6.1 and the logs don't show anything helpfull so the question is where do I need to do the rewriting and is there some example beside the ipsec.conf in /etc/examples ? Regards -- Markus Rosjatfon

Opensmtpd-extras documentation

2017-07-31 Thread Markus Rosjat
Hi there, Is there some documentation on the ldapFilter ? It's kinda frustrating to see a 535 Auth failed even you are sure you got the right credentials.  I have openldap running but without some basic info on how to pass looked  up information  on to smtpd I'm lost here Regards  Markus

Re: Opensmtpd-extras documentation

2017-08-01 Thread Markus Rosjat
ok turns out it's not a LDAP problem at all ... since openSMTPD doesn't authenticate with a plain password at all it will always fail. regards markus Am 31.07.2017 um 17:44 schrieb Markus Rosjat: Hi there, Is there some documentation on the ldapFilter ? It's kinda frustrating

maildrop-postfix question

2017-08-10 Thread Markus Rosjat
: s_connect() failed: No such file or directory /usr/local/bin/maildrop: Temporary authentication failure. regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220

OpenSMTP and OpenLDAP

2017-07-25 Thread Markus Rosjat
-- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print it, think

Re: OpenSMTP and OpenLDAP

2017-07-25 Thread Markus Rosjat
in OpenSMTP at all? And if so, where to find a piece of information how to configure it? regards MArkus Am 25.07.2017 um 10:50 schrieb Markus Rosjat: Hi there, I was just wondering if does two work together at all? I saw examples with ldapd that ships with the OS but not with OpenLDAP. Since I try

Re: OpenSMTP and OpenLDAP

2017-07-25 Thread Markus Rosjat
enSMTP and OpenLDAP Hey, On Tue, Jul 25, 2017 at 10:50:32AM +0200, Markus Rosjat wrote: > I was just wondering if does two work together at all? I saw examples with > ldapd that ships with the OS but not with OpenLDAP. Since I try to get my > user table defined, and the man only has options

Relayd 2 domains on 2 seperate vm

2017-04-26 Thread Markus Rosjat
then relayd? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before

Re: Relayd 2 domains on 2 seperate vm

2017-04-26 Thread Markus Rosjat
t;Host" value "www.mydomain.fr" forward to match request quick header "Host" value "app2-1.mydomain.fr" forward to } relay "proxy" { listen on $ext_addr port 443 tls protocol "httpsproxy" forward with tls to port 443 forward w

OpenLDAP and filesystem permission

2017-04-27 Thread Markus Rosjat
) but is this considerd secure or should I stick with the LDAP+local User approach? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen

Re: torrent downloads

2017-04-27 Thread Markus Rosjat
]. If the reason is a lack of human ressources, I think I can handle it. Regards. [1] : http://openbsd.somedomain.net/ -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220

relayd splice timeout

2017-04-27 Thread Markus Rosjat
relayd in foreground shows a splice timeout. So question is, can I and if so where can I adjust the timeout value. SSH might be a bad example for relayd use but its the easiest starting point thought. Better to discover stuff befor a setup gets more complicated. Regards -- Markus Rosjatfon

Re: relayd splice timeout

2017-04-28 Thread Markus Rosjat
Ursprüngliche Nachricht Von: Hiltjo Posthuma <hil...@codemadness.org> Datum: 28.04.17 11:34 (GMT+01:00) An: Markus Rosjat <ros...@ghweb.de> Cc: misc@openbsd.org Betreff: Re: relayd splice timeout On Thu, Apr 27, 2017 at 07:11:56PM +0200, Markus Rosjat

OpenBSDI 6.1 some Warnings when using OpenLDAP Tools

2017-08-09 Thread Markus Rosjat
program It's a fresh install from the ports so some of the maintainers might like to know that. regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax

  1   2   >