Re: Two minor issues with GNOME (autologin/night light)

2022-05-05 Thread Stuart Henderson
On 2022-05-05, David Demelier wrote: > 2. The autologin feature does not seem to work. Even though enabled in > the GNOME users settings and it has edited the /etc/gdm/custom.conf the > file to add: > > AutomaticLoginEnable=True > AutomaticLogin=markand > > It still goes to the GDM login

Re: relayd blocking by IP

2022-05-04 Thread Stuart Henderson
On 2022-05-04, Marcus MERIGHI wrote: > Hello! > > I need to block http/s traffic, but only for some Host: header values. > I.e. domain "xyz.abc" should be reachable, domain "klm.opq" not, both > behind the same IP. > > This rules out blocking with PF. > > I looked at relayd(8)/relayd.conf(5)

Re: rspamd and pyzor

2022-05-03 Thread Stuart Henderson
On 2022-05-03, kasak wrote: > rspamd manual assume, that we should use this construction: > > ExecStart=/bin/sh -c '/usr/bin/razor-check && /usr/bin/echo -n "spam" || > /usr/bin/echo -n "ham"' > > The razor-check manual confirm this: "razor-check" terminates with exit > value 0 if the signature

Re: mutt-wizard

2022-05-03 Thread Stuart Henderson
On 2022-05-02, ehakanduran wrote: > didn't) but I couldn't figure out a way to fix the second problem. Why > Ctrl-o doesn't work remains a mystery too. Any pointers will be very > much appreciated. See "stty -a", ^O is probably set to 'discard'. Try 'stty discard undef' to disable this and pass

Re: rspamd and pyzor

2022-05-03 Thread Stuart Henderson
On 2022-05-03, Michael Hekeler wrote: > But are you sure that you need it for pyzor?!?!?!? rspamd needs it. It's event-driven so they probably try to avoid blocking as much as possible, and by running it over TCP the load can be distributed between machines more easily. -- Please keep replies

Re: rspamd and pyzor

2022-05-03 Thread Stuart Henderson
On 2022-05-02, kasak wrote: > Hello misc! > > I have some information for rspamd users, and one question. > > As you may know, rspamd not using pyzor by directly calling pyzor binary. > > Instead, they say, you need to create special systemd socket, and call > pyzor through it. > > It is

Re: pkg-readmes missing for gnome and kde?

2022-05-01 Thread Stuart Henderson
On 2022-05-01, Antoine Jacoutot wrote: > On Sun, 2022-05-01 at 20:51 +0300, Mihai Popescu wrote: >> Hello, >> >> I tried to enable gnome or kde after install in an openbsd snapshot for >> amd64. >> Last time (some time ago) I know for sure there were some pkg-readmes >> for both gnome and kde

Re: OpenBSD 7.1 - hangs after userland upgrade on server hardware

2022-05-01 Thread Stuart Henderson
On 2022-05-01, Andrew Lemin wrote: > Hi all, > > I am totally stumped with issues while upgrading/installing 7.1 and I need > some help! > > Server; Supermicro X10SLV-Q (Intel Q87 Express), Xeon E3-1280 v3, 8G RAM, > Mellanox 10G NIC > > This server has been running OpenBSD flawlessly for years.

Re: creating new partition has corrupted the disklabel ("bad super block")

2022-04-30 Thread Stuart Henderson
On 2022-04-30, Nick Holland wrote: > On 4/30/22 5:16 AM, Sylvain Saboua wrote: >> Hello >> >> I have recently got an upgrade for my laptop with a 1TB SSD drive. >> I successfully managed to install a dual boot between archlinux and >> openbsd, both on encrypted partitions. >> >> Everything was

Re: bwfm0 no networking when combined with trunk (Raspberry Pi 4)

2022-04-30 Thread Stuart Henderson
On 2022-04-30, David Demelier wrote: > I have setup a trunk combination on my Pi 4 to aggregate the ethernet > port (bse0) with the wireless port (bwfm0) using the examples in the > documentation: trunk changes the MAC address to that of the first port, and there's a fair chance that changing

Re: Unusable resolution on a widescreen monitor during install

2022-04-27 Thread Stuart Henderson
On 2022-04-27, Nick Holland wrote: > On 4/27/22 9:15 AM, David Demelier wrote: >> >> http://markand.fr/static/openbsd-resolution.jpeg > > * Do a serial install (aren't I funny? As if there is a serial port on a > machine with an HDMI port! But maybe there is...Maybe I should go buy > a lottery

Re: clang 13 space issues with KARL

2022-04-27 Thread Stuart Henderson
On 2022-04-27, Nick Holland wrote: >> What can I do to make KARL reorder_kernel use less memory without buying more >> RAM? I've turned KARL off for now but that's not a real solution and I hate >> it. >> >> Is there no option in the clang 13.0.0 linker to store what it would normally >> store

Re: OpenBSD 7.1 and unbound 1.15.0

2022-04-27 Thread Stuart Henderson
On 2022-04-27, Renaud Allard wrote: > This is a cryptographically signed message in MIME format. > > --ms080604030904040206090102 > Content-Type: text/plain; charset=UTF-8; format=flowed > Content-Transfer-Encoding: 8bit > > > > On 4/26/22 16:25, Renaud Allard wrote: >> >> Hello, >>

Re: OpenBSD and multitasking

2022-04-26 Thread Stuart Henderson
On 2022-04-26, Mike Larkin wrote: > On Tue, Apr 26, 2022 at 02:13:16AM +0300, Mihai Popescu wrote: >> I can bear this since I'm not into large file transfer business. But >> here is another interesting fact: each time my disk is used by some >> file transfer, all the running applications, mostly

Re: Sysctl settings for transmission bittorrent (udp receive buffer size)

2022-04-25 Thread Stuart Henderson
On 2022-04-25, Daniel Schuermann wrote: > I can't get transmission (bittorrent client) to work properly. > > From the logs: > transmission-daemon: UDP Failed to set receive buffer: > requested 4194304, got 41600 > > On Linux I would do: > sysctl net.core.rmem_max=4194304 > I couldn't figure

Re: Should FUSE mounts be considered local?

2022-04-23 Thread Stuart Henderson
On 2022-04-22, Allan Streib wrote: > I had an SMB network share mounted on a directory under my $HOME (via > FUSE using usmb package), and overnight security(8) tried to check it for > setuid/setgid files. That did not go well. I see that I could have set > the SUIDSKIP environment variable but I

Re: kernel fault after 7.1

2022-04-23 Thread Stuart Henderson
On 2022-04-23, kasak wrote: > hello everybody. after upgrading to 7.1 my router started to panic very > often :(( about twice a day. Please report to b...@openbsd.org, with the information from your mail, plus dmesg, and an outline of how the machine is configured (what types of network

Re: 7.1 & nsd - failed writing to tcp: Permission denied

2022-04-23 Thread Stuart Henderson
On 2022-04-22, Laura Smith wrote: > --- Original Message --- > On Friday, April 22nd, 2022 at 18:16, Peter J. Philipp > wrote: > >> So that's weird becuase the 3-way handshake must have completed for nsd to >> reply a query. Meaning there was SYN's and ACK's being exchanged but perhaps

Re: No valid root disk found when upgrading

2022-04-22 Thread Stuart Henderson
On 2022-04-21, Stuart Henderson wrote: >> upgrade# cd /dev; sh MAKEDEV sd0 >> upgrade# mount -t ffs -r /dev/sd0a /mnt >> upgrade# ls /mnt >> .cshrc bsd dev sbin >> .profilebsd.booted etc

Re: No valid root disk found when upgrading

2022-04-21 Thread Stuart Henderson
On 2022-04-21, michal.lyszc...@bofc.pl wrote: > --47wmzg5ty6ypgy6x > Content-Type: text/plain; charset=us-ascii > Content-Disposition: inline > Content-Transfer-Encoding: 7bit > > Hello Stuart, > Thanks for your reply, here is more data > On 2022-04-21 21:43:08, Stuart He

Re: No valid root disk found when upgrading

2022-04-21 Thread Stuart Henderson
On 2022-04-21, michal.lyszc...@bofc.pl wrote: >> 16 partitions: >> #size offset fstype [fsize bsize cpg] >> a: 8400960 1024 4.2BSD 2048 16384 12960 >> b: 67119581 8401984swap >> c:4883971680

Re: Howto do "a detailed cleanup with the aid of the sysclean package"?

2022-04-21 Thread Stuart Henderson
On 2022-04-21, Florian Obser wrote: > On 2022-04-20 21:42 UTC, Stuart Henderson wrote: >> On 2022-04-20, Florian Obser wrote: >>> You will need a carefully curated /etc/sysclean.ignore file. >>> >>> You decided to put maildirs somewhere on the system, syscl

Re: Howto do "a detailed cleanup with the aid of the sysclean package"?

2022-04-20 Thread Stuart Henderson
On 2022-04-20, Florian Obser wrote: > You will need a carefully curated /etc/sysclean.ignore file. > > You decided to put maildirs somewhere on the system, sysclean is not > omniscient, you need to tell it to leave them alone. Same with .git > directories. > I don't recall needing to tell it

Re: Is there a way to build mod_auth_kerb?

2022-04-19 Thread Stuart Henderson
On 2022-04-18, Maksim Rodin wrote: > Hello, > I am trying to build mod_auth_kerb for apache2 on OpenBSD 6.9 > I installed heimdal-libs-7.7.0p0 and downloaded the latest src for > mod_auth_kerb from github > After unpacking and configuring the following way: > ./configure

Re: reordering libraries: fdcresult: overrun

2022-04-19 Thread Stuart Henderson
On 2022-04-19, rtw0 dtw0 wrote: > I would provide more info if I knew how to configure the mail service on > OBSD, which I had never considered useful before when I thought that I > might rely solely on the Handbook and man pages. You just need to get the information onto a computer which _can_

Re: no output from zathura

2022-04-18 Thread Stuart Henderson
I've committed a fix. If you report problems with ports, it would help to include at least: - OpenBSD version and machine arch (it never hurts to include the full dmesg) - Package version - (plus the description of what happens, any console messages etc, like you included here) And preferably

Re: Auto layout for disk partitions - a new user's perspective

2022-04-18 Thread Stuart Henderson
On 2022-04-18, James Mintram wrote: > Hi. I am new to OpenBSD, so these questions come from my first > experience with the system. > > I selected the auto layout option when partitioning my 256GB drive. I have > then found issues while doing the following: > > 1) Cloning src from the github

Re: Nginx + Syslog Question

2022-04-17 Thread Stuart Henderson
On 2022-04-17, David Anthony wrote: > I'm trying to send Nginx access logs to syslog. I've tried examples in > the default nginx configuration file and man page to no avail. Can > anyone help identify why I'm not seeing access logs? It runs in /var/www chroot, and uses its own code to write to

Re: Spamd as a proxy

2022-04-15 Thread Stuart Henderson
On 2022-04-15, alejan...@rogue-research.com wrote: > Hi Mr Hansteen, > > Thanks for the reply, I started my journey with OpenBSD this week and I > decided to buy your book to help me understand its PF system, it's been > very helpful. I've been reading man pages from pf,spamd,opensmtpd and >

Re: time drift in OpenBSD in proxmox (qemu-kvm) guest

2022-04-15 Thread Stuart Henderson
ep it like that if possible :) > On Fri, 15 Apr 2022 at 11:12, Stuart Henderson > wrote: > > > > On 2022-04-14, Stefan Sperling wrote: > > > On Thu, Apr 14, 2022 at 09:26:41PM -, Stuart Henderson wrote: > > >> I have some OpenBSD guests in Proxmox VE 7.1-

Re: time drift in OpenBSD in proxmox (qemu-kvm) guest

2022-04-15 Thread Stuart Henderson
On 2022-04-14, Stefan Sperling wrote: > On Thu, Apr 14, 2022 at 09:26:41PM -0000, Stuart Henderson wrote: >> I have some OpenBSD guests in Proxmox VE 7.1-7 (pve-qemu-kvm_6.1.0) and >> seeing pretty bad clock drift (50 seconds in ~7h uptime). ntpd can't cope >> with it. From

Re: IKEV2 two devices can connect but only one can make traffic

2022-04-15 Thread Stuart Henderson
On 2022-04-12, Łukasz Moskała wrote: > I remember talking with network engineer at one company I used to work at. > We used fortigate firewalls, and I asked why are we using SSLVPN instead of > ipsec-based vpn, as both were supported. > > He said something along the lines of "ipsec does not work

time drift in OpenBSD in proxmox (qemu-kvm) guest

2022-04-14 Thread Stuart Henderson
I have some OpenBSD guests in Proxmox VE 7.1-7 (pve-qemu-kvm_6.1.0) and seeing pretty bad clock drift (50 seconds in ~7h uptime). ntpd can't cope with it. From boot: 2022-04-14T13:58:19.844Z ntpd[26996]: adjusting local clock by 1.745061s 2022-04-14T13:59:24.070Z ntpd[26996]: adjusting local

Re: Request additions to qbittorrent-nox port README

2022-04-14 Thread Stuart Henderson
+cc ports@ & maintainer On 2022/04/14 21:11, u...@mailo.com wrote: > > 127.0.0.1 is probably the best thing to suggest > > for listening to localhost. > The thing is - I need it accessible from another machine over network. > With `localhost` it DOES work over network, > this is how I have used

Re: How do I report a kernel panic occuring on install media?

2022-04-14 Thread Stuart Henderson
On 2022/04/14 12:21, rtw0 dtw0 wrote: > Hi, > > To disable acpi permanently: > # config -ef /bsd > ukc > disable acpi > ukc > quit This is a REALLY BAD IDEA. >From my earlier mail: https://marc.info/?l=openbsd-misc=164983204029245=2 | (Note: acpi drivers are used for various machine

Re: Request additions to qbittorrent-nox port README

2022-04-13 Thread Stuart Henderson
On 2022-04-13, wrote: > I have had 2 issues with `qbittorrent-nox`, both are OpenBSD-specific > and IMHO it would be appropriate if README described them. > http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/net/qbittorrent/qbittorrent-nox/pkg/README?rev=1.3=text/x-cvsweb-markup > > I emailed Elias

Re: How do I report a kernel panic occuring on install media?

2022-04-13 Thread Stuart Henderson
On 2022-04-13, misc.99...@aleeas.com wrote: > > It sounds like you're trying to use the 32bit OpenBSD installer for a >> 64bit cpu. In that case, you would want the AMD64 installer. Even if that is the case, it's not very likely to change the ACPI parsing. > As far as I remember the CPU is only

Re: Question about /etc/resolvd.conf and local resolver

2022-04-13 Thread Stuart Henderson
On 2022-04-13, J Doe wrote: > For people reading this thread ... > > /etc/resolv.conf is the traditional file for configuring the system > resolver(s) while /etc/resolvd.conf is the configuration file for the > resolvd *daemon*, which is also involved in the configuration of the > system

Re: How do I report a kernel panic occuring on install media?

2022-04-13 Thread Stuart Henderson
On 2022-04-13, misc.99...@aleeas.com wrote: > I'm trying to boot OpenBSD 7.0 i386 image (sha256: > 2423307414df1800537063b3cafd9ae788b46711074b7f94d855c8a3de622f51) from a USB > flash drive on HP Mini, Intel Atom N2600 1.60 GHz machine. Before I could > install, unfortunately I'm facing a

Re: IKEV2 two devices can connect but only one can make traffic

2022-04-12 Thread Stuart Henderson
On 2022-04-11, Ettore Tagarelli wrote: > If I use the "dynamic keyword I get this error: "no IP address found for > dynamic" though "config address 192.168.98.1/24" is there. > Using 0.0.0.0/32 instead of 0.0.0.0/0 causes that traffic is not routed > ('cause /32 restrict the only address possible

Re: IKEV2 two devices can connect but only one can make traffic

2022-04-11 Thread Stuart Henderson
On 2022-04-11, Ettore Tagarelli wrote: > Hello, > I've an Openbsd 6.6 machine with IKEV2. I always used it with only one > client connected and it always worked. Trying to connect with two clients > (behind the same NAT) I found out that the connection seems established but > only one client

Re: TLS library problme: tlsv1 alert protocol

2022-04-09 Thread Stuart Henderson
On 2022-04-09, Stephan Mending wrote: > Hi Tom, > > Hm.. I am on the receiving end of this TLS Handshake. > I am running -release on one and -current on another. Problem and error > messages are the same. > > Excerpt of the running postfix main.cf: > > smtpd_tls_mandatory_ciphers = high >

Re: map/mount a directory/partition into memory

2022-04-08 Thread Stuart Henderson
On 2022-04-08, Stuart Henderson wrote: > On 2022-04-08, Stefan Hagen wrote: >> Mihai Popescu wrote (2022-04-08 05:17 CEST): >>> Since my computer is struggling with chromium and I suspect it's the >>> disk access being too slow, I want to map the directory accesse

Re: map/mount a directory/partition into memory

2022-04-08 Thread Stuart Henderson
On 2022-04-08, Mihai Popescu wrote: >> swap /tmp mfs rw,nodev,nosuid,-s=1g 0 0 > > for some reason, xenodm is not displayed and i am not able to login ... Permissions are probably wrong. Try this: - boot single-user - mount -uw / (don't mount other filesystems) - chmod 1777 /tmp - reboot --

Re: map/mount a directory/partition into memory

2022-04-08 Thread Stuart Henderson
On 2022-04-08, Stefan Hagen wrote: > Mihai Popescu wrote (2022-04-08 05:17 CEST): >> Since my computer is struggling with chromium and I suspect it's the >> disk access being too slow, I want to map the directory accessed by >> chromium ( i think it is ~/.cache) into the memory. >> >> Looking in

Re: pf documentation

2022-04-07 Thread Stuart Henderson
On 2022-04-07, Steve Litt wrote: > I need some easy beginner's pf documentation as well as some > intermediate pf documentation. I plan to make an OpenBSD/pf firewall. I > haven't done this in ten years, and imagine pf and the process of > turning OpenBSD into a firewall have changed in that

Re: TLS library problme: tlsv1 alert protocol

2022-04-07 Thread Stuart Henderson
On 2022-04-06, Tom Smyth wrote: > Hi Stephan, > at a guess I would say that there is no overlap between supported TLS > protool versions and ciphers > available on the client vs the server. This message explicitly suggests protocol version rather than cipher > if your system is using a recent

Re: redis fails to start

2022-04-06 Thread Stuart Henderson
On 2022-04-06, rea...@catastrophe.net wrote: > I have redis configured to start with rspamd. The configuration is default > with no changes after the port install. Redis has been failing to start and > doesn't give much information back when running with `--loglevel verbose'. > > I'm able to run

Re: RISC-V board to buy

2022-04-05 Thread Stuart Henderson
On 2022-04-05, Martin wrote: > Hi list, > > Can anybody know where to buy SiFive HiFive Unmatched (preferred) or > Microsemi PolarFire SoC Icicle Kit to run 7.1 on RISC-V architecture? Can't > find it in stock anywhere. Farnell have some of the Microsemi boards.

Re: OpenBSD-7.1beta EM7455 with default ports config detects as umb0 without AT ports

2022-04-05 Thread Stuart Henderson
On 2022-04-05, Martin wrote: > Hi list, > > Just connected EM7455 modem (factory default port configuration with MBIM + > AT port + NMEA port + DM port) to a machine with latest 7.1beta snapshot. > > The modem detected as umb0, but no AT port or NMEA port detected at all. > > How did developers

Re: OpenBSD benchmarks

2022-04-05 Thread Stuart Henderson
On 2022-04-04, Nicolas Goy wrote: > Hello, > > I'd like to make some 10gbit/s benchmarks for an OpenBSD based router. > > I was wondering if there was some "standard" pf ruleset I could use to > have a meaningful metric. It might be useful to have PF disabled, and PF enabled with a simple "pass"

Re: sysupgrade from -stable (was: error rebuilding binaries after 6.9->7.0 sysupgrade)

2022-04-04 Thread Stuart Henderson
On 2022/04/04 20:37, Steve Fairhead wrote: > On 04/04/2022 13:10, owner-m...@openbsd.org wrote: > > sysupgrade only copes with what look like release versions (no version > > suffix, upgrades to release+0.1 with no arguments, or snapshot with -s) > > or snapshots (-current or -beta suffix, by

Re: Internal Logging?

2022-04-04 Thread Stuart Henderson
On 2022-04-04, Eric Thomas wrote: > I'd like to understand more about how OpenBSD logs internal events such as: > > - pkg_add/delete events > - user logins > - X session start/stops > etc. > > Is there "one big log" where all of these types of events are stored? > Or are they logged in specific

Re: How to track system changes?

2022-04-04 Thread Stuart Henderson
On 2022-04-04, Eric Thomas wrote: > I want to have a high degree of confidence in my system's state > (packages that have been added, configs that have changed, permissions > changed, etc). I've read about "read only filesystems" and the > pro's/con's

Re: openbsd, softraid recovery (I have password)

2022-04-04 Thread Stuart Henderson
On 2022-04-03, Nick Holland wrote: > If you are going to find your data, you need to recreate the disklabel > partitions exactly as they were on the encrypted FFS from OpenBSD. > scan_ffs(8) may help. OoenBSD's scan_ffs only supports FFS1, the OS defaults to FFS2.

Re: error rebuilding binaries after 6.9->7.0 sysupgrade

2022-04-03 Thread Stuart Henderson
you want and install manually) Unless you modify sysupgrade you can't get from a "OpenBSD 7.1" kernel to downloading files from the /7.1/ directory. > Dave Raymond > > On 4/3/22, Stuart Henderson wrote: > > On 2022-04-03, Steve Fairhead wrote: > >> On 07/11/2021 10

Re: error rebuilding binaries after 6.9->7.0 sysupgrade

2022-04-03 Thread Stuart Henderson
On 2022-04-03, Steve Fairhead wrote: > On 07/11/2021 10:35, Steve Fairhead wrote: >> >> That's what I'd expect, and I did indeed run sysupgrade without specific >> options. Nonetheless I seem to have wound up with -current when I would >> have expected -stable: >> >> # dmesg | grep OpenBSD >>

Re: How to rebuild the ports tree?

2022-04-01 Thread Stuart Henderson
On 2022-04-01, Eric Thomas wrote: > @Crystal > >> If you want to work with the ports tree, it's _much_ better to set up >> DPB than just running 'make' in the various directories: > > Very cool blog! I def spent some time reading. The dpb method feels > like a litle too advanced for me at

Re: increasing max value of rdomain/rtable

2022-04-01 Thread Stuart Henderson
On 2022-04-01, Valdrin MUJA wrote: > I want to increase the number of rdomain/rtable from 255 to 1024. I will do > this at my own risk. I had a look at the kernel code but couldn't figure out > how to upgrade it. I would be very grateful if you could guide me on this. > Thanks in advance. I'm

Re: How to rebuild the ports tree?

2022-03-31 Thread Stuart Henderson
On 2022-03-31, Eric Thomas wrote: > --c9bb7b05db88e7ee > Content-Type: text/plain; charset="UTF-8" > > I'm stuck. I need to install the UniFi 6.2.26 port, I used the [FAQ to > setup the ports tree](https://www.openbsd.org/faq/ports/ports.html). > This seemed to work just fine.

Re: Multiple wgpeers on single wg(4) interface with same wgaip list

2022-03-31 Thread Stuart Henderson
On 2022-03-31, Matthew Ernisse wrote: > I am trying to setup several tunnels into a single wg(4) endpoint. > The first tunnel worked fine however when I add the second one the wgaip > statement moves to the last wgpeer configured. Is this expected behavior? Yes, you can't use these

Re: issue with move to php8 as default

2022-03-30 Thread Stuart Henderson
On 2022-03-30, ITwrx wrote: >> The php-fpm ports default to using /etc/php-fpm.conf. >> >> If you are running both php74_fpm and php80_fpm together then you must >> change this default for at least one of them and point it at its own >> configuration file e.g. >> >> php74_fpm_flags=-y

Re: issue with move to php8 as default

2022-03-30 Thread Stuart Henderson
You seem to have missed my reply: https://marc.info/?l=openbsd-misc=164855890727816=2 On 2022-03-30, ITwrx wrote: > On Wed, 30 Mar 2022 09:30:39 -0500 > ITwrx wrote: > >> > Hi ITwrx >> > >> > you will need to check your rc.conf.local and update it to start up >> > the php8.0 fpm >> > >> > it

Re: issue with move to php8 as default

2022-03-29 Thread Stuart Henderson
On 2022-03-28, ITwrx wrote: > I'm running php7.4 and php8 at the same time on an OpenBSD 7.0 machine > i'm testing as a web server. I'm pretty sure they were both starting up > fine until yesterday (it's been a while) after i updated with pkg_add -u > and syspatch. Now, php8 fails to start with:

Re: OpenBGPd: fatal in RDE: aspath_get: Cannot allocate memory

2022-03-29 Thread Stuart Henderson
On 2022-03-29, Claudio Jeker wrote: > On Tue, Mar 29, 2022 at 09:53:56AM +0200, Laurent CARON wrote: >> Hi, >> >> I'm happily running several OpenBGPd routers (Openbsd 7.0). >> >> After having applied the folloxing filters (to blackhole traffic from >> certain countries): >> >> include

Re: Question about /etc/resolvd.conf and local resolver

2022-03-27 Thread Stuart Henderson
On 2022-03-27, Peter J. Philipp wrote: > Some fun facts about DNS. A DNS packet can be 0x hex (or 65535 bytes dec) > maximally. This is true for TCP DNS packets which serve an unsigned short > indicator of length before the packet segment. With UDP it's a bit different > a UDP packet can

Re: Unwind in rdomain1 returning NXDOMAIN for local queries

2022-03-26 Thread Stuart Henderson
On 2022-03-26, Florian Obser wrote: > On 2022-03-25 20:07 UTC, Stuart Henderson wrote: >> (I found unwind more trouble than it's worth with rdomains though, >> I killed resolvd and hardcoded a public resolver in resolv.conf >> instead..) > > Do we need something simp

Re: Unwind in rdomain1 returning NXDOMAIN for local queries

2022-03-25 Thread Stuart Henderson
On 2022-03-25, Francisco Gaitan wrote: > On Fri, Mar 25, 2022 at 07:56:16AM -0400, Josh Grosse wrote: >> On Fri, Mar 25, 2022 at 11:41:08AM +0100, Francisco Gaitan wrote: >> > I have setup a WireGuard VPN so I run two instances of unwind, one for >> > rdomain 0 (unwind) and another for rdomain 1

Re: Desktops and laptops status of firewall and FDE

2022-03-25 Thread Stuart Henderson
On 2022-03-25, Mikolaj Kucharski wrote: > On Thu, Mar 24, 2022 at 09:56:24AM +, Mikolaj Kucharski wrote: >> Hi, >> >> Do you guys have an approach, a software to periodically monitor status of >> endpoint machines, laptops, desktops where the requirement is to have >> full disk encryption

Re: nxserver on OpenBSD

2022-03-24 Thread Stuart Henderson
On 2022-03-24, Sandeep Gupta wrote: > Hello, > > I am looking for an nxserver for openBSD. It seems all the well know > solutions -- NoMachine, OpenNX, nxserver. The only one which is actively > worked on is X2GO. Just wanted to confirm if OpenBSD has support for any of > the nxserver solutions

Re: Identifying a network

2022-03-23 Thread Stuart Henderson
On 2022-03-23, Zé Loff wrote: > > Hi all > > I have a laptop in which I use ifstated to determine whether it is "at > home" or whether it is "roaming", and bring up the VPN -- used to be > iked, now its wg -- for unwind and some NFS shares, if it is. > > My question is: how would you detect if

Re: question regarding rc.d multi daemon tool and synmlink

2022-03-23 Thread Stuart Henderson
On 2022-03-23, Sven F. wrote: > Dear reader, > > according to the rc.d man: > > -- > daemon_class is a special read-only variable. It is set to "daemon" > unless there is a login class configured in login.conf(5) with the same > name as the rc.d script itself, in which case it will be set to

Re: ipsec traffic is dropped between two machines

2022-03-22 Thread Stuart Henderson
On 2022-03-22, Philipp Buehler wrote: >> server-east PF rule: >> - >> @58 pass log quick on enc0 all flags S/SA tagged VPN.WEST > > enc(4) is an observer interface and not meant to take pf rules besides > "set skip on enc0" :-) I disagree, that's where I hang my "scrub

Re: rtable - cannot start svc anymore - current

2022-03-19 Thread Stuart Henderson
On 2022-03-18, Stuart Henderson wrote: > The thing most likely to have affected this is > https://marc.info/?t=16435008481=1=2 but it's not expected > that you should have to change anything, and I don't see that > problem here - I just did this to try and replicate : tb@ pointed

Re: rtable - cannot start svc anymore - current

2022-03-18 Thread Stuart Henderson
On 2022-03-18, Mark Patruck wrote: > Hi, > > after updating a first bunch of backup systems to -current today, i have > issues starting services on machines w/ different rdomains. > > $ cat /etc/rc.conf.local > ifstated_flags= > ntpd_flags=NO > ntpd106_rtable=106 > smtpd_flags=NO >

Re: Boise mirror certificate expired : Boise, ID, USA : mirrors.syringanetworks.net

2022-03-18 Thread Stuart Henderson
On 2022-03-18, Stuart Henderson wrote: > I have forwarded this to the listed address for the maintainer of this mirror. Oh, actually...we don't list that as supporting https, precisely because of this.

Re: Boise mirror certificate expired : Boise, ID, USA : mirrors.syringanetworks.net

2022-03-18 Thread Stuart Henderson
I have forwarded this to the listed address for the maintainer of this mirror. On 2022-03-18, Luke Small wrote: > Boise mirror certificate expired : Boise, ID, USA : > mirrors.syringanetworks.net > > mirrors@ didn't quite seem like it was being used. > > -Luke > -- Please keep replies on the

Re: chroot for go webserver with pledge and unveil

2022-03-17 Thread Stuart Henderson
On 2022-03-16, Marc Espie wrote: > On Tue, Mar 15, 2022 at 11:32:19PM +0100, i...@tutanota.com wrote: >> Since Go has support for pledge and unveil, I was thinking about >> "imitating" the setup for httpd. >> >> I basically need to run a Go webserver with access to MariaDB, >> but would like to

Re: Hardware for OpenBSD based access point

2022-03-15 Thread Stuart Henderson
On 2022-03-15, Stuart Longland wrote: > On Mon, 14 Mar 2022 20:16:14 +0100 > Nicolas Goy wrote: > >> I heard that controller based AP "fleet" can mitigate that by >> kicking devices that are on the "wrong" AP. But I am not sure how it >> works in practice as I only read about it and it is not

Re: Hardware for OpenBSD based access point

2022-03-14 Thread Stuart Henderson
On 2022-03-14, Nicolas Goy wrote: > On Mon, Mar 14, 2022 at 01:32:35PM -0000, Stuart Henderson wrote: >> There's no chance of meeting all of these requirements with OpenBSD. >> >> For AP-side 11ac there are some bwfm(4) devices which _might_ do but they >> are not c

Re: Hardware for OpenBSD based access point

2022-03-14 Thread Stuart Henderson
On 2022-03-14, Stefan Sperling wrote: > On Mon, Mar 14, 2022 at 04:58:07AM +0100, Nicolas Goy wrote: >> I actually have an OpenWRT box (LTE SMS gateway, the LTE modem wasn't >> compatible with OpenBSD when I installed it), and yeah, it is very >> decent. I guess that would be a viable

Re: Hardware for OpenBSD based access point

2022-03-14 Thread Stuart Henderson
On 2022-03-14, Nicolas Goy wrote: > Hello, > > I use OpenBSD for all my network gears except wireless access points. > > My current access points are getting old and I'd like to replace them. > > I did a bit of researches and there are quite some boards supported by > OpenBSD, but I cannot find

Re: Latency with run0 interface

2022-03-13 Thread Stuart Henderson
On 2022-03-14, rea...@catastrophe.net wrote: >>>If not, consider hunting down a mini PCIe iwm(4) 7260 card, or an >>>M.2 AX200 iwx(4) card with an adapter from M.2 to mini PCIe. >>>Both would need compatible pigtails and antennas as well. > > So I tried one obtained from here [1] but it sadly

Re: functional difference of isakmpd and iked

2022-03-13 Thread Stuart Henderson
On 2022-03-11, Axel Rau wrote: > > >> Am 09.03.2022 um 11:44 schrieb Axel Rau : >> >> are both able to support the same network topologies with both IPv4 and IPv6? > Seems to be a difficult question. Nobody wants to decode the isakmpd.conf to work out what the existing configuration does :-)

Re: Please put vi in base

2022-03-12 Thread Stuart Henderson
On 2022-03-12, Sven F. wrote: >> > Out of room? What does that even mean? Are you still using floppy disks!? Some of the install images *are* still using these, of course. The install images are there to run the installer. If you need a more complete system for repair purposes, boot from media

Re: Latency with run0 interface

2022-03-12 Thread Stuart Henderson
On 2022-03-12, Stefan Sperling wrote: > On Fri, Mar 11, 2022 at 02:41:05PM -0600, rea...@catastrophe.net wrote: >> >If not, consider hunting down a mini PCIe iwm(4) 7260 card, or an >> >M.2 AX200 iwx(4) card with an adapter from M.2 to mini PCIe. >> >Both would need compatible pigtails and

Re: Installer fails to boot on Raspberry Pi 400

2022-03-10 Thread Stuart Henderson
On 2022/03/10 12:53, tetrahe...@danwin1210.de wrote: > On Wed, Mar 09, 2022 at 01:08:35AM -0000, Stuart Henderson wrote: > > > panic: do_el0_error > > > > This is the error, it is unrelated to the above warning from bwfm. > > > > Try -current if you didn't

Re: Advice for hardening a PHP webserver on OpenBSD

2022-03-10 Thread Stuart Henderson
On 2022-03-10, Tom Smyth wrote: > Hi, > Owasp has some cheat sheets for hardening PHP configurations, > > https://cheatsheetseries.owasp.org/cheatsheets/PHP_Configuration_Cheat_Sheet.html > > you can combine it with httpd which would run the php app and website > inside a chroot jail, > > you can

Re: Installer fails to boot on Raspberry Pi 400

2022-03-08 Thread Stuart Henderson
On 2022-03-08, tetrahe...@danwin1210.de wrote: > Here is the error: > ``` > WARNING: CHECK AND RESET THE DATE! > gpio at bcmgpio0 not configured > bwfm0: failed loadfirmware of file brcmfmac43456-sdio.raspberrypi,400.bin This is a warning that the loadfirmware() call failed, this is expected on

Re: Driver support for Marvell Amethyst (on MikroTik RB5009UG+S+IN)

2022-03-07 Thread Stuart Henderson
On 2022-03-07, Alex Waite wrote: > Hello Everyone, > > I will purchase a new home router soon, and hope to consolidate my ancient > switch into it as well. > > Has anyone here had success running OpenBSD on the MikroTik RB5009UG+S+IN? [1] > > It's ARM8 64-bit, so I expect OpenBSD to install and

Re: disk i/o test

2022-03-06 Thread Stuart Henderson
On 2022-03-06, Alceu Rodrigues de Freitas Junior wrote: > > > Em 05/03/2022 15:29, Janne Johansson escreveu: > >> It can work the other way around also, using free RAM on the >> hypervisor to create >> a larger write cache than the VM itself can have. > > That would improve performance, but at

Re: disk i/o test

2022-03-03 Thread Stuart Henderson
On 2022-03-03, Nick Holland wrote: > You mention "legacy" options in the BIOS, you may be running an old > machine. But also look at softdep and noatime mount options, softdep > is a HUGE performance gain, noatime is a nice little kick with seemingly softdep can help if you are working on

Re: Unable to system upgrade

2022-03-03 Thread Stuart Henderson
On 2022-03-03, Łukasz Moskała wrote: > Hi Jason, > > Please keep responses on mailing list. > > The expired CA cert is in /etc/ssl/cert.pem > > I'll copy this from another thread that was on misc@ a while ago: > https://www.mail-archive.com/misc@openbsd.org/msg181131.html That thread talks about

Re: login.conf daemon datasize limit effects on VMs with 4GB+ RAM

2022-02-25 Thread Stuart Henderson
On 2022-02-25, Robert Nagy wrote: > Maybe we need a default vmd class? What do you guys think? I definitely think it makes sense. Not sure whether it should just go in etc.amd64 or the others too (vmd only exists on amd64 so far, but if it's ever added e.g. to arm64 then adding it in the other

Re: marc.info expired cert.

2022-02-24 Thread Stuart Henderson
On 2022-02-24, harold felton wrote: > following links fail in firefox: > https://marc.info/?l=openbsd-ports=147434362321356=2 > https://marc.info/?l=openbsd-tech=159346071801266=2 > > i can see the cached-version, but a refresh talks about expired-cert... > view-cert shows: Validity > not-before

Re: Updating mrouted in Base

2022-02-23 Thread Stuart Henderson
On 2022/02/23 09:16, Theo de Raadt wrote: > Stuart Henderson wrote: > > > On 2022-02-21, Trace the Route wrote: > > > Is it possible to include a newer version of mrouted in the base > > > installation of OpenBSD? The existing version of mrouted (v3.8) is >

Re: finding a limitation

2022-02-22 Thread Stuart Henderson
On 2022-02-22, Mihai Popescu wrote: >> Is that 260Mbps total maximum, or is that the limit for a single download >> but you can run 2 concurrent transfers and get close to the line speed? > > Total maximum. I tried to run 2 concurrent transfers in the same time, > the speed was shared among them

Re: finding a limitation

2022-02-22 Thread Stuart Henderson
On 2022-02-21, Mihai Popescu wrote: > I am using the computer described by the following dmesg and I am not > able to find where is a limitation. I have an internet connection of > 500 Mbps download. It is handled by a router, and my computer is > connected in the LAN. This link can be fully

Re: SSL write error: certificate verification failed: certificate has expired

2022-02-22 Thread Stuart Henderson
On 2022-02-21, Hugo Villeneuve wrote: > 2. > Connecting to "https://ftp.openbsd.org/pub/OpenBSD/; or > "https://www.openbsd.org/; on older release: > > Both web site INSIST on including the intermediary certificate: > > 2 s:/C=US/O=Internet Security Research Group/CN=ISRG Root X1 >

Re: Updating mrouted in Base

2022-02-22 Thread Stuart Henderson
On 2022-02-21, Trace the Route wrote: > Is it possible to include a newer version of mrouted in the base > installation of OpenBSD? The existing version of mrouted (v3.8) is > obviously quite old and lacks functionality found in newer versions. > > For example, the existing version of mrouted is

<    3   4   5   6   7   8   9   10   11   12   >