OpenBSD 4.2 - Netgear WG511 pcmcia wireless card - not respondiing

2008-02-01 Thread Theodore Wynnychenko
Hello: I recently decided to try OpenBSD. I successfully installed on a Sony Vaio PCG-672R laptop. (Actually, I have successfully installed OpenBSD 3 or 4 times now, and X-windows, and (i think) KDE. Practice makes perfect when I am trying to learn something new.) Anyway, I also have a Netgear

Re: OpenBSD 4.2 - Netgear WG511 pcmcia wireless card - not respondiing

2008-02-04 Thread Theodore Wynnychenko
Hi: Last week I asked about the failure of OpenBSD to work with a wireless pcmcia network card (WG511). I hope the question is not too basic, but, is the misc list the wrong place to ask the question? Does anyone have any advice for me about this? It seems the kernel correctly identifies the card

Re: OpenBSD 4.2 - Netgear WG511 pcmcia wireless card - notrespondiing

2008-02-04 Thread Theodore Wynnychenko
pcmcia wireless card - notrespondiing Did you install the firmware ? cf. http://www.nabble.com/OpenBSD-4.2---Netgear-WG511-pcmcia-wireless-card---not -respondiing-td15232095.html On lun, 2008-02-04 at 15:21 -0600, Theodore Wynnychenko wrote: Hi: Last week I asked about the failure of OpenBSD

FW: OpenBSD 4.2 - Netgear WG511 pcmcia wireless card - notrespondiing

2008-02-04 Thread Theodore Wynnychenko
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Marcus Glocker Sent: Monday, February 04, 2008 11:56 PM Are you sure your CardBus WG511 device is a Taiwanese model as stated in the man page (you will find this information on the back-side of the device)?

How do I setup OpenBSD to login automatically and lauch minicom?

2008-06-22 Thread Theodore Wynnychenko
Hello I am trying to figure out how to modify the boot process to automatically spawn a minicom session. (I know I have many other options for what I am trying to do, but I thaught this would be a good way to learn someghing about OpenBSD.) Basically, I have an old laptop, and (partially as a way

Re: How do I setup OpenBSD to login automatically and lauch minicom?

2008-06-24 Thread Theodore Wynnychenko
Here's a simple example of a script that just displays systat on a terminal that you could run in place of a getty: #!/bin/sh TERM=vt220 /usr/bin/sudo -u nobody /usr/bin/systat vmstat /dev/$1 /dev/$1 If you have problems, look at /var/log/authlog, if you see getty repeating too quickly

PF setup with tun0 as backup external if

2008-11-26 Thread Theodore Wynnychenko
Hello: I am trying to understand what approach I need to take. I have tried searching the lists, and have gone over the PF User's Guide/FAQ/Man pages, but am not sure how to approach this. I am trying to set up a firewall for a home network. The firewall is connected to the outside with a

couldn't map interrupt for fxp / intel PRO/100 VE after upgrade to 4.6 (or 4.5)

2009-10-20 Thread Theodore Wynnychenko
Hello: I am just wondering if anyone has any idea about this. I originally installed 4.4 on a Sony laptop, all was good. With the 4.5 release, the built in nic stopped working. I tried multiple snapshots, and, now, the current 4.6 release. I was wondering if there was anything I could do to make

Re: couldn't map interrupt for fxp / intel PRO/100 VE after upgrade to 4.6 (or 4.5)

2009-10-21 Thread Theodore Wynnychenko
THANK YOU! I disabled acpi at the boot prompt of the currently installed 4.5, and the network card is now recognized. Again, thanks a lot for pointing me in this direction. Bye - ted -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Anathae E.

Re: Hardware versus Software RAID

2009-11-21 Thread Theodore Wynnychenko
From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Marco Peereboom right but with no knowledge whatsoever about its content. On Sat, Nov 21, 2009 at 04:09:55PM -0701, Jeff Ross wrote: In my scenario, in a 1U server with 2 enclosures I do not have a hot spare online but

Re: Hardware versus Software RAID

2009-11-25 Thread Theodore Wynnychenko
On Sat, 21 Nov 2009 21:43:30, Marco Peereboom wrote: When possible use hardware RAID. ... ami is ok but has some issues. - So, since I have hardware RAID, let's stick with it. Now, what if it fails. - On Sat, 21 Nov 2009 22:54:58, Nick Holland wrote: There is more to RAID1 than

How to redirect output from /etc/rc.shutdown

2009-12-01 Thread Theodore Wynnychenko
Hello: I have been unable to discover this answer for myself. If I missed this somewhere, sorry for bothering the list. Anyway, I would like to have the system confirm a shutdown or reboot before actually doing it. I could do something like rename the shutdown/reboot/halt commands, and then

Re: How to redirect output from /etc/rc.shutdown

2009-12-02 Thread Theodore Wynnychenko
(OPPS, I mean to send this to the list last night.) Hello: Thanks. Anyway, I would like to have the system confirm a shutdown or reboot before actually doing it. Why? And who will be allowed to initiate a shutdown that way? Without knowing that, it's hard to suggest a sane approach. I was

PCMCIA serial port not working

2010-01-04 Thread Theodore Wynnychenko
Hello: I want to be able to use a laptop as a serial console from time to time. My current laptop does not have a RS232 serial port, so, I found a PCMCIA card with a serial port. It appears to be recognized fine by the OS on boot (dmesg below). However, when I try to use minicom on that line

OT: Interupted system call/broken pipe with squid squidguard

2010-02-08 Thread Theodore Wynnychenko
Hello: I recently installed squid Version 2.7.STABLE6 and SquidGuard: 1.4 Berkeley DB 4.6.21 on OpenBSD 4.5. At this point, I am still setting things up, so it is not proxying much of anything, except for testing, but I have been getting this error every morning at 7:00AM local time: Feb 3

Problem with dhclient and resolv.conf

2010-08-31 Thread Theodore Wynnychenko
Hello: Using 4.6 (updating to 4.7 is my next project), I have set up two machines at two separate sites to that create an ipsec tunnel between them. Both machines get a dynamic ip address for their internet connection from the ISP (comcast at one end, AT+T at the other). Both machines have the

2 seperate questions: segmentation fault and powerdown issue

2009-04-08 Thread Theodore Wynnychenko
Hello: I hope these questions are not off topic. I have been working with the 4.4 release for the last few months (learning something new keeps brain cells alive). I got an old P2 or P3 (?) up and running as a firewall at home. It appears to be very stable, however, every 1 to 3 weeks or so, I

couldn't map interrupt for fxp / intel PRO/100 VE after upgrade to 4.5

2009-05-04 Thread Theodore Wynnychenko
Hello: I have been working with OpenBSD since 4.4 came out, trying to learn things as I go. I decided to have a go with the upgrade process. So, I booted off the 4.5CD, and followed the steps to upgrade (I did not pay attention to the dmesg as it scrolled by when booting from the 4.5 CD). So, I

Basic question about following current

2014-11-09 Thread Theodore Wynnychenko
Hello I am thinking of taking the plunge and following current. It all seems straightforward. I have looked at the FAQ's and other sources. I understand that it goes like this (simplistically): Get a new snapshot from mirror Sysmerge etc/xetc Cp bsd.rd to / Boot

HTTPD - HTTP-HTTPS redirection?

2015-02-05 Thread Theodore Wynnychenko
Hello Recently, there was a thread entitled Best way forward w.r.t. apache/nginx/httpd? My needs for an http server are pretty low; and I was planning on using the new in-house httpd included in current. The only fancy thing I like is having http requests redirect to https. This is actually

Re: httpd tls - what am i missing?

2015-03-25 Thread Theodore Wynnychenko
Hello again: I am still having no luck with https and the new httpd server. I am sorry if this is something stupid, but I would really appreciate a whack with the clue stick. As I said originally, http connections work fine with openbsd-current, but https connections never connect. I have

Re: httpd tls - what am i missing?

2015-03-25 Thread Theodore Wynnychenko
On Wed, 25 Mar 2015 12:40:11 -0500 I took the server.key and server.crt files to an older machine (actually, the one I am trying to replace) that is running 4.9 (I think) and apache. On Wednesday, March 25, 2015 1:52 PM: Why not see if you can get it working with pound from packages/ports

Re: httpd tls - what am i missing?

2015-03-27 Thread Theodore Wynnychenko
On Thu, 26 Mar 2015 08:30:23 +0100 mxb wrote: Thank you for the suggestion. I was not aware of pound. I?d rather go for relayd. Which is out of the box. No need to install ?yet another port and make sure it is up2date?. httpd is based on relayd code which would reduce the scope of the

Re: httpd tls - what am i missing?

2015-03-27 Thread Theodore Wynnychenko
And, finally: 4. they DO NOT work when loaded by httpd I will be the first to admit that I don't really know much about public key cryptography and how openssl implements things. But, being simple, it seems to me that there are really only two possibilities. Either apache, pound, and

Re: httpd tls - what am i missing?

2015-03-26 Thread Theodore Wynnychenko
Quoting Kevin Chadwick m8il1i...@gmail.com: On Thu, 26 Mar 2015 08:30:23 +0100 mxb wrote: Thank you for the suggestion. I was not aware of pound. I?d rather go for relayd. Which is out of the box. No need to install ?yet another port and make sure it is up2date?. httpd is based on

Re: httpd tls - what am i missing?

2015-03-25 Thread Theodore Wynnychenko
Subject: Re: httpd tls - what am i missing? On 3/25/15, Theodore Wynnychenko t...@uchicago.edu wrote: Is there anything for me to look at/consider in trying to correct this? Thanks Ted Here is a working example from my server. Note that I don't bother with port 80. You might want to try

Re: httpd tls - what am i missing?

2015-03-27 Thread Theodore Wynnychenko
And, finally: 4. they DO NOT work when loaded by httpd I will be the first to admit that I don't really know much about public key cryptography and how openssl implements things. But, being simple, it seems to me that there are really only two possibilities. Either apache, pound, and

httpd tls - what am i missing?

2015-03-23 Thread Theodore Wynnychenko
Hello I think I missing something very obvious, but I have been struggling with this for a while, and hope that someone will point out my oversight. Running current: OpenBSD 5.7-current (RAMDISK_CD) #818: Wed Mar 18 18:59:52 MDT 2015

Re: httpd tls - what am i missing?

2015-05-11 Thread Theodore Wynnychenko
Hello I guess I was a bit remiss in posting a conclusion to the thread I started. Sorry about that. In any case, Joel S (jsing@) and I corresponded about this issue, and I did get a resolution. Here is a copy of the final message: --- From: Joel Sing Sent: Sunday, March 29, 2015 5:13 AM

Mount point for ntfs_3g mounted drive missing after failed umount

2015-06-07 Thread Theodore Wynnychenko
Hello I have been trying to use the ntfs_3g fuse package to get write access to an ntfs drive. While I have had no issues mounting the drive and writing to it, occasionally I have problems when trying to unmount the drive. Basically, I want to make a more portable copy of my data. I have an

httpd stops accepting connections after a few hours on current

2015-07-05 Thread Theodore Wynnychenko
Hello On current: OpenBSD 5.8-beta (GENERIC.MP) #1125: Fri Jul 3 20:54:45 MDT 2015 dera...@amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP System using 2 aliases on one interface: ifconfig em0 em0: flags=8843UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST mtu 1500 lladdr

Ipsec tunnel not starting after update to recent snapshot

2015-11-12 Thread Theodore Wynnychenko
Hello I recently updated to the 11-9 amd64 snapshot. I had started following current, and, in general, seem to be doing fine. But, after this last update, an IPSEC tunnel that I have been using for months/years all of a sudden is not coming up with a system reboot. I have not changed the

Ipsec tunnel not starting after update to recent snapshot

2015-11-10 Thread Theodore Wynnychenko
(( I have been trying to send this message all day - this is my third attempt -- I am sorry if it appears multiple times suddenly, but not sure why it is not posting to the list... )) Hello I recently updated to the 11-9 amd64 snapshot. I had started following current, and, in general, seem to

Re: httpd stops accepting connections after a few hours on current

2015-07-10 Thread Theodore Wynnychenko
-Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Edgar Pettijohn Sent: Friday, July 10, 2015 7:32 PM To: misc@openbsd.org Subject: Re: httpd stops accepting connections after a few hours on current On 07/08/15 22:04, Theodore Wynnychenko wrote

Re: httpd stops accepting connections after a few hours on current

2015-07-08 Thread Theodore Wynnychenko
From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Edgar Pettijohn Sent: Wednesday, July 08, 2015 8:52 PM To: misc@openbsd.org Subject: Re: httpd stops accepting connections after a few hours on current On 07/08/15 12:15, Henrik Friedrichsen wrote: I have encountered the

Error in package courier-imap-4.16.2 current Jan 1 amd64

2016-01-03 Thread Theodore Wynnychenko
Hello I am not sure if this is the correct list, but... I recently installed courier from packages. After installing courier-imap; I tried to start it with "rcctl start courier_imap", and it seemed to hang. So, I tried running /usr/local/libexec/imapd.rc directly, and saw an endless loop of "-".

Samba4 and OpenBSD

2016-01-09 Thread Theodore Wynnychenko
Hello: I am just wondering if anyone has any experience with Samba4 on OpenBSD. I noticed that the package is available, and the included smb.conf file is set up for a standalone server. I have been tinkering with it, and have been able to get 2 separate machines (OpenBSD) set up as AD DC's. I

ypldap.conf help - was: Samba4 and OpenBSD

2016-01-10 Thread Theodore Wynnychenko
Hello again: First, I will try to document what I did to get samba up as an AD DC in the next few days (I will note, as an older mail post stated, it takes a "LONG" time for it to start up when the system boots). But, I am hoping that someone can help me understand where my ypldap problem is. As

Re: ypldap.conf help - was: Samba4 and OpenBSD

2016-01-11 Thread Theodore Wynnychenko
ory update searching password entries searching group entries updates are over, cleaning up trees now flattening trees --- So, at least I seem to be moving forward. Thanks -Original Message- From: Theodore Wynnychenko [mailto:t...@uchicago.edu] Sent: Monday, January 11, 2016 9:21 AM To

Re: ypldap.conf help - was: Samba4 and OpenBSD

2016-01-11 Thread Theodore Wynnychenko
On Mon, Jan 11, 2016 at 9:37 AM, Stuart Henderson <s...@spacehopper.org> wrote: > On 2016-01-11, Theodore Wynnychenko <t...@uchicago.edu> wrote: >> directory "ldap://DC1.samba.domain.com:389; { > > afaik this just takes a hostname, not a URL. Confirmed. And see al

Re: Trying to get squid with ssl bump working

2016-01-29 Thread Theodore Wynnychenko
-Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Stuart Henderson Sent: Friday, January 29, 2016 6:31 PM To: misc@openbsd.org Subject: Re: Trying to get squid with ssl bump working ... I didn't include this line but I believe it's the default

Adding chunk to softraid volume with bioctl - required chunk size

2016-02-28 Thread Theodore Wynnychenko
Hello I have a question about RAID 1 volumes set up with bioctl. When I originally set up the softraid, I created a RAID partition that (essentially) took up the entire drive. However, the disklabel INSIDE the softraid does NOT use the all the space available (e.g. The chunks making up the

Does a softraid partition require an fdisk partition

2016-03-11 Thread Theodore Wynnychenko
Hello I recently changed disks in an openbsd system. Everything went smoothly, as expected. I dumped the old filesystems; installed the new disks; created "fdisk partitions" on the physical drives; made "disklabel partitions" on the physical drives; setup a softraid0; created the "disklabel

netsnmpd Fails to Start on Current

2016-10-04 Thread Theodore Wynnychenko
Hello I updated to the Oct 2 AMD64 snapshot yesterday. I then updated to the Oct 3 AMD64 snapshot today. After updating to the Oct 2 snapshot, I noticed that netsnmpd (from packages) was "failed" on reboot. I updated all the packages (pkg_add -vui), but had a failure ("bad minor" or something

Re: netsnmpd Fails to Start on Current [Solved]

2016-10-08 Thread Theodore Wynnychenko
On 2016-10-04, Theodore Wynnychenko <t...@uchicago.edu> wrote: > # /usr/local/sbin/snmpd -L e > kvm_openfiles: Operation not permitted > kvm_openfiles: /dev/mem: Operation not permitted On 2016-10-06, Stuart Henderson wrote: > Kernel virtual memory access is no longer permi

Using isc-dhcp-client as alternate dhclient

2016-09-20 Thread Theodore Wynnychenko
Hello I would like to get the isc-dhcp-client working as a replacement for the base dhclient. The primary reason for this is so that I can assign an alias to the interface. But, I can't seem to figure out how to get this done. I have two issues. First, I can't get the isc-dhcp-client to assign

Re: Unable to establish ikev2 vpn with ios using current - OpenBSD 6.1 GENERIC.MP#106 amd64 - can anyone help?

2017-06-07 Thread Theodore Wynnychenko
a problem with the current iked, I would really appreciate it. Thank you Ted -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Theodore Wynnychenko Sent: Monday, June 05, 2017 7:16 PM To: misc@openbsd.org Subject: Re: Unable to establish ikev2 vpn with

Unable to estable ikev2 vpn with ios after update to current

2017-06-04 Thread Theodore Wynnychenko
Hello I have been a bit remiss, and have not updated my system in a couple of months. I have been following current for a year or two, in general, without incident. Anyway, after updating last night, I am unable to establish a ikev2 vpn with an ios 10.3.2 device. A OBSD6.1<->OBSD6.1 ikev2 vpn

Re: Unable to establish ikev2 vpn with ios after update to current - OpenBSD 6.1 GENERIC.MP#103 amd64

2017-06-05 Thread Theodore Wynnychenko
have changed? I see nothing obvious that I need to change in the iked.conf based on the my reading of the current manpage. Thank you Ted -Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Theodore Wynnychenko Sent: Sunday, June 04, 2017 8:1

reordering libraries:/etc/rc[443]: ./test-ld.so: Permission denied

2017-09-25 Thread Theodore Wynnychenko
Hello I noticed this message in the dmesg after updating -current yesterday. I am not sure what it means. There is no file "test-ld.so" anywhere on the system that I can find. I also see that it appears this part of rc was just committed in the last few weeks. Why is this happening, and is

Re: apache2 cgi script stopped working with -current about April 2017

2017-09-25 Thread Theodore Wynnychenko
-Original Message- From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf Of Stuart Henderson Sent: Sunday, September 24, 2017 2:43 PM To: misc@openbsd.org Subject: Re: apache2 cgi script stopped working with -current about April 2017 On 2017-09-24, Theodore Wynnychenko &l

apache2 cgi script stopped working with -current about April 2017

2017-09-24 Thread Theodore Wynnychenko
Hello I have delayed asking for help hoping that I would figure this out on my own. But, after several months, of on-and-off attempts, I can't think of anything else, so... I have been following current for some time, now: OpenBSD 6.2 GENERIC.MP#105 amd64 I also continue to use apache2 in

Re: reordering libraries:/etc/rc[443]: ./test-ld.so: Permission denied

2017-09-27 Thread Theodore Wynnychenko
On Sep 25, 2017, at 9:31 PM, Philip Guenther <guent...@gmail.com> wrote: On Mon, 25 Sep 2017, Theodore Wynnychenko wrote: I noticed this message in the dmesg after updating -current yesterday. I am not sure what it means. There is no file "test-ld.so" anywhere on the s

Re: fw_update signify unsigned package on current and 6.2-stable -SOLVED

2017-11-01 Thread Theodore Wynnychenko
-Original Message- From: Theodore Wynnychenko Sent: Wednesday, November 01, 2017 8:43 AM To: misc@openbsd.org Subject: fw_update signify unsigned package on current and 6.2-stable Hello: How do I install the iwm-firmware without a network connection on either 6.2-stable

fw_update signify unsigned package on current and 6.2-stable

2017-11-01 Thread Theodore Wynnychenko
Hello: A couple of month ago, I decided to take the plunge and setup an openbsd laptop. I bought a relatively newer ThinkPad, and (a couple of months ago) set it up and started playing with the desktop environment. Well, life happened, and I put it aside for a while. Yesterday, I decided to

Is anyone able to use certificates with openbsd iked/ikev2 and Apple iOS (iphone)?

2018-06-02 Thread Theodore Wynnychenko
Hello Last year (before about 3/27/2017 when "Add support for RFC4754 (ECDSA) and RFC7427 authentication" diff was committed to current), I had set up and had been able to connect iOS devices (iphone/ipad) to OpenBSD's iked, and have ikev2 VPN's happen, almost as if by, magic. Authentication was

bioctl "intermitently" reports RAID 1 array as degraded

2018-04-14 Thread Theodore Wynnychenko
Hello I am trying to understand what I may be missing (I have been noticing this issue for a year or so). I have a machine running -current that is setup with 2 SSD hard drives. The SSD's are fdisk'ed with 1 openbsd partition: # fdisk sd0 Disk: sd0 geometry: 19457/255/63 [312581808

Change to init in -current?

2018-11-10 Thread Theodore Wynnychenko
Hello I just updated to -current. It had been about 2-3 months since I last updated. I have been doing so since (about) 5.9 or so. Anyway, way back then, I wanted to be able to login on a local serial terminal without entering a password (yes, I know that there may be disagreement about the

Re: Change to init in -current?

2018-11-12 Thread Theodore Wynnychenko
-Original Message- From: Theo de Raadt [mailto:dera...@openbsd.org] Sent: Saturday, November 10, 2018 7:57 PM To: t...@uchicago.edu Cc: misc@openbsd.org Subject: Re: Change to init in -current? Theodore Wynnychenko wrote: > So, to do this, I edited the appropriate terminal line in /

Re: TLS suddenly not working over IKED site-to-site

2018-12-15 Thread Theodore Wynnychenko
Hello again: I updated my iked endpoints to the most recent (12/14/18) amd64 snapshot today, and am still having problems with secure connections. So, today, I am just looking at the gateway machines. The iked vpn tunnel gets established without an issue. # ipsecctl -s all FLOWS: flow

Re: TLS suddenly not working over IKED site-to-site - SOLVED?

2018-12-20 Thread Theodore Wynnychenko
> -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf > Of William Ahern > Sent: Monday, December 17, 2018 1:11 PM > To: Theodore Wynnychenko > Cc: misc@openbsd.org > Subject: Re: TLS suddenly not working o

Re: TLS suddenly not working over IKED site-to-site

2018-12-10 Thread Theodore Wynnychenko
I would like to re-title this as something like "pf and iked instability on recent snapshots," but don’t know if doing so would break the mailing list thread, exiso, I left the subject unchanged... > -Original Message----- > From: Theodore Wynnychenko [mailto:t...@uchic

Re: Untable ssl connections over ikev2 VPN

2018-11-29 Thread Theodore Wynnychenko
> -Original Message- > Hello > > I have been having trouble getting an openBSD laptop to connect to ssl > connections when communicating over ikev2. > > In general terms (since I don't know exactly what specifics would be > important), this is what I observe: > > 1. OpenBSD

Re: TLS suddenly not working over IKED site-to-site

2018-12-03 Thread Theodore Wynnychenko
> -Original Message- > From: owner-m...@openbsd.org [mailto:owner-m...@openbsd.org] On Behalf > Of Rachel Roch > Sent: Monday, December 03, 2018 11:19 AM > To: misc@openbsd.org > Subject: TLS suddenly not working over IKED site-to-site > > I hope someone here can shed light on an

Re: Courier Imap not accepting connections after updat to -curent

2018-11-29 Thread Theodore Wynnychenko
dat to - > curent > > On 11/18/18 10:35 PM, Theodore Wynnychenko wrote: > > Hello > > > > I just updated to -current using a snapshot. > > > > I then updated packages (pkg_add -vui), which updated courier-imap. > > > > pkg_info | grep cou

Untable ssl connections over ikev2 VPN

2018-11-29 Thread Theodore Wynnychenko
Hello I have been having trouble getting an openBSD laptop to connect to ssl connections when communicating over ikev2. In general terms (since I don't know exactly what specifics would be important), this is what I observe: 1. OpenBSD laptop has no issues connecting to imaps or https on a

Re: TLS suddenly not working over IKED site-to-site

2018-12-08 Thread Theodore Wynnychenko
> > > Rachel, > > > > As a first step, try using s_client to connect to a TLS service and > see what comes back: > > > > $ openssl s_client -connect : -showcerts > > > > There are more possible options on s_client to debug more deeply but > this is a good start. > > > > > > --Paul > >

IKED fails to establish VPN on last 2 amd64 snapshots

2018-12-04 Thread Theodore Wynnychenko
Hello I am sorry, but I don't have access to any specific output right at this moment. However, there appears to be something odd happening with iked. Last week I noticed that ssl connections, when attempted through an iked vpn tunnel, appeared to hang, when those same connections made

Courier imap not accepting connections after update to -curent

2018-11-19 Thread Theodore Wynnychenko
Hello I just updated to -current using a snapshot. I then updated packages (pkg_add -vui), which updated courier-imap. pkg_info | grep courier courier-authlib-0.68.0p4 authentication library for courier courier-authlib-mysql-0.68.0p3 mysql authentication module for courier-authLib

Re: Adding an additional IP on a NIC getting DHCP address

2019-03-22 Thread Theodore Wynnychenko
Hello This is the first time I am responding to a post that is not my mine. I hope it is not too uninformed. Anyway, back in about October, 2016, I noticed that the included dhcp client would no longer assign an alias address alongside the address from the dhcp lease. Before about this

Re: Following current - pkg_add update forward depedencies don't match question

2019-11-02 Thread Theodore Wynnychenko
don't match question > > On 2019-11-01, Theodore Wynnychenko wrote: > > Hello > > > > I just updated a system to current the other day. > > > > OpenBSD 6.6 GENERIC.MP#411 amd64 > > > > The last time I updated was probably 2-3 months ago. > &

Courier-Imap no longer accepts ssl connections after update to -current

2019-11-02 Thread Theodore Wynnychenko
Hi (again): After updating to current yesterday, and then updating all the packages (using "pkg_add -vui -Dsnap"), I can no longer connect to the ssl (993) port of the courier-imap server running on the system. Prior to the update, ssl connections were working without an issue. Now, when

Re: Following current - pkg_add update forward depedencies don't match question

2019-11-03 Thread Theodore Wynnychenko
don't match question > > On 2019-11-02, Theodore Wynnychenko wrote: > > I decided to just try updating gettext, so (this is the full output > on that > > system): > > Well, that's the problem. Partial updates work sometimes but they can't > be relied upon, in particul

Re: Courier-Imap no longer accepts ssl connections after update to -current

2019-11-03 Thread Theodore Wynnychenko
ts ssl connections after > update to -current > > Theodore Wynnychenko wrote: > > Hi (again): > > > > After updating to current yesterday, and then updating all the > packages > > (using "pkg_add -vui -Dsnap"), I can no longer connect to the ssl &g

Following current - pkg_add update forward depedencies don't match question

2019-10-31 Thread Theodore Wynnychenko
Hello I just updated a system to current the other day. OpenBSD 6.6 GENERIC.MP#411 amd64 The last time I updated was probably 2-3 months ago. Anyway, when I went to updated packages (also following current/snapshots), I got a number of "forward dependencies - don't match" notices and the

Guidance: How often to update -current?

2020-03-21 Thread Theodore Wynnychenko
Hello I have been following -current since (about) 5.6. At first, I was pretty good. Probably no more than about 1 month between updates. But, life gets in the way... Recently, I had a prolonged (probably >4-6 month) period where I did not update, although I have recovered. Since then, I have

Icinga2 endpoints unable to connect to master after update to current package 2.12.1-1

2020-11-23 Thread Theodore Wynnychenko
Hello The other day I updated to current (6.8 GENERIC.MP#188). I then updated packages. I have been using Icinga2 since about OpenBSD 5.6, and everything was fine. A few hours after the update, I got a warning that my /var/log filesystem on the icinga2 master was full. Then, I noticed

openssl cms -encrypt does not work with EC key/cert

2021-05-06 Thread Theodore Wynnychenko
Hi I posted this to the openssl user list the other day, but now think that was the wrong place, since it is libressl on openbsd, right? So, let me ask here: Hello I recently decided to change from RSA to EC keys/certs. I do this primarily as a learning exercise (there is no real corporate or

Re: openssl cms -encrypt does not work with EC key/cert

2021-05-08 Thread Theodore Wynnychenko
Hello again: I am re-posting this message with additional information.. While I have no expectation that there will be any reply, I am hopeful there may be. In any case, I have been struggling with this, and cannot get it to work with EC certificates. I am now wondering if this is a bug or a,

iked in -current with Apple iOS 14

2021-04-01 Thread Theodore Wynnychenko
Hello After avoiding this for a couple of years, I just spent a lot of time figuring out how to get iked in -current to play with Apple iOS 14 (most recent version). I had been limping along by replacing iked in current with an older version, but Apple has made iOS ikev2 more and more

How I got iked in -current to work with iOS

2021-04-02 Thread Theodore Wynnychenko
Hi I had some time today, and decided to send this now. This is how I got OpenBSD's iked daemon (version in current about 3/28/2021) to work with Apple's iOS (iphone/ipad's) version (about) 14.4.2. Some prelude: So, I have no real reason to do this, other than that I want to. I think of it as a

Re: How I got iked in -current to work with iOS

2021-04-04 Thread Theodore Wynnychenko
Hello - I have added a small bit of additional information at the end. -Original Message- From: Theodore Wynnychenko [mailto:t...@uchicago.edu] Sent: Friday, April 02, 2021 1:46 PM To: misc@openbsd.org Subject: How I got iked in -current to work with iOS Hi I had some time today

Re: How I got iked in -current to work with iOS

2021-04-04 Thread Theodore Wynnychenko
Hello - I have added a small bit of additional information at the end. -Original Message- From: Theodore Wynnychenko Sent: Friday, April 02, 2021 1:46 PM To: misc@openbsd.org Subject: How I got iked in -current to work with iOS Hi I had some time today, and decided to send this now