R: smtpd: access.db?

2023-06-13 Thread Francesco Toscan
Il giorno lunedì 12 giugno 2023 22:41 Steve Fairhead ha scritto: > I'm in newbie mode again. I'm working on replacing an old OpenBSD server > running Sendmail with a new one running smtpd. With Sendmail, I rely > heavily on the access.db feature to block TLDs, usernames, email > addresses, and

Re: Overwriting softraid keys

2023-05-25 Thread Francesco Toscan
On Thu, May 25, 2023 at 09:35AM Stefan Sperling wrote: > On Wed, May 24, 2023 at 04:37:00PM +0000, Francesco Toscan wrote: > Hi misc@, > >> I'm going to migrate a FreeBSD ZFS-based fileserver to a OpenBSD 7.3 >> UFS-based one. >> In order to comply with reg

Overwriting softraid keys

2023-05-24 Thread Francesco Toscan
Hi misc@, I'm going to migrate a FreeBSD ZFS-based fileserver to a OpenBSD 7.3 UFS-based one. In order to comply with regulations, part of data must be encrypted; regulations also dictate that I have to be able to destroy the encryption keys. So, I want to split data into multiple partitions,

bwi(4) issues

2014-05-18 Thread Francesco Toscan
Hi misc@, I'm running 5.5-current from May 12 build (dmesg attached). I noticed a regression in bwi(4) network device driver. I knew it worked fine somewhere between 5.4-current built on January and 5.5-release, unfortunately I haven't enough informations to narrow the timeframe. BTW, here are

Re: bwi(4) issues

2014-05-18 Thread Francesco Toscan
On Sun, May 18, 2014 at 01:08:00PM +0200, Stefan Sperling wrote: On Sun, May 18, 2014 at 12:52:53PM +0200, Francesco Toscan wrote: Hi misc@, Network with bwi has become *slow*, slow as unusable. Every kind of traffic is somehow slowed. Transmissions work but they take forever

Re: bwi(4) issues

2014-05-18 Thread Francesco Toscan
On Sun, May 18, 2014 at 02:33:15PM +0200, Francesco Toscan wrote: The CAVEATS section of the man page seems to describe your issue. Perhaps it's a hardware problem? Does it work again if you downgrade to 5.5-release? I'll boot 5.5-release and report what's happening. Here's the followup

Content filtering in smtpd(8)

2014-02-26 Thread Francesco Toscan
Hi, looking at GSOC2014 OpenBSD Foundation's idea list, I found a reference to some Perl and Python bindings to smtpd's own content filtering framework. Is this content filtering api documented anywhere? I found no mention in smtpd.conf(5) or smtpd(8) man pages. I'd like to know whether this

Re: Content filtering in smtpd(8)

2014-02-26 Thread Francesco Toscan
Hi Gilles, On Wed, Feb 26, 2014 at 11:37:47AM +0100, Gilles Chehade wrote: On Wed, Feb 26, 2014 at 11:16:40AM +0100, Francesco Toscan wrote: Is this content filtering api documented anywhere? I found no mention in smtpd.conf(5) or smtpd(8) man pages. nope because we're still stabilizing

Re: ntp and pppoe

2007-11-18 Thread Francesco Toscan
Il giorno 17/nov/07, alle 20:02, Henning Brauer ha scritto: * Francesco Toscan [EMAIL PROTECTED] [2007-11-17 19:22]: I use ifstated to detect link changes and restart ntpd. bad idea. loses all state. just give it a little slack, it copes. Have still to try on 4.2, but on 4.0 I ended up

Re: ntp and pppoe

2007-11-17 Thread Francesco Toscan
Il giorno 17/nov/07, alle 16:59, Christoph Leser ha scritto: I use the pppoe0 device to connect to my isp. And I use ntpd. ntpd seems not to be aware of the changing ip address of the interface. It keeps sending messages with the source address it saw on startup, as can be seen for netstat

Re: RAIDFrame inconsistancy and server will not boot!

2007-10-26 Thread Francesco Toscan
2007/10/26, Jake Conk [EMAIL PROTECTED]: Hello, I was trying to restart my server and noticed it wasn't coming back online so when I went down to go take a look at it I was having a RAID problem. This is what was showing on the screen: ... PARTIALLY TRUNCATED INODE I=720 THE FOLLOWING

Re: RAIDFrame inconsistancy and server will not boot!

2007-10-26 Thread Francesco Toscan
On 10/26/07, Jake Conk [EMAIL PROTECTED] wrote: If the filesystem is screwed up then shouldn't the raid just ignore it and run on 1 disk until I fix the problem? That seems like the logical thing it should do unless all my mirrors of /var are messed up. No, raid doesn't do that. Let's assume

Re: Can't read authpf rules with pfctl

2007-10-22 Thread Francesco Toscan
2007/10/22, Jeff Simmons [EMAIL PROTECTED]: [...] firewall:~#pfctl -a '*' -sr anchor * all { pfctl: DIOCGETRULES: Invalid argument } Am I misreading the man page in assuming that both of these commands should return the block line that the authme login set up, or is something else going

Re: Squid/authpf with lookups on Active Directory

2007-10-19 Thread Francesco Toscan
Il giorno 19/ott/07, alle 17:03, Ari Constancio ha scritto: How can I authenticate users from AD to get through pf? I'm unsure I've correclty understood your request. If you mean How can I make my authpf users authenticate against AD then use login_ldap from ports (you probably have to do

Re: hardening BSD (was systrace/stsh policies)

2007-10-15 Thread Francesco Toscan
2007/10/14, Aaron [EMAIL PROTECTED]: I guess with all the hoopla about 'hardening'/trusted this and that/fuzzy knobs(i.e. SE Linux) i got a little overzealous looking for As others have already pointed out these knobs might not be useful to your setup and your needs. Think also that more

Debugging ral

2007-09-25 Thread Francesco Toscan
I'd like to thank in public Damien Bergamini, he helped me a lot in debugging my ral setup: it was very very slow and unreliable. With Damien's tips now I have a better understanding of my ral device and, above all, it works flawlessy. I wrote a small doc reporting this experience and

Re: Debugging ral

2007-09-25 Thread Francesco Toscan
A few lines above I wrote supported channel: i meant supported by your clients. Yes, this should be corrected, thank you. I don't know if some device supports those high channels: another ral adapter I tested does, my laptop doesn't. For example my iBook supports channels from 1 to 11 (don't

Re: pfctl explaination

2007-06-21 Thread Francesco Toscan
2007/6/20, Ted Unangst [EMAIL PROTECTED]: yes, reloading the rules makes another copy then switches over. if you have a really large table, this means having two copies of the table during the transition. Thank you for your answer. I've just tried to set table-entries to 550K, more than

Re: pfctl explaination

2007-06-21 Thread Francesco Toscan
2007/6/21, Peter N. M. Hansteen [EMAIL PROTECTED]: You may be hitting one or more of the several relevant limits, but have you tried something like 'pfctl -T flush -t tablename' before reloading the table data? Yes, if I first flush the table it works flawlessy. The 'problem' occurs only

pfctl explaination

2007-06-20 Thread Francesco Toscan
Hi misc@, I'm trying to understand how pfctl re-loads rules and tables. On my soekris board, 64MB RAM, I have a large table with more than 200K entries. It's used to perform some egress filtering (yes maybe it's too large but it's really effective). I raised up table-entries limit to 250K and I