Re: pf anchors attached to irrelevant states

2024-05-19 Thread Markus Wernig
On 5/19/24 13:37, Stuart Henderson wrote: I can confirm this is a problem, definitely seen in 7.4, I can't remember if 7.3 was affected. 7.2 from Dec 22 seems ok. Yes, 7.3 is affected. It is the same problem reported here: https://marc.info/?l=openbsd-misc=168754952806369

Re: lcamtuf on the recent xz debacle

2024-04-04 Thread Markus Wernig
On 4/4/24 23:17, Katherine Mcmillan wrote: an open source data compression utility available on almost all installations of Linux and other Unix-like operating systems." There are a couple of problems with this statement, but I just want to focus in on the "almost all installations of Linux

Re: Bridging firewall with online update/upgrade

2024-04-03 Thread Markus Wernig
On 4/3/24 18:19, Karel Lucas wrote: I want to use ETH1 for the input from my ADSL modem, ETH2 and ETH3 for the output to my network. Furthermore, I would like to use ETH4 for the update/upgrade of the firewall. Remove the connection from ETH1, plug it into ETH4, and update/upgrade. Then the

Re: can't find PID

2024-03-05 Thread Markus Wernig
I have asked myself the same question. When runninng tcpdump -n -i pflog0 with the -e -v flags (and only in that combination), it outputs tuples that looks like they should be a uid and pid: 16:40:47.110033 rule 2/(match) [uid 0, pid 92257] block in on trunk0: ... (it's 92257 on the machine

Re: Open-source security processor

2023-09-07 Thread Markus Wernig
On 9/8/23 00:24, Richard Thornton wrote: Say you had the guts of an x86_64 desktop running Windows on the bench and another computer running OpenBSD right next to it, is there some mechanism available that could allow you to integrity scan the NVMe drive (and also the firmware but that's

Re: volatility or something like that in the future ?

2023-08-19 Thread Markus Rosjat
... have you tried switching it off and on again ? Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227

Re: Allwinner D1 riscv64 mango pi SBC

2023-07-20 Thread Markus Rosjat
Hi Peter, I got a VisionFive2 SBC laying arround, so if this is of interest for the devs too I can ship it somewhere. cheers Markus Am 20.07.2023 um 10:32 schrieb Peter J. Philipp: Hi all, Just so we don't lose the warm fuzzy feelings around this.  Diana do you want to give me your

Re: IP6 redirects through relayd no longer working reliably

2023-06-28 Thread Markus Wernig
Just for the record: The problem was caused by a malfunctioning upstream gateway, which did no longer respond properly to neighbor solicitation requests. The SYN ACK from the server was dropped because the firewall had already removed the state created by the SYN. On 6/23/23 22:51, Markus

IP6 redirects through relayd no longer working reliably

2023-06-23 Thread Markus Wernig
hosts) 6 hostServer.B.IP6 100.00% up Now I'm out of ideas on how to debug this further. Has anyone been experiencing something similar? Has something fundamental changed in relayd or pf that could cause this? Does anybody spot an error in my configuration? Thanks for any pointer! Best regards Markus

All packets logged with relayd/* anchor rule number

2023-06-23 Thread Markus Wernig
uite sure this was different in earlier releases. Thank you in advance Markus

Re: carp status master on both firewalls

2023-04-14 Thread Markus Wernig
for my external carp interface both firewalls show master as status The config is below for reference: /etc/hostname.carp0 on fw1 inet x.x.x.114 255.255.255.240 x.x.x.127 vhid 40 carpdev em2 pass password advskew 1 inet alias x.x.x.115 0xfff0 inet alias x.x.x.116 0xfff0

Re: Compatible

2023-02-23 Thread Markus Rosjat
Cheers -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

Re: redirection puzzle

2022-12-02 Thread Markus Wernig
On 12/2/22 16:17, rsyk...@disroot.org wrote: echo 1 | tee $(tty) | sed 's/1/2/' Not 100% sure, but probably some timing/subshell issue. This works: tty=$(tty) && echo 1 | tee $tty | sed 's/1/2/' best /m

Re: Ipsec + bridge + egre issue with multiple bridges an non-static ip

2022-11-26 Thread Markus Wipp
Hi all, Sorry for the noise. I found out that it was pf. When I tested with pf disabled I always only did this with pf disabled on one side. Once I disabled on both sides it worked. So I need to figure out now, what exactly is the issue. Thanks Markus > On 26. Nov 2022, at 11:19, Markus W

Ipsec + bridge + egre issue with multiple bridges an non-static ip

2022-11-26 Thread Markus Wipp
2: arp who-has 192.168.80.1 tell 192.168.80.2 (ttl 64, id 46024, len 70) (ttl 54, id 49233, len 90) Many thanks for any hints that could help me make this work! Bedst rewards Markus signature.asc Description: Message signed with OpenPGP

Re: calling all PFsync users for experience, gotchas, feedback, tips and tricks

2022-05-11 Thread Markus Wernig
my PF firewalls in a trusted environment, where I also control the switches (no shared cloud etc. infrastructure), I have found that running pfsync over a dedicated VLAN interface on a pair of trunk(4)ed NICs on 2 trusted switches sufficiently satisfies that requirement. Best, Markus

Re: OpenBSD on WatchGuard devices

2022-03-13 Thread Markus Rosjat
- Installing openBSD on a notebook with a SSD HDD - setting tty to com0 in /etc/boot.conf After pluging in the HDD in the XTM5 it booted like a charm. Thanks again you wonderful helpful people :) Cheers -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla

Re: OpenBSD on WatchGuard devices

2022-03-11 Thread Markus Rosjat
here: https://www.reddit.com/r/PFSENSE/comments/rce3i6/howto_pfsense_252_on_watchguard_xtm_5/ I saw that already but the steps he took doesnt seem to work for me so far. Let us know how it goes. -- Łukasz Moskała Cheers -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H W

Re: OpenBSD on WatchGuard devices

2022-03-09 Thread Markus Rosjat
amd64 and you can very cheaply upgrade the CPU and add up to 8Gb RAM. On 10/03/2022, at 00:01, Markus Rosjat wrote: Hi list, has someone out there ever attemted to reuse WatchGuard devices? If so can he point out some hints on how to go about it? We have a few devices laying around here and

OpenBSD on WatchGuard devices

2022-03-09 Thread Markus Rosjat
Hi list, has someone out there ever attemted to reuse  WatchGuard devices? If so can he point out some hints on how to go about it? We have a few devices laying around here and i dont see the point in not trying to reuse them. Cheers -- Markus Rosjatfon: +49 351 8107224mail: ros

Re: GRE IP6/IP6 not working as soon as pf is enabled

2022-01-16 Thread Markus Wipp
yes, thats correct and just to make sure you got my last email. I was able to fix my issue inthe meantime by adding allow-opts > On 16. Jan 2022, at 12:40, David Gwynne wrote: > > you've set the net.inet.gre.allow sysctl to 1, right? > >> On 16 Jan 2022, at 17:05,

Fwd: GRE IP6/IP6 not working as soon as pf is enabled

2022-01-16 Thread Markus Wipp
Hi all, I got this information from Peter, which did the trick! I now have my complete rule-set with a block default policy working! Thanks to David and Georg as well for their help! Best regards Markus > Begin forwarded message: > > From: "Peter J. Philipp" > Su

Re: GRE IP6/IP6 not working as soon as pf is enabled

2022-01-15 Thread Markus Wipp
(id:597c seq:2) [icmp6 cksum ok] (len 64, hlim 64) > The bare "pass" rule not letting this work makes me feel like there's > more to this though. Yes, I also think that there must be more to it, but I just don’t see the trees for the forrest here. Thanks Markus signature.asc Description: Message signed with OpenPGP

GRE IP6/IP6 not working as soon as pf is enabled

2022-01-15 Thread Markus Wipp
) [uid 0, pid 74650] pass in on em0: 2a00:::::10 > 2a02::yyy:zzz::1: DSTOPT (type 0x04: len=1) gre [] 86dd [|ip6] [flowlabel 0xa8f7b] (len 116, hlim 243) Thanks in advance for any hints on how to solve this issue Best regards Markus

Re: (bug?) relayd forward to directives interfering

2021-08-13 Thread Markus Wernig
On 11.08.21 08:40, Vladimir Nikishkin wrote: > table { 127.0.0.1 } > table { 127.0.0.1 } Have you tried having the two backend listeners on different IP addresses rather than on different ports? Eg. 127.0.0.1 and 127.0.0.2? best /m

Re: Why demotion counter for group carp is set to 33 on boot?

2021-07-15 Thread Markus Wernig
On 7/13/21 9:32 AM, Tom K wrote: > why demotion counter for group carp is set to 33 on boot? This is the > primary firewall and there are no adskew settings in all hostname.carpX > files or anywhere else. > Because of this the other firewall which should be normaly the standby > (adskew 100),

Re: rad daemon strange error message

2021-06-30 Thread Markus Wernig
On 6/30/21 1:32 PM, Pierre Dupond wrote: > veteher30 has no IPv6 link-local address, ignoring ^ I don't know rad, but from the output above there seems to be a typo in some config.

Re: IPv6 NDP Confusion with PF enabled

2021-03-09 Thread Markus Wernig
On 3/8/21 11:05 PM, Antonino Sidoti wrote: > There is no blocking showing up when I examine the pflog0, I would run tcpdump -n -i em0 icmp6 during /etc/netstart with and without pf enabled. If you see a difference, that should help you find out what to allow in your ruleset. /m

Re: seeing carp interface state change for unknown reason ; cluestick hunting

2021-02-06 Thread Markus Wernig
On 2/7/21 1:38 AM, Bryan Stenson wrote: 31 RTM_IFINFO: iface status change: len 168, if# 3, name cnmac2, link: no carrier, mtu: 1500, Just grasping for something here...my next steps are to swap this unit out with the other one (to try and eliminate hardware failure of THIS unit). Any

Re: OpenBSD VM creation problem

2021-01-22 Thread Markus Wernig
mpbios and acpimadt in the kernel to make it work. See boot_config(8). From my notes from back then I also explicitly enabled acpi and ioapic, but I can't remember why ... best /markus

Re: auto-boot

2021-01-20 Thread Markus Wernig
On 1/20/21 10:01 AM, Bastien Durel wrote: If There is no software way to solve this problem, I shall need to buy a small HDMI screen and drop serial console ... If the console gets input from the serial port even with no cable plugged into it (and not just the other side disconnected),

Re: question about hostname.carp

2020-11-04 Thread Markus Wernig
On 11/4/20 4:05 PM, Harald Dunkel wrote: inet 10.0.1.1 0xff00 NONE vhid 41 pass secret carpdev em1 advbase 1 advskew 0 If you use the actual broadcast address 10.0.1.255 instead on NONE it will work with both.

Re: Encrypted notepad software suggestions

2020-09-28 Thread Markus Wernig
On 9/28/20 4:54 PM, William Orr wrote: > https://vim.fandom.com/wiki/Encryption That post is from 2001 (still valid, though). Vim from the current package defaults to blowfish2 as encryption algorithm. best /m

Re: Encrypted notepad software suggestions

2020-09-28 Thread Markus Wernig
On 9/28/20 9:18 AM, Martin wrote: > I'm looking for some notepad with encryption of notes/files created. Simply > Text File encryption is suitable too to hide some info from plain text files > I have. Depending on your definition of "notepad", vim (gvim) should have built-in encryption (:X

Re: Routing and forwarding: directly connected computers

2020-09-03 Thread Markus Wernig
On 9/3/20 5:41 PM, Ernest Stewart wrote: > And which pf rules and how to establish those routing tables are exactly what > I'm asking. Maybe if you share the output of the ping test from your original mail we could see what is actually happening. >From your setup I would assume that the IP

Re: Installation in a Xen guest (pvgrub)

2020-07-24 Thread Markus Kolb
Am 24.07.2020 17:30, schrieb Theo de Raadt: [...] non-OpenBSD bootloaders will do a shitty job of booting OpenBSD. I'm not going to bother explaining the situation in detail. People who try to go that way have already decided they don't care about the consequences. Ok. Thanks. Are you

Re: Installation in a Xen guest (pvgrub)

2020-07-24 Thread Markus Kolb
Am 21.07.2020 15:51, schrieb Pierre-Philipp Braun: [...] GRUB2 should be able to boot an OpenBSD kernel natively *2. Thing is, PVGRUB works for PV, not PVH nor PVHVM. However you might get NetBSD XEN/PV up and running at your XEN ISP *3, by leveraging PVGRUB indeed *3. And in case UFS is not

Re: Installation in a Xen guest (pvgrub)

2020-07-16 Thread Markus Kolb
Am 10.07.2020 23:30, schrieb Demi M. Obenour: [...] For me, OpenBSD boots fine in HVM mode (with an I/O emulator). I have not tried PVH mode and would not expect it to work. PV mode definitely won’t work, and should be avoided anyway for both security and performance reasons. Is HVM mode

Installation in a Xen guest (pvgrub)

2020-07-09 Thread Markus Kolb
is not available in the xenhost-builds of grub. There is also no chain-module for chainloader configs. Any ideas? Thanks Markus

Re: pfsync interface in carp group

2020-06-09 Thread Markus Wernig
On 6/9/20 9:25 PM, Paul B. Henson wrote: > Hmm, I had never considered using jumbo frames. ... > I guess multicast would work too Neither jumbo frames nor multicast will prevent group demotion when the other side of a crosslink cable goes physically down. Only not having the sync interface in

Re: pfsync interface in carp group

2020-06-08 Thread Markus Wernig
On 6/9/20 12:27 AM, Paul B. Henson wrote: > Yes, I am using a direct link between the two physical firewalls. [...] > Is this no longer a best practice? If it's in the documentation, I suppose it still is. But I have found it problematic, because taking down one firewall, or even only its sync

Re: pfsync interface in carp group

2020-06-07 Thread Markus Wernig
On 6/8/20 12:29 AM, Paul B. Henson wrote: > whenever I rebooted the secondary firewall, the > carp interfaces on the primary would flip to backup and then back to > master as the secondary one rebooted I don't see that behaviour on my carp pair. Are you using a cross-link cable between the two

Re: Select ssh key from ssh-agent?

2020-05-24 Thread Markus Wernig
On 5/24/20 3:55 AM, David A. Pocock wrote: > I can't relate; doing this from OpenBSD6.7 to OpenBSD6.7 the ecdsa forward > through and show up via ssh-add without any issues (and allow using the > intermediary host without having the keys present (and being able to choose > keys as per the

Re: Strange behavior when I try to use lladdr

2020-05-22 Thread Markus Wernig
On 5/22/20 12:12 PM, Денис Давыдов wrote: > I decided to reinstall OpenBSD to a newer version on my VMware ESXi > cluster. So I deleted an old router and start the new one using the old > configuration, except that I add lladdr parameter with the old MAC address Last I looked into it (some years

Re: 550 Invalid recipient domain

2020-02-04 Thread Markus Lude
ver) and rejected there? I think your mydestination setting is wrong and is missing localhost or did you mess up transport? Hard to say without config parts and logs. Regards, Markus PS: OpenBSD 6.4 is no longer supported

Re: usr/bin/whois: Query terms are ambiguous

2020-01-07 Thread Markus Lude
lowing two: telnet whois.arin.net 43 62.46.172.92 which is also what you get with "whois 62.46.172.92" and this: telnet whois.arin.net 43 n 62.46.172.92 and if you want to see the mentioned help above: telnet whois.arin.net 43 ? whois.apnic.net and whois.ripe.net understand "help" to display options. There seem to be no "standard" about options in queries to whois servers. Regards, Markus

Re: pfsync on VLAN - supported ?

2019-11-14 Thread Markus Wernig
On 14.11.2019 11:30, Rachel Roch wrote: >>> Does this mean Bad Things (TM) will happen if I try to use a dedicated vlan >>> interface for pfsync ? I have had pfsync running happily over a vlan interface for years, never a problem. > Regarding the extra port, in my case I'm using that for LACP

Re: random packet drops with syncookies/synproxy

2019-11-14 Thread Markus Wernig
On 09.11.2019 15:24, Claudio Jeker wrote: >> So nobody is using syncookies/synproxy at all? > > I guess that is a reasonably safe assumption. syncookies are rather new > and probably need more battle testing. OK, then I will send a bug report. > synproxy never helped me much in > case of a SYN

Re: random packet drops with syncookies/synproxy

2019-11-09 Thread Markus Wernig
Hm, also no replies to that one :-) On 11/6/19 8:15 PM, Markus Wernig wrote: > So just to make sure: Is anybody using syncookies and/or synproxy in > production in a similar setup? So nobody is using syncookies/synproxy at all? best /m

Re: random packet drops with syncookies/synproxy

2019-11-06 Thread Markus Wernig
Hi again Nobody has answered, so I suppose nobody else has this problem :-) That's good. So just to make sure: Is anybody using syncookies and/or synproxy in production in a similar setup? Thx /markus On 11/4/19 8:35 PM, Markus Wernig wrote: > Hi all > > After being hit by some

random packet drops with syncookies/synproxy

2019-11-04 Thread Markus Wernig
Is anybody aware of anything that could trigger this behaviour? Or have any hint where I could look further? I have all the log files if more info is needed. thx /markus (btw. the behaviour was the same on 6.5)

Re: Upgrade procedure (6.4 -> 6.5)

2019-05-02 Thread Markus Hennecke
why these files are not listed in "FIles to remove"? > Is there a way to track them? It's not like something gonna break, but > old configuration files (and manual pages) lying around can make > someone's life harder during the debug session. Take a look at the sysutils/sysclean port. Regards Markus

Re: Infinite spin when trying to burn a CD

2019-03-27 Thread Markus Rosjat
. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

Re: Infinite spin when trying to burn a CD

2019-03-26 Thread Markus Rosjat
sorry it might got a bit confusing Am 26.03.2019 um 15:41 schrieb Markus Rosjat: cd0(ahci0:2:0): Check Condition (error 0x70) on opcode 0x1e SENSE KEY: Illegal Request the opcode is for the cdb prevent allow media removal so I assume your hardware got a problem with the cdb send

Re: Infinite spin when trying to burn a CD

2019-03-26 Thread Markus Rosjat
the Openbsd system finds something wrong with your hardware. I'm not clever enough to speculate further. Sorry. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220

Re: httpd acme-client renew multiple domains

2019-03-26 Thread Markus Rosjat
:) regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you print

Re: pppoe(4) and vlan(4)

2019-02-25 Thread Markus Hennecke
Am 25.02.2019 um 16:30 schrieb Thomas Huber: > Hi misc, > > i got the opportuniy to have 4 ADSL links to my rural site. > Two links have already been there and OpenBSD -stable running a APU2 is > shaping the traffic between this two links. > > But now I struggle with setting up the 3rd (pppoe2)

Re: python3 script not running as root

2018-11-15 Thread Markus Rosjat
Hi Marc, Am 15.11.2018 um 14:05 schrieb Marc Espie: 6.4, or snapshot ? there was an unveil snafu with doas a few days ago. 6.4 release -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http

Re: python3 script not running as root

2018-11-15 Thread Markus Rosjat
scripts with a full path in the shebang seem to run anymore on 6.4 regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie

python3 script not running as root

2018-11-14 Thread Markus Rosjat
terminal with doas it works. That is kinda odd sice both root and my user have python3 and env in there $PATH at least the path to the executable. some hints would be appreciated. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann

GAMIN question again

2018-11-07 Thread Markus Rosjat
me  how to configure it please regards -- Markus Rosjatfon: +49 351 8107224mail:ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich

Re: migrate python script from sudo to doas

2018-11-03 Thread Markus Rosjat
Hi Vincent, Am 03.11.2018 um 07:22 schrieb vincent delft: Hello Markus, I cannot reproduce your problem. As you can see here under I can create a user "test1" on the command line, and, with the same userid, I can create it with python2 and python3 too. (I'm running 6.4) I see

Re: relayd.conf it's so confusing

2018-11-02 Thread Markus Rosjat
Hi again, Am 02.11.2018 um 11:26 schrieb Markus Rosjat: ..  but also the match defined in the new defined protocol is still working. Thats something that shouldn't happen at all. this seems to be resolved and was more or less browser related -- Markus Rosjatfon: +49 351 8107224mail

relayd.conf it's so confusing

2018-11-02 Thread Markus Rosjat
s was checking sysntax and a rcctl reload relayd I am relucdent to do a restart because it happens to crash the VM. The VM is running 6.1 with all syspatches applied. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker S

Re: httpd rewiterules like apache

2018-11-01 Thread Markus Rosjat
^(.*)http://some.tld/someotherdir/$1 [L,P] so a http://www.my.tld would go to http:/some.tld/something.http but woudnt http://some.tld/someotherdir/something.http or do I get it wrong? -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker St

httpd rewiterules like apache

2018-11-01 Thread Markus Rosjat
!) Since there is redirection I can do this but then the url gets of course replaced  in a block directive  block return 301 "http://dome.tld$REQUEST_URI; I read that there is rewrite support but as far as I figured it's just for location on the filesystem ? regards -- Markus Rosjatfon: +4

Re: syntax error and doas.conf

2018-10-31 Thread Markus Rosjat
Hi Bruno, Am 31.10.2018 um 12:23 schrieb Bruno Flueckiger: On 31.10.18 10:42, Markus Rosjat wrote: Losing ten minutes time because of a mistake you've made all by yourself made you write this useles mail. Imagine how many times you could have read the man page of doas(8) and find out

Re: syntax error and doas.conf

2018-10-31 Thread Markus Rosjat
/this/cmd because 99% of the time you only need root priv to do something like that. So some very nice guy, I think is name is Ted, thought "hey lets simplify it and skip all the heavy stuff that sudo brings along". At least I imagine he thought something like that :) regard -- Markus Ros

syntax error and doas.conf

2018-10-31 Thread Markus Rosjat
but you may have learn at least one thing ... read again what you just wrote before you save it :) Have a nice day list :) and happy helloween -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http

Re: migrate python script from sudo to doas

2018-10-31 Thread Markus Rosjat
install sudo package using the "pointing a cannon at a sparrow" approach :( regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107

Re: migrate python script from sudo to doas

2018-10-30 Thread Markus Rosjat
Hi, as I stated before on a cmd is no problem, Im using 6.4 release Am 30.10.2018 um 12:56 schrieb Solene Rapenne: Markus Rosjat wrote: hi all, I have some old python scripts that using os.spawnl to execute stuff like useradd  combined with sudo. This worked just fine on systems with sudo

migrate python script from sudo to doas

2018-10-30 Thread Markus Rosjat
status 1 So does someone had some issues with migrating scripts from sudo to doas, then some help or hintw would be very appreciated. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.g

Re: 6.4 doas gives "command not found" if no #!/bin/sh up top

2018-10-30 Thread Markus Rosjat
his change was made doas worked as expected with the script regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mai

cyrus-sasl/openldap question

2018-10-24 Thread Markus Rosjat
cyrus-sasl are a big fk^ in my opinion but thats another story. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob

Re: FAM Question

2018-10-22 Thread Markus Rosjat
trying to tell me. I simply need to know how to start gamin as a background process since FAM package isnt arround anymore. Usally there would be some kind of rc script in rc.d somewere but there isnt. There isnt a man page to be found so I'm lost how to get things running. regards -- Markus

Re: FAM Question

2018-10-21 Thread Markus Rosjat
hi Julian, Am 20.10.2018 um 01:01 schrieb Julian Suschlik: Would sysutils/entr help? canyou be more specific? thank you -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49

relayd smtp traffic

2018-10-19 Thread Markus Rosjat
redirect mailtraffic for a domain to this machine. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese

FAM Question

2018-10-19 Thread Markus Rosjat
or pkgconfig doesnt say anything regarding this so Im kinda lost here. So if someone hast som information about that share please. regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http

migrate users from old system

2018-10-16 Thread Markus Rosjat
themself. Any advice would be helpful. Regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich

Re: CARP on Hyper-V VM

2018-10-16 Thread Markus Rosjat
that because of the probable network disconnection. I will give it a shot later. regards MArkus -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351

CARP on Hyper-V VM

2018-10-16 Thread Markus Rosjat
in 6.3? regards -- Markus Rosjatfon: +49 351 8107224mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen Sie, ob diese Mail wirklich ausgedruckt werden muss! Before you

OT: how do you write your tools /scripts for everyday tasks

2018-05-30 Thread Markus Rosjat
of the time you ending up using subprocess to call a existing tool that you would use on a cmd anyway. So what you guys using these days, is it shellscripts, c programs, perl or? Would be cool to get some feedback on that :) regards -- Markus Rosjatfon: +49 351 8107223mail: ros

Re: httpd index directive confusion

2018-05-30 Thread Markus Rosjat
hi Paco, Am 30.05.2018 um 13:31 schrieb Paco Esteban: On Wed, 30 May 2018, Markus Rosjat wrote: so I Configure my Location in httpd.conf like this location "/admin/*" { root "/path/to/my/site/admin" root strip 1 direc

httpd index directive confusion

2018-05-30 Thread Markus Rosjat
} in my opinion this should show me the generated index.php but instead I get file not found. When I call the index.php explicitly like https://UrlToMySite.tld/admin/index.php it works. so where do I go wrong here? regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webse

Re: HPPA 720/60 and PS/2 Keyboard

2018-05-22 Thread Markus Hennecke
On Mon, 21 May 2018, Otto Moerbeek wrote: > On Mon, May 21, 2018 at 12:29:13PM +0200, Markus Hennecke wrote: > > > I tried updating my HPPA box from 6.2 to 6.3, but when booting the release > > or -current bsd.rd kernel the keyboard repeats the last key pressed. The &

Re: HPPA 720/60 and PS/2 Keyboard

2018-05-21 Thread Markus Hennecke
On Mon, 21 May 2018, Markus Hennecke wrote: > I tried updating my HPPA box from 6.2 to 6.3, but when booting the release > or -current bsd.rd kernel the keyboard repeats the last key pressed. The > 6.2 release did not show this behaviour. Is there anyone out there running > 6.3

HPPA 720/60 and PS/2 Keyboard

2018-05-21 Thread Markus Hennecke
I tried updating my HPPA box from 6.2 to 6.3, but when booting the release or -current bsd.rd kernel the keyboard repeats the last key pressed. The 6.2 release did not show this behaviour. Is there anyone out there running 6.3 or -current on hppa? Markus

Re: Status of X i386 openbsd 6.2 on x200

2018-04-14 Thread Markus Lude
On Mon, Apr 02, 2018 at 09:26:58PM +0200, Markus Lude wrote: > On Sun, Apr 01, 2018 at 09:41:07PM +, flipchan wrote: > > Hello all, > > > > I have tried to installed 6.1 and 6.2 on a thinkpad x200 it works but X > > does work ... > > > > Its works grea

Re: Using stmp auth for local account with PHP scripts

2018-04-04 Thread Markus Rosjat
` pointing your certificate's CN to `127.0.0.1`, or include `localhost` in your certificate SANs. And if your certificate is self signed, you'll have to manually accept it. I will give it a try , thank you for the advice Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H

Re: Using stmp auth for local account with PHP scripts

2018-04-04 Thread Markus Rosjat
for any relay via tls+auth://relaycred@relayhost:587 auth And then I can just setup the PHPMailer to use submission port on localhost with some credentials? Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099

Re: httpd.conf path substitution

2018-04-04 Thread Markus Rosjat
s just wondering if I did something wrong or it's simply not supported. Regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax: +49 351 8107227 Bitte prüfen S

Re: Status of X i386 openbsd 6.2 on x200

2018-04-02 Thread Markus Lude
ller chunks to see where the cause therein is. The T61 is quite old and still runs with 6.1. It is new for me that newer Thinkpads do have the same problem. Could you please post a trace of your crash? Regards, Markus

Using stmp auth for local account with PHP scripts

2018-04-01 Thread Markus Rosjat
I need to configure the "external" addr too for this purpose? Regards Markus

httpd.conf path substitution

2018-03-29 Thread Markus Rosjat
o/cert" server "domain.tld" { tls { key $tls_key certificate $tls_cert } } regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351

Re: httpd / acme-client confusion

2018-03-19 Thread Markus Rosjat
I did the forced renew. I will do the suggested changes to the config and keep an eye on it. My main problem was with the block statement the other thing I just noticed as I did testing with the config and started forcing the renew of the certificate regards -- Markus Rosjatfon: +49

Re: stop syslogd from opening port 514 UDP

2018-03-16 Thread Markus Hennecke
not given and no logging rules exist to send to a remote host the socket is closed per default since 6.2. Perhaps you are logging to a remote host? The syslogd here on my 6.2 system has not opened port 514. Kind regards Markus

Re: httpd / acme-client confusion

2018-03-16 Thread Markus Rosjat
the suggested changes Im okay with it :) regards Markus Am 16.03.2018 um 08:42 schrieb Florian Obser: this works for me: server "tlakh.xyz" { listen on 0.0.0.0 tls port 443 listen on :: tls port 443 tls certificate "/etc/ssl/tlakh.xyz.crt"

httpd / acme-client confusion

2018-03-15 Thread Markus Rosjat
sic https redirect? Or is it really the case that I need to load a config that hasn't a blok return statement in the http server definition? One last note, I did a syspatch today and don't know if this changed something in the behaviour of the components involved. regards -- Markus Rosjat

pf dropping fragmented UDP despite of scrub no-df

2017-12-04 Thread Markus Wernig
OPT UDPsize=4096 DO (36) (ttl 46, id 38692, len 64) 13:23:14.380013 72.13.58.105.44267 > dns1-external.domain.tld.domain: [udp sum ok] 47368 [1au] DNSKEY? domain.tld. ar: . OPT UDPsize=4096 DO (36) (ttl 46, id 53971, len 64) ... Thx /markus

board ord boards with case for a router firewall

2017-11-02 Thread Markus Rosjat
nic would be interesting, so if someone likes to share his experiences it would be much appreciated regards -- Markus Rosjatfon: +49 351 8107223mail: ros...@ghweb.de G+H Webservice GbR Gorzolla, Herrmann Königsbrücker Str. 70, 01099 Dresden http://www.ghweb.de fon: +49 351 8107220 fax

  1   2   3   4   5   6   7   >