Re: Qubes-OS is "fake" security

2017-05-12 Thread Daniel Ouellet
May I suggest you go read the FAQ before you spread misinformation. Qubes doesn't use KVM, it's built on Xen, and calling it just a GUI is like calling OpenBSD just a bunch of masturbating monkeys. > On May 12, 2017, at 2:37 PM, flipchan wrote: > > Qubes os is just linux with a gui for some kv

SoC Intel Xeon D-1518 & D-1548

2017-09-09 Thread Daniel Ouellet
Hi, Is there anyone that know of have one of the Intel Xeon D-1548 SoC that works on OpenBSD? I know the D-1518 does, I find the DMESG in the archive, but I can't find anything at all on the D-1548. Any clue. Here is the D-1518 https://marc.info/?l=openbsd-misc&m=146236157518744&w=2 I am askin

Re: CoDel Flows

2017-10-12 Thread Daniel Ouellet
> Also, the pf.conf man page says the default qlimit is 1024, but, if I > don't specify a qlimit, pfctl –vsq shows a qlength of 50 when I was > expecting it to be 1024. What am I missing? Why would you want to have a pool of 1024 oppose to the default of 50 slots for your queue? You will increas

OT: Temperature sensors suggestions?

2018-05-18 Thread Daniel Ouellet
Does anyone have a decent temperature sensors that can connect to an OpenBSD server and be reliable and give any decent reading via either USB or Serial port or even stand alone via Ethernet? I asked because yes I can use the sensors on some servers, but I got a pretty expensive router blowing up

Re: OT: Temperature sensors suggestions?

2018-05-18 Thread Daniel Ouellet
8 5:53 PM, Base Pr1me wrote: > I roll SHT31-Ds through ESP8266s via I2C. Of course, there is programming > involved. > Good hardware though, if that's what you're looking for. > > On Fri, May 18, 2018 at 2:42 PM, Daniel Ouellet wrote: > >> Does anyone have a

Daily insecurity output on valid users using key with valid shell and without password.

2018-07-01 Thread Daniel Ouellet
I find this annoying and sometime I over look this because I always get the example: == Running security(8): Checking the /etc/master.passwd file: Login share is off but still has a valid shell and alternate access files in home directory are still readable. Login xxx is off

Re: Daily insecurity output on valid users using key with valid shell and without password.

2018-07-01 Thread Daniel Ouellet
ation, conventionally have 13 asterisks in the password field. On 7/1/18 2:44 PM, Remco wrote: > Op 07/01/18 om 19:22 schreef Daniel Ouellet: >> I find this annoying and sometime I over look this because I always get >> the example: >> >> == >> Runnin

Re: Daily insecurity output on valid users using key with valid shell and without password.

2018-07-01 Thread Daniel Ouellet
Hi Stuart, The counting to 13 was actually a sarcastic joke. (: But thanks never the less. Daniel On 7/1/18 5:54 PM, Stuart Henderson wrote: > On 2018-07-01, Daniel Ouellet wrote: >> Ha the old man page. >> >> Not good to read to quickly. (: >> >> Sorry for

Re: "no route to host" from pkg_add

2018-08-10 Thread Daniel Ouellet
On 8/10/18 10:38 PM, Daniel Ouellet wrote: > Hi, > > I am not sure you got that right. > > If you are an ISP the minimum assignment is /32 and you assigned /48 to > end company and /56 to users. > > If you asked me that's a wasted, but that's what they

Re: "no route to host" from pkg_add

2018-08-10 Thread Daniel Ouellet
Hi, I am not sure you got that right. If you are an ISP the minimum assignment is /32 and you assigned /48 to end company and /56 to users. If you asked me that's a wasted, but that's what they suggest. For end users, a /64 would be plenty if you asked me and /56 for company would be plenty as

Re: "no route to host" from pkg_add

2018-08-10 Thread Daniel Ouellet
. https://tools.ietf.org/html/rfc6177 But that is still even crazy specially when you see users using NAT64 on IPv6... Anyway, back to my rock and I hope it help you address your assignment anyway. Daniel On 8/10/18 10:38 PM, Daniel Ouellet wrote: > Hi, > > I am not sure you got t

Re: want.html: Unifi wifi gear for interop debugging

2018-10-06 Thread Daniel Ouellet
On 10/6/18 11:48 AM, Tim Jones wrote: >> Thank you for handling the logistics so I don't have to do that >> on top of everything else I'm doing. >> I am looking forward to receiving your shipment. > > > Oh right, and the rest of us don't have day-jobs, plus other commitments > outside of working

Re: [OpenIKED] Is it impossible to differentiate the policies by dstid?

2018-11-06 Thread Daniel Ouellet
The source ID does default yes, but I have a tunnel gateway for multiple VPN and I HAD to specify the dstid on the passive side as well or ONLY the last rule was picked up for the 0.0.0.0/0 of some of them as an example for all the traffic flowing via the VPN. Any overlapping routes where not goin

Re: pf table for all publicly routable ipv4 addresses

2020-05-04 Thread Daniel Ouellet
Just a question and a thought may be. I am not sure why having this pass valid table oppose to block. The reason is that if you pass all valid IP's then some service you want to block, don't you have to add more rules to do that oppose to only allow incoming from service you want? Look to me you

Re: IKEv2 difference with 6.7

2020-06-15 Thread Daniel Ouellet
On 6/15/20 8:04 PM, Daniel Ouellet wrote: >> Probably related to the following change documented in >> https://www.openbsd.org/faq/upgrade67.html: >> >> iked(8)/isakmpd(8). The type of incoming ipsec(4) flows installed by iked(8) >> or >> isakmpd(8) was changed

Re: IKEv2 difference with 6.7

2020-06-15 Thread Daniel Ouellet
> Probably related to the following change documented in > https://www.openbsd.org/faq/upgrade67.html: > > iked(8)/isakmpd(8). The type of incoming ipsec(4) flows installed by iked(8) > or > isakmpd(8) was changed from "use" to "require". This means unencrypted traffic > matching the flows will n

Re: IKEv2 difference with 6.7

2020-06-16 Thread Daniel Ouellet
ow, it's stupid, but I do a lots of work from home and I need to keep the family happy too. (;) On 6/16/20 6:09 AM, Tobias Heider wrote: > Hi Daniel, > > On Mon, Jun 15, 2020 at 08:04:43PM -0400, Daniel Ouellet wrote: >>> Probably related to the following change documented in

Re: IKEv2 difference with 6.7

2020-06-16 Thread Daniel Ouellet
On 6/16/20 1:35 PM, Patrick Wildt wrote: > On Tue, Jun 16, 2020 at 01:09:32PM -0400, Daniel Ouellet wrote: >> Hi Tobias, >> >> I put below the full configuration and the flows as well with the 6.6 >> binary and switch to the 6.7 binary without any other changes as

Re: IKEv2 difference with 6.7

2020-06-16 Thread Daniel Ouellet
> The retransmits tell us that the peer doesn't answer. Or, to be more > precise, it doesn't receive *any* message from the peer. Can you have > a look at the peer's logs? Does the peer see these packets but chooses > not to reply? Is the peer also an OpenBSD? 6.6? 6.7? Not a big deal, but y

Re: IKEv2 difference with 6.7

2020-06-16 Thread Daniel Ouellet
Hi, > What I see is that the initial message is received but ignored, so this > side here probably runs into some kind of error. > To find out what exactly causes this, a more verbose log would help. > You could manually start iked with -dvv and share the log for an > incoming IKE_SA_INIT request

Re: IKEv2 difference with 6.7

2020-06-17 Thread Daniel Ouellet
Hi Tobias, > So the error message is probably in the other side's logs but here is > a guess: 5.6 doesn't know curve25519. > > Try adding the following to your iked.conf: > > ikesa group modp2048 Many thanks!!! That was the issue and you saved me from pulling what I have left of hairs.

Re: Correct subnet mask for alias IPs?

2020-06-19 Thread Daniel Ouellet
On 6/19/20 7:15 AM, Robert wrote: > Hi, > > I want to configure multiple alias IPs on the same interface and in the same > subnet. > (reason: hosting services with dedicated DNS names and IPs) > > inet 10.0.0.1 255.255.255.0 > inet alias 10.0.0.2 255.255.255.0 > inet alias 10.0.0.3 255.255.255.2

Any idea/suggestion for old Cisco router to be use running OpenBSD current for WG?

2020-06-23 Thread Daniel Ouellet
Hi, This might be a bit weird question, but I saw the wireguard being put in the kernel in the last few days and I am very existed abut it oppose to use the package on it and even today there was more on it. Many thanks for this!!! I also know there was effort and some Cisco router can run OpenB

Re: Any idea/suggestion for old Cisco router to be use running OpenBSD current for WG?

2020-06-23 Thread Daniel Ouellet
t; Pro for several years now without issue, and have dozens of ER4 and > ER-Lite devices out in the wild. > > If you're looking for non-x86 routing solutions, then the Edgerouter is > one of the best bets. > > Regards, > > Jordan > > On 2020-06-23 09:01, Daniel

Re: Any idea/suggestion for old Cisco router to be use running OpenBSD current for WG?

2020-06-23 Thread Daniel Ouellet
though it might not be the most ideal. > > Regards, > > Kaya > > On Tue, Jun 23, 2020 at 5:03 PM Daniel Ouellet wrote: >> >> Hi, >> >> This might be a bit weird question, but I saw the wireguard being put in >> the kernel in the last few days and I am

Adding more syspatch platform.

2020-08-11 Thread Daniel Ouellet
Just a general question as I got to really love syspatch and sysupgrade to the point that oppose to before, now my platforms are pretty much always up to date and patch in just a few days after patches are release or even in some cases the same day. To add more platform, I guess that mean man powe

Re: Microsoft's war on plain text email in open source

2020-08-26 Thread Daniel Ouellet
On 8/26/20 3:08 PM, Chris Bennett wrote: > On Wed, Aug 26, 2020 at 12:28:00PM -0500, Mike Hammett wrote: >> Text-only was great in 1985. >> >> > > And it's still pretty badass in 2020. > I really love the way company networks are brought down by a little > helpful Javascript in an HTML email. I

Re: pf.conf parser/lint

2020-09-04 Thread Daniel Ouellet
> We provide over FIVE ways to identify ports without using the hardware > driver names, but hey... this discussion is about the theory you can > check overall behaviour of a system by ignoring the important parts. I always put a description and group field in my hostname config so that it allow m

Re: Intl I350 Network Card Not Found

2020-09-17 Thread Daniel Ouellet
Hi Brandon, The key point here for the answer provided to iyou was "Firmware" not "driver" Two different things. Driver for Linux for example is use to allow the network stack of Linux to use the card based on what the actual card support. Firmware is what actually run on the flash of the card

Max Speed: configuration in smnpd.conf for display in mrtg

2019-08-22 Thread Daniel Ouellet
Hi, Wonder if anyone would know the answer for this. I try to figure out what is the entry needed in the snmpd.conf for the specific display that would show in mrtg when the scan is done. In short the display as Max Speed: 1000.0 Mbits/s to be display as for example Max Speed: 150.0

Re: Max Speed: configuration in smnpd.conf for display in mrtg

2019-08-25 Thread Daniel Ouellet
lot as new customers are added or removed, it was a lot simpler to do it in the actual router then trying to always go back and over write the final configuration or mrtg each time. Daniel On 8/23/19 12:12 PM, Stuart Henderson wrote: > On 2019-08-22, Daniel Ouellet wrote: >> Hi, >> >&

Re: Max Speed: configuration in smnpd.conf for display in mrtg

2019-08-28 Thread Daniel Ouellet
On 8/28/19 5:44 AM, Stuart Henderson wrote: > On 2019-08-26, Daniel Ouellet wrote: >> Thanks Stuart, >> >> I guess I had the right oid before, but the fact that is doesn't allow >> the replacement always give me a fail at restart, I assume I wasn't

Re: What is you motivational to use OpenBSD

2019-08-28 Thread Daniel Ouellet
On 8/28/19 10:32 AM, Mohamed salah wrote: > I wanna put something in discussion, what's your motivational to use > OPENBSD what not other bsd's what not gnu/Linux, if something doesn't work > fine on openbsd and you love this os so much what will do? - Simplicity. - Clean - Lean and Slim - Work as

Re: Incoming connection via VLAN

2019-09-02 Thread Daniel Ouellet
It's hard trying to help you as. Vlan syntax changed from the upgrade or 6.1 to 6.2 and the pf queuing changed from 6.3 to 6.4. So looks like you skip a few version and no where did you provide any details on your configuration. So I would suggest to go and read either the man page or look at th

Re: Certain size packets not passing through a L2 over L3 IPsec tunnel

2019-10-10 Thread Daniel Ouellet
On 10/10/19 4:25 PM, Russell Sutherland wrote: > I've set up a L2overL3 tunnel using the template as found in "man etherip". I > am running OpenBSD 5.9, which I believe is the first version to support the > etherip interface. > > I find the bridge/tunnel does not pass a small range of specific s

PC Engine APU.1D4 installation stopper.

2015-10-19 Thread Daniel Ouellet
Hi, I am trying to load OpenBSD on this box and no matter what I try I end up not being able too. I did search and saw plenty that were successful and all. May be it's the newer model. APU.1D4? Or is there any special truck? I tried from usb flash drive, and even from a Sata drive inside a USB

Re: PC Engine APU.1D4 installation stopper.

2015-10-19 Thread Daniel Ouellet
On 10/19/15 11:52 PM, Jonathan Gray wrote: > For i386/amd64 you have to tell boot you want serial output > either at the boot prompt or via boot.conf. > > stty com0 115200 > set tty com0 Well, I knew it was something stupid I overlook! I need an other beer. Just was to excited when I got the box

smtpd with accept from any for domain alias relay via smtp://127.0.0.1:10025 doesn't support check?

2015-10-30 Thread Daniel Ouellet
Isn't the long form domain alias should be supported here for the relay configuration in smtpd.conf In the man(5) smtpd.conf page I see this form as valid: accept from any for domain alias deliver to maildir accept from any for domain virtual deliver to \ maildir So, I would have e

Re: smtpd with accept from any for domain alias relay via smtp://127.0.0.1:10025 doesn't support check?

2015-10-30 Thread Daniel Ouellet
On 10/30/15 4:10 AM, Gilles Chehade wrote: > On Fri, Oct 30, 2015 at 03:56:23AM -0400, Daniel Ouellet wrote: >> Isn't the long form domain alias should be supported >> here for the relay configuration in smtpd.conf >> >> In the man(5) smtpd.conf page I see this

Re: APU.1D RealtekRTL8111E

2015-11-01 Thread Daniel Ouellet
dmesg in the archive already. APU.1D4 http://marc.info/?l=openbsd-misc&m=144531661519455&w=2 Works well so far and the box is somewhat hot as it is the heat sink for the board. But in your concern I have one question that really puzzle me about it. "...push 1 Gigabit of packets..." Here is th

Re: APU.1D RealtekRTL8111E

2015-11-01 Thread Daniel Ouellet
On 11/1/15 10:28 PM, Theo de Raadt wrote: >> "...push 1 Gigabit of packets..." >> >> Here is the logic that to me doesn't make sense. It' ok for you to >> disagree with me, but think about it for 2 minutes. > > oh come on daniel, your logic is all wrong. > > obviously the OP has bought a full 1G

Re: crash with -current

2015-11-02 Thread Daniel Ouellet
On 11/2/15 1:31 PM, Stuart Henderson wrote: > On 2015-11-02, Michael McConville wrote: >> My speculative 2¢. > > See, even the USA needs more than ASCII :-) May be not. $0.02 :-))

Any trick to send a reject emails form smtpd back into spamd?

2015-11-06 Thread Daniel Ouellet
I know this is not in the map page, so out of the box it's possible. But is there any trick for example to have something like this reject from any for domain recipient ! set pftable "spamd" in smtpd.conf and have it add the source IP into the spamd table of pf? So, instead of adding spam trap

Rspamd with smtpd

2015-11-10 Thread Daniel Ouellet
Does anyone use this port yet Rspamd. I saw Stuart + a few helpers making a port of Rspamd. Only on current now, so I install current on a server and try to run it. But anyone have any clue stick to provide on how to actually plug it with smtpd? Looks like Rspamd accept only input via the http s

Re: Rspamd with smtpd

2015-11-11 Thread Daniel Ouellet
On 11/11/15 5:30 AM, Stuart Henderson wrote: > On 2015-11-11, Joerg Jung wrote: >>> Am 11.11.2015 um 05:44 schrieb Daniel Ouellet : >>> >>> Does anyone use this port yet Rspamd. >>> >>> I saw Stuart + a few helpers making a port of Rspamd. Only on c

Octeon snapshots

2015-11-13 Thread Daniel Ouellet
I saw a commit today on this platform. The last snapshot is almost a month old. 10/18/152:19:00 AM. Just wonder if the snapshot might get some love. If not, totally fine, just wonder. I may just go buy myself a bigger USB drive to try to compile it on my Ubiquiti box and see how many da

Octeon uboot update/upgrade kernel need to be copied to the fat partition of your USB drive in Ubiquiti

2015-11-13 Thread Daniel Ouellet
Took me a while to find this, and I saw a few questions on misc@ as well and sense the same frustration I had. The thread was this one: http://marc.info/?l=openbsd-misc&m=144562030714263&w=2 I am sure more will have the same frustration then me on this as just compiling the kernel it does take a

Fwd: CVS: cvs.openbsd.org: src

2015-11-30 Thread Daniel Ouellet
Even removed the table password? NO way anymore to have difference password for emails then the system password without smtp-extra install? I can understand may be sqlite and ldap, but as a base system having different password from the system was and is very useful and I do it on all systems. O

Re: Fwd: CVS: cvs.openbsd.org: src

2015-11-30 Thread Daniel Ouellet
On 11/30/15 4:58 PM, Joerg Jung wrote: > On Mon, Nov 30, 2015 at 04:48:05PM -0500, Daniel Ouellet wrote: >> Even removed the table password? > > Yes. > >> NO way anymore to have difference password for emails then the system >> password without smtp-extra inst

Re: A branded USB stick as an alternative to the CD set?

2015-11-30 Thread Daniel Ouellet
On 11/30/15 8:43 PM, Theo de Raadt wrote: >> On Nov 30, 2015, at 2:34 PM, Theo de Raadt wrote: >>> >>> These days the CD revenue is about what a cashier at a store makes. > > Uncertain of the veracity of this site, > > http://www.payscale.com/research/CA/Job=Cashier/Hourly_Rate/725daaa6/Entry-Le

Re: Octeon snapshots

2015-12-05 Thread Daniel Ouellet
On 11/13/15 12:02 PM, Daniel Ouellet wrote: > I saw a commit today on this platform. The last snapshot is almost a > month old. > > 10/18/15 2:19:00 AM. > > Just wonder if the snapshot might get some love. > > If not, totally fine, just wonder. > > I may j

Re: Octeon snapshots

2015-12-05 Thread Daniel Ouellet
On 12/5/15 8:20 AM, Peter Kay wrote: > > > On 5 December 2015 09:36:29 GMT+00:00, Daniel Ouellet > wrote: >> On 11/13/15 12:02 PM, Daniel Ouellet wrote: >> To the kind sole. >> >> Not sure who did the new current updated release, but many thanks to >>

bsd.rd on Octeon ubnt_e200 doesn't fully boot

2015-12-05 Thread Daniel Ouellet
Not the end of the world, I was trying to see if I could boot OpenBSD on this version of the EdgeRouter Pro from Ubiquiti. I try the latest Octeon available just in case. I am still trying, but start to run out of idea and i do need to get some sleep now. Anyone have a possible Idea as what I may

Re: bsd.rd on Octeon ubnt_e200 doesn't fully boot

2015-12-05 Thread Daniel Ouellet
On 12/5/15 8:55 AM, Ted Unangst wrote: > Daniel Ouellet wrote: >> Not the end of the world, I was trying to see if I could boot OpenBSD on >> this version of the EdgeRouter Pro from Ubiquiti. I try the latest >> Octeon available just in case. > >> panic: pool_do_

Re: bsd.rd on Octeon ubnt_e200 doesn't fully boot

2015-12-05 Thread Daniel Ouellet
1 at softraid0: 256 targets root device: On 12/5/15 2:56 PM, Janne Johansson wrote: > My ERL would not run SMP if coremask was 0x1 (ie, use only one cpu) so I > setenv:ed the bootmask to add coremask=0x3 so that the bsd.mp would find > both cores, otherwise it bombed while probing for t

Re: bsd.rd on Octeon ubnt_e200 doesn't fully boot

2015-12-05 Thread Daniel Ouellet
ti product, you acknowledge that you have read and understood the Ubiquiti License Agreement (available in the Web UI at, by default, http://192.168.1.1) and agree to be bound by its terms. ubnt login: On 12/5/15 6:18 PM, Daniel Ouellet wrote: > I got a little bit more now. Not much, but stil

Re: Octeon snapshots

2015-12-05 Thread Daniel Ouellet
On 12/5/15 8:01 PM, jungle Boogie wrote: > On 5 December 2015 at 01:36, Daniel Ouellet wrote: >> I very much appreciate it. > > > I appreciate this too, but I can't complete the install. I tried an > update and now an install. > > Like the first time

Ikedv2 proper usage questions.

2015-12-08 Thread Daniel Ouellet
I have a few questions that I really need to clarify fro myself and I would very much appreciate some input. Reason is that I am having problem to keep the session up for a long time and just doing /etc/rc.d/iked stop and the start on the client side will bring the session back up, even if I see w

Interaction seen between dhcp renewal and iked session forcing it to try to switch to NAT-T and die form then on.

2015-12-09 Thread Daniel Ouellet
Sorry for the long details here. It may be relevant or related to some comment I have seen in regards to DHCP client killing traffic in the last few days on tech@ I have seen and that may be it might be useful. If not just ignore as i am still digging why iked session are unstable long term. But

When iked re-key, leave ghost behind

2015-12-11 Thread Daniel Ouellet
One question. Is it the only way to re-key the iked process when it reach it's 3 hours usage and/or the 500 Mb data exchange to restart a new process? Isn't it possible to kill the old one then that is not use anymore and stop having some routing problem that may be cause by it. I collect a HUGE

Re: When iked re-key, leave ghost behind

2015-12-11 Thread Daniel Ouellet
On 12/11/15 12:11 PM, Daniel Ouellet wrote: > One question. Is it the only way to re-key the iked process when it > reach it's 3 hours usage and/or the 500 Mb data exchange to restart a > new process? > > Isn't it possible to kill the old one then that is not use anymo

IKEDv2 lost tunnel. How to reproduce at will, effects and work around.

2015-12-11 Thread Daniel Ouellet
I sure hope this will help. ***Setup*** Two server on 5.8. Establish VPN with IKEDv2. One side active, one side passive. Use rsa keys, or pass phrase if you like. Active side: # cat /etc/iked.conf ikev2 Ouellet active from re0 to 66.63.5.250 from 66.63.50.16/28 to 0.0.0.0/0 peer 66.63.5.250 Pass

Re: syscall 5 "cpath" continues with octeon

2015-12-12 Thread Daniel Ouellet
I am really not sure what problem you are facing for sure. I did a few times form scratch and every time it goes without any problems what so ever and I really don't see where your cpath can come from at all. And I see no pledge issue what so ever either. Are you sure that you are actually using

Re: syscall 5 "cpath" continues with octeon

2015-12-12 Thread Daniel Ouellet
Worst case, delete all partitions (EXCEPT the first one, the FAT one) and use only one, install, test and then redo as you see fit. You can mount your FAT partition and access it right? You do have the bsd.rd file on that FAT partition right? May be your fat partition conflict with one of the de

Re: syscall 5 "cpath" continues with octeon

2015-12-13 Thread Daniel Ouellet
Hi, I thought about your problem and as i can't figure out what may be going on, I thought a picture would be worth a thousands words and as my English is not as good as I wish, I did a video instead. Not sure how many words that would be worth, but what ever, I am sure it would be way better the

Re: letsencrypt && https && openbsd.org = https://www.openbsd.org/

2015-12-13 Thread Daniel Ouellet
> Secondly, this whole thread should have ended long ago. So why you keep it going then. Let it die please

Re: syscall 5 "cpath" continues with octeon

2015-12-13 Thread Daniel Ouellet
Sorry about that by the way. The file is big, 156494156 Dec 13 02:40 Octeon-Install.mov On 12/13/15 2:58 AM, Daniel Ouellet wrote: > Hi, > > I thought about your problem and as i can't figure out what may be going > on, I thought a picture would be worth a thousands words an

Re: IKEDv2 lost tunnel. How to reproduce at will, effects and work around.

2015-12-15 Thread Daniel Ouellet
low is still true, but the same scenario with NAT-T will show up, just somewhat less frequently, but still present. Above so far, none. Best, Daniel On 12/11/15 8:51 PM, Daniel Ouellet wrote: > I sure hope this will help. > > ***Setup*** > Two server on 5.8. Establish VPN with IKEDv

Re: Can't build kernel GENERIC.MP on Dell Inspiron E1045

2015-12-15 Thread Daniel Ouellet
On 12/15/15 5:10 PM, Jack J. Woehr wrote: > Just installed 5.8 on an old Dell laptop, cvs'ed src -rOPENBSD_5_8 then > config'ed and tried to build GENERIC.MP: > Any tips? This has to be something silly ... Sure, use snapshots! You can get one already done every single day if you want... ftp:/

Any idea for table replacement configuration in iked.con

2015-12-19 Thread Daniel Ouellet
I am trying to find a more efficient way then creating a long list of policy in iked.conf that would be in in pf using table, but there isn;'t any table in iked.conf. As a simple example if I had this in pf table { 172.16.0.0/16, !172.16.1.0/24, 172.16.1.100 } would match all the /16, but not t

Re: LibreNMS chroot issues

2015-12-27 Thread Daniel Ouellet
> I was wondering if anybody tried running LibreNMS with httpd from the > base and even more fundamentally does httpd from the base support > "unsecure" mode. I read up and down httpd several times but I didn't see > anything about insecure mode. Yes, "unsecure mode" is call Linux. Or FreeBSD the

Lanner NCA-4010D

2017-11-30 Thread Daniel Ouellet
Just for the records as I know I was looking to find a dmesg for them and see if that would run OpenBSD before taking the chance to get them and it might be of interest to others as well. Here it goes with 4 more to come all run well so far. More update later after I test them as routers and see.

Lanner NCA-5210B

2017-11-30 Thread Daniel Ouellet
OpenBSD 6.2 (GENERIC.MP) #0: Thu Oct 12 19:53:18 CEST 2017 r...@syspatch-62-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP real mem = 3428722 (32698MB) avail mem = 33241083904 (31701MB) mpath0 at root scsibus0 at mpath0: 256 targets mainbus0 at root bios0 at mainbus0: SMBIOS rev.

Lanner NCA-5510A

2017-11-30 Thread Daniel Ouellet
OpenBSD 6.2 (GENERIC.MP) #0: Thu Oct 12 19:53:18 CEST 2017 r...@syspatch-62-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP real mem = 68589015040 (65411MB) avail mem = 66503278592 (63422MB) mpath0 at root scsibus0 at mpath0: 256 targets mainbus0 at root bios0 at mainbus0: SMBIOS rev.

Lanner FW-7573B

2017-11-30 Thread Daniel Ouellet
OpenBSD 6.2 (GENERIC.MP) #0: Thu Oct 12 19:53:18 CEST 2017 r...@syspatch-62-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP real mem = 17149325312 (16354MB) avail mem = 16622563328 (15852MB) mpath0 at root scsibus0 at mpath0: 256 targets mainbus0 at root bios0 at mainbus0: SMBIOS rev.

Lanner FW-8759A

2017-11-30 Thread Daniel Ouellet
OpenBSD 6.2 (GENERIC.MP) #0: Thu Oct 12 19:53:18 CEST 2017 r...@syspatch-62-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC.MP real mem = 17104031744 (16311MB) avail mem = 16578637824 (15810MB) mpath0 at root scsibus0 at mpath0: 256 targets mainbus0 at root bios0 at mainbus0: SMBIOS rev.

Re: Lanner NCA-4010D

2017-11-30 Thread Daniel Ouellet
inc.com/products/network-appliances/x86-desktop-network-appliances/nca-1510 > > Besides, how did you buy them? > > Sent from ProtonMail Mobile > > On Fri, Dec 1, 2017 at 05:24, Daniel Ouellet wrote: > >> Just for the records as I know I was looking to find a dmesg fo

Re: EdgeRouter Lite VS Alix2D3

2017-12-04 Thread Daniel Ouellet
On 12/4/17 8:49 AM, Ivo Chutkin wrote: > Hello list, > > When I read OpenBSD could run on EdgeRouter Lite, I give it a try (now > with 6.2 current as of 28.11.2017). > I expected closer performance to Alix, but ERL even do not respond on > console in reasonable times, for example, it takes 10-15 s

Re: EdgeRouter Lite VS Alix2D3

2017-12-04 Thread Daniel Ouellet
On 12/4/17 12:12 PM, Daniel Ouellet wrote: > On 12/4/17 8:49 AM, Ivo Chutkin wrote: >> Hello list, >> >> When I read OpenBSD could run on EdgeRouter Lite, I give it a try (now >> with 6.2 current as of 28.11.2017). >> I expected closer performance to Alix, but ERL

Re: NTP issue on Lanner FW-7526B

2017-12-08 Thread Daniel Ouellet
It is adjusting the time, but your clock is way off, so it try to do it slowly as to not mess any logs, but if you want to adjust it al at once and don't care about that for now rdate -n4 pool.ntp.org Simple. On 12/8/17 9:58 AM, mabi wrote: > Hi, > > I have a new Lanner FW-7526B firewall load

Re: Community-driven OpenBSD tutorials wiki?

2018-01-04 Thread Daniel Ouellet
On 1/4/18 11:46 AM, Marcus MERIGHI wrote: > andreasthu...@gmail.com (Andreas Thulin), 2018.01.04 (Thu) 15:17 (CET): >> Thought I'd create an OpenBSD wiki somewhere, where anyone (especially > >> existing tutorials become outdated, and was thinking that a wiki would >> make updates easier. > > Y

Re: OpenBSD Foundation on HTTPS

2018-02-06 Thread Daniel Ouellet
Come on guys. If you actually donate and click on any links there you would see it bring you to a secure page. No need to have this one https type really there isn't any information you enter on it... I guess the sand is way more think some places then others Must be nice beaches there and

Re: Date of yesterday

2018-04-09 Thread Daniel Ouellet
Here to confuse you even more, there is time zone that have 30 minutes and even 45 minutes differences. https://www.timeanddate.com/time/time-zones-interesting.html Have fun. On 4/9/18 4:44 PM, Daniel Ouellet wrote: > On 4/9/18 4:36 PM, Stephane HUC "PengouinBSD" wrote: >>

Re: Date of yesterday

2018-04-09 Thread Daniel Ouellet
On 4/9/18 4:36 PM, Stephane HUC "PengouinBSD" wrote: > what? > > please, explain-me! EDT EST for example. Some days are even 82800 long. Some time zone even have 1/2 hour if these still exists, so the would be 84600 or 88200.

Re: Pausing/Freezing issues with Protectli FW4B

2023-08-12 Thread Daniel Ouellet
On 8/11/23 7:06 PM, Tim Baumgard wrote: On Fri, Aug 11, 2023 at 5:56 PM Stuart Henderson wrote: On 2023-08-11, Tim Baumgard wrote: I'm having an issue with my Protectli FW4B that's become more of a problem lately. Essentially, it's the same thing that this person [0] encountered. IIRC thos

Re: Update from 6.5 to 7.3

2023-09-08 Thread Daniel Ouellet
I did a few from 6.6 to 7.3 and it was real easy. The source I used was: http://ftp.eu.openbsd.org/pub/OpenBSD/ Looks like this it the one that have the most files from the older version. They have all the files from 2.0 and up. (; Nice if you want to see how the system evolved over time. (;

Re: veb and vport on apu2 -- config feedback

2023-09-08 Thread Daniel Ouellet
Hi, A few things here. Comcast DO NOT use 9000 mtu, so don't try to use that. They sadly ONLY support 1500. if you force 9000 mtu, you will only create fragments. You can find it if you search for it as well. https://forums.xfinity.com/conversations/your-home-network/mtu-size/602db12cc5375f0

Re: Upgrading, release by release, from 6.8 to 7.4 -- my experience

2023-11-15 Thread Daniel Ouellet
Hi Austin, Quiet for many years. Nice to see you again from the time of CD Sales, etc. (; You are 100% correct that the sysupgrade kick ass big time! Anyway, just one thing on your upgrade and all. Not sure if your version 6.8 was also an upgrade form before or a clean install. The reason

Ideas for a mix of Arista Leyer 3 switches and OpenBSD BGPd setup.

2023-11-16 Thread Daniel Ouellet
I am looking at ideas to improve the setup, or if you do this, your experience with it. The setup have to account for so far. 4 main transit access in different locations and 249 peering setup in major data center for public and private peering. Currently ~945,000 IPv4 routes, ~196,000 IPv6

Re: pf queues

2023-11-29 Thread Daniel Ouellet
yes, all this can be make without hierarchy, only with priorities(because hierarchy it's priorities), but who and why decided that eight would be enough? the one who created cbq- he created it for practical tasks. but this "hateful eight" and this "flat-earth"- i don't understand what use they

Re: pf queues

2023-11-30 Thread Daniel Ouellet
On 11/29/23 6:47 PM, Stuart Henderson wrote: On 2023-11-29, Daniel Ouellet wrote: yes, all this can be make without hierarchy, only with priorities(because hierarchy it's priorities), but who and why decided that eight would be enough? the one who created cbq- he created it for prac

Getting stuck on trying a fresh install to 7.4

2023-12-06 Thread Daniel Ouellet
Hi, Hopefully you may have a clue stick to offer me. I try to do a fresh install on servers that run 6.7 to 7.4, but no matter what I try, I get stuck. I tried previous version and I was able to load 7.3. DMESG below for the bsd.rd. I try BIOS change for EFI ONLY, or Legacy & EFI, or Legac

Re: Getting stuck on trying a fresh install to 7.4

2023-12-06 Thread Daniel Ouellet
On 12/6/23 3:26 PM, Crystal Kolipe wrote: On Wed, Dec 06, 2023 at 03:08:09PM -0500, Daniel Ouellet wrote: I try to do a fresh install on servers that run 6.7 to 7.4, but no matter what I try, I get stuck. I tried previous version and I was able to load 7.3. DMESG below for the bsd.rd. When

Re: Getting stuck on trying a fresh install to 7.4

2023-12-06 Thread Daniel Ouellet
Any suggestion woudl be greattly appreciated. Old boot loaders cannot boot 7.4 kernels. Upgrade your 6.7 system to 7.3 first (the usual advice to avoid skipping releases during upgrades applies). Then upgrade to 7.4. I didn't care what's on it now. All fresh install will do. I have 22 to do. :

Re: Getting stuck on trying a fresh install to 7.4 (solved)

2023-12-06 Thread Daniel Ouellet
On 12/6/23 3:42 PM, Daniel Ouellet wrote: Any suggestion woudl be greattly appreciated. Old boot loaders cannot boot 7.4 kernels. Upgrade your 6.7 system to 7.3 first (the usual advice to avoid skipping releases during upgrades applies). Then upgrade to 7.4. I didn't care what's

Re: Getting stuck on trying a fresh install to 7.4

2023-12-07 Thread Daniel Ouellet
On 12/7/23 7:37 AM, Stuart Henderson wrote: On 2023-12-06, Daniel Ouellet wrote: Any suggestion woudl be greattly appreciated. Old boot loaders cannot boot 7.4 kernels. Upgrade your 6.7 system to 7.3 first (the usual advice to avoid skipping releases during upgrades applies). Then upgrade to

Re: Getting stuck on trying a fresh install to 7.4

2023-12-08 Thread Daniel Ouellet
On 12/8/23 3:34 AM, Stuart Henderson wrote: On 2023-12-07, Daniel Ouellet wrote: On 12/7/23 7:37 AM, Stuart Henderson wrote: On 2023-12-06, Daniel Ouellet wrote: Any suggestion woudl be greattly appreciated. Old boot loaders cannot boot 7.4 kernels. Upgrade your 6.7 system to 7.3 first

Re: Cannot PXE Boot PC Engines APU.1D4

2023-12-31 Thread Daniel Ouellet
I don't have any problem with many of my pc engine. But if you want something else I used these now because they support Core Boot. https://protectli.com/ I am not going back to BIOS that are not right and not supported after a year. No thanks! On 12/31/23 8:56 PM, Kenneth Hendrickson w

Re: Cannot PXE Boot PC Engines APU.1D4

2024-01-01 Thread Daniel Ouellet
On 1/1/24 3:12 PM, Stuart Henderson wrote: On 2024-01-01, Kenneth Hendrickson wrote: --- On Monday, January 1, 2024 at 06:10:57 AM EST, Stefan Sperling wrote: Booting 7.4 or -current kernels with an old pxeboot binary won't work. Make sure that both the kernel image and pxeboot originate

Re: Installing shellinabox on OpenBSD

2024-02-12 Thread Daniel Ouellet
Just use Putty if you want a window ssh client. It exists for more then 25 years now. and it is still supported. Just maintain your systems via ssh and move on. Putty also allow you to use ssh keys as well. I am not sure why people say they can't have a safe ssh client for window... On 2/1

  1   2   3   4   5   6   7   8   9   10   >