Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread zachm1996
On Sunday, February 9, 2020 at 3:29:26 AM UTC-6, zach...@gmail.com wrote: > > On Saturday, February 8, 2020 at 8:09:05 PM UTC-6, Marek > Marczykowski-Górecki wrote: >> >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA256 >> >> On Fri, Feb 07, 2020 at 02:13:56PM -0800, brend...@gmail.com wrote:

Re: VS: [qubes-users] Re: 2 new Intel vulnerabilites

2020-02-09 Thread reggelo
> > I've got the same exact setup and same issues with suspend/resume :( > > Haven't found any solution so far, have you? > I have tried with 4.1 (Build4.1-20200131) but the result is the same: suspend/resume not working :( With Debian (Bullseye) works!

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread zachm1996
On Saturday, February 8, 2020 at 8:09:05 PM UTC-6, Marek Marczykowski-Górecki wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Fri, Feb 07, 2020 at 02:13:56PM -0800, brend...@gmail.com > wrote: > > On Friday, February 7, 2020 at 9:35:25 PM UTC, zach...@gmail.com wrote: >

Re: [qubes-users] sys-firewall based on debian-10-minimal not recognized

2020-02-09 Thread 'awokd' via qubes-users
Sven Semmler: > Hi, > > I created a sys-firewall based on debian-10-minimal: > > * qvm-clone debian-10-minimal deb-10-sys-firewall > * qvm-create --template deb-10-sys-firewall --label blue dvm-sys-firewall > * qvm-prefs dvm-sys-firewall template_for_dispvms True > * qvm-create --class DispVM

Re: [qubes-users] Tips for configuring Qubes firewall?

2020-02-09 Thread 'awokd' via qubes-users
fiftyfourthparal...@gmail.com: > I'm new to Qubes and I've nearly finished setting up my machine for it's > first network connection (purged all Fedora, enabled AppArmor, disabled > passwordless root, etc.) > > Firewalls are an enigma to me but I know they're super important, so I just >

Re: [qubes-users] Can't update or install anything in dom0 last two days

2020-02-09 Thread 'awokd' via qubes-users
0...@tuta.io: > Hi. > > > This repos unreachable: > > baseurl=http://download.fedoraproject.org/pub/fedora/linux/releases/25/Everything/x86_64/os/ > baseurl=http://download.fedoraproject.org/pub/fedora/linux/updates/25/x86_64 > > > Can you recommended any another good dom0 trusted fedora

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread 'awokd' via qubes-users
Claudio Chinicz: > All the idea behind this is to keep your keys in a safe place (VM without > network), isolated from your application VM. > > I've installed the work-gpg (keys vault) and created a mail VM with > Thunderbird and Enigmail. > > While Enigmail cannot create new keys on the vault

Re: [qubes-users] How to install software in an AppVM without loosing persistence?

2020-02-09 Thread unman
On Sun, Feb 09, 2020 at 05:16:09PM +0100, dhorf-hfref.4a288...@hashmail.org wrote: > On Sun, Feb 09, 2020 at 12:49:39PM -, 'Monsieur DuPont' via qubes-users > wrote: > > That looks like a good solution, unfortunately I couldn't find any easy way > > to > > do it online (I have no experience

Re: [qubes-users] How to install software in an AppVM without loosing persistence?

2020-02-09 Thread 'Monsieur DuPont' via qubes-users
Depending on what the software is, and how it is installed, you may also be able to install to one of the persistent directories under /rw - /home/user (obviously) or under /usr/local That looks like a good solution, unfortunately I couldn't find any easy way to do it online (I have no

Re: [qubes-users] No Internet through sys-net and sys-firewall in qubes 4.0

2020-02-09 Thread 'awokd' via qubes-users
Taehwan Kim: > In sys-net > 4: vif16.0: mtu 1500 qdisc noop state DOWN group > default qlen 32 <-- I think this is sys-firewall connected to sys-net > > in sys-firewall > ip addr | grep -i cast > > 2: eth0: mtu 1500 qdisc mq state UP group > default qlen 1000 > 3: vif18.0: mtu 1500 qdisc

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread brendan . hoar
On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com wrote: > > > Has anyone tried utilizing the xen command line options to mask bits in > the cpuid, in particular section 1.2.35 cpuid_mask_ecx)? > > The man page below says that "Settings applied here take effect globally, >

[qubes-users] Re: Upgrade to 16 GB RAM for an X230

2020-02-09 Thread ggg397
I have posted on the other sites. Perhaps the best answer I will get is when I contact Crucial itself, during the week. I also wanted to ask info from those who are doing the same thing. Any comment about which device you used to put Core Boot onto laptop? I see of the programming

Re: [qubes-users] Where are the VM NICs?

2020-02-09 Thread 'awokd' via qubes-users
Ulrich Windl: > I have a question on the networks used for VM communication: > I'm using Xen PVMs, and then I see the virtual NICs a VM has in xentop (for > example). > However in Qubes OS the number of NICs is zero. So where are those NICS and > virtual LANs configured? I also could not find a

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread Claudio Chinicz
‎Thanks, I now better understand the concepts. On Sunday, 9 February 2020 15:41:39 UTC+2, awokd wrote: > > Claudio Chinicz: > > All the idea behind this is to keep your keys in a safe place (VM > without network), isolated from your application VM. > > > > I've installed the work-gpg (keys

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread Claudio Chinicz
Hi, thanks. It is now much clearer the inner workings of split gpg. On Sunday, 9 February 2020 15:49:45 UTC+2, qubes...@riseup.net wrote: > > Claudio Chinicz wrote: > > All the idea behind this is to keep your keys in a safe place (VM > > without network), isolated from your application VM. >

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Brendan Hoar
On Sun, Feb 9, 2020 at 9:15 AM Claudia wrote: > From linuxreviews.org: > "There have been reports of RDRAND issues after resuming from suspend on > some AMD family 15h and family 16h systems. [...] RDRAND support is > indicated by CPUID Fn0001_ECX[30]. This bit can be reset by clearing > MSR

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
> marmarek: > This is a very bad idea to "fix" it. Those missing/changed CPUID bits later > on will cause issues. > And given most of the microcode updates recently are about speculative > execution, missing those > features will make the host vulnerable to those issues again. There are >

Re: [qubes-users] How to add swap space

2020-02-09 Thread dhorf-hfref . 4a288f10
On Sun, Feb 09, 2020 at 02:13:53PM +, 'awokd' via qubes-users wrote: > https://github.com/Qubes-Community/Contents/blob/master/docs/misc/iaq.adoc#how-can-i-provision-a-vm-with-a-largernon-standard-swap-and-tmp for "up to 10GB" and on a modern qubes with lvm-pool there is also ... just start

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread qubes-lists
Claudio Chinicz wrote: > All the idea behind this is to keep your keys in a safe place (VM > without network), isolated from your application VM. > > I've installed the work-gpg (keys vault) and created a mail VM with > Thunderbird and Enigmail. > > While Enigmail cannot create new keys on the

Re: [qubes-users] Installation with VT-d disabled; need to redo?

2020-02-09 Thread 'awokd' via qubes-users
Ulrich Windl: > Hi! > > I'm new to Qubes OS and to this list: I installed QUbesOS on an 64GB USB > stick. That took almost 3 hours! (I filed some issues at github, too) > My problem was that I could not find the VT-d setting in the BIOS (see also >

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread unman
On Sun, Feb 09, 2020 at 01:49:00PM +, qubes-li...@riseup.net wrote: > Claudio Chinicz wrote: > > All the idea behind this is to keep your keys in a safe place (VM > > without network), isolated from your application VM. > > > > I've installed the work-gpg (keys vault) and created a mail VM

Re: [qubes-users] Re: Upgrade to 16 GB RAM for an X230

2020-02-09 Thread unman
On Sun, Feb 09, 2020 at 06:51:38AM -0800, ggg...@gmail.com wrote: > I have posted on the other sites. Perhaps the best answer I will get is > when I contact Crucial itself, during the week. I also wanted to ask info > from those who are doing the same thing. > > Any comment about which

Re: [qubes-users] Is Qubes Split GPG safe?

2020-02-09 Thread unman
On Sun, Feb 09, 2020 at 02:31:43PM +, unman wrote: > On Sun, Feb 09, 2020 at 01:49:00PM +, qubes-li...@riseup.net wrote: > > Claudio Chinicz wrote: > > > All the idea behind this is to keep your keys in a safe place (VM > > > without network), isolated from your application VM. > > > > >

Re: [qubes-users] How to install software in an AppVM without loosing persistence?

2020-02-09 Thread dhorf-hfref . 4a288f10
On Sun, Feb 09, 2020 at 12:49:39PM -, 'Monsieur DuPont' via qubes-users wrote: > That looks like a good solution, unfortunately I couldn't find any easy way to > do it online (I have no experience in Linux terminal kung fu). So any help > with that regards would be deeply appreciated,

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread brendan . hoar
On Sunday, February 9, 2020 at 3:19:34 PM UTC, Claudia wrote: > > > marmarek: > > This is a very bad idea to "fix" it. Those missing/changed CPUID bits > later on will cause issues. > > And given most of the microcode updates recently are about speculative > execution, missing those > > features

[qubes-users] lid close = system dead.

2020-02-09 Thread haaber
Hi experience (as well) problems since that last dom0 update. Journalctl mentions dom0 systemd-sleep: suspending system ... dom0 kernel: PM : suspend entry (deep) -- reboot -- which suggests that lid-open does not awake the system. Did someone already find a solution to that? It did work

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
February 9, 2020 9:52 AM, zachm1...@gmail.com wrote: > On Sunday, February 9, 2020 at 3:29:26 AM UTC-6, zach...@gmail.com wrote: > >> On Saturday, February 8, 2020 at 8:09:05 PM UTC-6, Marek >> Marczykowski-Górecki wrote: >>> If that's about something else, then fixing it would require finding

Re: [qubes-users] How to add swap space

2020-02-09 Thread 'awokd' via qubes-users
billol...@gmail.com: > > I need to add swap space to a VM, but it's not clear to me how to do it. > If this were "normal" linux, I'd just add a swap file, but I don't know if > I need can do that in dom0, and if that translates to available swap space > in my VMs. The last time I played with

Re: [qubes-users] Tips for configuring Qubes firewall?

2020-02-09 Thread fiftyfourthparallel
Thanks for taking the time to reply! -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To view this discussion on the web

Re: [qubes-users] create custom image result in problems with python-blivet sources

2020-02-09 Thread user74293
Hello. thanks for your hints, but i need a little more help. The actual versions in fc31 are: - python3-blivet-3.1.5-2.fc31.noarch.rpm - python3-blivet-3.1.7-1.fc31.noarch.rpm If i look for a matching storaged-project/blivet version then i don't find the file blivet-xxx-tests.tar.gz. The only

Antw: [EXT] Re: [qubes-users] Q: is Qubes OS a "portable" installation?

2020-02-09 Thread Ulrich Windl
>>> unman schrieb am 08.02.2020 um 02:10 in >>> Nachricht <21911_1581124220_5e3e0a7c_21911_3958_1_20200208011020.ga...@thirdeyesecurity.or >: > On Fri, Feb 07, 2020 at 11:06:40PM +0100, Ulrich Windl wrote: >> Hi! >> >> Being new to Qubes OS on an USB stick, I wonder whether the installation

[qubes-users] VLC gets black when maximized

2020-02-09 Thread Guerlan
My VLC gets all black when maximized and the video wont start playing again, I have to close it. I'm trying on debian9. Did someone have this problem? -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop

Re: [qubes-users] sys-firewall based on debian-10-minimal not recognized

2020-02-09 Thread Sven Semmler
On Sun, Feb 09, 2020 at 01:46:12PM +, 'awokd' via qubes-users wrote: > Maybe it doesn't like the "disposable" part? Try it with a regular AppVM > based on that same minimal template. I did: makes no difference. Also I've been running debian-based and fedora-based disposable sys-firewall for

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Claudia
February 9, 2020 8:52 PM, "Marek Marczykowski-Górecki" wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Sun, Feb 09, 2020 at 09:28:13AM -0800, brendan.h...@gmail.com wrote: >> On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com wrote: >>> >>> >>> Has anyone

[qubes-users] Confidential email from orpheu

2020-02-09 Thread orpheu via qubes-users
Hello,You have just received a confidential email via Tutanota (https://tutanota.com). Tutanota encrypts emails automatically end-to-end, including all attachments. You can reach your encrypted mailbox and also reply with an encrypted email with the following link:Show encrypted emailOr paste this

Re: [qubes-users] Re: Upgrade to 16 GB RAM for an X230

2020-02-09 Thread tetrahedra via qubes-users
On Sun, Feb 09, 2020 at 03:37:45PM +, unman wrote: Any other suggestions of fixes, upgrades, or tests to make? Replace Intel wifi with Atheros. What's the benefit of the Atheros chip over Intel? -- You received this message because you are subscribed to the Google Groups "qubes-users"

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread zachm1996
On Sunday, February 9, 2020 at 2:52:57 PM UTC-6, Marek Marczykowski-Górecki wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > On Sun, Feb 09, 2020 at 09:28:13AM -0800, brend...@gmail.com > wrote: > > On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com > wrote:

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread 'awokd' via qubes-users
Claudia: >> marmarek: >> For this particular case (microcode included in BIOS newer than in OS), I >> see two options: make >> BIOS (coreboot, right?) apply microcode update on resume too, or include >> newer microcode in OS. > > I want to make one thing clear: I am **not** suggesting this

Re: [qubes-users] Re: R4 system requirements; AMD compatibility?

2020-02-09 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Sun, Feb 09, 2020 at 09:28:13AM -0800, brendan.h...@gmail.com wrote: > On Sunday, February 9, 2020 at 5:25:56 PM UTC, brend...@gmail.com wrote: > > > > > > Has anyone tried utilizing the xen command line options to mask bits in > > the cpuid, in