Re: DNS advertisement in RA - rtadvd(8) part

2010-09-12 Thread Martin Pelikán
2010/9/12, Stefan Sperling s...@openbsd.org: I think we'll need a way to configure nameserver addresses from rtadvd.conf. Reading nameserver information from resolv.conf may be useful in certain setups, but it won't make everyone happy. What if the nameserver in resolv.conf is a loopback

PF misbehaving counters + code reuse

2010-09-01 Thread Martin Pelikán
Hello tech@ I've noticed different behavior of pf rule counters between IPv4 and IPv6. The easiest ruleset would look like: block match on em0 inet6 tag potazmo match on em0 inet tag ausfahrt pass on em0 from any to any tagged potazmo pass on em0 from any to any tagged ausfahrt where ping4s are

Re: DNSSEC and OpenBSD default BIND

2010-07-19 Thread Martin Pelikán
And if I use the DLV anchor, domains under .org TLD are not reachable (because, if I understand correctly, the key is signed with RSASHA1-NSEC3-SHA1 and Bind-9.4 doesn't support it). You're lucky that an error raised for you. I had to stop using DNSSEC because of misinterpretation NSEC3 too,

Re: ospf6d - /63 prefix causes livelock (partial diff)

2010-06-09 Thread Martin Pelikán
2010/6/9, claudio clau...@openbsd.org: That sounds like a bad nexthop. Can you run route -n monitor next to ospf6d and check the output (especially check the nexthop). You were right. Details follow. Please make sure that you run with -current ospf6d. I do, however, the problematic

Re: ospf6d - /63 prefix causes livelock (partial diff)

2010-06-09 Thread Martin Pelikán
2010/6/9, claudio clau...@openbsd.org: Wow! Did I mention that I hate IPv6? Noted. I kind of like it :-) So the problem is that you end up with a non link local address as nexthop. That is IIRC not allowed by the OSPFv3 RFC but anyway it would be better to check if the nexthop is link local

Re: routing commands make the system crash

2010-05-21 Thread Martin Pelikán
Hello everyone, you were right, it was broken. rt_if_remove_rtdelete was looking in wrong domain and the right one contained freed stuff. I'm not sure whether what I've done is correct and even less sure about what struct ifnet's if_rdomain is for. Can someone clarify this for me? (or through some

Re: 4.7 pf

2010-04-30 Thread Martin Pelikán
2010/4/30, Rod Whitworth glis...@witworx.com: Quite often we have people wanting a home firewall and these folk are the ones who will rarely do binat. Besides that all the examples of NAT in the pf.conf manpage and the upcoming pf FAQ use the match action without ever explaining why. (I'll

[patch] czech keyboard layout

2010-04-05 Thread Martin Pelikán
Hi, sorry for duplicity, blambert@ redirected me here. And the files in the original mail were removed. I've recently written czech keyboard layout to the console. It's basically standard cz_qwertz layout with every character that one might need from the us layout hidden under AltGr in the