openbsd-misc mailing list

FromSubjectsort iconDate
David Brohall
Poptop

Does anyone know a working poptop howto or have some configuration
files that works for OBSD 4.2?

Shall I disable GRE in kernel?
I tried but then poptop didn't install at all.
I also get some kind of IPv6 error even if I've diabled ipv6 in
ppp.conf.

Cheers,
David

Nov 14, 4:00 pm 2007
Bryan Irvine
Re: Poptop

Should be the same as in 4.1. A tip though, use a different IP range
not in use on your LAN. I had issues with machines not knowing where
to route before I did that.

--Bryan

Nov 14, 5:01 pm 2007
Christophe HAUSER
Macbook Pro

Hello,

I have some troubles booting OpenBSD 4.2 Install CD on a Macbook Pro
R1.1 (Core Duo T2400@1.83 )
I tried both bsd.rd and bsd.mp without success.
I didn't have any relevant messages.

bsd.rd hangs on :
npx0 at isa0 port 0xf0/16 : reported by CPUID ; using exception 16
biosmask ffff netmask ffff ttymask ffff
rd0 : fixed, 3800 blocks

while bsd.mp hangs on :
pctr : 686-class user-level performance counter enabled
mtrr Pentium Pro MTRR Support

I'm interested in any successful experienc...

Nov 14, 12:25 pm 2007
Christophe HAUSER
Re: Macbook Pro

Christophe HAUSER wrote:

Ok I just need to enable ACPI (boot -c).
Sorry !

Regards,

--
Christophe HAUSER | http://kereoz.free.fr
**
Association Actux
http://actux.tuxfamily.org
**

Nov 14, 2:02 pm 2007
kintaro oe
PF load balance: ipsec vpn + ftp issue

Hi Guys,

Hola..Good day!

I would like to ask for an advice about my
firewall/nat/pf box.

* network layout:

isp1---->|firewall|-->switch|----> servers
isp2---->|nat/pf | |----> clients

* pf.conf - http://www.openbsd.com/faq/pf/pools.html ;
as my reference i just copy this config file and
change the macro:

lan_net = "192.168.0.0/24"
int_if = "dc0"
ext_if1 = "fxp0"
ext_if2 = "fxp1"
ext_gw1 = "68.146.224.1"
ext_gw2 = "142.59.76.1"

# nat outgoing connection...

Nov 14, 11:17 am 2007
Unix Fan
Re: OT: OpenBSD on Asus eeePC

> Any other requests?

I personally would like to see a -current dmesg of this system... if you don't mind posting it here for us geeks to drool over :)

-Nix fan.

Nov 14, 11:08 am 2007
Kleber Rocha
PF new default flags S/SA problems

Hello,

I had many problems with my rules in PF, the new default flags S/SA,
causes problems in rules that are not written using flags, several
rules not match in OpenBSD 4.2.

Nov 14, 9:42 am 2007
Stuart Henderson
Re: PF new default flags S/SA problems

Well, OpenBSD 4.1, actually...

The old method results in nasty hard-to-diagnose problems for
TCP options used by some modern OS.

Think of it as a good opportunity to rewrite and clean your ruleset.

Nov 14, 10:26 am 2007
Jona Joachim
Re: OT: OpenBSD on Asus eeePC

According to Wikipedia it has a slot for SD and SDHC cards.

Best regards,
Jona

--
"I am chaos. I am the substance from which your artists and scientists
build rhythms. I am the spirit with which your children and clowns
laugh in happy anarchy. I am chaos. I am alive, and tell you that you
are free." Eris, Goddess Of Chaos, Discord & Confusion"

Nov 14, 8:58 am 2007
Evgeniy Sudyr
Cyrus-SASL2-mysql problem on 4.2

Hello misc,

I installed cyrus-sasl-2.1.22p1-mysql from packages and trying make it
working, but during testsaslauthd queries I not get any results :(.
I enabled log queries in mysql but there is no connection attempts
from saslauthd to needed table (no connection, no auth, nothing).

As described in documentation I created smtpd.conf and pit it to
needed dir.

# cat /usr/local/lib/sasl2/smtpd.conf
pwcheck_method: auxprop
auxprop_plugin: sql
sql_engine: mysql
mech_list: PLAIN LOGIN
sql_user...

Nov 14, 7:23 am 2007
Antoine Jacoutot
Re: Cyrus-SASL2-mysql problem on 4.2

If you use auxprop as pwcheck_method, then why are you testing with
testsaslauthd?
Also, did you install the sasl2 of postfix?

--
Antoine

Nov 14, 9:12 am 2007
David Zeillinger
Re: identifying sparse files and get ride of them trick avai...

Hi Daniel,

Did you happen to investigate why rsync -S is taking so much time? If it
doesn't deal with sparse file the way one expects, this option is probably
broken. Also have you already tried something like the advice in
http://lists.samba.org/archive/rsync/2003-August/007000.html ?

Anyway, I think the way to go is using tar. It preserves the sparseness
property of the files, so something like this could work: If you tar the
file without using compression, you would get a file the size of...

Nov 14, 8:22 am 2007
Daniel Ouellet
Re: identifying sparse files and get ride of them trick avai...

It takes a long time because it needs to process the full files anyway.

That goes against the first goal of the question to find the sparse
files for example. And tar doesn't remove the use of resource to tar it
anyway on either side and rsync also can use compression on the fly as
well witch it is in use as well already. And I am not sure it would work
anyway as if you think about it for a minute really. What's the
difference to copy a sparse file via scp, rsync or untar it. Why would
scp...

Nov 14, 4:58 pm 2007
Richard Wilson
Hardware for PF - more general questions

I have been pondering for some time getting a new core router, and a
recent question on HP Procurves vs Soekris boxes has kicked me into
thought. I have some more general questions:

I recall hearing tell (on here I think) that amd64 is a better arch for
routing, because of better interrupt handling or somesuch. Is this true?

I am under the impression that if I want to do BGP, I need 1GB of RAM
for the routing tables and whatnot. Given RAM is so cheap, and I'd like
some future-proofing, is there a...

Nov 14, 6:11 am 2007
Stuart Henderson
Re: Hardware for PF - more general questions

OpenBSD/amd64 used to be worse than OpenBSD/i386 on the same hardware,
I'm not sure about now - I haven't seen any recently published i386 vs

Depends which routes you take. You probably want 1GB if you receive
full routes. Given there's no cisco tax on RAM here, this is quite

bgpd uses a bunch of memory during 'bgpctl reload'; my normally
<100Mb RDE processes on full table routers rise to around 300M while
that happens - free ram on a 1G RAM box drops to around 480M with
views of 230k + 66k ...

Nov 14, 7:32 am 2007
Clint Pachl
Slow Performance on Encrypted svnd

Reading through the archives I have found several people say that
encrypting via an svnd device isn't much slower than writing directly to
a raw unencrypted disk. While I found this to be true for svnd devices
backed by files, svnd devices backed by whole disks and disk partitions
are extremely slow. I have tried tuning many parameters, namely the
fragment and block size and the cylinders per group in the disklabel
associated with the svnd, but nothing has improved the performance.

I am runni...

Nov 14, 6:02 am 2007
knitti
Re: Slow Performance on Encrypted svnd

Instead of e.g. /dev/sd0a try /dev/rsd0a. I didn't try with svnd, but
when copying partitions with dd I use this.

--knitti

Nov 14, 7:41 am 2007
Clint Pachl
Re: Slow Performance on Encrypted svnd

I tried that, but like I said fdisk complained when the svnd device is
associated with the raw direct access disk device. For example

# vnconfig -k svnd0 /dev/rwd1c

# fdisk -c 19457 -h 255 -s 63 -i svnd0 # disk CHS
fdisk: error initializing MBR: bad address

# fdisk -c 19456 -h 254 -s 63 -i svnd0 # OpenBSD partition CHS
fdisk: error initializing MBR: bad address

# fdisk -i svnd0
Warning CHS values out of bounds only saving LBA values
fdisk: error initializing MBR: bad address

Nov 14, 4:51 pm 2007
knitti
Re: Slow Performance on Encrypted svnd

well, the 'c' slice is a bit 'special', perhaps try an 'a' slice filling the
whole disk but the first track? After all, I think its weird not to have
an MBR etc. on the real disk. (Which doesn't mean that I couldn't
imagine that).

--knitti

Nov 14, 6:36 pm 2007
Clint Pachl
Re: Slow Performance on Encrypted svnd

I understand that the "c" partition is special. But when the entire disk
(i.e. wd0c) is just acting as a storage backend and the svnd device is
the front end, I don't think it matters. It's not like I'm going to be
running newfs or fsck on the actual disk. Anyway, I have tried on the
"a" partition too, but I get the same results.

Like I said, everything works fine if I use the buffered device,
wd0[ac], not rwd0[ac], but it is so slow. dd'ing to the unbuffered
device is much faster than dd'i...

Nov 14, 6:54 pm 2007
Mikel Lindsaar
Best way to automate administration of multiple servers

Hello all,

I've been googling around for some answers and I thought I would ask
the list as well.

In the past I have used different compters for different tasks. I
would have many different installs of OpenBSD on many different
platforms.

However, i am moving some stuff into a data center and am getting a
blade server with 10 blades (up to 20 total). I have been playing
with this and it is running great, but as each blade has exactly the
same specs (same drive, ram, processor etc) I was won...

Nov 14, 4:45 am 2007
Edd Barrett
Re: Best way to automate administration of multiple servers

Hi,

The multixterm program that comes with expect is useful for ssh'ing to
lots of machines and running the same commands on them all.

Unfortunately vi has stopped working for me in multixterm. Might be
something to do with the value of $TERM.

--
Best Regards

Edd

---------------------------------------------------
http://students.dec.bournemouth.ac.uk/ebarrett

Nov 14, 10:30 am 2007
Will Maier
Re: Best way to automate administration of multiple servers

See also sysutils/clusterit, which has several tools useful for this
purpose. I use dsh to run oneliners on groups of machines, though
you can use it interactively, too.

--

o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net |
*------------------[ BSD Unix: Live Free or Die ]------------------*

Nov 14, 10:52 am 2007
Will Maier
Re: Best way to automate administration of multiple servers

cfengine[0] (which we use at work to manage ~500 Linux machines) or
radmind (which I use at home to manage my OpenBSD servers,
workstations and laptops).

There are at least two schools of thought on how one should manage >
1 machine. cfengine is the most popular convergent tool, where you
specify an ideal state using a declarative language and the clients
iterate towards that state. radmind is the most useful congruent
tool, where you specify (or directly imply) the exact sequence of
operatio...

Nov 14, 8:19 am 2007
Susan Brown
your website review

Dear Misc:
We can increase your monthly web traffic and get you the best position on
every major
search engine guaranteed never to move (ex: Yahoo!, Google, MSN, AltaVista,
etc.). No
gimmicks. No flashy sales pitch, 100% guarantee. If you want to increase
your online
business, we will get you the results. For a free informative consultation
and site review
email us at susanbrown90@gmail.com . List all the site(s) you want reviewed
and include
how we can reach you.
Sincerely,
Susan Brown
e...

Nov 14, 4:42 am 2007
Didier Wiroth
win32-codecs, avi and amd64 question

Hello,

I'm currently running current i386 on my amd64 processor.
I'm considering to move to the amd64 distribution but I noticed that the
win32-codecs package is only for i386.

Is there currently a win32-codecs alternative for amd64 or is it possible to
watch avi (+/- all codecs) movies on amd64?

Thank you very much!
Didier

Nov 14, 3:41 am 2007
Paul Irofti
Re: win32-codecs, avi and amd64 question

I've been using mplayer on amd64 for more than a year now and played
various formats and encodings. The only problems I encountered were with
newer wmf formats (which is usually poor quality anyway and quite often
some `funny clip' you receive from your local oha user group).

Nov 14, 8:12 am 2007
Girish Venkatachalam
Re: win32-codecs, avi and amd64 question

mplayer plays every damn format out there. :)

It works quite well on OpenBSD though there are rough edges.

Try some advanced option of mencoder and boom...

Anyway I better shut up or send patches.

As to win32codecs working on amd64 if you can run them under a chroot
jail and try 32 bit emulation it might work.

Hey I am talking thro' my hat and you know what that means.

But I have played several video formats(avi, wmv...) without the closed
source win32codecs package.

I wonder why p...

Nov 14, 7:10 am 2007
Janne Johansson
Re: win32-codecs, avi and amd64 question

On which OS would that be?

Nov 14, 9:43 am 2007
Jacob Meuser
Re: win32-codecs, avi and amd64 question

IMO vlc has higher quality playback of most media, can do things
mplayer can't, has a nicer ui, etc, etc ...

--
jakemsr@sdf.lonestar.org
SDF Public Access UNIX System - http://sdf.lonestar.org

Nov 14, 9:44 am 2007
Girish Venkatachalam
Re: win32-codecs, avi and amd64 question

UI?

Well I am a command line person.

mplayer cannot understand DVD menus. That is the only problem mplayer
has IMHO.

I honestly tried vlc. But it was too GUI oriented, all sorts of ugly
output like KDE and other C++ junk out there...

Now I again it is my opinion.

Can you tell me what vlc can do that mplayer can't?

Have you tried to "study" mplayer's man pages, the html documentation
and stuff?

It takes a long time to learn but once learnt you start feeling that it
is the best th...

Nov 14, 10:43 am 2007
Antoine Jacoutot
Re: win32-codecs, avi and amd64 question

I committed a workaround a couple of days ago that might help.
Cheers!

--
Antoine

Nov 14, 7:52 am 2007
Girish Venkatachalam
Re: win32-codecs, avi and amd64 question

Wow! That is great news. :)

I specifically had problems with DVD creation and creating a video with
still pictures.

Thanks. I shall test if I get time.

Best,
Girish

Nov 14, 10:44 am 2007
Jacob Meuser
Re: win32-codecs, avi and amd64 question

try playing the movies with ffplay from the ffmpeg package. if
that can do something useful, then you don't need win32-codecs.

as far as media players, I prefer vlc or kaffeine.

--
jakemsr@sdf.lonestar.org
SDF Public Access UNIX System - http://sdf.lonestar.org

Nov 14, 4:48 am 2007
Jason George
Re: HP Procurve or Soekris w. OpenBSD ?

These look like an updated version of the embedded machines I bought from
Portwell a few years ago. (2GHz P4 Celeron, 4 x em + 2 x fxp, CF, etc, etc)

Nov 14, 3:02 am 2007
Rafał Brodewicz
Mising dependencies expat.8.0

Hello.
I'm trying to add vim package and I'm getting following error:

Can't install gettext-0.14.6p0: lib not found expat.8.0
Dependencies for gettext-0.14.6p0 resolve to: libiconv-1.9.2p3
Full dependency tree is libiconv-1.9.2p3
Can't install vim-7.1.33-no_x11: can't resolve gettext-0.14.6p0

I didn't find expat.8.0 on any server.
So, is this dependency ok?

Regards.

--
Rafal Brodewicz
raff@brodewicz.pl

Nov 14, 2:46 am 2007
Daniel Ouellet Nov 14, 2:55 am 2007
Linden Varley
ospfd errors

Hi,

I was wondering if anyone could offer any solution to this OSPFD error
when it starts up:

"ospfd[11601]: send_packet: error sending packet on interface em0: No
route to host"

It says there is no route to host for every interface defined in ospfd.conf

This is using the default config on an OpenBSD 4.0 amd64 install.

(Note, ip forwarding and ip multicast forwarding are enabled)

Thanks,
Linden.

Nov 14, 1:11 am 2007
Esben Norby
Re: ospfd errors

Please post your /etc/ospfd.conf and the output of ifconfig here.

No need to enable ip multicast forwarding.

/Esben

Nov 14, 4:08 am 2007
Stuart Henderson
Re: ospfd errors

Check PF rules:

1. pass proto ospf

2. typically, martian filters include the multicast range,

Please upgrade. What you're trying should work, but there have
been many fixes/improvements to the routing daemons since 4.0,
and this is usually easier to do _before_ it's all running.

Nov 14, 5:58 am 2007
new_guy
Connectivity Issues with Linksys 802.11 USB Adapter

Hi guys,

I have a Linksys WUSB11 v2.8 802.11 USB wireless adapter on a fresh OpenBSD
4.2 install. It is recognized as an atu0 device. Internally it works great.
I can ping all of the IPs inside the gateway (and ping the gateway) and
browse to internal web sites, etc. Externally, I have no connectivity on
atu0, but I can get outside on my wired (fxp0) interface. Here's the
relevant portion of my ifconfig with the wired (fxp0) interface down:

fxp0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTI...

Nov 14, 12:33 am 2007
Stuart Henderson
Re: Connectivity Issues with Linksys 802.11 USB Adapter

These are in the same subnet, this won't work. You might like

Wow, a nabble post with sufficient information to spot the
problem, that is somewhat unusual :-)

Nov 14, 6:01 am 2007
Girish Venkatachalam
Re: Connectivity Issues with Linksys 802.11 USB Adapter

Can't you bridge them or create separate subnets and route them?

Is trunking the purpose here?

Just wondering....

regards,
Girish

Nov 14, 7:14 am 2007
new_guy
Re: Connectivity Issues with Linksys 802.11 USB Adapter

It was just an experiment. I was trying to do some funky routing through the
wireless interface. I'll play with it some more. Thanks to all for the tips!

Brad

--
View this message in context: http://www.nabble.com/Connectivity-Issues-with-Linksys-802.11-USB-Adapte...
Sent from the openbsd user - misc mailing list archive at Nabble.com.

Nov 14, 10:36 am 2007
Stuart Henderson
Re: Connectivity Issues with Linksys 802.11 USB Adapter

failover trunks are quite good for this situation (depending on how
long your switch takes to notice the move). Separate subnets are another
option but means doing more (and losing active connections) when you
change between wired and wireless.

You might use bridge(4) for an access point but that's somewhat

Nov 14, 7:37 am 2007
Girish Venkatachalam Nov 14, 10:46 am 2007
Josh
4.2 firewall freezes up

I am having problems with a pair of firewall machines which keep on
freezing up. I have just installed 4.2 on them, and previously they were
running freebsd 6.2 for about a year without any problems.

Basically the machine becomes unresponsive to anything, but there is no
panic screen or anything like that, and it also does not release its
carp ip's, I have to actually pull the power before the backup firewall
takes over.

Any ideas on this?

Thanks,
Josh

OpenBSD 4.2 (GENERIC) #...

Nov 13, 11:14 pm 2007
Dave Harrison
Daily insecurity report and drop priv accounts for handling ...

Hi all,

I've been wondering how to deal with this particular issue for quite
some time now, and I can't find any references to "the right way"(TM)
to handle it.

I always prefer to run automated tasks as limited privilege users on
my OpenBSD hosts - such as tasks that pull files across from other
hosts, and other such nightly tasks. To make this work the drop priv
user account needs a shell and a home dir (for SSH keys etc), and has
no need for a password. However this causes the /etc/security ...

Nov 13, 8:06 pm 2007
Nick Holland
Re: Daily insecurity report and drop priv accounts for handl...

here's my way of squishing those messages:
* create the user, give it a non-trivial (but easy to type) PW. This
is often useful in the development stage anyway. Don't use a trivial
password in case you forget to do the next step...
* When ready to kill the PW, rather than clearing it, by putting a
few repeated chars in the encrypted PW string, for example, "----",
using vipw.

You now have an account that technically has a PW, but it is unlikely
anyone will find something that hashes to...

Nov 13, 11:17 pm 2007
Calomel
Re: Daily insecurity report and drop priv accounts for handl...

Dave,

In our backup environment the backup user needs a shell and home dir for
ssh keys as you described. The passwd is disabled and ssh keys are
required. We also limit access to the backup user to specific source ip
addresses like the backup server.

We also use ssh wrappers. Using the command argument in the ssh keys file
you can have a script check what command is being run. The backup user only
needs to accept rsync so that is what we are validating. If any other
command is run or if a shell...

Nov 13, 11:46 pm 2007
previous daytodaynext day
NoneNovember 14, 2007None