openbsd-misc mailing list

FromSubjectsort iconDate
Wijnand Wiersma
Almost success: OpenBSD on Xen

Hi All,

I don't know if many of you already tried to run OpenBSD on Xen as a HVM
guest, but here is a small report of my attempts this evening.

The virtual server runs on a debian sarge with xen packages from the
backports debian repository. Hardware is a dell 2950 with cpu
virtualisation enabled in BIOS.

I had to use Paul's boot iso image
(http://www.weirdnet.nl/openbsd/serial/ ) to boot and use the serial
console. I could have used the VNC option but all text was too scrambled
to be ...

Feb 26, 6:44 pm 2007
Bryan Irvine
no controlling tty error

I recently had a crashed disk. I recovered from backup, and made some
changes to fstab.

Now I can't get postgresql to start.

I get an error that no controlling tty. If I try to start it anyway
it tells me that postmaster isn't in the same directory as pg_ctl (but
it is).

Maybe somebody else can spot what I'm missing.

errors:
GTX-440:/root#su - _postgresql
sh: No controlling tty (open /dev/tty: Permission denied)
sh: warning: won't have full job control

$ pg_ctl -D data/ start
sh: can...

Feb 26, 5:39 pm 2007
Matthias Kilian
Re: no controlling tty error

Use ls(1) to see what's wrong with /dev (probably just empty), then
use MAKEDEV(8) to repair it.

Ciao,
Kili

--
GUIs normally make it simple to accomplish simple actions and impossible to
accomplish complex actions.
-- Doug Gwyn (22/Jum/91 in `comp.unix.wizards')

Feb 26, 6:04 pm 2007
Stuart Henderson
Re: no controlling tty error

this all points to permissions on /dev being wrong.

(cd /dev;sh MAKEDEV all), I would untar the relevant OS distribution
*.tgz over the top as well (with the p flag) to fix up any other files
that may have been broken.

Feb 26, 6:00 pm 2007
Bryan Irvine
Re: no controlling tty error

ah this did it. I'm not sure why it was all messed up. As far as I
recall I didn't mess with /dev hrmmmm

ah well MAKEDEV all fixed it. Everything is ok now.

Feb 26, 6:21 pm 2007
Ingo Schwarze
Re: no controlling tty error

Did you tighten up any permissions?

# cd /dev; ls -al tty null
crw-rw-rw- 1 root wheel 2, 2 Feb 26 22:29 null
crw-rw-rw- 1 root wheel 1, 0 Feb 26 22:25 tty

Feb 26, 5:57 pm 2007
RJ45
kadmin problem

when I try to connect to kadmin remote server (MIT)
from openbsd SSH login gateway, the application hangs:

kadmin> add --random-key host/myhost.mydomain
administrator/admin@REALM's Password:

it hangs...

I tryed to dobthis because I can;t logon using SSH
I have this error:

Feb 26 21:42:54 myhost krb5: verify: Server not found in Kerberos
database

so I tryed to register the OpenBSD krb5 client host
to krb5 server usign kadmin but as I Said it hangs...

what I have to do ?

than...

Feb 26, 4:52 pm 2007
scorch
Re: kadmin problem

a bit more info could help here! it looks as if you're unable to contact
the kdc probably because of either a missing krb5.conf or some
DNS-related issues.

- what are you actually trying to do?
login to remote-host using ssh-gssapi authentication?
setting up krb for some other app e.g. openafs?
- what is your setup?
krb5.conf
do you have a keytab already set up?
are you in the same NW - i.e. no NAT hiding in the way?
- can you do a kinit succussfully?
- what is in your credentials cach...

Feb 26, 6:19 pm 2007
Jacob Yocom-Piatt
Re: kadmin problem

i'm guessing it hangs b/c you don't have this particular KDC as your
default in your /etc/krb5.conf. posting a sanitized version of this file
would be helpful for diagnosis.

verify you're actually connected to the remote KDC's kadmin port before
trying to issue commands. read the manual page for kadmin. having the

Feb 26, 5:18 pm 2007
Sebastian Reitenbach
Re: two servers (4.0 and 3.9) constantly keep freezing

thanks for your answers, now I now that there is no other way for now, than
recompiling
kernel.

thanks
Sebastian

Feb 26, 4:26 pm 2007
Tang Tse
openbsd 4.0 and usb

Hi,

I got some troubles. My openbsd hasn't any usb support, i tried to moun and
usb pen drive, or configure my usb printer with no good results.

I'm using downloaded openbsd from the ftp ( using cd40.iso to boot and get
the install program then download the rest trough ftp ), and Jon Drews
suggested me to get orginal CD , i will wait til 4.1 ( thanks Jon for all ).

Here is the output for dmesg:

OpenBSD 4.0 (GENERIC) #1107: Sat Sep 16 19:15:58 MDT 2006
deraadt@i386.openbsd.org :/usr/src...

Feb 26, 3:45 pm 2007
Otto Moerbeek
Re: openbsd 4.0 and usb

No trace of any USB device. Is USB disabled in the BIOS?

Feb 26, 4:09 pm 2007
Tang Tse
Re: openbsd 4.0 and usb

Yes, it's up. Maybe an unsupported usb chipset?

Feb 26, 4:21 pm 2007
Otto Moerbeek
Re: openbsd 4.0 and usb

unsupported devices show up in the dmesg as "not configured". So your
USB hardware might be broken, or maybe it is hiding behind an PCI
bridge or something like that (though that is pure speculation). Try
booting a snapshotd bsd.rd to see what that demsg shows in that case.

-Otto

Feb 26, 4:32 pm 2007
Nikolay Sturm
filesystem hackathon: still seeking donations

Hi,

unfortunately the first call for hardware donations wasn't really that
successful, we got a few interesting pieces of hardware, but we are
still lacking major parts. So here's the second call for donations.

In order to have a successful event we need the following pieces of
hardware:
- 2 fast build boxes, preferrably sth like a Sun Fire X2100 M2 or
comparable
- 8 250G SATA disks
- 8 250G IDE disks

As an alternative, we also ask for financial donations. All money
collected will be used...

Feb 26, 2:00 pm 2007
Nikolay Sturm
Re: filesystem hackathon: still seeking donations

It looks like I messed up the words, all we are asking for is hardware
*loans*. If you or your company can spare a bunch of disks or a server for
a week, that would already help us enormously. Donations are welcome as
well, of course. :)

PS: f2k7 will take place in Vienna from April 10th to 15th.

thanks,

Nikolay

Feb 26, 7:14 pm 2007
Bob Beck
Re: filesystem hackathon: still seeking donations

Particularly a company in europe - flying this sort of gear
across the atlantic for this event from north america is just

Feb 26, 7:25 pm 2007
Samuel Moñux
Source Interface for outgoing connections

Hi everyone,

I'm having some issues with an ipsec connection with vpnc (isakmp is
not an option, since does not support xauth, and I don't control the
other end) from an OpenBSD firewall/router to a Cisco device.

I think problems could be natt related so I would like to eliminate
nat from the equation, but the problem is that the "outside" interface
is a private address. This firewall routes between a DMZ (public /29),
a LAN segment (private /24), and the outside (private /30).

------ LAN --...

Feb 26, 12:36 pm 2007
Darren Spruell
Re: Source Interface for outgoing connections

If you could get vpnc to bind to a specific interface it seems like
that would be possible. Can you see if that's an option?

The way I see it, NAT may not be an issue; any worthwhile modern IPsec
implementation supports NAT traversal, which vpnc appears to (I see a
reference to '--natt-mode' on their page.) If you can support NAT-T on
the client and server, it may be a non-issue for you.

Haven't used vpnc myself, but just looking at the package install
message there's a couple of considerations...

Feb 26, 1:59 pm 2007
Anselm R. Garbe
OpenBSD 4.0 / Xorg -> vesa 1920x1200 widescreen resolution

Hi there,

I got a Thinkpad Z61p
(http://www.ciao.de/Lenovo_ThinkPad_Z61p_9452__2342038)
with a 1920x1200 WUXGA widescreen display driven by an ATI
Mobility FireGL V5200 - PCI Express x16 adaptor.

Last weekend I tried to install OpenBSD 4.0 onto this box -
everything essential works fine, except that it seems impossible
to force the vesa driver of Xorg to work with a (or in
particular this) widescreen resolution properly.

The highest resolution I got working with the vesa driver was
1600x1200...

Feb 26, 9:52 am 2007
Darrin Chandler
Re: OpenBSD 4.0 / Xorg -> vesa 1920x1200 widescreen resolution

For my laptop (whole different brand/chipset, but similar problem), I
had to manually make a ModeLine. After that I had no problem at all
using 1920x1200.

--
Darrin Chandler | Phoenix BSD Users Group
dwchandler@stilyagin.com | http://bsd.phoenix.az.us/
http://www.stilyagin.com/darrin/ |

Feb 26, 12:36 pm 2007
Anselm R. Garbe
Re: OpenBSD 4.0 / Xorg -> vesa 1920x1200 widescreen resolution

Well, would you like to send me your xorg.conf? I've seen
various ones using ModeLines, but no one worked in conjunction
with the vesa driver for me. If you can confirm that it really
works with the vesa driver for you using special modelines, I'd
really invest more time into debugging the issue. ;)

Regards,
--
Anselm R. Garbe >< http://www.suckless.org/ >< GPG key: 0D73F361

Feb 26, 1:29 pm 2007
Darrin Chandler
Re: OpenBSD 4.0 / Xorg -> vesa 1920x1200 widescreen resolution

After switching to the vesa driver it didn't work. Perhaps it can be
made to work with additional information (clock lines?) but I don't
know. Sorry. I hope you find something that works for you.

--
Darrin Chandler | Phoenix BSD Users Group
dwchandler@stilyagin.com | http://bsd.phoenix.az.us/
http://www.stilyagin.com/darrin/ |

Feb 26, 2:12 pm 2007
Jacek Artymiak
Free Advertising for the BSD Community

Hi,

As some of you might know, I self-publish my books, which gives me
full control of the contents, for better or worse. Because of the way
my printers work, I must typeset my manuscripts to match their funky
specs and sometimes I have a few blank pages left at the end. I need
to pay for them anyway, so I thought I'd offer them to you for free.
My next book is coming out in two weeks. I don't know how many pages I
can offer but I though I'd give you an early warning :-)

If you are a BSD profess...

Feb 26, 7:25 am 2007
Sebastian Reitenbach
two servers (4.0 and 3.9) constantly keep freezing

Hi list,

I have two servers, one running 4.0 and one with 3.9, they are used as web
servers, with a
mysql database running on them. Both are more or less idle, but I have seem
these messages
in /var/log/messages on both servers:
bsd: uvm_mapent_alloc: out of static map entries

I found this thread, where someone has seen the same problem:
http://marc.theaimsgroup.com/?l=openbsd-tech&m=115959929717470&w=2

The servers are either freezing completely, or may still answer on pings, and
...

Feb 26, 6:36 am 2007
Bryan Irvine
Re: two servers (4.0 and 3.9) constantly keep freezing

I had the same problem for a long time. I found this site and it
hasn't happened since:
http://www.openbsdsupport.org/mysql.htm

--Bryan

Feb 26, 7:11 pm 2007
tico-obsd@raapid.net
Re: two servers (4.0 and 3.9) constantly keep freezing

Hi Sebastian,

I don't know if this will help at all, but I remember having a
Cyrus-IMAP server that always had a fair amount of disk I/O and tons of
open files that would exhibit the similar behavior. Unfortunately, it
wasn't running GENERIC (had RAIDFRAME and a couple of other things
enabled), it was running an old OpenBSD 3.6 (amd64) system and I didn't
have time to debug the issue since it was a production box, so I just
changed the /usr/src/sys/uvm/uvm_map.h KMAP_ENT #define to be 4000
...

Feb 26, 12:12 pm 2007
Pedro Martelletto
Re: two servers (4.0 and 3.9) constantly keep freezing

Unfortunately, no. Nothing has changed since the above thread.

-p.

Feb 26, 7:34 am 2007
sof bo
USB host class ACM

hello,

does someone have information or used the host class ACM?

thanks
___________________________________________________________________________
Dicouvrez une nouvelle fagon d'obtenir des riponses ` toutes vos questions !
Profitez des connaissances, des opinions et des expiriences des internautes
sur Yahoo! Questions/Riponses
http://fr.answers.yahoo.com

Feb 26, 6:13 am 2007
Jonathan Gray Feb 26, 8:33 am 2007
Pete
CARP / HSRP problem

I have a pair of 3.9 pf firewalls running CARP. I have two ethernet
connections to my provider who is running Cisco HSRP. When they reload the
active router or bounce the active interface, then the Ciscos can no longer
see the CARP virtual interface until I cause a CARP failover by rebooting the
active firewall or admining down the external interface on the active
firewall.

Through all of this, I have outbound connectivity from the firewall since it
is on the same subnet as the Ciscos.

I a...

Feb 26, 6:06 am 2007
Andre Ruppert Feb 26, 3:54 am 2007
Andre Ruppert
Re: O'Reilly Net article: short comparison between Cisco PIX...

...and OpenBSD, of course...

sorry, I forgot....

Andre

Feb 26, 7:30 am 2007
Craig Barraclough
Anchor naming / evaluation (naming mismatch)

Having trouble sending this to pf@benzedrine list, so I'm sending to
misc@ instead
------
I got caught by an interesting situation recently, which I eventually
tracked down to the following situation.
The anchor in the main ruleset was given like:
anchor "test/*"
However the anchor was populated using just the name, e.g. like this:
load anchor "test" from "/tmp/test-r.anchor"
(In reality, it was being loaded from an external program)

The result of this was the contents of the anchor are visible ...

Feb 26, 12:35 am 2007
Anderson Nadal
OpenBGPD bug??

Hy all.

I found a possible OpenBGPD bug.
I have a bgp session with Cymru to receive a bogon network using bgp. I
have others sessions with my local carrier to.
Sometimes, the Cymru sessions go down, after some seconds the session is
established.
Wheel, after some sessions up and down, the bgpd process crash.

Look the log:

Feb 25 21:53:27 my_router bgpd[8131]: neighbor 38.229.0.5 (Peering Bogon
1): state change Active -> OpenSent, reason: Connection opened
Feb 25 21:53:27 my_router bgpd...

Feb 25, 11:44 pm 2007
Henning Brauer
Re: OpenBGPD bug??

you're petty much leaving out all relevant information.
you don't mention which version you run, you don't show your config,
and you don't show complete logs at time of failure. impossible to
track down possible bugs like this.

that said, chances are very good this is fixed in -current/4.1.

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg ...

Feb 26, 2:38 am 2007
Anderson Nadal
Re: OpenBGPD bug??

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ok Henning.

I'm using 3.9, and my config is:

group "peering ASXXXX" {
remote-as XXXX
neighbor $principal {
descr "Link Principal"
announce all
local-address $mypeer1
depend on carp1
set metric 1
set localpref 200
}
neighbor $backup {
descr "Link BKP"
announce all
...

Feb 26, 1:56 pm 2007
Henning Brauer
Re: OpenBGPD bug??

well, this is obviously not your full config, but in this case, I am
reasnably certain the problem is fixed. Now is a good time to give

you obviously have update logging enabled, so you get what you ask for

--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam

Feb 26, 2:32 pm 2007
Anderson Nadal
Re: OpenBGPD bug??

Ok, i will try a upgrade to 4.0 or 4.1

I know about logging update enabled, i just told you. :)

Thanks for your help.

[]'s
Nadal

"Nco discuta com idiotas, eles te levam ati o nmvel deles e te vencem por serem experientes"

+-------------------------------------------------------+
| Anderson Nadal <nadal@ondacorp.com.br> - CCNA/RHCE |
| Coordenador Tecnico |
| Fone: + 55 41 3331 8200 |
| FAX: + 55 41 ...

Feb 26, 3:06 pm 2007
stephan
OT: vanishing WDxxxxYS series disks, firmware problem

i've just had to deal with vanishing Caviar drives from one of my ami raids - in
case you have these disks as well you are better off reading
http://www.theinquirer.net/default.aspx?article=37188 (this is kinda old news,
but might save you some sleepless nights anyway).

Stephan

--------------------------------------------------------------------
This message was sent using Webmail@INI: https://webmail.ini.ethz.ch

Feb 25, 10:49 pm 2007
Bray Mailloux
DHCP server issues.

I've been toying with the DHCP server options but cannot seem to bring
up the process; everytime I run ps there is no dhcpd process to be found
and no computers on my network are pulling down addresses from the server.
My DHCPD.conf file looks as such.

-bash-3.1# nano /etc/dhcpd.conf
GNU nano 1.2.5 File: /etc/dhcpd.conf

# $OpenBSD: dhcpd.conf,v 1.1 1998/08/19 04:25:45 form Exp $
#
# DHCP server options.
# See dhcpd.conf(5) and dhcpd(8) for more information.
#

# Netw...

Feb 25, 8:45 pm 2007
Peter Hessler
Re: DHCP server issues.

You can't have entities on the same subnet on different interfaces.
Make your external interface your public IP. or a different subnet.

--
On-line, adj.:
The idea that a human being should always be accessible to a
computer.

Feb 25, 11:32 pm 2007
Jon Morby
Re: DHCP server issues.

Hi Bray

What do the logs say?

Also, try running dhcpd with -d -f

-d Force dhcpd to log to stderr. This can be useful for
debugging,
and also at sites where a complete log of all dhcp
activity must
be kept, but syslogd(8) is not reliable or otherwise
cannot be
used. Normally, dhcpd will log all output using the
syslog(3)
function with the log facility set to LOG_DAEMON.

-f Run dhcpd as a foreground pro...

Feb 25, 9:20 pm 2007
Darren Spruell
Re: DHCP server issues.

Take a look in /etc/rc and see how the system initializes dhcpd. Are
you missing the leases file?

DS

Feb 25, 9:03 pm 2007
djgoku
Re: DHCP server issues.

What does /etc/dhcpd.interfaces have in it? This should have the
interface with which you would like to run a DHCP server from.

To manually test that your dhcpd.conf is working try:

# dhcpd rl1
# ps aux | grep dhcpd

Feb 25, 9:03 pm 2007
William Bloom
Re: site-to-site vpn 4.0 to cisco 3000

On further study of the iskampd.conf man page, I am thinking that you
may be correct by turning you attention to the isakmpd.conf as a
possible trouble spot.

I notice that you specified group mod768 (Diffie -Hellman group 1)in
your ipsec statements. As I said, not having had occasion to run a
VPN before using OpenBSD as an endpoint, I am having to generalize
from all the other VPN setups that I have done. Generally, the
Diffie-Hellman group is only relevant in two places, one being the
'main' mo...

Feb 25, 10:16 pm 2007
William Bloom
Re: site-to-site vpn 4.0 to cisco 3000

The man page for isakpd.conf indeed sheds some light, there's an
example in that page that show's how to specify lifetimes for both
phases...

[General]
Default-phase-1-lifetime= 3600,60:86400
Default-phase-2-lifetime= 1200,60:86400

At this point, if the lifetimes indeed agree, then I myself would be
a little puzzled over why the proposal would be rejected. Both
endpoints are configured to use the peer address as the ID? At first
blush, your sett...

Feb 25, 9:53 pm 2007
c l
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED

Finally got this to work. Here's the config that ended up working.

I'm not sure why I didn't notice before but the quick mode stuff wasn't
setup correctly.

ipsec.conf
ike esp from 192.168.1.0/24 to 10.10.0.0/16 peer 2.2.2.2 \
main auth hmac-sha1 enc 3des group modp768 \
quick auth hmac-sha1 enc 3des group none psk openbsdrules

cisco
IKE proposal
authentication mode - presharedkeys
authentication algorithm - sha/hmac-160
encryption - 3DES-168
DH Group - 1 768-bits
Lifet...

Feb 25, 10:06 pm 2007
Claer
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED

There is another potential problem with this configuration. You did not
specify the ike mode: active, passive, dynamic.

The default behavior is to use "active". "dynamic" mode comes with DPD
(Dead Peer Detection) and don't work with some devices. I remember a
post here stating that it doesn't interoperate with Netscreen at the
other end.

You're lucky to not enter into this problem :)

Routing in the enc0 interface is done with the flow statement in the
ipsec.conf file. Your ipsec.conf should in...

Feb 26, 5:02 am 2007
William Bloom
Re: site-to-site vpn 4.0 to cisco 3000 SOLVED

Ah. Disregard my last post. I didn't realize that the 'ipsec'
configuration specifies main mode (phase 1 negotiation) and quick
mode (phase 2 negotiation) in separate substatements. Good find.
That makes perfect sense.

Bill

--
William Bloom
williambloom@mac.com

Feb 25, 10:19 pm 2007
previous daytodaynext day
NoneFebruary 26, 2007None