openbsd-misc mailing list

FromSubjectsort iconDate
poncenby
OT: embedded single board recommendation

List,

Does anyone know of an embedded single board computer, much like a
WRAP/ALIX.C, which has at least one miniPCIe slot?

having no luck on the intertubes am i right in thinking that these board
just are not suitable for 802.11n networking? considering power
requirements, bus bandwidth etc etc

Any thoughts welcome

poncenby

Sep 21, 6:58 pm 2007
Joe Gibbens
Gettnig sendto no buffer space available errors... irq probl...

I'm seeing some sendto: No buffer space available errors along with some ssh
session hangs. The symptoms are intermitent and look a lot like this
thread.
http://monkey.org/openbsd/archive/misc/0309/msg00827.html
The system is 4.1 stable generic with the sangoma wanpipe driver. Most
traffic is moving between the t1 card and em0.

Is this probably an irq issue?
If so,
Is there any reason not to put the nics and the wic on the same irq? (is the
context switching advantage still valid?)
Does it mak...

Sep 21, 6:26 pm 2007
pu
ccd interleave 0 does not work

Hi,

I'm trying to concatenate 2 disks using ccd. With an interleave factor
of 0, as described by the man page of ccd(4), it doesn't work. An
interleave factor of 1 works, though. Also, the fstype is 4.2BSD in my
example, but there's no difference if I set it to CCD.

This resembles a bug that was fixed March 30th, 2007:
http://archive.openbsd.nu/?ml=openbsd-bugs&a=2007-03&t=3406566.

User error or system error?

# cat /etc/ccd.conf
# $OpenBSD: ccd.conf,v 1.1 1996/08/24 20:5...

Sep 21, 6:10 pm 2007
Adi
Re: libc: missing POSIX functions

char slave[PATH_MAX] ?

I think it's a reasonable assumption that no library function

'ttyname(slavefd)' will do.

Sep 21, 4:50 pm 2007
infos
Transfert 8 et Super8, montage video, duplication CD/DVD, cl...

Vous avez besoin pour votre entreprise et aussi ` titre personnel de sauvegarder vos anciens films (8, Super8, VHS, Hi8, Video8, DV et autres) et leur donner une nouvelle jeunesse en les mettant sur DVD, ceci ` moindre co{t. Ne cherchez plus, nous sommes l`.

Nous sommes prisents sur le marchi depuis 10 ans avec des appareils professionnels, nous vous rendrons un risultat comparable ` l'original et souvent mjme mieux.

Ceci pour des films magnitiques mais aussi super8, 8mm et 16mm.
Nous vous invitons `...

Sep 21, 3:45 pm 2007
rwaite1
Re: Is AMD64 page out of date about W^X?

I sent a message and it looks like it got rejected... basically I found out that ia32e is EM64T(Intel's marketing name for it).
I was thinking it was the itanium arch which is actually ia64. But either way...
EM64T is supposed to run on AMD64... and it appears that the Intel chips do support the NXE bit since around 2005.
Can anyone confirm that the newer ia32e chips (made after early 2005) are actually supporting W^X? It seems that just because NXE is shown in the dmesg wouldn't necessarily mean that ...

Sep 21, 2:48 pm 2007
Adriaan
Re: Is AMD64 page out of date about W^X?

On 9/21/07, rwaite1@tampabay.rr.com <rwaite1@tampabay.rr.com> wrote:
[snip]

You can lookup support for the Execution Disable Bit for your
processor at http://processorfinder.intel.com/Default.aspx
For example http://processorfinder.intel.com/details.aspx?sSpec=SL99W

=Adriaan=

Sep 21, 3:37 pm 2007
Douglas A. Tutty
lock(1) to lock all virtual terminals?

I don't use X much and instead use lots of Virtual Terminals.

Since I'm on dialup, sometimes I need to leave multiple VTs open to do
things, perhaps downloading something, or its just that I'm in the
middle of things.

How can I lock the whole virtual termial setup? lock(1) only lets me
lock the one VT without blocking the ability to switch to others. On
Debian, there's vlock -a that does this. I don't see anything similar
in the available packages for OBSD.

I can't read code so I don't kn...

Sep 21, 12:46 pm 2007
Siju George
Re: Skype on OpenBSD 4.1 using Fedora RPM

OK :-)
I did this on a 4.1/i386.
For other versions it would be similar however since we are going to
use the Skype Linux Binary we will need an x86 system. Linux emulation
is available only for x86 systems.

1) Enable Linux Emulation option in kernel

You will have a line

#kern.emul.linux=1 # enable running Linux binaries

in your "/etc/sysctl.conf" file. You need to uncomment it ( remove the
# in the begining ) and make it look like

kern.emul.linux=1 # enable...

Sep 21, 11:48 am 2007
Jason Calhoun
Problems with ftp-proxy - Solution

Hi all,

I finally found a solution to my ftp-proxy problem. The machine is a Dell
2950 with broadcom gigabit NICs, so I'm using the bnx driver included in the
generic kernel. It seems that the TCP checksum offloading causes problems
in certain cases. I found a reference to this on another message board
first, but look also at bug report 5437.
http://cvs.openbsd.org/cgi-bin/query-pr-wrapper?full=yes&numbers=5437 This
report is closed, but the behavior I saw matched this report. In any ...

Sep 21, 11:30 am 2007
Christian Weisgerber
Re: 4.1 on ALIX.1C - recommendations?

I recently got a Soekris net5501, which is uncannily similar (I
guess they're both based on the same reference design), and moved
the same kind of infrastructure functions to that box, so I had to

Do you want to do kernel development and debugging on that box?

It depends on how you view the machine. I decided to forgo the
usual multiuser system approach and treat the box as an appliance.
The whole point is that it will just sit there, performs its job,
and I won't have to touch it. I didn...

Sep 21, 10:54 am 2007
Christoph Leser
WG: Re: isakmp phase 2 negotiation failed

Maybe there is a problem with your isakmpd.conf:

The hierachy should be as follows ( that's at least what I
read from man isakmpd.conf:

Connections lists <ipsec-connection>s: cobbled-caley

<ipsec-connections> names <IPsec-configuration>: low-crypto-quick

<IPsec-configuration> names <Suites> QM-ESP-DES-MD5-SUITE !!
so maybe it should be

[low-crypto-quick]
DOI= IPSEC
EXCHANGE_TYPE= QUICK_MODE
Suites= QM-E...

Sep 21, 10:47 am 2007
Stefan Sczekalla-Wal...
spamdb never shows any entries ?!?

Hi,

I tryed to set up spamd on OpenBSD4.1

but after "preloading" the database at /var/db/spamd

using:

isabsd # /usr/libexec/spamd-setup -d
Getting http://www.openbsd.org/spamd/nixspam.gz
blacklist nixspam 39960 entries
whitelist override 40138 entries
Getting http://www.openbsd.org/spamd/chinacidr.txt.gz
blacklist china 431 entries
whitelist override 609 entries
Getting http://www.openbsd.org/spamd/koreacidr.txt.gz
blacklist korea 270 entries
whitelist override 448 entries

spamdb doe...

Sep 21, 8:26 am 2007
Juan Miscaro
Re: spamdb never shows any entries ?!?

Ask a question on any topic and get answers from real people. Go to Yahoo! Answers and share what you know at http://ca.answers.yahoo.com

Sep 21, 9:15 am 2007
Jeremy C. Reed
Re: spamdb never shows any entries ?!?

See your pf(4) table <spamd>

pfctl -t spamd -T show | wc -l

That is unrelated. spamdb only touches the hash database on the
filesystem. Also spamd itself doesn't use the pf <spamd> table -- it uses
the pf <spamd-white> table.

Jeremy C. Reed

Sep 21, 9:01 am 2007
Stuart Henderson
Re: spamdb never shows any entries ?!?

This changed in 4.1; unless you use -b, it's no longer
necessary to keep the blacklist in a PF table.

Sep 21, 9:26 am 2007
Christoph Leser
WG: isakmp phase 2 negotiation failed

> -----Urspr|ngliche Nachricht-----
> Von: owner-misc@openbsd.org
[mailto:owner-misc@openbsd.org]Im Auftrag
> von n0g0013
> Gesendet: Donnerstag, 20. September 2007 23:52
> An: misc@openbsd.org
> Betreff: isakmp phase 2 negotiation failed
>
>
> having a nightmare getting two openbsd (one 3.8, one 4.0) boxes to
> setup a tunnel. finally got the phase 1 negotiation going (or so i
> believe from reviewing the logs) but it appears that the phase two
...

Sep 21, 7:38 am 2007
Jan Stary
4.1 on ALIX.1C - recommendations?

Hi all,

last night, I installed 4.1 on the new ALIX.1C:
http://www.pcengines.ch/alix1c.htm (see dmesg at bottom).
The intended use of the box is a home router/firewall/NAT/DNS/DHCP
for my home "network" of about four computers (heterogeneous).

Everything works fine (as usual with OpenBSD), but
there are a few fine points I need some advice with.

Firstly, swap (i don't really mind reinstalling). Install guide says

On the root disk, the two partitions 'a' and 'b' must be
created. The instal...

Sep 21, 7:33 am 2007
Craig Skinner Sep 21, 10:57 am 2007
Nick Holland
Re: 4.1 on ALIX.1C - recommendations?

oops. That's no longer true, you can now install Just Fine with no swap

If you gotta ask, it won't matter.

You have three bad NICs (vr, rl, xl) and one good one (fxp). But it
just won't matter for your use.

You got yourself a little economy car of a computer system. You got it
because it is small and cheap to operate, and you will be operating it
in rush-hour. Don't worry about which tail fin will give you the "best"
performance. (no idea how well that analogy "travels" around t...

Sep 21, 9:49 am 2007
Jan Stary
Re: 4.1 on ALIX.1C - recommendations?

OK, ext_if="fxp0" && int_if="vr0" for me then. (Made me read your post
at bottom of http://archive.openbsd.nu/?ml=openbsd-misc&a=2004-01&t=18114

This isn't really a concern in my situation - about the only thing
the box will ever write is syslog messages (to an internal @loghost,

There is a lifelong waranty for the CF card anyway, so I will just

The only other storage option on the ALIX board is a 44pin IDE; the CF
card is quieter and eats less yticirtcele, which is more ...

Sep 21, 10:53 am 2007
AfricaByBike Newsletter
2007-09-20 from sweden to south africa by bike

I've now reached the french alps by bike. I will soon cycle beside the mediterranean sea near the coast. I have taken some pictures and written some about my expedition. If you're interested you can point your brower too the following address:
http://www.narfstrom.se

Friendly regards from Grenoble, Rhtne Alps - France

Andreas

Sep 21, 6:10 am 2007
Gregory Edigarov
Question on interface enumeration

Hello Everybody,

Supposing I have several identical NIC's in my server, can I predict
which become int0, which become int1, etc?

A link to document explaining (or man something) would absolutely suffice.
Thank you.
--

With best regards,
Gregory Edigarov

Sep 21, 4:45 am 2007
Nick Holland
Re: Question on interface enumeration

Not Easily, at least if you are referring to a machine you know nothing
about and haven't powered up yet. However, it is easy to make simple
tests to find out.

Assuming PCI, they go by order of the slots in the bus, which isn't
something OpenBSD controls. Many machines have curious orders.
For example, I have a Dell GX1 which has five PCI slots; the order
is something like: 2 3 4 0 1. (To add insult to injury, I had four
port NICs in every slot, took a while to find dc0! :)

Now, once I kno...

Sep 21, 7:12 am 2007
Gregory Edigarov
Re: Question on interface enumeration

I.e. they depend on the PCI slot they inserted, if I get you correct.
Well, thank you for so in-depth explanation, but what I meant really
was: is it guaranteed that if one take a card from the server and then
install the other card of the same make to the same slot, it will have
the same id?
I will do more research about it , however.... :-)

The best thing however would be to have the ability to set the name of
an intreface based on it's mac address, perhaps somebody is working on
it/having ...

Sep 21, 11:07 am 2007
Marius ROMAN
Re: Question on interface enumeration

Something like iftab on debian.

Sep 21, 11:54 am 2007
Pamela
Search Foreclosures Now !**HOT**

Buy Foreclosures Half Price
Buy and sell foreclosures
Search over 1.2 million listings

Reply with "Send Info" & I'll show you how!

Sep 21, 3:35 am 2007
Bryan Irvine
Re: OpenBSD firewalls as virtual machine ?

I don't like the idea of virtualiazing the firewalls either. It's
just asking for trouble.

What happens when the host OS gets hacked? Better I think to get some of these:
http://www.netgate.com/product_info.php?cPath=67&products_id=369

and some soekris boards. You'll be able to fit 2 firewalls per 'u'.
Then either use VLANS, or put a nic on each segment.

-Bryan

Sep 21, 7:09 pm 2007
Kent Watsen
Re: OpenBSD firewalls as virtual machine ?

Some commercial firewalls (i.e. Juniper/NetScreen ScreenOS-based gear)
have been offering virtual-systems for years now. I think the negative
comments received here may be appropriate when sharing the system with
non-secure guest OSs, but it seems that it might be alright if its
nothing but firewalls

Cheers,
Kent

Sep 21, 8:07 am 2007
Scott Wells
Re: OpenBSD firewalls as virtual machine ?

It sounds to me like the comments here are largely appropriate,
virtualizing firewalls in the limited context that has been explained
probably isn't a real good idea...at least due to perceived load.
Additionally, if there are that many fireuwalls being ran, instead of
numerous interfaces in a fewer number of machines, you're going to
continue to have problems being able to virtualize enough hardware
network interfaces.

However, I don't fully agree with the sentiment that running a firewall ...

Sep 21, 9:19 am 2007
Douglas A. Tutty
Re: OpenBSD firewalls as virtual machine ?

I don't understand the logic of having multiple firewalls on one box.
If one box can handle the throughput requirements of all the NICs, why
not just one big firewall?

Doug.

Sep 21, 10:52 am 2007
user
Re: OpenBSD firewalls as virtual machine ?

Douglas A. Tutty wrote:

There are lots of places where multiple firewalls are better than a
single firewall. If one believed in the idea of "a perfect VM
environment", it could make sense to do that.

1) Unrelated projects: If Project A and Project B are not related,
keeping them on separate firewalls can simplify the rule sets and
administration.

2) Separate administration: If you run a data center with lots of
different people managing different systems, "They" can administer their
systems ...

Sep 21, 11:12 pm 2007
Luca Corti
Re: OpenBSD firewalls as virtual machine ?

Overlapping IP address space.

ciao

Luca

Sep 21, 11:17 am 2007
bofh
Re: OpenBSD firewalls as virtual machine ?

That's why god created competant network admins and NAT.

--
"This officer's men seem to follow him merely out of idle curiosity."
-- Sandhurst officer cadet evaluation.

Sep 21, 3:29 pm 2007
Luca Corti
Re: OpenBSD firewalls as virtual machine ?

You are not always in control of all things. Powerful technology is
about choice, not about one absolute right way. BTW, NAT sucks.

ciao

Luca

Sep 21, 5:15 pm 2007
Stuart Henderson Sep 21, 3:51 pm 2007
Luca Corti
Re: OpenBSD firewalls as virtual machine ?

We are talking about OpenBSD here, and support for VRF is not there.

ciao

Luca

Sep 21, 5:16 pm 2007
Claudio Jeker
Re: OpenBSD firewalls as virtual machine ?

That may change faster then you expect

Sep 21, 6:34 pm 2007
Luca Corti
Re: OpenBSD firewalls as virtual machine ?

These are great news. If the implementation will allow to assign
interfaces to different VRFs it would solve the virtual router/firewall
setup without the need for OS virtualization.

ciao

Luca

Sep 21, 8:06 pm 2007
Tony Sarendal Sep 21, 7:10 pm 2007
Darren Spruell
Re: OpenBSD firewalls as virtual machine ?

(I'd hoped you would have prefaced that with a statement like "these
are my stock options talking, but...")

This is the kind of bad advice that virtualization companies (and
naive users of those technologies) need to stop spreading. This
security model is flawed, and people should not rely on these virtual
machine environments to provide firewall services.

Here's an entirely realistic scenario at this point:

- Administrator pays loads of money for VMware ESX; for better ROI, he
intends to re...

Sep 21, 10:48 am 2007
Ted Unangst
Re: OpenBSD firewalls as virtual machine ?

so what do you recommend? running all 10 services on the same
non-virtualized machine?

Sep 21, 4:28 pm 2007
Craig Skinner
Re: OpenBSD firewalls as virtual machine ?

When I provided patch support for Solaris 10, the number of times that a
patch would not add to the global zone, thus affecting all local zones
on the host, was fairly common. This affected airlines, banks and oil
companies that you have heard of......

I know an OS is different to a VM platform, but you are still relying on
someone else to do their bit. And just because you have a lottery ticket
worth of support contract does not mean that it will actually get
patched in a timely manner, fr...

Sep 21, 11:09 am 2007
Tony Sarendal
Re: OpenBSD firewalls as virtual machine ?

I have no detailed knowledge of those devices, but I'm pretty sure their
virtual
firewalls are not accomplished by virtualizing the OS, but by supporting
multiple routing tables and rules-sets.

Virtual and virtual may be different in reality.

/Tony

Sep 21, 8:58 am 2007
Darren Spruell
Re: OpenBSD firewalls as virtual machine ?

I'll echo Nick's statements here. Virtualization does not provide
reliable enough segmentation to rely on for security assurance. Do not
buy into the market smack the vendors are putting out about it.

As far as that goes, the more time goes on, the weaker the assumption
of virtualized segmentation becomes. Research from IntelGuardians and
other groups appears to be coming closer to completely unraveling
virtualization security, at least in terms of how it's implemented in
VMware for example. See ...

Sep 21, 2:18 am 2007
Craig Skinner
Re: OpenBSD firewalls as virtual machine ?

Virtual equals complex.

Network devices are supposed to be reliable.

Complex does not equal reliable - just ask anyone that has served in the
military!

Sep 21, 4:03 am 2007
n0g0013
Re: isakmp phase 2 negotiation failed

On 20.09-19:17, Daniel Ouellet wrote:

thanks for the advice. unfortunately both systems are off-site
production machines and cannot be easily upgraded. i will try
manually keying the tunnel in the short term. thanks again

--
t
t
w

Sep 21, 7:00 am 2007
bofh
Re: Is AMD64 page out of date about W^X?

Isn't one of the core2 bugs that nx is only honored for one of the
cores but not the other?

--
"This officer's men seem to follow him merely out of idle curiosity."
-- Sandhurst officer cadet evaluation.

Sep 21, 4:21 pm 2007
Ted Unangst
Re: Is AMD64 page out of date about W^X?

do you have an errata number?

Sep 21, 4:33 pm 2007
bofh
Re: Is AMD64 page out of date about W^X?

Sorry, iirc it was in that link that Theo posted on core 2 errata.
Hopefully I didn't read it incorrectly. But I disclaim everything...

--
"This officer's men seem to follow him merely out of idle curiosity."
-- Sandhurst officer cadet evaluation.

Sep 21, 4:55 pm 2007
previous daytodaynext day
NoneSeptember 21, 2007None