| From | Subject | Date |
|---|---|---|
| Mitja Muženič / Kerb ... | Re: note for faq, maybe
Yes, I can confirm that. I too got bitten by it before and I was considering
proposing a patch for upgradeXX.html, but I got sidetracked.
| Jul 10, 7:38 am 2008 |
| Daniel Melameth | Re: why pf log output to /var/log/messages & /dev/console ?
Appears you turned pf debugging on--try 'pfctl -x none' to shut it off.
| Jul 9, 5:56 pm 2008 |
| (private) HKS | Re: sshd_config(5) PermitRootLogin yes
My 4.3 installs defaulted to PermitRootLogin yes after install.
-HKS
On Thu, Jul 10, 2008 at 10:35 AM, Brian A. Seklecki
| Jul 10, 9:07 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 5:01 PM, Claus Assmann <
ca+OpenBSD_misc@zardoc.endmail.org <ca%2BOpenBSD_misc@zardoc.endmail.org>>
I first have to excuse myself cause I claimed that there were no errors in
the log file!
Well, there was no debugging output enabled. Now I did that with '-d0-17.4'
flags!
Still I don't see anything weird in there! I don't know if you can provide
with an example of such an error or warning?
Thanks
George
| Jul 10, 9:18 am 2008 |
| Brynet | Re: sshd_config(5) PermitRootLogin yes
The keyword here is *default*.
Say you installed OpenBSD on a soekris, it's nice having root enabled
"temporarily".
That way you can login at a later time, create a lesser privledged
account, edit the sudoers file.. and disable root logins in sshd_config.
I believe the developers decision is the best one in this case, it's one
of the first thing I disable though.
| Jul 10, 10:21 am 2008 |
| Will Maier | Re: sendmail STARTTLS
Did you restart sendmail?
--
o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net |
*---------------------[ BSD: Live Free or Die ]--------------------*
| Jul 10, 7:12 am 2008 |
| Wade, Daniel | Re: sshd_config(5) PermitRootLogin yes
afterboot(8) covers this
http://www.openbsd.org/cgi-bin/man.cgi?query=afterboot&apropos=0&sektion=0&ma
npath=OpenBSD+Current&arch=i386&format=html
| Jul 10, 9:21 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 5:05 PM, Stuart Henderson <stu@spacehopper.org>
exaclly! That's what I did. Below is a extract from my current sendmail.cfmail:
-----------
# CA directory
O CACertPath=/etc/mail/CA
# CA file
O CACertFile=/etc/mail/CA/cacert.pem
# Server Cert
O ServerCertFile=/etc/mail/CA/cert.pem
# Server private key
O ServerKeyFile=/etc/mail/CA/key.pem
# Client Cert
O ClientCertFile=/etc/mail/CA/cert.pem
# Client private key
O ClientKeyFile=/etc/mail/CA/key.pem
# File containing ...
| Jul 10, 8:31 am 2008 |
| Leonardo Rodrigues | Re: how to undelete?
If I'm not mistaken, openbsd zeroes the data when you delete a file.
I remember trying to recover a file and then receiving a 0Kb file =)
If you still want to try, you could try using the sleuth kit
(available in ports) to recover something.
| Jul 9, 11:40 pm 2008 |
| Henning Brauer | Re: how to undelete?
no, that would be pointless.
--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam
| Jul 10, 4:14 am 2008 |
| Claus Assmann | Re: sendmail STARTTLS
STARTTLS=server: file /etc/mail/smkey.pem unsafe: Group readable file
Either you aren't running sendmail or you broke logging...
| Jul 10, 3:12 pm 2008 |
| Stuart Henderson | Re: Actual BIND error - Patching OpenBSD 4.3 named ?
right, unbound already randomises the source port (arc4random
from guess where) and also the source address if you list more
than one (assign aliases to the interfaces, and list all of
the IP address in "outgoing-interface" lines in config).
http://nlnetlabs.nl/publications/DNS_cache_poisoning_vulnerability.html
they have their own methods to avoid stomping on ports used
by other UDP services, but since they don't have control over
the rest of the OS, it's a bunch of config parameters, ...
| Jul 10, 7:28 am 2008 |
| Darrin Chandler | Re: sshd_config(5) PermitRootLogin yes
I usually leave it enabled, but with the 'without-password' setting so
that keys must be used.
--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation
| Jul 10, 11:06 am 2008 |
| Vijay Sankar | Re: sendmail STARTTLS
I don't think -B8BITMIME works with sendmail on OpenBSD -- at least it does
not on my 4.3 i386 from CD and on 4.4 -current. Were you thinking of
EightBitMode=mode or do you have any errors on /var/log/maillog with this
flag?
--
Vijay Sankar, M.Eng., P.Eng.
ForeTell Technologies Limited
59 Flamingo Avenue, Winnipeg, MB Canada R3J 0X6
Phone: +1 204 885 9535, E-Mail: vsankar@foretell.ca
| Jul 10, 9:59 am 2008 |
| Eric DILLENSEGER | Re: i945 on Intel Mac mini
I noticed drm was disabled in the generic kernel, so I gave it a try and
built a new one with inteldrm, but still no change, the same error
remains. Is this normal?
I've been wondering if this could be related to disk I/O as it usually
happens when reading from disk. How can I spot the bottleneck?
| Jul 9, 10:40 pm 2008 |
| bofh | Re: note for faq, maybe
On Thu, Jul 10, 2008 at 2:26 PM, Nick Holland <nick@holland-consulting.net>
(through a bitnet gateway)...
--
http://www.glumbert.com/media/shift
http://www.youtube.com/watch?v=tGvHNNOLnCk
"This officer's men seem to follow him merely out of idle curiosity." --
Sandhurst officer cadet evaluation.
"Securing an environment of Windows platforms from abuse - external or
internal - is akin to trying to install sprinklers in a fireworks factory
where smoking on the job is permitted." -- ...
| Jul 10, 11:50 am 2008 |
| Will Maier | Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 02:08:30PM +0200, GVG GVG wrote:
Did you look in your maillogs?
--
o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net |
*---------------------[ BSD: Live Free or Die ]--------------------*
| Jul 10, 6:33 am 2008 |
| David Vasek | Re: how to undelete?
For the archives: unless it is specifically requested as
rm -P
Regards,
David
| Jul 10, 5:03 am 2008 |
| Marco Peereboom | Re: sshd_config(5) PermitRootLogin yes
And they got it all wrong. It is all for the perceived sense of
security. Not being able to login over ssh right after install sucks.
I am that guy that ends up enabling it on all other boxes that use a
different default.
The machine I install and then deploy to be hostile network connected
gets some extra love in that department however crippling every box by
default for no gain is counter productive.
| Jul 10, 11:31 am 2008 |
| Brian A. Seklecki | Re: sshd_config(5) PermitRootLogin yes
On Soekris, does the first boot console access not function properly until
ttys(5) or boot.conf(5) are edited? Do you need to run headless, but with
stored network configuration from the installer?
| Jul 10, 10:39 am 2008 |
| Eric Dillenseger | Ports dependencies
Hi misc@,
When installing a package from the ports, there are build dependencies
and runtime dependencies.
In many cases, B-deps aren't used once the package is installed.
Is there any other way than looking at the ports makefile to spot the
B-deps installed on a system ?
| Jul 10, 5:00 am 2008 |
| David Hill | Re: sendmail Maildir
Hi George -
You need to use a mail delivery agent (MDA), such as procmail, maildrop,
or dovecot's deliver.
- David
| Jul 10, 8:10 am 2008 |
| Darrin Chandler | Re: sshd_config(5) PermitRootLogin yes
This is how I normally do it. I don't like to stand at a crash cart kvm
when I can sit at my desk. ;-)
If you have a good root password then it's not much of an issue anyway.
--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation
| Jul 10, 11:27 am 2008 |
| Ted Unangst | Re: 4.4 beta wont shut down properly
One thing to rule out would be the buffer cache changes. These were
committed over a little time, but you could check a kernel from june
9th (before) and june 15th (after). of course, that's the week of the
hackathon, so lots of other changes occurred as well. but try those
dates.
| Jul 10, 8:44 am 2008 |
| Johannes (Barix) | Re: Digital IO - Phidgets support? alternatives?
Hi, here's the Barix voice :)
The products are quite different in that the Barionet can be programmed in a
basic dialect for quite sophisticated functions (if required), connects via
IP, and can be polled by SNMP, CGI, UDP or TCP (ascii protocols).
You could also use much cheaper products from our range (see
http://www.barix.com barix website ) like the X8 or IO12 (industrial I/O),
but these have an RS-485 interface so you need to poll them with Modbus/RTU
- or have the Barionet do this for ...
| Jul 10, 1:25 pm 2008 |
| David Krause | Re: Actual BIND error - Patching OpenBSD 4.3 named ?
It doesn't notice this as an improvement because it is making multiple
requests to the same name server, and pf will map all these requests
using the same outgoing port.
David
| Jul 10, 9:58 am 2008 |
| Edd Barrett | Re: Iwi, wireless bad behavior
After iwi is boned, also my fxp is boned. Same situation different hardware.
I mailed damien pointing at this thread, but no reply.
--
Best Regards
Edd
http://students.dec.bournemouth.ac.uk/ebarrett
| Jul 10, 4:18 pm 2008 |
| GVG GVG | sendmail STARTTLS
Dear list,
running currently 4.3 generic with sendmail:
Compiled with: DNSMAP LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8 MIME8TO7
NAMED_BIND NETINET NETINET6 NETUNIX NEWDB NIS PIPELINING
SCANF
STARTTLS TCPWRAPPERS USERDB XDEBUG
----------------------
did try to setup STARTTLS but I don't think that it works! here are the
modifications in my .mc file:
----------------------
define(`CERT_DIR', `MAIL_SETTINGS_DIR`'CA')dnl
define(`confCACERT_PATH', ...
| Jul 10, 5:08 am 2008 |
| Stuart Henderson | Re: sendmail Maildir
You need a local delivery agent that can understand Maildir.
e.g. procmail, maildrop, Dovecot's deliver, [..]
| Jul 10, 8:07 am 2008 |
| James Hartley | Re: Can't install using pkg_add from FTP mirror and from ...
You should study Section 15.4.1 of the FAQ:
http://openbsd.org/faq/faq15.html#NoFun
However if you still have questions, please provide the output of the
following command:
$ sysctl kern.version
As others, I too suspect you have installed -current & are trying to
install -release packages.
| Jul 9, 9:01 pm 2008 |
| my mail | Re: Can't install using pkg_add from FTP mirror and from ...
thanks for your reply, but i have download OpenBSD 4.3 from this address ftp://ftp.jaist.ac.jp/pub/OpenBSD/4.3/
and all packages i download from this ftp://ftp.jaist.ac.jp/pub/OpenBSD/4.3/packages/
so all of this i install OpenBSD release not snapshots
why in my system have libiconv.so.5.0 because i never install it?
it's possible this happen because i install bash from ports?
after install openbsd, then i install bash from ports then i try to install gdm from packages i have ...
| Jul 9, 7:45 pm 2008 |
| GVG GVG | Re: sendmail Maildir
On Thu, Jul 10, 2008 at 5:07 PM, Stuart Henderson <stu@spacehopper.org>
I intend to install Dovecot! So obviously that will do the job!
Thanks for your prompt reply
George
| Jul 10, 8:25 am 2008 |
| Jacob Meuser | Re: Can't install using pkg_add from FTP mirror and from ...
my guess is you checked out or updated your ports tree incorrectly.
you want 4.3 ports to match your 4.3 base, so you need to use the
-rOPENBSD_4_3 tag with the cvs command. otherwise, you will get a
-current ports tree, and you will have problems.
--
jakemsr@sdf.lonestar.org
SDF Public Access UNIX System - http://sdf.lonestar.org
| Jul 9, 11:24 pm 2008 |
| Gordon Grieder | Re: how to undelete?
For some unknown reason this prompted me to look at the rm manpage for the
hell of it (yeah, bored and tired at the moment). There's an odd comment in
the STANDARDS section which says
"The interactive mode used to be a dsw command, a carryover from the an-
cient past with an amusing etymology."
That piqued my interest further (yeah, still bored and still tired at the
moment) so I googled away and found this tidbit about the mysterious dsw
command: ...
| Jul 10, 7:23 am 2008 |
| Brian A. Seklecki | Re: sshd_config(5) PermitRootLogin yes
Works for me, I guess. =/
| Jul 10, 9:43 am 2008 |
| Nick Holland | Re: note for faq, maybe
Sounds good, but as I've successfully avoided both PPP and PPPoE for
well over ten years now, I have no way to completely test, a diff
would be nice.
Nick.
| Jul 10, 11:26 am 2008 |
| Brian A. Seklecki | sshd_config(5) PermitRootLogin yes
Am I reading this right?
http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?rev=1.80&content...
I dont have a fresh install anywhere -- but I want to say that it doesnt
default to PermitRootLogin yes after the install.
I remember that I filed PRs with FreeBSD/NetBSD a few years ago to get
this changed, but Redhat Support is giving some some noise about:
"Well the source vendor doesn't disable it by default ..."
~BAS
| Jul 10, 7:35 am 2008 |
| Charles Smith | yacc rebuild
Good afternoon!
So, before the next make build I must rebuild the yacc alone.
I would like to know how can I rebuild yacc.
I searched in old errata patches, Makefiles, bsd.*.mk files.
In my previous logfile (2008.07.07/src_make_build) I see, that by
yacc the "make cleandir" is used:
"rm -f yacc.cat1 ...
rm -f .depend ...tags"
So is this correct?
cd usr.bin/yacc
make obj
make cleandir
make depend
make
make install
In general, how can I ascertain, what kind of make Phony Targets ...
| Jul 10, 9:47 am 2008 |
| Claus Assmann | Re: sendmail STARTTLS
1. man starttls (and see the referenced website).
2. increase the LogLevel (even though those errors should be logged
at the default level.)
| Jul 10, 8:01 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
Thnaks
George
| Jul 10, 6:36 am 2008 |
| Top Shop | Celluless - Hit cena na internetu- samo do 12. 07.
Top Shop
Ekskluzivna pretprodaja - samo na internetu!
80-95%
| Jul 10, 11:12 am 2008 |
| Dongsheng Song | why pf log output to /var/log/messages & /dev/console ?
I searched /etc/syslog.conf, but can't find how to disable it.
Jul 10 08:40:04 proxy /bsd: pf: loose state match: TCP in wire:
192.168.4.132:3833 58.253.67.248:80 stack: - [lo=3472355129
high=3472419308 win=65535 modulator=0] [lo=3167937694 high=3168002906
win=64857 modulator=0] 10:10 R seq=3472355129 (3472354451)
ack=3167937694 len=0 ackskew=0 pkts=5:3 dir=in,fwd
Jul 10 08:43:37 proxy /bsd: pf: wire key attach failed on all: TCP out
wire: 219.149.124.163:80 210.21.12.116:50157 ...
| Jul 9, 5:48 pm 2008 |
| Brian | Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
I have to agree with this guy. The openBSD team all ways goes above and beyond what we see other vendors do. The solutions have lasting value, rather then quick fixes that break a year later.
Anybody else remember the nvidia close driver issue that Theo had foreseen years before it happened? Trust these guys. They will deliver.
Brian
| Jul 9, 7:51 pm 2008 |
| Jose Fragoso | Re: trouble with running spamd on 4.4 BETA [SOLVED]
Hi again,
It seems that I needed:
set skip on lo0
Funny thing is that the same ruleset works on 4.3 without the
need for this statement.
Was there some change in the route-to logic from 4.3 to 4.4?
This may be of interest for someone running spamd in a bridge
setup.
Kind regards,
Jose.
--
Be Yourself @ mail.com!
Choose From 200+ Email Addresses
Get a Free Account at www.mail.com
| Jul 10, 2:18 pm 2008 |
| Dongsheng Song | Re: why pf log output to /var/log/messages & /dev/console ?
Thank you, it's OK now !
| Jul 9, 11:50 pm 2008 |
| Peter N. M. Hansteen | Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
reading tea leaves^H^H^H^H^H^H^H^H^H^Hsource-changes has me thinking
the BIND bug has spurred some activity in other parts of the tree, too
(as in, "bugs are never unique, in OpenBSD we look for patterns or
AOL!
--
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.
| Jul 10, 1:24 am 2008 |
| Will Maier | Re: sshd_config(5) PermitRootLogin yes
Yes.
This has been discussed. Check the archives if you'd like.
--
o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net |
*---------------------[ BSD: Live Free or Die ]--------------------*
| Jul 10, 9:12 am 2008 |
| Vijay Sankar | Re: sendmail -B option
Sorry for the noise. I should not have sent that message.
What happened was, in a misguided attempt to help, I tried running sendmail
with the various options GVG had mentioned.
/usr/sbin/sendmail -L sm-mta -C/etc/mail/sendmail.cf -bd -qp -B8BITMIME -X
/$HOME/mail_log
and got the error
Jul 10 11:54:09 vijay sm-mta[22142]:
NOQUEUE:SYSERR(root): /etc/mail/sendmail.cf: line 0: cannot open: No such
file or directory
on my desktop. Obviously this had nothing to do with -B8BITMIME ...
| Jul 10, 1:10 pm 2008 |
| Philip Guenther | sendmail -B option
On Thu, Jul 10, 2008 at 9:59 AM, Vijay Sankar <vsankar@foretell.ca> wrote:
<sigh> What do you think it does, how did you use it, and how did you
determine that it has no effect?
I've already noted that the -B option only affects submission and is
ignored when running sendmail as a daemon, making GVG's usage of it
incorrect. If you aren't feeding the sendmail command an email
message on stdin, then the -B option isn't for you.
Philip Guenther
| Jul 10, 10:21 am 2008 |
| Philip Guenther | Re: sendmail STARTTLS
Off topic to this thread, but:
On Thu, Jul 10, 2008 at 8:24 AM, GVG GVG <gvgter@googlemail.com> wrote:
Remove -B8BITMIME from that: the -B option is only applicable when
sending email. Indeed, you should be seeing this error at boot time:
WARNING: Ignoring submission mode -B option (not in submission mode)
What docs suggested that you add that?
(For the topic of this thread, you did eyeball /var/log/maillog after
restarting, right?)
Philip Guenther
| Jul 10, 9:39 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
Thanks for your reply but I thought that this is necessary only if SMTP_AUTH
should be enabled! In my case I'll use an IMAP server instead!
George
| Jul 10, 6:19 am 2008 |
| my mail | Re: Can't install using pkg_add from FTP mirror and from ...
thank you all (Jacob Meuser, Markus Lude, Louis V. Lambrecht, James Hartley) for your help
i have reinstall my openbsd 4.3 and then use this -rOPENBSD_4_3 for update ports, and now i have been able to install from packages and ports
it's my faults because i remember, i have update ports without -rOPENBSD_4_3 tags
i litle bit confused about release and stable, if i download ISO from OpenBSD/4.3 ftp, then this is a release, then if i want using --stable, i must using -rOPENBSD_4_3 tags for ...
| Jul 10, 1:33 am 2008 |
| Dawe | Re: Ports dependencies
pkg_info -t might help you.
| Jul 10, 5:41 am 2008 |
| Jacob Yocom-Piatt | Re: sshd_config(5) PermitRootLogin yes
maybe if people actually READ THE ARCHIVES, they'd be better informed. i
wish this mailing list had
PermitStupidEmails No
as the default.
i really fail to see how this setting does anything other than make mgmt
| Jul 10, 3:59 pm 2008 |
| Will Maier | Re: sendmail STARTTLS
No. So you updated your .mc file as above, installed it as
/etc/mail/localhost.cf and HUPed sendmail? By default on OpenBSD,
sendmail is started with the following flags:
-L sm-mta -C/etc/mail/localhost.cf -bd -q30m
If you installed your new .cf file as sendmail.cf, sendmail won't
read it (unless you change or drop the -C flag).
--
o--------------------------{ Will Maier }--------------------------o
| web:.......http://www.lfod.us/ | email.........willmaier@ml1.net ...
| Jul 10, 7:55 am 2008 |
| GVG GVG | sendmail Maildir
Dear List,
having a 4.3 and sendmail installation, the default locations where the
mails go is /var/mail/$USER. How can I change that and point to a Maildir
formatted location?
Thanks
George
| Jul 10, 7:56 am 2008 |
| Marc Balmer | note for faq, maybe
if you use pppoe(4) for internet, and want to do a remote
update from 4.2 to 4.3, over said pppoe(4) link, then the
normal update procedure will not work, because the 4.3
kernel and the 4.2 ifconfig binary can not work together.
after rebooting the new 4.3 bsd kernel, the network will
not be configure and you will walk/drive to the system (just
like I did today).
so, brefore rebooting to 4.3, at least unpack the 4.3 ifconfig
binary from base43.tgz
- Marc
| Jul 10, 6:55 am 2008 |
| Stuart Henderson | Re: sendmail STARTTLS
You did rebuild the .cf file from the .mc file, right?
STARTTLS(8) OpenBSD System Manager's Manual STARTTLS(8)
[...]
Now that you have the TLS-enabled versions of the .mc files you must gen-
erate .cf files from them and install the .cf files in /etc/mail.
[...]
| Jul 10, 8:05 am 2008 |
| Fred Crowson | Re: sshd_config(5) PermitRootLogin yes
Hi Brian,
The default is: PermitRootLogin yes
As illustrated on below.
HTH
Fred
bsd:fred /home/fred> ssh root@192.168.5.26
root@192.168.5.26's password:
Last login: Wed Mar 5 19:08:20 2008
OpenBSD 4.4-beta (GENERIC) #232: Wed Jul 2 12:31:55 MDT 2008
Welcome to OpenBSD: The proactively secure Unix-like operating system.
Please use the sendbug(1) utility to report bugs in the system.
Before reporting a bug, please try to reproduce it with the latest
version of the code. With ...
| Jul 10, 9:12 am 2008 |
| Marco Peereboom | Re: sshd_config(5) PermitRootLogin yes
Of course it is enabled by default. Why do I want a box that is
freshly installed and unreachable?
| Jul 10, 9:34 am 2008 |
| my mail | Re: Can't install using pkg_add from FTP mirror and from ...
this a result from previous command
# ls -ald /var/db/pkg/.*
ls: /var/db/pkg/.*: No such file or directory
# ls -ald /var/db/pkg/
drwxr-xr-x 53 root wheel 1536 Jul 9 15:17 /var/db/pkg/
# ls -al /var/db/pkg/.*
ls: /var/db/pkg/.*: No such file or directory
# ls -al /var/db/pkg/
total 212
drwxr-xr-x 53 root wheel 1536 Jul 9 15:17 .
drwxr-xr-x 5 root wheel 512 Jul 8 11:07 ..
drwxr-xr-x 2 root wheel 512 Jul 7 ...
| Jul 9, 8:10 pm 2008 |
| Louis V. Lambrecht | Re: Can't install using pkg_add from FTP mirror and from ...
Nothing for ls -ald /var/db/pkg/.*
is a positive point.
What is completely wrong for a 4.3 release, as Jacob said,
your libiconv should be *libiconv-1.9.2p5
*as a result your gettext is also wrong, should be *gettext-0.16.1
*You, somehow, incorrectly installed the latest gettext (from current)
and correctly try to install glib2 from release. Wich is not compatible.
Since you don't have dot entries in the /var/db/pkg
you probably can pkg_delete gettext and libiconv
and reinstall them from ...
| Jul 9, 9:50 pm 2008 |
| Markus Lude | Re: Can't install using pkg_add from FTP mirror and from ...
Yes, you mix -stable and -current. If you build from ports you should
use the same branch as the rest of your system (-stable).
The latest version of bash in -stable is 3.2.33, not 3.2.39. The later
one is in -current. When you build bash you seems to have pulled in
(build) the newer libiconv too. The latest version of libiconv in
-stable is 1.9.2p5.
You may read chapter 5 and 15 of the FAQ, especially
http://www.openbsd.org/faq/faq15.html#NoFun
Regards,
Markus
| Jul 9, 10:08 pm 2008 |
| Vincent Li | Transparent OpenBSD firewall rules for Retrospect
Hi OpenBSD PF experts,
I am managing a private network 192.168.1.0/24, 192.168.1.2 is my
Retrospect backup server running on OS X 10.5 to back up the rest of
computers.
To add another layer to protect my backup server, I add an OpenBSD4.3 PF
transparent firewall in front of 192.168.1.2, Since it is transparent, all
my current private network setting keeps the same.
my /etc/bridgename.bridge0:
add sis0
add sis1
blocknoip sis0
blocknoip sis1
up
my ...
| Jul 10, 3:31 pm 2008 |
| Josh | 4.4 beta wont shut down properly
Hello.
On two machines now, recent snapshots are not powering off properly on machines which used to, when I run shutdown -p -h now.
It stops at syncing disks, and stays there forever. After a hard reset, / comes up as not being unmounted successfully.
I am a quite busy right now, but if someone could tell me what src files deal with this area, So I can perhaps back track to a time when shutdowns worked ok after work.
Anyone have any ideas?
Cheers,
Josh
OpenBSD 4.4-beta (GENERIC) ...
| Jul 9, 7:40 pm 2008 |
| Louis V. Lambrecht | Re: Can't install using pkg_add from FTP mirror and from ...
Frankly, re-re-re-re-read the FAQ.
Since you just re-installed and still want -current packages, the best
way would
be to grab a snapshot and do a fresh install.
Do this on a date at which your mirror has packages with the same date than
the snapshots. (or a day or two off).
Release updates are almost foolproof, updating from snapshots might break,
while a snapshot of the next day would be perfect.
My personal opinion:
when you have both the stock OS and sources and started installing ...
| Jul 10, 8:55 am 2008 |
| Daniel B. | Re: Iwi, wireless bad behavior
I have similar behavior using bwi(4) driver, although I'm using WPA2.
But it's something worst since I can use for some minutes when I lost
the connection. After that, I can't even make nfe(4) run.
The only "solution" I found is reboot. Since this isn't a solution, when
possible, I prefer to use nfe(4) Ethernet connection.
Cheers,
| Jul 10, 11:43 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
Sorry I did a mistake! The changes in the .mc file are:
----------------
define(`CERT_DIR', `MAIL_SETTINGS_DIR`'CA')dnl
define(`confCACERT_PATH', `CERT_DIR')dnl
define(`confCACERT', `CERT_DIR/cacert.pem')dnl
define(`confSERVER_CERT', `CERT_DIR/cert.pem')dnl
define(`confSERVER_KEY', `CERT_DIR/key.pem')dnl
define(`confCLIENT_CERT', `CERT_DIR/cert.pem')dnl
define(`confCLIENT_KEY', `CERT_DIR/key.pem')dnl
--------------
using the same certs for 'server' and 'client'! So the files do ...
| Jul 10, 7:26 am 2008 |
| Brian A. Seklecki | Re: sshd_config(5) PermitRootLogin yes
No -- I just find that most of afterboot(8) can be done from the console;
even serial console, at first boot, configure the network, add a non-root
user, add them to wheel, enable sshd.
I guess I'm just having trouble imagining the situation where you have
console access, but need to do basic post-install configuration via the
network, as root, remotely.
Even with CF/Embedded, you ship out master.passwd prepopualted.
And this is likely the rationel why the rest of the projects changed ...
| Jul 10, 10:38 am 2008 |
| Giancarlo Razzolini | Re: sshd_config(5) PermitRootLogin yes
I do prefer to use the siteXX.tgz and the install.site script to do
this, since it is the recommended way to customize the install process:
http://www.openbsd.org/faq/faq4.html#site
I remember other thread on this list about this. At some point someone
asked "Why not ask the installing user to create an unprivileged account
during the install process?". The answer was simple and very coherent:
"Because we want the user to give root user a strong password. If we
prompt for another user creation, ...
| Jul 10, 11:16 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
Yes they do exist:
------------------------------
-bash-3.2$ pwd
/etc/mail/CA
-bash-3.2$ ls -l
total 56
-rw-r--r-- 1 root wheel 1229 Jun 23 17:02 cacert.pem
-rw-r--r-- 1 root wheel 875 Jun 18 13:46 cacert.pm
-rw------- 1 root wheel 3848 Jun 23 17:11 cert.pem
drwxr-xr-x 2 root wheel 512 Jun 17 16:25 certs
drwxr-xr-x 2 root wheel 512 Jun 23 17:17 crl
-rw------- 1 root wheel 3 Jun 23 17:17 crlnumber
-rw------- 1 root wheel 68 Jun 23 17:11 index.txt
-rw------- 1 ...
| Jul 10, 6:56 am 2008 |
| GVG GVG | Re: sendmail STARTTLS
correct but I didn't install as 'localhost' but as 'sendmail.cf'. My server
does accept mails from the outside world! After that I did restart the box!
Sendmail gets started as:
sendmail_flags="-L sm-mta -C/etc/mail/sendmail.cf -bd -qp -B8BITMIME -X
/[$HOME]/mail_log"
| Jul 10, 8:24 am 2008 |
| mail-lists | VPN Failover
Hello List,
I'm having some issues with IPSec VPN tunnels.
Here is what I'm trying to do:
I have a VPN 'server' with 2 internet connections (IP1, IP2)
I have several remote locations which connect to the VPN server.
When IP1 goes down on the VPN server I want the remote
locations to negotiate the tunnel with IP2
What is the best way to accomplish this? I have tried a couple of
different things, none successful.
My ipsec.conf on the ...
| Jul 10, 6:36 am 2008 |
| Pete Vickers | Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
looks like there is some work in progress to update the in-tree BIND
to 9.4.2-P1 + local tweaking, for example:
http://www.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/bind/lib/dns/dispatch.c?r1=1.8
As Theo points out, patience is a virtue, and it's the "+ local
tweaking" above that is the reason I gratefully use OpenBSD.
/Pete
| Jul 10, 1:15 am 2008 |
| Paul de Weerd | Re: sshd_config(5) PermitRootLogin yes
Note that you can already create this account and edit sudoers while
still in the installer kernel. Simply `mnt/usr/sbin/chroot /mnt` and
you are in your new system where you can change basic things (such as
adding users and editing config files, do not expect to be able to do
more fancy stuff like firewalling (so you can edit pf.conf, you just
can not load it until after rebooting), you're still in the install
kernel which lacks several key features provided by the regular
kernel).
root ...
| Jul 10, 10:40 am 2008 |
| previous day | today | next day |
|---|---|---|
| July 9, 2008 | July 10, 2008 | July 11, 2008 |
| Greg KH | Og dreams of kernels |
| Jens Axboe | [PATCH 31/33] Fusion: sg chaining support |
| Arnd Bergmann | Re: finding your own dead "CONFIG_" variables |
| Mark Brown | [PATCH 2/2] Subject: natsemi: Allow users to disable workaround for DspCfg reset |
| Tony Breeds | [LGUEST] Look in object dir for .config |
git: | |
| Brian Downing | Re: Git in a Nutshell guide |
| John Benes | Re: master has some toys |
| Matthias Lederhofer | [PATCH 4/7] introduce GIT_WORK_TREE to specify the work tree |
| Alexander Sulfrian | [RFC/PATCH] RE: git calls SSH_ASKPASS even if DISPLAY is not set |
| Junio C Hamano | Re: Rss produced by git is not valid xml? |
| Linux Kernel Mailing List | iSeries: fix section mismatch in iseries_veth |
| Linux Kernel Mailing List | ixbge: remove TX lock and redo TX accounting. |
| Linux Kernel Mailing List | ixgbe: fix several counter register errata |
| Linux Kernel Mailing List | b43: fix build wit |
