openbsd-misc mailing list

Fromsort iconSubjectDate
Mitja Muženič / Kerb ...
Re: note for faq, maybe
Yes, I can confirm that. I too got bitten by it before and I was considering proposing a patch for upgradeXX.html, but I got sidetracked.
Jul 10, 7:38 am 2008
Daniel Melameth
Re: why pf log output to /var/log/messages & /dev/console ?
Appears you turned pf debugging on--try 'pfctl -x none' to shut it off.
Jul 9, 5:56 pm 2008
(private) HKS
Re: sshd_config(5) PermitRootLogin yes
My 4.3 installs defaulted to PermitRootLogin yes after install. -HKS On Thu, Jul 10, 2008 at 10:35 AM, Brian A. Seklecki
Jul 10, 9:07 am 2008
GVG GVG
Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 5:01 PM, Claus Assmann < ca+OpenBSD_misc@zardoc.endmail.org <ca%2BOpenBSD_misc@zardoc.endmail.org>> I first have to excuse myself cause I claimed that there were no errors in the log file! Well, there was no debugging output enabled. Now I did that with '-d0-17.4' flags! Still I don't see anything weird in there! I don't know if you can provide with an example of such an error or warning? Thanks George
Jul 10, 9:18 am 2008
Brynet
Re: sshd_config(5) PermitRootLogin yes
The keyword here is *default*. Say you installed OpenBSD on a soekris, it's nice having root enabled "temporarily". That way you can login at a later time, create a lesser privledged account, edit the sudoers file.. and disable root logins in sshd_config. I believe the developers decision is the best one in this case, it's one of the first thing I disable though.
Jul 10, 10:21 am 2008
Will Maier
Re: sendmail STARTTLS
Did you restart sendmail? -- o--------------------------{ Will Maier }--------------------------o | web:.......http://www.lfod.us/ | email.........willmaier@ml1.net | *---------------------[ BSD: Live Free or Die ]--------------------*
Jul 10, 7:12 am 2008
Wade, Daniel Jul 10, 9:21 am 2008
GVG GVG
Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 5:05 PM, Stuart Henderson <stu@spacehopper.org> exaclly! That's what I did. Below is a extract from my current sendmail.cfmail: ----------- # CA directory O CACertPath=/etc/mail/CA # CA file O CACertFile=/etc/mail/CA/cacert.pem # Server Cert O ServerCertFile=/etc/mail/CA/cert.pem # Server private key O ServerKeyFile=/etc/mail/CA/key.pem # Client Cert O ClientCertFile=/etc/mail/CA/cert.pem # Client private key O ClientKeyFile=/etc/mail/CA/key.pem # File containing ...
Jul 10, 8:31 am 2008
Leonardo Rodrigues
Re: how to undelete?
If I'm not mistaken, openbsd zeroes the data when you delete a file. I remember trying to recover a file and then receiving a 0Kb file =) If you still want to try, you could try using the sleuth kit (available in ports) to recover something.
Jul 9, 11:40 pm 2008
Henning Brauer
Re: how to undelete?
no, that would be pointless. -- Henning Brauer, hb@bsws.de, henning@openbsd.org BS Web Services, http://bsws.de Full-Service ISP - Secure Hosting, Mail and DNS Services Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam
Jul 10, 4:14 am 2008
Claus Assmann
Re: sendmail STARTTLS
STARTTLS=server: file /etc/mail/smkey.pem unsafe: Group readable file Either you aren't running sendmail or you broke logging...
Jul 10, 3:12 pm 2008
Stuart Henderson
Re: Actual BIND error - Patching OpenBSD 4.3 named ?
right, unbound already randomises the source port (arc4random from guess where) and also the source address if you list more than one (assign aliases to the interfaces, and list all of the IP address in "outgoing-interface" lines in config). http://nlnetlabs.nl/publications/DNS_cache_poisoning_vulnerability.html they have their own methods to avoid stomping on ports used by other UDP services, but since they don't have control over the rest of the OS, it's a bunch of config parameters, ...
Jul 10, 7:28 am 2008
Darrin Chandler
Re: sshd_config(5) PermitRootLogin yes
I usually leave it enabled, but with the 'without-password' setting so that keys must be used. -- Darrin Chandler | Phoenix BSD User Group | MetaBUG dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/ http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation
Jul 10, 11:06 am 2008
Vijay Sankar
Re: sendmail STARTTLS
I don't think -B8BITMIME works with sendmail on OpenBSD -- at least it does not on my 4.3 i386 from CD and on 4.4 -current. Were you thinking of EightBitMode=mode or do you have any errors on /var/log/maillog with this flag? -- Vijay Sankar, M.Eng., P.Eng. ForeTell Technologies Limited 59 Flamingo Avenue, Winnipeg, MB Canada R3J 0X6 Phone: +1 204 885 9535, E-Mail: vsankar@foretell.ca
Jul 10, 9:59 am 2008
Eric DILLENSEGER
Re: i945 on Intel Mac mini
I noticed drm was disabled in the generic kernel, so I gave it a try and built a new one with inteldrm, but still no change, the same error remains. Is this normal? I've been wondering if this could be related to disk I/O as it usually happens when reading from disk. How can I spot the bottleneck?
Jul 9, 10:40 pm 2008
bofh
Re: note for faq, maybe
On Thu, Jul 10, 2008 at 2:26 PM, Nick Holland <nick@holland-consulting.net> (through a bitnet gateway)... -- http://www.glumbert.com/media/shift http://www.youtube.com/watch?v=tGvHNNOLnCk "This officer's men seem to follow him merely out of idle curiosity." -- Sandhurst officer cadet evaluation. "Securing an environment of Windows platforms from abuse - external or internal - is akin to trying to install sprinklers in a fireworks factory where smoking on the job is permitted." -- ...
Jul 10, 11:50 am 2008
Will Maier
Re: sendmail STARTTLS
On Thu, Jul 10, 2008 at 02:08:30PM +0200, GVG GVG wrote: Did you look in your maillogs? -- o--------------------------{ Will Maier }--------------------------o | web:.......http://www.lfod.us/ | email.........willmaier@ml1.net | *---------------------[ BSD: Live Free or Die ]--------------------*
Jul 10, 6:33 am 2008
David Vasek
Re: how to undelete?
For the archives: unless it is specifically requested as rm -P Regards, David
Jul 10, 5:03 am 2008
Marco Peereboom
Re: sshd_config(5) PermitRootLogin yes
And they got it all wrong. It is all for the perceived sense of security. Not being able to login over ssh right after install sucks. I am that guy that ends up enabling it on all other boxes that use a different default. The machine I install and then deploy to be hostile network connected gets some extra love in that department however crippling every box by default for no gain is counter productive.
Jul 10, 11:31 am 2008
Brian A. Seklecki
Re: sshd_config(5) PermitRootLogin yes
On Soekris, does the first boot console access not function properly until ttys(5) or boot.conf(5) are edited? Do you need to run headless, but with stored network configuration from the installer?
Jul 10, 10:39 am 2008
Eric Dillenseger
Ports dependencies
Hi misc@, When installing a package from the ports, there are build dependencies and runtime dependencies. In many cases, B-deps aren't used once the package is installed. Is there any other way than looking at the ports makefile to spot the B-deps installed on a system ?
Jul 10, 5:00 am 2008
David Hill
Re: sendmail Maildir
Hi George - You need to use a mail delivery agent (MDA), such as procmail, maildrop, or dovecot's deliver. - David
Jul 10, 8:10 am 2008
Darrin Chandler
Re: sshd_config(5) PermitRootLogin yes
This is how I normally do it. I don't like to stand at a crash cart kvm when I can sit at my desk. ;-) If you have a good root password then it's not much of an issue anyway. -- Darrin Chandler | Phoenix BSD User Group | MetaBUG dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/ http://www.stilyagin.com/ | Daemons in the Desert | Global BUG Federation
Jul 10, 11:27 am 2008
Ted Unangst
Re: 4.4 beta wont shut down properly
One thing to rule out would be the buffer cache changes. These were committed over a little time, but you could check a kernel from june 9th (before) and june 15th (after). of course, that's the week of the hackathon, so lots of other changes occurred as well. but try those dates.
Jul 10, 8:44 am 2008
Johannes (Barix)
Re: Digital IO - Phidgets support? alternatives?
Hi, here's the Barix voice :) The products are quite different in that the Barionet can be programmed in a basic dialect for quite sophisticated functions (if required), connects via IP, and can be polled by SNMP, CGI, UDP or TCP (ascii protocols). You could also use much cheaper products from our range (see http://www.barix.com barix website ) like the X8 or IO12 (industrial I/O), but these have an RS-485 interface so you need to poll them with Modbus/RTU - or have the Barionet do this for ...
Jul 10, 1:25 pm 2008
David Krause
Re: Actual BIND error - Patching OpenBSD 4.3 named ?
It doesn't notice this as an improvement because it is making multiple requests to the same name server, and pf will map all these requests using the same outgoing port. David
Jul 10, 9:58 am 2008
Edd Barrett
Re: Iwi, wireless bad behavior
After iwi is boned, also my fxp is boned. Same situation different hardware. I mailed damien pointing at this thread, but no reply. -- Best Regards Edd http://students.dec.bournemouth.ac.uk/ebarrett
Jul 10, 4:18 pm 2008
GVG GVG
sendmail STARTTLS
Dear list, running currently 4.3 generic with sendmail: Compiled with: DNSMAP LOG MAP_REGEX MATCHGECOS MILTER MIME7TO8 MIME8TO7 NAMED_BIND NETINET NETINET6 NETUNIX NEWDB NIS PIPELINING SCANF STARTTLS TCPWRAPPERS USERDB XDEBUG ---------------------- did try to setup STARTTLS but I don't think that it works! here are the modifications in my .mc file: ---------------------- define(`CERT_DIR', `MAIL_SETTINGS_DIR`'CA')dnl define(`confCACERT_PATH', ...
Jul 10, 5:08 am 2008
Stuart Henderson
Re: sendmail Maildir
You need a local delivery agent that can understand Maildir. e.g. procmail, maildrop, Dovecot's deliver, [..]
Jul 10, 8:07 am 2008
James Hartley
Re: Can't install using pkg_add from FTP mirror and from ...
You should study Section 15.4.1 of the FAQ: http://openbsd.org/faq/faq15.html#NoFun However if you still have questions, please provide the output of the following command: $ sysctl kern.version As others, I too suspect you have installed -current & are trying to install -release packages.
Jul 9, 9:01 pm 2008
my mail
Re: Can't install using pkg_add from FTP mirror and from ...
thanks for your reply, but i have download OpenBSD 4.3 from this address ftp://ftp.jaist.ac.jp/pub/OpenBSD/4.3/ and all packages i download from this ftp://ftp.jaist.ac.jp/pub/OpenBSD/4.3/packages/ so all of this i install OpenBSD release not snapshots why in my system have libiconv.so.5.0 because i never install it? it's possible this happen because i install bash from ports? after install openbsd, then i install bash from ports then i try to install gdm from packages i have ...
Jul 9, 7:45 pm 2008
GVG GVG
Re: sendmail Maildir
On Thu, Jul 10, 2008 at 5:07 PM, Stuart Henderson <stu@spacehopper.org> I intend to install Dovecot! So obviously that will do the job! Thanks for your prompt reply George
Jul 10, 8:25 am 2008
Jacob Meuser
Re: Can't install using pkg_add from FTP mirror and from ...
my guess is you checked out or updated your ports tree incorrectly. you want 4.3 ports to match your 4.3 base, so you need to use the -rOPENBSD_4_3 tag with the cvs command. otherwise, you will get a -current ports tree, and you will have problems. -- jakemsr@sdf.lonestar.org SDF Public Access UNIX System - http://sdf.lonestar.org
Jul 9, 11:24 pm 2008
Gordon Grieder
Re: how to undelete?
For some unknown reason this prompted me to look at the rm manpage for the hell of it (yeah, bored and tired at the moment). There's an odd comment in the STANDARDS section which says "The interactive mode used to be a dsw command, a carryover from the an- cient past with an amusing etymology." That piqued my interest further (yeah, still bored and still tired at the moment) so I googled away and found this tidbit about the mysterious dsw command: ...
Jul 10, 7:23 am 2008
Brian A. Seklecki Jul 10, 9:43 am 2008
Nick Holland
Re: note for faq, maybe
Sounds good, but as I've successfully avoided both PPP and PPPoE for well over ten years now, I have no way to completely test, a diff would be nice. Nick.
Jul 10, 11:26 am 2008
Brian A. Seklecki
sshd_config(5) PermitRootLogin yes
Am I reading this right? http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/sshd_config?rev=1.80&content... I dont have a fresh install anywhere -- but I want to say that it doesnt default to PermitRootLogin yes after the install. I remember that I filed PRs with FreeBSD/NetBSD a few years ago to get this changed, but Redhat Support is giving some some noise about: "Well the source vendor doesn't disable it by default ..." ~BAS
Jul 10, 7:35 am 2008
Charles Smith
yacc rebuild
Good afternoon! So, before the next make build I must rebuild the yacc alone. I would like to know how can I rebuild yacc. I searched in old errata patches, Makefiles, bsd.*.mk files. In my previous logfile (2008.07.07/src_make_build) I see, that by yacc the "make cleandir" is used: "rm -f yacc.cat1 ... rm -f .depend ...tags" So is this correct? cd usr.bin/yacc make obj make cleandir make depend make make install In general, how can I ascertain, what kind of make Phony Targets ...
Jul 10, 9:47 am 2008
Claus Assmann
Re: sendmail STARTTLS
1. man starttls (and see the referenced website). 2. increase the LogLevel (even though those errors should be logged at the default level.)
Jul 10, 8:01 am 2008
GVG GVG Jul 10, 6:36 am 2008
Top Shop
Celluless - Hit cena na internetu- samo do 12. 07.
Top Shop Ekskluzivna pretprodaja - samo na internetu! 80-95%
Jul 10, 11:12 am 2008
Dongsheng Song
why pf log output to /var/log/messages & /dev/console ?
I searched /etc/syslog.conf, but can't find how to disable it. Jul 10 08:40:04 proxy /bsd: pf: loose state match: TCP in wire: 192.168.4.132:3833 58.253.67.248:80 stack: - [lo=3472355129 high=3472419308 win=65535 modulator=0] [lo=3167937694 high=3168002906 win=64857 modulator=0] 10:10 R seq=3472355129 (3472354451) ack=3167937694 len=0 ackskew=0 pkts=5:3 dir=in,fwd Jul 10 08:43:37 proxy /bsd: pf: wire key attach failed on all: TCP out wire: 219.149.124.163:80 210.21.12.116:50157 ...
Jul 9, 5:48 pm 2008
Brian
Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
I have to agree with this guy. The openBSD team all ways goes above and beyond what we see other vendors do. The solutions have lasting value, rather then quick fixes that break a year later. Anybody else remember the nvidia close driver issue that Theo had foreseen years before it happened? Trust these guys. They will deliver. Brian
Jul 9, 7:51 pm 2008
Jose Fragoso
Re: trouble with running spamd on 4.4 BETA [SOLVED]
Hi again, It seems that I needed: set skip on lo0 Funny thing is that the same ruleset works on 4.3 without the need for this statement. Was there some change in the route-to logic from 4.3 to 4.4? This may be of interest for someone running spamd in a bridge setup. Kind regards, Jose. -- Be Yourself @ mail.com! Choose From 200+ Email Addresses Get a Free Account at www.mail.com
Jul 10, 2:18 pm 2008
Dongsheng Song Jul 9, 11:50 pm 2008
Peter N. M. Hansteen
Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
reading tea leaves^H^H^H^H^H^H^H^H^H^Hsource-changes has me thinking the BIND bug has spurred some activity in other parts of the tree, too (as in, "bugs are never unique, in OpenBSD we look for patterns or AOL! -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.
Jul 10, 1:24 am 2008
Will Maier
Re: sshd_config(5) PermitRootLogin yes
Yes. This has been discussed. Check the archives if you'd like. -- o--------------------------{ Will Maier }--------------------------o | web:.......http://www.lfod.us/ | email.........willmaier@ml1.net | *---------------------[ BSD: Live Free or Die ]--------------------*
Jul 10, 9:12 am 2008
Vijay Sankar
Re: sendmail -B option
Sorry for the noise. I should not have sent that message. What happened was, in a misguided attempt to help, I tried running sendmail with the various options GVG had mentioned. /usr/sbin/sendmail -L sm-mta -C/etc/mail/sendmail.cf -bd -qp -B8BITMIME -X /$HOME/mail_log and got the error Jul 10 11:54:09 vijay sm-mta[22142]: NOQUEUE:SYSERR(root): /etc/mail/sendmail.cf: line 0: cannot open: No such file or directory on my desktop. Obviously this had nothing to do with -B8BITMIME ...
Jul 10, 1:10 pm 2008
Philip Guenther
sendmail -B option
On Thu, Jul 10, 2008 at 9:59 AM, Vijay Sankar <vsankar@foretell.ca> wrote: <sigh> What do you think it does, how did you use it, and how did you determine that it has no effect? I've already noted that the -B option only affects submission and is ignored when running sendmail as a daemon, making GVG's usage of it incorrect. If you aren't feeding the sendmail command an email message on stdin, then the -B option isn't for you. Philip Guenther
Jul 10, 10:21 am 2008
Philip Guenther
Re: sendmail STARTTLS
Off topic to this thread, but: On Thu, Jul 10, 2008 at 8:24 AM, GVG GVG <gvgter@googlemail.com> wrote: Remove -B8BITMIME from that: the -B option is only applicable when sending email. Indeed, you should be seeing this error at boot time: WARNING: Ignoring submission mode -B option (not in submission mode) What docs suggested that you add that? (For the topic of this thread, you did eyeball /var/log/maillog after restarting, right?) Philip Guenther
Jul 10, 9:39 am 2008
GVG GVG
Re: sendmail STARTTLS
Thanks for your reply but I thought that this is necessary only if SMTP_AUTH should be enabled! In my case I'll use an IMAP server instead! George
Jul 10, 6:19 am 2008
my mail
Re: Can't install using pkg_add from FTP mirror and from ...
thank you all (Jacob Meuser, Markus Lude, Louis V. Lambrecht, James Hartley) for your help i have reinstall my openbsd 4.3 and then use this -rOPENBSD_4_3 for update ports, and now i have been able to install from packages and ports it's my faults because i remember, i have update ports without -rOPENBSD_4_3 tags i litle bit confused about release and stable, if i download ISO from OpenBSD/4.3 ftp, then this is a release, then if i want using --stable, i must using -rOPENBSD_4_3 tags for ...
Jul 10, 1:33 am 2008
Dawe
Re: Ports dependencies
pkg_info -t might help you.
Jul 10, 5:41 am 2008
Jacob Yocom-Piatt
Re: sshd_config(5) PermitRootLogin yes
maybe if people actually READ THE ARCHIVES, they'd be better informed. i wish this mailing list had PermitStupidEmails No as the default. i really fail to see how this setting does anything other than make mgmt
Jul 10, 3:59 pm 2008
Will Maier
Re: sendmail STARTTLS
No. So you updated your .mc file as above, installed it as /etc/mail/localhost.cf and HUPed sendmail? By default on OpenBSD, sendmail is started with the following flags: -L sm-mta -C/etc/mail/localhost.cf -bd -q30m If you installed your new .cf file as sendmail.cf, sendmail won't read it (unless you change or drop the -C flag). -- o--------------------------{ Will Maier }--------------------------o | web:.......http://www.lfod.us/ | email.........willmaier@ml1.net ...
Jul 10, 7:55 am 2008
GVG GVG
sendmail Maildir
Dear List, having a 4.3 and sendmail installation, the default locations where the mails go is /var/mail/$USER. How can I change that and point to a Maildir formatted location? Thanks George
Jul 10, 7:56 am 2008
Marc Balmer
note for faq, maybe
if you use pppoe(4) for internet, and want to do a remote update from 4.2 to 4.3, over said pppoe(4) link, then the normal update procedure will not work, because the 4.3 kernel and the 4.2 ifconfig binary can not work together. after rebooting the new 4.3 bsd kernel, the network will not be configure and you will walk/drive to the system (just like I did today). so, brefore rebooting to 4.3, at least unpack the 4.3 ifconfig binary from base43.tgz - Marc
Jul 10, 6:55 am 2008
Stuart Henderson
Re: sendmail STARTTLS
You did rebuild the .cf file from the .mc file, right? STARTTLS(8) OpenBSD System Manager's Manual STARTTLS(8) [...] Now that you have the TLS-enabled versions of the .mc files you must gen- erate .cf files from them and install the .cf files in /etc/mail. [...]
Jul 10, 8:05 am 2008
Fred Crowson
Re: sshd_config(5) PermitRootLogin yes
Hi Brian, The default is: PermitRootLogin yes As illustrated on below. HTH Fred bsd:fred /home/fred> ssh root@192.168.5.26 root@192.168.5.26's password: Last login: Wed Mar 5 19:08:20 2008 OpenBSD 4.4-beta (GENERIC) #232: Wed Jul 2 12:31:55 MDT 2008 Welcome to OpenBSD: The proactively secure Unix-like operating system. Please use the sendbug(1) utility to report bugs in the system. Before reporting a bug, please try to reproduce it with the latest version of the code. With ...
Jul 10, 9:12 am 2008
Marco Peereboom
Re: sshd_config(5) PermitRootLogin yes
Of course it is enabled by default. Why do I want a box that is freshly installed and unreachable?
Jul 10, 9:34 am 2008
my mail
Re: Can't install using pkg_add from FTP mirror and from ...
this a result from previous command # ls -ald /var/db/pkg/.* ls: /var/db/pkg/.*: No such file or directory # ls -ald /var/db/pkg/ drwxr-xr-x 53 root wheel 1536 Jul 9 15:17 /var/db/pkg/ # ls -al /var/db/pkg/.* ls: /var/db/pkg/.*: No such file or directory # ls -al /var/db/pkg/ total 212 drwxr-xr-x 53 root wheel 1536 Jul 9 15:17 . drwxr-xr-x 5 root wheel 512 Jul 8 11:07 .. drwxr-xr-x 2 root wheel 512 Jul 7 ...
Jul 9, 8:10 pm 2008
Louis V. Lambrecht
Re: Can't install using pkg_add from FTP mirror and from ...
Nothing for ls -ald /var/db/pkg/.* is a positive point. What is completely wrong for a 4.3 release, as Jacob said, your libiconv should be *libiconv-1.9.2p5 *as a result your gettext is also wrong, should be *gettext-0.16.1 *You, somehow, incorrectly installed the latest gettext (from current) and correctly try to install glib2 from release. Wich is not compatible. Since you don't have dot entries in the /var/db/pkg you probably can pkg_delete gettext and libiconv and reinstall them from ...
Jul 9, 9:50 pm 2008
Markus Lude
Re: Can't install using pkg_add from FTP mirror and from ...
Yes, you mix -stable and -current. If you build from ports you should use the same branch as the rest of your system (-stable). The latest version of bash in -stable is 3.2.33, not 3.2.39. The later one is in -current. When you build bash you seems to have pulled in (build) the newer libiconv too. The latest version of libiconv in -stable is 1.9.2p5. You may read chapter 5 and 15 of the FAQ, especially http://www.openbsd.org/faq/faq15.html#NoFun Regards, Markus
Jul 9, 10:08 pm 2008
Vincent Li
Transparent OpenBSD firewall rules for Retrospect
Hi OpenBSD PF experts, I am managing a private network 192.168.1.0/24, 192.168.1.2 is my Retrospect backup server running on OS X 10.5 to back up the rest of computers. To add another layer to protect my backup server, I add an OpenBSD4.3 PF transparent firewall in front of 192.168.1.2, Since it is transparent, all my current private network setting keeps the same. my /etc/bridgename.bridge0: add sis0 add sis1 blocknoip sis0 blocknoip sis1 up my ...
Jul 10, 3:31 pm 2008
Josh
4.4 beta wont shut down properly
Hello. On two machines now, recent snapshots are not powering off properly on machines which used to, when I run shutdown -p -h now. It stops at syncing disks, and stays there forever. After a hard reset, / comes up as not being unmounted successfully. I am a quite busy right now, but if someone could tell me what src files deal with this area, So I can perhaps back track to a time when shutdowns worked ok after work. Anyone have any ideas? Cheers, Josh OpenBSD 4.4-beta (GENERIC) ...
Jul 9, 7:40 pm 2008
Louis V. Lambrecht
Re: Can't install using pkg_add from FTP mirror and from ...
Frankly, re-re-re-re-read the FAQ. Since you just re-installed and still want -current packages, the best way would be to grab a snapshot and do a fresh install. Do this on a date at which your mirror has packages with the same date than the snapshots. (or a day or two off). Release updates are almost foolproof, updating from snapshots might break, while a snapshot of the next day would be perfect. My personal opinion: when you have both the stock OS and sources and started installing ...
Jul 10, 8:55 am 2008
Daniel B.
Re: Iwi, wireless bad behavior
I have similar behavior using bwi(4) driver, although I'm using WPA2. But it's something worst since I can use for some minutes when I lost the connection. After that, I can't even make nfe(4) run. The only "solution" I found is reboot. Since this isn't a solution, when possible, I prefer to use nfe(4) Ethernet connection. Cheers,
Jul 10, 11:43 am 2008
GVG GVG
Re: sendmail STARTTLS
Sorry I did a mistake! The changes in the .mc file are: ---------------- define(`CERT_DIR', `MAIL_SETTINGS_DIR`'CA')dnl define(`confCACERT_PATH', `CERT_DIR')dnl define(`confCACERT', `CERT_DIR/cacert.pem')dnl define(`confSERVER_CERT', `CERT_DIR/cert.pem')dnl define(`confSERVER_KEY', `CERT_DIR/key.pem')dnl define(`confCLIENT_CERT', `CERT_DIR/cert.pem')dnl define(`confCLIENT_KEY', `CERT_DIR/key.pem')dnl -------------- using the same certs for 'server' and 'client'! So the files do ...
Jul 10, 7:26 am 2008
Brian A. Seklecki
Re: sshd_config(5) PermitRootLogin yes
No -- I just find that most of afterboot(8) can be done from the console; even serial console, at first boot, configure the network, add a non-root user, add them to wheel, enable sshd. I guess I'm just having trouble imagining the situation where you have console access, but need to do basic post-install configuration via the network, as root, remotely. Even with CF/Embedded, you ship out master.passwd prepopualted. And this is likely the rationel why the rest of the projects changed ...
Jul 10, 10:38 am 2008
Giancarlo Razzolini
Re: sshd_config(5) PermitRootLogin yes
I do prefer to use the siteXX.tgz and the install.site script to do this, since it is the recommended way to customize the install process: http://www.openbsd.org/faq/faq4.html#site I remember other thread on this list about this. At some point someone asked "Why not ask the installing user to create an unprivileged account during the install process?". The answer was simple and very coherent: "Because we want the user to give root user a strong password. If we prompt for another user creation, ...
Jul 10, 11:16 am 2008
GVG GVG
Re: sendmail STARTTLS
Yes they do exist: ------------------------------ -bash-3.2$ pwd /etc/mail/CA -bash-3.2$ ls -l total 56 -rw-r--r-- 1 root wheel 1229 Jun 23 17:02 cacert.pem -rw-r--r-- 1 root wheel 875 Jun 18 13:46 cacert.pm -rw------- 1 root wheel 3848 Jun 23 17:11 cert.pem drwxr-xr-x 2 root wheel 512 Jun 17 16:25 certs drwxr-xr-x 2 root wheel 512 Jun 23 17:17 crl -rw------- 1 root wheel 3 Jun 23 17:17 crlnumber -rw------- 1 root wheel 68 Jun 23 17:11 index.txt -rw------- 1 ...
Jul 10, 6:56 am 2008
GVG GVG
Re: sendmail STARTTLS
correct but I didn't install as 'localhost' but as 'sendmail.cf'. My server does accept mails from the outside world! After that I did restart the box! Sendmail gets started as: sendmail_flags="-L sm-mta -C/etc/mail/sendmail.cf -bd -qp -B8BITMIME -X /[$HOME]/mail_log"
Jul 10, 8:24 am 2008
mail-lists
VPN Failover
Hello List, I'm having some issues with IPSec VPN tunnels. Here is what I'm trying to do: I have a VPN 'server' with 2 internet connections (IP1, IP2) I have several remote locations which connect to the VPN server. When IP1 goes down on the VPN server I want the remote locations to negotiate the tunnel with IP2 What is the best way to accomplish this? I have tried a couple of different things, none successful. My ipsec.conf on the ...
Jul 10, 6:36 am 2008
Pete Vickers
Re: Vulnerability Note VU#800113 - Multiple DNS implemen ...
looks like there is some work in progress to update the in-tree BIND to 9.4.2-P1 + local tweaking, for example: http://www.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/bind/lib/dns/dispatch.c?r1=1.8 As Theo points out, patience is a virtue, and it's the "+ local tweaking" above that is the reason I gratefully use OpenBSD. /Pete
Jul 10, 1:15 am 2008
Paul de Weerd
Re: sshd_config(5) PermitRootLogin yes
Note that you can already create this account and edit sudoers while still in the installer kernel. Simply `mnt/usr/sbin/chroot /mnt` and you are in your new system where you can change basic things (such as adding users and editing config files, do not expect to be able to do more fancy stuff like firewalling (so you can edit pf.conf, you just can not load it until after rebooting), you're still in the install kernel which lacks several key features provided by the regular kernel). root ...
Jul 10, 10:40 am 2008
previous daytodaynext day
July 9, 2008July 10, 2008July 11, 2008