Re: (boring) why is KEEPKERNELS unset and obj gets cleaned?

2024-07-07 Thread Janne Johansson
Den sön 7 juli 2024 kl 13:34 skrev Anon Loli : > > > I don't want the reproductibility of the build, as I want to change the > > > source > > > code of the src/sys/dev/pci/azalia.c :) consider me a tester :P > > > And it's such a shame that I have to wait a lot of hours... AGAIN > > > So as far as

Re: Running OpenBSD on a VPS.

2024-07-13 Thread Janne Johansson
> address and things like that. Contabo at least offers to setup a VPS > with custom iso images providing VLC console access and such. From a I think you mean a VNC console, not the road-cone media player. I could bear the mistake once, but now it looks like a pattern, hence the nitpicking about t

Re: Lastest snapshot - all application got a speed increase

2024-08-07 Thread Janne Johansson
> What is this kernel lock everybody talks about. I mean what is locked? > Some actions must be done and devs call lock before and after it is > done, they call unlock? > What is kernel lock doing exactly, it prevents other procedures to run? It is quite a large topic, but the 30 second intro is h

Re: Lastest snapshot - all application got a speed increase

2024-08-07 Thread Janne Johansson
> > > What is this kernel lock everybody talks about. I mean what is locked? > > > Some actions must be done and devs call lock before and after it is > > > done, they call unlock? > > > What is kernel lock doing exactly, it prevents other procedures to run? > I was on wikipedia, i did my gogling.

Re: Automatic Disk Partitioning

2024-08-07 Thread Janne Johansson
> Now I understand the rationale. It might be beneficial for the installer > to offer multiple templates when selecting the automatic partitioning > option. These templates could cater to various common use cases, making This sounds like "lots more testing needs to be done for each release, for ea

Re: pkg_add and partial installs

2024-08-13 Thread Janne Johansson
> > While I have had updates fail in the past, I've never seen the output > > "partial installation recorded ...". > > > > Am I correct that the best way of dealing with this is via re-running: > > pkg_add ? Are any manual steps required for dealing with the "partial > > install" ? > > I was wonde

Re: I wrote this about packages and ports in 2023, hopefully still useful to some who come here

2024-08-31 Thread Janne Johansson
Den lör 31 aug. 2024 kl 14:05 skrev Mihai Popescu : > If your intention is/was to help a new OpenBSD user to install > packages, then my feedback is a simple no. This article is far from > helping a beginner to easily install packages. I think Peter knows that OpenBSD frowns upon mindless "blindly

Re: donation

2009-04-13 Thread Janne Johansson
Ingo Schwarze wrote: Hi misc@, some days ago, i publicly asked Wim to tell me what he did with the donation i sent him via IBAN for the OpenBSD project, whether he kept it or whether he passed it on to the project, see the posting included below. --8<-- The posting cited below started a priv

Re: Low power OpenBSD machine

2009-04-14 Thread Janne Johansson
Nico Meijer wrote: Hi Timothy, Is it possible to build something like I describe which uses under 30 Watts, and if so, what hardware would people recommend? I am very happy with several mini-itx systems, both from VIA and from Jetway. For instance, a VIA VB7002 with 1.5Ghz C7-D CPU and 2Gb of

Re: openntpd on openbsd on esx

2009-04-14 Thread Janne Johansson
Clifford Bailey wrote: Hi, I'm trying to run a couple of ntp servers using openntpd on openbsd 4.2 running as a vm on a vmware esx server. My problem is that the machines never seem to become completely stable. They become syncronised, but in 24 hours they may lose syncronisation 2 or 3 times.

Re: Hardware recommendations for gigabit throughput ipsec

2009-04-16 Thread Janne Johansson
John Arnold wrote: Hi all, I'm looking for any advice on what hardware would be suitable to achieve a gigabit capable point to point ipsec vpn (using aes/3des & sha1/md5). Has anybody done this? I did some tests (my 'vpn shootout') between two older 2.4GHz Xeon 1U dells with a point-to-poi

Re: Multiple layers of NAT

2009-04-22 Thread Janne Johansson
Lars Nooden wrote: Alexander Hall wrote: Lars Nooden wrote: Sometimes I have to set up a LAN inside a pre-existing NAT'd LAN and traffic from the inner LAN (B) does not make it to the Internet or even to final, external interface (4). I've searched around a bit and see there is something wro

Re: Multiple layers of NAT

2009-04-22 Thread Janne Johansson
Michiel van Baak wrote: I've searched around a bit and see there is something wrong (in general) with "double NAT" I dont know where you got that info from, but as long as each NAT is set up correctly, there isnt any difference in being NATed once or five times. I have seen trouble with 'dou

Re: Problem with slow disk I/O

2009-04-23 Thread Janne Johansson
On Apr 23 18:09:55, Thomas Pfaff wrote: First on Ubuntu: /dev/sda2 on / type ext3 (rw,relatime,errors=remount-ro) ~$ time (tar -zxf ports.tar.gz && sync) real0m47.784s 47.78 seconds wall clock time Then the same commands on OpenBSD: /dev/wd0k on /home type ffs (local, nodev, nosuid, softde

Re: Transparent firewall (bridge) with DMZ + LAN

2009-04-27 Thread Janne Johansson
Felipe Alfaro Solana wrote: On Mon, Apr 27, 2009 at 1:10 AM, bofh wrote: People use it because they have a need to do something. When you're told there's a better way to do things, pay attention, Still no arguments on why idiots use transparent firewalls. Good to know. Just read up on.. fo

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Janne Johansson
Yuriy Grishin wrote: Indeed you're right. I've got the same experience with php5-gd library. The audit program told that this library is vulnerable but there was no patch available. So this message was about useless. On the other hand in most cases this sort of applications could save admin's

Re: Even and Odd numbered OpenBSD versions

2009-05-19 Thread Janne Johansson
Artur Grabowski wrote: Mark Romer writes: Hello, just a simple question. We have here at work a old hand at openbsd and he says he only uses openbsd versions that are even numbered. >> [...] but what does everything else think? He's odd. Sounds like a candidate for the 2007 years Slacka

Re: softraid - speed

2009-05-20 Thread Janne Johansson
Uwe Dippel wrote: I tried again, setting up RAID1 on 2 U320 drives, 15k, as described in softraid(4). Now I find the speed to be too slow. Writing to a single file is kind of okay: [everything/pwd is /mnt, which is a softraid drive, /dev/sd3f] [..] But a dump && restore of /usr is a tad sick

Re: softraid

2009-05-23 Thread Janne Johansson
Uwe Dippel wrote: Uwe Dippel uniten.edu.my> writes: To me this seems a result of the sequence at boot: at first we identify the physical drives, that is sd0, sd1, sd2 and sd3 in this case, and only later do we get softraid up, sensibly roaming the RAID one up. Sensibly? Because fstab can't kno

Re: Get Top 10 Search Engine Ranking at Low Cost

2009-05-28 Thread Janne Johansson
Anton Parol wrote: How does one take advantage of such a good offer, when theres no URL? Hi, *TOP 10 SEARCH ENGINE RANKINGS* You have to prove your google skills by finding them. They should be in the top 10 of search engine rankings, presumably.

Re: OpenBSD as a storage SAN

2009-06-03 Thread Janne Johansson
Lars Nooden wrote: OpenAFS is part of the base distro. No. The base includes arla, an AFS client.

Re: assigning more than 493 MB memory for qemu virtual machines

2009-06-24 Thread Janne Johansson
Siju George wrote: > Hi, > > Trying to assign 512 MB memory to a qemu vrtual machine resulted in the error. > > $ sudo qemu -m 512 -hda wd0.img -hdb wd1.img -cdrom LATEST-Devel.iso > Could not map physical memory > > -m 493 works > -m 494 & -m 495 gives segmentation fault > Is it a bug in qemu

Re: What is wrong with this pf config

2011-12-11 Thread Janne Johansson
2011/12/11 John Tate > > So I have a suggestion worth considering, if the line "block in all" does > not appear pfctl -nf should perhaps spit out a warning. Much like you've > done with your pretty compilers over there. > > There are still lots of reasons to run PF even if you don't want "block i

Re: OpenVPN issues on 5.0

2011-12-16 Thread Janne Johansson
2011/12/16 Erling Westenvik > > Links to foolproof HOWTO's will be much > appreciated! Nature has thwarted all attempts to make such HOWTOs by make ever better fools, which probably is why you: > > > > > ...but I have spent two days Googling, > > > > > reading tons of HOWTO's and trying out dif

Re: OpenVPN issues on 5.0

2011-12-22 Thread Janne Johansson
2011/12/22 Erling Westenvik : > Sorry for bumping this here @ misc when my question propably belong to > some OpenVPN forum, but it seems like no-one out there can say much on > OpenVPN issues that appears to be OpenBSD spesific. > > What puzzles me is that I cannot make the tun-interface show up i

Re: yt_execution_fails_due_to_lua_error-[4.9-stable]

2012-01-24 Thread Janne Johansson
2012/1/20 soko.tica : > Hello, > > I was trying to download a youtube video from a box running 4.9 > stable, but got the following error: > = > Getting http://www.youtube.com/watch?v=i7pkyDUX5uM ... > /usr/local/bin/lua: /usr/local/share/lua/5.1/base.lua:433: > stack traceback: >[C]: in

Re: Routerboard RB600 and hifn(4)

2012-01-24 Thread Janne Johansson
I think accelerator cards need to provide both checksumming (md5 or sha1) and crypto in HW before its actually any use. Otherwise you will spend most of your time copying data around. 2012/1/22 Stefan Johansson : > Hello! > > Does anyone on the list have experience with a hifn(4) card (such as the

Re: Build libc separately

2012-01-24 Thread Janne Johansson
I think this would be a good case of "If you don't know how to do it, it is the wrong solution to your problem". Or, you will get a really decent amount of training in how to recover broken installations. 2012/1/24 Serguey Kuritsin : > Hello! > > I need to compile libc with different compiler (llv

Re: Long delay updating xenocara source tree?

2012-01-31 Thread Janne Johansson
2012/1/31 Dave Anderson : > > I do have a slowish ADSL link (384Kbps/1536Kbps) which would limit me to > very roughly 1MB/min outbound, so I took advice to use '-z 9' to > compress data and that reduced the total time for a xenocara source tree > update from about 11 hours to about 2.5 hours. (Tho

Re: Is fdisk partition a must for a non-system disk on i386

2012-02-06 Thread Janne Johansson
2012/2/7 Alan Cheng : > Hello list, > > I'm playing around with fdisk on a vmware virtual machine with 5.0 i386. > Despite what's in FAQ14.4, I found I can still create disklabel partitions > without a fdisk partition (no fdisk -i $disk) on a blank disk. > > I'm confused. So my question is: > 1. I

Re: Is fdisk partition a must for a non-system disk on i386

2012-02-07 Thread Janne Johansson
te to the list for help on what I > mis-understood ... > > thanks. > Alan > > > On Tue, Feb 7, 2012 at 3:41 PM, Janne Johansson wrote: >> >> 2012/2/7 Alan Cheng : >> > Hello list, >> > >> > I'm playing around with fdisk on a vmware virtual machine

Re: pgt firmware ...

2012-02-26 Thread Janne Johansson
2012/2/26 Wesley M. : > Try this : > add wget package using pkg_add -vi wget > wget http://firmware.openbsd.org/firmware/5.0/pgt-firmware-1.2p2.tgz Or skip getting wget alltogether and just use the /usr/bin/ftp which can talk http good enough for this. Or, skip getting the package down locally and

Re: pgt firmware ...

2012-02-27 Thread Janne Johansson
2012/2/27 David Walker : > Thank you Peter. > I still get the same error message (error line wrapped): > > pkg_add ./pgt-firmware-1.2p2.tgz > Bad pkg_db: No such file or directory at [...] > Somethings wrong with my environment but what ... Yes, the thing that makes it impossible for you to run ex

Re: Trusting the Installation

2012-02-28 Thread Janne Johansson
2012/2/29 Tomas Bodzar : > On Wed, Feb 29, 2012 at 3:44 AM, Nathan Stiles >> I was also expecting the checksum to be served over HTTPS. > > Some exact reason for that? Especially regarding a lot of issues and > flaws discovered during last months/years in various implementations > of SSL/certifica

Re: may 7 carp addresses be too much on 5.0/amd64 ?

2012-03-03 Thread Janne Johansson
2012/3/2 PP;Q Q P(P8P?P8QP8P= : > hello! > > we are running CARP-ed load balancers (carp over different vlans). > it was running just great with 6 carp addresses. > > when we added 7th, randomly we get MASTERs on both server for certain carp > interface. After reboot we can get different carp in

Re: may 7 carp addresses be too much on 5.0/amd64 ?

2012-03-03 Thread Janne Johansson
2012/3/3 Janne Johansson : >> >> when we added 7th, randomly we get MASTERs on both server for certain carp >> interface. After reboot we can get different carp interface on dual MASTER >> state, and so on. >> carp negotiations are ok, tcpdump shows them all. both pe

Re: My OpenBSD 5.0 installation experience (long rant)

2012-03-12 Thread Janne Johansson
2012/3/12 Fredrik Staxeng : >>> >So you state that the fact that "if one chooses to use the whole disk, >>> >the whole disk is used" needs further documentation? >>> >>> Once upon a time, mkfs used to make a 10-second pause before starting. >>> That's the way you do it. >> >>That is an answer to th

Re: may 7 carp addresses be too much on 5.0/amd64 ?

2012-03-13 Thread Janne Johansson
2012/3/4 PP;Q Q P(P8P?P8QP8P= : > thank to Camiel Dobbelaar, carp log at 6 shown ip_output problem, which > lead me to: > > pass quick proto carp no state Which doesn't match the PF FAQ which says: "Since CARP is its own protocol it should have an explicit pass rule in filter rulesets: pass out

Re: IPSec isakmpd pre shared interoperability with Fortigate VPN

2012-04-01 Thread Janne Johansson
2012/4/1 Girish Venkatachalam : > Dear all, > > I am having a ball of a time configuring ipsec.conf against our > friendly Fortigate VPN box. > I think the model is some very old one, perhaps 50B or something. > Now some other Linux based commercial VPN is able to talk to it as > Fortigate also is

Re: Havege entropy gathering

2012-04-06 Thread Janne Johansson
OpenBSD will use RNGs on CPU:s that have them, like the VIA C7 series. 2012/4/6 Kevin Chadwick : > I was looking at this entropy gatherer (havege) and was wondering if > OpenBSD uses any similar techniques? > > www.irisa.fr/caps/projects/hipsor/ > -- To our sweethearts and wives. May they nev

Re: bnx[01] -> trunk0 -> vlan119 -> carp119 problem

2012-04-19 Thread Janne Johansson
2012/4/19 Stuart Henderson : >> I have now removed the trunking to see if that affected it, but no >> joy. So I now have: >> >> bnx0: flags=28843 mtu >> 1500 > > Don't know how you got to this state but I'm pretty sure this > interface should be in promiscuous mode. > > If you made changes at runti

Re: bnx[01] -> trunk0 -> vlan119 -> carp119 problem

2012-04-20 Thread Janne Johansson
2012/4/20 Stuart Henderson : >> If you can Matt, try to set the carppeer option so it unicasts carp >> status packets between the hosts over the vlans, and see if it helps. > > The parent iface not being in promisc mode is likely to at least > break reception of packets destined for the carp MAC ad

Re: win32-codecs, avi and amd64 question

2007-11-14 Thread Janne Johansson
Girish Venkatachalam wrote: I'm currently running current i386 on my amd64 processor. I'm considering to move to the amd64 distribution but I noticed that the win32-codecs package is only for i386. As to win32codecs working on amd64 if you can run them under a chroot jail and try 32 bit emulatio

Re: : no 4.2-stable package updates??

2007-12-13 Thread Janne Johansson
Raimo Niskanen wrote: On Wed, Dec 12, 2007 at 08:35:50AM +0100, Antoine Jacoutot wrote: This was announced on ports@ IIRC. So if there are security bugs in a package or port shipped with OpenBSD 4.2, there will be no updated package or updated port available? That is correct. Now, this will

Re: OpenBSD supported servers ?

2007-12-26 Thread Janne Johansson
Rui Miguel Silva Seabra wrote: http://www.armorlogic.com/openbsd_information_server_compatibility_list.html A lot of the models on that list are no longer available new, and many of the problems mentioned are fixed in 4.2 or -current. Yes. Maybe we could compile a more updated list, which wou

Re: Real men don't attack straw men

2008-01-08 Thread Janne Johansson
L wrote: Karthik Kumar wrote: Firmware are not free enough when they have a license that does not allow them to be redistributed with the system. You are talking of free as in freedom and not price, right? If the whole point was to avoid paying $$$ in OpenBSD, my bad. The GNG foundation spe

Re: VPN works but not when using CARP interface

2008-01-23 Thread Janne Johansson
James Rippas wrote: Help/suggestions greatly appreciated. I don't know where to look next. I'm not sure, but this part doesn't look good. 213733.723906 Default attribute_unacceptable: ENCRYPTION_ALGORITHM: got AES_CBC, expected 3DES_CBC 213733.723978 Default message_negotiate_sa: no compatib

Re: What is our ultimate goal??

2008-02-20 Thread Janne Johansson
Henning Brauer wrote: * Mayuresh Kathe <[EMAIL PROTECTED]> [2008-02-20 14:07]: (not that now I can do anything about it, all's lost for me) Could you please read http://research.sun.com/minds/2007-0710/ yeah, i did, lots of marketing blubber, lots of bla bla, lots of vague indications, nothin

Re: There's something about OpenBSD...

2008-02-22 Thread Janne Johansson
[EMAIL PROTECTED] wrote: For instance 'ggrep -r ...' instead of 'grep -r ...' to search recursively with gnu grep (a worthless feature imho). Displaying the name of the file and the matched line nicely like grep -r does is not elegant with find + grep without using a script or a long and inelega

Re: BSD Documentation License?

2008-03-27 Thread Janne Johansson
Ted Walther wrote: [snip] (The 2/3-term BSD license meant to do basically the same, but it used more words to do the same. The old 4-term BSD license included some terms to make University of California benefit from advertising, if there was going to be any.) I have been generating midi, ogg,

Re: Forcing ports install

2008-04-02 Thread Janne Johansson
On Wed, 2008-04-02 at 22:33 +1000, N J wrote: > Basically my question is how do I get the port to install without > having to remove then old package and dependencies first? > I'm trying to build pidgin out of the ports tree. > > Tried: set env FORCE_PKG_REGISTER > Tried: make install FORCE_PKG_REG

Re: compiling tools

2007-01-05 Thread Janne Johansson
Joachim Schipper wrote: I think that the best way for me to use ccache is to be able to revector the CC and C++ compilers ... but I'm not certain, could I just put something like "make CC=ccache build" as my main compilation command (after, of course, I do the dependencies) and get the compiole

Re: HTTP URL filtering?

2007-02-22 Thread Janne Johansson
Daniel Ouellet wrote: Toni Mueller wrote: I don't want to generally deny, or slow down, IE users of the site (I can't), but only want to deny them range requests. I didn't find a knob in Apache to do this. If anyone else does, I'm still interested. May be I am thick here, I still don't underst

Re: OpenBSD and Kerberos Client

2007-06-05 Thread Janne Johansson
[EMAIL PROTECTED] wrote: Hello all, I'm having a problem setting up kerberos on an OpenBSD system. Please advise as you can. ...8<... I then tried kadmin on krbc2, which doesn't work. It doesn't even bother with trying to get to the admin server. It just gives me a prompt 'kadmin>'. Perhaps t

Re: OpenBSD and Kerberos Client

2007-06-05 Thread Janne Johansson
[EMAIL PROTECTED] wrote: -Original Message- From: Janne Johansson [mailto:[EMAIL PROTECTED] Sent: Tuesday, June 05, 2007 11:09 AM To: David Rogal Cc: misc@openbsd.org Subject: Re: OpenBSD and Kerberos Client [EMAIL PROTECTED] wrote: Hello all, I'm having a problem setting up ker

Re: OpenBSD and Kerberos Client

2007-06-05 Thread Janne Johansson
[EMAIL PROTECTED] wrote: Might I suggest you try this from the OBSD box: /usr/sbin/ktutil -k /etc/kerberosV/krb5.keytab get \ -p myname/[EMAIL PROTECTED] host/[EMAIL PROTECTED] Same problem, it just hangs. Please note that kinit / klist work just fine. Kadmin and ktutil both hang. Looks like a

Re: linker scripts

2007-06-20 Thread Janne Johansson
Constantine Kousoulos wrote: Having a linux background (and a limited NetBSD experience), i expected to find linker scripts in the kernel source code. However, this is simply not true for most architectures. What is the logic behind the lack of linker scripts? Do you have an actual problem or

Re: IBM T60 - APM issues

2007-06-26 Thread Janne Johansson
atstake atstake wrote: On 6/27/07, viq <[EMAIL PROTECTED]> wrote: $ grep apmhalt /etc/sysctl.conf #machdep.apmhalt=1 # 1=powerdown hack, try if halt -p doesn't work Thanks but that didn't help. At the monent I'm thinking of re-compiling the kernel as someone mentioned (off the l

Re: SSH brute force attacks no longer being caught by PF rule

2007-08-13 Thread Janne Johansson
Joachim Schipper wrote: Finally, Subversion over SSH uses lots of connections, should you ever want to use that. connection multiplexing can be useful for this sort of thing. Yes, it would be, but I never got it to work reliably (Subversion likes to close connections before opening the next o

Re: Ports changes web page is badly out of date

2007-09-10 Thread Janne Johansson
Landry Breuil wrote: http://www.openbsd.org/portsplus/index.html which is referenced by http://www.openbsd.org/plus42.html yeah, perhaps someone feels like start keeping portsplus up to date from now on? please contact me if so. http://ports.openbsd.nu/ homepage would be a good start point to

Re: hardening BSD (was systrace/stsh policies)

2007-10-15 Thread Janne Johansson
Eduardo Tongson wrote: Robert Watson's paper discusses concurrency vulnerabilities. Impact include policy bypass and audit trail invalidation. A bypass means it is useless. That pretty much hammered in the last nail on the coffin for security tools based on system call interposition. I actuall

Re: kernel settings for pf default block

2006-07-05 Thread Janne Johansson
c.s.r.c.murthy wrote: Hello Matthew, "block all" in pf.conf is ok, but it will go away when the rules are flushed for known/unknown reasons. I feel it is desirable to have a kernel parameter that does default blocking when all rules are flushed. But the default blocking will "go away when th

Re: Question related to "automaticly" encrypted /tmp && /vat/tmp (like swap..?)

2006-07-07 Thread Janne Johansson
Daniel A. Ramaley wrote: I have not seen documented how mfs allocates memory, so i just did a quick test. On a machine with 205 MB of RAM free i mounted a 128 MB mfs. Free RAM dropped to 199 MB; only 6 MB used! So OpenBSD must only allocate RAM for sectors that have actually been written to.

Re: OT: (don't open if you don't like) Kerberized FTP client/Server

2006-07-17 Thread Janne Johansson
Eric Pancer wrote: On Mon, 2006-07-17 at 20:34:36 -0600, Bob Beck wrote... Authenticating using kerberos and ftp is possible, but why use clear text passwords. Set up ssh to use kerberos and use sftp/scp. There are many windows things out there to provide a bozo front end to sftp/scp. i

Re: OT: (don't open if you don't like) Kerberized FTP client/Server

2006-07-17 Thread Janne Johansson
Jan Johansson <[EMAIL PROTECTED]> wrote: Gustavo Rios <[EMAIL PROTECTED]> wrote: What kind of ftp client have you been using on windows for such task? Is it possible to have such environment working with standard openbsd ftp server ? KTelnet does Kerberized FTP but I would suggest using SSH/SC

Re: Process dies when it reaches a size of 1GB.

2006-07-17 Thread Janne Johansson
Joe Gibbens wrote: I'm running squid-transparent on 3.9, and the process dies every time it reaches 1GB. FATAL: xcalloc: Unable to allocate 1 blocks of 4108 bytes! The system has 2GB ram # ulimit -aH time(cpu-seconds)unlimited file(blocks) unlimited coredump(blocks) unlimited dat

Re: squid process dies when it reaches a size of 1GB.

2006-07-18 Thread Janne Johansson
Joe Gibbens wrote: Thanks for the reply Janne. So my only way to run a process over 1GB in size is a custom kernel? Is Yes, as of now, on i386. there an easier way to run a large cache with a process size over 1GB? You can do other things aswell, like bumping cachepct to ~12 with confi

Re: Missing security announcements

2008-11-13 Thread Janne Johansson
All this chatter now isn't going to change anything when the next errata comes out. You want security announcement? Do something to make it happen! > Ted, > > everybody knows that's not going to happen. > I remember having asked the same question YEARS AGO and > nothing has changed since then.

Re: Using a separate boot partition

2008-11-14 Thread Janne Johansson
Stuart Henderson wrote: I'm backing ben here : OpenBSD / should be small enough to fit it entirely into a "boot" partition. /etc/{master.,}passwd and /etc/{s,}pwd.db can grow pretty large on some systems... # wc -l < /etc/passwd 118993 # ls -lh /etc/*db -rw-r--r-- 1 root wheel75.2M No

Re: Research for a Software Security paper

2008-11-20 Thread Janne Johansson
Jose de Paula Eufrasio Junior wrote: Hello, before anything else, I did read all material about the OpenBSD security policies on the website. ... I read the documentation on the site already and would like to get some more info about the process. ... 2) The OpenBSD and OpenSSH code is alway

Re: Research for a Software Security paper

2008-11-20 Thread Janne Johansson
Jose de Paula Eufrasio Junior wrote: On Thu, Nov 20, 2008 at 7:44 AM, Janne Johansson <[EMAIL PROTECTED]> wrote: You said twice above that you read all materials and couldn't figure out if the code is always available or have periodic releases? Booo. As I also said: "

Re: Kerberos ~/.k5user file

2008-04-08 Thread Janne Johansson
On Mon, 2008-04-07 at 20:48 -0700, Clint Pachl wrote: > Is the ~/.k5user file supported in OpenBSD's Heimdal implementation? I'm ... > BTW, what is /root/.klogin? Is it for kerberos 4? It doesn't have a man Yes, it is (was) for krb4. [demime 1.01d removed an attachment of type application/pgp-s

Re: wpa now in current?!

2008-04-17 Thread Janne Johansson
Stephan A. Rickauer wrote: Great stuff. I just hope all those who whined for years about not having WPA in OpenBSD are now man enough to give back by donating some money. No excuses. WPA-PSK only and for a limited number of drivers. That what I said! http://undeadly.org/cgi?action=article&sid

Re: Really large drives (was Re: Is there a "badblocks"-equivalent for OpenBSD?)

2008-04-21 Thread Janne Johansson
On Sun, 2008-04-20 at 22:53 -0500, Matthew Weigel wrote: > David Gwynne wrote: > > > solaris suffers from this problem. you cant use big disks with 32bit > > solaris kernels. > > For UFS, at least, but doesn't ZFS on i386 (not amd64) scale? The filesystem yes, but the block addressing no. I had to

Re: How to HIDE "OpenBSD" as user-agent?

2008-04-29 Thread Janne Johansson
On Tue, 2008-04-29 at 06:18 -0600, macintoshzoom wrote: > How to HIDE "OpenBSD" as user-agent? > > For security reasons it is sometimes interesting to hide GLOBALLLY th > O.S. you are running on AGAINST GIVING ANY CLUE TO HACKERS ABOUT HOW TO > ATTACK YOU. Which of course is bullshit, since the l

Re: small, random essay on performance tuning, was: "remove...."

2008-06-09 Thread Janne Johansson
On Sat, 2008-06-07 at 13:23 +0300, Lars Noodin wrote: > It seems from the messages, and my limited > experience, that many come to OpenBSD from other systems where messing > with the kernel is both required and expected[1], that includes Linux > and FreeBSD. > > [1] Case in point see AFS client

Re: vsftpd [more secure]

2008-06-10 Thread Janne Johansson
Saulo Bozzi wrote: *Name* *Version* vsftpd 1.1.3 vsftpd 1.2.2 vsftpd 1.2.2 vsftpd 2.0.1 vsftpd 2.0.4 what version should i use? what is more secure...th

Re: vsftpd [more secure]

2008-06-11 Thread Janne Johansson
Saulo Bozzi wrote: my question is to the system administrator. that know about vsftpd. thnkz. regardsbye. ..and my reply was to a person that thinks "the Ford car owner maillist" is the optimal place to ask for driving directions from London to Paris. If the vsftpd guys/forums/mail

Re: anoncvs.se.openbsd.org: No space left on device

2008-06-17 Thread Janne Johansson
On Mon, 2008-06-16 at 19:44 +0200, Martin Toft wrote: > Hi misc@ > > I get the following error message when updating the xenocara module from > anoncvs.se.openbsd.org: I'll talk to them. [demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]

Re: CARP not leaving backup state

2008-07-24 Thread Janne Johansson
William Stuart wrote: Hello everyone, I am sorry for not mentioning it was a vmWare instance. The packet replay seemed to be the culprit. This occured when we moved the image to a vmWare host running vmWare ESX 3.5 from 3.0. Our working theory is that under 3.5 pernicious mode works diffe

Re: OpenBSD 4.0 - Where is it?

2006-10-26 Thread Janne Johansson
ICMan wrote: I admit that I am not the most up to date on the release process, but why is 4.0 not out on the FTP server yet if people are receiving it in their homes on CD? And how do I get on that list of people who get the pre-release? Folks who pre-order gets an advantage. The rest of us

Re: error building userland - inconsistent operand constraints in an `asm'

2005-05-25 Thread Janne Johansson
; /usr/src/lib/libpthread/arch/i386/_atomic_lock.c:22: inconsistent operand > constraints in an `asm' > *** Error code 1 > -- Janne Johansson Sektionen fvr IT & Media, Stockholms Universitet Frescati Hagvdg 10 106 91 STOCKHOLM http://www.it.su.se

Re: quick malloc guard patch

2005-05-25 Thread Janne Johansson
for debugging, but probably too expensive for normal usage. -- Janne Johansson Sektionen fvr IT & Media, Stockholms Universitet Frescati Hagvdg 10 106 91 STOCKHOLM http://www.it.su.se

Re: Serial console from sparc to i386?

2005-06-01 Thread Janne Johansson
Mike Sazhin wrote: Hello, I want to try sparc with OpenBSD and see if it is useful for what I do. I do not have a monitor or keyboard that can go with it so I hope to be able to install using a serial console. I have done this on i386 to i386. Now I want to know if (with the proper cable, an

Re: Rackmount Servers using SATA

2005-06-03 Thread Janne Johansson
4, Ultra-DMA mode 5 dkcsum: wd0 matched BIOS disk 80 root on wd0a rootdev=0x0 rrootdev=0x300 rawdev=0x302 They seem to work nicely with the internal SATA disks and Obsd3.7. -- Janne Johansson Sektionen fvr IT & Media, Stockholms Universitet Frescati Hagvdg 10 106 91 STOCKHOLM http://www.it.su.se

Re: Can't make 3.7-stable release (tries to exceed capacity of /dev/svnd0a?)

2005-07-11 Thread Janne Johansson
vant info and got his problem solved really quick. If one could only get coming generations to see this problem report too... -- Janne Johansson Sektionen fvr IT & Media, Stockholms Universitet Frescati Hagvdg 10 106 91 STOCKHOLM http://www.it.su.se

Re: cross-tools, m68k build, libgcc2 build throws bad assembler code

2005-08-03 Thread Janne Johansson
When I tried crosscompiling for amiga-m68k-openbsd, I always stated the target as 'amiga' (or mac68k, mvme68k and so on) and not as "m68k". The makefiles solve the arch-part themselves. Dunno if it solves your problem, but worth a shot, unless obsd-crosscompiling changed recently

Re: VPN behind a router, now with OpenVPN

2005-08-04 Thread Janne Johansson
see servers, but, how can I do to > check my connections is encrypted? > > Last days with IPSEC, doing an tcpdump -i enc0 gives me > 'private/confidential)... but now, how can I do? tcpdump the external interfaces, looking at packets on the udp port you selected for OpenVPN. (5000

Re: 3.8 beta requests

2005-08-24 Thread Janne Johansson
Theo de Raadt wrote: Of course not. HOW CAN IT? Get real! The hardware is STILL only providing permissions at the page level! If you have aggressive amounts of ram and/or patience you could have something along the malloc.conf "P"-option for ALL sizes. Of course it would suck for any app mo

Re: package installation script hints

2005-08-26 Thread Janne Johansson
Paul de Weerd wrote: On Fri, Aug 26, 2005 at 12:06:29AM +0200, Marc Espie wrote: | > 2 - How is pkg_add -u working for people? | | It works fine for me. I don't know about other people yet, you tell me... I haven't used it very much yet, but so far everything works great for me. But this is ju

Re: Assembly Language Programs

2006-04-12 Thread Janne Johansson
Alessandro Coppelli wrote: Hi to all. I am interested to developing a little assembly language programs. I rode the article written by Thomas Sommers ( http://user.nj.net/~tms/hello.html ) I followed author's instructions but at the end of compilation as -o .o .s ld -o .o what I have is

Re: pf and pmtu discovery

2006-04-20 Thread Janne Johansson
Lars Weste wrote: Hi, with scrub in all set at the firewall, will openbsd handle icmp packets of type unreach code needfrag automatically, because of the statefulness? scrub no-df fixes this, no?

Last call for swedes wanting to attend the fundraiser event.

2006-06-02 Thread Janne Johansson
http://slackathon2006.unix.se for info (in swedish), attach /index_en.html for an (almost 100% updated) english version. It's tomorrow (3rd of June) at the Stockholm University, so this really is the last call, but in case I missed some of you swedes when spamming all local lists and forums, an

Re: i386 binaries on amd64

2005-08-30 Thread Janne Johansson
Tony Lambiris wrote: In reading some mailing lists, I noticed some people pass in the -m32 flag when compiling to compile 32bit instead of 64bit... I added the flag to the Makefile and everything compiles except when I try to link all the objects into an executable, I get these errors: /usr/b

Re: openAFS or arla support?

2005-10-13 Thread Janne Johansson
ober wrote: Do you guys prefer --with-transarc paths? So let me know as I am writing it as we speak. The goal is to allow you to install a single server AFS cell with a single script. I use it the old version on Linux fine. However would like feedback for transarc/non transarc paths. I'd pre

Re: theo

2005-12-01 Thread Janne Johansson
Sophie Laurie wrote: The only thing that spoils OpenBSD is theo de raadt But it caters so well the needs for all the worst nastiest anal-carotid-constriction-software-patent-loving-spam-your-grandma- for-a-dollar-bottom-feeding-killing-babies-in-palestine-and-iraq type organizations to be able

Re: OpenBSD's AFS informations

2006-02-27 Thread Janne Johansson
Bruno Carnazzi wrote: So, I'd like to know if OpenBSD's AFS could do the following (I assume that our actual file servers are replaced by OpenBSD AFS cells) : * Gently synchronize/distribute 2 physical file servers in 1 logical file server (real time is not needed) Yes. * Does it scale we

Re: OpenBSD 5.1 i386- ports vs packages

2012-05-13 Thread Janne Johansson
2012/5/7 Dimitry T : > P.S Is there any changes in performance if change in kernel conf i386 to > i686? > "Some reasons why you should not build a custom kernel: > > You do not need to, normally. > You will not get a faster system." > > Can this applies to my question? Why don't you spend 15 minu

Re: Error while copying data from another disk

2012-05-14 Thread Janne Johansson
2012/5/14 Mik J : > After my new OpenBSD installation, I'm trying to copy data from my backup disk and I have these errors. > wd0f: uncorrectable data error reading > fsbn 1671616960 of 1671616896-1671617023) > I have in previous messages that some sectors should be dead on my hard drive and that I

Re: a live cd/dvd?

2012-05-14 Thread Janne Johansson
2012/5/14 Kevin Chadwick : > On Sat, 12 May 2012 11:16:34 -0700 > Tyler Morgan wrote: > >> Anyway, I hope that perspective is useful in some way. I have no strong >> opinion on the usefulness of an OpenBSD live CD, and this isn't a Linux >> mailing list blah blah blah > > WHilst you have valid poin

<    1   2   3   4   5   6   7   >