DNS cache poisoning patch and PF

2008-08-12 Thread Kyle Drake
Regarding the new DNS cache poisoning problems: I was told that the way they resolved the problem was to randomize the source ports. I was wondering if I needed to make any changes to PF firewall, as I'm currently running DNS through a single port (TCP/UDP domain port). I have a strict firewall pol

Re: BSD Port from OpenJDK

2008-10-15 Thread Kyle Drake
a lot of my servers. Thank you. Kyle Drake Net Brew Design http://www.netbrewdesign.com

Re: OpenBSD 4.0 - Postfix & Dovecot SASL

2006-09-23 Thread Kyle Drake
I'm not sure about SASL per-se, but Dovecot is pretty good. It's very easy to setup, and it has more of a postfix-like configuration approach. That said, I wouldn't migrate to it out of a working setup unless you had an above-average reason too (if Cyrus's security is dangerously bad, then I would

Re: Bind performance

2006-11-22 Thread Kyle Drake
I've had very good results with MaraDNS, been using it for at least two years now with no problems. Some highlights: Memory based, so it loads all the configuration settings on startup and then jails itself so it cannot write to the FS Small, and FAST - It's been benchmarked as faster than Bind (

Re: It is 2010. Still no >3GB support by default?

2010-06-07 Thread Kyle Drake
Touchi. -Kyle On Mon, Jun 7, 2010 at 3:43 PM, Dexter Tomisson wrote: > No, > "640k ought to be enough for anybody" > > On 7 June 2010 22:12, Bret S. Lambert wrote: > >> On Mon, Jun 07, 2010 at 09:52:50PM +0300, Dexter Tomisson wrote: >> >> "It's the future, where's my goddamn flying car?"

Re: OpenBSD users.

2010-07-21 Thread Kyle Drake
Portland, Oregon (United States) -Kyle