Re: Realtek High Definition Soundcard

2005-10-06 Thread Berk Gulenler

   Jakob Breivik Grimstveit wrote:

Berk Gulenler wrote on Thu, 06 Oct 2005 17:01:

  

Is there any way to install Realtek high definition soundcard? I try the 
open sound system program(lastest version). But it doesnt work.


What didn't work? It's impossible to help unless you provide more information
than this...

  

   This is log file of open sound system. It may help about the problem.
   Starting OSS/FreeBSD  3.99.3c Tue Oct 4 17:06:45 EEST 2005
5:06PM  up 13 mins, 1 user, load averages: 0.16, 0.06, 0.05
   === config =
   # Use soundconf to edit this file.
   /SECUREAUDIO ON
   /IRQEXCLUDE 3 4
   /DMAEXCLUDE 2
   -PCI26688086 #Intel High Definition Audio (Azalia) *BETA*
   HDAUDIO ON
   #NEEDS_MMPCI
   == pnpres.dat 
   
   Config option 'intelpci_rate_tuning=280' defined
   Warning: Some of the devices failed to initialize
   OSS/FreeBSD 3.99.3c (C) 4Front Technologies 1996-2004
   License serial number: E0008
    UNREGISTERED VERSION 
   Drivers: ALL
   License will expire after: 12/2005
   *** Unregistered version ***
   Build: 200509191034
   Kernel: FreeBSD 5.4-RELEASE #0: Sun May  8 10:21:06 UTC 2005
   [EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC
   Card config:
   (Intel High Definition Audio (Azalia) controller at 0xdfffc000 irq 16)
   Audio devices:
   Synth devices:
   Midi devices:
   Mixers:
   == dmesg printout follows 
   sc0: VGA <16 virtual consoles, flags=0x300>
   sio1: configured irq 3 not in bitmap of probed irqs 0
   sio1: port may not be enabled
   vga0:  at port 0x3c0-0x3df iomem 0xa-0xb on
   isa0
   ums0: Microsoft Basic Optical Mouse, rev 1.10/0.00, addr 2, iclass 3/1
   ums0: 3 buttons and Z dir.
   Timecounter "TSC" frequency 276759 Hz quality 800
   Timecounters tick every 10.000 msec
   acd0: CDRW  at ata0-master PIO4
   ad4: 114498MB  [232632/16/63] at ata2-master
   SATA150
   Mounting root from ufs:/dev/ad4s3a
   myk0: link up
   hdaudio: RIRB timeout
   hdaudio_mixer_attach: Codec #2 is not responding
   hdaudio: Codec attach failed (-5)
   oss: Probing the hardware for Intel High Definition Audio (Azalia)
   controller failed.
   Waiting (max 60 seconds) for system process `vnlru' to stop...done
   Waiting (max 60 seconds) for system process `bufdaemon' to stop...done
   Waiting (max 60 seconds) for system process `syncer' to stop...
   Syncing disks, vnodes remaining...4 1 3 0 0 done
   No buffers busy after final sync
   Uptime: 29m28s
   myk0: link down
   ukphy0: detached
   miibus0: detached
   Shutting down ACPI
   Rebooting...
   Copyright (c) 1992-2005 The FreeBSD Project.
   Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993,
   1994
   The Regents of the University of California. All rights reserved.
   FreeBSD 5.4-RELEASE #0: Sun May  8 10:21:06 UTC 2005
   [EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC
   ACPI APIC Table: 
   Timecounter "i8254" frequency 1193182 Hz quality 0
   CPU: Intel(R) Pentium(R) 4 CPU 2.80GHz (2800.00-MHz 686-class CPU)
 Origin = "GenuineIntel"  Id = 0xf34  Stepping = 4

   Features=0xbfebfbff
 Hyperthreading: 2 logical CPUs
   real memory  = 536014848 (511 MB)
   avail memory = 514842624 (490 MB)
   ioapic0  irqs 0-23 on motherboard
   npx0:  on motherboard
   npx0: INT 16 interface
   acpi0:  on motherboard
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   acpi0: Power Button (fixed)
   acpi_bus_number: can't get _ADR
   acpi_bus_number: can't get _ADR
   Timecounter "ACPI-safe" frequency 3579545 Hz quality 1000
   acpi_timer0: <24-bit timer at 3.579545MHz> port 0x408-0x40b on acpi0
   cpu0:  on acpi0
   acpi_throttle0:  on cpu0
   pcib0:  port 0xcf8-0xcff on acpi0
   pci0:  on pcib0
   pcib1:  at device 1.0 on pci0
   pci1:  on pcib1
   pci1:  at device 0.0 (no driver attached)
   pci1:  at device 0.1 (no driver attached)
   pci0:  at device 27.0 (no driver attached)
   pcib2:  at device 28.0 on pci0
   pci5:  on pcib2
   pcib3:  at device 28.1 on pci0
   pci4:  on pcib3
   myk0: 
   port 0xa800-0xa8ff mem 0xdfcfc000-0xdfcf irq 17 at device 0.0 on
   pci4
   myk0: Ethernet address: 00:11:11:65:a8:b5
   pcib4:  at device 28.2 on pci0
   pci3:  on pcib4
   pcib5:  at device 28.3 on pci0
   pci2:  on pcib5
   uhci0:  port
   0xcc00-0xcc1f irq 23 at device 29.0 on pci0
   usb0:  on uhci0
   usb0: USB revision 1.0
   uhub0: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1
   uhub0: 2 ports with 2 removable, self powered
   uhci1:  port
   0xd000-0xd01f irq 19 at device 29.1 on pci0
   usb1:  on uhci1
   usb1: USB revision 1.0
   uhub1: Intel UHCI root hub, class 9/0, rev 1.00/1.00, addr 1
   uhub1: 2 ports with 2 removable, self powered
   uhci2:  port
   0xd400-0x

Re: disk errors help!!

2005-10-06 Thread Glenn Dawson

At 06:55 PM 10/6/2005, RYAN vAN GINNEKEN wrote:
My freebsd 4.11 system has been subjected to a power failure and 
seems to have many disk errors something about soft updates and not 
being able to read certain sectors it comes up with the standard 
single user pick your shell command and tells me to run fsck 
manually.  I have run it several times but the system keeps comming 
with ad0s4 marked dirty which is my /usr partition.  Sometimes i get 
a resetting device ata0 timeout error.  What should i do of course i 
have no current backups for this system and the most important thing 
is retrieving my users data it would be great if i could get the 
system to boot up but if i have to reinstall no biggy as long as i 
can get most of my data back.


ps  i promise to do remote backups nightly for the rest of my life.


Sounds like you definitely have some problems.

If you have somewhere to put it, you can use dd with 
conv=noerror,sync to get an image of the drive, less the damaged 
areas (which get filled in with nul's by the sync option).  Once you 
have the image, you can use it as a backing store for md(4), fsck 
that, mount it and get whatever you can from what's left.


-Glenn




--
Computer King/CaNMail

http://www.computerking.ca http://www.canmail.org

Sales, Service, and Hosting
Email, Data, and Web Packages
Ask about web design specials

Affiliates
http://www.computerking.ca/pages/links/affiliates/affiliates.htm

--

If you eat a live frog in the morning, nothing worse will happen to 
either of you for the rest of the day.


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


FreeBSD FD_SETSIZE

2005-10-06 Thread Tamouh H.

Hi!

I'm having problems resolving FD_SETSIZE issues with FreeBSD 5.4 and Apache.
This error always continues:


[Thu Oct 6 14:51:31 2005] [warn] send body: filedescriptor (1367) larger
than FD_SETSIZE (1024) found, you probably need to rebuild Apache with a
larger FD_SETSIZE


I did re-compile apache (we made sure FD_SETSIZE is enabled)

however, the problem still occurs. so I modified
/usr/local/apache/bin/apachectl and added :

ulimit -n 16480
also in
/etc/init.d/httpd

But the same problem continues, it is happening much less than before, but
we continue to see it.

Doing
 shows: 11095

How else would we need to increase the FD_SETSIZE on FreeBSD 5 ?

I read somewhere there is also need to change it at:
/usr/include/sys/select.h ?

This requires recompiling Kernel, correct ? How about adding this to the
FBSD kernel:
options FD_SETSIZE nnn as suggested in Apache FAQ:
http://httpd.apache.org/docs/1.3/mi...freebsd-setsize

Also it appears there are different places the FD_SETSIZE need to be changed
as per:
http://apache.active-venture.com/descriptors.html

I couldn't find good resources about FD_SETSIZE or tuning FreeBSD for large
sites except to:



Any input or experiences with these are welcomed.

Thanks!

Tamouh


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Replacing a failing HD

2005-10-06 Thread Bob Ababurko

Craig Deal wrote:
 


-Original Message-
From: [EMAIL PROTECTED] 
[mailto:[EMAIL PROTECTED] On Behalf Of Bob Ababurko

Sent: Wednesday, October 05, 2005 7:53 AM
To: Charlie Schluting; freebsd-questions@freebsd.org
Subject: Re: Replacing a failing HD

Yes, I guess I should mention that the drives were on the 
same machine, actually the same bus and/or channel.  I have 
also done this on Solaris. 
 I believe it was Solaris 8, but it works just the same.  I 
am not sure if it would work over a network.  Just make sure 
you dd the disk as a whole as in /dev/daX and not by the slice.


-Bob


Charlie Schluting wrote:

I have used dd to image a drive many times before in freebsd.  It 
works like a champion and will boot up just fine.  I may have 
misunderstood your mail but if not then it will work.





Well, maybe my weird "over ssh calling a setuid program 


that calls a 

script" dd was flawed somehow. I'll do it again with both drives in 
the same machine.


Thanks for the response!




Hope it's ok to continue this thread, but can you explain in more detail how
to use dd to copy a HD. I read "man dd" and was unable to figure out how
this is done.

Thanks,
Craig

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


This is what I have done in the past.

dd if=/dev/da0 of=/dev/da1 bs=8192b

where da0 is the disk you want to copy and da1 is the new, blank disk. 
I should also mention that it is wise to do this in single user mode.  I 
actually have read this somewhere and understand the point of it, but I 
must also say that I have done it both ways and they have both worked. 
YMMV  I would have to say it is all dependant and what you have running.


I have done this too many times to count and it is very easy.

peace,
Bob
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Playing Flash and video media in Firefox

2005-10-06 Thread Andrew P.
On 10/7/05, Ian Moore <[EMAIL PROTECTED]> wrote:
> On Friday 07 October 2005 08:24, edward wrote:
> > Hi,
> > I'm not quite sure how to get Firefox (on 5.4-Stable, Xorg 6.8.2 and KDE
> > 3.4.2) to play the following media :
> > - Flash
> > - Quicktime
> > - Windows Media
> > Any clue ?
> > Thanks all,
> > Edward
> >
>
> Try installing www/plugger and also www/linux-flashplugin-6.0r79_3 and
> www/linuxpluginwrapper.
> Don't forget to read the port message for each port when you install them and
> do what they say.!
>
> Configuring the flash plugin has been discussed in the last week on this list
> if you get stuck.
>
> --
> Ian
> gpg key: http://home.swiftdsl.com.au/~imoore/no-spam.asc
>
>
>

Consider www/plugger-plugins-hubbe instead of www/plugger,
you'll have to do less configuration. Also www/mplayer-plugin
often helps.

Still, I haven't figured out how to watch webcasts from some
stupid sites that try to detect whether you have WMP
installed. Has anyone been able to play videos from cnn.com
for example? (Lately, I mean. They've switched from pay-
per-month realmedia to free wmv)
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


compile error when upgrading from 4.8 to 4.11

2005-10-06 Thread Mark Jayson Alvarez
Good day!

Here's my system:

4.8-RELEASE FreeBSD 4.8-RELEASE #0: Thu Apr  3
10:53:38 GMT 2003
[EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC
 i386

Here's my GCC

gcc version 2.95.4 20020320 [FreeBSD]

Here's what I did:

1. Download 4.11 miinst.iso
2. Install the sources
3. cd to /usr/src
4. Make buildworld

And the last few lines during the compilation looks
like this:

===> sys/boot/i386/btx/btxldr
(cd /usr/src/sys/boot/i386/btx/btxldr; m4
-DLOADER_ADDRESS=0x20 btxldr.s ) |  as  -o
btxldr.o
ld -N -e start -Ttext 0x20 -o btxldr.out btxldr.o
objcopy -S -O binary btxldr.out btxldr
===> sys/boot/i386/btx/lib
as  -o btxcsu.o
/usr/src/sys/boot/i386/btx/lib/btxcsu.s
as  -o btxsys.o
/usr/src/sys/boot/i386/btx/lib/btxsys.s
as  -o btxv86.o
/usr/src/sys/boot/i386/btx/lib/btxv86.s
ld  -i -o crt0.o btxcsu.o btxsys.o btxv86.o
===> sys/boot/i386/boot2
as  --defsym FLAGS=0x80
/usr/src/sys/boot/i386/boot2/boot1.s -o boot1.o
ld -nostdlib -static -N -e start -Ttext 0x7c00 -o
boot1.out boot1.o
objcopy -S -O binary boot1.out boot1
dd if=/dev/zero of=boot2.ldr bs=512 count=1
2>/dev/null
*** Error code 126

Stop in /usr/src/sys/boot/i386/boot2.
*** Error code 1


Any idea?


Thanks!



__ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


RE: Replacing a failing HD

2005-10-06 Thread Craig Deal
 
> -Original Message-
> From: [EMAIL PROTECTED] 
> [mailto:[EMAIL PROTECTED] On Behalf Of Bob Ababurko
> Sent: Wednesday, October 05, 2005 7:53 AM
> To: Charlie Schluting; freebsd-questions@freebsd.org
> Subject: Re: Replacing a failing HD
> 
> Yes, I guess I should mention that the drives were on the 
> same machine, actually the same bus and/or channel.  I have 
> also done this on Solaris. 
>   I believe it was Solaris 8, but it works just the same.  I 
> am not sure if it would work over a network.  Just make sure 
> you dd the disk as a whole as in /dev/daX and not by the slice.
> 
> -Bob
> 
> 
> Charlie Schluting wrote:
> >>I have used dd to image a drive many times before in freebsd.  It 
> >>works like a champion and will boot up just fine.  I may have 
> >>misunderstood your mail but if not then it will work.
> >>
> > 
> > 
> > Well, maybe my weird "over ssh calling a setuid program 
> that calls a 
> > script" dd was flawed somehow. I'll do it again with both drives in 
> > the same machine.
> > 
> > Thanks for the response!


Hope it's ok to continue this thread, but can you explain in more detail how
to use dd to copy a HD. I read "man dd" and was unable to figure out how
this is done.

Thanks,
Craig

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Compile error when upgrading 4.8 to 4.11

2005-10-06 Thread Mark Jayson Alvarez
Good day!

Here's my system:

4.8-RELEASE FreeBSD 4.8-RELEASE #0: Thu Apr  3
10:53:38 GMT 2003
[EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC
 i386

Here's my GCC

gcc version 2.95.4 20020320 [FreeBSD]

Here's what I did:

1. Download 4.11 miinst.iso
2. Install the sources
3. cd to /usr/src
4. Make buildworld

And the last few lines during the compilation looks
like this:

===> sys/boot/i386/btx/btxldr
(cd /usr/src/sys/boot/i386/btx/btxldr; m4
-DLOADER_ADDRESS=0x20 btxldr.s ) |  as  -o
btxldr.o
ld -N -e start -Ttext 0x20 -o btxldr.out btxldr.o
objcopy -S -O binary btxldr.out btxldr
===> sys/boot/i386/btx/lib
as  -o btxcsu.o
/usr/src/sys/boot/i386/btx/lib/btxcsu.s
as  -o btxsys.o
/usr/src/sys/boot/i386/btx/lib/btxsys.s
as  -o btxv86.o
/usr/src/sys/boot/i386/btx/lib/btxv86.s
ld  -i -o crt0.o btxcsu.o btxsys.o btxv86.o
===> sys/boot/i386/boot2
as  --defsym FLAGS=0x80
/usr/src/sys/boot/i386/boot2/boot1.s -o boot1.o
ld -nostdlib -static -N -e start -Ttext 0x7c00 -o
boot1.out boot1.o
objcopy -S -O binary boot1.out boot1
dd if=/dev/zero of=boot2.ldr bs=512 count=1
2>/dev/null
*** Error code 126

Stop in /usr/src/sys/boot/i386/boot2.
*** Error code 1


Any idea?


Thanks!






__ 
Yahoo! Mail - PC Magazine Editors' Choice 2005 
http://mail.yahoo.com
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: wazzup with this java build warning?

2005-10-06 Thread Randy Schultz
On Thu, 6 Oct 2005, Kris Kennaway spaketh thusly:

-}> 
-}> Tnx Ken.
-}
-}Who's Ken? ;P

Blech.  Sorry about that Kris.  The Sam Smith Taddy Porter musta snuck up
on me when I wasn't looking.  ;>

-}
-}> So it's ok and the end result will be the native jdk?
-}
-}Yes.

Sweetness.  Tnx again.

--
 Randy([EMAIL PROTECTED])  715-726-2832 email bodhisattva <*>

 "There is no fire like passion, there is no shark like hatred,  there is no
snare like folly, there is no torrent like greed."

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: wazzup with this java build warning?

2005-10-06 Thread Kris Kennaway
On Thu, Oct 06, 2005 at 09:12:48PM -0500, Randy Schultz wrote:
> On Thu, 6 Oct 2005, Kris Kennaway spaketh thusly:
> 
> -}On Thu, Oct 06, 2005 at 07:32:41PM -0500, Randy Schultz wrote:
> -}> Doing a make in ports/java/jdk14.  Have in ports/distfiles the files the
> -}> make asks for.  When the make continues it warns with:
> -}> 
> -}> ===>Verifying install for /usr/local/linux-sun-jdk1.4.2/bin/javac in 
> /usr/ports/java/linux-sun-jdk14
> -}> ==
> -}> Warning: This JDK may be unstable. You are advised to use the native
> -}> FreeBSD JDK, in ports/java/jdk14.
> -}> 
> -}> 
> -}> I don't get this.  I am using ports/java/jdk14, performing the make there,
> -}> yet it barks with this.  Is this some debris from a bygone check or did I 
> -}> miss a step?
> -}
> -}No, read what it says..it's installing the linux-sun-jdk14 port as
> -}part of the build of jdk14.  Why?  Because you need a java compiler to
> -}bootstrap the java compiler.
> 
> Tnx Ken.

Who's Ken? ;P

> So it's ok and the end result will be the native jdk?

Yes.

Kris


pgpF41e7yqz6v.pgp
Description: PGP signature


Re: wazzup with this java build warning?

2005-10-06 Thread Randy Schultz
On Thu, 6 Oct 2005, Kris Kennaway spaketh thusly:

-}On Thu, Oct 06, 2005 at 07:32:41PM -0500, Randy Schultz wrote:
-}> Doing a make in ports/java/jdk14.  Have in ports/distfiles the files the
-}> make asks for.  When the make continues it warns with:
-}> 
-}> ===>Verifying install for /usr/local/linux-sun-jdk1.4.2/bin/javac in 
/usr/ports/java/linux-sun-jdk14
-}> ==
-}> Warning: This JDK may be unstable. You are advised to use the native
-}> FreeBSD JDK, in ports/java/jdk14.
-}> 
-}> 
-}> I don't get this.  I am using ports/java/jdk14, performing the make there,
-}> yet it barks with this.  Is this some debris from a bygone check or did I 
-}> miss a step?
-}
-}No, read what it says..it's installing the linux-sun-jdk14 port as
-}part of the build of jdk14.  Why?  Because you need a java compiler to
-}bootstrap the java compiler.

Tnx Ken.

So it's ok and the end result will be the native jdk?

--
 Randy([EMAIL PROTECTED])  715-726-2832 email bodhisattva <*>

 "There is no fire like passion, there is no shark like hatred,  there is no
snare like folly, there is no torrent like greed."

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


disk errors help!!

2005-10-06 Thread RYAN vAN GINNEKEN
My freebsd 4.11 system has been subjected to a power failure and seems 
to have many disk errors something about soft updates and not being able 
to read certain sectors it comes up with the standard single user pick 
your shell command and tells me to run fsck manually.  I have run it 
several times but the system keeps comming with ad0s4 marked dirty which 
is my /usr partition.  Sometimes i get a resetting device ata0 timeout 
error.  What should i do of course i have no current backups for this 
system and the most important thing is retrieving my users data it would 
be great if i could get the system to boot up but if i have to reinstall 
no biggy as long as i can get most of my data back.


ps  i promise to do remote backups nightly for the rest of my life.


--
Computer King/CaNMail

http://www.computerking.ca http://www.canmail.org

Sales, Service, and Hosting
Email, Data, and Web Packages
Ask about web design specials

Affiliates
http://www.computerking.ca/pages/links/affiliates/affiliates.htm

--

If you eat a live frog in the morning, nothing worse will happen to either of 
you for the rest of the day.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: SoundBlaster Audigy Question

2005-10-06 Thread Benjamin Lutz
Sean Murphy wrote:
> I have an onboard soundcard for my FreeBSD box and I was thinking of
> getting the new Audigy card.  Does the FreeBSD drivers for the Audigy
> take advantage of surround sound, EAX, digital connections, or number of
> channels? Or does the soundcard operate at a more basic level ie. stereo
> sound no hardware acceleration etc.

It'll be supported in stereo mode only. There is an alternative driver
called emu10kx which supports the other channels and digital outs. I'm
not aware of any FreeBSD software that'd know how to make use of things
like EAX, so not having that supported by the driver won't be a big loss :)

> Is there any reason to have such a high end soundcard in a FreeBSD system?

Feature-wise, no. The audigy does give you better sound quality (eg,
less noise) than cheapo cards though.

Cheers
Benjamin


signature.asc
Description: OpenPGP digital signature


Re: OT: New design

2005-10-06 Thread Olivier Nicole
Hi,

As there is a thread on that topic... here my 2 cents.

I find it sort of painfull to have to go 2 clicks to find sings like
the handbook that used to be linked from the home page.

The design is certainly nicer, but maybe not as usefull as it used to
be.

That say, I can survive :)

Olivier
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Determining what a port will install... (more than pretty-print-*) [Soln]

2005-10-06 Thread Eric Schuele

Csaba Henk wrote:

On Tue, Oct 04, 2005 at 11:19:03AM -0500, Eric Schuele wrote:


Csaba Henk wrote:


Because all such scripts are fundamentally broken.

When make decides which ports to pull in, it doesn't only use the flat
data of build and run dependencies, but uses its full Turing complete
computing power. Eg., what happens when a port needs a postscript
interpreter? 


Then do the pretty-print(s) not provide the useful information they 
appear to?  I mean, If the above were true then they would have no 
value... and should go away.  Or do they provide true but incomplete 
information?



As far as I can see, they tell you the list of packages which would be
installed if you were doing the install from scratch (ie., no packages
were installed). This is a somewhat useful information, anyway.

Btw., is make really Turing complete? As far as I can see, complex tasks
are delegated to shell, but I can't recall seeing any "while" in make
code...



Should it use the AFPL or the GNU edition as a dependency?
Of course, doing a favor toward one of them (and taking away user's
choice) is unacceptable. So what happens is that make directly checks
whether the gs executable is present.

See, for example, print/gv. Your script's output will include
ghostscript-gnu-7.07_13 both as a build and a run dependency.
Yet when I type make, my ghostscript-gnu-7.07_12 installation will
be happily utilized as the following output snippet shows:


Is this not acceptable behavior since it is just a port revision? 
Shouldn't the revision be compatible in every way with the vendor's release?



What do you mean by this? The behaviour seen upon installing gv is
absolutely what one would expect. It's just hard to make proper
predictions.


It 'sounded' as if you were stating that it was inappropriate for the 
7.07_12 port to be used in place of the 7.07_13 (which was required)... 
when this seemed correct to me.  I'm sure I just misunderstood what you 
were saying... disregard my comment.






Thanks for contributing to the script.



You are welcome.

Regards,
Csaba




--
Regards,
Eric
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Playing Flash and video media in Firefox

2005-10-06 Thread Ian Moore
On Friday 07 October 2005 08:24, edward wrote:
> Hi,
> I'm not quite sure how to get Firefox (on 5.4-Stable, Xorg 6.8.2 and KDE
> 3.4.2) to play the following media :
> - Flash
> - Quicktime
> - Windows Media
> Any clue ?
> Thanks all,
> Edward
>

Try installing www/plugger and also www/linux-flashplugin-6.0r79_3 and 
www/linuxpluginwrapper. 
Don't forget to read the port message for each port when you install them and 
do what they say.!

Configuring the flash plugin has been discussed in the last week on this list 
if you get stuck.

-- 
Ian
gpg key: http://home.swiftdsl.com.au/~imoore/no-spam.asc


pgp1KJDjstBeX.pgp
Description: PGP signature


Re: xine / kaffeine core dumps with bus error

2005-10-06 Thread Ian Moore
On Friday 07 October 2005 02:40, Tijl Coosemans wrote:
> On Wednesday 05 October 2005 01:45, Ian Moore wrote:
> > On Wednesday 05 October 2005 00:44, Brian John wrote:
> > > I think I'm having a similar problem with totem (which uses xine)
> > > and vlc. Can you try installing /usr/ports/multimedia/vlc and see
> > > what that does? If that gives a bus error as well then I think we
> > > might have the same issue.  I haven't been able to find a solution
> > > to this yet...
> >
> > Yep, vlc gives a bus error too. Looks like we have the same problem!
>
> I don't know what the exact problem is, but the bus error occurs when
> loading "/usr/X11R6/lib/xine/plugins/1.1.0/xineplug_dmx_audio.so". When
> you remove that file or rename it such that there's no longer ".so" in
> the file name, then xine should work.

It doesn't work for me - it still core dumps and kdump gives a very similar 
trace to the previous one:

 37294 xine RET   read 4096/0x1000
 37294 xine CALL  mmap(0,0x5e000,0x5,0x20002,0x6,0,0,0)
 37294 xine RET   mmap 704172032/0x29f8d000
 37294 xine CALL  mprotect(0x29fbb000,0x1000,0x7)
 37294 xine RET   mprotect 0
 37294 xine CALL  mprotect(0x29fbb000,0x1000,0x5)
 37294 xine RET   mprotect 0
 37294 xine CALL  mmap(0x29fbc000,0x3000,0x3,0x12,0x6,0,0x2e000,0)
 37294 xine RET   mmap 704364544/0x29fbc000
 37294 xine CALL  mmap(0x29fbf000,0x2c000,0x3,0x1012,0x,0,0,0)
 37294 xine RET   mmap 704376832/0x29fbf000
 37294 xine CALL  close(0x6)
 37294 xine RET   close 0
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/usr/X11R6/lib/libstdc++.so.4"
 37294 xine RET   access -1 errno 2 No such file or directory
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/usr/local/lib/libstdc++.so.4"
 37294 xine RET   access -1 errno 2 No such file or directory
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/lib/libstdc++.so.4"
 37294 xine RET   access -1 errno 2 No such file or directory
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/usr/lib/libstdc++.so.4"
 37294 xine RET   access 0
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/usr/X11R6/lib/libm.so.3"
 37294 xine RET   access -1 errno 2 No such file or directory
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/usr/local/lib/libm.so.3"
 37294 xine RET   access -1 errno 2 No such file or directory
 37294 xine CALL  access(0x2816a000,0)
 37294 xine NAMI  "/lib/libm.so.3"
 37294 xine RET   access 0
 37294 xine CALL  mprotect(0x29f74000,0xf000,0x7)
 37294 xine RET   mprotect 0
 37294 xine CALL  mmap(0,0x348,0x3,0x1000,0x,0,0,0)
 37294 xine RET   mmap 704557056/0x29feb000
 37294 xine CALL  munmap(0x29feb000,0x348)
 37294 xine RET   munmap 0
 37294 xine CALL  mprotect(0x29f74000,0xf000,0x5)
 37294 xine RET   mprotect 0
 37294 xine CALL  mmap(0,0xb48,0x3,0x1000,0x,0,0,0)
 37294 xine RET   mmap 704557056/0x29feb000
 37294 xine CALL  munmap(0x29feb000,0xb48)
 37294 xine RET   munmap 0
 37294 xine PSIG  SIGBUS SIG_DFL
 37294 xine CALL  kse_thr_interrupt(0,0x4,0xa)
 37294 xine NAMI  "xine.core"

I'm not sure how you figured out it was that plugin - I guess you are having 
the same problem and that file was appearing in your ktrace? 

Just in case there was some cruft in my plugins, I tried moving the whole 
1.1.0 dir somewhere else and rebuilt libxine and xine.
Then I tried running xine again and it crashed with the same trace as before.

Cheers,
-- 
Ian
gpg key: http://home.swiftdsl.com.au/~imoore/no-spam.asc


pgpMkd8gONjD0.pgp
Description: PGP signature


Re: vsftpd watch problem

2005-10-06 Thread Yuan Jue
Thank you very much for your information!

On Friday 07 October 2005 04:00, Joe S wrote:
> ...this is not really a "pragmatic" problem. You are using an FTP server
> that aims to be simple and light. VSFTPD does not have any tools to
> provide you with usage, to my knowledge.
>
> * ProFTPD, on the other hand, has utility programs (ftpwho, ftpcount,
> ftptop) that read the scoreboard and display the information you are
> looking for. Security record of PROFTPD:
> http://secunia.com/search/?search=proftpd
>
> * PureFTPD has a utility (pure-ftpwho) that will also display the
> information you are looking for. Security record of PUREFTPD:
> http://secunia.com/search/?search=pureftpd


-- 
Best Regards.

Yuan Jue
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: wazzup with this java build warning?

2005-10-06 Thread Kris Kennaway
On Thu, Oct 06, 2005 at 07:32:41PM -0500, Randy Schultz wrote:
> Doing a make in ports/java/jdk14.  Have in ports/distfiles the files the
> make asks for.  When the make continues it warns with:
> 
> ===>Verifying install for /usr/local/linux-sun-jdk1.4.2/bin/javac in 
> /usr/ports/java/linux-sun-jdk14
> ==
> Warning: This JDK may be unstable. You are advised to use the native
> FreeBSD JDK, in ports/java/jdk14.
> 
> 
> I don't get this.  I am using ports/java/jdk14, performing the make there,
> yet it barks with this.  Is this some debris from a bygone check or did I 
> miss a step?

No, read what it says..it's installing the linux-sun-jdk14 port as
part of the build of jdk14.  Why?  Because you need a java compiler to
bootstrap the java compiler.

Kris

pgp8D3Xf9AwHg.pgp
Description: PGP signature


wazzup with this java build warning?

2005-10-06 Thread Randy Schultz
Doing a make in ports/java/jdk14.  Have in ports/distfiles the files the
make asks for.  When the make continues it warns with:

===>Verifying install for /usr/local/linux-sun-jdk1.4.2/bin/javac in 
/usr/ports/java/linux-sun-jdk14
==
Warning: This JDK may be unstable. You are advised to use the native
FreeBSD JDK, in ports/java/jdk14.


I don't get this.  I am using ports/java/jdk14, performing the make there,
yet it barks with this.  Is this some debris from a bygone check or did I 
miss a step?

--
 Randy([EMAIL PROTECTED])  715-726-2832 email bodhisattva <*>

 "There is no fire like passion, there is no shark like hatred,  there is no
snare like folly, there is no torrent like greed."

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


opencroquet?

2005-10-06 Thread Mike Hernandez
Has anyone gotten opencroquet (http://www.opencroquet.org/) to work
with freebsd? I see a version for mac, linux, and windows. Maybe under
linux emulation?

Mike
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: sendmail not starting at boot

2005-10-06 Thread Annelise Anderson

On Thu, 6 Oct 2005, Chuck Swiger wrote:


Annelise Anderson wrote:

On 5.4-STABLE as of October 1, sendmail doesn't start on reboot.
I have to either do it by hand or run sh rc.sendmail (which does
start it).  There's no sendmail.sh in /usr/local/etc/rc.d.


Sendmail is part of the FreeBSD base system by default, and not something in 
/usr/local.  You should have a /etc/rc.d/sendmail RC script...


Interesting, it was blank except for the first line.  My failure to do
anything but mergemaster -p.



The rc.conf has sendmail_enable="YES" and I even changed this
in /etc/defaults/rc.conf.


Don't change /etc/defaults/rc.conf.  Change /etc/rc.conf only.


I supposed I could clip some of rc.sendmail and put in in a
sendmail.sh file for /usr/local/etc/rc.d, but perhaps something
more obvious is wrong.  I want sendmail to be not only a
local mta but to be the incoming and outgoing server.


OK.  Setting:

sendmail_enable="YES"

...ought to do the trick, so something else is going on.


Have you checked /var/log/messages and /var/log/maillog?
Is your hostname set to a valid FQDN?
Is local DNS working properly on that machine?

Have you copied /etc/mail/freebsd.mc to /etc/mail/host.example.com.mc, 
editting that file if and as needed, and doing a "make all" in /etc/mail? 
See /etc/mail/README.


Thank you for this and my apologies for a second copy of this message,
which also went to the list after I added a smart relay host (nothing
was going out beyond the stanford.edu domain, which I guess is
something Stanford imposes).

Annelise

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Acroread7 with Firefox

2005-10-06 Thread Beecher Rintoul
Has anyone gotten acroread to work with Firefox? I have linuxpluginwrapper and 
acroread7 installed. In addition both Java and Flash are installed and work. 
I have tried both the plugin install script and symlinking the plugin to 
browser plugins, but when I do about:plugins in Firefox it doesn't show up. I 
tried google but I couldn't find anything helpful.  Acroread7 does work as a 
standalone. Am I missing something?

TIA,

Beech
-- 
---
Beech Rintoul - System Administrator - [EMAIL PROTECTED]
/"\   ASCII Ribbon Campaign  | NorthWind Communications
\ / - NO HTML/RTF in e-mail  | 201 East 9th Avenue Ste.310
 X  - NO Word docs in e-mail | Anchorage, AK 99501
/ \ 
---













pgpoMRU2DSTzJ.pgp
Description: PGP signature


Stale dependency problem

2005-10-06 Thread Ugo Bellavance

Hi,


When I run portupgrade, I get this:

[EMAIL PROTECTED] portupgrade -a
Stale dependency: php4-overload-4.3.10_2 --> php4-4.3.10_2 -- manually 
run 'pkgdb -F' to fix, or specify -O to force.


So I run it:

[EMAIL PROTECTED] pkgdb -F
--->  Checking the package registry database
Stale dependency: php4-overload-4.3.10_2 -> php4-4.3.10_2 (lang/php4):
cannot convert nil into String
New dependency? (? to help):

When I do '?', I get this:

New dependency? (? to help): ?
 [Enter] to skip, [Ctrl]+[D] to delete,  [.][Enter] to abort, [Tab] to 
complete


Now I'm lost.  Can anyone give me a hint to start with?

Regards,
--
Ugo

-> Please don't send a copy of your reply by e-mail.  I read the list.
-> Please avoid top-posting, long signatures and HTML, and cut the 
irrelevant parts in your replies.


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: run php from crontab

2005-10-06 Thread martin hudec
Hello,

On Fri, Oct 07, 2005 at 12:47:19AM +0200 or thereabouts, Janko Harej wrote:
> I would like to set crontab for executing php script. I've set up
> apache 1.3 with mod_php and mysql and egroupware. All works fine. The
> problem is that I can not find php on my disk. I've tried to install
> php4 package but the sistem tells me, that there is already mod_php
> installed.
> 
> Can anybody help me? How can I set something like
> 
> /5 * * * * apache /usr/bin/php -q
> /var/www/html/phpgwapi/cron/asyncservices.php default
> 
> in my cron tab if I don't know where php preprocesor is. How can I
> figure out how apache is serving php pages?

  You need to have lang/php4 port installed first, because it conflicts
  with mod_php4*. Install www/mod_php4 after you have lang/php4 
  installed.

  Also read pkg-message.mod in lang/php4 for instructions how to enable
  php support in Apache. After then, go for lang/php4-extensions to
  install whatever php module your heart desires.

Cheers,

-- 
martin hudec


   * 421 907 303 393
   * [EMAIL PROTECTED]
   * http://www.aeternal.net

"Nothing travels faster than the speed of light with the possible 
exception of bad news, which obeys its own special laws."

   Douglas Adams, "The Hitchhiker's Guide to the Galaxy"


pgp8HruqNe1hr.pgp
Description: PGP signature


Playing Flash and video media in Firefox

2005-10-06 Thread edward

Hi,
I'm not quite sure how to get Firefox (on 5.4-Stable, Xorg 6.8.2 and KDE 
3.4.2) to play the following media :

- Flash
- Quicktime
- Windows Media
Any clue ?
Thanks all,
Edward

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


run php from crontab

2005-10-06 Thread Janko Harej
Hi,

I would like to set crontab for executing php script. I've set up
apache 1.3 with mod_php and mysql and egroupware. All works fine. The
problem is that I can not find php on my disk. I've tried to install
php4 package but the sistem tells me, that there is already mod_php
installed.

Can anybody help me? How can I set something like

/5 * * * * apache /usr/bin/php -q
/var/www/html/phpgwapi/cron/asyncservices.php default

in my cron tab if I don't know where php preprocesor is. How can I
figure out how apache is serving php pages?

Thanks
--
Janko
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Re: LDAP + PAM + pam_groupdn / pam_member_attribute (revisited)

2005-10-06 Thread Brian A. Seklecki


Ahhh.  Cheeky bastards.  You sit around and think "group" for 18 hours 
with regard to POSIX Groups.  Then it comes time to sit down and configure 
"group membership" login restriction.  But really, they are entirely 
unrelated concepts.  It even says in the man page:


"Specifies the distinguished name of a group to which a user must belong 
for logon authorization to succeed."


Right? Right?

But...

"pam_groupdn" has absolutely nothing to do with whether the DN/RND of the 
user trying to authenticate contains an attribute "uid=user1", which 
matches a "memberUid" multi-value attribute in any object type 
"posixGroup".


This is simply not what the code checks.  That would make too much sense 
to use the symantics of UNIX / POSIX to make this determination.  I.e.,


"You're in that UNIX group, you can login."

Instead, it checks to see if the entire DN of authenticating user/DN is in 
SOME/ANY multi-value attribute defined by "pam_member_attribute".


That explains why the authors of "LDAP System Administration" go to the 
trouble of creating an entirely different "ou=Hosts" (which, once again, 
is an entirely ambiguous name) for containing "host/group" objects (which 
are really supposed to be used for DNS!)  with "member:" attributes for 
this purpose.


What's more, the values of your "pam_member_attribute", in this case 
"memberUid", but really should be, "memberDN", must be the entire DN and 
not an RDN.


For example:

memberDN: cn=Keyser Soze,ou=People,o=priv,dc=root,dc=com

but this won't work (RDN?):

memberDN: uid=ksoze,ou=People,o=priv,dc=root,dc=com

[snip]

$ ldapsearch blah blah

# dev, posixGroups, priv, root, com
dn: cn=dev,ou=posixGroups,o=priv,dc=root,dc=com
cn: dev
objectClass: posixGroup
objectClass: top
gidNumber: 65532
memberUid: cn=Keyser Soze,ou=People,o=priv,dc=root,dc=com
memberUid: cn=Am Biguity,ou=People,o=priv,dc=root,dc=com

Of course, this isn't explained anywhere in the man page and has probably 
lead to unfathomable ammounts of similar confusion previously.  One would 
naturally thing "Oh, excellent, POSIX groups as ACLs for restricting 
access to groups of machines", but no >:}


A better name would be "Cluster ACL" or "Host ACL" or "ACL Group" 
"HostGroup Object".


Another option would be some kind of ldap.conf(5) style regular expression 
you could use to convert/match a POSIX ACL into a "pam_groupdn".  That 
would be nice and dirty and would keep par.


Good times, good times.

And now to go submit a send-pr(1) to the FreeBSD port maintainer with a 
patch to pam_ldap.5, pray it gets commited back upstream, and then drink 
myself blind in the left eye so I can never read another LDAP man page.


~BAS

On Thu, 6 Oct 2005, Brian A. Seklecki wrote:



This should be so insanely easy.  I'm relatively certain this a FreeBSD PAM 
specific issue.  From "LDAP system administration [electronic resource] / 
Gerald Carter. 1st ed.  Beijing ; Sebastopol, CA : O'Reilly, c2003."


in ldap.conf and nss_ldap.conf

--

# Group to enforce membership of
pam_groupdn cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com

# Group member attribute
pam_member_attribute memberUid

---

...and then in LDAP, have an object, *ANY* object will function as a "group", 
as long as it supports a multi-value attribute, in this case memberUid such 
as a posixGroup:


# groupName, posixGroups, priv, root, dn
dn: cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com
cn: cfdev
objectClass: posixGroup
objectClass: top
gidNumber: 65532
memberUid: user1
memberUid: user2
memberUid: user3
memberUid: user4
memberUid: user5
memberUid: user6


...this result returned by the same search I'm asking PAM to do:

$ ldapsearch -D "cn=bofh,dc=root,dc=com" -b dc=root,dc=com -H 
ldap://ldapserver -Z -W "(objectClass=posixGroup)"


Then adjust for PAM in SSHD:


# auth
authrequiredpam_nologin.so  no_warn
authsufficient  pam_opie.so no_warn 
no_fake_prompts

authrequisite   pam_opieaccess.so   no_warn allow_local
#auth   sufficient  pam_krb5.so no_warn 
try_first_pass
#auth   sufficient  pam_ssh.so  no_warn 
try_first_pass
authsufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass
authrequiredpam_unix.so no_warn 
try_first_pass


# account
#accountrequiredpam_krb5.so
account requiredpam_login_access.so
account required/usr/local/lib/pam_ldap.so 
ignore_authinfo_unavail ignore_unknown_user

account requiredpam_unix.so

# session
#sessionoptionalpam_ssh.so
session requiredpam_permit.so
#session sufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass


# password
#password   sufficient  pam_krb5.so no_warn 
try_first_pass
passwordrequiredpam_unix.so no_warn 
try_first_pass
#password 

Re: [ldap] Re: LDAP + PAM + pam_groupdn / pam_member_attribute (revisited)

2005-10-06 Thread Brian A. Seklecki


right!

...from pam_ldap(5):

PAM CONFIGURATION

   It is possible to configure some aspects of pam_ldap on a per-service
   basis, in the PAM configuration file (this is usually /etc/pam.conf;
   for PAM implementations based on Linux-PAM, per-service files in
   /etc/pam.d are also supported).

[..]


 debug:  This option is recognized by pam_ldap but is presently ignored.

~bas
AA


[A


On Thu, 6 Oct 2005, Jeff Saxton wrote:


you can run pam modules in debug mode:

"The last option listed in a PAM configuration line supplies any additional 
arguments that should be passwd toe the module upon invocation.


debug
 Enables generation of debugtging information either to standard output or 
via the syslogd daemon"


Good luck

Brian A. Seklecki wrote:


This should be so insanely easy.  I'm relatively certain this a FreeBSD PAM 
specific issue.  From "LDAP system administration [electronic resource] / 
Gerald Carter. 1st ed.  Beijing ; Sebastopol, CA : O'Reilly, c2003."


in ldap.conf and nss_ldap.conf

--

# Group to enforce membership of
pam_groupdn cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com

# Group member attribute
pam_member_attribute memberUid

---

...and then in LDAP, have an object, *ANY* object will function as a 
"group", as long as it supports a multi-value attribute, in this case 
memberUid such as a posixGroup:


# groupName, posixGroups, priv, root, dn
dn: cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com
cn: cfdev
objectClass: posixGroup
objectClass: top
gidNumber: 65532
memberUid: user1
memberUid: user2
memberUid: user3
memberUid: user4
memberUid: user5
memberUid: user6


...this result returned by the same search I'm asking PAM to do:

$ ldapsearch -D "cn=bofh,dc=root,dc=com" -b dc=root,dc=com -H 
ldap://ldapserver -Z -W "(objectClass=posixGroup)"


Then adjust for PAM in SSHD:


# auth
authrequiredpam_nologin.so  no_warn
authsufficient  pam_opie.so no_warn 
no_fake_prompts

authrequisite   pam_opieaccess.so   no_warn allow_local
#auth   sufficient  pam_krb5.so no_warn 
try_first_pass
#auth   sufficient  pam_ssh.so  no_warn 
try_first_pass
authsufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass
authrequiredpam_unix.so no_warn 
try_first_pass


# account
#accountrequiredpam_krb5.so
account requiredpam_login_access.so
account required/usr/local/lib/pam_ldap.so 
ignore_authinfo_unavail ignore_unknown_user

account requiredpam_unix.so

# session
#sessionoptionalpam_ssh.so
session requiredpam_permit.so
#session sufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass


# password
#password   sufficient  pam_krb5.so no_warn 
try_first_pass
passwordrequiredpam_unix.so no_warn 
try_first_pass
#password required  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass



...when I change "account ..pam_ldap.so" to sufficient, it allows users in 
who aren't in the required group (as it should if the check fails).  When I 
change it to required, it doesn't let them in, but there isn't a single 
useful debugging error message.


How could something so widely used as PAM make it into the wild without 
hooks for debugging?


~BAS

On Thu, 6 Oct 2005, Brian A. Seklecki wrote:



Did anyone every get this combination working?

Is 'pam_member_attribute' supposed to be uniqueMember or memberUid?

When you look at a postGroup entity, the multi-value attribute is 
memberUid!


Is there *any* way at all get debugging information out of PAM libraries, 
or is it just so insanely esoteric that it's not an option?


My favorite thing about PADL's documentation by far is the lack of 
examples.


~BAS >:}


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to 
"[EMAIL PROTECTED]"




l8*
-lava

x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8

---
You are currently subscribed to ldap@umich.edu as: [EMAIL PROTECTED]
To unsubscribe send email to [EMAIL PROTECTED] with the word 
UNSUBSCRIBE as the SUBJECT of the message.


--
Jeff Saxton
SenSage, Inc.
55 Hawthorne Street Suite 700
San Francisco, CA 94105
Phone:  415.808.5900
Fax:415.371.1385
Direct: 415-808-5921
Cell:   415-640-6392
mailto:[EMAIL PROTECTED]

Enterprise Security Analytics

SenSage, the leading provider of enterprise security analytics, offers
unparalleled performance and a scalable means for organizations to centrally
aggregate, efficiently analyze, dynamically monitor and cost-effectively
store massive volumes of event log data.





l8*
-lava

x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8
_

RE: Hidden spot on hard drives?

2005-10-06 Thread Joshua Weaver
What is the software called? Let somebody research it from there.  Or dload
the prog and crack it open wit Ida...

-Josh

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Hidden spot on hard drives?

2005-10-06 Thread cpghost
On Wed, Oct 05, 2005 at 07:44:37PM +0100, Jonathon McKitrick wrote:
> the company where I work (with Windows) is evaluating a copy protection
> product that stores info somewhere on the HDD where the user cannot touch it,
> a format will not erase it, and Norton Ghost will not find it.
> 
> 1.  Any idea where this info could be stored?

Where from do smartmontools fetch the results of the disk selftests?
Perhaps from an area that is not mapped, using some unusual controller
commands? This controlled-accessed area looks like a nice place to hide
some data, even hidden from a "dd if=/dev/ad1 ..." (they don't get reset
even after a disk format).

Though I haven't read the source code of smartctl... Just wildguessing here.

> 2.  Any way the same thing could be done under FreeBSD?
> 
> Thanks,
> 
> jm

-cpghost.

-- 
Cordula's Web. http://www.cordula.ws/
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


SoundBlaster Audigy Question

2005-10-06 Thread Sean Murphy
I have an onboard soundcard for my FreeBSD box and I was thinking of 
getting the new Audigy card.  Does the FreeBSD drivers for the Audigy 
take advantage of surround sound, EAX, digital connections, or number of 
channels? Or does the soundcard operate at a more basic level ie. stereo 
sound no hardware acceleration etc.


Is there any reason to have such a high end soundcard in a FreeBSD system?

Thanks

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Converting from IPFW to IPFILTER

2005-10-06 Thread Charles Swiger

On Oct 6, 2005, at 5:44 PM, Brian E. Conklin wrote:

I am getting ready to switch a FreeBSD 4.11 machine from IPFW to
IPFILTER for better FTP and NAT support.


Hmm.  Is there something natd doesn't handle for your case...?


I currently have IPFW compiled into the kernel.
Do I need to recompile a kernel without IPFW before I can  
enable IPF?

Can I just set IPFW to allow everything by default?
Thanks in advance for your advice.


If you're going to switch to using IPF, you might want to consider  
upgrading or reinstalling the OS  to 5.4 instead of 4.11.


--
-Chuck


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Jerry McAllister
> 
> On Thu, Oct 06, 2005 at 12:55:58PM -0400, Christian Kuhtz wrote:
> > 
> > Yeah, but also the most irrelevant when it comes to supply chain folk.
> 
> Supply-chain folk?  Is that a euphemism for "suits?"

Supply Chain Management is a whole field which probably most people 
from the old days might have called the purchasing department.

jerry

> My employer is audited by clients on a regular basis.  If you have your
> internal documentation and processes together, it doesn't seem to bother
> any of the corporate-types we run up against in the health-care industry
> that we are running a freely-available, open-source OS.
> 
> If you require "commercial support" I'd like to think there is a
> commercial entity that can lease such an option to you.  The FreeBSD
> foundation hasn't gone down that road yet, unlike some other projects.
> Maybe someday, but if you need a commercial support option that is
> co-branded with your Operating System, you could do worse than Solaris,
> or Red Hat Enterprise.

I think there are some persons out there who sell FreeBSD support
for a fee.

jerry

> 
> -danny
> 
> > >On 10/6/05, Ansar Mohammed <[EMAIL PROTECTED]> wrote:
> > >
> > >>I guess I am interested in finding out if there is support that is  
> > >>offered
> > >>by the FreeBSD project, not from third party vendors.
> > >>
> > >
> > >FreeBSD offers non-commercial support through
> > >mailing-lists and doc-project (FAQs and Handbooks)
> > >which is probably the most comprehensive,
> > >active and effective support there is.
> ___
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "[EMAIL PROTECTED]"
> 

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Converting from IPFW to IPFILTER

2005-10-06 Thread Brian E. Conklin
Hello Everyone,
I am getting ready to switch a FreeBSD 4.11 machine from IPFW to
IPFILTER for better FTP and NAT support.
I currently have IPFW compiled into the kernel.
Do I need to recompile a kernel without IPFW before I can enable IPF?
Can I just set IPFW to allow everything by default?
Thanks in advance for your advice.

Brian E. Conklin
Director of Information Services
Mason General Hospital
PO Box 1668, Shelton, WA 98584
http://www.masongeneral.com

=
Mason General Hospital
901 Mt. View Drive
PO Box 1668
Shelton, WA 98584
http://www.masongeneral.com
(360) 426-1611
=
This message is intended for the sole use of the individual and entity
to whom it is addressed and may contain information that is privileged,
confidential and exempt from disclosure under applicable law. If you
are not the addressee nor authorized to receive for the addressee, you
are hereby notified that you may not use, copy, disclose or distribute
to anyone this message or any information contained in the message. If
you have received this message in error, please immediately notify the
sender and delete the message.

Replying to this message constitutes consent to electronic monitoring
of this message.

Thank you.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


RE: Restoring Data from a DD image

2005-10-06 Thread Gayn Winters


> -Original Message-
> From: Bill Schmitt (SW) [mailto:[EMAIL PROTECTED] 
> Sent: Thursday, October 06, 2005 1:16 PM
> To: [EMAIL PROTECTED]
> Cc: [EMAIL PROTECTED]
> Subject: Re: Restoring Data from a DD image
> 
> 
> Gayn Winters wrote:
> 
> >>-Original Message-
> >>From: [EMAIL PROTECTED] 
> >>[mailto:[EMAIL PROTECTED] On Behalf Of 
> >>Bill Schmitt (SW)
> >>Sent: Thursday, October 06, 2005 11:11 AM
> >>To: [EMAIL PROTECTED]
> >>Subject: Restoring Data from a DD image
> >>
> >>
> >>I've just replaced a hard disk that was dying fast. I've 
> done a full 
> >>installation of 4.9 (later releases won't install, which I've 
> >>submitted 
> >>a problem report on already). The old disk is connected but 
> >>not mounted. 
> >>Searching around, I found some suggestions to try to read the 
> >>old disk 
> >>to restore what I can and I used dd to copy what could be found (dd 
> >>-if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg 
> conv=noerror,sync) and it 
> >>seems to have copied the file. Now, I'm a little stuck. Can 
> >>someone help 
> >>me understand how do I mount that image somewhere to browse 
> >>it and copy 
> >>what I can from it? If I'm not going about this the right way, I'd 
> >>appreciate other suggestions
> >>
> >>
> >>
> >
> >I'm a little confused:
> > 
> >Did you try to copy (dd) the old disk before you did a new install?  
> >If so, to where?
> >
> >Is /dev/ad0 your new disk with the fresh 4.9 installation on 
> ad0s1? Or
> >did you just add a new disk as /dev/ad1 and did the fresh install on
> >ad1s1?
> >
> >Is your unmounted old disk /dev/ad0 or /dev/ad1 now?
> >
> >I'm guessing that ad1 is your new install, ad0 is not 
> mounted, and you
> >were able to copy ad0s1e to oldimag.dmg with the above dd 
> command.  If
> >so, continue. If not, send a correction.
> >
> >Why not try 
> >   mount -r -t ufs /usr/olddsk/oldimag.dmg /mnt
> >   cd /mnt
> >   ls
> >
> >I ***think*** mount will do this.  If not, try dd'ing 
> oldimag.dmg to a
> >spare slice, e.g. if you created /tmp as /dev/ad1s1e, then you could
> >   dd if=/usr/olddsk/oldimag.dmg of=/dev/ad1s1e
> >   cd /tmp
> >   ls
> >
> >Good luck!
> >
> >-gayn
> >

> Sorry, when I first decided to try FreeBSD, I had a 4.7GB as 
> the primary 
> on ad0 and moved usr to ad1 when I added the drive that 
> ultimately went 
> bad (a 60GB) as ad1. When I had to do a full installation 
> again, I put a 
> new drive (80GB) into place where the 4.7GB drive was and 
> started from 
> scratch with ad1 disabled. So, now I'm booting from the new drive and 
> have used dd to copy whatever is found on the damaged ad1 to 
> an image on 
> ad0. It's after that I get stuck. I've looked at the man page 
> for mount, 
> but  I haven't seen anything specific to an image. I tried your 
> suggested mount command, but it responded "Block device required". I 
> suppose I can try to dd back to the 4.7GB drive that I would 
> now mount 
> as ad1. We'll see what happens.
> 
> Thanks,
> 
> Bill
> 

As Joe S suggests, use mdconfig or vnconfig to create the block device,
then mount works. (I tried it with mdconfig using 5.4.) Dd'ing to a
spare slice or partition will surely work as well.  

-gayn


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: LDAP + PAM + pam_groupdn / pam_member_attribute (revisited)

2005-10-06 Thread Brian A. Seklecki


This should be so insanely easy.  I'm relatively certain this a 
FreeBSD PAM specific issue.  From "LDAP system administration [electronic 
resource] / Gerald Carter. 1st ed.  Beijing ; Sebastopol, CA : O'Reilly, 
c2003."


in ldap.conf and nss_ldap.conf

--

# Group to enforce membership of
pam_groupdn cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com

# Group member attribute
pam_member_attribute memberUid

---

...and then in LDAP, have an object, *ANY* object will function as a 
"group", as long as it supports a multi-value attribute, in this case 
memberUid such as a posixGroup:


# groupName, posixGroups, priv, root, dn
dn: cn=groupName,ou=posixGroups,o=priv,dc=root,dc=com
cn: cfdev
objectClass: posixGroup
objectClass: top
gidNumber: 65532
memberUid: user1
memberUid: user2
memberUid: user3
memberUid: user4
memberUid: user5
memberUid: user6


...this result returned by the same search I'm asking PAM to do:

$ ldapsearch -D "cn=bofh,dc=root,dc=com" -b dc=root,dc=com -H 
ldap://ldapserver -Z -W "(objectClass=posixGroup)"


Then adjust for PAM in SSHD:


# auth
authrequiredpam_nologin.so  no_warn
authsufficient  pam_opie.so no_warn 
no_fake_prompts
authrequisite   pam_opieaccess.so   no_warn 
allow_local
#auth   sufficient  pam_krb5.so no_warn 
try_first_pass
#auth   sufficient  pam_ssh.so  no_warn 
try_first_pass
authsufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass
authrequiredpam_unix.so no_warn 
try_first_pass


# account
#accountrequiredpam_krb5.so
account requiredpam_login_access.so
account required/usr/local/lib/pam_ldap.so 
ignore_authinfo_unavail ignore_unknown_user

account requiredpam_unix.so

# session
#sessionoptionalpam_ssh.so
session requiredpam_permit.so
#session sufficient  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass


# password
#password   sufficient  pam_krb5.so no_warn 
try_first_pass
passwordrequiredpam_unix.so no_warn 
try_first_pass
#password required  /usr/local/lib/pam_ldap.so no_warn 
try_first_pass



...when I change "account ..pam_ldap.so" to sufficient, it allows users in 
who aren't in the required group (as it should if the check fails).  When 
I change it to required, it doesn't let them in, but there isn't a single 
useful debugging error message.


How could something so widely used as PAM make it into the wild without 
hooks for debugging?


~BAS

On Thu, 6 Oct 2005, Brian A. Seklecki wrote:



Did anyone every get this combination working?

Is 'pam_member_attribute' supposed to be uniqueMember or memberUid?

When you look at a postGroup entity, the multi-value attribute is memberUid!

Is there *any* way at all get debugging information out of PAM libraries, or 
is it just so insanely esoteric that it's not an option?


My favorite thing about PADL's documentation by far is the lack of examples.

~BAS >:}


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"



l8*
-lava

x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Danny Howard
On Thu, Oct 06, 2005 at 12:55:58PM -0400, Christian Kuhtz wrote:
> 
> Yeah, but also the most irrelevant when it comes to supply chain folk.

Supply-chain folk?  Is that a euphemism for "suits?"

My employer is audited by clients on a regular basis.  If you have your
internal documentation and processes together, it doesn't seem to bother
any of the corporate-types we run up against in the health-care industry
that we are running a freely-available, open-source OS.

If you require "commercial support" I'd like to think there is a
commercial entity that can lease such an option to you.  The FreeBSD
foundation hasn't gone down that road yet, unlike some other projects.
Maybe someday, but if you need a commercial support option that is
co-branded with your Operating System, you could do worse than Solaris,
or Red Hat Enterprise.

-danny

> >On 10/6/05, Ansar Mohammed <[EMAIL PROTECTED]> wrote:
> >
> >>I guess I am interested in finding out if there is support that is  
> >>offered
> >>by the FreeBSD project, not from third party vendors.
> >>
> >
> >FreeBSD offers non-commercial support through
> >mailing-lists and doc-project (FAQs and Handbooks)
> >which is probably the most comprehensive,
> >active and effective support there is.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Nessus no longer open source

2005-10-06 Thread Charles Swiger

On Oct 6, 2005, at 12:04 PM, Gayn Winters wrote:

"Nessus 3 will be available for many platforms, but do understand that
we won't be able to support every distribution / operating system
available. I also understand that some free software advocates won't
want to use a binary-only Nessus 3. This is why Nessus 2 will
continue to be maintained and will stay under the GPL."

I'm not sure if Nessus 3 will be supported as a FreeBSD package.


Probably not-- if the new license for Nessus 3 forbids commercial  
redistribution, then we won't be able to provide a package.  However,  
the FreeBSD ports system has options to handle software which is  
under a restrictive license or distributed only as a binary.



[ ... ] The thing that seems germane
to the FreeBSD community is that ports, even extremely popular  
ones, are

vulnerable, since under the GPL the AUTHOR of the code is not bound by
the same restrictions that the users are.  I'm not a lawyer, but as I
understand it, the author can create a derived work of something under
the GPL and license the derived work (a "rewrite" in the case of  
nessus

3) and arbitrarily restrict it.


The author or copyright holder of software has the right to  
redistribute their software under other terms if they wish to do so;  
this has nothing to do with the GPL in particular, or even with  
creating derivative works in general.  (One creates a derivative work  
when someone other than the original author makes changes to a work.)


However, the GPL'ed version of the software, in this case Nessus 2,  
remains and will always remain available under the terms of the GPL.   
The decision to open source software is not revokable in that sense.   
People who are not happy with the direction Tenable is going with  
Nessus 3 could fork Nessus 2 and continue to develop it, if they  
choose to do so, with or without further contributions from Tenable.


--
-Chuck

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


LDAP + PAM + pam_groupdn (revisited)

2005-10-06 Thread Brian A. Seklecki


Did anyone every get this combination working?

Is 'pam_member_attribute' supposed to be uniqueMember or memberUid?

When you look at a postGroup entity, the multi-value attribute is 
memberUid!


Is there *any* way at all get debugging information out of PAM libraries, 
or is it just so insanely esoteric that it's not an option?


My favorite thing about PADL's documentation by far is the lack of 
examples.


~BAS >:}


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re[2]: bruteforceblocker + PF

2005-10-06 Thread Daniel Gerzo
Hi Dave,

Thursday, October 6, 2005, 10:24:20 PM, you wrote about:

> Hello,
> I've got bruetforceblocker going with pf, i just installed the port. My
> box is a 5.4 machine. I have it going on my lan server, which does ssh for
> my network, it's the box you'll hit if you ssh in as opposed to the firewall
> box. It's adding ip's to the table, but it's doing it staggeringly, i see
> activity in my logs where atempts are made and then the IP's keep coming
> back as if they're not being blocked.

I'm running BruteForceBlocker on a bunch of the boxes and I have no
problem with it. can you check the pf table, if it is growing? Can you
also see messages like:

User root from 67.15.192.35 not allowed because not listed in AllowUsers
67.15.192.35 was logged with total count of 1.
Failed password for invalid user root from 67.15.192.35 port 36082 ssh2
67.15.192.35 was logged with total count of 2.
User root from 67.15.192.35 not allowed because not listed in AllowUsers
67.15.192.35 was logged with total count of 3.
Failed password for invalid user root from 67.15.192.35 port 36111 ssh2
IP 67.15.192.35 reached the maximum number of failed attempts!!!
Adding IP to the firewall...

in your auth logfile?

If you want to check the pf table use command like:
# pfctl -t bruteforce -T show

> Thanks.
> Dave.

-- 
Best Regards,
  Daniel Gerzo

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Nice brushup!!! www.freebsd.org

2005-10-06 Thread Erik Nørgaard

Hi,

I just saw the new website - did it get on today? - this is really a 
nice job - well done!!! I hope this will support the impression that 
FreeBSD is professional, all the way through.


I know that some people like to think that a nice website is just 
eyecandy - empty calories - but it works, and it's a pleasure to browse!


Congratulations!

Erik
--
Ph: +34.666334818   web: http://www.locolomo.org
S/MIME Certificate: http://www.locolomo.org/crt/2004071206.crt
Subject ID:  A9:76:7A:ED:06:95:2B:8D:48:97:CE:F2:3F:42:C8:F2:22:DE:4C:B9
Fingerprint: 4A:E8:63:38:46:F6:9A:5D:B4:DC:29:41:3F:62:D3:0A:73:25:67:C2
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: bruteforceblocker + PF

2005-10-06 Thread Dave

Hello,
   I've got bruetforceblocker going with pf, i just installed the port. My 
box is a 5.4 machine. I have it going on my lan server, which does ssh for 
my network, it's the box you'll hit if you ssh in as opposed to the firewall 
box. It's adding ip's to the table, but it's doing it staggeringly, i see 
activity in my logs where atempts are made and then the IP's keep coming 
back as if they're not being blocked.

Thanks.
Dave.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Dell PowerEdge w/ Intel AFT / Broadcom BASP

2005-10-06 Thread Brian A. Seklecki


For the record on this, Dell claims that AFT/ALB is entirely software 
based.



On Wed, 5 Oct 2005, Brian A. Seklecki wrote:


All:

This may be better for freebsd-cluster@freebsd.org, but that list is kind of 
ghost town, and this question is more a standards-based:


Does anyone deploy Dell Poweredge in a HA configuration utilizing these 
features?


http://www.intel.com/network/connectivity/resources/technologies/load_balancing.htm
http://www1.us.dell.com/content/topics/global.aspx/power/en/ps1q03_bhutani?c=us&cs=555&l=en&s=biz
http://www.broadcom.com/drivers/faq_drivers.php#55

Do we know what underlying standards and protocols compose these 
"technologies"? 802.3ad, Cisco FEC?


Intel AFT claims to provide redundancy over a "team" of NICs.  ALB claims 
link aggregation; but they don't specify if they're doing it in hardware or 
sofware (see Below)


Broadcom BASP claims the same, given different terminology and vendor.

I'm looking for a "fault tolerant" configuration for a HA cluster.  "Load 
balancing" and/or "link aggregation" is not required.  I need to be able to 
"team" two NICs into one Virtual NIC.  Each NIC connects to two redundant 
managed switches, on which the connecting switch ports exist in the same VLAN 
(which is then ISL/802.1q trunked between them).  Essentially

the same ethernet segment.

I see ng_one2many(4), but the man page doesn't really state what standard 
that uses.  It seems to be all in-kernel magic (LACP and 802.3.ad aren't 
mentioned in the man page); will this meet the above requirements?


There were some ng_one2many(4) patches a while back to add more intellegence, 
(FEC/802.3ad heartbeat like control protocol)


http://marc.theaimsgroup.com/?t=10769597742&r=1&w=2
...but no mention of them ever being commited.

I see ng_fec(4) also, but I don't think that Cisco Ethernet Channel can occur 
between two switches and one server (correct me if I'm wrong).


I question the Hardware v.s. Software issue on the Intel NICs becase the Dell 
PowerEdges Severs that happen to have Intel NIC Chipsets using em(4) (many 
have Broadcom), seem to automatically try to "team" NICs when they're 
connected to unmanaged PowerConnect switches, breaking ng_one2many logic. 
They constantly alternate MAC addresses between the primary ethernet, the 
secondary ethernet, and a 3rd 1-byte-off Virtual MAC.


This automatic attempt to team seems like a hardware feature.  If it was a 
software feature, in theory it wouldn't try to team w/o being instructed to?


On the other hand, *managed* Dell PowerConnect switches feature something 
called "LAG", which the docs describe as 802.3ad / LACP.


I haven't tried ng_one2many on non-Dell or Dell Managed switches to see if 
the MAC address "bouncing" problem persists, but I'll try that today.


So the big question:

*) Is the Windows/Linux-only software for configuring "teams" of NICs,
   described in the URLs below, designed to configure a hardware level
   feature that might have more intellegent link failure detection than
   ng_many2one? (I.e., other than just lost carrier, say, STP storm
   detection or excessive packet error thresholds).  Or is it software?

*) If it is a hardware feature, could our em(4) driver be adapted or
   could it possibly be configured using OpenManage via the Intel
   IPMI/DMI/SMI whatever?

*) Can Cisco FEC or 802.3ad provide reundancy between two switches and
   one server w/ two NICs?  Will NetGraph ever have a 802.3ad module?

*) What combination of Switch and NIC related teaming / failover technology
   are known to be compatible with FreeBSD ?

TIA,
~BAS



l8*
-lava

x.25 - minix - bitnet - plan9 - 110 bps - ASR 33 - base8
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: bruteforceblocker + PF

2005-10-06 Thread Daniel Gerzo
Hi questions, Enrique Ayesta Perojo,



   It seems like bruteforceblocker is running, since you can see
   messages in your auth.log. this is good. could you please provide
   me info, which version of openssh are you using, so I can debug? I
   have som reports, that my bruteforceblocker does not work with
   older versions of openssh, since it uses little bit different
   format of warnings, so my regexps does not apply. Also, please send
   here the format of those messages.

   Thank you.

-- 
Sincerely,
  Daniel Gerzo

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Restoring Data from a DD image

2005-10-06 Thread Bill Schmitt (SW)

Gayn Winters wrote:


-Original Message-
From: [EMAIL PROTECTED] 
[mailto:[EMAIL PROTECTED] On Behalf Of 
Bill Schmitt (SW)

Sent: Thursday, October 06, 2005 11:11 AM
To: [EMAIL PROTECTED]
Subject: Restoring Data from a DD image


I've just replaced a hard disk that was dying fast. I've done a full 
installation of 4.9 (later releases won't install, which I've 
submitted 
a problem report on already). The old disk is connected but 
not mounted. 
Searching around, I found some suggestions to try to read the 
old disk 
to restore what I can and I used dd to copy what could be found (dd 
-if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg conv=noerror,sync) and it 
seems to have copied the file. Now, I'm a little stuck. Can 
someone help 
me understand how do I mount that image somewhere to browse 
it and copy 
what I can from it? If I'm not going about this the right way, I'd 
appreciate other suggestions


   



I'm a little confused:

Did you try to copy (dd) the old disk before you did a new install?  
If so, to where?


Is /dev/ad0 your new disk with the fresh 4.9 installation on ad0s1? Or
did you just add a new disk as /dev/ad1 and did the fresh install on
ad1s1?

Is your unmounted old disk /dev/ad0 or /dev/ad1 now?

I'm guessing that ad1 is your new install, ad0 is not mounted, and you
were able to copy ad0s1e to oldimag.dmg with the above dd command.  If
so, continue. If not, send a correction.

Why not try 
  mount -r -t ufs /usr/olddsk/oldimag.dmg /mnt

  cd /mnt
  ls

I ***think*** mount will do this.  If not, try dd'ing oldimag.dmg to a
spare slice, e.g. if you created /tmp as /dev/ad1s1e, then you could
  dd if=/usr/olddsk/oldimag.dmg of=/dev/ad1s1e
  cd /tmp
  ls

Good luck!

-gayn


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"



 

Sorry, when I first decided to try FreeBSD, I had a 4.7GB as the primary 
on ad0 and moved usr to ad1 when I added the drive that ultimately went 
bad (a 60GB) as ad1. When I had to do a full installation again, I put a 
new drive (80GB) into place where the 4.7GB drive was and started from 
scratch with ad1 disabled. So, now I'm booting from the new drive and 
have used dd to copy whatever is found on the damaged ad1 to an image on 
ad0. It's after that I get stuck. I've looked at the man page for mount, 
but  I haven't seen anything specific to an image. I tried your 
suggested mount command, but it responded "Block device required". I 
suppose I can try to dd back to the 4.7GB drive that I would now mount 
as ad1. We'll see what happens.


Thanks,

Bill

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: vsftpd watch problem

2005-10-06 Thread Joe S

Yuan Jue wrote:

Hi all

Here is a pragmatic problem. I used vsftpd to setup a ftp server. And as a 
result, some guys start to download something from my ftp server. I do want 
to know the downloader's IP and the speed he/she download from me, just as a 
status-watching for my notebook. 

Can anyone give me some clue how to do this stuff? Using vsftpd itself or 
using some freebsd utilities are both acceptable. I appreciate any 
suggestions. 

...this is not really a "pragmatic" problem. You are using an FTP server 
that aims to be simple and light. VSFTPD does not have any tools to 
provide you with usage, to my knowledge.


* ProFTPD, on the other hand, has utility programs (ftpwho, ftpcount, 
ftptop) that read the scoreboard and display the information you are 
looking for. Security record of PROFTPD: 
http://secunia.com/search/?search=proftpd


* PureFTPD has a utility (pure-ftpwho) that will also display the 
information you are looking for. Security record of PUREFTPD: 
http://secunia.com/search/?search=pureftpd


HTH.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


RE: Nessus no longer open source

2005-10-06 Thread Ted Mittelstaedt

This happened with the SAINT scanner also, however they didn't have the
decency to keep an older release train going under GPL.  SAINT was a
rework of SATAN which was released open source, making that a
particularly
bitter pill.  I believe when SAINT did this, that was what gave the
impetus to
Nessus to become popular.

Security scanning as an esoteric field and not a lot of people are true
experts
however there's a huge demand for it from some very deep pockets.  Thus
this kind of thing is inevitable.

One of the duties of the OSS market is to serve as a spawning ground for
commercial software packages.  There was a huge amount of commercial
software born from the BSD code, and in fact a number of the BSD
networking
utilities made it into Windows - including their BSD copyright notices in
fact.

Consider also that the military would almost certainly not want to use an
open source scanner because that gives the enemy a list of what
vulnerabilities
you know about, and what ones you possibly don't.  I can think of a
number
of other deep pockets like VISA that are the same way.  Closing the
source
for Nessus 3 will open it up to consideration by a number of customers
who
would have been prevented from using it.  Almost certainly the research
in the
vulnerabilities that go into Nessus 3 will trickle into Nessus 2
eventually.  So
this move, far from being a blow to OSS, actually strengthens it.  If you
want
to bitch about something then bitch about SAINT.

Ted

>-Original Message-
>From: [EMAIL PROTECTED]
>[mailto:[EMAIL PROTECTED] Behalf Of Gayn Winters
>Sent: Thursday, October 06, 2005 9:04 AM
>To: freebsd-questions@freebsd.org
>Subject: Nessus no longer open source
>
>
>One of the highest rated open source security programs, nessus, will no
>longer be open source.  Quoting from an email from Renaud Deraison
><[EMAIL PROTECTED]> to [EMAIL PROTECTED],
>
>"Nessus 3 will be available free of charge, including on the Windows
>platform, but will not be released under the GPL.
>
>"Nessus 3 will be available for many platforms, but do understand that
>we won't be able to support every distribution / operating system
>available. I also understand that some free software advocates won't
>want to use a binary-only Nessus 3. This is why Nessus 2 will
>continue to be maintained and will stay under the GPL."
>
>I'm not sure if Nessus 3 will be supported as a FreeBSD package.
>
>Apparently the folks at Tenable feel that they have been supporting the
>open source community but have been getting little back in plug-ins and
>vulnerabilities and virtually nothing back on the scanning engine for
>over six years. In fact, they have been slowly tightening their
>licensing (cf.
>http://mail.nessus.org/pipermail/nessus/2005-January/msg00185.html), and
>it would appear that they can and will continue to tighten it over time.
>
>Fyodor's analysis
>(http://seclists.org/lists/nmap-hackers/2005/Oct-Dec/.html) is that
>the open source community should take heed.  He provides a list of ways
>to contribute to open source software projects.  While the list is
>excellent, there are no new ideas in it.  The thing that seems germane
>to the FreeBSD community is that ports, even extremely popular ones, are
>vulnerable, since under the GPL the AUTHOR of the code is not bound by
>the same restrictions that the users are.  I'm not a lawyer, but as I
>understand it, the author can create a derived work of something under
>the GPL and license the derived work (a "rewrite" in the case of nessus
>3) and arbitrarily restrict it.  Given Renaud's claim that no one
>contributed to the scanning engine, he seems to have every right to
>create a new and closed version of it.
>
>The moral here, if there is one, is that if you really like a port, then
>you should contribute to it one way or another!
>
>Comments?
>
>-gayn
>
>
>
>___
>freebsd-questions@freebsd.org mailing list
>http://lists.freebsd.org/mailman/listinfo/freebsd-questions
>To unsubscribe, send any mail to
>"[EMAIL PROTECTED]"
>
>--
>No virus found in this incoming message.
>Checked by AVG Anti-Virus.
>Version: 7.0.344 / Virus Database: 267.11.9/116 - Release Date:
>9/30/2005
>

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: bruteforceblocker + PF

2005-10-06 Thread Noel Jones
On 10/6/05, Enrique Ayesta Perojo <[EMAIL PROTECTED]> wrote:
> El Miércoles, 5 de Octubre de 2005 21:53, Noel Jones escribió:
>
> > I'm going to assume this is just a small part of your pf.conf, because
> > the part you show doesn't allow any internet access.  Maybe you should
> > show us your entire pf.conf.
>

This simple pf config should work.

> No, i don't see any of these messages, the only message i see is the start of
> the log:
>
> !!! log started at Wed Oct  5 18:53:23 2005 !!!
>

I manually installed bruteforceblocker 1.1 (later noticed it's in
ports/security) and when it starts, it looks like:
--- log started at Wed Oct  5 13:13:01 2005 ---

So it appears that your software is different from mine.

Are you also seeing sshd logging information about failed and accepted
login attempts?

One thing I did notice was that all the lines in the
bruteforceblocker.pl script ended with ^M.  So I used vi to remove
them.  I don't know if that is part of your problem or not, but it's
something you might check.

FWIW, after making the suggested change to my syslog.conf file and
editing the file locations in the bruteforceblocker.pl script, it
worked first try here.  The only other suggestion I have is to check
your /etc/syslog.conf changes.
Find the line that looks like:
auth.info;authpriv.info/var/log/auth.log
and change it to:
auth.info;authpriv.info | exec
/usr/local/sbin/bruteforceblocker.pl


--
Noel Jones
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Andrew P.
On 10/6/05, Kris Kennaway <[EMAIL PROTECTED]> wrote:
> On Thu, Oct 06, 2005 at 12:10:58PM -0400, Ansar Mohammed wrote:
> > I guess I am interested in finding out if there is support that is offered
> > by the FreeBSD project, not from third party vendors.
>
> Not commercial support, since FreeBSD isn't a commercial project.
>
> Kris
>
>
>

I'm sorry, but all effective legislative systems (including
that of the USA) allow officially non-profit and non-
commercial organizations to take on commercial
activities. And many such organizations exercise this
right.

IMHO, there's no official commercial support, because
money can hardly buy more than what's already
available for free.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Restoring Data from a DD image

2005-10-06 Thread Joe S

Joe S wrote:

Bill Schmitt (SW) wrote:

I've just replaced a hard disk that was dying fast. I've done a full 
installation of 4.9 (later releases won't install, which I've 
submitted a problem report on already). The old disk is connected but 
not mounted. Searching around, I found some suggestions to try to read 
the old disk to restore what I can and I used dd to copy what could be 
found (dd -if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg 
conv=noerror,sync) and it seems to have copied the file. Now, I'm a 
little stuck. Can someone help me understand how do I mount that image 
somewhere to browse it and copy what I can from it? If I'm not going 
about this the right way, I'd appreciate other suggestions



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to 
"[EMAIL PROTECTED]"




man vnconfig
man mount

This may work:

# vnconfig /dev/vn0 /usr/olddsk/oldimag.dmg
# mount /dev/vn0 /some_mount_point_on_your_system



You may need to use /dev/vn0c instead of /dev/vn0 in both commands.
See the handbook for more info:
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/disks-virtual.html

Note: vnconfig is for 4.x, while mdconfig is for 5.x

-joe
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Restoring Data from a DD image

2005-10-06 Thread Joe S

Bill Schmitt (SW) wrote:
I've just replaced a hard disk that was dying fast. I've done a full 
installation of 4.9 (later releases won't install, which I've submitted 
a problem report on already). The old disk is connected but not mounted. 
Searching around, I found some suggestions to try to read the old disk 
to restore what I can and I used dd to copy what could be found (dd 
-if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg conv=noerror,sync) and it 
seems to have copied the file. Now, I'm a little stuck. Can someone help 
me understand how do I mount that image somewhere to browse it and copy 
what I can from it? If I'm not going about this the right way, I'd 
appreciate other suggestions



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to 
"[EMAIL PROTECTED]"




man vnconfig
man mount

This may work:

# vnconfig /dev/vn0 /usr/olddsk/oldimag.dmg
# mount /dev/vn0 /some_mount_point_on_your_system

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Hidden spot on hard drives?

2005-10-06 Thread Joe S

Joe S wrote:

Jonathon McKitrick wrote:


the company where I work (with Windows) is evaluating a copy protection
product that stores info somewhere on the HDD where the user cannot 
touch it,

a format will not erase it, and Norton Ghost will not find it.

1.  Any idea where this info could be stored?
2.  Any way the same thing could be done under FreeBSD?

Thanks,

jm



# dd if=/dev/zero of=/dev/zero

Will overwrite the entire drive.


Oops! Should have typed:

# dd if=/dev/zero of=/dev/ad0


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


semi OT: problems with mrtg(+snmp??)

2005-10-06 Thread Robert Huff

Is there anyone out there willing to help troubleshoot some
mrtg(/snmp?) issues privately?


Robert Huff


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


RE: Restoring Data from a DD image

2005-10-06 Thread Gayn Winters
> -Original Message-
> From: [EMAIL PROTECTED] 
> [mailto:[EMAIL PROTECTED] On Behalf Of 
> Bill Schmitt (SW)
> Sent: Thursday, October 06, 2005 11:11 AM
> To: [EMAIL PROTECTED]
> Subject: Restoring Data from a DD image
> 
> 
> I've just replaced a hard disk that was dying fast. I've done a full 
> installation of 4.9 (later releases won't install, which I've 
> submitted 
> a problem report on already). The old disk is connected but 
> not mounted. 
> Searching around, I found some suggestions to try to read the 
> old disk 
> to restore what I can and I used dd to copy what could be found (dd 
> -if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg conv=noerror,sync) and it 
> seems to have copied the file. Now, I'm a little stuck. Can 
> someone help 
> me understand how do I mount that image somewhere to browse 
> it and copy 
> what I can from it? If I'm not going about this the right way, I'd 
> appreciate other suggestions
> 

I'm a little confused:
 
Did you try to copy (dd) the old disk before you did a new install?  
If so, to where?

Is /dev/ad0 your new disk with the fresh 4.9 installation on ad0s1? Or
did you just add a new disk as /dev/ad1 and did the fresh install on
ad1s1?

Is your unmounted old disk /dev/ad0 or /dev/ad1 now?

I'm guessing that ad1 is your new install, ad0 is not mounted, and you
were able to copy ad0s1e to oldimag.dmg with the above dd command.  If
so, continue. If not, send a correction.

Why not try 
   mount -r -t ufs /usr/olddsk/oldimag.dmg /mnt
   cd /mnt
   ls

I ***think*** mount will do this.  If not, try dd'ing oldimag.dmg to a
spare slice, e.g. if you created /tmp as /dev/ad1s1e, then you could
   dd if=/usr/olddsk/oldimag.dmg of=/dev/ad1s1e
   cd /tmp
   ls

Good luck!

-gayn


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Determining what a port will install... (more than pretty-print-*) [Soln]

2005-10-06 Thread Csaba Henk
On Tue, Oct 04, 2005 at 11:19:03AM -0500, Eric Schuele wrote:
> Csaba Henk wrote:
> >Because all such scripts are fundamentally broken.
> >
> >When make decides which ports to pull in, it doesn't only use the flat
> >data of build and run dependencies, but uses its full Turing complete
> >computing power. Eg., what happens when a port needs a postscript
> >interpreter? 
> 
> Then do the pretty-print(s) not provide the useful information they 
> appear to?  I mean, If the above were true then they would have no 
> value... and should go away.  Or do they provide true but incomplete 
> information?

As far as I can see, they tell you the list of packages which would be
installed if you were doing the install from scratch (ie., no packages
were installed). This is a somewhat useful information, anyway.

Btw., is make really Turing complete? As far as I can see, complex tasks
are delegated to shell, but I can't recall seeing any "while" in make
code...

> >Should it use the AFPL or the GNU edition as a dependency?
> >Of course, doing a favor toward one of them (and taking away user's
> >choice) is unacceptable. So what happens is that make directly checks
> >whether the gs executable is present.
> >
> >See, for example, print/gv. Your script's output will include
> >ghostscript-gnu-7.07_13 both as a build and a run dependency.
> >Yet when I type make, my ghostscript-gnu-7.07_12 installation will
> >be happily utilized as the following output snippet shows:
> 
> Is this not acceptable behavior since it is just a port revision? 
> Shouldn't the revision be compatible in every way with the vendor's release?

What do you mean by this? The behaviour seen upon installing gv is
absolutely what one would expect. It's just hard to make proper
predictions.

> Thanks for contributing to the script.

You are welcome.

Regards,
Csaba
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: passwd file corrupted

2005-10-06 Thread Gary W. Swearingen
"Efren Bravo" <[EMAIL PROTECTED]> writes:

> #vipw root  returns-> usage: vipw [-d directory]

See that "usage" msg?  Compare it with your commands.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Restoring Data from a DD image

2005-10-06 Thread Bill Schmitt (SW)
I've just replaced a hard disk that was dying fast. I've done a full 
installation of 4.9 (later releases won't install, which I've submitted 
a problem report on already). The old disk is connected but not mounted. 
Searching around, I found some suggestions to try to read the old disk 
to restore what I can and I used dd to copy what could be found (dd 
-if=/dev/ad0s1e of=/usr/olddsk/oldimag.dmg conv=noerror,sync) and it 
seems to have copied the file. Now, I'm a little stuck. Can someone help 
me understand how do I mount that image somewhere to browse it and copy 
what I can from it? If I'm not going about this the right way, I'd 
appreciate other suggestions



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Here's the proof.

2005-10-06 Thread Mike Hernandez
On 10/6/05, Bob Ababurko <[EMAIL PROTECTED]> wrote:
> What is this and where are the other mails to this thread?


Smells like classic trolling to me


Mike
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: IPFW logging and dynamic rules

2005-10-06 Thread Bob Johnson
On 10/5/05, jmulkerin <[EMAIL PROTECTED]> wrote:
> How about using snort and guardian.Guardian.pl will add a ipfw rule
> each time it sees an alert from Snort.  You'll need to adjust the snort
> rules for what you want to alert on but its a pretty safe and
> lightweight asset. (just my novice 2 cents...)
>

Thanks, I'll look at Guardian.  I had not planned to get that
sophisticated about it, but even if I don't use it on this system, I
have others where it may be just what I need.

- Bob
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Openoffice 1.1.5 compile failure

2005-10-06 Thread Robert K. Day
I'm trying to compile the latest version of OpenOffice from ports,
through portupgrade -Rra, but it fails. I'm using the options
WITHOUT_MOZILLA and WITHOUT_JAVA. Here's the part of the build that
fails:

-+ creating locale dependent resource bundles
mkdir -p ../../unxfbsd.pro/misc/registry/res/de/org/openoffice/
/usr/local/bin/xsltproc -o ../../unxfbsd.pro/misc/registry/res/de/org/openoffice
/Inet.properties \
--stringparam locale de \
../../util/resource.xsl org/openoffice/Inet.xcs
XPath error : Undefined variable
compilation error: file ../../util/resource.xsl line 87 element template
Failed to compile predicate
XPath error : Undefined variable
compilation error: file ../../util/resource.xsl line 87 element template
Failed to compile predicate
dmake:  Error code 5, while making '../../unxfbsd.pro/misc/registry/res/de/org/o
penoffice/Inet.properties'
---* TG_SLO.MK *---

ERROR: Error 65280 occurred while making /usr/ports/editors/openoffice.org-1.1/w
ork/OOo_1.1.5/officecfg/registry/schema
dmake:  Error code 1, while making 'build_all'
---* TG_SLO.MK *---
*** Error code 255

I'm not sure exactly what the error is, but it mentions Inet -
internet? Is this linked to the use of WITHOUT_MOZILLA?

Any help is appreciated,
Robert
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: IPFW logging and dynamic rules

2005-10-06 Thread Bob Johnson
On 10/5/05, Alex de Kruijff <[EMAIL PROTECTED]> wrote:
> On Thu, Sep 29, 2005 at 11:45:42AM -0400, Bob Johnson wrote:
> > In FreeBSD 5.4R, I tried an IPFW configuration that includes something
> > like this (plus a lot of other rules):
> >
> >check-state
> >deny tcp from any to any established
> >allow log tcp from any to ${my-ip} dst-port 22 setup limit src-addr 3
> > + other rules that use keep-state
[...]
> > Is there some way to get the first version to log only the initial
> > packet while still retaining the dynamic limit src-addr rule?
>
> Yes you could use count instead of allow.
>
> check-state
> count log tcp from any to ${my-ip} dst-port 22 limit src-addr 3
> allow tcp from any to ${my-ip} dst-port 22 setup limit src-addr 3
>

Thanks, I'll try that.  I had overlooked the count option when I was
reading the man pages.

>
> Howto's based on my ppersonal use, including information about
> setting up a firewall and creating traffic graphs with MRTG
> http://www.kruijff.org/alex/FreeBSD/
>

And I will look over your tutorial as well.  Thanks!

- Bob
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Here's the proof.

2005-10-06 Thread Bob Ababurko

Joshua Weaver wrote:

 [mailer daemon - original message truncated]

It appears you are right. I guess the Gates foundation does have a
controlling interest in FreeBSD. I wonder what direction Microsoft will take
when the complete the merger?

-Josh

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"



What is this and where are the other mails to this thread?
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: burning multisession cd's and bootable windows isos

2005-10-06 Thread Lowell Gilbert
"Dave" <[EMAIL PROTECTED]> writes:

> Thanks for your reply. I will give your crib sheet a go and if it
> is as good as it sounds i will like it! Do you have any other info
> along those lines, not necessarily on that subject but fast tips like
> that? If so i'd be interested.

The official FreeBSD documentation is excellent, and includes a
section (in the FreeBSD Handbook) on how to duplicate a CD-ROM.  

http://be-well.ilk.org/FreeBSD/doc/en_US.ISO8859-1/books/handbook/creating-cds.html#IMAGING-CD

My crib sheet was really only for my own use, so it assumes my shell.
csh-type shells would need slightly different syntax.

I have some other tricks of my own, on my web site at
 < http://be-well.ilk.org/~lowell/systuff/ >

> When you say grab all the tracks do you mean use dd when burning?

I did mean that.  But I'm not sure it's necessary; using the raw disk
device *should* get all of the data on the disk.

> Currently i use windows copy to get everything, i've got hidden files
> and os files turned on so i get all the files, i have never tried it

For a bootable CD, getting all of the files isn't enough.  Some of the
data you need isn't in a file on the CD filesystem.

> using unix for the copy, then hooking up to the share crossnetwork,
> doing the work, and then burning, do you know anyone who has done
> this, i'd like not to make a deaddisk if i can help it.

I recommend using CD-RW disks when experimenting, and then you don't
worry about wasting the burn.  Or just buy enough super-cheapie blanks
that you don't worry about wasting them.

Good luck.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: md device backing files on nfs mounts?

2005-10-06 Thread Lowell Gilbert
"Chad Leigh -- Shire.Net LLC" <[EMAIL PROTECTED]> writes:

> On Oct 6, 2005, at 10:51 AM, Lowell Gilbert wrote:
> 
> > "Chad Leigh -- Shire.Net LLC" <[EMAIL PROTECTED]> writes:
> >
> >
> >> Can the files that back an md device be resident on an nfs mount?
> >>
> >> I run some jails with each having its own root based on an md
> >> device.
> >> I am thinking of having a backend nfs server have all the  storage
> >> and
> >> serve it to various front end servers.  If one front end  server went
> >> down I could easily bring it up on another one.  Kind of  poor-man's
> >> redundancy
> >>
> >
> > How do you get the NFS mount before you have a root?
> 
> Just the jails would be on md devices on the nfs mounted  filesystem.
> Ie, main computer boots normally, mounts nfs  filesystem, then mounts
> md devices backed by files on the nfs  fielsystem

Yes, okay, that seems obvious now.  Maybe I need more caffeine.

I just tried it without the jails and was able to mount and use the
filesystem.  The permissions *are* a little tricky, because root is
(as usual) mapped to nobody on my NFS mounts, and needs write access
on the backing file.

I did the procedure from the last example in the mdconfig(8) manual,
and it worked just like on a local disk.  There might have been some
anomalies with the output of ls(1), but I can't reproduce those now.

You might want to try measuring performance if you implement this; it
could have some strange interactions with VM and buffering.

Clever idea, by the way.

> 
> Chad
> 
> > Also, I suspect the permissions might be a little tricky...
> >
> > Some kind of netbooting might work.

-- 
Lowell Gilbert, embedded/networking software engineer, Boston area
http://be-well.ilk.org/~lowell/
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: burning multisession cd's and bootable windows isos

2005-10-06 Thread Dave

Hi,
   Thanks for your reply. I will give your crib sheet a go and if it is as 
good as it sounds i will like it! Do you have any other info along those 
lines, not necessarily on that subject but fast tips like that? If so i'd be 
interested.
   When you say grab all the tracks do you mean use dd when burning? 
Currently i use windows copy to get everything, i've got hidden files and os 
files turned on so i get all the files, i have never tried it using unix for 
the copy, then hooking up to the share crossnetwork, doing the work, and 
then burning, do you know anyone who has done this, i'd like not to make a 
deaddisk if i can help it.

Thanks.
Dave.

- Original Message - 
From: "Lowell Gilbert" <[EMAIL PROTECTED]>

To: "Dave" <[EMAIL PROTECTED]>
Cc: 
Sent: Thursday, October 06, 2005 1:00 PM
Subject: Re: burning multisession cd's and bootable windows isos



"Dave" <[EMAIL PROTECTED]> writes:


Hello,
I've got two questions on burning cdr/cdrw disks. I'm using freebsd
5.4-p6 and using cdrtools for cdr/rw and dvd+rw-tools for dvdr/rw
burning.
My first question has to do with multisession disk burning, burn
some, take it out, go back later and write more to the disk until it's
full. I've not been able to make this work with either cd's or dvd's
and would appreciate a tutorial or howto on multisession burning.


From my crib sheet:

 for cdrecord:

 dv=/dev/acd0
 export CDR_DEVICE=1,0,0
 filenames=be-well.`date "+%y%m%d"`*

 # first session
 mkisofs -R $filenames |cdrecord -v 
driveropts=burnfree -multi -data -tao -


 #other sessions
 OFST=`cdrecord -msinfo`
 echo $OFST
 mkisofs -M $dv -C $OFST -R $filenames |cdrecord -v 
driveropts=burnfree -tao -multi -data -


Season to taste.



My second question regards burning a windows xp disk under
bsd. I've got one, a vanilla xp pro disk and i want to slipstream
it. I copy the files from the disk to my windows hard disk, slipstream
them with servicepack two plus some additional hardware drivers, now
i've got an xpsp2+drivers installation tree. I copy that over to a
network share, log on to my bsd machine, and i have no idea on how to
use mkisofs to make a bootable iso to burn to disk. I've tried just
making an iso of the installtree and burning that with cdrecord, made
some coasters that's about it. My goal is to have a bootable disk thag
acts just like the original vanilla xp disk, boots right in to the
install and so forth.


Have you tried just copying the filesystem image, instead of the
files?  [But make sure you get all of the tracks, if there are more
than one.]




___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Kris Kennaway
On Thu, Oct 06, 2005 at 12:10:58PM -0400, Ansar Mohammed wrote:
> I guess I am interested in finding out if there is support that is offered
> by the FreeBSD project, not from third party vendors.

Not commercial support, since FreeBSD isn't a commercial project.

Kris


pgpOutCgq3qeA.pgp
Description: PGP signature


Re: xine / kaffeine core dumps with bus error

2005-10-06 Thread Tijl Coosemans
On Wednesday 05 October 2005 01:45, Ian Moore wrote:
> On Wednesday 05 October 2005 00:44, Brian John wrote:
> > I think I'm having a similar problem with totem (which uses xine)
> > and vlc. Can you try installing /usr/ports/multimedia/vlc and see
> > what that does? If that gives a bus error as well then I think we
> > might have the same issue.  I haven't been able to find a solution
> > to this yet...
>
> Yep, vlc gives a bus error too. Looks like we have the same problem!

I don't know what the exact problem is, but the bus error occurs when 
loading "/usr/X11R6/lib/xine/plugins/1.1.0/xineplug_dmx_audio.so". When 
you remove that file or rename it such that there's no longer ".so" in 
the file name, then xine should work.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Jerry McAllister
> 
> I guess I am interested in finding out if there is support that is offered
> by the FreeBSD project, not from third party vendors.

Basically FreeBSD support is what you see on the web page.
In some sense, you could say that all of FreeBSD- development 
and support - is by third party sources or maybe that all third
party contributers are part of the FreeBSD project at some level.

In other words, development in FreeBSD land comes from those who
use it to provide services - of any kind including supporting
other's use of it for hire.

But, no, the FreeBSD project per se does not offer commercial support.

jerry

> 
> On 10/6/05, Kevin Kinsey <[EMAIL PROTECTED]> wrote:
> >
> > Ansar Mohammed wrote:
> >
> > >Does the FreeBSD project offer commercial support? I notice that the
> > FreeBSD
> > >mall offers commercial support.
> > >
> > >
> > >
> >
> > It's a fine question, but it's well documented on the Project's
> > web site:
> >
> > http://www.freebsd.org/support.html
> >
> > Kevin Kinsey
> >
> ___
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "[EMAIL PROTECTED]"
> 
> 

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


RE: Here's the proof.

2005-10-06 Thread Joshua Weaver
 [mailer daemon - original message truncated]

It appears you are right. I guess the Gates foundation does have a
controlling interest in FreeBSD. I wonder what direction Microsoft will take
when the complete the merger?

-Josh

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Foo JH
> FreeBSD offers non-commercial support through
> mailing-lists and doc-project (FAQs and Handbooks)
> which is probably the most comprehensive,
> active and effective support there is.
It's a blame game as much as it is a genuine need for commercial help. As
much as mailing lists and community support are strong and effective, that's
not the kind of comfort level that corporates are going for, especially if
they are betting their million-dollar product/ server on it.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


re: Enabling cgi scripts in apache

2005-10-06 Thread Garrett Cooper

On Oct 5, 2005, at 9:41 PM, Glenn Dawson wrote:



At 09:31 PM 10/5/2005, Garrett Cooper wrote:



Hi,
Just having problems again enabling cgi script execution in
apache. The script exists, it's the right set of permissions, and the
perl interpreter is reference correctly, as well as the following
line in the httpd.conf file:

AddHandler cgi-script .cgi




Without being able to see the config, the name of the script, the  
contents of the script,  or the directory it's in, the simple stuff  
comes to mind.


Does the AddHandler directive actually apply to the directory that  
contains the script?


Does the script end in .cgi ?

What shows up in your apache error log?

What error shows up in the browser when you try to browse to the  
script?


-Glenn



Ah, yes... should have explained more in that regard.
The server serves the file exacting as written and doesn't  
display the result that I want on the server (which is the script  
doing something for that matter).
All that I have really changed from the defaults is the  
AddHandler section, so Apache just doesn't know how to serve CGI  
files, although mod-cgi is loaded properly I think.
Just go to http://wongle.mine.nu for the script since it's a  
part of the main page.

-Garrett

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Hidden spot on hard drives?

2005-10-06 Thread Jerry McAllister
> 
> Norberto Meijome <[EMAIL PROTECTED]> writes:
> 
> > Where does HPA(Host protected Area) sit in all this? is this the
> > 'boot sector' trick?
> 
> I don't know.  I just heard that some computer makers are somehow
> reserving as much as half the HDD for a full copy of the OS to recover
> from when the normal one trips over itself.  I'm guessing that this has
> more to do with MSFT licensing terms than with saving a buck from not
> including a CDROM.  I wonder if there's some low-level way to tell a
> modern disk drive where you want "sector 0" to start.

Manufacturers put all sorts of stuff in areas on the disk that 
will not normally show up if you are booting an MS system.  But those
areas are just disk outside the current slice to FreeBSD.  An example
is Dell makes a bootable diagnostic section on its disks.   It will
only normally boot when you choose run diagnostics during boot.  But
if you create a "dual" booted machine with FreeBSD, then to FreeBSD it 
is just slice 1, XP is slice 2 and FreeBSd is slice 3.  The FreeBSD MBR
recognizes it and lists 1 - ???,  2 - DOS,  3 - FreeBSD at boot time.
If the "reserved" slice was not bootable, I don't think it would
mention it in the boot menu, but it would still be just plain disk
in another slice to FreeBSD. 

As others have mentioned, some have tried to make special drivers
that do funny things like half-stepping the heads or accessing
the replacement sector area.   But, the same type of software could
be written to access it and if FreeBSD were installed, it would ignore
that stuff unless some driver was created and installed to access it.
So, it wouldn't make much of a protection scheme.

As for moving sector 0, I don't know.  It would probably have to
be something in the controller, but???

jerry

> ___
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to "[EMAIL PROTECTED]"
> 

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: burning multisession cd's and bootable windows isos

2005-10-06 Thread Lowell Gilbert
"Dave" <[EMAIL PROTECTED]> writes:

> Hello,
> I've got two questions on burning cdr/cdrw disks. I'm using freebsd
> 5.4-p6 and using cdrtools for cdr/rw and dvd+rw-tools for dvdr/rw
> burning.
> My first question has to do with multisession disk burning, burn
> some, take it out, go back later and write more to the disk until it's
> full. I've not been able to make this work with either cd's or dvd's
> and would appreciate a tutorial or howto on multisession burning.

>From my crib sheet:

  for cdrecord: 

  dv=/dev/acd0
  export CDR_DEVICE=1,0,0
  filenames=be-well.`date "+%y%m%d"`*

  # first session
  mkisofs -R $filenames |cdrecord -v driveropts=burnfree -multi -data -tao -

  #other sessions
  OFST=`cdrecord -msinfo`
  echo $OFST
  mkisofs -M $dv -C $OFST -R $filenames |cdrecord -v driveropts=burnfree -tao 
-multi -data - 

Season to taste.


> My second question regards burning a windows xp disk under
> bsd. I've got one, a vanilla xp pro disk and i want to slipstream
> it. I copy the files from the disk to my windows hard disk, slipstream
> them with servicepack two plus some additional hardware drivers, now
> i've got an xpsp2+drivers installation tree. I copy that over to a
> network share, log on to my bsd machine, and i have no idea on how to
> use mkisofs to make a bootable iso to burn to disk. I've tried just
> making an iso of the installtree and burning that with cdrecord, made
> some coasters that's about it. My goal is to have a bootable disk thag
> acts just like the original vanilla xp disk, boots right in to the
> install and so forth.

Have you tried just copying the filesystem image, instead of the
files?  [But make sure you get all of the tracks, if there are more
than one.]


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: md device backing files on nfs mounts?

2005-10-06 Thread Chad Leigh -- Shire.Net LLC


On Oct 6, 2005, at 10:51 AM, Lowell Gilbert wrote:


"Chad Leigh -- Shire.Net LLC" <[EMAIL PROTECTED]> writes:



Can the files that back an md device be resident on an nfs mount?

I run some jails with each having its own root based on an md   
device.
I am thinking of having a backend nfs server have all the  storage  
and

serve it to various front end servers.  If one front end  server went
down I could easily bring it up on another one.  Kind of  poor-man's
redundancy



How do you get the NFS mount before you have a root?


Just the jails would be on md devices on the nfs mounted  
filesystem.   Ie, main computer boots normally, mounts nfs  
filesystem, then mounts  md devices backed by files on the nfs  
fielsystem


Chad


Also, I suspect the permissions might be a little tricky...

Some kind of netbooting might work.



---
Chad Leigh -- Shire.Net LLC
Your Web App and Email hosting provider
[EMAIL PROTECTED]


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Christian Kuhtz


Yeah, but also the most irrelevant when it comes to supply chain folk.

On Oct 6, 2005, at 12:45 PM, Andrew P. wrote:


On 10/6/05, Ansar Mohammed <[EMAIL PROTECTED]> wrote:

I guess I am interested in finding out if there is support that is  
offered

by the FreeBSD project, not from third party vendors.



FreeBSD offers non-commercial support through
mailing-lists and doc-project (FAQs and Handbooks)
which is probably the most comprehensive,
active and effective support there is.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions- 
[EMAIL PROTECTED]"




___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


burning multisession cd's and bootable windows isos

2005-10-06 Thread Dave

Hello,
I've got two questions on burning cdr/cdrw disks. I'm using freebsd 5.4-p6 
and using cdrtools for cdr/rw and dvd+rw-tools for dvdr/rw burning.
   My first question has to do with multisession disk burning, burn some, 
take it out, go back later and write more to the disk until it's full. I've 
not been able to make this work with either cd's or dvd's and would 
appreciate a tutorial or howto on multisession burning.
   My second question regards burning a windows xp disk under bsd. I've got 
one, a vanilla xp pro disk and i want to slipstream it. I copy the files 
from the disk to my windows hard disk, slipstream them with servicepack two 
plus some additional hardware drivers, now i've got an xpsp2+drivers 
installation tree. I copy that over to a network share, log on to my bsd 
machine, and i have no idea on how to use mkisofs to make a bootable iso to 
burn to disk. I've tried just making an iso of the installtree and burning 
that with cdrecord, made some coasters that's about it. My goal is to have a 
bootable disk thag acts just like the original vanilla xp disk, boots right 
in to the install and so forth.

   Any help appreciated.
Thanks.
Dave.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: md device backing files on nfs mounts?

2005-10-06 Thread Lowell Gilbert
"Chad Leigh -- Shire.Net LLC" <[EMAIL PROTECTED]> writes:

> Can the files that back an md device be resident on an nfs mount?
> 
> I run some jails with each having its own root based on an md  device.
> I am thinking of having a backend nfs server have all the  storage and
> serve it to various front end servers.  If one front end  server went
> down I could easily bring it up on another one.  Kind of  poor-man's
> redundancy

How do you get the NFS mount before you have a root?
Also, I suspect the permissions might be a little tricky...

Some kind of netbooting might work.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Andrew P.
On 10/6/05, Ansar Mohammed <[EMAIL PROTECTED]> wrote:
> I guess I am interested in finding out if there is support that is offered
> by the FreeBSD project, not from third party vendors.

FreeBSD offers non-commercial support through
mailing-lists and doc-project (FAQs and Handbooks)
which is probably the most comprehensive,
active and effective support there is.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Realtek High Definition Soundcard

2005-10-06 Thread Jakob Breivik Grimstveit
Berk Gulenler wrote on Thu, 06 Oct 2005 17:01:

> Is there any way to install Realtek high definition soundcard? I try the 
> open sound system program(lastest version). But it doesnt work.

What didn't work? It's impossible to help unless you provide more information
than this...

-- 
Jakob Breivik Grimstveit, , 48298152
Besøk Newsergalleriet: 

Experience varies directly with equipment ruined.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Hidden spot on hard drives?

2005-10-06 Thread Andrew P.
On 10/6/05, Gary W. Swearingen <[EMAIL PROTECTED]> wrote:
> Norberto Meijome <[EMAIL PROTECTED]> writes:
>
> > Where does HPA(Host protected Area) sit in all this? is this the
> > 'boot sector' trick?
>
> I don't know.  I just heard that some computer makers are somehow
> reserving as much as half the HDD for a full copy of the OS to recover
> from when the normal one trips over itself.

It's all on the BIOS/partitioning level anyway. FreeBSD
won't be too shy to look into both parts of the hard
drive. These "protection" measures are always more
or less security through obscurity. Which is somewhat
effective, but never long-lasting.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Abit AW8 / Pentium D and 3ware raid cards compatibility

2005-10-06 Thread Gerald de la Pascua
I posted a few weeks back regarding problems making the aw8 board,
work with a 3ware card 7006-2,
 the system wouldn't boot at all,
 after much discussion with 3ware they said, sorry nothing we can do,
cannot offer an alternative suggested card, so I was about to change the
mother board, infact 3ware were unaware of any motherboard which worked
with their cards, which also worked with a pentiumD chip, which to be honest
I wasn't very impressed with since pentiumD isn't that exotic technology.
 however ABIT have now issued 1.3 bios for the motherboard, (I had looked on

the site an installed 1.2 already ), With this it works fine,
 the only issue I had were some acpi errors, so I disabled acpi,
since it is a server this doesn't seem to be too much of an issue to me,
 the machine seems to run significantly faster than the old
pentium2.8single core,
it is difficult to asses the value for money of the machine, although the
pentiumD
is a similar price to the normal pentiums, the mother boards are
significantly more
expensive, however if you just want good performance and you don't mind
spending
a hundred pounds or so more, I would say its definitely worth it,
 I hope this is of some help to other users, if you would like clarification
on anything,
I am happy to give more info,
 kind regards,
 Gerald
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Ansar Mohammed
I guess I am interested in finding out if there is support that is offered
by the FreeBSD project, not from third party vendors.

On 10/6/05, Kevin Kinsey <[EMAIL PROTECTED]> wrote:
>
> Ansar Mohammed wrote:
>
> >Does the FreeBSD project offer commercial support? I notice that the
> FreeBSD
> >mall offers commercial support.
> >
> >
> >
>
> It's a fine question, but it's well documented on the Project's
> web site:
>
> http://www.freebsd.org/support.html
>
> Kevin Kinsey
>
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Hidden spot on hard drives?

2005-10-06 Thread Gary W. Swearingen
Norberto Meijome <[EMAIL PROTECTED]> writes:

> Where does HPA(Host protected Area) sit in all this? is this the
> 'boot sector' trick?

I don't know.  I just heard that some computer makers are somehow
reserving as much as half the HDD for a full copy of the OS to recover
from when the normal one trips over itself.  I'm guessing that this has
more to do with MSFT licensing terms than with saving a buck from not
including a CDROM.  I wonder if there's some low-level way to tell a
modern disk drive where you want "sector 0" to start.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Setting mount_nfs options in /etc/fstab

2005-10-06 Thread Doug Poland
On Thu, Oct 06, 2005 at 03:45:32PM +0100, Brian Candler wrote:
> I am reading large log files via NFS, and I find that if I mount them
> with mount_nfs -a 4 then performance is improved.
> 
> My question is: is there any way to set the option '-a 4' in
> /etc/fstab? Or am I forced to mount the filesystems the manual way in
> /etc/rc.local?
> 
> mount_nfs supports a number of options via -o, many of which it
> describes as "historic" and "deprecated", but they don't include
> something to set readahead as far as I can see.
> 
Here's an fstab entry of mine for an nfs mount.

fs:/data/data   nfs -3,-R=3,-b,-i,-s,-r=32768,-w=32768,rw   
0   0

Your options and milage may vary...

-- 
Regards,
Doug
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Nessus no longer open source

2005-10-06 Thread Kirk Strauser
On Thursday 06 October 2005 11:04, Gayn Winters wrote:

> [...] under the GPL the AUTHOR of the code is not bound by the same
> restrictions that the users are. 

I don't think that's completely true.  The author has copyright over the 
work that they themselves wrote, but it's my understanding that outside 
contributors retain copyright to the portions they wrote unless they 
explicitly sign control over to the authors.

In other words, Nessus would be completely free to remove contributed 
patches, or re-write them internally, but I don't think they're legally 
able to close-source any code they didn't write.

Much ado was made at one point about some scammer or another offering to 
"buy" Linux.  The general concensus is that this would be legally 
impossible without the permission of everyone who'd ever submitted a patch, 
unless those patches were removed.
-- 
Kirk Strauser
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: FreeBSD Support (Commerical)

2005-10-06 Thread Kevin Kinsey

Ansar Mohammed wrote:


Does the FreeBSD project offer commercial support? I notice that the FreeBSD
mall offers commercial support.

 



It's a fine question, but it's well documented on the Project's
web site:

http://www.freebsd.org/support.html

Kevin Kinsey
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: passwd file corrupted

2005-10-06 Thread Norberto Meijome

Efren Bravo wrote:

On Thu, Oct 06, 2005 at 10:31:32AM -0500, Efren Bravo wrote:


How can I check /etc/passwd file integrity because I think it is
corrupted. When I try to execute vipw efrenba or root it doesn't works.




Can you explain how vipw 'doesn't work'? What does it say? Is your
$EDITOR variable set correctly?



#vipw root  returns-> usage: vipw [-d directory]
and ...
#vipw -d /etc root  returns the same
and ...
#vipw root -d /etc  the same

#echo $EDITOR
vi


how about just 'vipw' ?
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Nessus no longer open source

2005-10-06 Thread Gayn Winters
One of the highest rated open source security programs, nessus, will no
longer be open source.  Quoting from an email from Renaud Deraison
<[EMAIL PROTECTED]> to [EMAIL PROTECTED],

"Nessus 3 will be available free of charge, including on the Windows  
platform, but will not be released under the GPL.

"Nessus 3 will be available for many platforms, but do understand that  
we won't be able to support every distribution / operating system  
available. I also understand that some free software advocates won't  
want to use a binary-only Nessus 3. This is why Nessus 2 will  
continue to be maintained and will stay under the GPL."

I'm not sure if Nessus 3 will be supported as a FreeBSD package.

Apparently the folks at Tenable feel that they have been supporting the
open source community but have been getting little back in plug-ins and
vulnerabilities and virtually nothing back on the scanning engine for
over six years. In fact, they have been slowly tightening their
licensing (cf.
http://mail.nessus.org/pipermail/nessus/2005-January/msg00185.html), and
it would appear that they can and will continue to tighten it over time.

Fyodor's analysis
(http://seclists.org/lists/nmap-hackers/2005/Oct-Dec/.html) is that
the open source community should take heed.  He provides a list of ways
to contribute to open source software projects.  While the list is
excellent, there are no new ideas in it.  The thing that seems germane
to the FreeBSD community is that ports, even extremely popular ones, are
vulnerable, since under the GPL the AUTHOR of the code is not bound by
the same restrictions that the users are.  I'm not a lawyer, but as I
understand it, the author can create a derived work of something under
the GPL and license the derived work (a "rewrite" in the case of nessus
3) and arbitrarily restrict it.  Given Renaud's claim that no one
contributed to the scanning engine, he seems to have every right to
create a new and closed version of it.

The moral here, if there is one, is that if you really like a port, then
you should contribute to it one way or another!

Comments?

-gayn
 


___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: twa kernel panic under heavy load

2005-10-06 Thread Dan Rue
On Wed, Oct 05, 2005 at 09:27:53AM -0400, Lowell Gilbert wrote:
> Dan Rue <[EMAIL PROTECTED]> writes:
> 
> > Greetings,
> > 
> > I am running a 3ware 9500 SATA raid card in a 12x300GB raid 50
> > configuration.  Too often, I am seeing reboots during high I/O (rsync)
> > operations.  
> > 
> > [EMAIL PROTECTED]:~$ uname -a
> > FreeBSD leopard.claimlynx.com 5.4-SECURITY FreeBSD 5.4-SECURITY #0: Thu
> > Jun 30 02:25:52 UTC 2005
> > [EMAIL PROTECTED]:/usr/obj/usr/src/sys/GENERIC  i386
> > 
> > Here is dmesg identifying the controller: 
> > 3ware device driver for 9000 series storage controllers, version: 
> > 2.50.02.012
> > twa0: <3ware 9000 series Storage Controller> port 0xb800-0xb8ff mem 
> > 0xfb80-0xfbff,0xfc5ffc00-0xfc5ffcff irq 24 at device 2.0 on pci2
> > twa0: 12 ports, Firmware FE9X 2.06.00.009, BIOS BE9X 2.03.01.051
> > 
> > 
> > Is this somethign that has been worked on in 5-STABLE or 6?  Would
> > a kernel dump be helpful?  Please aim me at the appropriate list or
> > people that would know.
> 
> The driver was imported from 3ware's own code on their website, and a
> new version was imported since the 5.4 release was branched.  Your
> problem may or may not have been fixed, but debugging it on the old
> code base is definitely not worth anyone's time.
> 
> Definitely upgrade and see what happens.

I upgraded to 5-STABLE yesterday.  Last night, while running rsync, the
machine rebooted on me again..

>From /var/log/messages: 
Oct  5 23:08:41 leopard kernel: ected status bit(s): status reg = 0x15025f32; 
Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected 
status bit(s): status reg = 0x15025f32; Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard last message repeated 7 times
Oct  5 23:08:41 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected 
status bit(s): status reg =ected status bit(s): status reg = 0x15025f32; 
Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected 
status bit(s): status reg = 0x15025f32; Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard last message repeated 106 times
Oct  5 23:08:41 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missected status 
bit(s): status reg = 0x15025f32; Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected 
status bit(s): status reg = 0x15025f32; Missing bits: [MC_RDY,]
Oct  5 23:08:41 leopard last message repeated 296 times
Oct  5 23:09:42 leopard kernel: twa0: ERROR: (0x05: 0x210b): Request timed 
out!:request = 0xc2425600
Oct  5 23:09:42 leopard kernel: twa0: INFO: (0x16: 0x1108): Resetting 
controller...:  
Oct  5 23:09:42 leopard kernel: twa0: INFO: (0x04: 0x005e): Cache synchronized 
after power fail: unit=0
Oct  5 23:09:42 leopard kernel: twa0: INFO: (0x04: 0x0001): Controller reset 
occurred: resets=1
Oct  5 23:09:42 leopard kernel: twa0: INFO: (0x16: 0x1107): Controller reset 
done!:  
Oct  5 23:12:59 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected st
atus bit(s): status reg = 0x15025d50; Missing bits: [MC_RDY,]
Oct  5 23:13:00 leopard last message repeated 379 times
Oct  5 23:13:00 leopard kernel: twa0: ERROR: (0x16: 0x1301): Missing expected 
status bit(s): status reg = 0x15025d52; Missing bits: [MC_RDY,]
Oct  5 23:46:31 leopard syslogd: kernel boot file is /boot/kernel/kernel

Please let me know who I may contact to get this debugged.
Thanks, 
Dan
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


FreeBSD Support (Commerical)

2005-10-06 Thread Ansar Mohammed
Does the FreeBSD project offer commercial support? I notice that the FreeBSD
mall offers commercial support.
 
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Fwd: cvsup upgrade from 4.7 to 5.4

2005-10-06 Thread Gobbledegeek
See below
Ps: I joined the list only for this answer...

-- Forwarded message --
From: Gobbledegeek <[EMAIL PROTECTED]>
Date: Oct 6, 2005 9:02 PM
Subject: Re: cvsup upgrade from 4.7 to 5.4
To: Chuck Swiger <[EMAIL PROTECTED]>


There isn't a a category to refuse under src-* for s390,sparc,amd64, ppc
etc... hence the question. I'm still on dial-up in this age hence the
need

Rgrds

On 10/6/05, Chuck Swiger <[EMAIL PROTECTED]> wrote:
> Gobbledegeek wrote:
> >   I'm upgrading from 4.7 to 5.4 using cvsup and I see that with
> > src-all, files specific to s390, sparc, ppc are also being downloaded.
> > How can I prevent this from happening? I only want to download i386
> > files...
>
> You've already asked this question.  This isn't a problem that you ought to 
> try
> to solve, because the size of architecture-specific files is tiny, but if you
> are determined, read the section of "man cvsup" about "REFUSE FILES".
>
> --
> -Chuck
>
>


--
Nonchalantly yours
GobbledeGeek
[Every thing but Gobbledegook.. !!]


--
Nonchalantly yours
GobbledeGeek
[Every thing but Gobbledegook.. !!]
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: sendmail/postfix ports question

2005-10-06 Thread David Kelly
On Thu, Oct 06, 2005 at 11:16:50AM -0400, Matt Singerman wrote:
> Hello all,
> 
> I have a server running FreeBSD 5.2.1 that provides (amongst other
> things) MTA services to our office via sendmail.  For a variety of a
> reasons, I would like to move away from sendmail to postfix.  However,
> the postfix package cannot, as I am sure you know, simply install with
> sendmail on the system, since they install files to the same places.  I
> am assuming that I have to delete the sendmail package off the system
> before I can install postfix (someone please correct me if this
> assumption is wrong).  My question is, is there a way to safely and
> accurately save my sendmail configuration in the event that postfix
> simply does not work out?  I would really prefer not to have to face a
> situation where I am left high and dry with no MTA working :)

Install postfix from ports. It does NOT install files to the same place
as sendmail with the optional exception of /etc/mail/mail.conf which
provides redirects to the postfix versions.

Also read what postfix says during installation. Needs a bit of info
added to /etc/rc.conf.

Add "NO_SENDMAIL=1" (just define it) to /etc/make.conf and a "make
buildworld" will not build sendmail. Not certain how to surely remove
sendmail once its installed.

-- 
David Kelly N4HHE, [EMAIL PROTECTED]

Whom computers would destroy, they must first drive mad.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Which MySQL version best to use and with/without linux threads?

2005-10-06 Thread Peter Giessel
On Thursday, October 06, 2005, at 07:22AM, Greg 'groggy' Lehey <[EMAIL 
PROTECTED]> wrote:
>> *** MySQL Log 4.1.14 ***
>> 051002 17:41:47   1 Connect Access denied for user 
>> 'abbc'@'localhost' (using password: YES)
>
>This is the same authentication problem seen from the other side.
>
>> 051002 17:42:08   2 Connect [EMAIL PROTECTED] on
>
>And this
>> *** End Log Snipet ***
>>
>> *** MySQL Log after downgrading (4.0.26) ***
>> 051003  8:53:56   5 Connect [EMAIL PROTECTED] on aukebay
>
>And this is the next day.  It looks as if it worked.

Yes, it worked after the downgrade was complete, but the 051002 17:42:08 
connection
was the same day, the same time frame (21 seconds later).  It worked from the
command line, but not from Dovecot.

>> *** End Log Snipet ***
>>
>> The 17:42:08 connection is when I:
>> # mysql -u abbc -p
>> logged in from the command line using the password in the dovecot config 
>> file.
>>
>> I didn't touch the dovecot config file after downgrading, and I used the same
>> .sql file to populate the database with both version of MySQL, so the 
>> password
>> was unchanged.
>
>So you're saying that the authentication problem was despite proven
>good user name and password?

Yes.  That is exactly what I'm saying.

>It's not clear that there was anything wrong on the morning of 3
>October.  Did you give up or continue?

I deinstalled 4.1.14 later on the 2nd and started recompiling 4.0.26.
I finished installing and fixing downgrade issues on the 3rd, at which
time dovecot connected successfully.

>There have been some changes to authentication (in particular,
>password hashing) between 4.0 and 4.1.  It's possible that you need to
>do something to your Dovecot configuration, but unfortunately I don't
>know Dovecot at all.

I'm not saying anything is wrong with 4.1, I was just trying to point
out that there *may* in some cases be compatibility issues with 4.1.

It doesn't *always* play nice with others, as the OP claimed, and as
you say, its probably a dovecot issue, but downgrading solved it
nicely.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


vsftpd watch problem

2005-10-06 Thread Yuan Jue
Hi all

Here is a pragmatic problem. I used vsftpd to setup a ftp server. And as a 
result, some guys start to download something from my ftp server. I do want 
to know the downloader's IP and the speed he/she download from me, just as a 
status-watching for my notebook. 

Can anyone give me some clue how to do this stuff? Using vsftpd itself or 
using some freebsd utilities are both acceptable. I appreciate any 
suggestions. 

-- 
Best Regards.

Yuan Jue
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


dump/restore puzzle

2005-10-06 Thread Freminlins
I have a puzzling problem with dump and restore. I'm looking to implement a
dump and restore pipe to automatically make copy of a file system onto
another system completely. I've used / only as an example (because it's
small) and I'm not overwriting /.

I do the following:
1. Level 0 dump and restore pipe which works as expected

frem# dump 0auLf - / | ( restore -rf - )
DUMP: Date of this level 0 dump: Thu Oct 6 16:16:17 2005
DUMP: Date of last level 0 dump: the epoch
DUMP: Dumping snapshot of /dev/ad0s1a (/) to standard output
DUMP: mapping (Pass I) [regular files]
DUMP: mapping (Pass II) [directories]
DUMP: estimated 54582 tape blocks.
DUMP: dumping (Pass III) [directories]
DUMP: dumping (Pass IV) [regular files]
expected next file 8069, got 818
DUMP: DUMP: 55429 tape blocks
DUMP: finished in 19 seconds, throughput 2917 KBytes/sec
DUMP: level 0 dump on Thu Oct 6 16:16:17 2005
DUMP: DUMP IS DONE


2. I touch a file, just to make a difference, then do a level 1 dump and
restore which works as expected (the new file is extracted).

frem# touch /hello
frem# dump 1auLf - / | ( restore -rf - )
DUMP: Date of this level 1 dump: Thu Oct 6 16:16:50 2005
DUMP: Date of last level 0 dump: Thu Oct 6 16:16:17 2005
DUMP: Dumping snapshot of /dev/ad0s1a (/) to standard output
DUMP: mapping (Pass I) [regular files]
DUMP: mapping (Pass II) [directories]
DUMP: estimated 36 tape blocks.
DUMP: dumping (Pass III) [directories]
DUMP: dumping (Pass IV) [regular files]
DUMP: DUMP: 35 tape blocks
DUMP: finished in less than a second
DUMP: level 1 dump on Thu Oct 6 16:16:50 2005
DUMP: DUMP IS DONE
expected next file 24550, got 819

3. I remove the file and do another level 1 dump and restore. This doesn't
work.

frem# rm /hello
frem# dump 1auLf - / | ( restore -rf - )
DUMP: Date of this level 1 dump: Thu Oct 6 16:17:08 2005
DUMP: Date of last level 0 dump: Thu Oct 6 16:16:17 2005
DUMP: Dumping snapshot of /dev/ad0s1a (/) to standard output
DUMP: mapping (Pass I) [regular files]
DUMP: mapping (Pass II) [directories]
DUMP: estimated 35 tape blocks.
DUMP: dumping (Pass III) [directories]
DUMP: dumping (Pass IV) [regular files]
DUMP: DUMP: 34 tape blocks
DUMP: finished in less than a second
DUMP: level 1 dump on Thu Oct 6 16:17:08 2005
DUMP: DUMP IS DONE
Incremental tape too high

4. If I then touch another file, this still doesn't work.

frem# touch /hello2
frem# dump 1auLf - / | ( restore -rf - )
DUMP: Date of this level 1 dump: Thu Oct 6 16:24:51 2005
DUMP: Date of last level 0 dump: Thu Oct 6 16:23:50 2005
DUMP: Dumping snapshot of /dev/ad0s1a (/) to standard output
DUMP: mapping (Pass I) [regular files]
DUMP: mapping (Pass II) [directories]
DUMP: estimated 37 tape blocks.
DUMP: dumping (Pass III) [directories]
DUMP: dumping (Pass IV) [regular files]
DUMP: DUMP: 36 tape blocks
DUMP: finished in less than a second
DUMP: level 1 dump on Thu Oct 6 16:24:51 2005
DUMP: DUMP IS DONE
Incremental tape too high


How can I go about achieving this (ignoring rsync, etc),

Thanks,
Frem.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: correct syntax for openssl 0.9.8 in port

2005-10-06 Thread Alistair Sutton
On 30/07/05, J.D. Bronson <[EMAIL PROTECTED]> wrote:
> At 12:57 PM 7/30/2005, Kris Kennaway wrote:
> >On Sat, Jul 30, 2005 at 12:46:37PM -0500, J.D. Bronson wrote:
> > > I update my port tree on 5.4 to the latest and I am trying to figure
> > > out what steps I need to build openssl 0.9.8 in 
> > > /usr/ports/security/openssl
> > > and end up overwriting any base files.
> > >
> > > This question comes up often, perhaps a comment can be put into the
> > > makefile?
> > >
> > > I have tried all the ideas on the archives and either it wont build
> > > or it keeps trying to build 0.9.7g !!!
> > >
> > > *ANY* advice will be greatly appreciated.
> > >
> > > I am able to compile the src code cleanly, but that install will
> > > place files in their own spot and obviously not overwrite base files.
> >
> >Read the makefile for the appropriate variables to set.
> >
> >Kris
>
> This is obviously my issue. I cannot figure out what variables to set.
> What I think it should be, it whines about.
>
> Can someone at least POST what we should use so this will at least be
> in the archives once and for all?

To get the openssl port to overwrite the base files built by the
system you need to put

OPENSSL_OVERWRITE_BASE=yes

into /etc/make.conf

If you then don't want the system to rebuilt openssl you'll need to have

NO_OPENSSL=yes

in /etc/make.conf as well otherwise each time you update your world it
will overwrite the files installed by the port.

It might be easier just to have

WITH_OPENSSL_PORT=yes

in /etc make.conf so that software will always try to build with the
openssl from the port. Even though the system will rebuild openssl
each time you update your world, nothing outside of the base system
should try and use those libraries.

It might be an idea to read

/usr/share/examples/etc/make.conf

to get a full list of what the various options are and what they can do.

HTH,

Al
--
GPG/PGP: http://www.no-dns-yet.org.uk/~everlone/pubkey.gpg
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: Setting mount_nfs options in /etc/fstab

2005-10-06 Thread Brian Candler
On Thu, Oct 06, 2005 at 10:10:14AM -0500, Doug Poland wrote:
> Here's an fstab entry of mine for an nfs mount.
> 
> fs:/data  /data   nfs -3,-R=3,-b,-i,-s,-r=32768,-w=32768,rw   
> 0   0
> 
> Your options and milage may vary...

That works for me, thank you. Perhaps the fstab(5) page could be clearer
then. It says:

 The fourth field, (fs_mntops), describes the mount options associated
 with the file system.  It is formatted as a comma separated list of
 options.  It contains at least the type of mount (see fs_type below) plus
 any additional options appropriate to the file system type.  See the
 options flag (-o) in the mount(8) page and the file system specific page,
 such as mount_nfs(8), for additional options that may be specified.

and also later:

 struct fstab {
 char*fs_spec;   /* block special device name */
 char*fs_file;   /* file system path prefix */
 char*fs_vfstype;/* File system type, ufs, nfs */
 char*fs_mntops; /* Mount options ala -o */ <<<
 char*fs_type;   /* FSTAB_* from fs_mntops */
 int fs_freq;/* dump frequency, in days */
 int fs_passno;  /* pass number on parallel fsck */
 };

When I read this, the implication to me was that only options which you
could pass using -o to mount or mount_nfs were permitted.

Cheers,

Brian.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


sendmail/postfix ports question

2005-10-06 Thread Matt Singerman
Hello all,

I have a server running FreeBSD 5.2.1 that provides (amongst other
things) MTA services to our office via sendmail.  For a variety of a
reasons, I would like to move away from sendmail to postfix.  However,
the postfix package cannot, as I am sure you know, simply install with
sendmail on the system, since they install files to the same places.  I
am assuming that I have to delete the sendmail package off the system
before I can install postfix (someone please correct me if this
assumption is wrong).  My question is, is there a way to safely and
accurately save my sendmail configuration in the event that postfix
simply does not work out?  I would really prefer not to have to face a
situation where I am left high and dry with no MTA working :)

Thanks,

Matt
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


Re: passwd file corrupted, solved, sorry

2005-10-06 Thread Efren Bravo
On Thu, Oct 06, 2005 at 10:31:32AM -0500, Efren Bravo wrote:
> How can I check /etc/passwd file integrity because I think it is
> corrupted. When I try to execute vipw efrenba or root it doesn't works.

>Can you explain how vipw 'doesn't work'? What does it say? Is your
>$EDITOR variable set correctly?

>#vipw root  returns-> usage: vipw [-d directory]
>and ...
>#vipw -d /etc root  returns the same
>and ...
>#vipw root -d /etc  the same
>
>#echo $EDITOR
>vi

Sorry, I was confused, I referred to the pw instead of vipw...  
  
I already solved the problem


Thanks



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


  1   2   >