Re: ftp.openbsd.org currently unreachable

2023-06-20 Thread Peter N. M. Hansteen
On Tue, Jun 20, 2023 at 05:30:20PM -0400, Alex Gaynor wrote:
> 
> I'm writing to provide a heads up that ftp.openbsd.org appears to
> currently be unreachable.

It looks to be back now, so it was likely a temporary problem somewhere
along the likely multi-hop way.

That said, unless you are running a mirror, the general recommendation
is to find a mirror reasonably close to you network-wise (which may
rougly correspond to geographical positions) and stick to those. 

The sites listed at https://www.openbsd.org/ftp.html are synced often
enough that you probably won't miss out on much for long.

- Peter

PS cross-posting to several OpenBSD mailing lists is generally frowned upon.

-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
https://bsdly.blogspot.com/ https://www.bsdly.net/ https://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.



Re: Which hardware for a firewall?

2023-06-20 Thread Stuart Henderson
On 2023-06-20, Nick Holland  wrote:
> On 6/20/23 13:13, Karel Lucas wrote:
>> 
>> Hi all,
>> 
>> I'm going to create a firewall with openBSD, and would like to use the
>> ARM64 or ARMv7 distribution for that. Unfortunately I don't know what
>> hardware I can get for this, and that's the reason for this mail. Can
>> someone point me to a suitable platform for this? If this email does not
>> belong on this mailing list, I offer my apology. This is my first post
>> on this mailing list, and ask for understanding. Sincerely, Karel.

R5S is probably most likely to fit the bill.

armv7 is probably too slow to be of all that much interest.

Be aware that OpenBSD is a bit less polished on arm platforms.
Most are at least a bit more awkward than most amd64.

> Fortunately, since there's only one speed connection, a set number of
> devices doing a fixed number of things in each location, we will have no
> problem advising you on the best choice for your application...
>
> oh, wait... :)
>
> Well, here's the HW compatibility for those platforms:
> https://www.openbsd.org/arm64.html
> https://www.openbsd.org/armv7.html

There's only partial detail of what works on the various boards, and
some need fiddling with boot loaders/device trees.




Re: (fwd) [FD] OpenBSD kernel relinking is not transactional and a local exploit exists

2023-06-20 Thread Tomasz Rola
On Mon, Jun 19, 2023 at 05:34:12PM -0600, Theo de Raadt wrote:
> That writeup is bullshit.

Ok, I see.

-- 
Regards,
Tomasz Rola

--
** A C programmer asked whether computer had Buddha's nature.  **
** As the answer, master did "rm -rif" on the programmer's home**
** directory. And then the C programmer became enlightened...  **
** **
** Tomasz Rola  mailto:tomasz_r...@bigfoot.com **



Re: Which hardware for a firewall?

2023-06-20 Thread Nick Holland

On 6/20/23 13:13, Karel Lucas wrote:


Hi all,

I'm going to create a firewall with openBSD, and would like to use the
ARM64 or ARMv7 distribution for that. Unfortunately I don't know what
hardware I can get for this, and that's the reason for this mail. Can
someone point me to a suitable platform for this? If this email does not
belong on this mailing list, I offer my apology. This is my first post
on this mailing list, and ask for understanding. Sincerely, Karel.



Fortunately, since there's only one speed connection, a set number of
devices doing a fixed number of things in each location, we will have no
problem advising you on the best choice for your application...

oh, wait... :)

Well, here's the HW compatibility for those platforms:
https://www.openbsd.org/arm64.html
https://www.openbsd.org/armv7.html

You will have to decide what fits your needs.

Honestly, though, I'd suggest just recycling an old PC and a surplus
network card (or multi-port card, depending on how people toss stuff
out around you).  If you want "the best choice", this is probably it.

Nick.



Which hardware for a firewall?

2023-06-20 Thread Karel Lucas



Hi all,

I'm going to create a firewall with openBSD, and would like to use the 
ARM64 or ARMv7 distribution for that. Unfortunately I don't know what 
hardware I can get for this, and that's the reason for this mail. Can 
someone point me to a suitable platform for this? If this email does not 
belong on this mailing list, I offer my apology. This is my first post 
on this mailing list, and ask for understanding. Sincerely, Karel.




Re: Wrong SHA256 sums for latest snapshot

2023-06-20 Thread Nick Holland

On 6/19/23 14:38, Benjamin Stürz wrote:

Hi misc@,

I have issues installing the latest snapshot from cdn.openbsd.org.


Snapshots change frequently.  They take time to distribute around
the world.  Content Delivery Networks pull from lots of different
sources and cache various things at various times.

Kinda easy to see how things like this not only happen, but are
kinda expected.

For snapshots, you might want to pick a favorite local mirror and
use that.  I doubt you will see a huge difference in performance
for an install or upgrade.

Nick.