Re: Why regen for host ssh key is fail first time?

2015-01-17 Thread dmitry.sensei
By Changlog the ssh-keygen -A issue was fixed 18.01.2015 6:50 пользователь "Theo de Raadt" написал: > > > I reproduced the error, it happens the same to me, but it actually > > > generates the keys, but you get that error. I did a trace. I'm rather > > > new in OpenBSD, looks l

Re: Why regen for host ssh key if fail first time?

2015-01-17 Thread Theo de Raadt
> > I reproduced the error, it happens the same to me, but it actually > > generates the keys, but you get that error. I did a trace. I'm rather > > new in OpenBSD, looks like it could be related with mprotect(2), but > > not sure. Maybe you should submit the bug > > Actually it was 'silently' fix

Re: OpenBSD 5.5 ISAKMPD

2015-01-17 Thread Boris Goldberg
Hello Motty, Friday, January 16, 2015, 5:24:33 PM, you wrote: MC> is actually OpenBSD 4.8 not OpenBSD 5.5, I apologize for the mistake. >>> I'm trying to setup IPSec Tunnel using the following parameters. >>> Phase 1 >>> exchange encryption: AES256 >>> Data Integrity: SHA256 >>> DH: group 20 >>>

Re: Report of an NSA Employee about a Backdoor in the OpenSSH Daemon [pdf] (spiegel.de)

2015-01-17 Thread Stefan Sperling
On Sat, Jan 17, 2015 at 10:59:19PM +0100, Daniel Cegiełka wrote: > http://www.spiegel.de/media/media-35663.pdf > > "PANT SPARTY is a backdoor in the SSH daemon for *NIX, based on > OpenSSH portable" They are not talking about the official OpenSSH code. To save everyone a bit of time (and hassle

Re: Clarification on patching 5.5-release...

2015-01-17 Thread Daniel Dickman
Hi Andrew, On Sat, Jan 17, 2015 at 4:13 PM, Andrew Lester wrote: > Hello misc, > > I've got some simple questions on the patch process which I couldn't find > answers to on > my own. Currently I am running 5.5-RELEASE, and sitting on my 5.6 disc set > waiting to > upgrade. I want to make sure I

Report of an NSA Employee about a Backdoor in the OpenSSH Daemon [pdf] (spiegel.de)

2015-01-17 Thread Daniel Cegiełka
http://www.spiegel.de/media/media-35663.pdf "PANT SPARTY is a backdoor in the SSH daemon for *NIX, based on OpenSSH portable" +local copy (pdf). Daniel [demime 1.01d removed an attachment of type application/pdf which had a name of media-35663.pdf]

Re: Why regen for host ssh key if fail first time?

2015-01-17 Thread Daniel Jakots
On Sat, 17 Jan 2015 21:36:09 +, Oriol Demaria wrote: > I reproduced the error, it happens the same to me, but it actually > generates the keys, but you get that error. I did a trace. I'm rather > new in OpenBSD, looks like it could be related with mprotect(2), but > not sure. Maybe you should

Re: Why regen for host ssh key if fail first time?

2015-01-17 Thread Oriol Demaria
The 16/01/2015 17:30, Dmitry Orlov wrote: > Hi :) > > In last snapshot (ISO). All ssh* configs are default > > OpenBSD 5.7-beta (GENERIC) #731: Fri Jan 16 01:37:07 MST 2015 > > Welcome to OpenBSD: The proactively secure Unix-like operating system. > > Please use the sendbug(1) utility to report

good router/firewall sbc?

2015-01-17 Thread Christopher Barry
Greetings, Looking for recommendations for a good small device with the following: * 4GbE interfaces * external USB * external serial port * can run obsd well I've checked out the Soekris stuff, but wondering what else people use and like. -- Regards, -C

Clarification on patching 5.5-release...

2015-01-17 Thread Andrew Lester
Hello misc, I've got some simple questions on the patch process which I couldn't find answers to on my own. Currently I am running 5.5-RELEASE, and sitting on my 5.6 disc set waiting to upgrade. I want to make sure I've been patching my 5.5 system correctly first, though. :) 1) Can patches be