Re: Search OpenBSD mailing list archives?

2018-12-12 Thread ivpgbe
Marc.info On Wed, Dec 12, 2018, at 5:56 PM, Paul Swanson wrote: > Hi, > > Is there a facility for searching the mailing list archives? > > I can't seem to find one. > > Cheers, > > Paul Swanson

Search OpenBSD mailing list archives?

2018-12-12 Thread Paul Swanson
Hi, Is there a facility for searching the mailing list archives? I can't seem to find one. Cheers, Paul Swanson

Re: vmm(4) update EPT to match mprotect in intial elf load. (Solo5 using vmm, doesn't involved vmd)

2018-12-12 Thread Mike Larkin
On Thu, Dec 13, 2018 at 12:41:10AM +, Adam Steen wrote: > Hi All > > The Solo5/Mirage tender is in the process of enforcing that guest executable > code is not also writable (W^X), but it looks like vmm is not updating EPT > to match the prot from mprotect(). > > further information >

vmm(4) update EPT to match mprotect in intial elf load. (Solo5 using vmm, doesn't involved vmd)

2018-12-12 Thread Adam Steen
Hi All The Solo5/Mirage tender is in the process of enforcing that guest executable code is not also writable (W^X), but it looks like vmm is not updating EPT to match the prot from mprotect(). further information https://github.com/Solo5/solo5/issues/303#issuecomment-446503933 copied here for

Re: ikev2 and road warriors setup

2018-12-12 Thread Radek
Hello again, I am using PPTP VPN (npppd) and it works as expected on windows clients - traffic to the "LAN behind that VPNgateway" is going through VPNgateway. The "rest" is going through clients' gateway - DO NOT "use default gateway on remote network". I have been playing around with

Re: radeondrm failure on amd64 but not on i386?

2018-12-12 Thread Allan Streib
Still having this issue on -current as of Dec10. machdep.allowaperture=2 does get me past this, but am seeing weird behavior, some regions of screens/terminals not painting or refreshing. So, as this is a major inconvenience I am looking to update the video card. Any recommendations for a

Re: iked : pf.conf rule for outgoing traffic

2018-12-12 Thread Thuban
* Stuart Henderson le [10-12-2018 18:19:41 +]: > On 2018-12-07, Thuban wrote: > > * Stuart Henderson le [06-12-2018 13:44:50 +]: > >> On 2018-12-06, Thuban wrote: > >> > * Thuban le [02-12-2018 19:16:09 +0100]: > >> >> Hi, > >> >> I need help to write a correct rule in pf.conf. > >>

Re: rtwn

2018-12-12 Thread Theo de Raadt
Eric Furman wrote: > On Tue, Dec 11, 2018, at 8:56 PM, Stanislav wrote: > > OK. What can I do? > > Could you recommend an action I can make? > > Is it normal if I just wait for new version of rtwn? > > Or does this situation mean that mentioned card probably never will be > > supported? > > >

Re: rtwn

2018-12-12 Thread Eric Furman
On Tue, Dec 11, 2018, at 8:56 PM, Stanislav wrote: > OK. What can I do? > Could you recommend an action I can make? > Is it normal if I just wait for new version of rtwn? > Or does this situation mean that mentioned card probably never will be > supported? > > I have searched similar cases. >

Re: rtwn

2018-12-12 Thread Stefan Sperling
On Tue, Dec 11, 2018 at 06:56:22PM -0700, Stanislav wrote: > OK. What can I do? > Could you recommend an action I can make? > Is it normal if I just wait for new version of rtwn? > Or does this situation mean that mentioned card probably never will be > supported? > > I have searched similar

Re: rtwn

2018-12-12 Thread Stanislav
OK. What can I do? Could you recommend an action I can make? Is it normal if I just wait for new version of rtwn? Or does this situation mean that mentioned card probably never will be supported? I have searched similar cases. Stefan Sperling's report at EuroBSDcon2017: "Sometimes just adding

Re: [OpenBSD 6.4][OpenIKED] Route to IPSec tunnel?

2018-12-12 Thread Zhi-Qiang Lei
Hi Aaron, Thanks! I also tried gif. But the behavior is quite weird. Through the gif devices, the gateway and VPN server can ping each other, while the packets on gateway enc0 from the client routing to the gif device always got bad checksums. I think it is related to the bugs on gif(4) man

Re: [OpenBSD 6.4][OpenIKED] Route to IPSec tunnel?

2018-12-12 Thread Aaron Mason
Hi Siegfried (Maintainers of the IPSec stack and ISAKMPD are welcome to tear my answer apart) IPSec tunnels are, for want of a better term, entirely transparent - the underlying OS and its clients have no idea that it exists. In order to route across an IPSec tunnel, use gif(4) to create an

Block udp fragments to a single host while reassembling is on

2018-12-12 Thread Joerg Streckfuss
Dear list, i want to block udp fragments to a specific host while the reassembling is turned on for all other traffic: In pf I would write something like this: # reassemble fragmented packets (default yes) set reassemble yes # scrub all traffic match all scrub (random-id no-df) # block

Re: Renew/extend CA created with ikectl

2018-12-12 Thread Kim Zeitler
Hello Stuart thanks for the reply, already suspected something along those lines. On 12/10/18 7:14 PM, Stuart Henderson wrote: It's a bit awkward but can be done, you'll find some information at