Re: Default software in the base

2013-07-29 Thread Jiri B
On Tue, Jul 30, 2013 at 12:03:42AM +0400, h...@riseup.net wrote: > [...] > Like Clang for i386/amd64 guys with all the new and fancy and then make a > balanced > transition slowly phasing out aging architectures? First you do not get project's goals, see the website. jirib

Re: Automatically direct to serial console BEFORE passphrase prompt on FDE (i386)

2013-07-22 Thread Jiri B
On Mon, Jul 22, 2013 at 09:36:25PM +1000, Joel Sing wrote: > Otherwise you could use a modified boot(8), which defaulted to serial - see > constab in sys/arch/i386/stand/boot/conf.c for example. What about installboot to have an option telling it to switch to serial by default (still keeping poss

/var/cron/log - purpose not being in /var/log?

2013-07-16 Thread Jiri B
Hi, what is the purpose to have cron's log in /var/cron/log and not in usual log directory - /var/log ? Historical reason? jirib

Re: Softraid performance: CRYPTO on top of RAID 1?

2013-07-03 Thread Jiri B
On Thu, Jul 04, 2013 at 02:33:51AM +1000, Joel Sing wrote: > [...snip...] FWIW one of my servers (handles mail, etc) is a Sun Fire V210 > (sparc64) machine with 2x1GHz CPU, 2GB RAM and a pair of SCSI drives - it > runs perfectly well in a similar CRYPTO on RAID 1 configuration. That said, > you'

Re: Question about caching system

2013-06-25 Thread Jiri B
On Mon, Jun 24, 2013 at 05:43:35PM +0200, Christiano F. Haesbaert wrote: > On 24 June 2013 15:37, Ioana b wrote: > > Hello, > > > > is there any kind of name service cache system like nscd for linux > > available any time soon? It would be helpful to have a cache for the users > > You can use b

OpenBSD project infra - like 'FreeBSD cluster refit' slides

2013-06-12 Thread Jiri B
Hi, I was read 'The FreeBSD.org cluster refit'[1] slides about FreeBSD project infrastructure (servers, network setup, authentication...). Could anybody share similar info for OpenBSD project? How it is managed, configured etc... IIRC, vether(4) was developed for Theo's needs to have better conne

Re: ESXi virtual switch and vic driver, asynchronous speeds

2013-06-09 Thread Jiri B
On Mon, Jun 10, 2013 at 06:20:59AM +, Alexey E. Suslikov wrote: > Second - to ask DC people to give you a decent network emulation > like vio(4) or em(4). VMWare is not following virtio standard, they have vmx ;) jirib

Re: /var/cache/fontconfig ??

2013-06-09 Thread Jiri B
>Sorry but this seems to bizzare to make 'cache' appropriate >subdir in /var just because of one specific tool. Wouldn't be >better to customize it to use /var/db/fontconfig? Ahh, on other machine there's also 'cups' and 'libvirt' :) jirib

Re: /var/cache/fontconfig ??

2013-06-09 Thread Jiri B
> > See fc-cache(1) > > > > > > "These files are generated by fc-cache and contain maps from file > > names to font properties. They are read by the fontconfig > > library at application startup to locate appropriate fonts." > > > > thanks! (no cookie though) > > i guess we should properly doc

/var/cache/fontconfig ??

2013-06-08 Thread Jiri B
Hello, I haven't found any comment in hier(7) about /var/cache and there seems to be only dir - 'fontconfig'. I'm not sure how this directory was created, probably during install of the xbaseXX set. Shouldn't this in /var/db ? If not, then hier(7) probably needs update. jirib

extattr on OpenBSD

2013-06-06 Thread Jiri B
As now FUSE is in the tree, is there a plan to resuscitate extattr on OpenBSD, so some filesystems in usespace could work or benefit from it? I'd like to see to be able to access glusterfs for example which uses extattr for its own metadata. Just curious. jirib

Re: Is it possible to do with pf?

2013-05-28 Thread Jiri B
On Tue, May 28, 2013 at 02:11:58PM -0500, Mark Felder wrote: > Yes, it's in the man page for pf.conf. Search for "user". > On limitation, you cannot redirect outgoing traffic being from the host itself back to the host itself :( Example: if you want to redirect all traffic of user 'foo' via Tor'

Re: Working on suspend/resume

2013-05-28 Thread Jiri B
What is general way how to help debugging hanged OS after resume? This happends all the time on my Lenovo T500 if X is running. It seems to work better if I'm in virtual terminal. jirib

key/cert fingeprint as ssh env variable

2013-05-23 Thread Jiri B
Hello, I was reading about ssh & certificates and was curious how to inform logging user about this certificate expiration. IIRC it is not possible by default now, so an option would be to have a repository with all signed certificates and check the certs for expiration. Then next idea was how to

Re: a sftp user can enter into a directory which he does not have rights

2013-05-21 Thread Jiri B
On Tue, May 21, 2013 at 12:59:55PM -0700, Philip Guenther wrote: > On Tue, May 21, 2013 at 12:52 PM, Jiri B wrote: > > I'm very surprised to see something like this. Comparing with > > normal unix filesystem, 'sftpuser' would not even enter such > > dire

a sftp user can enter into a directory which he does not have rights

2013-05-21 Thread Jiri B
I'm very surprised to see something like this. Comparing with normal unix filesystem, 'sftpuser' would not even enter such directory. Is this OK? * sftpuser has only group 'sftpuser' $ sftp sftpuser@localhost Connected to localhost. sftp> cd / sftp> ls -l drwxr-xr-x2 00 5

Re: provide option to dhclient at boot

2013-05-20 Thread Jiri B
On Mon, May 20, 2013 at 11:56:15AM +0200, Daniel Polak wrote: > I'd like to use the -l option to have dhclient use an alternate location > for the leases file. > Netstart starts dhclient at boot but I don't see a way to supply the -l > option to dhclient other than to modify netstart. > > Am I mis

Re: provide option to dhclient at boot

2013-05-20 Thread Jiri B
On Mon, May 20, 2013 at 11:56:15AM +0200, Daniel Polak wrote: > I'd like to use the -l option to have dhclient use an alternate location > for the leases file. > Netstart starts dhclient at boot but I don't see a way to supply the -l > option to dhclient other than to modify netstart. > > Am I mis

Re: who is using obsd

2013-05-14 Thread Jiri B
On Tue, May 14, 2013 at 11:18:07AM +0100, Mark Duller wrote: > > Unless s.o. has to use some proprietary software that is tighly > > linked to internals of an other OS there is no technical reason to > > use any other OS as a basis for a desktop system > > except for resume from suspend not worki

Re: DHCLIENT v5.3

2013-05-09 Thread Jiri B
On Wed, May 08, 2013 at 07:58:26PM -0700, Chris Cappuccio wrote: > For now you'll need to call your dns script from dhclient. A system() will do > the trick. Is planned to have an ability to fire a script/command from dhclient in the future? I used to be putting on/off various dns servers for my

Re: Xephyr bug with Firefox

2013-04-22 Thread Jiri B
On Sun, Apr 21, 2013 at 04:12:59PM -0700, Robert Connolly wrote: > Hello. > > I use Xephyr with Firefox. I also run Firefox as a dedicated user. > At seemingly random times, but on a regular basis, Firefox will > behave oddly. Firefox will open links in a new window, scrolling up > or down with my

Re: nginx in 5.2 without mail proxy features - Reasons?

2013-04-19 Thread Jiri B
On Fri, Apr 19, 2013 at 12:59:17PM +0200, Bruno Flueckiger wrote: > --without-mail_pop3_module --without-mail_imap_module > --without-mail_smtp_module > > The last two lines show that all three mail modules (POP3/IMAP/SMTP) > had been disabled by configure before compilation took place. > > Can a

Re: Blocking traceroute

2013-04-19 Thread Jiri B
On Thu, Apr 18, 2013 at 10:52:00PM -0400, Stuart McMurray wrote: > You don't even need socat. You could do it all with pf. > Except for DNS, though, you'd have to block outbound DNS traffic to > maintain anonymity. It's not possible to redirect outgoing traffic back to local IP where source host

Parallella: A Supercomputer For Everyone (and OpenBSD?)

2013-04-18 Thread Jiri B
I just found info about Adapteva's Parallella supercomputer, a board based on their Epiphany chip, all should be opensource. If any dev would be interested in thise piece of hardware, mail me and I will send you money to buy it. It should be available in May 2013. Some info about Parallella: * Z

Re: Xwindows Startup without user login

2013-04-10 Thread Jiri B
On Wed, Apr 10, 2013 at 12:29:37PM +0200, Manuel Giraud wrote: > Renaud Allard writes: > > > # echo 'su - auser -c "/usr/X11R6/bin/startx"' >> /etc/rc.local what about man tty? jirib

Re: Xwindows Startup without user login

2013-04-09 Thread Jiri B
> > Haven't tried it, but SLiM (ports/x11/slim) has an autologin feature. > > I will have a look at it. Thanks, Why do you need a DM if you need autologin into X? Is it not possible to start xinit on a console? jirib

[OT] Multipath TCP - RFC6824

2013-03-29 Thread Jiri B
Very interesting, looks like better bandwidth without having LACP in switches or upgrading to faster nics. http://multipath-tcp.org/pmwiki.php?n=Main.50Gbps jirib

Re: empty pf log / pflogd not starting?

2013-03-24 Thread Jiri B
On Sun, Mar 24, 2013 at 02:19:13PM -0700, David Ruggiero wrote: > I'll hack the pflogd script for now until full 5.3 is released, when > things presumably will work better. FYI 5.3 release if based on older code, so your comment is irrelevant. jirib

Re: sendmail stops remote delivery when PTR for local IP points to domain-part

2013-03-21 Thread Jiri B
On Thu, Mar 21, 2013 at 01:40:11PM +0100, Maurice Janssen wrote: > Are you sure this is becaus of the PTR record (according to the subject of > your email)? I think sendmail looks up the A and MX record for > example.com and sees that the A record is a local IP. > So, do you need the A record for

Re: renaming name of interfaces

2013-03-14 Thread Jiri B
On Thu, Mar 14, 2013 at 12:17:50PM +0100, Peter N. M. Hansteen wrote: > On Thu, Mar 14, 2013 at 07:12:08AM -0400, Jiri B wrote: > > > just for curiosity, is it planned for future? > > > > I can't just now think about real usability... > > Me neither

Re: renaming name of interfaces

2013-03-14 Thread Jiri B
On Thu, Mar 14, 2013 at 02:10:40PM +, Christian Weisgerber wrote: > Peter N. M. Hansteen wrote: > > > Me neither. For most use cases I can think of, interface groups (a feature > > we > > do have, see ifconfig(8) and possibly other references elsewhere) will give > > you what others have i

renaming name of interfaces

2013-03-14 Thread Jiri B
Hello, just for curiosity, is it planned for future? I can't just now think about real usability... jirib

Re: Squid proxy

2013-03-12 Thread Jiri B
On Tue, Mar 12, 2013 at 03:59:27PM +, Stuart Henderson wrote: > For 2.7 uou must have the proxy configured specifically in your browser > for this to work - the SSL interception features are only in 3.x, and > the "server first" mode which works with transparent (a.k.a. > interception) proxy ne

Re: Squid proxy

2013-03-12 Thread Jiri B
On Tue, Mar 12, 2013 at 01:00:58PM +, Stuart Henderson wrote: > On 2013-03-10, Rosen Iliev wrote: > > Transparent proxy will not be useful for HTTPS connections. > > To handle HTTPS you'll need not-transparent proxy. > > Actually squid 3.3 (not in ports yet) can do this using the > sslbump MI

Re: Squid proxy

2013-03-10 Thread Jiri B
On Sun, Mar 10, 2013 at 04:35:15PM +0100, Alessandro Baggi wrote: > Hi jirib, > but if squid has problems (bad configuration, machine failure > without failover) there are 120 pcs, that try to communicate with a > failure proxy. At this point, how to solve? With transparent I can > remove redirect

Re: Squid proxy

2013-03-10 Thread Jiri B
On Sun, Mar 10, 2013 at 12:38:35PM +0100, Alessandro Baggi wrote: > Hi list, > I'm plannig to setup a squid proxy for a network with about 120 User. > I have not great experience with proxying network that has over 20 user. > For this scenario, is better transparent or not-trasparent proxy? Non-tr

Re: "offline" mail setup for road warrior

2013-03-09 Thread Jiri B
On Sat, Mar 09, 2013 at 04:56:59PM +0100, Peter Hessler wrote: > I use offlineimap for the local copy. this also syncs up the > Read/Unread/Replied/etc statuses. I haven't bothered replying to emails > this way, but it is at least half of the method. I understood his mail that he wants to have f

Re: "offline" mail setup for road warrior

2013-03-09 Thread Jiri B
On Sat, Mar 09, 2013 at 12:18:50AM +0100, frantisek holop wrote: > hi there, > > i am fishing for ideas from others regarding > how to read/send email in my current life situation > (=being on the road all the time connecting once > in a while with 3rd world wifi). > > i have my own mail server,

Re: X11 Fonts Configuration

2013-03-09 Thread Jiri B
On Sat, Mar 09, 2013 at 10:16:29AM +, James Griffin wrote: > Cheers, Patrick. I had a read of > http://www.openbsd.org/faq/truetype.html and I think because I installed > the fonts as a package they were registered properly automatically. Terminus font is not trutype font. jirib

Re: X11 Fonts Configuration

2013-03-09 Thread Jiri B
On Sat, Mar 09, 2013 at 09:35:06AM +, James Griffin wrote: > Hi > > I've installed the Terminus font package obviously to use the font. I haven't > needed to create an xorg.conf file as X just works without it but; do I need > to create one and add the font path(s) to it to use the Terminus

Re: installer - moving sets location right after network for automated installation

2013-03-07 Thread Jiri B
On Thu, Mar 07, 2013 at 10:23:41AM -0700, Theo de Raadt wrote: > > I was thinking that if we would move part in the installer which let the > > user > > locate installation sets right after setting networking, we could introduce > > some install.site alternative which could feed installer with con

installer - moving sets location right after network for automated installation

2013-03-07 Thread Jiri B
Hi, I was thinking that if we would move part in the installer which let the user locate installation sets right after setting networking, we could introduce some install.site alternative which could feed installer with configuration for setting disks etc... Or is there any (semi)official idea ho

Re: Get total size of all files in directory using unit Bytes?

2013-03-04 Thread Jiri B
On Mon, Mar 04, 2013 at 12:32:32PM +0100, Paolo Aglialoro wrote: > Great one! > How to put that nice expression into an alias without console complaining > when executed? A shell function instead of an alias? jirib

Re: Precisions on ZFS (was: Millions of files in /var/www & inode / out of space issue.)

2013-02-22 Thread Jiri B
On Fri, Feb 22, 2013 at 04:22:51AM -0500, Jiri B wrote: > On Fri, Feb 22, 2013 at 03:29:21AM +0100, Juan Francisco Cantero Hurtado > wrote: > > OpenBSD doesn't have support for loadable kernel modules or FUSE, so > > OpenBSD should include the code inside of th

Re: Precisions on ZFS (was: Millions of files in /var/www & inode / out of space issue.)

2013-02-22 Thread Jiri B
On Fri, Feb 22, 2013 at 03:29:21AM +0100, Juan Francisco Cantero Hurtado wrote: > OpenBSD doesn't have support for loadable kernel modules or FUSE, so > OpenBSD should include the code inside of the kernel. This is a big > difference with FreeBSD/NetBSD/Linux. http://www.openbsd.org/cgi-bin/cvsweb

Re: Millions of files in /var/www & inode / out of space issue.

2013-02-20 Thread Jiri B
On Wed, Feb 20, 2013 at 12:32:02AM +0100, Matthias Appel wrote: > And by talking of ZFS, why not consider > ext3/4,reiser,xfs,jfs,ntfs,whatever-fs to be ported to OpenBSD? Where are the diffs? For example real improvement would be FAT/NTFS speed on OpenBSD, as it is much much slower than on Linux.

Re: Installing Openbsd 5.2 as KVM guest

2013-02-14 Thread Jiri B
On Thu, Feb 14, 2013 at 08:54:36AM +0100, Xavier Naveira wrote: > The xml file for virsh look like this: > > > > > ^^ - needs newer than 5.2. I've been testing OpenBSD -current on RHEVM 3.2 which is being cooked right now. jirib

Re: bootable OpenBSD USB stick from windows?

2013-02-11 Thread Jiri B
On Mon, Feb 11, 2013 at 10:51:29PM +, Heptas Torres wrote: > Hello > I have an old laptop with no CD-ROM but can boot from USB. Given that > I only have access to a windows machine to burn an iso image, do you > know of an easy way (e.g. some windows programa) to create a bootable > OpenBSD USB

Re: softraid RAID1 + CRYPTO error writing metadata

2013-02-08 Thread Jiri B
On Sat, Feb 09, 2013 at 03:26:33AM +1100, Joel Sing wrote: > > Would stackable softraid volumes work in near future or is it big > > problem as how softraid was designed? > > Generally speaking they already "work" - there are just some caveats, > primarily relating to assembly and shutdown. Most

Re: softraid RAID1 + CRYPTO error writing metadata

2013-02-08 Thread Jiri B
On Sat, Feb 09, 2013 at 02:56:47AM +1100, Joel Sing wrote: > While stacked softraid volumes generally work, they are not officially > supported (for a variety of reasons). The problem that you mention above is > due to the way that softraid volumes are shutdown - the shutdown order is > approxim

Re: openbsd and vmware

2013-02-05 Thread Jiri B
Try to consider oVirt[1], it is open-source, based on top of KVM, aims to be vSphere competitor. ...forgotten url - http://www.ovirt.org jirib

Re: openbsd and vmware

2013-02-05 Thread Jiri B
On Tue, Feb 05, 2013 at 03:03:34AM -0800, Bogdan Andu wrote: > Hello, > > A few questions related to openbsd and vmware. > > > What are the best practices to run OpenBSD in vmware? > > Are there any known problems one should take into consideration before > virtualization? > > I already have

Re: CARP best practices

2013-01-30 Thread Jiri B
On Wed, Jan 30, 2013 at 09:29:42AM -0800, Johan Beisser wrote: > On Wed, Jan 30, 2013 at 8:56 AM, System Administrator > wrote: > > I finally got to deploy a CARP firewall cluster (HA failover for now). > > Using only the official OpenBSD.org documentation, everything went very > > smoothly even

Re: two equal filenames in one dir

2013-01-27 Thread Jiri B
On Sun, Jan 27, 2013 at 05:20:14AM -0500, Jiri B wrote: > Hello, > > I'm confused, how is it possible I have two files with same > names in one dir? > > $ ls -li > total 1245376 > 3611817 -rw-r--r-- 1 jirib jirib 168392755 Jan 14 23:35 > Crostata_Alla_Fruta.m

two equal filenames in one dir

2013-01-27 Thread Jiri B
Hello, I'm confused, how is it possible I have two files with same names in one dir? $ ls -li total 1245376 3611817 -rw-r--r-- 1 jirib jirib 168392755 Jan 14 23:35 Crostata_Alla_Fruta.mp4 3741698 -rw-r--r-- 1 jirib jirib 165519511 Mar 12 2010 Pizza Margherita-10115892.mp4 3611818 -rw-r--

Re: tor + rdomain

2013-01-26 Thread Jiri B
On Sat, Jan 26, 2013 at 02:11:06PM +0100, Sébastien Marie wrote: > Hi, > > I would like to have some help for perform a network isolation using rtable, > to use tor without network leak. > I use -current. The host is a workstation (no forwarding set in sysctl). I just run a program which should

Re: Use pax instead of cpio in FAQ 14.4 (Adding extra disks)

2013-01-12 Thread Jiri B
On Sat, Jan 12, 2013 at 01:10:16AM +, Christian Weisgerber wrote: > I tend to recommend dump|restore, but those aren't on bsd.rd. Really? I had feeling that the best way to do disaster recovery is to use bsd.rd, make partitioning and dump/restore... Quite pitty if dump/restore is not included.

Re: new computer

2013-01-09 Thread Jiri B
On Wed, Jan 09, 2013 at 04:53:08PM +0100, Zoran Kolic wrote: > For some future period I will get new node to run on openbsd. > First dilema is to have laptop or desktop. Both have something > to learn about supported hardware. I'd like to know what are > popular el cheapo parts. Current, since at m

Re: Current isolation best practices?

2013-01-09 Thread Jiri B
On Wed, Jan 09, 2013 at 07:28:41AM +, John Long wrote: > I use Solaris zones to isolate a lot of stuff and I can host shell accounts > and occasional open source projects safely as far as I know. I would like to > be able to offer OpenBSD shell accounts but I don't know how to do that > safely

Re: Current isolation best practices?

2013-01-08 Thread Jiri B
On Tue, Jan 08, 2013 at 01:54:04PM -0500, Jean-Philippe Ouellet wrote: > Hello misc@, > > I'm researching locking things down, and I'm wondering what the current > best practice is for isolating risky programs. It seems this community > has traditionally shunned virtualization as a solution, and a

Re: 3k machines

2013-01-02 Thread Jiri B
On Wed, Jan 02, 2013 at 10:37:37AM -0200, Friedrich Locke wrote: > Don't get me wrong. > I only said they have 3K machine. I never said they are using OBSD. > Actually, only servers are OBSD. > For desktops, they are using win/linux. > > I am trying to change those desktops from win/linux to OBSD.

Re: A point about the BSD license I'm feeling edgy about

2012-12-29 Thread Jiri B
On Sat, Dec 29, 2012 at 03:35:39PM -0700, Diana Eichert wrote: > >Everyone here knows what the BSD licence is: do what the fuck you want with > >the code. The only thing you're not allowed to do is claim you wrote it when > >you didn't. > > > >The licence does NOT prevent you from doing bad, evil

Re: openbsd clusters

2012-12-27 Thread Jiri B
On Thu, Dec 27, 2012 at 05:28:24PM -0600, Alvaro Mantilla Gimenez wrote: > Is not this what you are trying to accomplish? > > http://docs.openafs.org/AdminGuide/index.html#HDRWQ57.html#HDRWQ59 > > and then, adding space: > > http://docs.openafs.org/AdminGuide/index.html#HDRWQ130.html > > and if

Re: openbsd clusters

2012-12-27 Thread Jiri B
On Wed, Dec 26, 2012 at 03:26:43PM -0500, Nick Holland wrote: > Probably thinking of this thread: > http://marc.info/?t=117689108200011&r=1&w=2 > and my two contributions to it. A number of other people provided some > good (and some bad) comments, too...read through 'em all. You get to > decide

Re: Best postscript printer with network support?

2012-12-27 Thread Jiri B
On Thu, Dec 27, 2012 at 04:28:04PM +0530, Girish Venkatachalam wrote: > I want to print from my OpenBSD machines on the ethernet LAN. > > I asked HP and Epson but did not get a good response. I want to avoid HP. > > I want basic printing with Postscript ability over the network. > > Also good va

Re: directory monitoring

2012-12-24 Thread Jiri B
On Sat, Dec 22, 2012 at 06:19:10PM +0100, Martijn van Duren wrote: > Hello misc, > > I recently compiled minidlna to run on my local OBSD based home server. > It runs great by default, but it relies upon inotify to receive > information on filesystem changes. > I really like the program, but it's

Re: openbsd clusters

2012-12-22 Thread Jiri B
On Sat, Dec 22, 2012 at 01:23:12PM +, Stuart Henderson wrote: > > But for other services i don't have now what i could use. A example: i need > > a file system that must expand by adding more machine in the network in a > > simple way. I was studying OpenAFS, but OBSD 5.1 only support it for i3

Re: KSH command logged to syslog

2012-12-17 Thread Jiri B
On Mon, Dec 17, 2012 at 02:03:03PM +, Stuart Henderson wrote: > Wouldn't it be better to use an ssh forced command, which then looks > up the users desired shell (or other command called directly from ssh) > and wraps it in a logger? ForceCommand runs under destination user permissions so if y

Re: Isolating Firefox in a nested X server, and running as a different user

2012-12-16 Thread Jiri B
On Sun, Dec 16, 2012 at 02:21:59PM -0800, Robert Connolly wrote: > I would like to hear comments about using pf to filter user/group, > to make sure Firefox uses a proxy. The idea behind this is to stop > Firefox from leaking my IP. Is this the most efficient way to do > this? I block an user usin

Re: KSH command logged to syslog

2012-12-14 Thread Jiri B
On Fri, Dec 14, 2012 at 01:50:49PM +0100, Dustin Fechner wrote: > On 12/14/2012 12:20 PM, Lorenzo Crapovich wrote: > > Hi folks.I'm looking for a clean solution, to log through syslog > > every single shell command that a user make. > > Why not log to /var/account/acct? > See accton(8) and sa(8).

Re: KSH command logged to syslog

2012-12-14 Thread Jiri B
On Fri, Dec 14, 2012 at 11:20:09AM +, Lorenzo Crapovich wrote: > Hi folks.I'm looking for a clean solution, to log through syslog every single > shell command that a user make.I've found many wrapper scripts, or stuff like > 'sudosh, snoopy logger', but actually, it sounds pretty dirty imho. >

Re: Groff replacement

2012-12-05 Thread Jiri B
On Thu, Dec 06, 2012 at 01:53:42PM +0800, Yusof Khalid - FreeBSD / OpenBSD wrote: > Hi list, > > I just noticed that groff is remove from the ports list, I'm trying to > install dansguardian to work with my squid proxy. Got the following error : > > make install > ===> Checking files for dansgu

Re: Isolating Firefox in a nested X server, and running as a different user

2012-12-03 Thread Jiri B
On Sat, Dec 01, 2012 at 08:53:53PM -0800, Robert Connolly wrote: > Hello. > > In an effort to isolate Firefox (or any graphical browser) from my > user account, I have added a 'firefox' user and group, added > 'firefox' user to sshd_config to allow x11 forwarding, and ran the > following commands:

Re: bsd cloud

2012-11-27 Thread Jiri B
On Tue, Nov 27, 2012 at 04:13:47PM -0200, Friedrich Locke wrote: > Hi folks, > > i have seen, some minutes ago, a message about cloud with BSD! > I have seen announcements on cloud computing every where. What is the > difference between a BSD cloud and a linux cloud ? A windows cloud and a > linux

Re: xfsdump INTERRUPT

2012-11-20 Thread Jiri B
On Mon, Nov 19, 2012 at 02:10:09PM -0800, rlinsurf wrote: > I'm trying to use xfsdump to copy all the files from my home DVR to a bigger > hard drive. You sent probably to bad list, this is linux stuff. jirib

Re: Replacing Apache with nginx

2012-11-20 Thread Jiri B
On Mon, Nov 19, 2012 at 04:42:57PM -0300, Martín Ferco wrote: > I can see that some files have been updated by the OpenBSD team, reading > README.OpenBSD in the source directory. One of those changes seems to have > been the inclusion of the "-u" flag to chroot nginx (I'm not entirely sure > about

Re: Hardware hunting

2012-11-16 Thread Jiri B
On Thu, Nov 15, 2012 at 10:30:26PM -0600, Axton wrote: > > The supermicro Atom based machines are nice. I am a fan of the remote > management interface, which allows power cycle, KVM over IP, virtual media, > etc. Really? KVM over IP on Supermicro doesn't work from OpenBSD. Serial console redirec

Re: question about built-in support for full disk encryption

2012-11-11 Thread Jiri B
On Sun, Nov 11, 2012 at 11:20:53AM +, hepta tor wrote: > Thanks for the pointer. Do you know if there are any guidelines on how > to configure FDE with what's implemented in -current? > At > http://geekyschmidt.com/2011/01/19/configuring-openbsd-softraid-fo-encryption > there is a kind of mini

Re: hardware suggestion: off topic (probably)

2012-11-06 Thread Jiri B
On Tue, Nov 06, 2012 at 02:28:49PM -0200, Friedrich Locke wrote: > Dear list members, > > I have setted up a web server in my working environment and i was asked to > install webalizer. Now my boss asked me to install a tool that "looks" at > webalizer stats files and suggest a hardware capacity f

Re: USB-to-Serial adapter on OpenBSD 4.9

2012-11-06 Thread Jiri B
On Tue, Nov 06, 2012 at 04:22:17AM -0800, ML mail wrote: > Hi, > > On my OpenBSD 4.9 i386 PC there is no serial port so I bought a USB-to-Serial > adapter in the hope to be able to use it but I can't figure out which device > in /dev to use for that. When I connect the adapter I have the followi

would boot(8) now face an attack as truecrypt evil maid?

2012-11-05 Thread Jiri B
I suppose boot(8) supporting now crypto volumes would face same attack as truecrypt - Evil Mail[1] Could be some easy _workaround_ for this? Such as copying boot loader from fixed disks to an usb stick to prevent this kind of physical hardware attack? jirib [1] http://theinvisiblethings.blogspo

Re: boot(8) on amd64 asks for passphrase but keydisk...?

2012-11-05 Thread Jiri B
On Sun, Nov 04, 2012 at 02:46:55PM -0600, Aaron Poffenberger wrote: > Theo de Raadt writes: > > >> Well I moved to position that booting with a passphrase and then > >> concatenate strong passphrase from an Yubikey configured with > >> static passphrase would be better solution than keydisk and >

Re: boot(8) on amd64 asks for passphrase but keydisk...?

2012-11-04 Thread Jiri B
On Sun, Nov 04, 2012 at 11:07:49AM +0100, Stefan Sperling wrote: > On Sat, Nov 03, 2012 at 07:08:58PM -0400, Jiri B wrote: > > This is totally fantastic what jsing@ did, boot(8) can now ask > > for passphrase for root disk laying on softraid crypto volume. > > It works OK.

boot(8) on amd64 asks for passphrase but keydisk...?

2012-11-03 Thread Jiri B
This is totally fantastic what jsing@ did, boot(8) can now ask for passphrase for root disk laying on softraid crypto volume. It works OK. But I didn't know it works with passphrase beforeso I first tried with keydisk... What a surprise, boot(8) could not use key disk for crypto volume (still prin

Re: GENERIC-kernel hangs at acpivout, ASUS N55SF laptop

2012-10-30 Thread Jiri B
On Tue, Oct 30, 2012 at 10:24:03AM +0400, Mike Korbakov wrote: > This device has no COM port etc, a can only attach photo from screen. Yep, photo -> text. > To use config I must boot, isn't it ? config allows you to change kernel before it is used. > Now faulty driver is known, may be the time

Re: GENERIC-kernel hangs at acpivout, ASUS N55SF laptop

2012-10-29 Thread Jiri B
On Tue, Oct 30, 2012 at 06:47:15AM +0400, Mike Korbakov wrote: > Hi, Group! > > GENERIC kernel from OpenBSD5.1 to current hangs at boot, > trace pointed to acpivout. I've commented acpivout in kernel config, > kernel boots successfully, but X seems unstable and CPU runs > at lowest speed. Quite u

Re: IBM System x3100 M4 - panic

2012-10-12 Thread Jiri B
On Fri, Oct 12, 2012 at 10:36:57PM +0200, Alexander Hall wrote: > On 10/12/12 22:23, Jiri B wrote: > >On Fri, Oct 12, 2012 at 03:19:34PM -0300, Walter Souza wrote: > >>>RUN AT LEAST 'trace' AND 'ps' AND INCLUDE OUTPUT WHEN REPORTING THIS PANIC! > >>

Re: IBM System x3100 M4 - panic

2012-10-12 Thread Jiri B
On Fri, Oct 12, 2012 at 03:19:34PM -0300, Walter Souza wrote: > > RUN AT LEAST 'trace' AND 'ps' AND INCLUDE OUTPUT WHEN REPORTING THIS PANIC! > > IF RUNNING SMP, USE 'mach ddbcpu <#>' AND 'trace' ON OTHER PROCESSORS, TOO. > > DO NOT EVEN BOTHER REPORTING THIS WITHOUT INCLUDING THAT INFORMATION! > >

Re: the idea of /fastboot ?

2012-10-11 Thread Jiri B
On Thu, Oct 11, 2012 at 09:29:50PM +0600, �?л�?�? Шипи�?ин wrote: > > there are http access logs for half an year. > it's easier to rotate them on a single filesystem from many points of view, > we also share it via samba (very tricky to share many chunks). > > and it is bad idea to mount access

Re: Recommended new laptop under US$800 for OpenBSD

2012-10-06 Thread Jiri B
On Sat, Oct 06, 2012 at 08:46:28PM +0200, Erling Westenvik wrote: > And I am very satisfied with my ThinkPad T500 (September 2008 model, or > August 2009, I'm not sure...) which my nephew gave to me since the > company he works for considered it outdated. I'm running current and > everything works

Re: Nginx, FCGI and C programs

2012-10-04 Thread Jiri B
On Thu, Oct 04, 2012 at 08:20:43PM +0300, Ville Valkonen wrote: > Hi, > > I've configured Nginx and FCGI to run some C/C++ apps, well almost. > > When navitaging to http://host.foo/weezel/progut/default.cgi nginx's error log > states the following (below there is test.c, test.c == default.cgi): >

Re: tmux and current directory

2012-09-30 Thread Jiri B
On Sun, Sep 30, 2012 at 06:24:08PM +, Stuart Henderson wrote: > On 2012-09-30, Jan Stary wrote: > > On current/i386, tmux seems to open a new shell with the current > > directory being the same as in the window I am opening from. > > > > What that means in particular is that if I run 'man what

Re: !!!!

2012-09-05 Thread Jiri B
OpenBSD provides good basics for you, but yes it doesn't by default sign packages. If you are still paranoid and you want signed packages you can build them by your own - dpb. Just read documentation. j.

Re: one keydisk to access multiple encrypted systems

2012-08-27 Thread Jiri B
On Sat, Aug 25, 2012 at 09:54:25AM -0600, Aaron Bieber wrote: > One key disk for multiple machines is impossible from what I > understand. Passphrase fallback is also currently impossible. IIRC Linux cryptsetup has 4 slots you can use for keys. It would be nice if this would be possible on OpenBS

Dell Latitude E6420 issues - not working...

2012-08-14 Thread Jiri B
Hi all, I have in my hands Dell Latitude E6420 so I tried to boot OpenBSD snapshot and booting got stucked on these lines... (I retyped from a photos I made.) The last line was one with 'scsibus1 at umass0' below, then I touched a key and console was full of pbkbcintr lines... How can I help to

Re: CDE source is available on sourceforge ...

2012-08-06 Thread Jiri B
On Mon, Aug 06, 2012 at 09:22:27PM +0200, Tom Knienieder wrote: > Some people might find this interesting. > > CDE source is available here: > http://sourceforge.net/projects/cdesktopenv/files/ ...and the most interesting info is... 3) What license is it released under? The source code to the p

Re: openbsd : project : isc : infrastructure support

2012-07-23 Thread Jiri B
On Mon, Jul 23, 2012 at 09:27:56PM +0200, Mayuresh Kathe wrote: > anyone on the list with infrastructure support to help us with the following? Yes, install OpenBSD. > a way to host our project webpage and email system via a shell interface. > the domain name is owned by us. > we would like to h

cvsync - creating empty dir 'cvsync'

2012-07-13 Thread Jiri B
Hello, does anybody know why does cvsync create empty 'cvsync' dir inside the prefix for repositories? The config is same style as on OpenBSD page with refuse file excluding 'X11' and 'XF4'. (here localhost is ftp5.eu.openbsd.org via http proxy) # cvsync -c /etc/cvsync.conf Connecting to loca

Re: misc questions from beginner

2012-07-12 Thread Jiri B
On Thu, Jul 12, 2012 at 07:40:09PM +0200, Wojciech Puchar wrote: > 1) is ANY form of support for virtualization extension planned? It already exists, it is called LDOMs, or you can use ESXi ;) jirib

Re: Help neede for 'pkgin'

2012-07-10 Thread Jiri B
On Tue, Jul 10, 2012 at 03:00:28AM -0700, srimanta kundu wrote: > Hello Sir, > > I have installed netBSD 5.1.2 via VMWare Player. But I cannot use > the 'pkgin' command there. It is shown the command not found. > Please tell how > can get that command in my netBSD? Great sir, but now go to NetBSD

<    1   2   3   4   5   6   >