[qubes-devel] Re: Xen 4.10/4.11 for Qubes 4.1

2018-05-16 Thread Simon Gaiser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Marek Marczykowski-Górecki: > Hi Simon, > > I'd like to start merging things for Qubes 4.1, but for that, I need > a new branch in vmm-xen repo. I consider using 4.11 for that - it is > still in rc phase, but until we'll be anywhere near R4.1, Xen 4

[qubes-devel] qubes-iptables not starting properly

2018-05-16 Thread Elias Mårtenson
After my most recently upgrade of dom0 and all templates on my Qubes 4 installation (two days ago), I started facing the following problem: After booting the system, all networking is down. I traced the problem to sys-firewall failing to start qubes-iptables: = [user@sys-fir

Re: [qubes-devel] qubes-iptables not starting properly

2018-05-16 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, May 16, 2018 at 06:11:26AM -0700, Elias Mårtenson wrote: > After my most recently upgrade of dom0 and all templates on my Qubes 4 > installation (two days ago), I started facing the following problem: > > After booting the system, all netwo

Re: [qubes-devel] qubes-iptables not starting properly

2018-05-16 Thread Elias Mårtenson
On 16 May 2018 at 21:14, Marek Marczykowski-Górecki < marma...@invisiblethingslab.com> wrote: ... this log is from 20:47:38. > > See for earlier log entries. > You are right. I'm stupid. Here's the relevant log. There was indeed an error: May 16 20:44:47 sys-firewall qubes-iptables[417]: iptabl

Re: [qubes-devel] PSA: keep your code signing keys inaccessible to email clients

2018-05-16 Thread Joe
On 05/14/2018 05:30 PM, Jean-Philippe Ouellet wrote: On Mon, May 14, 2018 at 11:26 AM, Holger Levsen wrote: On Mon, May 14, 2018 at 11:20:29AM -0400, Jean-Philippe Ouellet wrote: The immediate impact on Qubes developers is that one should use separate keys… or simple use an email client whic

Re: [qubes-devel] PSA: keep your code signing keys inaccessible to email clients

2018-05-16 Thread Konstantin Ryabitsev
On 05/16/18 10:53, Joe wrote: > But in any case gpg signing is pretty tricky. > For instance the "clearsign" thing is basically worthless. You will have to explain such statements, please. Regards, -- Konstantin Ryabitsev Director, IT Infrastructure Security The Linux Foundation -- You receive

Re: [qubes-devel] PSA: keep your code signing keys inaccessible to email clients

2018-05-16 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, May 14, 2018 at 11:37:03AM -0400, Jean-Philippe Ouellet wrote: > On Mon, May 14, 2018 at 11:28 AM, Konstantin Ryabitsev > wrote: > > On 05/14/18 11:20, Jean-Philippe Ouellet wrote: > >> Shouldn't be terribly surprising to this crowd, but: ht

Re: [qubes-devel] qubes-iptables not starting properly

2018-05-16 Thread Marek Marczykowski-Górecki
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Wed, May 16, 2018 at 09:17:42PM +0800, Elias Mårtenson wrote: > On 16 May 2018 at 21:14, Marek Marczykowski-Górecki < > marma...@invisiblethingslab.com> wrote: > > ... this log is from 20:47:38. > > > > See for earlier log entries. > > > > You a