Stuart Henderson | 1 May 2013 15:42
Picon
Favicon

OpenBSD 5.3 released May 1, 2013

------------------------------------------------------------------------
- OpenBSD 5.3 RELEASED -------------------------------------------------

May 1, 2013.

We are pleased to announce the official release of OpenBSD 5.3.
This is our 33rd release on CD-ROM (and 34th via FTP).  We remain
proud of OpenBSD's record of more than ten years with only two remote
holes in the default install.

As in our previous releases, 5.3 provides significant improvements,
including new features, in nearly all areas of the system:

 - Improved hardware support, including:
    o New driver oce(4) for Emulex OneConnect 10Gb Ethernet adapters.
    o New driver rtsx(4) for the Realtek RTS5209 card reader.
    o New driver mfii(4) for the LSI Logic MegaRAID SAS Fusion controllers.
    o New driver smsc(4) for SMSC LAN95xx 10/100 USB Ethernet adapters.
    o New drivers for Toradex OAK USB sensors: uoaklux(4) (illuminance),
      uoakrh(4) (temperature and relative humidity) and
      uoakv(4) (+/- 10V 8channel ADC).
    o New drivers for virtio(4) devices: vio(4) (network), vioblk(4)
      (block devices, attaching as SCSI disks) and viomb(4)
      (memory ballooning).
    o Support for Adaptec 39320LPE added to ahd(4).
    o Broadcom 5718/5719/5720 Gigabit Ethernet devices supported in bge(4).
    o Intel X540-based 10Gb Ethernet devices supported in ix(4).
    o Support for SFP+ hot-plug (82599) and various other improvements
      in ix(4).
    o TX interrupt mitigation, hardware VLAN tagging and checksum offload
(Continue reading)

Todd C. Miller | 3 Apr 2013 17:32
Favicon

upcoming OpenBSD mailing list downtime

The OpenBSD mailing lists will be down on Saturday April 20th from
05:30 through 18:00 MDT while the machine room the server lives in
is under maintenance.

This also affects ftp.usa.openbsd.org (aka anoncvs3.usa.openbsd.org)
which is located in the same place.

 - todd

Damien Miller | 22 Mar 2013 01:40
Picon
Favicon

Announce: OpenSSH 6.2 released


Changes since OpenSSH 6.1
=========================

This release introduces a number of new features:

Features:

 * ssh(1)/sshd(8): Added support for AES-GCM authenticated encryption in
   SSH protocol 2. The new cipher is available as aes128-gcm <at> openssh.com
   and aes256-gcm <at> openssh.com. It uses an identical packet format to the
   AES-GCM mode specified in RFC 5647, but uses simpler and different
   selection rules during key exchange.

 * ssh(1)/sshd(8): Added support for encrypt-then-mac (EtM) MAC modes
   for SSH protocol 2. These modes alter the packet format and compute
   the MAC over the packet length and encrypted packet rather than over
   the plaintext data. These modes are considered more secure and are
   used by default when available.

 * ssh(1)/sshd(8): Added support for the UMAC-128 MAC as
   "umac-128 <at> openssh.com" and "umac-128-etm <at> openssh.com". The latter
   being an encrypt-then-mac mode.

 * sshd(8): Added support for multiple required authentication in SSH
   protocol 2 via an AuthenticationMethods option. This option lists
   one or more comma-separated lists of authentication method names.
   Successful completion of all the methods in any list is required for
   authentication to complete. This allows, for example, requiring a
   user having to authenticate via public key or GSSAPI before they
(Continue reading)

Bob Beck | 1 Nov 2012 17:47
Picon
Favicon

OpenBSD 5.2 Released


------------------------------------------------------------------------
- OpenBSD 5.2 RELEASED -------------------------------------------------

November 1, 2012.

We are pleased to announce the official release of OpenBSD 5.2.
This is our 32nd release on CD-ROM (and 33rd via FTP).  We remain
proud of OpenBSD's record of more than ten years with only two remote
holes in the default install.

As in our previous releases, 5.2 provides significant improvements,
including new features, in nearly all areas of the system:

 - pthreads(3) support:
   o The most significant change in this release is the replacement of the
     user-level uthreads by kernel-level rthreads, allowing multithreaded
     programs to utilize multiple CPUs/cores.
   o Use PTHREAD_MUTEX_STRICT_NP as default mutex type.
   o Added pthread spinlock and barrier routines.
   o Added pthread_mutex_timedlock(3) and sem_timedwait(3).
   o Added pthread_condattr_setclock(3).
   o Added support for live multi-threaded debugging in gdb(1).
   o Improved handling for rusage totals and interval timers in threaded
     processes.
   o Changed the RLIMIT_NPROC rlimit to count processes instead of threads.
   o Added a new system limit kern.maxthread for the max number of threads.
   o Closed race conditions in thread creation, and in fork(2) and open(2) in a
     threaded process.
   o Improved handling of threaded processes in ps(1), top(1), and fstat(1).
(Continue reading)

Todd C. Miller | 31 Oct 2012 16:35
Favicon

OpenBSD mailing list policy change

Since its inception, the OpenBSD mailing lists have allowed postings
from any address, regardless of whether or not the sender was a
member of the mailing list.  As the years have gone by, more and
more spam has gotten through, evading both grey listing and
SpamAssassin.

To address this problem, the OpenBSD list server will start requiring
that posts be made from an address that is subscribed to the mailing
list, or an address that is marked as an "alias" in the sender's
majordomo settings.  Messages that don't meet this criteria will
have to be confirmed by the sender (not the moderator) via an
automated message sent by the list server.

This change will take effect the morning of November 1, shortly
after OpenBSD 5.2 is released.

I realize that there are a number of people who post from an address
different from the one that they are subscribed with.  It is easy
to add extra addresses as "aliases" in your majordomo settings which
will allow you to post from that address without requiring confirmation.
The simplest way to do this is via the web interface at

    https://lists.openbsd.org/cgi-bin/mj_wwwusr?func=show

After logging in, if you scroll down past your subscriptions list
you will see a section titled "Other E-mail Addresses".  Simply
enter the address you wish to post from in the "Other address:" box
and click the "alias" button.

For those of you who read the lists via alternate means (web-based
(Continue reading)

Todd C. Miller | 18 Oct 2012 16:24
Favicon

OpenBSD mailing list downtime Sat October 20th

The machine room the mailing list server resides in will be undergoing
maintenance on the 20th from 5am to 7pm MDT.  As a result, the
OpenBSD mailing lists will be unavailable for part (possibly all)
of that time.

 - todd

Bob Beck | 6 Oct 2012 17:49
Picon
Favicon

OpenBSD 5.2 song - and pre-orders for 5.2!

We have made available the song that will come out
with the 5.2 release. The song and details of it are linked
from:

    http://openbsd.org/lyrics.html

Go have a look and a listen!

The details for the upcoming 5.2 release are available at

    http://www.openbsd.org/52.html

A reminder to you all that Pre-orders for 5.2 are can be made
by starting from:

    http://openbsd.org/orders.html

Please consider buying a CD or three.  Sales of CD's and merchandise
are vital to OpenBSD's continued existence.  It is only this revenue stream
that keeps the power and air conditionong on, and keeps us all hacking.

   Thanks!

Damien Miller | 29 Aug 2012 04:18
Picon
Favicon

Announce: OpenSSH 6.1 released djm <at> mindrot.org


OpenSSH 6.1 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0
implementation and includes sftp client and server support.

Once again, we would like to thank the OpenSSH community for their
continued support of the project, especially those who contributed
code or patches, reported bugs, tested snapshots or donated to the
project. More information on donations may be found at:
http://www.openssh.com/donations.html

Changes since OpenSSH 6.0
=========================

This is primarily a bugfix release.

Features:

 * sshd(8): This release turns on pre-auth sandboxing sshd by default for
   new installs, by setting UsePrivilegeSeparation=sandbox in sshd_config.
 * ssh-keygen(1): Add options to specify starting line number and number of
   lines to process when screening moduli candidates, allowing processing
   of different parts of a candidate moduli file in parallel
 * sshd(8): The Match directive now supports matching on the local (listen)
   address and port upon which the incoming connection was received via
   LocalAddress and LocalPort clauses.
 * sshd(8): Extend sshd_config Match directive to allow setting AcceptEnv
   and {Allow,Deny}{Users,Groups}
(Continue reading)

Matt Olander | 1 Jun 2012 03:28
Favicon

MeetBSD California 2012

MeetBSD California returns for its third biennial installment!

On behalf of the MeetBSD California 2012 team, it's my pleasure to
invite all of you to MeetBSD California 2012. It will take place
Saturday and Sunday, November 3rd and 4th, 2012 at the Yahoo! campus
in Sunnyvale, CA. It will feature one day of scheduled talks on
Saturday followed by one day of unConference-style community-scheduled
emergent activities on Sunday.

We’re looking forward to another engaging and interesting conference!
By combining scheduled talks and community-driven events like
lightning talks and hacking sessions, we hope that everyone will get
the most out of this year’s activities.

Registration is open now; register before June 30th to get an early
bird discount of $10 off the normal $75 entrance fee.

The conference hotel is the Sheraton Sunnyvale. A special conference
rate is available which includes complimentary wireless internet. Use
this link to reserve rooms:
https://www.starwoodmeeting.com/StarGroupsWeb/booking/reservation?id=1205228308&key=66BBA
The special conference rate expires on October 18th, so plan
accordingly.

The Conference Afterparty will be held at the Sheraton Sunnyvale in
the Sterling Ballroom on the evening of Saturday the 3rd. Be ready to
have fun and relax with your fellow hackers and enthusiasts from all
over the world!

To keep up with information about MeetBSD California 2012, follow us
(Continue reading)

Bob Beck | 1 May 2012 16:46
Picon
Favicon

OpenBSD 5.1 released May 1, 2012


- OpenBSD 5.1 RELEASED -------------------------------------------------

May 1, 2012.

We are pleased to announce the official release of OpenBSD 5.1.
This is our 31st release on CD-ROM (and 31th via FTP).  We remain
proud of OpenBSD's record of more than ten years with only two remote
holes in the default install.

As in our previous releases, 5.1 provides significant improvements,
including new features, in nearly all areas of the system:

 - Improved hardware support, including:
   o umsm(4) supports additional mobile broadband devices.
   o Non-GigE ale(4) devices can now establish link to a GigE link partner.
   o Support for Intel 82580 has been added to em(4).
   o Support for MegaRAID 9240 has been added to mfi(4).
   o Support for Nuvoton NCT6776F has been added to lm(4).
   o Support for Centrino Advanced-N 6205 has been added to iwn(4).
   o Support for SiS 1182/1183 SATA has been added to pciide(4).
   o Support for Synaptics touch pads through the synaptics(4) X.Org
     input driver is now enabled by default.
   o Support for Intel Sandy Bridge integrated graphics cards has been
     added to the intel(4) X.Org driver.
   o Assembler implementation of the AES-GCM mode for new Intel and
     future AMD CPUs has been added.
   o usb(4) probes bus after resume, improves functionality for some laptops. 

 - Generic network stack improvements:
(Continue reading)

Damien Miller | 22 Apr 2012 02:53
Favicon

Announce: OpenSSH 6.0 released


OpenSSH 6.0 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol version 1.3, 1.5 and 2.0
implementation and includes sftp client and server support.

Once again, we would like to thank the OpenSSH community for their
continued support of the project, especially those who contributed
code or patches, reported bugs, tested snapshots or donated to the
project. More information on donations may be found at:
http://www.openssh.com/donations.html

Changes since OpenSSH 5.9
=========================

This is primarily a bugfix release.

Features:

 * ssh-keygen(1): Add optional checkpoints for moduli screening
 * ssh-add(1): new -k option to load plain keys (skipping certificates)
 * sshd(8): Add wildcard support to PermitOpen, allowing things like
   "PermitOpen localhost:*".  bz #1857
 * ssh(1): support for cancelling local and remote port forwards via the
   multiplex socket. Use ssh -O cancel -L xx:xx:xx -R yy:yy:yy user <at> host"
   to request the cancellation of the specified forwardings
 * support cancellation of local/dynamic forwardings from ~C commandline

Bugfixes:
(Continue reading)


Gmane