Andreas Thulin | 1 Sep 15:14 2015

How to create "paranoid" cipher list in httpd.conf

Hi misc readers!

This is my first attempt to ask for help using misc <at>, so please
bear with me if I'm making mistakes. Also, apologies if I'm asking about
something recently discussed.

I want to limit the number of tls ciphers​ in httpd.conf so that only
strong (>128 bit) ciphers with Forward Secrecy capabilities (ECDHE) are
accepted. I'm also only using TLSv1.2.

My current httpd.conf contains a line saying

tls ciphers "STRONG:ECDHE:!aNULL:!SSLv3: <at> STRENGTH"

which renders out "Configuration OK" with '# /usr/sbin/httpd -n'.
Also, when testing that string using

# openssl ciphers -v 'STRONG:ECDHE:!aNULL:!SSLv3: <at> STRENGTH'

I get a nice, acceptable list of the ciphers. However, when running a
server test
there's a much longer list of ciphers, including both non-FS and medium
strength ciphers.

I'm thinking that either

   1. my assumption that my httpd.conf is all dandy is wrong (highly
   2. SSL Labs is lying to me (improbable), or
Quartz | 1 Sep 04:38 2015

pf vs mp

Quick question: I need to make a decision between a faster single core 
and a slower multicore. The faq currently states that pf gets no 
improvement from mp. Is this still correct/current information? 
Presumably it would see no benefit from hyperthreading either, right?

For an OpenBSD machine acting as a gateway/firewall/router with a 
handful of related tasks (pf, dhcp server, etc) would mp yield anything?

Gabriel Kuri | 1 Sep 02:04 2015

Multiple Instances of NSD

In migrating from bind to nsd, I currently have split views in bind and
need to run multiple instances of nsd to accomplish the same thing. What's
the best way to start multiple instances of nsd? I tried copying
/etc/rc.d/nsd to /etc/rc.d/nsd-internal and in the rc script I changed
daemon_flags to "-c /var/nsd/etc/nsd-internal.conf" to reflect the new
config name, but it doesn't work, that instance of nsd doesn't start and
there's no errors in /var/log/daemon and I have no idea why it's not
starting. I also updated nsd-internal.conf to use a different port,
different PID file and DB name, so they wouldn't conflict with the primary
instance of nsd, but no luck.

Anyone else running multiple instances of nsd, if so, what did you do to
get it to work?

sven falempin | 31 Aug 22:04 2015


"eeprom" at iic0 addr 0x50 not configured : huh ?

"Intel Bay Trail TXE" rev 0x0e at pci0 dev 26 function 0 not configured :
what ?

OpenBSD 5.8 (GENERIC) #254: Fri Aug 14 04:59:16 EDT 2015
real mem = 4152320000 (3959MB)
avail mem = 4022620160 (3836MB)
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: SMBIOS rev. 2.8  <at>  0xe9570 (14 entries)
bios0: vendor American Megatrends Inc. version "BAR3NA01" date 08/11/2015
bios0: NF533 NF533
acpi0 at bios0Entering acpi matching devices!!!: rev 2
acpi0: sleep states S0 S3 S4 S5
acpi0: wakeup devices XHC1(S4) EHC1(S4) PXSX(S4) PXSX(S4) PXSX(S4) PXSX(S4)
acpitimer0 at acpi0: 3579545 Hz, 24 bits
acpimadt0 at acpi0 addr 0xfee00000: PC-AT compat
cpu0 at mainbus0: apid 0 (boot processor)
cpu0: Intel(R) Celeron(R) CPU J1900  <at>  1.99GHz, 2000.45 MHz
cpu0: 1MB 64b/line 16-way L2 cache
cpu0: smt 0, core 0, package 0
Atanas Vladimirov | 31 Aug 20:35 2015

ddb.html typo

Index: ddb.html
RCS file: /home/vlado/cvsync/cvsroot/www/ddb.html,v
retrieving revision 1.3
diff -u -p -r1.3 ddb.html
--- ddb.html	30 Aug 2015 17:32:13 -0000	1.3
+++ ddb.html	31 Aug 2015 07:50:13 -0000
 <at>  <at>  -16,7 +16,7  <at>  <at> 

 <h3><font color="#0000e0">Minimum information for kernel problems</font></h3>

-Familiarize yourself with <a href="reports.html">the general bug reporting 
+Familiarize yourself with <a href="report.html">the general bug reporting 
  first. All of that will apply.

 When reporting a kernel panic or crash, please remember:

Craig Skinner | 31 Aug 11:52 2015

[DIFF] user & group delete named in upgrade57.html

Hi there,

BIND is binned.

--- upgrade57.html	Mon Aug 31 10:44:41 2015
+++ upgrade57-del-named.html	Mon Aug 31 10:46:46 2015
 <at>  <at>  -495,6 +495,8  <at>  <at>  rm -r /var/tmp
 ln -s /tmp /var/tmp

 groupdel _lkm
+userdel named
+groupdel named
 userdel smmsp
 groupdel smmsp

Adam Jeanguenat | 31 Aug 15:54 2015

doas(1) and $PATH inheritance...

I'm not sure where I'm going wrong here, but I've been giving doas(1)
a whirl and ran into something that's left be a bit puzzled.

I have some scripts in ~/bin, and my user account has PATH set
as desired. I can run things out of that dir as expected without
invoking doas, but attempting to prefix the command with doas in the
same manner I previously did with sudo doesn't seem to work.

Without doas:

   $ ls -lA ~/bin
   total 8
   -rwxr-xr-x  1 avj  avj  22 Aug 26 11:31 testes
   $ cat ~/bin/testes
   echo testes, testes, 123
   $ echo $PATH
   $ which testes
   $ testes
   testes, testes, 123

With doas:

   $ cat /etc/doas.conf
   permit nopass keepenv { PATH PS1 SSH_AUTH_SOCK } :wheel
   $ id
   uid=1001(avj) gid=1001(avj) groups=1001(avj), 0(wheel)
   $ doas which testes
Patrick | 30 Aug 23:29 2015

Re: OpenBSD on Fiber

Patrick | 30 Aug 20:08 2015

OpenBSD on Fiber


I have a fiber internet connection with 500Mbs download and 500Mbs upload.
I installed a long time ago a firewall with OpenBSD 5.5 with routing and
PF. But after a speedtest the line is stuck at around 200Mbs. Even when i
download a test bin the speed is around 17Mbs. After this experience i had
FreeBSD installed which doing fine with my fiber network. I have tested 5.6
and 5.7 and even 5.8 for testing any improvements in the network speed.
Does anybody now what can cause this problem? Below i have my specs posted:

*Hardware / OS*
HP DL380 G6
vSphere ESXI 6 (Updated to last patches)

Virtual Machine 11 (Also tried 8)
Type: Other 32Bit / Other 64Bit And FreeBSD 64bit same results
1 CPU & 1 core

*What i have tried (This all had no results)*
Upgrade the virtual machine hardware.
Forward the network cards from pci slots to the VM
Different ethernet adapters, VMXNET3 is still the best which is getting the
highest speeds.
Add system tweaks in sysctl.conf & disabling PF
Use other versions of OpenBSD 32Bit / 64Bit.

Best Regards,

Alessandro DE LAURENZIS | 30 Aug 13:12 2015

disklabel(8) "disk" and "label" fields

Dead misc <at>  readers,

This is the output of disklabel(8) for a USB key with 2 partitions (one
FAT32 and one OpenBSD):

# /dev/rsd1c:
type: SCSI
disk: SCSI disk
label: USB 2.0 FD      
duid: 55c000a328c876de
bytes/sector: 512
sectors/track: 63
tracks/cylinder: 255
sectors/cylinder: 16065
cylinders: 487
total sectors: 7831552
boundstart: 5242880
boundend: 7340032
drivedata: 0 

16 partitions:
#                size           offset  fstype [fsize bsize  cpg]
  a:          2097152          5242880  4.2BSD   2048 16384    1 
  c:          7831552                0  unused                   
  i:          4194304               64   MSDOS                   

Just curious: how to change "disk" (SCSI disk) and "label" (USB 2.0 FD)
