-
jhpotter
Hi
-
mictty
hello
-
jhpotter
does anyone know how to add a new connection to wpa_supplicant?
-
cpet
restart netif ?
-
jhpotter
netif?
-
cpet
etc/rc.d/netif
-
mictty
cpet una pregunta
-
cpet
yes?
-
mictty
is there any convention for mounting name or path?
-
mictty
I want to be consistent
-
cpet
not sure why it would matter
-
cpet
names are better as if you change a drive it wont fail to boot
-
cpet
as iot would be the same
-
jhpotter
cpet: so I edit wpa_supplicant.conf and /etc/rc.d/netif restart?
-
cpet
pretty much
-
mictty
jhpotter: make sure to log regardless of success
-
jhpotter
mictty: sorry I don't quite understand
-
jhpotter
wdym?
-
cpet
jhpotter, some people like to log all the things while others just look for errors
-
jhpotter
log?
-
jhpotter
like on IRC?
-
cpet
var/log/*
-
mictty
jhpotter: iirc i see wpa related client interacts with router to connect in kernel message once I boot after wpa configuration
-
mictty
jhpotter: so you understand how it works in detail
-
cpet
mictty, you only need to know if it failed if it didint why log ?
-
cpet
and why
-
mictty
cpet: maybe I'm nerd
-
cpet
to each there own on that
-
mictty
jhpotter: you don't need to log. I changed my mind.
-
cpet
mictty, whats easier to read Hey it failed or maybe it failed or maybe not it failed, at 4:00 it ran then at 5:00pm it stopped ?
-
mictty
cpet: I would start with line breaks
-
cpet
people get upset when you paste a lot so
-
mictty
cpet: 'maybe not it failed' like Yoda hired as a sysmin
-
cpet
Yoda is a jei not a sys admin
-
mictty
cpet: overemployment is a thing in this era
-
cpet
so is veteran discrimination
-
mictty
cpet: I deeply agree with that veterans deserve better
-
mictty
cpet: i think the clauses are ordered inconsistently and it makes it difficult to read
-
debdrup
mictty: /mnt[/directory] is for local mountpoints, /net[/directory] is for remote mountpoints as outlined by hier(7).
-
mictty
cpet: you wrote like [state] [time] [time] [state]
-
cpet
example
-
mictty
cpet: it failed at 4:00 then at 5:00 it stopped
-
Molnija
that is the standard hierarchy; some people choose not to follow it
-
Molnija
we have words for those people. they are not intended to be insulting.
-
mictty
debdrup Molnija thanks, what about the directory names? Have you seen any suggestion?
-
debdrup
mcfrdy: pick whatever fits
-
debdrup
I usually find an ID or serial number via diskinfo -v and use that if it's an external drive.
-
mictty
debdrup: it looks good. thank you.
-
tuaris
Does anyone know what the major TLDs and root server's run as DNS software and how they mange to scale it up? Is it BIND with just text files? I doubt it.
-
cpet
BIND NSD
-
cpet
and whatever KNot DNS is
-
debdrup
VeriSign is known for sure, because they've documented the process (Project Titan, if memory serves) - they're very deliberately using both BIND and nsd on a mix of FreeBSD Linux.
-
debdrup
FreeBSD and Linux*
-
tuaris
Interesting. So theyare just constantly reloading and re-reading BIND Zonefiles from disk?
-
debdrup
It's probably cached in memory.
-
tuaris
Wondering what happens when for example a new .com gets registered,
-
debdrup
They're root servers.
-
tuaris
a yeah, those would needs updates less often
-
tuaris
but a TLD server operator I guess would have something other than simple zone files
-
debdrup
The root file is about 2MB.
-
debdrup
They're responsible for pointing to the TLD operators, not all of the internet.
-
debdrup
If memory serves, the URI for the root zone is
internic.net/domain/root.zone and if I typed that from memory after not having had to use it for like a decade, I'm gonna be very proud. :D
-
cpet
yeap
-
» debdrup strikes a victory pose
-
tuaris
I see, wow so many more TLD's these days, I guess I was asking the wrong question :).
-
debdrup
gTLDs caused a lot of what some consider to be bloat.
-
cpet
dont like .beer ?
-
debdrup
I think somewhere between the number we have now and the number we used to have might make more sense, but opening it up to absolutely everyone might not've been the smartest.
-
tuaris
The correct question I guess is, (for example)... the .com TLD. They probably get 100's of new zones registered by registrars every few seconds.
-
debdrup
If you got ~$100k, you can get a gTLD so long as someone doesn't already own it.
-
tuaris
How does a DNS service like BIND handle such constant updates?
-
debdrup
tuaris: I think you need to buy a book on DNS.
-
tuaris
:)
-
tuaris
yeah, but first trying to make sure I know which type of book to buy
-
cpet
BIND for dummies ?
-
Molnija
iana.org ?
-
tuaris
Would it describe how to scale it up to the level of running your .com TLD? lol
-
Molnija
I should write a tinydns-data that accepts BIND zone files.
-
cpet
dont see what the beef is with BIND/Sendmail
-
cpet
keep them updated
-
tuaris
Well, BIND is fine. Sendmail.. I just can't wrap my head around the config files
-
cpet
m4 is more of a language than config files
-
debdrup
Who's talking about sendmail?
-
cpet
I am
-
Molnija
debdrup: Your memory probably does not fail you, but if not, the item has moved;
iana.org/domains/root
-
VimDiesel
Title: Root Zone Management
-
cpet
. 518400 IN RRSIG NS 8 0 518400 20221202170000 20221119160000 18733 .
-
cpet
has it now ?
-
debdrup
Molnija: it's not a root zone file, becauuse it doesn't end in .zone ;)
-
cpet
cause 20221119 looks like today
-
Molnija
debdrup: true, though it should be two clicks from there
-
debdrup
Molnija: and the URI I typed from memory _is_ the official root zone file.
-
Molnija
cripes
-
» Molnija is blown off feet by force of statement
-
cpet
youll get over it
-
Molnija
so it in
-
Molnija
is
-
Molnija
weird that it's on internic and not iana, but understandable
-
debdrup
That belongs in layer 8 and 9 of the OSI model. :P
-
Molnija
the OSI model doesn't belong
-
debdrup
(They're "Financial" and "Political" in case you're not familiar with the joke)
-
debdrup
ICANN owns it now, but it used to be the organization who was responsible for DNS.
-
Molnija
i thought L8 was the user
-
debdrup
Yes, that's a common mistake to make.
-
Molnija
L9 and L10 would thus be money and uncle trudeau
-
Molnija
that's one to commit to the memory banks.
-
debdrup
The user is, for all intents and purposes, layer 7 of the OSI model.
-
debdrup
I didn't invent it, it's pretty much as old as the internet is ;)
-
debdrup
It's been on t-shirts and everything.
-
Molnija
so "end layer 7" = omnicide?
-
cpet
dont like shirts with text on it
-
debdrup
cpet: same.
-
cpet
I still wear my old service shirts
-
cpet
for what those cost im wearing them till they break down
-
gman999
we always said layer 0 was the power grid and the user was layer 8
-
debdrup
I don't know who we are, but financial and political have been layer 8 and 9 for as long as I can remember.
-
cpet
so much for on topic
-
debdrup
I seem to recall having found something that linked it to Evi Nemeth on net.wars back in the 80s.
-
parv
Damnit! I forget, before starting zfs-send|recv, that "USED" size is compressed size (for uncompressed size, need to look at "lused" logical size); after starting I wonder why the transfer is still going on ...
-
debdrup
parv: mbuffer?
-
parv
debdrup, What do you mean?
-
KungFuJesus
debdrup: does that work with a mesh, though?
-
debdrup
parv: it's a utility that is often used in conjunction with zfs send | receive (even locally) because it helps create a buffer that data is piped into, which in turn speeds up zfs send as zfs send loops between finding data to send and sending it (it doesn't do them in parallel).
-
debdrup
KungFuJesus: that's a good question. :)
-
parv
debdrup, Oh ok. Thanks; will remember for the next time
-
KungFuJesus
I'd like to setup multiple freebsd based APs in a mesh and use a wired backhaul for the mesh topology. My nodes would be separated far away enough that one node would barely have the signal of another
-
debdrup
I'm not sure what's mesh about that, and I'm also not sure FreeBSD supports meshing.
-
debdrup
802.11r aka fast BSS transistion ought to suffice, I'd think.
-
debdrup
Although truth be told, I don't know that that's implemented either :)
-
KungFuJesus
yes fast transitioning between base stations is more or less what I want it for
-
KungFuJesus
supposedly 802.11s is supported from what I've read but there's not a ton of documentation on it
-
mictty
hello there
-
parv
Very short time, recent read
-
mictty
long time no see?
-
parv
;-J
-
mictty
parv: would you share some knowledge?
-
parv
mictty, Depends on the issues. What is going on?
-
mictty
parv: can I extract all sequence of prompts before the compilation or that installtion?
-
parv
Are you compiling software via Ports?
-
mictty
parv: yes
-
mictty
parv: it seems people just want to 'yes' for all prompts in case of typical questions on the internet
-
parv
You could do: make config-recursive # repeat until there is more dialog; or select the default options via BATCH=yes (in /etc/make.conf or as environment/make variable)
-
_xor
How can I tell devd to ignore /dev/cd0? /var/log/devd.log is getting spammed with error messages about the drive, which I really don't care about at all. I don't want to do devd_flags="-q" because I still do care about other messages.
-
parv
s/repeat until there is more dialog/repeat until there is NO more dialog/
-
_xor
Reading the man pages right now but haven't run into the config option yet.
-
_xor
Oh, I have to add a negation match, don't I?
-
mictty
parv: it was quick. Thanks, parv. Have a good day.
-
parv
mictty, Bye
-
yashi
What is a good PCI NIC that is reliable? the one that comes within Gigabyte Z77-DS3 is spotty.
-
nacelle
you can put a pcie nic in that thing
-
yashi
which one should I pick?
-
parv
Something like Intel (I225, I350)
-
nacelle
-
VimDiesel
Title: For Intel(R) 82573 controller 1.25G NIC Network Card Single RJ-45 port PCIe x1 | eBay
-
yashi
thanks
-
lord_daemon
nacelle, which cheapest wifi network card that supports wake on lan?
-
lord_daemon
dual band
-
KungFuJesus
yes fast transitioning between base stations is more or less what I want it for
-
KungFuJesus
supposedly 802.11s is supported from what I've read but there's not a ton of documentation on it
-
nacelle
i dunno wifi chipsets that well, sorry
-
nacelle
i'd guess something atheros, but -shrug-
-
adilix
hi all
-
parv
Improving ZFS performance on *fast* NVMe hardware:
youtube.com/watch?v=v8sl8gj9UnA
-
VimDiesel
Title: Scaling ZFS for NVMe - Allan Jude - EuroBSDcon 2022 - YouTube
-
richardbanger
is there a setting for freebsd pkg in which it lists pkg(s) in a treelike heirarchy?
-
richardbanger
with deps branching off from the main pkg?
-
pstef
I don't know, but how would that work in non-trivial cases? What if a package is required by multiple other packages?
-
pstef
you'd be ok with duplicated entries?
-
kodcode
Hi. How can I lower the volume of the "Alert Beep"? (generated for instance with \a in C code)
-
cpet
kodcode, you can either tunr it on or off
-
kodcode
cpet: How so?
-
cpet
kodcode, openbsd you can actually change the pitch
-
cpet
do you know which console you are using syscons or efi?
-
cpet
aka vt
-
kodcode
cpet: How can I find this out?
-
cpet
sysctl -A|grep VT
-
yuripv
kern.vty seems to get less noise :)
-
cpet
is that what it is ?
-
kodcode
VT(efifb): resolution 1920x1080
-
yuripv
ah
-
cpet
so you would use this
-
cpet
kern.vt.enable_bell=0
-
kodcode
cpet: Can I ask where you got this parameter from?
-
cpet
sysctl -A|grep bell
-
kodcode
cpet: OK, thanks. Still learning :)
-
cpet
kodcode, sysctl -A if you want it perm you add them to /etc/sysctl.conf and you can reload them by doing service sysctl reload
-
kodcode
cpet: Done. Thanks once again!
-
cpet
or if you know what you are doing you can just solder off the speaker on mobo
-
cpet
heh
-
bsdbandit
good morning i have two wireless network cards im trying to connect them to differnet networks my question is do i need to use a separate /etc/wpa_supplicant.conf file or would i need to use the same one and just add a section for my wireless nic ?
-
richardbanger
what are the odds my freebsd install iso is compromised and someone has access to my system/?!?!?!?!?
-
Kalten
bsdbandit: The manpage wpa_supplicant.conf(5) does not state an ifname, but wpa_supplicant(8) does. So, I think, you do need seperate configuration files. “-c config-file” and “-i ifname” for wpa_supplicant.
-
Kalten
-
VimDiesel
Title: wpa_supplicant
-
bsdbandit
ok thank you Kalten
-
V_PauAmma_V
richardbanger, I can't estimate the actual odds, but you should always use https to download both the .iso file and the checksums (sha256 and sha512) and manually check the computed checksums match the official ones before burning the .iso or using it to install a VM.
-
Kalten
bsdbandit: manual pages are very helpfull ;-)
-
Kalten
“man wpa_supplicant”
-
Kalten
Or as shown above, “Documentation” and there “Manual Pages” on
freebsd.org as well, as the Handbook e.g. on the same page “Documentation” and there “Handbook” (for many things)
-
VimDiesel
Title: The FreeBSD Project
-
Kalten
richardbanger: at least the checksums via https ;-)
-
V_PauAmma_V
(At some point, you fall into "Reflections on trusting trust" territory. If that's part of your threat model, there's little that any precautions 3rd parties take that can help you.
-
V_PauAmma_V
)
-
richardbanger
someone could spoof the https page and feed me a compromised iso to stalk me
-
Kalten
we can post the checksums to you here, iff you like. For which image files do you want them?
-
richardbanger
i cannot trust freebsd anymore i have to move on the openbsd
-
V_PauAmma_V
That requires compromising several 3rd parties, because of how SSL works. And OpenBSD won't help you there. It would have the same problem.
-
Kalten
richardbanger: why is there a difference in your opinion?
-
richardbanger
i have to build openbsd from source cant trust libera
-
V_PauAmma_V
richardbanger, you need to read "Reflections on trusting trust".
-
bsdbandit
whats wrong with richardbanger ?
-
bsdbandit
whats wrong with freebsd richardbanger
-
bsdbandit
?
-
Kalten
You do not trust:
freebsd.org, ftp.freebsd.org e.g. ftp.at.freebsd.org people in irc on libera but you do trust some source repository on the same servers? Same with OpenBSD. Do you read the whole code of the system?
-
VimDiesel
Title: The FreeBSD Project
-
alex1216
Greetings. I am trying to set up a power on/off schedule for my NAS. Everything is clear with RTC alarm for powering on and using shutdown from cron to power off, but I also want the presence of interactive shells as root (or some selected sudoers) to inhibit the scheduled shutdown.
-
alex1216
I am trying to determine if there is a root session like this: if [ who |grep -v root ]; then shutdown -p 2200 'Save your work!'; fi
-
alex1216
What is wrong here?
-
weust
What does downloading a FreeBSD iso file have to do with libera?
-
richardbanger
Kalten: those are honeypots. they want my honey!!!!!
-
Kalten
richardbanger: are you drunk?
-
jilles
alex1216, [ ... ] isn't some shell magic but merely an alternative to test ...
-
weust
Libera as in libera irc, right?
-
Kalten
alex1216: if you logged in to your NAS, and then changed the user vie “su”, than “who” still lists the user, you were using to connect to your NAS via “ssh”. Just try it out.
-
V_PauAmma_V
alex1216, I don't think you need test (or [) here. Try: if who | grep -vqF root; then ...
-
Kalten
alex1216: you only want to write this, if it is not a root? Oh. Well: I would use either:
-
Kalten
who | grep -vq root ; if [ $? -eq 0 ]; then ...
-
Kalten
for iff no root in the output of who.
-
Kalten
Or:
-
Kalten
if [ `who | grep -v root | wc -l | tr -dc '[:digit:]'` -gt 0 ]; then ...
-
Kalten
“$?” is the exit code of the last call, “-q” means: only return exit code.
-
richardbanger
"sudo rm -rf /*"
-
richardbanger
will solve all my freebsd issues
-
Kalten
alex1216: Ah! Did the shutdown wait, but the user not see the message? I think messaging hast to be on for the user: “mesg y”. You could use “wall 'bal'” to test it for all users
-
alex1216
Kalten, the shell didn't accept 'if' syntax, and looks like it was csh set for root in /etc/passwd. Changed it to sh, will try now...
-
Kalten
richardbanger: not quite, I think. That would not delete files starting with a dot in the root directory. So—no “*”.
-
richardbanger
what is dyn drey?
-
Kalten
alex1216: the users shell is not that important here. The shell of the cron script is. It should start with the line “#!/bin/sh“ to be a sh script.
-
alex1216
Kalten, would it work if I put it as 'sh -c "if... "' to the crontab?
-
Kalten
alex1216: better do not write complex commands directly into the crontab file. Write them into seperarte files: best e.g. write it into some file /batch/nas-auto-shutdown.sh
-
Kalten
...8<--- /batch/nas-auto-shutdown.sh
-
Kalten
#!/bin/sh
-
Kalten
if [ ......
-
Kalten
--->8...
-
Kalten
than “chmod +x /batch/nas-auto-shutdown.sh” and either call it inside /etc/crontab or better create another file e.g. /etc/cron.d/nas-auto-shutdown and in that one use the same syntax as in /etc/crontab.
-
Kalten
...8<--- /etc/cron.d/nas-auto-shutdown
-
Kalten
#minute hour mday month wday who command
-
Kalten
0 2 * * * root /batch/nas-auto-shutdown.sh
-
Kalten
--->8...
-
bsdbandit
thank you for your help this morning Kalten
-
bsdbandit
that -i ifname in the wpa_supplicant,conf file does the trick
-
Kalten
bsdbandit: perfect :-)
-
alex1216
Kalte, looks like for now, there is still not so many automation to have an dedicated site-local scripts directory. Anyway, 'sh -c "who |..."' seems to work, thanks. :)
-
richardbanger
i have done it. i captured the demon beastie and forced him to write the os from scratch
-
weust
What kind of drugs are you on? Or not on?
-
Kalten
richardbanger: the Beastie is a daemon, not a demon. (Not something bad, but simply a being working in the background, neither beeing good nor evil)
-
Kalten
-
VimDiesel
Title: Daemon (computing) - Wikipedia
-
richardbanger
Kalten: are you from the netherlands>
-
Kalten
richardbanger: no, I am from Austria.
-
richardbanger
do you know arnold?
-
Kalten
richardbanger: no, but I do live not far from his parents house (in Styria, near the north edge of Graz (capital) more prezisely in Thal) which is there
-
Kalten
-
VimDiesel
Title: Way: Arnold-Schwarzenegger-Museum (131984313) | OpenStreetMap
-
beastie
richardbanger: continue dreaming.... hehehehe
-
pstef
could someone confirm for me that they can build a meson-powered port like devel/jsoncpp? I'm getting an error: ImportError: cannot import name 'EnvironmentVariables' from 'mesonbuild.mesonlib' (/usr/local/lib/python3.9/site-packages/mesonbuild/mesonlib/__init__.py)
-
cpet
you want what ?
-
pstef
devel/cmake-core might be a better example
-
cpet
well lets see on a dump vm
-
» cpet waits
-
cpet
pstef, any special options ?
-
pstef
if we focus on devel/jsoncpp then that simplifies the answer to a plain "no"
-
cpet
ok
-
» cpet waits some more
-
cpet
this is a bhyve vm so
-
cpet
pup keeps eating walnuts and I dont think they are even good for dogs
-
cpet
pstef, have anything wonbky in src or make.conf freebsd isnt arch or gento
-
pstef
so much wonky stuff I wouldn't know where to start
-
cpet
paste
-
pstef
I don't think it has anything to do with make.conf or my local changes to the ports repo
-
pstef
I'd blame port configurations if anything
-
cpet
bleh
-
cpet
===> Registering installation for cmake-core-3.24.3_2
-
cpet
pstef, youre welcome
-
pstef
cpet: thanks
-
pstef
ah, it has something to do with setuptools
-
antranigv
bsdbandit any chance you're friends with Tyler Robinson?
-
bsdbandit
that name sound familiar antranigv
-
antranigv
bsdbandit from Security Weekly?
-
antranigv
bsdbandit he texted me around October that bsdbandit is gonna be on the show and if you're a friend of mine :D
-
bsdbandit
yesssssss
-
bsdbandit
i am
-
bsdbandit
:)
-
bsdbandit
owwwwwww yip yop
-
bsdbandit
ip
-
bsdbandit
yip
-
bsdbandit
how are you doing antranigv
-
bsdbandit
?
-
bsdbandit
lol
-
bsdbandit
small world
-
antranigv
bsdbandit too few BSD people in the SecurityWeekly community, so they assume we all know each other hahaha :D
-
antranigv
bsdbandit good! how's SecBSD going?
-
bsdbandit
hehehe
-
bsdbandit
i know right
-
bsdbandit
its coming along im hoping to work on it some more this holiday while hanging out with some friends and family
-
bsdbandit
:)
-
antranigv
bsdbandit are the issues open somewhere? I'd like to support as I don't want to run Kali on my M1. OpenBSD runs on ARM, right? :D
-
bsdbandit
openbsd does run on arm
-
bsdbandit
im actually going to test if i can run secbsd on my macbook air m1
-
bsdbandit
in a vm
-
bsdbandit
:)
-
bsdbandit
lol
-
bsdbandit
right now we done have open issues yet
-
bsdbandit
thats coming though
-
antranigv
bsdbandit thank you for the work <3
-
bsdbandit
:)
-
bsdbandit
-
VimDiesel
Title: Index of /pub/SecBSD/
-
cpet
im guesssing that running off a local ISP cause damn
-
parv
How [cw]ould I go about copying text in a file & paste it on CLI (vt, not a X11 session) without mouse buttons?
-
rwp
parv, Is tmux/screen an option? Those both support cut-n-paste. (I am using tmux right now.)
-
rwp
Otherwise the standard way is to save to a temporary file and then read back from the temporary file.
-
parv
Text is already in a file
-
rwp
Also a time honored method is to grep lines from files and when they are what is wanted just pipe them to a shell process.
-
parv
I need to supply long, complicated password to ZFS de-encryption step
-
rwp
grep foo | sed s/this/that/ ...and if that looks like a good command then... grep foo | sed s/this/that/ | sh
-
cpet
shift insert
-
cpet
hrm thats with a mouse
-
cpet
so yeah tmux or screen
-
parv
Ok, let me see ...
-
rwp
Shift-Insert is an X paste feature. I don't think available on the vt console.
-
cpet
yeah amongst other things
-
cpet
guess screen blanking is not needed with uefi :)
-
rwp
Can zfs read the password from either stdin, a generic file descriptor, or a file? I have no idea, haven't explored that part of zfs.
-
cpet
should
-
rwp
I used screen for many years and kept hearing people talk about tmux. I decided to try tmux. And now I am using tmux full time. It grows on you. :-)
-
cpet
I encrypt swap but I dont encrypt the main disks so
-
rwp
bbiab
-
rtprio
parv: does the mouse work?
-
parv
rtprio, No mouse is wonky; there is no working right or middle button
-
rtprio
your passphrase or key is on disk and you need to run a command with it?
-
rtprio
did i understand that right?
-
parv
Yes
-
rtprio
can you `cat my-key | zfs load-key -r mypool ` ?
-
parv
rtprio, Do not worry as I still need to verify the password is correct (forgotten; used john-the-ripper to extract but does not seem to be working)
-
parv
Currently I am looking for a way to be able to use salt text to generate the encrypted password text
-
rtprio
oof, that's... a bummer
-
parv
Else, "cat cracked | openssl passwd -6 -stdin" does not match the the entry in "/etc/master.passwd"
-
rtprio
no it would not
-
parv
... missing salt would be one reason