-
demido
if i have zfs raid10 on root on 8 HDs, can i clean shut down, pull the HDs, put the HDs in a different server with the same specs, start that server up, and it'll boot up normally just like the other server did when the HDs were in that 1?
-
the_oz
depends on the mode you set up the zvol with, because they have different way of labeling the drives
-
demido
how can i check?
-
demido
the_oz
-
the_oz
Disk Installation and Labeling
-
the_oz
page 16
-
demido
ty
-
the_oz
-
demido
ah i was searching handbook
-
the_oz
yeah there are 2 books and they're both great
-
demido
page 16 was of what?
-
the_oz
16th of pages
-
demido
which book is "Disk Installation and Labeling" in?
-
the_oz
ok you must be looking in the chapters
-
the_oz
ummmmmm
-
the_oz
Chapter 0: Introduction
-
demido
ya nvm i'll wait and ask someone who isn't fucked up on drugs
-
the_oz
the one I linked
-
the_oz
Good day
-
demido
smartd offer any benefits for ufs on hardware raid?
-
dch
mzar: thanks for the PR etc for blocklist, I was skiing last week and didnt get round to it. I am not really clear how we get the new version into src/contrib/blocklist yet
-
dch
but working on it!
-
dch
demido: TLDR yes. just make sure you're using the same bootmethod (EFI or MBR) in the server bios.
-
mzar
dch: we should convince emaste to import it
-
dch
mzar: I'm hoping to learn how to do it actually
-
dch
"how hard can it be"
-
mzar
dch: I don't know
-
mzar
probably you have to do something like "blocklist merge"
-
mzar
but we have it still named "blacklist" and that's probably good
-
mzar
maybe emaste can reveal how he applies own patches after merging last version of OpenSSH
-
mzar
have to go for a walk, bbl
-
dch
-
demido
dch what's blocklist do?
-
dch
its super neat
-
dch
demido: for failed connections (like smtp, or sshd) the daemon passes the file descriptor of the failed connection to blocklistd
-
demido
is it like a generalized fail2ban for more than just sshd?
-
dch
blocklistd tracks the number of failures by IP, and if it exceeds a configurable threshold, stores the IP in a db, and updates a pf table
-
dch
I got swamped by an ssh password cracker last week, which already fails in pre-auth
-
dch
and freebsd's blocklistd doesn't accommodate that
-
demido
do you run sshd on 22?
-
dch
so I fixed that, it worked brilliantly, and a few hours later I had my bandwidth back
-
dch
nope
-
dch
2200, with custom ciphers, exclusively pubkey
-
dch
but there were a *lot* of inbound connection attempts
-
demido
so a "friend" found your custom port and started hammering?
-
dch
exactly, from many many different IPs
-
demido
fucking asshole
-
dch
its a residential ADSL line here, so it broke things
-
dch
-
dkeav
-
dch
-
dch
dkeav: that is one partial solution, I am working on distributing the blocklist IPs across all servers, and thus covering more than just 1 port/attack vector
-
dkeav
geoblocking tends to quiet things down quite a lot too
-
demido
were the IPs isolated to a single net block or totally different?
-
demido
would be nice to find the guy and beat him to death or pay a hooker with aids to fuck him
-
dkeav
"allegedly"
-
dkeav
but i like your style of vendetta
-
dch
all over the place, lots from russian, china, usa, europe, asia, "the world"
-
angry_vincent
Hi
-
voy4g3r2
hello, i recently have been working with poudriere local repository and after a reset reboot i am receiving some "odd" messages:
pastebin.com/ptcNDFT7 has anyone experienced that a poudriere local repository "started" to just NOT work anymore?
-
mzar
voy4g3r2: do you have configured mirror_type ?
-
voy4g3r2
yes, i have it as https
-
voy4g3r2
-
voy4g3r2
what is even more odd.. multiple jails that reference it, also have the same issue.. it is like the poudriere repo is "foobar"
-
mzar
voy4g3r2: do you have mirrors configured ?
-
voy4g3r2
no clue, so probably not :)
-
mzar
so remove this lin or set type to "none"
-
voy4g3r2
okay
-
mzar
does it help ?
-
voy4g3r2
nope :(
-
mzar
so something else is wrong
-
voy4g3r2
yeah.. it is updating the repository right now
-
voy4g3r2
going to come back in a few hours.. it was working.. then it was not
-
voy4g3r2
thanks for the tips.. i am going to do some more searching
-
voy4g3r2
plus cobra kai is on.. so it will keep me out of trouble