OpenBSD Jumpstart: Learn to Tame OpenBSD Quickly
openbsdjumpstart.org
openbsdjumpstart.org
After hearing about JETPLOW [0], I decided to replace the Cisco ASA that I had been using for my (fiber) Internet connection at home with an open-source router/firewall.
I had a RouterMaxx 1106 [1] (PDF) laying around so I decided to put OpenBSD on it and use that. In short order, I built an OpenBSD virtual machine, used flashrd [2] to build an OpenBSD image I could put on a CompactFlash card, and had it up and running.
It just works.
About two years later, it's still humming along nicely. The only downtime that I've had is when I upgraded to a new OpenBSD version. I could've minimized somewhat but I use a new CF card every time.
Nowadays, I've also got a dedicated laptop running OpenBSD that I use solely for "security critical" stuff for $work. A separate machine stands in between the Internet and our MX hosts and runs OpenBSD's spamd [3] to help keep spam out of our users' mailboxes (N.B.: the number of messages hitting out Barracuda dropped by ~70%, with zero complaints received from any of our users).
In addition, we're just beginning a project to basically rebuild our entire server infrastructure and we'll be using OpenBSD for certain functions: remote access (OpenVPN), SSH jump hosts, possibly authoritative DNS, etc.
I'm a firm believer in using "the best tool for the job". Most of our servers will be running FreeBSD, but OpenBSD definitely has its place in our environment.
[0]: https://nsa.gov1.info/dni/nsa-ant-catalog/firewalls/
[1]: http://www.balticnetworks.com/docs/routermaxx%206%20port.pdf
A tip for first-timers: perform the installation with an Ethernet internet connection. On my laptop, wireless firmware was installed and configured automagically on first boot. After that it's all gravy.
Yes, it's much easier that way.
Then, once the firmware for your wireless card is installed, configure your wired and wireless interfaces as a failover trunk (if you switch back and forth between them very often). This way, your IP address doesn't change when you {dis}connect your Ethernet cable. Obviously, everyone has different needs but this works out great for me (I plug in when at my desk and use wireless the rest of the time).
Seems the currently recommended method is to just run dhclient on both wireless and wired interfaces and let the routing table to decide which to use.
That said. Finding pre-built binary packages can be hit or miss. And ports requires X11 to be installed.
But when all is said and done. It's the community that's most important. And OpenBSD has one of the kindest and active IRC channels on freenode. Far from the "in your face"/elitist reputation others have stated before.
Sure.. though from what I can see, openbsd didn't support wpa enterprise until 2013, and at that point it was supported using wpa_supplicant.
http://www.undeadly.org/cgi?action=article&sid=2013012814221...
I've found a great use case for it though; older, slower hardware (think P4 and older) actually benefits from running OpenBSD versus most modern Linux distros. For example, I have an ancient PIII laptop that refuses to run anything other than OpenBSD, Slackware, and Haiku OS. Out of those, OpenBSD is the fastest and least buggy. Granted, it's just a toy/hobby device, but I found it intriguing nonetheless.
There's also a general choppiness to X itself. All of this with accelerated Intel graphics, so it's not necessarily driver related. I just figure that given the project's focus on security and clean code, desktop OS performance takes a necessary back seat.
Even with all of that, I give every new release a thorough test run on my old workstation and laptop, just to see if things have improved in that area. And they have been steadily improving!
It's just laggy and runs hotter than Linux. I get a solid hour and a half more battery life on Linux too.
Obviously I reported it.
http://www.laptopmag.com/reviews/laptops/fujitsu-lifebook-s7...
The above ~5yr old laptop will give 60fps running minecraft with no hiccups / glitches. Installed an SSD and frankly its a perfect workstation for anything I would use and I see no lag.
In FreeBSD, it's powerd. In OpenBSD... apmd?
You are free to search marc.info for the fruitless threads of me trying to solve multi-second system freezes when opening emacs or changing workspaces if you like.
The fact that the devs dogfood their stuff is irrelevant: it doesn't perform even remotely as well as Linux on the same (modern) hardware.
Also there was fix in ACPI in 5.8 to fix power use in newer processors. If I remember it correctly the processor didn't use the deep sleep states so they consumed more power.
Openbsd has always felt turbo fast to me. Easily the tightest Unix experience, in my experience.
That said, there's a bunch of trade-offs. Virtualization on OpenBSD is, as far as I can tell, effectively a non-starter for any major project (i.e. those with many VMs, a virtual network, virtual disks, etc.). Containers seem to not exist, at all, though I found some historic mentions of jail-based options.
It seems like a perfect candidate for a VM or container guest OS, due to security focus, small size, simple deployment, etc. But, you then have to have two sets of skills: Managing your guest operating system, and managing your host operating system. Since Linux is the strongest container or VM hosting OS on the server (this was once debatable when Solaris Zones was new and Linux was still somewhat immature on the container front, but I don't think anyone would make the case that Linux isn't the obvious choice for hosting VMs or containers in most deployments today), and Linux is pretty far away from OpenBSD, you've got two pretty widely divergent skill sets needed.
Nonetheless, every time I read about OpenBSD, I feel a strong urge to give it a try. It seems extremely elegant in the way old UNIX systems were elegant. It appeals to me on a lot of fronts. Also, the code and documentation are extremely readable, in ways I've rarely seen elsewhere (FreeBSD also meets this description, but it's so much bigger it can still be daunting).
I wonder if anyone is working on a Zones port to any BSD? OpenBSD with a convincing container or virtualization story would be a tipping point for me, in terms of being willing to put in the effort to learn it and use it.
http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/...
Nevertheless, jails have been the BSD "container story" for over fifteen years.
Being old does give it a long history of successful use. Jails are exactly what Docker for FreeBSD uses for its containers; I'm not sure what more you'd be looking for in a container system, if lxc is something you'll mention in a positive light.
pause for laughter
Join us: https://smartos.org
But, be real here. Linux likely sees more contributions in a month than SmartOS has had in its whole existence. The size and scope of the ecosystem is just vastly different. Most people have never even heard of SmartOS. And, Linux has caught up. It's always been a leader on full virtualization (Xen was developed first for Linux, after all), but it's also now got several great container options, including core kernel support than runs deep. There's not much you can do with SmartOS that you can't do with Linux today; and, the reverse is not true.
Don't get me wrong: SmartOS seems really cool, and I want to spend some time with it in the near future. We've always had a soft spot for Solaris (despite not selling a lot to Solaris users, since they're so vastly outnumbered by Linux users), and there's no one I can imagine better for the task of pushing it forward than Joyent.
If I were to make an REST API server, that serves 10,000 requests per second per core, which OS should I use?
But, here is an answer - 10,000 requests per second is 100 microseconds per request. At 100Mbps network speed, this gives (roughly) 10 characters per microsecond or a budget of 1,000 characters combined per request. We will take 100 characters for the request, and 900 characters for the reply. Of course, you could go with 1Gps network service, and multiply this by 10. But, you will need at least 20kpps "per core".
However, you also have to contend with disk i/o and/or the database layer.
Which OS? I think you are probably a long way from being able to answer that question. Note that OpenBSD will not be as "multicore performant" but that may not matter in your application.
The server I'm using has Intel SSDs, capable of 400,000 read IOPS per drive. Redis caching can be used to reduce database accesses as well.
Also, make use of netmap: http://info.iet.unipi.it/~luigi/netmap/ That is available for FreeBSD and Linux.
10k messages per sec is doable. But probably not off the shelf.
They also make binpatch-ng which helps you create binary patches which you can then distribute around to your machines.
I wonder why there are any similar initiative for OpenBSD? I am sure OpenBSD is great fit for Server and Internet based Appliance where security is a prime concern, and doesn't require PC desktop support.
Learn to tame OpenBSD quickly.
December 24, 2015
History
Forked from NetBSD. Theo De Raadt is the founder and leader of the OpenBSD project. The first OpenBSD release (1.1/CVS) appear on October 18, 1995.
Why use OpenBSD ?
UNIX-like
Get the last version of OpenSSH, OpenSMTPD, OpenNTPD, OpenBGPD, OpenOSPFD, LibreSSL
Get the last PF (Packet Filter) features
Security focused Operating System
Thorough documentation
Cryptography
Forked from NetBSD. Theo De Raadt is the founder and leader of the OpenBSD project. The first OpenBSD release (1.1/CVS) appear on October 18, 1995.OpenBSD Version numbers
Six month release cycle
New release is incremented by 0.1
OpenBSD's Flavors -release: The version of OpenBSD shipped every six months
-current: Development just after the release
-stable: Release, plus patches (support ~ 1 year)
InstallationReally simple, ready in 5 minutes (KISS).
Get more information: http://www.openbsd.org/faq/faq4.html
Networking (Files)
File Contain
/etc/myname Default hostname.
/etc/hostname.if Configuration for each network interface, for example: /etc/hostname.bge0
/etc/mygate Default gateway.
/etc/resolv.conf Resolver (DNS).
/etc/hosts Known hosts on the network.
Networking # See available network cards:
/sbin/ifconfig
# Restart networking service:
/bin/sh /etc/netstart
# Set DHCP for 're0' interface, on the fly:
/sbin/dhclient re0
Networking (Routing) # Show the routing table (ipv4):
/usr/bin/netstat -rnf inet
# Show the routing table (ipv6):
/usr/bin/netstat -rnf inet6
# Delete all gateway entries from the routing table:
/sbin/route -n flush
Networking (set at startup)Example 1: configure static IP address for re0.
## file: /etc/hostname.re0
inet 192.168.0.58 255.255.255.0
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart re0' to apply changes to running system.Example 2: configure DHCP for bge0.
## file: /etc/hostname.bge0
dhcp
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart bge0' to apply changes to running system.Example 3: configure wireless.
## file: /etc/hostname.iwn0
nwid ACCESS_POINT_NAME
wpakey THE_SECRET_KEY
dhcp
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart iwn0' to apply changes to running system.PF (Packet Filter)
Ruleset: /etc/pf.conf
Useful commands. # Disable PF
/sbin/pfctl -d
# Enable PF and load the rules
/sbin/pfctl -ef /etc/pf.conf
# Just load the rules (apply changes)
/sbin/pfctl -f /etc/pf.conf
# View the loaded rules
/sbin/pfctl -s rules
For more information, read the manual: pfctl(8)Pf ruleset sample
## file: /etc/pf.conf
# Protect a laptop (allow only ping/ssh from anywhere)
set skip on lo
set fingerprints "/dev/null"
block log all
pass in on egress inet proto icmp all icmp-type echoreq
pass in on egress inet proto tcp from any to any port ssh
pass out
# For more information, read the manual: pf.conf(5)
Debug PF with tcpdump(8) /usr/sbin/tcpdump -nettti pflog0
Manage usersManually
/usr/sbin/user [add|del|info|mod] user_name
The interactive way # Add users
/usr/sbin/adduser
# Remove users
/usr/sbin/rmuser
For more information, read the manual: adduser(8)Manage Groups
File: /etc/group
/usr/sbin/group [add|del|info|mod] group_name
Members in 'wheel' group can use su(1) to become 'root'.For more information, read the manual: group(8,5)
sudo replaced with doas(1)
## file: /etc/doas.conf
# Permit the user 'Marc' to reboot the box
permit nopass marc as root cmd reboot
Marc can now reboot the box: $ doas reboot
For more information, read the manual: doas.conf(5)Install Packages
export PKG_PATH=http://ftp.openbsd.org/pub/OpenBSD/5.8/packages/amd64/
# OR use 'installpath' variable in /etc/pkg.conf:
installpath=http://ftp2.fr.openbsd.org/pub/OpenBSD/%c/packages/%a/
# Add sudo package
/usr/sbin/pkg_add sudo
Some packages provide configuration and other information in a file located in '/usr/local/share/doc/pkg-readmes'.For more information, read the manual: pkg.conf(5)
Packages
# List packages installed
/usr/sbin/pkg_info
# View install-message for a specific package
/usr/sbin/pkg_info -M package_name
# Remove a Package
/usr/sbin/pkg_delete package_name
# Delete unused dependencies
/usr/sbin/pkg_delete -a
For more information, read the manual: packages(7)Install non-free firmware packages
/usr/sbin/fw_update
Firmware is downloaded from release-specific directories at: http://firmware.openbsd.org/firmware/Manage daemons, services
File: /etc/rc.conf.local
/usr/sbin/rcctl [enable|disable|start|stop|reload|restart] daemon_name
# Examples
/usr/sbin/rcctl enable ipsec
/usr/sbin/rcctl enable isakmpd
/usr/sbin/rcctl set isakmpd flags -K
/usr/sbin/rcctl start isakmpd
For more information, read the manual: rcctl(8)Run a script at startup
File: /etc/rc.local
For more information, read the manual: rc.local(8)Update OpenBSD
Any security or reliability fixes can be found at: http://www.openbsd.org/errata.html
You can also use the openup tool from M:tier
Upgrade OpenBSD
To upgrade 5.6 to 5.8, you need to follow instructions:
http://www.openbsd.org/faq/upgrade57.html & http://www.openbsd.org/faq/upgrade58.html
OpenBSD Filesystem
The most important:
/ Root directory.
/home User home directories.
/root Default home directory for the superuser.
/mnt A temporary mount point.
/etc System configuration files and scripts.
/etc/examples Example configuration files for base system daemons.
/etc/skel (dot) files for new accounts.
/etc/signify Key files used for signify(1).
/tmp Cleaned after a reboot.
/var/tmp Symbolic link to the system /tmp.
/var/log Log files.
/var/run pid, socket files, utmp, dmesg.boot
/var/db Database files.
/var/www Configuration files for httpd(8).
/usr/local Used for third packages installed.
/usr/src BSD and/or local source files.
For more information, read the manual: hier(7)OpenBSD Kernels
/bsd
Pure kernel executable (the operating system loaded into memory at boot-time).
/bsd.mp
Pure kernel executable for multiprocessor machines.
/bsd.rd
Installation kernel. The built-in RAM disk contains utilities which can be run without an external file system, so this kernel is useful for limited system maintenance too.
Tune the system sysctl(8) get or set kernel state
config(8) modify a kernel
Need more help ? FAQ: http://www.openbsd.org/faq/
Manual page: afterboot(8)
Mailing list: misc@
Presentations & Papers http://www.openbsd.org/papers/
Supporting OpenBSD Donations [1]
OpenBSD Foundation [2]
OpenBSD Store [3]
Thank you.
Feedback: contact@[1] http://www.openbsd.org/donations.html
> Get the last PF (Packet Filter) features
last -> latest
Posting about typo's and such here in the comments helps no one.
lol, I was considering not posting comments on HN anymore. This is just cake. I don't even know why I try, bye HN thanks for all the fishes.
I'm having trouble seeing how pointing out a typo to other HN readers -- who can't fix it -- benefits any of us. If you felt inclined to point it out to someone, you should have pointed it to the author (who conveniently provided a way to contact him).
If we always pointed out every typo or grammatical error in every submission (as users on some other discussion sites tend to do), this comments section would be full of them and the quality of the site would quickly diminish.