Learn to tame OpenBSD quickly.
December 24, 2015
History
Forked from NetBSD. Theo De Raadt is the founder and leader of the OpenBSD project. The first OpenBSD release (1.1/CVS) appear on October 18, 1995.
Why use OpenBSD ?
UNIX-like
Get the last version of OpenSSH, OpenSMTPD, OpenNTPD, OpenBGPD, OpenOSPFD, LibreSSL
Get the last PF (Packet Filter) features
Security focused Operating System
Thorough documentation
Cryptography
Forked from NetBSD. Theo De Raadt is the founder and leader of the OpenBSD project. The first OpenBSD release (1.1/CVS) appear on October 18, 1995.OpenBSD Version numbers
Six month release cycle
New release is incremented by 0.1
OpenBSD's Flavors -release: The version of OpenBSD shipped every six months
-current: Development just after the release
-stable: Release, plus patches (support ~ 1 year)
InstallationReally simple, ready in 5 minutes (KISS).
Get more information: http://www.openbsd.org/faq/faq4.html
Networking (Files)
File Contain
/etc/myname Default hostname.
/etc/hostname.if Configuration for each network interface, for example: /etc/hostname.bge0
/etc/mygate Default gateway.
/etc/resolv.conf Resolver (DNS).
/etc/hosts Known hosts on the network.
Networking # See available network cards:
/sbin/ifconfig
# Restart networking service:
/bin/sh /etc/netstart
# Set DHCP for 're0' interface, on the fly:
/sbin/dhclient re0
Networking (Routing) # Show the routing table (ipv4):
/usr/bin/netstat -rnf inet
# Show the routing table (ipv6):
/usr/bin/netstat -rnf inet6
# Delete all gateway entries from the routing table:
/sbin/route -n flush
Networking (set at startup)Example 1: configure static IP address for re0.
## file: /etc/hostname.re0
inet 192.168.0.58 255.255.255.0
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart re0' to apply changes to running system.Example 2: configure DHCP for bge0.
## file: /etc/hostname.bge0
dhcp
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart bge0' to apply changes to running system.Example 3: configure wireless.
## file: /etc/hostname.iwn0
nwid ACCESS_POINT_NAME
wpakey THE_SECRET_KEY
dhcp
# For more information, read the manual: hostname.if(5)
Don't forget to run 'sh /etc/netstart iwn0' to apply changes to running system.PF (Packet Filter)
Ruleset: /etc/pf.conf
Useful commands. # Disable PF
/sbin/pfctl -d
# Enable PF and load the rules
/sbin/pfctl -ef /etc/pf.conf
# Just load the rules (apply changes)
/sbin/pfctl -f /etc/pf.conf
# View the loaded rules
/sbin/pfctl -s rules
For more information, read the manual: pfctl(8)Pf ruleset sample
## file: /etc/pf.conf
# Protect a laptop (allow only ping/ssh from anywhere)
set skip on lo
set fingerprints "/dev/null"
block log all
pass in on egress inet proto icmp all icmp-type echoreq
pass in on egress inet proto tcp from any to any port ssh
pass out
# For more information, read the manual: pf.conf(5)
Debug PF with tcpdump(8) /usr/sbin/tcpdump -nettti pflog0
Manage usersManually
/usr/sbin/user [add|del|info|mod] user_name
The interactive way # Add users
/usr/sbin/adduser
# Remove users
/usr/sbin/rmuser
For more information, read the manual: adduser(8)Manage Groups
File: /etc/group
/usr/sbin/group [add|del|info|mod] group_name
Members in 'wheel' group can use su(1) to become 'root'.For more information, read the manual: group(8,5)
sudo replaced with doas(1)
## file: /etc/doas.conf
# Permit the user 'Marc' to reboot the box
permit nopass marc as root cmd reboot
Marc can now reboot the box: $ doas reboot
For more information, read the manual: doas.conf(5)Install Packages
export PKG_PATH=http://ftp.openbsd.org/pub/OpenBSD/5.8/packages/amd64/
# OR use 'installpath' variable in /etc/pkg.conf:
installpath=http://ftp2.fr.openbsd.org/pub/OpenBSD/%c/packages/%a/
# Add sudo package
/usr/sbin/pkg_add sudo
Some packages provide configuration and other information in a file located in '/usr/local/share/doc/pkg-readmes'.For more information, read the manual: pkg.conf(5)
Packages
# List packages installed
/usr/sbin/pkg_info
# View install-message for a specific package
/usr/sbin/pkg_info -M package_name
# Remove a Package
/usr/sbin/pkg_delete package_name
# Delete unused dependencies
/usr/sbin/pkg_delete -a
For more information, read the manual: packages(7)Install non-free firmware packages
/usr/sbin/fw_update
Firmware is downloaded from release-specific directories at: http://firmware.openbsd.org/firmware/Manage daemons, services
File: /etc/rc.conf.local
/usr/sbin/rcctl [enable|disable|start|stop|reload|restart] daemon_name
# Examples
/usr/sbin/rcctl enable ipsec
/usr/sbin/rcctl enable isakmpd
/usr/sbin/rcctl set isakmpd flags -K
/usr/sbin/rcctl start isakmpd
For more information, read the manual: rcctl(8)Run a script at startup
File: /etc/rc.local
For more information, read the manual: rc.local(8)Update OpenBSD
Any security or reliability fixes can be found at: http://www.openbsd.org/errata.html
You can also use the openup tool from M:tier
Upgrade OpenBSD
To upgrade 5.6 to 5.8, you need to follow instructions:
http://www.openbsd.org/faq/upgrade57.html & http://www.openbsd.org/faq/upgrade58.html
OpenBSD Filesystem
The most important:
/ Root directory.
/home User home directories.
/root Default home directory for the superuser.
/mnt A temporary mount point.
/etc System configuration files and scripts.
/etc/examples Example configuration files for base system daemons.
/etc/skel (dot) files for new accounts.
/etc/signify Key files used for signify(1).
/tmp Cleaned after a reboot.
/var/tmp Symbolic link to the system /tmp.
/var/log Log files.
/var/run pid, socket files, utmp, dmesg.boot
/var/db Database files.
/var/www Configuration files for httpd(8).
/usr/local Used for third packages installed.
/usr/src BSD and/or local source files.
For more information, read the manual: hier(7)OpenBSD Kernels
/bsd
Pure kernel executable (the operating system loaded into memory at boot-time).
/bsd.mp
Pure kernel executable for multiprocessor machines.
/bsd.rd
Installation kernel. The built-in RAM disk contains utilities which can be run without an external file system, so this kernel is useful for limited system maintenance too.
Tune the system sysctl(8) get or set kernel state
config(8) modify a kernel
Need more help ? FAQ: http://www.openbsd.org/faq/
Manual page: afterboot(8)
Mailing list: misc@
Presentations & Papers http://www.openbsd.org/papers/
Supporting OpenBSD Donations [1]
OpenBSD Foundation [2]
OpenBSD Store [3]
Thank you.
Feedback: contact@[1] http://www.openbsd.org/donations.html