OpenBSD 5.6: What will be there
openbsd.org
openbsd.org
So, who makes a modern laptop with good OpenBSD hardware compatability?
There is a brief warning about nVidia here: http://www.openbsd.org/amd64.html
This may help. Using `apm -C` or `apm -A`
People mustn't expect everything to ever work straight out of the box on anything. Much like you have to install the Lenovo PM driver on windows, you have to config apm on OpenBSD.
This is also well known.
Quick howto which covers the basics: http://geekyschmidt.com/2011/03/27/openbsd-laptop-mini-howto
> People mustn't expect everything to ever work straight out of the box on anything.
--Why?
> Much like you have to install the Lenovo PM driver on windows, you have to config apm on OpenBSD.
I don't for my Hackintosh. And I don't install the Lenovo PM driver on Windows. Windows update may, but I don't.
Just pointing out that this is a perspective thing. PFsense and similar can very-much-so be just as "big iron" as Cisco et al.
Just making the case that "just buy Cisco" doesn't do anyone really any good in a very wide market with a lot of very good options - sometimes paying for the brand doesn't mean you are getting something better.
If it wasn't intended to be run on laptops, why do most OpenBSD devs run it on their laptops? Why does it have graphics drivers with LVDS output? Touchpad support? Why does it have X with multiple window managers and OpenGL with 3D acceleration? KMS? ACPI suspend & hibernate? Sound daemon? Disk encryption?
There are a lot of features that make mostly (only?) sense on laptops, and the developers spend a lot of effort to make sure it works. It'd be absurd to claim the system is not intended to run on laptops.
I've run OpenBSD on my netbook for years. And it works pretty damn well, right out of the box.
I use it exclusively on servers, and on all laptops/desktops I use for real work. Its a breath of fresh air! No bloat, no evil, gets the job done - Not to mention some lovely features such as Full (no unencrypted boot slice) disk encryption via softraid, a completely unprivileged X server (with KMS supported GPUs), and a brilliant set of simple and solid daemons included in the base system.
The only time I'll switch away is to use linux - The two reasons there being 1) High-end Gaming, 2) Virtualization.
Just make sure your partitions are 4k aligned to minimized write amplification. Many openbsd devs use SSDs. I've used one with openbsd for years without problems. Honestly it's a requirement given the shortcomings of ffs.
http://www.openbsd.org/faq/faq14.html#flashmem
There's no mention of the 4K alignment issue, however.
For the moment, just make sure you leave a slice of the SSD unused. You could also on occasion backup the OpenBSD install, replace it with an empty ext4fs and fstrim it via a livecd, then restore the OpenBSD install.
I'm hoping it's because they are going to be using HTTPS with pinned certs to ensure you are downloading from a proper mirror. But that's hope, not actual knowledge.
Is there an FTP equivalent of this?
Frankly, if I was looking to implement this, I'd start with SFTP/SCP. FTP/S is, at best, a rarely implemented kludge.
How does removing tape installation as a feature affect businesses who use tape as a backup method?
Insert standard disclaimer about it being open source and if someone wanted to resurrect tape install more power to them, etc.
This is intriguing. I would certainly like to know more about what is happening with this.
signify(1) pubkeys for this release:
base: RWR0EANmo9nqhpPbPUZDIBcRtrVcRwQxZ8UKGWY8Ui4RHi229KFL84wV
fw: RWT4e3jpYgSeLYs62aDsUkcvHR7+so5S/Fz/++B859j61rfNVcQTRxMw
pkg: RWSPEf7Vpp2j0PTDG+eLs5L700nlqBFzEcSmHuv3ypVUEOYwso+UucXbNow you've learned a valuable lesson about asking a rhetorical question on the internet. None of the other responders knew the correct answer.
I have had to remove the IPv6 option from my kernels because enabling IPv6 by default (which to me seems like a "policy" decision) has become so pervasive. Nice to see this change; here's hoping other OS's follow suit.
This is sensible but means I can't use OpenBSD to connect to one of my client's VPNs. Unless there's another way?
http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/pppd/M...
Worst case scenario you'd have to restore some bits of old source (chap_ms.c and maybe the necessary md4 routines).
I didn't even know there was support for Kerberos in OpenSSl, but it's also under the LibreSSL bullet points as well.
Log message:
Remove SRP and Kerberos support from libssl. These are complex protocols
all on their own and we can't effectively maintain them without using them,
which we don't. If the need arises, the code can be resurrected.
Or in Theo's words: It is crap. Eventually we recognize the risk is to high.
Another relevant commit message, with a fun quote: Log message:
The complexity and quality of kerberosV and the fact that almost
nobody is using it doesn't justify to have it in base - disable and
remove it. If the 2 two people who use it still want it, they can
make a port or recompile OpenBSD on their own.
There is a quote in theo.c from August 2010: "basically, dung beetles
fucking. that's what kerberosV + openssl is like".
Discussed with many. Tests by henning@ reyk@ and others.
ok deraadt@ henning@
I recommend you take a look at the whole message, it'll give you a vague idea of how big the code base was. Keep in mind that this particular commit was followed by a lot of smaller commits removing remnants of kerberos that had kinda spread all over the system...Why?
> end to end connectivity is the internet.
It was definitely the original idea of the internet, but I'd say it no longer is the reality. People want to access Google and Facebook. The vast majority of users don't need or want their device to be directly reachable from the internet but communicate through cloud services.
End to end connectivity is the Internet.... and by contrast, privately addressed networks are not on the Internet but must reach it via gateways.
Reaching one another via centralized services rather than distributed federation is a problem, not a solution, in communications protocol design. See also: Everyone Hates Facebook.
> See also: Everyone Hates Facebook.
I don't know in what kind of bubble you are living but 1.3 billion people are on Facebook; whether it's cool to hate it is not germane to the topic at hand.
So, users are stuck behind asymmetric dsl lines, behind poorly functioning NAT routers and couldn't use p2p for what they want to use p2p for ... legally.
There are exceptions of course, like this project:
or:
https://www.tahoe-lafs.org/trac/tahoe-lafs
But after decades of stagnation, and even regression, in the ISP industry -- getting working p2p solutions to catch on is an uphill struggle. And when people don't have software they can, or want, to run as a service -- the demand doesn't exist either.
Contrast this with how people used to run their own BBS back in the day...
I don't disagree with the ideal of everyone being able to serve their own content directly to the internet, I just don't think it reflects reality, specifically the abilities and inclinations of most people. I'm curious how people come to hold on to such beliefs when they are so incongruous with actual human behavior.
I would say that a great many things are not noticed by or are tolerated by the majority, and it's only when they're presented with a better solution do they notice.
Even client-server business models can benefit from peer-to-peer communications. The most obvious is media providers using their clients' connections to avoid having to maintain as large a CDN, and to cut some costs that way. If someone's listened or watched something near you, you can download from them instead.
And then there's all sorts of systems which really could be truly peer-to-peer, from social networking to a replacement for ebay.
Which means we'll have toasters sporting some proprietary, dumber-than-IPv6, less-functional-than-IPv6, less-secure-than-IPv6, IP address equivalent on the IoT. With DRM preventing you from toasting bread not approved by the vendor. Because there will come a point where buying a toaster without IoT enablement (in the future, toast marketing is nichy but profitable) will be about as easy as buying a 2014 production TV that doesn't sport cable hookups.
Tilt at those windmills...
Edit: If you mean mac68k then yes, but that platform was dropped after the 5.1 release. http://www.openbsd.org/mac68k.html
Not to mention another verifiable source for the signify keys.