I think the more interesting question is why OpenBSD over Linux (which distro?) or FreeBSD. For me, this comes down to preference for simplicity, an absence of weird abstractions over top of simple things like networking, and confidence in the quality of the base system. I like FreeBSD and happily use it in several instances (freebsd-update is pretty great for online updating), but have had very mixed results with Linux systems (mostly debian and ubuntu). Sometimes things work, and sometimes I waste hours trolling through internet forums trying to figure out how to make it do what I want.
Really though, if you want to know what the difference is, you should just try it. Pull down the ISO, fire up a VM, do the install, and then try to get some work done. Take the time to read the man pages for afterboot, pkg_add and rc.conf.local, and you'll be on your way. The worst that could happen is you don't like it..
On the other hand you can find documentation for Fedora and Ubuntu server in terms of blog-posts for just about everything.
As I talk to more people about it, there seems to be a growing pattern that, it's just whatever system you grew up with is the one you're most comfortable with, and is the one you're most likely to use going forward.
I wish it was for a lofty goal like security and "code correctness" etc... but the honest answer is that it's extremely simple (once you get used to it) and I tend to be extremely lazy at times. Configuration is very straightforward for a lot of things and there have been very few surprises along the way. Actually no surprises that I can recall in most of what I do since 5.0.
I wouldn't recommend it as a desktop system although plenty of people (including my boss) use it as such. There is some fiddling required for this that I'd rather not do, but for very simple, stable and surprise-free servers, it works very well for me. I also wouldn't recommend it for first-time admins either, although their man pages are some of the most thorough and helpful I've ever read.
For a more "desktop" experience, OpenBSD 5.6 also has working GNOME 3.12.2.
One thing that tends to trip up desktop users is the default ulimits, BSD has login classes which may need to be tuned in login.conf(5). This is especially true if you plan on using modern web browsers which are resource hogs.
The documentation is exceptionally good, and the simplicity for configuration is a nice bonus.
My memory was always that ISOs were hard to find, and when I didn't see a big flashing link I guess I tuned out.
I'll revisit OpenBSD in the future, for the moment I'm enjoying FreeBSD though.
I've been running OpenBSD on a laptop (which works as my desktop) for years now, and I can say there's been very little fiddling. In fact it's proved to be the best out-of-the-box experience I've had with any OS (including Windows XP and a whole bunch of Linux distros).
> I also wouldn't recommend it for first-time admins either
I have to admit I wasn't administrating things for the first time when I did it on OpenBSD.. but OpenBSD was so simple and straightforward that I eventually lost the will to fiddle with other systems.
They really have gone out of the way to make sure the system is Dead Simple to configure (the best configuration is no need for any configuration at all!), and when you really need to change something, the documentation is unparalleled.
Of course, different people have different needs so what works for me might not work for everyone. I know that what seems to work for most people doesn't really work for me...
I think with any BSD, trying to run it on modern hardware will be a frustrating experience as it lags behind Linux in hardware support (which itself lags behind Windows/OSX). Of course, BSDs are more coherent OSes and if it were not for hardware support I would use it exclusively.
Thankfully, it looks like they're finally gonna get there soon: http://www.bsdcan.org/2014/schedule/events/452.en.html
> The problem with FreeBSD is that it has almost no
> security features turned on by default.
What security features would you like to see turned on by default?ASLR is apparently around the corner+ as well.
Didn't OpenBSD get ASLR in 2008 or something like that? It only took 6 years for FreeBSD to get it.... >_<
+for some definition of corner.I use OpenBSD because 3-4 years ago I discovered a bug in the FreeBSD kernel that meant my OSS project wouldn't work. When generating lots of IGMPv2 packets on FreeBSD I could consistently cause the kernel to panic. I wrote a bug report, but I'm not a kernel hacker so I just switched to OpenBSD.
Manpages in Linux are atrocious, and each distro has their own way of doing things that only half works. I don't like GNU info, and Googling for docs is unacceptable. I often work in places with no Internet and I need the doc with me.
That said, I've been starting to care quite a lot more about security and code correctness in light of recent events and have been waiting for today to install OpenBSD on my machine.
https://www.archlinux.org/packages/community/any/arch-wiki-d...
I can't be the only person that wants to deploy Linux based services piped through pf on OpenBSD and doesn't want to get into colocation.
Native IPv6 is enabled on every host which, as a network engineer, is a huge plus for me. Physical location is at One Wilshire in Los Angeles and ARP has great connectivity and lots of peering.
It's a small operation which, depending on your point of view, can be either a good thing or a bad thing. There is no "instant provisioning" (or wasn't, the last time I ordered a new host) so it may take a day or so for your host to be available for your use. On the other hand, you can often catch the owner in #arpnetworks on freenode and chat directly with him (or get quick answers to (general) questions from other happy customers). He's also on HN occasionally, if memory serves.
They also have a new Xen (PV or HVM) oferring, but I don't know how well OpenBSD would work with that.
Another possibility is iwStack[1], another KVM-based hosting provider.
Why:
1. After install sometimes I do not have access or prompt access to the machine;
2. It is safe and the need for updates are minimal.
It works..
http://en.wikipedia.org/wiki/DevOps
Are you asking if OpenBSD is part of people's workflow, or if it is part of their permanent infrastructure?
I ran into a huge backset with openbsd at work 3 years ago when I wanted to run two redundant load balancers with carp in vSphere. Turns out I had to enable promiscuous mode on an entire port group to make it happen. These days we use virtual switches so maybe it's easier now but in those days we did not want to do it because it would mean enabling promiscuous mode on an esx host adapter, affecting everyone on that host.
XenServer has it worse -- no option to turn it on at all.