<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app02</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 09:04:23 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Ed25519”</title>
    <link>https://www.bsdnow.tv/tags/ed25519</link>
    <pubDate>Wed, 26 Aug 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>104: Beverly Hills 25519</title>
  <link>https://www.bsdnow.tv/104</link>
  <guid isPermaLink="false">0bc0c068-36fe-429f-b7f4-38ac01fb7f19</guid>
  <pubDate>Wed, 26 Aug 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0bc0c068-36fe-429f-b7f4-38ac01fb7f19.mp3" length="58136116" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</itunes:subtitle>
  <itunes:duration>1:20:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener"&gt;EdgeRouter Lite, meet OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it &lt;/li&gt;
&lt;li&gt;We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)&lt;/li&gt;
&lt;li&gt;Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it&lt;/li&gt;
&lt;li&gt;He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt; and &lt;a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener"&gt;various&lt;/a&gt; &lt;a href="https://www.marc.info/?t=143974140500001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;other&lt;/a&gt; &lt;a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener"&gt;places&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One thing to &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143991822827285&amp;amp;w=2" rel="nofollow noopener"&gt;note&lt;/a&gt; about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W&lt;sup&gt;X&lt;/sup&gt; at all)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener"&gt;Design and Implementation of the FreeBSD Operating System interview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development&lt;/li&gt;
&lt;li&gt;InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors&lt;/li&gt;
&lt;li&gt;"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."&lt;/li&gt;
&lt;li&gt;Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144027474117290&amp;amp;w=2" rel="nofollow noopener"&gt;Path list parameter in OpenBSD tame&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've mentioned OpenBSD's relatively new "&lt;a href="https://marc.info/?l=openbsd-tech&amp;amp;m=143725996614627&amp;amp;w=2" rel="nofollow noopener"&gt;tame&lt;/a&gt;" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges&lt;/li&gt;
&lt;li&gt;One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between&lt;/li&gt;
&lt;li&gt;Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers&lt;/li&gt;
&lt;li&gt;The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener"&gt;on Reddit&lt;/a&gt; &lt;a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener"&gt;and Hacker News&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener"&gt;FreeBSD &amp;amp; PC-BSD 10.2-RELEASE&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out&lt;/li&gt;
&lt;li&gt;The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13&lt;/li&gt;
&lt;li&gt;New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to&lt;/li&gt;
&lt;li&gt;A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet&lt;/li&gt;
&lt;li&gt;The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions&lt;/li&gt;
&lt;li&gt;ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards&lt;/li&gt;
&lt;li&gt;The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups&lt;/li&gt;
&lt;li&gt;In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener"&gt;full release notes&lt;/a&gt; for the rest of the details and changes&lt;/li&gt;
&lt;li&gt;PC-BSD also followed with &lt;a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener"&gt;their 10.2-RELEASE&lt;/a&gt;, sporting a few more additional features
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Damien Miller - &lt;a href="mailto:djm@openbsd.org" rel="nofollow noopener"&gt;djm@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/damienmiller" rel="nofollow noopener"&gt;@damienmiller&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenSSH: phasing out broken crypto, default cipher changes&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference Shimane&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another&lt;/li&gt;
&lt;li&gt;This time they had NetBSD running on some Sony NWS devices (MIPS-based)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener"&gt;JavaStations&lt;/a&gt; were also on display - something we haven't ever seen before (made between 1996-2000)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener"&gt;BAFUG videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos of their recent meetings&lt;/li&gt;
&lt;li&gt;Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works&lt;/li&gt;
&lt;li&gt;Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener"&gt;a second video&lt;/a&gt;, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"&lt;/li&gt;
&lt;li&gt;In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)&lt;/li&gt;
&lt;li&gt;People should record presentations at their BSD users groups and send them to us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener"&gt;L2TP over IPSEC on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well&lt;/li&gt;
&lt;li&gt;Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic&lt;/li&gt;
&lt;li&gt;This guide specifically covers L2TP, using npppd and pre-shared keys&lt;/li&gt;
&lt;li&gt;Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener"&gt;Reliable bare metal with TrueOS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS&lt;/li&gt;
&lt;li&gt;This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution&lt;/li&gt;
&lt;li&gt;Most importantly, he also covers how to keep everything redundant and deal with hard drives failing&lt;/li&gt;
&lt;li&gt;The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like&lt;/li&gt;
&lt;li&gt;Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144047868127049&amp;amp;w=2" rel="nofollow noopener"&gt;Kernel W&lt;sup&gt;X&lt;/sup&gt; on i386&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned some big W&lt;sup&gt;X&lt;/sup&gt; kernel changes in OpenBSD &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" rel="nofollow noopener"&gt;a while back&lt;/a&gt;, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)&lt;/li&gt;
&lt;li&gt;Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well&lt;/li&gt;
&lt;li&gt;Check out &lt;a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener"&gt;our interview with Mike&lt;/a&gt; for some more background info on memory protections like W&lt;sup&gt;X&lt;/sup&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener"&gt;Markus writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener"&gt;Theo writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssh, openssl, chacha20, chacha20-poly1305, aes, md5, hmac, cbc, gcm, cryptography, ed25519, curve25519, erl, edgerouter lite, tame, bafug</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>75: From the Foundation (Part 1)</title>
  <link>https://www.bsdnow.tv/75</link>
  <guid isPermaLink="false">34bf4647-35b0-4919-9b96-c12799506f14</guid>
  <pubDate>Wed, 04 Feb 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/34bf4647-35b0-4919-9b96-c12799506f14.mp3" length="61549780" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be starting a two-part series detailing the activities of various BSD foundations. Ed Maste from the FreeBSD foundation will be joining us this time, and we'll talk about what all they've been up to lately. All this week's news and answers to viewer-submitted questions, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:25:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be starting a two-part series detailing the activities of various BSD foundations. Ed Maste from the FreeBSD foundation will be joining us this time, and we'll talk about what all they've been up to lately. All this week's news and answers to viewer-submitted questions, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.djm.net.au/2015/02/key-rotation-in-openssh-68.html" rel="nofollow noopener"&gt;Key rotation in OpenSSH 6.8&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;Damien Miller&lt;/a&gt; posted a new blog entry about one of the features in the upcoming OpenSSH 6.8&lt;/li&gt;
&lt;li&gt;Times changes, key types change, problems are found with old algorithms and we switch to new ones&lt;/li&gt;
&lt;li&gt;In OpenSSH (and the SSH protocol) however, there hasn't been an easy way to rotate host keys... until now&lt;/li&gt;
&lt;li&gt;With this change, when you connect to a server, it will log &lt;em&gt;all&lt;/em&gt; the server's public keys in your known_hosts file, instead of just the first one used during the key exchange&lt;/li&gt;
&lt;li&gt;Keys that are in your known_hosts file but not on the server will get automatically removed&lt;/li&gt;
&lt;li&gt;This fixes the problem of old servers still authenticating with ancient DSA or small RSA keys, as well as providing a way for the server to rotate keys every so often&lt;/li&gt;
&lt;li&gt;There are some instructions in the blog post for how you'll be able to rotate host keys and eventually phase out the older ones - it's really simple&lt;/li&gt;
&lt;li&gt;There are a lot of big changes coming in OpenSSH 6.8, so we'll be sure to cover them all when it's released
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/port-arm/2015/01/30/msg002809.html" rel="nofollow noopener"&gt;NetBSD Banana Pi images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about the &lt;a href="http://www.bananapi.org/p/product.html" rel="nofollow noopener"&gt;Banana Pi&lt;/a&gt; a bit before - it's a small ARM board that's comparable to the popular Raspberry Pi&lt;/li&gt;
&lt;li&gt;Some NetBSD -current images were posted on the mailing list, so now you can get some BSD action on one of these little devices&lt;/li&gt;
&lt;li&gt;There are even a set of prebuilt pkgsrc packages, so you won't have to compile everything initially&lt;/li&gt;
&lt;li&gt;The email includes some steps to get everything working and an overview of what comes with the image&lt;/li&gt;
&lt;li&gt;Also check &lt;a href="https://wiki.netbsd.org/ports/evbarm/allwinner/" rel="nofollow noopener"&gt;the wiki page&lt;/a&gt; for some related boards and further instructions on getting set up&lt;/li&gt;
&lt;li&gt;On a related note, NetBSD also recently &lt;a href="https://blog.netbsd.org/tnf/entry/raspberry_pi_gpu_acceleration_in" rel="nofollow noopener"&gt;got GPU acceleration working&lt;/a&gt; for the Raspberry Pi (which is a first for their ARM port)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=142255048510669&amp;amp;w=2" rel="nofollow noopener"&gt;LibreSSL shirts and other BSD goodies&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've been keeping up with the LibreSSL saga and want a shirt to show your support, they're finally available to buy online&lt;/li&gt;
&lt;li&gt;There are two versions, either "&lt;a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTLSSL.jpg" rel="nofollow noopener"&gt;keep calm and use LibreSSL&lt;/a&gt;" or the slightly more snarky "&lt;a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTOSSL.jpg" rel="nofollow noopener"&gt;keep calm and abandon OpenSSL&lt;/a&gt;"&lt;/li&gt;
&lt;li&gt;While on the topic, we thought it would be good to make people aware of shirts for other BSD projects too&lt;/li&gt;
&lt;li&gt;You can get some FreeBSD, &lt;a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=pc-bsd" rel="nofollow noopener"&gt;PCBSD&lt;/a&gt; and FreeNAS &lt;a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=shirts" rel="nofollow noopener"&gt;stuff&lt;/a&gt; from the &lt;a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=tshirt" rel="nofollow noopener"&gt;FreeBSD mall site&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenBSD recently launched their &lt;a href="https://www.openbsdstore.com" rel="nofollow noopener"&gt;new store&lt;/a&gt;, but the selection is still a bit limited right now&lt;/li&gt;
&lt;li&gt;NetBSD has a &lt;a href="https://www.netbsd.org/gallery/devotionalia.html#cafepress" rel="nofollow noopener"&gt;couple places&lt;/a&gt; where you can buy shirts and other apparel with the flag logo on it&lt;/li&gt;
&lt;li&gt;We couldn't find any DragonFlyBSD shirts unfortunately, which is a shame since &lt;a href="http://www.dragonflybsd.org/images/small_logo.png" rel="nofollow noopener"&gt;their logo&lt;/a&gt; is pretty cool&lt;/li&gt;
&lt;li&gt;Profits from the sale of the gear go back to the projects, so pick up some swag and support your BSD of choice (and of course wear them at any Linux events you happen to go to)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=35.0" rel="nofollow noopener"&gt;OPNsense 15.1.4 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OPNsense guys have been hard at work since &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;we spoke to them&lt;/a&gt;, fixing lots of bugs and keeping everything up to date&lt;/li&gt;
&lt;li&gt;A number of versions have come out since then, with 15.1.4 being the latest (assuming they haven't updated it &lt;strong&gt;again&lt;/strong&gt; by the time this airs)&lt;/li&gt;
&lt;li&gt;This version includes the latest round of FreeBSD kernel security patches, as well as minor SSL and GUI fixes&lt;/li&gt;
&lt;li&gt;They're doing a great job of getting upstream fixes pushed out to users quickly, a very welcome change&lt;/li&gt;
&lt;li&gt;A developer has also posted an interesting write-up titled "&lt;a href="http://lastsummer.de/development-workflow-in-opnsense/" rel="nofollow noopener"&gt;Development Workflow in OPNsense&lt;/a&gt;"&lt;/li&gt;
&lt;li&gt;If any of our listeners are trying OPNsense as their gateway firewall, let us know how you like it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ed Maste - &lt;a href="mailto:board@freebsdfoundation.org" rel="nofollow noopener"&gt;board@freebsdfoundation.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener"&gt;The FreeBSD foundation&lt;/a&gt;'s activities&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/02/rolling-with-snapshots.html" rel="nofollow noopener"&gt;Rolling with OpenBSD snapshots&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the cool things about the -current branch of OpenBSD is that it doesn't require any compiling&lt;/li&gt;
&lt;li&gt;There are signed binary snapshots being continuously re-rolled and posted on the FTP sites for every architecture&lt;/li&gt;
&lt;li&gt;This provides an easy method to get onboard with the latest features, and you can also easily upgrade between them without reformatting or rebuilding&lt;/li&gt;
&lt;li&gt;This blog post will walk you through the process of using snapshots to stay on the bleeding edge of OpenBSD goodness&lt;/li&gt;
&lt;li&gt;After using -current for seven weeks, the author comes to the conclusion that it's not as unstable as people might think&lt;/li&gt;
&lt;li&gt;He's now helping test out patches and new ports since he's running the same code as the developers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/tech-pkg/2015/02/02/msg014224.html" rel="nofollow noopener"&gt;Signing pkgsrc packages&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As of the time this show airs, the official &lt;a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener"&gt;pkgsrc&lt;/a&gt; packages aren't cryptographically signed&lt;/li&gt;
&lt;li&gt;Someone from Joyent has been working on that, since they'd like to sign their pkgsrc packages for SmartOS&lt;/li&gt;
&lt;li&gt;Using GNUPG pulled in a lot of dependencies, and they're trying to keep the bootstrapping process minimal&lt;/li&gt;
&lt;li&gt;Instead, they're using netpgpverify, a fork of NetBSD's &lt;a href="https://en.wikipedia.org/wiki/Netpgp" rel="nofollow noopener"&gt;netpgp&lt;/a&gt; utility&lt;/li&gt;
&lt;li&gt;Maybe someday this will become the official way to sign packages in NetBSD?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-announce/2015-February/001624.html" rel="nofollow noopener"&gt;FreeBSD support model changes&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Starting with 11.0-RELEASE, which won't be for a few months probably, FreeBSD releases are going to have a different support model&lt;/li&gt;
&lt;li&gt;The plan is to move "from a point release-based support model to a set of releases from a branch with a guaranteed support lifetime"&lt;/li&gt;
&lt;li&gt;There will now be a five-year lifespan for each major release, regardless of how many minor point releases it gets&lt;/li&gt;
&lt;li&gt;This new model should reduce the turnaround time for errata and security patches, since there will be a lot less work involved to build and verify them&lt;/li&gt;
&lt;li&gt;Lots more detail can be found in the mailing list post, including some important changes to the -STABLE branch, so give it a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://guillaumevincent.com/2015/01/31/OpenSMTPD-Dovecot-SpamAssassin.html" rel="nofollow noopener"&gt;OpenSMTPD, Dovecot and SpamAssassin&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've been talking about setting up your own BSD-based mail server on the last couple episodes&lt;/li&gt;
&lt;li&gt;Here we have another post from a user setting up OpenSMTPD, including Dovecot for IMAP and SpamAssassin for spam filtering&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;lot&lt;/strong&gt; of people &lt;a href="http://permalink.gmane.org/gmane.mail.opensmtpd.general/2265" rel="nofollow noopener"&gt;regularly ask the developers&lt;/a&gt; how to combine OpenSMTPD with spam filtering, and this post should finally reveal the dark secrets&lt;/li&gt;
&lt;li&gt;In addition, it also covers SSL certificates, PKI and setting up MX records - some things that previous posts have lacked&lt;/li&gt;
&lt;li&gt;Just be sure to replace those "apt-get" commands and "eth0" interface names with something a bit more sane…&lt;/li&gt;
&lt;li&gt;In related news, OpenSMTPD has got some interesting new features &lt;a href="http://article.gmane.org/gmane.mail.opensmtpd.general/2272" rel="nofollow noopener"&gt;coming soon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;They're also planning to &lt;a href="https://github.com/OpenSMTPD/OpenSMTPD/issues/534" rel="nofollow noopener"&gt;switch to LibreSSL by default&lt;/a&gt; for the portable version
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lastsummer.de/freebsd-desktop-on-the-t400/" rel="nofollow noopener"&gt;FreeBSD 10 on the Thinkpad T400&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSD laptop articles are becoming popular it seems - this one is about FreeBSD on a T400&lt;/li&gt;
&lt;li&gt;Like most of the ones we've mentioned before, it shows you how to get a BSD desktop set up with all the little tweaks you might not think to do&lt;/li&gt;
&lt;li&gt;This one differs in that it takes a more minimal approach to graphics: instead of a full-featured environment like XFCE or KDE, it uses the i3 tiling window manager&lt;/li&gt;
&lt;li&gt;If you're a commandline junkie that basically just uses X11 to run more than one terminal at once, this might be an ideal setup for you&lt;/li&gt;
&lt;li&gt;The post also includes some bits about the DRM and KMS in the 10.x branch, as well as vt
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/02/1810/" rel="nofollow noopener"&gt;PC-BSD 10.1.1 Released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Automatic background updater now in&lt;/li&gt;
&lt;li&gt;Shiny new Qt5 utils&lt;/li&gt;
&lt;li&gt;OVA files for VM’s&lt;/li&gt;
&lt;li&gt;Full disk encryption with GELI v7
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2MsjllAyU" rel="nofollow noopener"&gt;Camio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20eYELsAg" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Y2GN1az" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20ARVQ1T6" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt; (&lt;a href="http://slexy.org/view/s212XezEYt" rel="nofollow noopener"&gt;TJ's lengthy reply&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DRgEv4j8" rel="nofollow noopener"&gt;Christopher writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-February/264010.html" rel="nofollow noopener"&gt;Special Instructions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-users/2015/01/19/msg015669.html" rel="nofollow noopener"&gt;Pretending to be a VT220&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ssh, ed25519, banana pi, opnsense, libressl, t400, opensmtpd, dovecot, mail server, spamassassin, foundation, donations</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be starting a two-part series detailing the activities of various BSD foundations. Ed Maste from the FreeBSD foundation will be joining us this time, and we'll talk about what all they've been up to lately. All this week's news and answers to viewer-submitted questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blog.djm.net.au/2015/02/key-rotation-in-openssh-68.html" rel="nofollow noopener">Key rotation in OpenSSH 6.8</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">Damien Miller</a> posted a new blog entry about one of the features in the upcoming OpenSSH 6.8</li>
<li>Times changes, key types change, problems are found with old algorithms and we switch to new ones</li>
<li>In OpenSSH (and the SSH protocol) however, there hasn't been an easy way to rotate host keys... until now</li>
<li>With this change, when you connect to a server, it will log <em>all</em> the server's public keys in your known_hosts file, instead of just the first one used during the key exchange</li>
<li>Keys that are in your known_hosts file but not on the server will get automatically removed</li>
<li>This fixes the problem of old servers still authenticating with ancient DSA or small RSA keys, as well as providing a way for the server to rotate keys every so often</li>
<li>There are some instructions in the blog post for how you'll be able to rotate host keys and eventually phase out the older ones - it's really simple</li>
<li>There are a lot of big changes coming in OpenSSH 6.8, so we'll be sure to cover them all when it's released
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/port-arm/2015/01/30/msg002809.html" rel="nofollow noopener">NetBSD Banana Pi images</a></h3>

<ul>
<li>We've talked about the <a href="http://www.bananapi.org/p/product.html" rel="nofollow noopener">Banana Pi</a> a bit before - it's a small ARM board that's comparable to the popular Raspberry Pi</li>
<li>Some NetBSD -current images were posted on the mailing list, so now you can get some BSD action on one of these little devices</li>
<li>There are even a set of prebuilt pkgsrc packages, so you won't have to compile everything initially</li>
<li>The email includes some steps to get everything working and an overview of what comes with the image</li>
<li>Also check <a href="https://wiki.netbsd.org/ports/evbarm/allwinner/" rel="nofollow noopener">the wiki page</a> for some related boards and further instructions on getting set up</li>
<li>On a related note, NetBSD also recently <a href="https://blog.netbsd.org/tnf/entry/raspberry_pi_gpu_acceleration_in" rel="nofollow noopener">got GPU acceleration working</a> for the Raspberry Pi (which is a first for their ARM port)
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142255048510669&amp;w=2" rel="nofollow noopener">LibreSSL shirts and other BSD goodies</a></h3>

<ul>
<li>If you've been keeping up with the LibreSSL saga and want a shirt to show your support, they're finally available to buy online</li>
<li>There are two versions, either "<a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTLSSL.jpg" rel="nofollow noopener">keep calm and use LibreSSL</a>" or the slightly more snarky "<a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTOSSL.jpg" rel="nofollow noopener">keep calm and abandon OpenSSL</a>"</li>
<li>While on the topic, we thought it would be good to make people aware of shirts for other BSD projects too</li>
<li>You can get some FreeBSD, <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=pc-bsd" rel="nofollow noopener">PCBSD</a> and FreeNAS <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=shirts" rel="nofollow noopener">stuff</a> from the <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=tshirt" rel="nofollow noopener">FreeBSD mall site</a></li>
<li>OpenBSD recently launched their <a href="https://www.openbsdstore.com" rel="nofollow noopener">new store</a>, but the selection is still a bit limited right now</li>
<li>NetBSD has a <a href="https://www.netbsd.org/gallery/devotionalia.html#cafepress" rel="nofollow noopener">couple places</a> where you can buy shirts and other apparel with the flag logo on it</li>
<li>We couldn't find any DragonFlyBSD shirts unfortunately, which is a shame since <a href="http://www.dragonflybsd.org/images/small_logo.png" rel="nofollow noopener">their logo</a> is pretty cool</li>
<li>Profits from the sale of the gear go back to the projects, so pick up some swag and support your BSD of choice (and of course wear them at any Linux events you happen to go to)
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=35.0" rel="nofollow noopener">OPNsense 15.1.4 released</a></h3>

<ul>
<li>The OPNsense guys have been hard at work since <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">we spoke to them</a>, fixing lots of bugs and keeping everything up to date</li>
<li>A number of versions have come out since then, with 15.1.4 being the latest (assuming they haven't updated it <strong>again</strong> by the time this airs)</li>
<li>This version includes the latest round of FreeBSD kernel security patches, as well as minor SSL and GUI fixes</li>
<li>They're doing a great job of getting upstream fixes pushed out to users quickly, a very welcome change</li>
<li>A developer has also posted an interesting write-up titled "<a href="http://lastsummer.de/development-workflow-in-opnsense/" rel="nofollow noopener">Development Workflow in OPNsense</a>"</li>
<li>If any of our listeners are trying OPNsense as their gateway firewall, let us know how you like it
***</li>
</ul>

<h2>Interview - Ed Maste - <a href="mailto:board@freebsdfoundation.org" rel="nofollow noopener">board@freebsdfoundation.org</a></h2>

<p><a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">The FreeBSD foundation</a>'s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://homing-on-code.blogspot.com/2015/02/rolling-with-snapshots.html" rel="nofollow noopener">Rolling with OpenBSD snapshots</a></h3>

<ul>
<li>One of the cool things about the -current branch of OpenBSD is that it doesn't require any compiling</li>
<li>There are signed binary snapshots being continuously re-rolled and posted on the FTP sites for every architecture</li>
<li>This provides an easy method to get onboard with the latest features, and you can also easily upgrade between them without reformatting or rebuilding</li>
<li>This blog post will walk you through the process of using snapshots to stay on the bleeding edge of OpenBSD goodness</li>
<li>After using -current for seven weeks, the author comes to the conclusion that it's not as unstable as people might think</li>
<li>He's now helping test out patches and new ports since he's running the same code as the developers
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/tech-pkg/2015/02/02/msg014224.html" rel="nofollow noopener">Signing pkgsrc packages</a></h3>

<ul>
<li>As of the time this show airs, the official <a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener">pkgsrc</a> packages aren't cryptographically signed</li>
<li>Someone from Joyent has been working on that, since they'd like to sign their pkgsrc packages for SmartOS</li>
<li>Using GNUPG pulled in a lot of dependencies, and they're trying to keep the bootstrapping process minimal</li>
<li>Instead, they're using netpgpverify, a fork of NetBSD's <a href="https://en.wikipedia.org/wiki/Netpgp" rel="nofollow noopener">netpgp</a> utility</li>
<li>Maybe someday this will become the official way to sign packages in NetBSD?
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-announce/2015-February/001624.html" rel="nofollow noopener">FreeBSD support model changes</a></h3>

<ul>
<li>Starting with 11.0-RELEASE, which won't be for a few months probably, FreeBSD releases are going to have a different support model</li>
<li>The plan is to move "from a point release-based support model to a set of releases from a branch with a guaranteed support lifetime"</li>
<li>There will now be a five-year lifespan for each major release, regardless of how many minor point releases it gets</li>
<li>This new model should reduce the turnaround time for errata and security patches, since there will be a lot less work involved to build and verify them</li>
<li>Lots more detail can be found in the mailing list post, including some important changes to the -STABLE branch, so give it a read
***</li>
</ul>

<h3><a href="http://guillaumevincent.com/2015/01/31/OpenSMTPD-Dovecot-SpamAssassin.html" rel="nofollow noopener">OpenSMTPD, Dovecot and SpamAssassin</a></h3>

<ul>
<li>We've been talking about setting up your own BSD-based mail server on the last couple episodes</li>
<li>Here we have another post from a user setting up OpenSMTPD, including Dovecot for IMAP and SpamAssassin for spam filtering</li>
<li>A <strong>lot</strong> of people <a href="http://permalink.gmane.org/gmane.mail.opensmtpd.general/2265" rel="nofollow noopener">regularly ask the developers</a> how to combine OpenSMTPD with spam filtering, and this post should finally reveal the dark secrets</li>
<li>In addition, it also covers SSL certificates, PKI and setting up MX records - some things that previous posts have lacked</li>
<li>Just be sure to replace those "apt-get" commands and "eth0" interface names with something a bit more sane…</li>
<li>In related news, OpenSMTPD has got some interesting new features <a href="http://article.gmane.org/gmane.mail.opensmtpd.general/2272" rel="nofollow noopener">coming soon</a></li>
<li>They're also planning to <a href="https://github.com/OpenSMTPD/OpenSMTPD/issues/534" rel="nofollow noopener">switch to LibreSSL by default</a> for the portable version
***</li>
</ul>

<h3><a href="http://lastsummer.de/freebsd-desktop-on-the-t400/" rel="nofollow noopener">FreeBSD 10 on the Thinkpad T400</a></h3>

<ul>
<li>BSD laptop articles are becoming popular it seems - this one is about FreeBSD on a T400</li>
<li>Like most of the ones we've mentioned before, it shows you how to get a BSD desktop set up with all the little tweaks you might not think to do</li>
<li>This one differs in that it takes a more minimal approach to graphics: instead of a full-featured environment like XFCE or KDE, it uses the i3 tiling window manager</li>
<li>If you're a commandline junkie that basically just uses X11 to run more than one terminal at once, this might be an ideal setup for you</li>
<li>The post also includes some bits about the DRM and KMS in the 10.x branch, as well as vt
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/02/1810/" rel="nofollow noopener">PC-BSD 10.1.1 Released</a></h3>

<ul>
<li>Automatic background updater now in</li>
<li>Shiny new Qt5 utils</li>
<li>OVA files for VM’s</li>
<li>Full disk encryption with GELI v7
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2MsjllAyU" rel="nofollow noopener">Camio writes in</a></li>
<li><a href="http://slexy.org/view/s20eYELsAg" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s20Y2GN1az" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s20ARVQ1T6" rel="nofollow noopener">Sean writes in</a> (<a href="http://slexy.org/view/s212XezEYt" rel="nofollow noopener">TJ's lengthy reply</a>)</li>
<li><a href="http://slexy.org/view/s2DRgEv4j8" rel="nofollow noopener">Christopher writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-February/264010.html" rel="nofollow noopener">Special Instructions</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-users/2015/01/19/msg015669.html" rel="nofollow noopener">Pretending to be a VT220</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be starting a two-part series detailing the activities of various BSD foundations. Ed Maste from the FreeBSD foundation will be joining us this time, and we'll talk about what all they've been up to lately. All this week's news and answers to viewer-submitted questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blog.djm.net.au/2015/02/key-rotation-in-openssh-68.html" rel="nofollow noopener">Key rotation in OpenSSH 6.8</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">Damien Miller</a> posted a new blog entry about one of the features in the upcoming OpenSSH 6.8</li>
<li>Times changes, key types change, problems are found with old algorithms and we switch to new ones</li>
<li>In OpenSSH (and the SSH protocol) however, there hasn't been an easy way to rotate host keys... until now</li>
<li>With this change, when you connect to a server, it will log <em>all</em> the server's public keys in your known_hosts file, instead of just the first one used during the key exchange</li>
<li>Keys that are in your known_hosts file but not on the server will get automatically removed</li>
<li>This fixes the problem of old servers still authenticating with ancient DSA or small RSA keys, as well as providing a way for the server to rotate keys every so often</li>
<li>There are some instructions in the blog post for how you'll be able to rotate host keys and eventually phase out the older ones - it's really simple</li>
<li>There are a lot of big changes coming in OpenSSH 6.8, so we'll be sure to cover them all when it's released
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/port-arm/2015/01/30/msg002809.html" rel="nofollow noopener">NetBSD Banana Pi images</a></h3>

<ul>
<li>We've talked about the <a href="http://www.bananapi.org/p/product.html" rel="nofollow noopener">Banana Pi</a> a bit before - it's a small ARM board that's comparable to the popular Raspberry Pi</li>
<li>Some NetBSD -current images were posted on the mailing list, so now you can get some BSD action on one of these little devices</li>
<li>There are even a set of prebuilt pkgsrc packages, so you won't have to compile everything initially</li>
<li>The email includes some steps to get everything working and an overview of what comes with the image</li>
<li>Also check <a href="https://wiki.netbsd.org/ports/evbarm/allwinner/" rel="nofollow noopener">the wiki page</a> for some related boards and further instructions on getting set up</li>
<li>On a related note, NetBSD also recently <a href="https://blog.netbsd.org/tnf/entry/raspberry_pi_gpu_acceleration_in" rel="nofollow noopener">got GPU acceleration working</a> for the Raspberry Pi (which is a first for their ARM port)
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142255048510669&amp;w=2" rel="nofollow noopener">LibreSSL shirts and other BSD goodies</a></h3>

<ul>
<li>If you've been keeping up with the LibreSSL saga and want a shirt to show your support, they're finally available to buy online</li>
<li>There are two versions, either "<a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTLSSL.jpg" rel="nofollow noopener">keep calm and use LibreSSL</a>" or the slightly more snarky "<a href="https://shop.openbsdeurope.com/images/shop_openbsdeurope_com/products/large/TSHIRTOSSL.jpg" rel="nofollow noopener">keep calm and abandon OpenSSL</a>"</li>
<li>While on the topic, we thought it would be good to make people aware of shirts for other BSD projects too</li>
<li>You can get some FreeBSD, <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=pc-bsd" rel="nofollow noopener">PCBSD</a> and FreeNAS <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=shirts" rel="nofollow noopener">stuff</a> from the <a href="https://www.freebsdmall.com/cgi-bin/fm/scan/fi=prod_bsd/se=tshirt" rel="nofollow noopener">FreeBSD mall site</a></li>
<li>OpenBSD recently launched their <a href="https://www.openbsdstore.com" rel="nofollow noopener">new store</a>, but the selection is still a bit limited right now</li>
<li>NetBSD has a <a href="https://www.netbsd.org/gallery/devotionalia.html#cafepress" rel="nofollow noopener">couple places</a> where you can buy shirts and other apparel with the flag logo on it</li>
<li>We couldn't find any DragonFlyBSD shirts unfortunately, which is a shame since <a href="http://www.dragonflybsd.org/images/small_logo.png" rel="nofollow noopener">their logo</a> is pretty cool</li>
<li>Profits from the sale of the gear go back to the projects, so pick up some swag and support your BSD of choice (and of course wear them at any Linux events you happen to go to)
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=35.0" rel="nofollow noopener">OPNsense 15.1.4 released</a></h3>

<ul>
<li>The OPNsense guys have been hard at work since <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">we spoke to them</a>, fixing lots of bugs and keeping everything up to date</li>
<li>A number of versions have come out since then, with 15.1.4 being the latest (assuming they haven't updated it <strong>again</strong> by the time this airs)</li>
<li>This version includes the latest round of FreeBSD kernel security patches, as well as minor SSL and GUI fixes</li>
<li>They're doing a great job of getting upstream fixes pushed out to users quickly, a very welcome change</li>
<li>A developer has also posted an interesting write-up titled "<a href="http://lastsummer.de/development-workflow-in-opnsense/" rel="nofollow noopener">Development Workflow in OPNsense</a>"</li>
<li>If any of our listeners are trying OPNsense as their gateway firewall, let us know how you like it
***</li>
</ul>

<h2>Interview - Ed Maste - <a href="mailto:board@freebsdfoundation.org" rel="nofollow noopener">board@freebsdfoundation.org</a></h2>

<p><a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">The FreeBSD foundation</a>'s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://homing-on-code.blogspot.com/2015/02/rolling-with-snapshots.html" rel="nofollow noopener">Rolling with OpenBSD snapshots</a></h3>

<ul>
<li>One of the cool things about the -current branch of OpenBSD is that it doesn't require any compiling</li>
<li>There are signed binary snapshots being continuously re-rolled and posted on the FTP sites for every architecture</li>
<li>This provides an easy method to get onboard with the latest features, and you can also easily upgrade between them without reformatting or rebuilding</li>
<li>This blog post will walk you through the process of using snapshots to stay on the bleeding edge of OpenBSD goodness</li>
<li>After using -current for seven weeks, the author comes to the conclusion that it's not as unstable as people might think</li>
<li>He's now helping test out patches and new ports since he's running the same code as the developers
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/tech-pkg/2015/02/02/msg014224.html" rel="nofollow noopener">Signing pkgsrc packages</a></h3>

<ul>
<li>As of the time this show airs, the official <a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener">pkgsrc</a> packages aren't cryptographically signed</li>
<li>Someone from Joyent has been working on that, since they'd like to sign their pkgsrc packages for SmartOS</li>
<li>Using GNUPG pulled in a lot of dependencies, and they're trying to keep the bootstrapping process minimal</li>
<li>Instead, they're using netpgpverify, a fork of NetBSD's <a href="https://en.wikipedia.org/wiki/Netpgp" rel="nofollow noopener">netpgp</a> utility</li>
<li>Maybe someday this will become the official way to sign packages in NetBSD?
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-announce/2015-February/001624.html" rel="nofollow noopener">FreeBSD support model changes</a></h3>

<ul>
<li>Starting with 11.0-RELEASE, which won't be for a few months probably, FreeBSD releases are going to have a different support model</li>
<li>The plan is to move "from a point release-based support model to a set of releases from a branch with a guaranteed support lifetime"</li>
<li>There will now be a five-year lifespan for each major release, regardless of how many minor point releases it gets</li>
<li>This new model should reduce the turnaround time for errata and security patches, since there will be a lot less work involved to build and verify them</li>
<li>Lots more detail can be found in the mailing list post, including some important changes to the -STABLE branch, so give it a read
***</li>
</ul>

<h3><a href="http://guillaumevincent.com/2015/01/31/OpenSMTPD-Dovecot-SpamAssassin.html" rel="nofollow noopener">OpenSMTPD, Dovecot and SpamAssassin</a></h3>

<ul>
<li>We've been talking about setting up your own BSD-based mail server on the last couple episodes</li>
<li>Here we have another post from a user setting up OpenSMTPD, including Dovecot for IMAP and SpamAssassin for spam filtering</li>
<li>A <strong>lot</strong> of people <a href="http://permalink.gmane.org/gmane.mail.opensmtpd.general/2265" rel="nofollow noopener">regularly ask the developers</a> how to combine OpenSMTPD with spam filtering, and this post should finally reveal the dark secrets</li>
<li>In addition, it also covers SSL certificates, PKI and setting up MX records - some things that previous posts have lacked</li>
<li>Just be sure to replace those "apt-get" commands and "eth0" interface names with something a bit more sane…</li>
<li>In related news, OpenSMTPD has got some interesting new features <a href="http://article.gmane.org/gmane.mail.opensmtpd.general/2272" rel="nofollow noopener">coming soon</a></li>
<li>They're also planning to <a href="https://github.com/OpenSMTPD/OpenSMTPD/issues/534" rel="nofollow noopener">switch to LibreSSL by default</a> for the portable version
***</li>
</ul>

<h3><a href="http://lastsummer.de/freebsd-desktop-on-the-t400/" rel="nofollow noopener">FreeBSD 10 on the Thinkpad T400</a></h3>

<ul>
<li>BSD laptop articles are becoming popular it seems - this one is about FreeBSD on a T400</li>
<li>Like most of the ones we've mentioned before, it shows you how to get a BSD desktop set up with all the little tweaks you might not think to do</li>
<li>This one differs in that it takes a more minimal approach to graphics: instead of a full-featured environment like XFCE or KDE, it uses the i3 tiling window manager</li>
<li>If you're a commandline junkie that basically just uses X11 to run more than one terminal at once, this might be an ideal setup for you</li>
<li>The post also includes some bits about the DRM and KMS in the 10.x branch, as well as vt
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/02/1810/" rel="nofollow noopener">PC-BSD 10.1.1 Released</a></h3>

<ul>
<li>Automatic background updater now in</li>
<li>Shiny new Qt5 utils</li>
<li>OVA files for VM’s</li>
<li>Full disk encryption with GELI v7
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2MsjllAyU" rel="nofollow noopener">Camio writes in</a></li>
<li><a href="http://slexy.org/view/s20eYELsAg" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s20Y2GN1az" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s20ARVQ1T6" rel="nofollow noopener">Sean writes in</a> (<a href="http://slexy.org/view/s212XezEYt" rel="nofollow noopener">TJ's lengthy reply</a>)</li>
<li><a href="http://slexy.org/view/s2DRgEv4j8" rel="nofollow noopener">Christopher writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-February/264010.html" rel="nofollow noopener">Special Instructions</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-users/2015/01/19/msg015669.html" rel="nofollow noopener">Pretending to be a VT220</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>23: Time Signatures</title>
  <link>https://www.bsdnow.tv/23</link>
  <guid isPermaLink="false">d9e9eb7a-e7aa-4029-8881-05cc5f75e8b6</guid>
  <pubDate>Wed, 05 Feb 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d9e9eb7a-e7aa-4029-8881-05cc5f75e8b6.mp3" length="54539109" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:15:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener"&gt;FreeBSD foundation's 2013 fundraising results&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation finally counted all the money they made in 2013&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;$768,562 from 1659 donors&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Nice little blog post from the team with a giant beastie picture&lt;/li&gt;
&lt;li&gt;"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."&lt;/li&gt;
&lt;li&gt;A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener"&gt;OpenSSH 6.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned the CFT last week, and it's &lt;a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener"&gt;finally here&lt;/a&gt;!&lt;/li&gt;
&lt;li&gt;New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)&lt;/li&gt;
&lt;li&gt;Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA&lt;/li&gt;
&lt;li&gt;Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes &lt;a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener"&gt;can't even attempt to login&lt;/a&gt; lol~&lt;/li&gt;
&lt;li&gt;New bcrypt private key type, 500,000,000 times harder to brute force&lt;/li&gt;
&lt;li&gt;Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one&lt;/li&gt;
&lt;li&gt;Portable version &lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=261320" rel="nofollow noopener"&gt;already in&lt;/a&gt; FreeBSD -CURRENT, &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;sortby=date&amp;amp;revision=342618" rel="nofollow noopener"&gt;and ports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots more bugfixes and features, see the full release note or &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;our interview&lt;/a&gt; with Damien&lt;/li&gt;
&lt;li&gt;Work has already started on 6.6, which &lt;a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener"&gt;can be used without OpenSSL&lt;/a&gt;!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener"&gt;Crazed Ferrets in a Berkeley Shower&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In 2000, &lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;MWL&lt;/a&gt; wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."&lt;/li&gt;
&lt;li&gt;This is basically an updated version about why he uses the BSD license, in response to recent &lt;a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener"&gt;comments from Richard Stallman&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL&lt;/li&gt;
&lt;li&gt;Check out the full post if you're one of those people that gets into license arguments&lt;/li&gt;
&lt;li&gt;The takeaway is "BSD is about making the world a better place. For everyone."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener"&gt;OpenBSD on BeagleBone Black&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi&lt;/li&gt;
&lt;li&gt;A blog post about installing OpenBSD on a BBB from.. our guest for today!&lt;/li&gt;
&lt;li&gt;He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"&lt;/li&gt;
&lt;li&gt;It goes through the whole process, details different storage options and some workarounds&lt;/li&gt;
&lt;li&gt;Could be a really fun weekend project if you're interested in small or embedded devices
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ted Unangst - &lt;a href="mailto:tedu@openbsd.org" rel="nofollow noopener"&gt;tedu@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/tedunangst" rel="nofollow noopener"&gt;@tedunangst&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's &lt;a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener"&gt;signify&lt;/a&gt; infrastructure, ZFS on OpenBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;Running an NTP server&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener"&gt;Getting started with FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new video and blog series about starting out with FreeBSD&lt;/li&gt;
&lt;li&gt;The author has been a fan since the 90s and has installed it on every server he's worked with&lt;/li&gt;
&lt;li&gt;He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users&lt;/li&gt;
&lt;li&gt;The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140204080515" rel="nofollow noopener"&gt;More OpenBSD hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience&lt;/li&gt;
&lt;li&gt;He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work&lt;/li&gt;
&lt;li&gt;This summary goes into detail about all the stuff he got done there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=261266" rel="nofollow noopener"&gt;X11 in a jail&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!&lt;/li&gt;
&lt;li&gt;A new tunable option will let jails access /dev/kmem and similar device nodes&lt;/li&gt;
&lt;li&gt;Along with a change to DRM, this allows full X11 in a jail&lt;/li&gt;
&lt;li&gt;Be sure to check out our &lt;a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener"&gt;jail tutorial and jailed VNC tutorial&lt;/a&gt; for ideas
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;10.0 "Joule Edition" &lt;a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener"&gt;finally released&lt;/a&gt;!&lt;/li&gt;
&lt;li&gt;AMD graphics are now officially supported&lt;/li&gt;
&lt;li&gt;GNOME3, MATE and Cinnamon desktops are available&lt;/li&gt;
&lt;li&gt;Grub updates and fixes&lt;/li&gt;
&lt;li&gt;PCBSD also &lt;a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener"&gt;got a mention in eweek&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener"&gt;Justin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener"&gt;Daniel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener"&gt;Martin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt; - &lt;a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener"&gt;unofficial FreeBSD RPI Images&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, security, gpg, gnupg, signed, packages, iso, set, patches, ted unangst, verify, verification, digital signature, ed25519, chacha20, license, debate, gnu, gpl, general public license, copyleft, copyfree, free software, open source, rms, richard stallman, clang, llvm, cddl, linux, gplv2, gplv3, ntp, ntpd, openntpd, isc, network time protocol, server, ssh, openssh, 6.5, foundation, donations, gcm, aes, aes-gcm, hmac, arm, armv7, beaglebone, black, serial, tty, zol, leaseweb, zfsonlinux, ecc</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener">FreeBSD foundation's 2013 fundraising results</a></h3>

<ul>
<li>The FreeBSD foundation finally counted all the money they made in 2013</li>
<li><strong>$768,562 from 1659 donors</strong></li>
<li>Nice little blog post from the team with a giant beastie picture</li>
<li>"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."</li>
<li>A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener">OpenSSH 6.5 released</a></h3>

<ul>
<li>We mentioned the CFT last week, and it's <a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener">finally here</a>!</li>
<li>New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)</li>
<li>Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA</li>
<li>Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes <a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener">can't even attempt to login</a> lol~</li>
<li>New bcrypt private key type, 500,000,000 times harder to brute force</li>
<li>Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one</li>
<li>Portable version <a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261320" rel="nofollow noopener">already in</a> FreeBSD -CURRENT, <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=342618" rel="nofollow noopener">and ports</a></li>
<li>Lots more bugfixes and features, see the full release note or <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">our interview</a> with Damien</li>
<li>Work has already started on 6.6, which <a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener">can be used without OpenSSL</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener">Crazed Ferrets in a Berkeley Shower</a></h3>

<ul>
<li>In 2000, <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a> wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."</li>
<li>This is basically an updated version about why he uses the BSD license, in response to recent <a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener">comments from Richard Stallman</a></li>
<li>Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL</li>
<li>Check out the full post if you're one of those people that gets into license arguments</li>
<li>The takeaway is "BSD is about making the world a better place. For everyone."
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener">OpenBSD on BeagleBone Black</a></h3>

<ul>
<li>Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi</li>
<li>A blog post about installing OpenBSD on a BBB from.. our guest for today!</li>
<li>He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"</li>
<li>It goes through the whole process, details different storage options and some workarounds</li>
<li>Could be a really fun weekend project if you're interested in small or embedded devices
***</li>
</ul>

<h2>Interview - Ted Unangst - <a href="mailto:tedu@openbsd.org" rel="nofollow noopener">tedu@openbsd.org</a> / <a href="https://twitter.com/tedunangst" rel="nofollow noopener">@tedunangst</a></h2>

<p>OpenBSD's <a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener">signify</a> infrastructure, ZFS on OpenBSD</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">Running an NTP server</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener">Getting started with FreeBSD</a></h3>

<ul>
<li>A new video and blog series about starting out with FreeBSD</li>
<li>The author has been a fan since the 90s and has installed it on every server he's worked with</li>
<li>He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users</li>
<li>The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140204080515" rel="nofollow noopener">More OpenBSD hackathon reports</a></h3>

<ul>
<li>As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience</li>
<li>He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work</li>
<li>This summary goes into detail about all the stuff he got done there
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261266" rel="nofollow noopener">X11 in a jail</a></h3>

<ul>
<li>We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!</li>
<li>A new tunable option will let jails access /dev/kmem and similar device nodes</li>
<li>Along with a change to DRM, this allows full X11 in a jail</li>
<li>Be sure to check out our <a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener">jail tutorial and jailed VNC tutorial</a> for ideas
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0 "Joule Edition" <a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener">finally released</a>!</li>
<li>AMD graphics are now officially supported</li>
<li>GNOME3, MATE and Cinnamon desktops are available</li>
<li>Grub updates and fixes</li>
<li>PCBSD also <a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener">got a mention in eweek</a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener">Justin writes in</a></li>
<li><a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener">Alex writes in</a> - <a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener">unofficial FreeBSD RPI Images</a></li>
<li><a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener">FreeBSD foundation's 2013 fundraising results</a></h3>

<ul>
<li>The FreeBSD foundation finally counted all the money they made in 2013</li>
<li><strong>$768,562 from 1659 donors</strong></li>
<li>Nice little blog post from the team with a giant beastie picture</li>
<li>"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."</li>
<li>A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener">OpenSSH 6.5 released</a></h3>

<ul>
<li>We mentioned the CFT last week, and it's <a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener">finally here</a>!</li>
<li>New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)</li>
<li>Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA</li>
<li>Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes <a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener">can't even attempt to login</a> lol~</li>
<li>New bcrypt private key type, 500,000,000 times harder to brute force</li>
<li>Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one</li>
<li>Portable version <a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261320" rel="nofollow noopener">already in</a> FreeBSD -CURRENT, <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=342618" rel="nofollow noopener">and ports</a></li>
<li>Lots more bugfixes and features, see the full release note or <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">our interview</a> with Damien</li>
<li>Work has already started on 6.6, which <a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener">can be used without OpenSSL</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener">Crazed Ferrets in a Berkeley Shower</a></h3>

<ul>
<li>In 2000, <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a> wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."</li>
<li>This is basically an updated version about why he uses the BSD license, in response to recent <a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener">comments from Richard Stallman</a></li>
<li>Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL</li>
<li>Check out the full post if you're one of those people that gets into license arguments</li>
<li>The takeaway is "BSD is about making the world a better place. For everyone."
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener">OpenBSD on BeagleBone Black</a></h3>

<ul>
<li>Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi</li>
<li>A blog post about installing OpenBSD on a BBB from.. our guest for today!</li>
<li>He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"</li>
<li>It goes through the whole process, details different storage options and some workarounds</li>
<li>Could be a really fun weekend project if you're interested in small or embedded devices
***</li>
</ul>

<h2>Interview - Ted Unangst - <a href="mailto:tedu@openbsd.org" rel="nofollow noopener">tedu@openbsd.org</a> / <a href="https://twitter.com/tedunangst" rel="nofollow noopener">@tedunangst</a></h2>

<p>OpenBSD's <a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener">signify</a> infrastructure, ZFS on OpenBSD</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">Running an NTP server</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener">Getting started with FreeBSD</a></h3>

<ul>
<li>A new video and blog series about starting out with FreeBSD</li>
<li>The author has been a fan since the 90s and has installed it on every server he's worked with</li>
<li>He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users</li>
<li>The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140204080515" rel="nofollow noopener">More OpenBSD hackathon reports</a></h3>

<ul>
<li>As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience</li>
<li>He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work</li>
<li>This summary goes into detail about all the stuff he got done there
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261266" rel="nofollow noopener">X11 in a jail</a></h3>

<ul>
<li>We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!</li>
<li>A new tunable option will let jails access /dev/kmem and similar device nodes</li>
<li>Along with a change to DRM, this allows full X11 in a jail</li>
<li>Be sure to check out our <a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener">jail tutorial and jailed VNC tutorial</a> for ideas
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0 "Joule Edition" <a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener">finally released</a>!</li>
<li>AMD graphics are now officially supported</li>
<li>GNOME3, MATE and Cinnamon desktops are available</li>
<li>Grub updates and fixes</li>
<li>PCBSD also <a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener">got a mention in eweek</a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener">Justin writes in</a></li>
<li><a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener">Alex writes in</a> - <a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener">unofficial FreeBSD RPI Images</a></li>
<li><a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>16: Cryptocrystalline</title>
  <link>https://www.bsdnow.tv/16</link>
  <guid isPermaLink="false">d9af27cf-c4ff-4572-b119-cbfd0e4167c8</guid>
  <pubDate>Wed, 18 Dec 2013 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d9af27cf-c4ff-4572-b119-cbfd0e4167c8.mp3" length="79454910" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be showing you how to do a fully-encrypted installation of FreeBSD and OpenBSD. We also have an interview with Damien Miller - one of the lead developers of OpenSSH - about some recent crypto changes in the project. If you're into data security, today's the show for you. The latest news and all your burning questions answered, right here on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:50:21</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be showing you how to do a fully-encrypted installation of FreeBSD and OpenBSD. We also have an interview with Damien Miller - one of the lead developers of OpenSSH - about some recent crypto changes in the project. If you're into data security, today's the show for you. The latest news and all your burning questions answered, right here on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://johnchapin.boostrot.net/blog/2013/12/07/secure-comms-with-openbsd-and-openvpn-part-1/" rel="nofollow noopener"&gt;Secure communications with OpenBSD and OpenVPN&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Starting off today's theme of encryption...&lt;/li&gt;
&lt;li&gt;A new blog series about combining OpenBSD and OpenVPN to secure your internet traffic&lt;/li&gt;
&lt;li&gt;Part 1 covers installing OpenBSD with full disk encryption (which we'll be doing later on in the show)&lt;/li&gt;
&lt;li&gt;Part 2 covers the initial setup of OpenVPN certificates and keys&lt;/li&gt;
&lt;li&gt;Parts 3 and 4 are the OpenVPN server and client configuration&lt;/li&gt;
&lt;li&gt;Part 5 is some updates and closing remarks
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2013Dec-newsletter" rel="nofollow noopener"&gt;FreeBSD Foundation Newsletter&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The December 2013 semi-annual newsletter was sent out from the foundation&lt;/li&gt;
&lt;li&gt;In the newsletter you will find the president's letter, articles on the current development projects they sponsor and reports from all the conferences and summits they sponsored&lt;/li&gt;
&lt;li&gt;The president's letter alone is worth the read, really amazing&lt;/li&gt;
&lt;li&gt;Really long, with lots of details and stories from the conferences and projects
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://evertiq.com/design/33394" rel="nofollow noopener"&gt;Use of NetBSD with Marvell Kirkwood Processors&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Article that gives a brief history of NetBSD and how to use it on an IP-Plug computer&lt;/li&gt;
&lt;li&gt;The IP-Plug is a "multi-functional mini-server was developed by Promwad engineers by the order of AK-Systems. It is designed for solving a wide range of tasks in IP networks and can perform the functions of a computer or a server. The IP-Plug is powered from a 220V network and has low power consumption, as well as a small size (which can be compared to the size of a mobile phone charger)."&lt;/li&gt;
&lt;li&gt;Really cool little NetBSD ARM project with lots of graphs, pictures and details
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://adrianchadd.blogspot.com/2013/12/experimenting-with-zero-copy-network-io.html" rel="nofollow noopener"&gt;Experimenting with zero-copy network IO&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Long blog post from Adrian Chadd about zero-copy network IO on FreeBSD&lt;/li&gt;
&lt;li&gt;Discusses the different OS' implementations and options&lt;/li&gt;
&lt;li&gt;He's able to get 35 gbit/sec out of 70,000 active TCP sockets, but isn't stopping there&lt;/li&gt;
&lt;li&gt;Tons of details, check the full post
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Damien Miller - &lt;a href="mailto:djm@openbsd.org" rel="nofollow noopener"&gt;djm@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/damienmiller" rel="nofollow noopener"&gt;@damienmiller&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Cryptography in OpenBSD and OpenSSH&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;Full disk encryption in FreeBSD &amp;amp; OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=wWmVW2R_uz8" rel="nofollow noopener"&gt;OpenZFS office hours&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy &lt;a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener"&gt;George Wilson&lt;/a&gt; sat down to take some ZFS questions from the community&lt;/li&gt;
&lt;li&gt;You can see more info about it &lt;a href="http://open-zfs.org/wiki/OpenZFS_Office_Hours" rel="nofollow noopener"&gt;here&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.shiningsilence.com/dbsdlog/2013/12/09/12934.html" rel="nofollow noopener"&gt;License summaries in pkgng&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A discussion between &lt;a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener"&gt;Justin Sherill&lt;/a&gt; and some NYCBUG guys about license frameworks in pkgng&lt;/li&gt;
&lt;li&gt;Similar to pkgsrc's "ACCEPTABLE_LICENSES" setting, pkgng could let the user decide which software licenses he wants to allow&lt;/li&gt;
&lt;li&gt;Maybe we could get a "pkg licenses" command to display the license of all installed packages&lt;/li&gt;
&lt;li&gt;Ok bapt, do it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener"&gt;The FreeBSD challenge continues&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Checking in with our buddy from the Linux foundation...&lt;/li&gt;
&lt;li&gt;The switching from Linux to FreeBSD blog series continues for his month-long trial&lt;/li&gt;
&lt;li&gt;Follow up from last week: "As a matter of fact, I did check out PC-BSD, and wanted the challenge.  Call me addicted to pain and suffering, but the pride and accomplishment you feel from diving into FreeBSD is quite rewarding."&lt;/li&gt;
&lt;li&gt;Since we last mentioned it, he's decided to go from a VM to real hardware, got all of his common software installed, experimented with the Linux emulation, set up virtualbox, learned about slices/partitions/disk management, found BSD alternatives to his regularly-used commands and lots more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=336615" rel="nofollow noopener"&gt;Ports gets a stable branch&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For the first time ever, FreeBSD's ports tree will have a maintained "stable" branch&lt;/li&gt;
&lt;li&gt;This is similar to how pkgsrc does things, with a rolling release for updated software and stable branch for only security and big fixes&lt;/li&gt;
&lt;li&gt;All commits to this branch require approval of portmgr, looks like it'll start in 2014Q1
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iRV1tOzB" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21gAR5lgf" rel="nofollow noopener"&gt;Spencer writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s203iOnFh1" rel="nofollow noopener"&gt;Campbell writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2yUqj3vKW" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2egcTPBXH" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonfly bsd, pcbsd, tutorial, howto, guide, bsd, interview, ssh, arm, openssh, sftp, security, damien miller, djm, mindrot, encryption, crypto, chacha20, poly1305, aes, hmac, mac, sha256, cipher, rc4, base64, encode, decode, ed25519, bcrypt, md5, hash, salt, openzfs, office hours, openvpn, vps, vpn, ssl, tun, tap, foundation, newsletter, freebsd journal, ixsystems, ecc, rsa, dsa, ecdsa, tunnel, keys, password, passphrase, full disk encryption, fde, installation, encrypted install, unencrypted</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be showing you how to do a fully-encrypted installation of FreeBSD and OpenBSD. We also have an interview with Damien Miller - one of the lead developers of OpenSSH - about some recent crypto changes in the project. If you're into data security, today's the show for you. The latest news and all your burning questions answered, right here on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://johnchapin.boostrot.net/blog/2013/12/07/secure-comms-with-openbsd-and-openvpn-part-1/" rel="nofollow noopener">Secure communications with OpenBSD and OpenVPN</a></h3>

<ul>
<li>Starting off today's theme of encryption...</li>
<li>A new blog series about combining OpenBSD and OpenVPN to secure your internet traffic</li>
<li>Part 1 covers installing OpenBSD with full disk encryption (which we'll be doing later on in the show)</li>
<li>Part 2 covers the initial setup of OpenVPN certificates and keys</li>
<li>Parts 3 and 4 are the OpenVPN server and client configuration</li>
<li>Part 5 is some updates and closing remarks
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2013Dec-newsletter" rel="nofollow noopener">FreeBSD Foundation Newsletter</a></h3>

<ul>
<li>The December 2013 semi-annual newsletter was sent out from the foundation</li>
<li>In the newsletter you will find the president's letter, articles on the current development projects they sponsor and reports from all the conferences and summits they sponsored</li>
<li>The president's letter alone is worth the read, really amazing</li>
<li>Really long, with lots of details and stories from the conferences and projects
***</li>
</ul>

<h3><a href="http://evertiq.com/design/33394" rel="nofollow noopener">Use of NetBSD with Marvell Kirkwood Processors</a></h3>

<ul>
<li>Article that gives a brief history of NetBSD and how to use it on an IP-Plug computer</li>
<li>The IP-Plug is a "multi-functional mini-server was developed by Promwad engineers by the order of AK-Systems. It is designed for solving a wide range of tasks in IP networks and can perform the functions of a computer or a server. The IP-Plug is powered from a 220V network and has low power consumption, as well as a small size (which can be compared to the size of a mobile phone charger)."</li>
<li>Really cool little NetBSD ARM project with lots of graphs, pictures and details
***</li>
</ul>

<h3><a href="http://adrianchadd.blogspot.com/2013/12/experimenting-with-zero-copy-network-io.html" rel="nofollow noopener">Experimenting with zero-copy network IO</a></h3>

<ul>
<li>Long blog post from Adrian Chadd about zero-copy network IO on FreeBSD</li>
<li>Discusses the different OS' implementations and options</li>
<li>He's able to get 35 gbit/sec out of 70,000 active TCP sockets, but isn't stopping there</li>
<li>Tons of details, check the full post
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>Cryptography in OpenBSD and OpenSSH</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">Full disk encryption in FreeBSD &amp; OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.youtube.com/watch?v=wWmVW2R_uz8" rel="nofollow noopener">OpenZFS office hours</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener">George Wilson</a> sat down to take some ZFS questions from the community</li>
<li>You can see more info about it <a href="http://open-zfs.org/wiki/OpenZFS_Office_Hours" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2013/12/09/12934.html" rel="nofollow noopener">License summaries in pkgng</a></h3>

<ul>
<li>A discussion between <a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener">Justin Sherill</a> and some NYCBUG guys about license frameworks in pkgng</li>
<li>Similar to pkgsrc's "ACCEPTABLE_LICENSES" setting, pkgng could let the user decide which software licenses he wants to allow</li>
<li>Maybe we could get a "pkg licenses" command to display the license of all installed packages</li>
<li>Ok bapt, do it
***</li>
</ul>

<h3><a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener">The FreeBSD challenge continues</a></h3>

<ul>
<li>Checking in with our buddy from the Linux foundation...</li>
<li>The switching from Linux to FreeBSD blog series continues for his month-long trial</li>
<li>Follow up from last week: "As a matter of fact, I did check out PC-BSD, and wanted the challenge.  Call me addicted to pain and suffering, but the pride and accomplishment you feel from diving into FreeBSD is quite rewarding."</li>
<li>Since we last mentioned it, he's decided to go from a VM to real hardware, got all of his common software installed, experimented with the Linux emulation, set up virtualbox, learned about slices/partitions/disk management, found BSD alternatives to his regularly-used commands and lots more
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=336615" rel="nofollow noopener">Ports gets a stable branch</a></h3>

<ul>
<li>For the first time ever, FreeBSD's ports tree will have a maintained "stable" branch</li>
<li>This is similar to how pkgsrc does things, with a rolling release for updated software and stable branch for only security and big fixes</li>
<li>All commits to this branch require approval of portmgr, looks like it'll start in 2014Q1
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iRV1tOzB" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s21gAR5lgf" rel="nofollow noopener">Spencer writes in</a></li>
<li><a href="http://slexy.org/view/s203iOnFh1" rel="nofollow noopener">Campbell writes in</a></li>
<li><a href="http://slexy.org/view/s2yUqj3vKW" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2egcTPBXH" rel="nofollow noopener">Clint writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be showing you how to do a fully-encrypted installation of FreeBSD and OpenBSD. We also have an interview with Damien Miller - one of the lead developers of OpenSSH - about some recent crypto changes in the project. If you're into data security, today's the show for you. The latest news and all your burning questions answered, right here on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://johnchapin.boostrot.net/blog/2013/12/07/secure-comms-with-openbsd-and-openvpn-part-1/" rel="nofollow noopener">Secure communications with OpenBSD and OpenVPN</a></h3>

<ul>
<li>Starting off today's theme of encryption...</li>
<li>A new blog series about combining OpenBSD and OpenVPN to secure your internet traffic</li>
<li>Part 1 covers installing OpenBSD with full disk encryption (which we'll be doing later on in the show)</li>
<li>Part 2 covers the initial setup of OpenVPN certificates and keys</li>
<li>Parts 3 and 4 are the OpenVPN server and client configuration</li>
<li>Part 5 is some updates and closing remarks
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2013Dec-newsletter" rel="nofollow noopener">FreeBSD Foundation Newsletter</a></h3>

<ul>
<li>The December 2013 semi-annual newsletter was sent out from the foundation</li>
<li>In the newsletter you will find the president's letter, articles on the current development projects they sponsor and reports from all the conferences and summits they sponsored</li>
<li>The president's letter alone is worth the read, really amazing</li>
<li>Really long, with lots of details and stories from the conferences and projects
***</li>
</ul>

<h3><a href="http://evertiq.com/design/33394" rel="nofollow noopener">Use of NetBSD with Marvell Kirkwood Processors</a></h3>

<ul>
<li>Article that gives a brief history of NetBSD and how to use it on an IP-Plug computer</li>
<li>The IP-Plug is a "multi-functional mini-server was developed by Promwad engineers by the order of AK-Systems. It is designed for solving a wide range of tasks in IP networks and can perform the functions of a computer or a server. The IP-Plug is powered from a 220V network and has low power consumption, as well as a small size (which can be compared to the size of a mobile phone charger)."</li>
<li>Really cool little NetBSD ARM project with lots of graphs, pictures and details
***</li>
</ul>

<h3><a href="http://adrianchadd.blogspot.com/2013/12/experimenting-with-zero-copy-network-io.html" rel="nofollow noopener">Experimenting with zero-copy network IO</a></h3>

<ul>
<li>Long blog post from Adrian Chadd about zero-copy network IO on FreeBSD</li>
<li>Discusses the different OS' implementations and options</li>
<li>He's able to get 35 gbit/sec out of 70,000 active TCP sockets, but isn't stopping there</li>
<li>Tons of details, check the full post
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>Cryptography in OpenBSD and OpenSSH</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">Full disk encryption in FreeBSD &amp; OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.youtube.com/watch?v=wWmVW2R_uz8" rel="nofollow noopener">OpenZFS office hours</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener">George Wilson</a> sat down to take some ZFS questions from the community</li>
<li>You can see more info about it <a href="http://open-zfs.org/wiki/OpenZFS_Office_Hours" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2013/12/09/12934.html" rel="nofollow noopener">License summaries in pkgng</a></h3>

<ul>
<li>A discussion between <a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener">Justin Sherill</a> and some NYCBUG guys about license frameworks in pkgng</li>
<li>Similar to pkgsrc's "ACCEPTABLE_LICENSES" setting, pkgng could let the user decide which software licenses he wants to allow</li>
<li>Maybe we could get a "pkg licenses" command to display the license of all installed packages</li>
<li>Ok bapt, do it
***</li>
</ul>

<h3><a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener">The FreeBSD challenge continues</a></h3>

<ul>
<li>Checking in with our buddy from the Linux foundation...</li>
<li>The switching from Linux to FreeBSD blog series continues for his month-long trial</li>
<li>Follow up from last week: "As a matter of fact, I did check out PC-BSD, and wanted the challenge.  Call me addicted to pain and suffering, but the pride and accomplishment you feel from diving into FreeBSD is quite rewarding."</li>
<li>Since we last mentioned it, he's decided to go from a VM to real hardware, got all of his common software installed, experimented with the Linux emulation, set up virtualbox, learned about slices/partitions/disk management, found BSD alternatives to his regularly-used commands and lots more
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=336615" rel="nofollow noopener">Ports gets a stable branch</a></h3>

<ul>
<li>For the first time ever, FreeBSD's ports tree will have a maintained "stable" branch</li>
<li>This is similar to how pkgsrc does things, with a rolling release for updated software and stable branch for only security and big fixes</li>
<li>All commits to this branch require approval of portmgr, looks like it'll start in 2014Q1
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iRV1tOzB" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s21gAR5lgf" rel="nofollow noopener">Spencer writes in</a></li>
<li><a href="http://slexy.org/view/s203iOnFh1" rel="nofollow noopener">Campbell writes in</a></li>
<li><a href="http://slexy.org/view/s2yUqj3vKW" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2egcTPBXH" rel="nofollow noopener">Clint writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
