<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Thu, 04 Jun 2026 08:32:39 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Freebsd Mastery”</title>
    <link>https://www.bsdnow.tv/tags/freebsd%20mastery</link>
    <pubDate>Wed, 17 Dec 2014 08:00:00 -0500</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>68: Just the Essentials</title>
  <link>https://www.bsdnow.tv/68</link>
  <guid isPermaLink="false">d06324f4-7dc5-4b8f-9618-666fe480b68d</guid>
  <pubDate>Wed, 17 Dec 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d06324f4-7dc5-4b8f-9618-666fe480b68d.mp3" length="62609620" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be talking with Michael Lucas about his newest BSD book, "FreeBSD Mastery: Storage Essentials." It's got lots of great information about the disk subsystems, GEOM, filesystems, you name it. We've also got the usual round of news and answers to your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:26:57</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be talking with Michael Lucas about his newest BSD book, "FreeBSD Mastery: Storage Essentials." It's got lots of great information about the disk subsystems, GEOM, filesystems, you name it. We've also got the usual round of news and answers to your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/channel/UCLy8AikPZfWEmzWxUec69PA/videos" target="_blank" rel="nofollow noopener"&gt;More BSD conference videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned it a few times, but the "New Directions in Operating Systems" conference was held in November in the UK&lt;/li&gt;
&lt;li&gt;The presentations videos are now online, with a few BSD-related talks of interest&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" target="_blank" rel="nofollow noopener"&gt;Antti Kantee&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=GoB73cVyScI" target="_blank" rel="nofollow noopener"&gt;Rump kernels and why / how we got here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Franco Fichtner, &lt;a href="https://www.youtube.com/watch?v=WiMNuGTRgbA" target="_blank" rel="nofollow noopener"&gt;An introduction to userland networking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" target="_blank" rel="nofollow noopener"&gt;Robert Watson&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=60elN996rtg" target="_blank" rel="nofollow noopener"&gt;New ideas about old OS security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of other interesting, but non-BSD-related, talks were also presented, so check the &lt;a href="https://www.youtube.com/playlist?list=PLmRrx948XMnEUlzKOCYn3AzT8OAInP_5M" target="_blank" rel="nofollow noopener"&gt;full list&lt;/a&gt; if you're interested in operating systems in general&lt;/li&gt;
&lt;li&gt;The 2014 AsiaBSDCon videos are also slowly being uploaded (better late than never)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" target="_blank" rel="nofollow noopener"&gt;Kirk McKusick&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=E04LxKiu79I" target="_blank" rel="nofollow noopener"&gt;An Overview of Security in the FreeBSD Kernel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" target="_blank" rel="nofollow noopener"&gt;Matthew Ahrens&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=8T9Rh-46jhI" target="_blank" rel="nofollow noopener"&gt;OpenZFS ensures the continued excellence of ZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Eric Allman, &lt;a href="https://www.youtube.com/watch?v=o2dmreSy76Q" target="_blank" rel="nofollow noopener"&gt;Bambi Meets Godzilla: They Elope - Open Source Meets the Commercial World&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_12_25-the_gift_of_giving" target="_blank" rel="nofollow noopener"&gt;Scott Long&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=4sZZN8Szh14" target="_blank" rel="nofollow noopener"&gt;Modifying the FreeBSD kernel Netflix streaming servers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener"&gt;Dru Lavigne&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=z5apZFFvx4k" target="_blank" rel="nofollow noopener"&gt;ZFS for the Masses&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kris Moore, &lt;a href="https://www.youtube.com/watch?v=w-0PlAVSg5U" target="_blank" rel="nofollow noopener"&gt;Snapshots, Replication, and Boot Environments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_05_07-lets_get_raid" target="_blank" rel="nofollow noopener"&gt;David Chisnall&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=NLqDAclXMMU" target="_blank" rel="nofollow noopener"&gt;The Future of LLVM in the FreeBSD Toolchain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Luba Tang, &lt;a href="https://www.youtube.com/watch?v=fWgbBUPMsVw" target="_blank" rel="nofollow noopener"&gt;Bold, fast optimizing linker for BSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_23-its_gonna_get_nasty" target="_blank" rel="nofollow noopener"&gt;John Hixson&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=iwF82aep-l8" target="_blank" rel="nofollow noopener"&gt;Introduction to FreeNAS development&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Zbigniew Bodek, &lt;a href="https://www.youtube.com/watch?v=2KLXcyLZ_RE" target="_blank" rel="nofollow noopener"&gt;Transparent Superpages for FreeBSD on ARM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Michael Dexter, &lt;a href="https://www.youtube.com/watch?v=rjNg1eQ7uAk" target="_blank" rel="nofollow noopener"&gt;Visualizing Unix: Graphing bhyve, ZFS and PF with Graphite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_01_15-bhyve_mind" target="_blank" rel="nofollow noopener"&gt;Peter Grehan&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=wptkUxJSNMY" target="_blank" rel="nofollow noopener"&gt;Nested Paging in Bhyve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Martin Matuška, &lt;a href="https://www.youtube.com/watch?v=nb8jB5x0OX4" target="_blank" rel="nofollow noopener"&gt;Deploying FreeBSD systems with Foreman and mfsBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_16-certified_package_delivery" target="_blank" rel="nofollow noopener"&gt;James Brown&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=6eKMLuzsTbY" target="_blank" rel="nofollow noopener"&gt;Analysys of BSD Associate Exam Results&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mindaugas Rasiukevicius, &lt;a href="https://www.youtube.com/watch?v=cgBh0iC9WhM" target="_blank" rel="nofollow noopener"&gt;NPF - progress and perspective&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Luigi Rizzo, &lt;a href="https://www.youtube.com/watch?v=nW8iHgOL9y4" target="_blank" rel="nofollow noopener"&gt;Netmap as a core networking technology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener"&gt;Michael W. Lucas&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=o0purspHg-o" target="_blank" rel="nofollow noopener"&gt;Sudo: You're Doing it Wrong&lt;/a&gt; (not from a BSD conference, but still good)&lt;/li&gt;
&lt;li&gt;They should make for some great material to watch during the holidays
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://networkfilter.blogspot.com/2014/12/security-openbsd-vs-freebsd.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD vs FreeBSD security features&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;From the author of both the OpenBSD and FreeBSD secure gateway articles we've featured in the past comes a new entry about security&lt;/li&gt;
&lt;li&gt;The article goes through a list of all the security features enabled (and disabled) by default in both FreeBSD and OpenBSD&lt;/li&gt;
&lt;li&gt;It covers a wide range of topics, including: memory protection, randomization, encryption, privilege separation, Capsicum, securelevels, MAC, Jails and chroots, network stack hardening, firewall features and &lt;strong&gt;much more&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;This is definitely one of the most in-depth and complete articles we've seen in a while - the author seems to have done his homework&lt;/li&gt;
&lt;li&gt;If you're looking to secure any sort of BSD box, this post has some very detailed explanations of different exploit mitigation techniques - be sure to read the whole thing&lt;/li&gt;
&lt;li&gt;There are also &lt;a href="http://daemonforums.org/showthread.php?s=16fd0771d929aff294b252924b414f2c&amp;amp;t=8823" target="_blank" rel="nofollow noopener"&gt;some good comments&lt;/a&gt; on DaemonForums &lt;a href="https://lobste.rs/s/e3s9xr/security_openbsd_vs_freebsd" target="_blank" rel="nofollow noopener"&gt;and lobste.rs&lt;/a&gt; that you may want to read 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2014/12/the-password-you-changed-it-right.html" target="_blank" rel="nofollow noopener"&gt;The password? You changed it, right?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener"&gt;Peter Hansteen&lt;/a&gt; has a new blog post up, detailing some weird SSH bruteforcing he's seen recently&lt;/li&gt;
&lt;li&gt;He apparently reads his auth logs when he gets bored at an airport&lt;/li&gt;
&lt;li&gt;This new bruteforcing attempt seems to be targetting D-Link devices, as evidenced by the three usernames the bots try to use&lt;/li&gt;
&lt;li&gt;More than 700 IPs have tried to get into Peter's BSD boxes using these names in combination with weak passwords&lt;/li&gt;
&lt;li&gt;Lots more details, including the lists of passwords and IPs, can be found in the full article&lt;/li&gt;
&lt;li&gt;If you're &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;using a BSD router&lt;/a&gt;, things like this can be easily prevented with PF or fail2ban (and you probably don't have a "d-link" user anyway)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.infoworld.com/article/2858288/unix/intro-to-freebsd-for-linux-users.html" target="_blank" rel="nofollow noopener"&gt;Get started with FreeBSD, an intro for Linux users&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another new BSD article on a mainstream technology news site - seems we're getting popular&lt;/li&gt;
&lt;li&gt;This article is written for Linux users who may be considering switching over to BSD and wondering what it's all about&lt;/li&gt;
&lt;li&gt;It details installing FreeBSD 9.3 and getting a basic system setup, while touching on ports and packages, and explaining some terminology along the way&lt;/li&gt;
&lt;li&gt;"Among the legions of Linux users and admins, there seems to be a sort of passive curiosity about FreeBSD and other &lt;em&gt;BSDs. Like commuters on a packed train, they gaze out at a less crowded, vaguely mysterious train heading in a slightly different direction and wonder what traveling on that train might be like"
*&lt;/em&gt;*&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Michael W. Lucas - &lt;a href="mailto:mwlucas@michaelwlucas.com" target="_blank" rel="nofollow noopener"&gt;mwlucas@michaelwlucas.com&lt;/a&gt; / &lt;a href="https://twitter.com/mwlauthor" target="_blank" rel="nofollow noopener"&gt;@mwlauthor&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener"&gt;FreeBSD Mastery: Storage Essentials&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://poolp.org/0xa86e/Some-OpenSMTPD-overview,-part-3" target="_blank" rel="nofollow noopener"&gt;OpenSMTPD status update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" target="_blank" rel="nofollow noopener"&gt;OpenSMTPD guys&lt;/a&gt;, particularly Gilles, have posted an update on what they've been up to lately&lt;/li&gt;
&lt;li&gt;As of 5.6, it's become the default MTA in OpenBSD, and sendmail will be totally gone in 5.7&lt;/li&gt;
&lt;li&gt;Email is a much more tricky protocol than you might imagine, and the post goes through some of the weirdness and problems they've had to deal with&lt;/li&gt;
&lt;li&gt;There's also &lt;a href="https://poolp.org/0xa871/The-state-of-filters" target="_blank" rel="nofollow noopener"&gt;another post&lt;/a&gt; that goes into detail on their upcoming filtering API - a feature &lt;strong&gt;many&lt;/strong&gt; have requested&lt;/li&gt;
&lt;li&gt;The API is still being developed, but you can test it out now if you know what you're doing - full details in the article&lt;/li&gt;
&lt;li&gt;OpenSMTPD also has portable versions in FreeBSD ports and NetBSD pkgsrc, so check it out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2014-December/065806.html" target="_blank" rel="nofollow noopener"&gt;OpenCrypto changes in FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A little while back, &lt;a href="http://www.bsdnow.tv/episodes/2014_10_29-ipsecond_wind" target="_blank" rel="nofollow noopener"&gt;we talked to John-Mark Gurney&lt;/a&gt; about updating FreeBSD's OpenCrypto framework, specifically for IPSEC&lt;/li&gt;
&lt;li&gt;Some of that work has just landed in the -CURRENT branch, and the commit has a bit of details&lt;/li&gt;
&lt;li&gt;The ICM and GCM modes of AES were added, and both include support for AESNI&lt;/li&gt;
&lt;li&gt;There's a new port - "nist-kat" - that can be used to test the new modes of operation&lt;/li&gt;
&lt;li&gt;Some things were fixed in the process as well, including an issue that would leak timing info and result in the ability to forge messages&lt;/li&gt;
&lt;li&gt;Code was also borrowed from both OpenBSD and NetBSD to make this possible
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.protoc.org/blog/2014/11/23/first-thoughts-on-the-new-openbsd-httpd-server/" target="_blank" rel="nofollow noopener"&gt;First thoughts on OpenBSD's httpd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have a blog post from a user of OpenBSD's new homegrown web server that made its debut in 5.6&lt;/li&gt;
&lt;li&gt;The author loves that it has proper privilege separation, a very simple config syntax and that it always runs in a chroot&lt;/li&gt;
&lt;li&gt;He also mentions dynamic content hosting with FastCGI, and provides an example of how to set it up&lt;/li&gt;
&lt;li&gt;Be sure to check &lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener"&gt;our interview with Reyk&lt;/a&gt; about the new httpd if you're curious on how it got started&lt;/li&gt;
&lt;li&gt;Also, if you're running the version that came with 5.6, there's &lt;a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.6/common/009_httpd.patch.sig" target="_blank" rel="nofollow noopener"&gt;a huge patch&lt;/a&gt; you can apply to get a lot of the features and fixes from -current without waiting for 5.7
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=B04EuZ9hpAI" target="_blank" rel="nofollow noopener"&gt;Steam on PCBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the most common questions people who want to use BSD as a desktop ask us is "can I run games?" or "can I use steam?"&lt;/li&gt;
&lt;li&gt;Steam through the Linux emulation layer (in FreeBSD) may be possible soon, but it's already possible to use it with WINE&lt;/li&gt;
&lt;li&gt;This video shows how to get Steam set up on PCBSD using the Windows version&lt;/li&gt;
&lt;li&gt;There are also some instructions in the video description to look over&lt;/li&gt;
&lt;li&gt;A &lt;a href="https://www.youtube.com/watch?v=BJ88B8aWdk0" target="_blank" rel="nofollow noopener"&gt;second video&lt;/a&gt; details getting streaming set up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2JgqXcw4i" target="_blank" rel="nofollow noopener"&gt;Charlie writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2WormjMCs" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20UmdFrbj" target="_blank" rel="nofollow noopener"&gt;Predrag writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, freebsd mastery, storage essentials, ufs, zfs, disks, book, review, michael lucas, asiabsdcon, operatingsystems.io, opensmtpd, steam</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be talking with Michael Lucas about his newest BSD book, "FreeBSD Mastery: Storage Essentials." It's got lots of great information about the disk subsystems, GEOM, filesystems, you name it. We've also got the usual round of news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCLy8AikPZfWEmzWxUec69PA/videos" target="_blank" rel="nofollow noopener">More BSD conference videos</a></h3>

<ul>
<li>We mentioned it a few times, but the "New Directions in Operating Systems" conference was held in November in the UK</li>
<li>The presentations videos are now online, with a few BSD-related talks of interest</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" target="_blank" rel="nofollow noopener">Antti Kantee</a>, <a href="https://www.youtube.com/watch?v=GoB73cVyScI" target="_blank" rel="nofollow noopener">Rump kernels and why / how we got here</a></li>
<li>Franco Fichtner, <a href="https://www.youtube.com/watch?v=WiMNuGTRgbA" target="_blank" rel="nofollow noopener">An introduction to userland networking</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" target="_blank" rel="nofollow noopener">Robert Watson</a>, <a href="https://www.youtube.com/watch?v=60elN996rtg" target="_blank" rel="nofollow noopener">New ideas about old OS security</a></li>
<li>Lots of other interesting, but non-BSD-related, talks were also presented, so check the <a href="https://www.youtube.com/playlist?list=PLmRrx948XMnEUlzKOCYn3AzT8OAInP_5M" target="_blank" rel="nofollow noopener">full list</a> if you're interested in operating systems in general</li>
<li>The 2014 AsiaBSDCon videos are also slowly being uploaded (better late than never)</li>
<li><a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" target="_blank" rel="nofollow noopener">Kirk McKusick</a>, <a href="https://www.youtube.com/watch?v=E04LxKiu79I" target="_blank" rel="nofollow noopener">An Overview of Security in the FreeBSD Kernel</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" target="_blank" rel="nofollow noopener">Matthew Ahrens</a>, <a href="https://www.youtube.com/watch?v=8T9Rh-46jhI" target="_blank" rel="nofollow noopener">OpenZFS ensures the continued excellence of ZFS</a></li>
<li>Eric Allman, <a href="https://www.youtube.com/watch?v=o2dmreSy76Q" target="_blank" rel="nofollow noopener">Bambi Meets Godzilla: They Elope - Open Source Meets the Commercial World</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_25-the_gift_of_giving" target="_blank" rel="nofollow noopener">Scott Long</a>, <a href="https://www.youtube.com/watch?v=4sZZN8Szh14" target="_blank" rel="nofollow noopener">Modifying the FreeBSD kernel Netflix streaming servers</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener">Dru Lavigne</a>, <a href="https://www.youtube.com/watch?v=z5apZFFvx4k" target="_blank" rel="nofollow noopener">ZFS for the Masses</a></li>
<li>Kris Moore, <a href="https://www.youtube.com/watch?v=w-0PlAVSg5U" target="_blank" rel="nofollow noopener">Snapshots, Replication, and Boot Environments</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_07-lets_get_raid" target="_blank" rel="nofollow noopener">David Chisnall</a>, <a href="https://www.youtube.com/watch?v=NLqDAclXMMU" target="_blank" rel="nofollow noopener">The Future of LLVM in the FreeBSD Toolchain</a></li>
<li>Luba Tang, <a href="https://www.youtube.com/watch?v=fWgbBUPMsVw" target="_blank" rel="nofollow noopener">Bold, fast optimizing linker for BSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_23-its_gonna_get_nasty" target="_blank" rel="nofollow noopener">John Hixson</a>, <a href="https://www.youtube.com/watch?v=iwF82aep-l8" target="_blank" rel="nofollow noopener">Introduction to FreeNAS development</a></li>
<li>Zbigniew Bodek, <a href="https://www.youtube.com/watch?v=2KLXcyLZ_RE" target="_blank" rel="nofollow noopener">Transparent Superpages for FreeBSD on ARM</a></li>
<li>Michael Dexter, <a href="https://www.youtube.com/watch?v=rjNg1eQ7uAk" target="_blank" rel="nofollow noopener">Visualizing Unix: Graphing bhyve, ZFS and PF with Graphite</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_15-bhyve_mind" target="_blank" rel="nofollow noopener">Peter Grehan</a>, <a href="https://www.youtube.com/watch?v=wptkUxJSNMY" target="_blank" rel="nofollow noopener">Nested Paging in Bhyve</a></li>
<li>Martin Matuška, <a href="https://www.youtube.com/watch?v=nb8jB5x0OX4" target="_blank" rel="nofollow noopener">Deploying FreeBSD systems with Foreman and mfsBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_16-certified_package_delivery" target="_blank" rel="nofollow noopener">James Brown</a>, <a href="https://www.youtube.com/watch?v=6eKMLuzsTbY" target="_blank" rel="nofollow noopener">Analysys of BSD Associate Exam Results</a></li>
<li>Mindaugas Rasiukevicius, <a href="https://www.youtube.com/watch?v=cgBh0iC9WhM" target="_blank" rel="nofollow noopener">NPF - progress and perspective</a></li>
<li>Luigi Rizzo, <a href="https://www.youtube.com/watch?v=nW8iHgOL9y4" target="_blank" rel="nofollow noopener">Netmap as a core networking technology</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael W. Lucas</a>, <a href="https://www.youtube.com/watch?v=o0purspHg-o" target="_blank" rel="nofollow noopener">Sudo: You're Doing it Wrong</a> (not from a BSD conference, but still good)</li>
<li>They should make for some great material to watch during the holidays
***</li>
</ul>

<h3><a href="http://networkfilter.blogspot.com/2014/12/security-openbsd-vs-freebsd.html" target="_blank" rel="nofollow noopener">OpenBSD vs FreeBSD security features</a></h3>

<ul>
<li>From the author of both the OpenBSD and FreeBSD secure gateway articles we've featured in the past comes a new entry about security</li>
<li>The article goes through a list of all the security features enabled (and disabled) by default in both FreeBSD and OpenBSD</li>
<li>It covers a wide range of topics, including: memory protection, randomization, encryption, privilege separation, Capsicum, securelevels, MAC, Jails and chroots, network stack hardening, firewall features and <strong>much more</strong></li>
<li>This is definitely one of the most in-depth and complete articles we've seen in a while - the author seems to have done his homework</li>
<li>If you're looking to secure any sort of BSD box, this post has some very detailed explanations of different exploit mitigation techniques - be sure to read the whole thing</li>
<li>There are also <a href="http://daemonforums.org/showthread.php?s=16fd0771d929aff294b252924b414f2c&amp;t=8823" target="_blank" rel="nofollow noopener">some good comments</a> on DaemonForums <a href="https://lobste.rs/s/e3s9xr/security_openbsd_vs_freebsd" target="_blank" rel="nofollow noopener">and lobste.rs</a> that you may want to read 
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/12/the-password-you-changed-it-right.html" target="_blank" rel="nofollow noopener">The password? You changed it, right?</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener">Peter Hansteen</a> has a new blog post up, detailing some weird SSH bruteforcing he's seen recently</li>
<li>He apparently reads his auth logs when he gets bored at an airport</li>
<li>This new bruteforcing attempt seems to be targetting D-Link devices, as evidenced by the three usernames the bots try to use</li>
<li>More than 700 IPs have tried to get into Peter's BSD boxes using these names in combination with weak passwords</li>
<li>Lots more details, including the lists of passwords and IPs, can be found in the full article</li>
<li>If you're <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">using a BSD router</a>, things like this can be easily prevented with PF or fail2ban (and you probably don't have a "d-link" user anyway)
***</li>
</ul>

<h3><a href="http://www.infoworld.com/article/2858288/unix/intro-to-freebsd-for-linux-users.html" target="_blank" rel="nofollow noopener">Get started with FreeBSD, an intro for Linux users</a></h3>

<ul>
<li>Another new BSD article on a mainstream technology news site - seems we're getting popular</li>
<li>This article is written for Linux users who may be considering switching over to BSD and wondering what it's all about</li>
<li>It details installing FreeBSD 9.3 and getting a basic system setup, while touching on ports and packages, and explaining some terminology along the way</li>
<li>"Among the legions of Linux users and admins, there seems to be a sort of passive curiosity about FreeBSD and other <em>BSDs. Like commuters on a packed train, they gaze out at a less crowded, vaguely mysterious train heading in a slightly different direction and wonder what traveling on that train might be like"
*</em>*</li>
</ul>

<h2>Interview - Michael W. Lucas - <a href="mailto:mwlucas@michaelwlucas.com" target="_blank" rel="nofollow noopener">mwlucas@michaelwlucas.com</a> / <a href="https://twitter.com/mwlauthor" target="_blank" rel="nofollow noopener">@mwlauthor</a></h2>

<p><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener">FreeBSD Mastery: Storage Essentials</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://poolp.org/0xa86e/Some-OpenSMTPD-overview,-part-3" target="_blank" rel="nofollow noopener">OpenSMTPD status update</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" target="_blank" rel="nofollow noopener">OpenSMTPD guys</a>, particularly Gilles, have posted an update on what they've been up to lately</li>
<li>As of 5.6, it's become the default MTA in OpenBSD, and sendmail will be totally gone in 5.7</li>
<li>Email is a much more tricky protocol than you might imagine, and the post goes through some of the weirdness and problems they've had to deal with</li>
<li>There's also <a href="https://poolp.org/0xa871/The-state-of-filters" target="_blank" rel="nofollow noopener">another post</a> that goes into detail on their upcoming filtering API - a feature <strong>many</strong> have requested</li>
<li>The API is still being developed, but you can test it out now if you know what you're doing - full details in the article</li>
<li>OpenSMTPD also has portable versions in FreeBSD ports and NetBSD pkgsrc, so check it out
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/svn-src-head/2014-December/065806.html" target="_blank" rel="nofollow noopener">OpenCrypto changes in FreeBSD</a></h3>

<ul>
<li>A little while back, <a href="http://www.bsdnow.tv/episodes/2014_10_29-ipsecond_wind" target="_blank" rel="nofollow noopener">we talked to John-Mark Gurney</a> about updating FreeBSD's OpenCrypto framework, specifically for IPSEC</li>
<li>Some of that work has just landed in the -CURRENT branch, and the commit has a bit of details</li>
<li>The ICM and GCM modes of AES were added, and both include support for AESNI</li>
<li>There's a new port - "nist-kat" - that can be used to test the new modes of operation</li>
<li>Some things were fixed in the process as well, including an issue that would leak timing info and result in the ability to forge messages</li>
<li>Code was also borrowed from both OpenBSD and NetBSD to make this possible
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/11/23/first-thoughts-on-the-new-openbsd-httpd-server/" target="_blank" rel="nofollow noopener">First thoughts on OpenBSD's httpd</a></h3>

<ul>
<li>Here we have a blog post from a user of OpenBSD's new homegrown web server that made its debut in 5.6</li>
<li>The author loves that it has proper privilege separation, a very simple config syntax and that it always runs in a chroot</li>
<li>He also mentions dynamic content hosting with FastCGI, and provides an example of how to set it up</li>
<li>Be sure to check <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener">our interview with Reyk</a> about the new httpd if you're curious on how it got started</li>
<li>Also, if you're running the version that came with 5.6, there's <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.6/common/009_httpd.patch.sig" target="_blank" rel="nofollow noopener">a huge patch</a> you can apply to get a lot of the features and fixes from -current without waiting for 5.7
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=B04EuZ9hpAI" target="_blank" rel="nofollow noopener">Steam on PCBSD</a></h3>

<ul>
<li>One of the most common questions people who want to use BSD as a desktop ask us is "can I run games?" or "can I use steam?"</li>
<li>Steam through the Linux emulation layer (in FreeBSD) may be possible soon, but it's already possible to use it with WINE</li>
<li>This video shows how to get Steam set up on PCBSD using the Windows version</li>
<li>There are also some instructions in the video description to look over</li>
<li>A <a href="https://www.youtube.com/watch?v=BJ88B8aWdk0" target="_blank" rel="nofollow noopener">second video</a> details getting streaming set up
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2JgqXcw4i" target="_blank" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s2WormjMCs" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20UmdFrbj" target="_blank" rel="nofollow noopener">Predrag writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be talking with Michael Lucas about his newest BSD book, "FreeBSD Mastery: Storage Essentials." It's got lots of great information about the disk subsystems, GEOM, filesystems, you name it. We've also got the usual round of news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCLy8AikPZfWEmzWxUec69PA/videos" target="_blank" rel="nofollow noopener">More BSD conference videos</a></h3>

<ul>
<li>We mentioned it a few times, but the "New Directions in Operating Systems" conference was held in November in the UK</li>
<li>The presentations videos are now online, with a few BSD-related talks of interest</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" target="_blank" rel="nofollow noopener">Antti Kantee</a>, <a href="https://www.youtube.com/watch?v=GoB73cVyScI" target="_blank" rel="nofollow noopener">Rump kernels and why / how we got here</a></li>
<li>Franco Fichtner, <a href="https://www.youtube.com/watch?v=WiMNuGTRgbA" target="_blank" rel="nofollow noopener">An introduction to userland networking</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" target="_blank" rel="nofollow noopener">Robert Watson</a>, <a href="https://www.youtube.com/watch?v=60elN996rtg" target="_blank" rel="nofollow noopener">New ideas about old OS security</a></li>
<li>Lots of other interesting, but non-BSD-related, talks were also presented, so check the <a href="https://www.youtube.com/playlist?list=PLmRrx948XMnEUlzKOCYn3AzT8OAInP_5M" target="_blank" rel="nofollow noopener">full list</a> if you're interested in operating systems in general</li>
<li>The 2014 AsiaBSDCon videos are also slowly being uploaded (better late than never)</li>
<li><a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" target="_blank" rel="nofollow noopener">Kirk McKusick</a>, <a href="https://www.youtube.com/watch?v=E04LxKiu79I" target="_blank" rel="nofollow noopener">An Overview of Security in the FreeBSD Kernel</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" target="_blank" rel="nofollow noopener">Matthew Ahrens</a>, <a href="https://www.youtube.com/watch?v=8T9Rh-46jhI" target="_blank" rel="nofollow noopener">OpenZFS ensures the continued excellence of ZFS</a></li>
<li>Eric Allman, <a href="https://www.youtube.com/watch?v=o2dmreSy76Q" target="_blank" rel="nofollow noopener">Bambi Meets Godzilla: They Elope - Open Source Meets the Commercial World</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_25-the_gift_of_giving" target="_blank" rel="nofollow noopener">Scott Long</a>, <a href="https://www.youtube.com/watch?v=4sZZN8Szh14" target="_blank" rel="nofollow noopener">Modifying the FreeBSD kernel Netflix streaming servers</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener">Dru Lavigne</a>, <a href="https://www.youtube.com/watch?v=z5apZFFvx4k" target="_blank" rel="nofollow noopener">ZFS for the Masses</a></li>
<li>Kris Moore, <a href="https://www.youtube.com/watch?v=w-0PlAVSg5U" target="_blank" rel="nofollow noopener">Snapshots, Replication, and Boot Environments</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_07-lets_get_raid" target="_blank" rel="nofollow noopener">David Chisnall</a>, <a href="https://www.youtube.com/watch?v=NLqDAclXMMU" target="_blank" rel="nofollow noopener">The Future of LLVM in the FreeBSD Toolchain</a></li>
<li>Luba Tang, <a href="https://www.youtube.com/watch?v=fWgbBUPMsVw" target="_blank" rel="nofollow noopener">Bold, fast optimizing linker for BSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_23-its_gonna_get_nasty" target="_blank" rel="nofollow noopener">John Hixson</a>, <a href="https://www.youtube.com/watch?v=iwF82aep-l8" target="_blank" rel="nofollow noopener">Introduction to FreeNAS development</a></li>
<li>Zbigniew Bodek, <a href="https://www.youtube.com/watch?v=2KLXcyLZ_RE" target="_blank" rel="nofollow noopener">Transparent Superpages for FreeBSD on ARM</a></li>
<li>Michael Dexter, <a href="https://www.youtube.com/watch?v=rjNg1eQ7uAk" target="_blank" rel="nofollow noopener">Visualizing Unix: Graphing bhyve, ZFS and PF with Graphite</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_15-bhyve_mind" target="_blank" rel="nofollow noopener">Peter Grehan</a>, <a href="https://www.youtube.com/watch?v=wptkUxJSNMY" target="_blank" rel="nofollow noopener">Nested Paging in Bhyve</a></li>
<li>Martin Matuška, <a href="https://www.youtube.com/watch?v=nb8jB5x0OX4" target="_blank" rel="nofollow noopener">Deploying FreeBSD systems with Foreman and mfsBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_16-certified_package_delivery" target="_blank" rel="nofollow noopener">James Brown</a>, <a href="https://www.youtube.com/watch?v=6eKMLuzsTbY" target="_blank" rel="nofollow noopener">Analysys of BSD Associate Exam Results</a></li>
<li>Mindaugas Rasiukevicius, <a href="https://www.youtube.com/watch?v=cgBh0iC9WhM" target="_blank" rel="nofollow noopener">NPF - progress and perspective</a></li>
<li>Luigi Rizzo, <a href="https://www.youtube.com/watch?v=nW8iHgOL9y4" target="_blank" rel="nofollow noopener">Netmap as a core networking technology</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael W. Lucas</a>, <a href="https://www.youtube.com/watch?v=o0purspHg-o" target="_blank" rel="nofollow noopener">Sudo: You're Doing it Wrong</a> (not from a BSD conference, but still good)</li>
<li>They should make for some great material to watch during the holidays
***</li>
</ul>

<h3><a href="http://networkfilter.blogspot.com/2014/12/security-openbsd-vs-freebsd.html" target="_blank" rel="nofollow noopener">OpenBSD vs FreeBSD security features</a></h3>

<ul>
<li>From the author of both the OpenBSD and FreeBSD secure gateway articles we've featured in the past comes a new entry about security</li>
<li>The article goes through a list of all the security features enabled (and disabled) by default in both FreeBSD and OpenBSD</li>
<li>It covers a wide range of topics, including: memory protection, randomization, encryption, privilege separation, Capsicum, securelevels, MAC, Jails and chroots, network stack hardening, firewall features and <strong>much more</strong></li>
<li>This is definitely one of the most in-depth and complete articles we've seen in a while - the author seems to have done his homework</li>
<li>If you're looking to secure any sort of BSD box, this post has some very detailed explanations of different exploit mitigation techniques - be sure to read the whole thing</li>
<li>There are also <a href="http://daemonforums.org/showthread.php?s=16fd0771d929aff294b252924b414f2c&amp;t=8823" target="_blank" rel="nofollow noopener">some good comments</a> on DaemonForums <a href="https://lobste.rs/s/e3s9xr/security_openbsd_vs_freebsd" target="_blank" rel="nofollow noopener">and lobste.rs</a> that you may want to read 
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/12/the-password-you-changed-it-right.html" target="_blank" rel="nofollow noopener">The password? You changed it, right?</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener">Peter Hansteen</a> has a new blog post up, detailing some weird SSH bruteforcing he's seen recently</li>
<li>He apparently reads his auth logs when he gets bored at an airport</li>
<li>This new bruteforcing attempt seems to be targetting D-Link devices, as evidenced by the three usernames the bots try to use</li>
<li>More than 700 IPs have tried to get into Peter's BSD boxes using these names in combination with weak passwords</li>
<li>Lots more details, including the lists of passwords and IPs, can be found in the full article</li>
<li>If you're <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">using a BSD router</a>, things like this can be easily prevented with PF or fail2ban (and you probably don't have a "d-link" user anyway)
***</li>
</ul>

<h3><a href="http://www.infoworld.com/article/2858288/unix/intro-to-freebsd-for-linux-users.html" target="_blank" rel="nofollow noopener">Get started with FreeBSD, an intro for Linux users</a></h3>

<ul>
<li>Another new BSD article on a mainstream technology news site - seems we're getting popular</li>
<li>This article is written for Linux users who may be considering switching over to BSD and wondering what it's all about</li>
<li>It details installing FreeBSD 9.3 and getting a basic system setup, while touching on ports and packages, and explaining some terminology along the way</li>
<li>"Among the legions of Linux users and admins, there seems to be a sort of passive curiosity about FreeBSD and other <em>BSDs. Like commuters on a packed train, they gaze out at a less crowded, vaguely mysterious train heading in a slightly different direction and wonder what traveling on that train might be like"
*</em>*</li>
</ul>

<h2>Interview - Michael W. Lucas - <a href="mailto:mwlucas@michaelwlucas.com" target="_blank" rel="nofollow noopener">mwlucas@michaelwlucas.com</a> / <a href="https://twitter.com/mwlauthor" target="_blank" rel="nofollow noopener">@mwlauthor</a></h2>

<p><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener">FreeBSD Mastery: Storage Essentials</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://poolp.org/0xa86e/Some-OpenSMTPD-overview,-part-3" target="_blank" rel="nofollow noopener">OpenSMTPD status update</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" target="_blank" rel="nofollow noopener">OpenSMTPD guys</a>, particularly Gilles, have posted an update on what they've been up to lately</li>
<li>As of 5.6, it's become the default MTA in OpenBSD, and sendmail will be totally gone in 5.7</li>
<li>Email is a much more tricky protocol than you might imagine, and the post goes through some of the weirdness and problems they've had to deal with</li>
<li>There's also <a href="https://poolp.org/0xa871/The-state-of-filters" target="_blank" rel="nofollow noopener">another post</a> that goes into detail on their upcoming filtering API - a feature <strong>many</strong> have requested</li>
<li>The API is still being developed, but you can test it out now if you know what you're doing - full details in the article</li>
<li>OpenSMTPD also has portable versions in FreeBSD ports and NetBSD pkgsrc, so check it out
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/svn-src-head/2014-December/065806.html" target="_blank" rel="nofollow noopener">OpenCrypto changes in FreeBSD</a></h3>

<ul>
<li>A little while back, <a href="http://www.bsdnow.tv/episodes/2014_10_29-ipsecond_wind" target="_blank" rel="nofollow noopener">we talked to John-Mark Gurney</a> about updating FreeBSD's OpenCrypto framework, specifically for IPSEC</li>
<li>Some of that work has just landed in the -CURRENT branch, and the commit has a bit of details</li>
<li>The ICM and GCM modes of AES were added, and both include support for AESNI</li>
<li>There's a new port - "nist-kat" - that can be used to test the new modes of operation</li>
<li>Some things were fixed in the process as well, including an issue that would leak timing info and result in the ability to forge messages</li>
<li>Code was also borrowed from both OpenBSD and NetBSD to make this possible
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/11/23/first-thoughts-on-the-new-openbsd-httpd-server/" target="_blank" rel="nofollow noopener">First thoughts on OpenBSD's httpd</a></h3>

<ul>
<li>Here we have a blog post from a user of OpenBSD's new homegrown web server that made its debut in 5.6</li>
<li>The author loves that it has proper privilege separation, a very simple config syntax and that it always runs in a chroot</li>
<li>He also mentions dynamic content hosting with FastCGI, and provides an example of how to set it up</li>
<li>Be sure to check <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener">our interview with Reyk</a> about the new httpd if you're curious on how it got started</li>
<li>Also, if you're running the version that came with 5.6, there's <a href="http://ftp.openbsd.org/pub/OpenBSD/patches/5.6/common/009_httpd.patch.sig" target="_blank" rel="nofollow noopener">a huge patch</a> you can apply to get a lot of the features and fixes from -current without waiting for 5.7
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=B04EuZ9hpAI" target="_blank" rel="nofollow noopener">Steam on PCBSD</a></h3>

<ul>
<li>One of the most common questions people who want to use BSD as a desktop ask us is "can I run games?" or "can I use steam?"</li>
<li>Steam through the Linux emulation layer (in FreeBSD) may be possible soon, but it's already possible to use it with WINE</li>
<li>This video shows how to get Steam set up on PCBSD using the Windows version</li>
<li>There are also some instructions in the video description to look over</li>
<li>A <a href="https://www.youtube.com/watch?v=BJ88B8aWdk0" target="_blank" rel="nofollow noopener">second video</a> details getting streaming set up
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2JgqXcw4i" target="_blank" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s2WormjMCs" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20UmdFrbj" target="_blank" rel="nofollow noopener">Predrag writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>48: Liberating SSL</title>
  <link>https://www.bsdnow.tv/48</link>
  <guid isPermaLink="false">e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809</guid>
  <pubDate>Wed, 30 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809.mp3" length="43106548" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>59:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD has gotten quite a lot done this quarter&lt;/li&gt;
&lt;li&gt;Changes in the way release branches are supported - major releases will get at least five years over their lifespan&lt;/li&gt;
&lt;li&gt;A new automounter is in the works, hoping to replace amd (which has some issues)&lt;/li&gt;
&lt;li&gt;The CAM target layer and RPC stack have gotten some major optimization and speed boosts&lt;/li&gt;
&lt;li&gt;Work on ZFSGuru continues, with a large status report specifically for that&lt;/li&gt;
&lt;li&gt;The report also mentioned some new committers, both source and ports&lt;/li&gt;
&lt;li&gt;It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show&lt;/li&gt;
&lt;li&gt;"Foundation-sponsored work resulted in &lt;strong&gt;226 commits&lt;/strong&gt; to FreeBSD over the April to June period"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724094043" target="_blank" rel="nofollow noopener"&gt;A new OpenBSD HTTPD is born&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Work has begun on a new HTTP daemon in the OpenBSD base system&lt;/li&gt;
&lt;li&gt;A lot of people are &lt;a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" target="_blank" rel="nofollow noopener"&gt;asking&lt;/a&gt; "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?&lt;/li&gt;
&lt;li&gt;Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)&lt;/li&gt;
&lt;li&gt;It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter&lt;/li&gt;
&lt;li&gt;This has the added benefit of the usual, easy-to-understand syntax and privilege separation &lt;/li&gt;
&lt;li&gt;There's a very brief &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" target="_blank" rel="nofollow noopener"&gt;man page&lt;/a&gt; online already&lt;/li&gt;
&lt;li&gt;It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs&lt;/li&gt;
&lt;li&gt;Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" target="_blank" rel="nofollow noopener"&gt;pkgng 1.3 announced&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest version of FreeBSD's second generation &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener"&gt;package management system&lt;/a&gt; has been released, with lots of new features&lt;/li&gt;
&lt;li&gt;It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)&lt;/li&gt;
&lt;li&gt;Lots of the code has been sandboxed for extra security&lt;/li&gt;
&lt;li&gt;You'll probably notice some new changes to the UI too, making things more user friendly&lt;/li&gt;
&lt;li&gt;A few days later &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;sortby=date&amp;amp;revision=362996" target="_blank" rel="nofollow noopener"&gt;1.3.1&lt;/a&gt; was released to fix a few small bugs, then &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363108" target="_blank" rel="nofollow noopener"&gt;1.3.2&lt;/a&gt; shortly thereafter and &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363363" target="_blank" rel="nofollow noopener"&gt;1.3.3&lt;/a&gt; yesterday
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" target="_blank" rel="nofollow noopener"&gt;FreeBSD after-install security tasks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A number of people have written in to ask us "how do I secure my BSD box after I install it?"&lt;/li&gt;
&lt;li&gt;With this blog post, hopefully most of their questions will finally be answered in detail&lt;/li&gt;
&lt;li&gt;It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things&lt;/li&gt;
&lt;li&gt;Not only does it just list things to do, but the post also does a good job of explaining why you should do them&lt;/li&gt;
&lt;li&gt;Maybe we'll see some more posts in this series in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Brent Cook - &lt;a href="mailto:bcook@openbsd.org" target="_blank" rel="nofollow noopener"&gt;bcook@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/busterbcook" target="_blank" rel="nofollow noopener"&gt;@busterbcook&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;LibreSSL's portable version and development&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener"&gt;FreeBSD Mastery - Storage Essentials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener"&gt;MWL&lt;/a&gt;'s new book about the FreeBSD storage subsystems now has an early draft available&lt;/li&gt;
&lt;li&gt;Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes&lt;/li&gt;
&lt;li&gt;Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance&lt;/li&gt;
&lt;li&gt;You'll get access to the completed (e)book when it's done if you buy the early draft&lt;/li&gt;
&lt;li&gt;The suggested price is $8
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" target="_blank" rel="nofollow noopener"&gt;Why BSD and not Linux?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another thread comes up asking why you should choose BSD over Linux or vice-versa&lt;/li&gt;
&lt;li&gt;Lots of good responses from users of the various BSDs&lt;/li&gt;
&lt;li&gt;Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."&lt;/li&gt;
&lt;li&gt;And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."&lt;/li&gt;
&lt;li&gt;Some other users share their switching experiences - worth a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" target="_blank" rel="nofollow noopener"&gt;More g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Following up from last week's &lt;a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" target="_blank" rel="nofollow noopener"&gt;huge list&lt;/a&gt; of hackathon reports, we have a few more&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" target="_blank" rel="nofollow noopener"&gt;Landry Breuil&lt;/a&gt; spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140728122850" target="_blank" rel="nofollow noopener"&gt;Andrew Fresh&lt;/a&gt; enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140729070721" target="_blank" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth&lt;/li&gt;
&lt;li&gt;Luckily we didn't have to cover 20 new ones this time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" target="_blank" rel="nofollow noopener"&gt;BSDTalk episode 243&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest episode of &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener"&gt;BSDTalk&lt;/a&gt; is out, featuring an interview with Ingo Schwarze of the OpenBSD team&lt;/li&gt;
&lt;li&gt;The main topic of discussion is mandoc, which some users might not be familiar with&lt;/li&gt;
&lt;li&gt;mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)&lt;/li&gt;
&lt;li&gt;We'll catch up to you soon, Will!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2xLRQytAZ" target="_blank" rel="nofollow noopener"&gt;Thomas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21AYng20n" target="_blank" rel="nofollow noopener"&gt;Stephen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DwLRdQDS" target="_blank" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2E05L31BC" target="_blank" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Nmg3Jrk" target="_blank" rel="nofollow noopener"&gt;Bob Beck writes in&lt;/a&gt; - and note the "Caution" section that was added to &lt;a href="http://www.libressl.org/" target="_blank" rel="nofollow noopener"&gt;libressl.org&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, portable, openssh, security, linux, arc4random, intrinsic functions, rng, prng, status report, pkgng, openhttpd, relayd, httpd, web server, zfsguru, zfs, freebsd mastery, book, storage, ufs, geom, disks, presentation, talk, comparison, mandoc</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" target="_blank" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" target="_blank" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" target="_blank" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" target="_blank" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" target="_blank" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" target="_blank" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" target="_blank" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" target="_blank" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" target="_blank" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" target="_blank" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" target="_blank" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" target="_blank" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" target="_blank" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" target="_blank" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" target="_blank" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" target="_blank" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" target="_blank" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" target="_blank" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" target="_blank" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" target="_blank" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" target="_blank" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" target="_blank" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" target="_blank" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" target="_blank" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" target="_blank" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" target="_blank" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" target="_blank" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" target="_blank" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" target="_blank" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" target="_blank" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" target="_blank" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" target="_blank" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" target="_blank" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" target="_blank" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" target="_blank" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" target="_blank" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" target="_blank" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" target="_blank" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" target="_blank" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" target="_blank" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" target="_blank" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" target="_blank" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" target="_blank" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" target="_blank" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" target="_blank" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" target="_blank" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" target="_blank" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
