<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app02</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 10:14:03 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Linux Foundation”</title>
    <link>https://www.bsdnow.tv/tags/linux%20foundation</link>
    <pubDate>Wed, 25 Feb 2015 08:00:00 -0500</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>78: From the Foundation (Part 2)</title>
  <link>https://www.bsdnow.tv/78</link>
  <guid isPermaLink="false">6999608e-fe27-4efa-96b0-eb1e928acf0a</guid>
  <pubDate>Wed, 25 Feb 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/6999608e-fe27-4efa-96b0-eb1e928acf0a.mp3" length="50146996" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:09:38</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener"&gt;BSDCan 2015 schedule&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well&lt;/li&gt;
&lt;li&gt;Just a reminder: it's going to be held on June 12th and 13th at the University of Ottawa in Canada&lt;/li&gt;
&lt;li&gt;This year's conference will have a massive &lt;strong&gt;fifty&lt;/strong&gt; talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)&lt;/li&gt;
&lt;li&gt;Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  "birds of a feather" gatherings&lt;/li&gt;
&lt;li&gt;In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks&lt;/li&gt;
&lt;li&gt;That's not the &lt;a href="https://twitter.com/bsdcan/status/570394627158773760" rel="nofollow noopener"&gt;ideal balance&lt;/a&gt; we'd hope for, but &lt;a href="https://twitter.com/bsdcan/status/570398181864972288" rel="nofollow noopener"&gt;BSDCan says&lt;/a&gt; they'll try to improve that next year&lt;/li&gt;
&lt;li&gt;Those numbers are based on the speaker's background, or any past presentations, for the few whose actual topic wasn't made obvious from the title (so there may be a small margin of error)&lt;/li&gt;
&lt;li&gt;Michael Lucas (who's on the BSDCan board) wrote up &lt;a href="http://blather.michaelwlucas.com/archives/2325" rel="nofollow noopener"&gt;a blog post&lt;/a&gt; about the proposals and rejections this year&lt;/li&gt;
&lt;li&gt;If you can't make it this year, don't worry, we'll be sure to announce the recordings when they're made available&lt;/li&gt;
&lt;li&gt;We also &lt;a href="http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north" rel="nofollow noopener"&gt;interviewed Dan Langille&lt;/a&gt; about the conference and what to expect this year, so check that out too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception" rel="nofollow noopener"&gt;SSL interception with relayd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was a lot of commotion recently about &lt;a href="http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/" rel="nofollow noopener"&gt;superfish&lt;/a&gt;, a way that Lenovo was intercepting HTTPS traffic and injecting advertisements&lt;/li&gt;
&lt;li&gt;If you're running &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8" rel="nofollow noopener"&gt;relayd&lt;/a&gt;, you can mimic this &lt;em&gt;evil&lt;/em&gt; setup on your own networks (just for testing of course…)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener"&gt;Reyk Floeter&lt;/a&gt;, the guy who wrote relayd, came up a blog post about how to do &lt;a href="https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf" rel="nofollow noopener"&gt;just that&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It starts off with some backstory and some of the things relayd is capable of&lt;/li&gt;
&lt;li&gt;relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL&lt;/li&gt;
&lt;li&gt;When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario&lt;/li&gt;
&lt;li&gt;The post is very long, with lots of &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=135887624714548&amp;amp;w=2" rel="nofollow noopener"&gt;details&lt;/a&gt; and some sample config files - the whole nine yards
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=77.0" rel="nofollow noopener"&gt;OPNsense 15.1.6.1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OPNsense team has released yet another version in rapid succession, but this one has some big changes&lt;/li&gt;
&lt;li&gt;It's now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)&lt;/li&gt;
&lt;li&gt;This version also features a new tool for easily upgrading between versions, simply called "opnsense-update" (similar to freebsd-update)&lt;/li&gt;
&lt;li&gt;It also includes &lt;strong&gt;security&lt;/strong&gt; fixes &lt;a href="https://kb.isc.org/article/AA-01235" rel="nofollow noopener"&gt;for BIND&lt;/a&gt; &lt;a href="http://php.net/ChangeLog-5.php#5.6.6" rel="nofollow noopener"&gt;and PHP&lt;/a&gt;, as well as some other assorted bug fixes&lt;/li&gt;
&lt;li&gt;The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)&lt;/li&gt;
&lt;li&gt;With the news of m0n0wall shutting down last week, they've also released bare minimum hardware specifications required to run OPNsense on embedded devices&lt;/li&gt;
&lt;li&gt;Encouraged by last week's mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental &lt;a href="https://forum.opnsense.org/index.php?topic=78.0" rel="nofollow noopener"&gt;images built against LibreSSL&lt;/a&gt; for testing (and have instructions on how to switch over without reinstalling)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html" rel="nofollow noopener"&gt;OpenBSD on a Minnowboard Max&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;What would our show be without at least one story about someone installing BSD on a weird device&lt;/li&gt;
&lt;li&gt;For once, it's actually not NetBSD…&lt;/li&gt;
&lt;li&gt;This article is about the &lt;a href="http://www.minnowboard.org/meet-minnowboard-max/" rel="nofollow noopener"&gt;minnowboard max&lt;/a&gt;, a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi&lt;/li&gt;
&lt;li&gt;It's using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)&lt;/li&gt;
&lt;li&gt;The author describes his entirely solid-state setup, noting that there's virtually no noise, no concern about hard drives dying and very reasonable power usage&lt;/li&gt;
&lt;li&gt;You'll find instructions on how to get OpenBSD installed and going throughout the rest of the article&lt;/li&gt;
&lt;li&gt;Have a look at the spec sheet if you're interested, they make for cool little BSD boxes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html" rel="nofollow noopener"&gt;Netmap for 40gbit NICs in FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he's just committed&lt;/li&gt;
&lt;li&gt;The ixl(4) driver, that's one for the X1710 40-gigabit card, now has netmap support&lt;/li&gt;
&lt;li&gt;It's currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too&lt;/li&gt;
&lt;li&gt;This should make for some serious packet-pushing power&lt;/li&gt;
&lt;li&gt;If you have any network hardware like this, he would appreciate testing for the new code
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ken Westerback - &lt;a href="mailto:directors@openbsdfoundation.org" rel="nofollow noopener"&gt;directors@openbsdfoundation.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener"&gt;The OpenBSD foundation&lt;/a&gt;'s activities&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150221222235" rel="nofollow noopener"&gt;s2k15 hackathon report: dhclient/dhcpd/fdisk&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to&lt;/li&gt;
&lt;li&gt;Ken was also busy, getting a few networking-related things fixed and improved in the base system&lt;/li&gt;
&lt;li&gt;He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd&lt;/li&gt;
&lt;li&gt;The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it&lt;/li&gt;
&lt;li&gt;There's apparently plans for "dhclientng" - presumably a big improvement (rewrite?) of dhclient
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/user/bsdtutorial/videos" rel="nofollow noopener"&gt;FreeBSD beginner video series&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD&lt;/li&gt;
&lt;li&gt;We usually assume that people who watch the show are already familiar with basic concepts, but they'd be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand&lt;/li&gt;
&lt;li&gt;So far, he's covered &lt;a href="https://www.youtube.com/watch?v=D26rOHkI-iE" rel="nofollow noopener"&gt;how to get FreeBSD&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=PCyYW19bPDU" rel="nofollow noopener"&gt;an introduction to installing in VirtualBox&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=HCE89kObutA" rel="nofollow noopener"&gt;a simple installation&lt;/a&gt; or a more in-depth &lt;a href="https://www.youtube.com/watch?v=OwqCjz9Fgao" rel="nofollow noopener"&gt;manual installation&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=6YJhdOGjN50" rel="nofollow noopener"&gt;navigating the filesystem&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=Yl5Bg2qz21I" rel="nofollow noopener"&gt;basic ssh use&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=ioB73i7QUjI" rel="nofollow noopener"&gt;managing users and groups&lt;/a&gt; and finally some &lt;a href="https://www.youtube.com/watch?v=VxxbO-gt9FA" rel="nofollow noopener"&gt;basic editing&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=16FNtCj-uS4" rel="nofollow noopener"&gt;with vi&lt;/a&gt; and a few other topics&lt;/li&gt;
&lt;li&gt;Everyone's gotta start somewhere and, with a little bit of initial direction, today's newbies could be tomorrow's developers&lt;/li&gt;
&lt;li&gt;It should be an ongoing series with more topics to come
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to" rel="nofollow noopener"&gt;NetBSD tests: zero unexpected failures&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The NetBSD guys have a new blog post up about their &lt;a href="http://wiki.netbsd.org/tutorials/atf/" rel="nofollow noopener"&gt;testing suite&lt;/a&gt; for all the CPU architectures&lt;/li&gt;
&lt;li&gt;They've finally gotten the number of "expected" failures down to zero on a few select architectures&lt;/li&gt;
&lt;li&gt;Results are &lt;a href="http://releng.netbsd.org/test-results.html" rel="nofollow noopener"&gt;published&lt;/a&gt; on a special release engineering page, so you can have a look if you're interested&lt;/li&gt;
&lt;li&gt;The rest of the post links to the "top performers" (ones with less than ten failure) in the -current branch
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace" rel="nofollow noopener"&gt;PCBSD switches to IPFW&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The PCBSD crew continues their recent series of switching between major competing features&lt;/li&gt;
&lt;li&gt;This time, they've switched the default firewall away from PF to FreeBSD's native IPFW firewall&lt;/li&gt;
&lt;li&gt;Look forward to Kris wearing a "keep calm and use IPFW" shir- wait
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21U6Ln6wC" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Kp0xdfIb" rel="nofollow noopener"&gt;Dan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216DcA8DP" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s271iJjqtQ" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21zerHI9P" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=142454205416445&amp;amp;w=2" rel="nofollow noopener"&gt;VCS flamebait&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html" rel="nofollow noopener"&gt;Hidden agenda&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openbsd foundation, donations, openssh, funding, hackathon, gsoc, core infrastructure initiative, linux foundation, charity, lenovo, superfish, relayd, opnsense, soekris</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener">BSDCan 2015 schedule</a></h3>

<ul>
<li>The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well</li>
<li>Just a reminder: it's going to be held on June 12th and 13th at the University of Ottawa in Canada</li>
<li>This year's conference will have a massive <strong>fifty</strong> talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)</li>
<li>Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  "birds of a feather" gatherings</li>
<li>In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks</li>
<li>That's not the <a href="https://twitter.com/bsdcan/status/570394627158773760" rel="nofollow noopener">ideal balance</a> we'd hope for, but <a href="https://twitter.com/bsdcan/status/570398181864972288" rel="nofollow noopener">BSDCan says</a> they'll try to improve that next year</li>
<li>Those numbers are based on the speaker's background, or any past presentations, for the few whose actual topic wasn't made obvious from the title (so there may be a small margin of error)</li>
<li>Michael Lucas (who's on the BSDCan board) wrote up <a href="http://blather.michaelwlucas.com/archives/2325" rel="nofollow noopener">a blog post</a> about the proposals and rejections this year</li>
<li>If you can't make it this year, don't worry, we'll be sure to announce the recordings when they're made available</li>
<li>We also <a href="http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north" rel="nofollow noopener">interviewed Dan Langille</a> about the conference and what to expect this year, so check that out too
***</li>
</ul>

<h3><a href="http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception" rel="nofollow noopener">SSL interception with relayd</a></h3>

<ul>
<li>There was a lot of commotion recently about <a href="http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/" rel="nofollow noopener">superfish</a>, a way that Lenovo was intercepting HTTPS traffic and injecting advertisements</li>
<li>If you're running <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8" rel="nofollow noopener">relayd</a>, you can mimic this <em>evil</em> setup on your own networks (just for testing of course…)</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, the guy who wrote relayd, came up a blog post about how to do <a href="https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf" rel="nofollow noopener">just that</a></li>
<li>It starts off with some backstory and some of the things relayd is capable of</li>
<li>relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL</li>
<li>When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario</li>
<li>The post is very long, with lots of <a href="https://www.marc.info/?l=openbsd-tech&amp;m=135887624714548&amp;w=2" rel="nofollow noopener">details</a> and some sample config files - the whole nine yards
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=77.0" rel="nofollow noopener">OPNsense 15.1.6.1 released</a></h3>

<ul>
<li>The OPNsense team has released yet another version in rapid succession, but this one has some big changes</li>
<li>It's now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)</li>
<li>This version also features a new tool for easily upgrading between versions, simply called "opnsense-update" (similar to freebsd-update)</li>
<li>It also includes <strong>security</strong> fixes <a href="https://kb.isc.org/article/AA-01235" rel="nofollow noopener">for BIND</a> <a href="http://php.net/ChangeLog-5.php#5.6.6" rel="nofollow noopener">and PHP</a>, as well as some other assorted bug fixes</li>
<li>The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)</li>
<li>With the news of m0n0wall shutting down last week, they've also released bare minimum hardware specifications required to run OPNsense on embedded devices</li>
<li>Encouraged by last week's mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental <a href="https://forum.opnsense.org/index.php?topic=78.0" rel="nofollow noopener">images built against LibreSSL</a> for testing (and have instructions on how to switch over without reinstalling)
***</li>
</ul>

<h3><a href="http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html" rel="nofollow noopener">OpenBSD on a Minnowboard Max</a></h3>

<ul>
<li>What would our show be without at least one story about someone installing BSD on a weird device</li>
<li>For once, it's actually not NetBSD…</li>
<li>This article is about the <a href="http://www.minnowboard.org/meet-minnowboard-max/" rel="nofollow noopener">minnowboard max</a>, a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi</li>
<li>It's using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)</li>
<li>The author describes his entirely solid-state setup, noting that there's virtually no noise, no concern about hard drives dying and very reasonable power usage</li>
<li>You'll find instructions on how to get OpenBSD installed and going throughout the rest of the article</li>
<li>Have a look at the spec sheet if you're interested, they make for cool little BSD boxes
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html" rel="nofollow noopener">Netmap for 40gbit NICs in FreeBSD</a></h3>

<ul>
<li>Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he's just committed</li>
<li>The ixl(4) driver, that's one for the X1710 40-gigabit card, now has netmap support</li>
<li>It's currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too</li>
<li>This should make for some serious packet-pushing power</li>
<li>If you have any network hardware like this, he would appreciate testing for the new code
***</li>
</ul>

<h2>Interview - Ken Westerback - <a href="mailto:directors@openbsdfoundation.org" rel="nofollow noopener">directors@openbsdfoundation.org</a></h2>

<p><a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">The OpenBSD foundation</a>'s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150221222235" rel="nofollow noopener">s2k15 hackathon report: dhclient/dhcpd/fdisk</a></h3>

<ul>
<li>The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to</li>
<li>Ken was also busy, getting a few networking-related things fixed and improved in the base system</li>
<li>He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd</li>
<li>The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it</li>
<li>There's apparently plans for "dhclientng" - presumably a big improvement (rewrite?) of dhclient
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/bsdtutorial/videos" rel="nofollow noopener">FreeBSD beginner video series</a></h3>

<ul>
<li>A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD</li>
<li>We usually assume that people who watch the show are already familiar with basic concepts, but they'd be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand</li>
<li>So far, he's covered <a href="https://www.youtube.com/watch?v=D26rOHkI-iE" rel="nofollow noopener">how to get FreeBSD</a>, <a href="https://www.youtube.com/watch?v=PCyYW19bPDU" rel="nofollow noopener">an introduction to installing in VirtualBox</a>, <a href="https://www.youtube.com/watch?v=HCE89kObutA" rel="nofollow noopener">a simple installation</a> or a more in-depth <a href="https://www.youtube.com/watch?v=OwqCjz9Fgao" rel="nofollow noopener">manual installation</a>, <a href="https://www.youtube.com/watch?v=6YJhdOGjN50" rel="nofollow noopener">navigating the filesystem</a>, <a href="https://www.youtube.com/watch?v=Yl5Bg2qz21I" rel="nofollow noopener">basic ssh use</a>, <a href="https://www.youtube.com/watch?v=ioB73i7QUjI" rel="nofollow noopener">managing users and groups</a> and finally some <a href="https://www.youtube.com/watch?v=VxxbO-gt9FA" rel="nofollow noopener">basic editing</a> <a href="https://www.youtube.com/watch?v=16FNtCj-uS4" rel="nofollow noopener">with vi</a> and a few other topics</li>
<li>Everyone's gotta start somewhere and, with a little bit of initial direction, today's newbies could be tomorrow's developers</li>
<li>It should be an ongoing series with more topics to come
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to" rel="nofollow noopener">NetBSD tests: zero unexpected failures</a></h3>

<ul>
<li>The NetBSD guys have a new blog post up about their <a href="http://wiki.netbsd.org/tutorials/atf/" rel="nofollow noopener">testing suite</a> for all the CPU architectures</li>
<li>They've finally gotten the number of "expected" failures down to zero on a few select architectures</li>
<li>Results are <a href="http://releng.netbsd.org/test-results.html" rel="nofollow noopener">published</a> on a special release engineering page, so you can have a look if you're interested</li>
<li>The rest of the post links to the "top performers" (ones with less than ten failure) in the -current branch
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace" rel="nofollow noopener">PCBSD switches to IPFW</a></h3>

<ul>
<li>The PCBSD crew continues their recent series of switching between major competing features</li>
<li>This time, they've switched the default firewall away from PF to FreeBSD's native IPFW firewall</li>
<li>Look forward to Kris wearing a "keep calm and use IPFW" shir- wait
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21U6Ln6wC" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Kp0xdfIb" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s216DcA8DP" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s271iJjqtQ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21zerHI9P" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142454205416445&amp;w=2" rel="nofollow noopener">VCS flamebait</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html" rel="nofollow noopener">Hidden agenda</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week we continue our two-part series on the activities of various BSD foundations. Ken Westerback joins us today to talk all about the OpenBSD foundation and what it is they do. We've also got answers to your emails and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener">BSDCan 2015 schedule</a></h3>

<ul>
<li>The list of presentations for the upcoming BSDCan conference has been posted, and the time schedule should be up shortly as well</li>
<li>Just a reminder: it's going to be held on June 12th and 13th at the University of Ottawa in Canada</li>
<li>This year's conference will have a massive <strong>fifty</strong> talks, split up between four tracks instead of three (but unfortunately a person can only be in one place at a time)</li>
<li>Both Allan and Kris had at least one presentation accepted, and Allan will also be leading a few  "birds of a feather" gatherings</li>
<li>In total, there will be three NetBSD talks, five OpenBSD talks, eight BSD-neutral talks, thirty-five FreeBSD talks and no DragonFly talks</li>
<li>That's not the <a href="https://twitter.com/bsdcan/status/570394627158773760" rel="nofollow noopener">ideal balance</a> we'd hope for, but <a href="https://twitter.com/bsdcan/status/570398181864972288" rel="nofollow noopener">BSDCan says</a> they'll try to improve that next year</li>
<li>Those numbers are based on the speaker's background, or any past presentations, for the few whose actual topic wasn't made obvious from the title (so there may be a small margin of error)</li>
<li>Michael Lucas (who's on the BSDCan board) wrote up <a href="http://blather.michaelwlucas.com/archives/2325" rel="nofollow noopener">a blog post</a> about the proposals and rejections this year</li>
<li>If you can't make it this year, don't worry, we'll be sure to announce the recordings when they're made available</li>
<li>We also <a href="http://www.bsdnow.tv/episodes/2014_12_31-daemons_in_the_north" rel="nofollow noopener">interviewed Dan Langille</a> about the conference and what to expect this year, so check that out too
***</li>
</ul>

<h3><a href="http://www.reykfloeter.com/post/41814177050/relayd-ssl-interception" rel="nofollow noopener">SSL interception with relayd</a></h3>

<ul>
<li>There was a lot of commotion recently about <a href="http://www.forbes.com/sites/thomasbrewster/2015/02/19/superfish-need-to-know/" rel="nofollow noopener">superfish</a>, a way that Lenovo was intercepting HTTPS traffic and injecting advertisements</li>
<li>If you're running <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/relayd.8" rel="nofollow noopener">relayd</a>, you can mimic this <em>evil</em> setup on your own networks (just for testing of course…)</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, the guy who wrote relayd, came up a blog post about how to do <a href="https://gist.github.com/reyk/4b42858d1eab3825f9bc#file-relayd-superfish-conf" rel="nofollow noopener">just that</a></li>
<li>It starts off with some backstory and some of the things relayd is capable of</li>
<li>relayd can run as an SSL server to terminate SSL connections and forward them as plain TCP and, conversely, run as an SSL client to terminal plain TCP connections and tunnel them through SSL</li>
<li>When you combine these two, you end up with possibilities to filter between SSL connections, effectively creating a MITM scenario</li>
<li>The post is very long, with lots of <a href="https://www.marc.info/?l=openbsd-tech&amp;m=135887624714548&amp;w=2" rel="nofollow noopener">details</a> and some sample config files - the whole nine yards
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=77.0" rel="nofollow noopener">OPNsense 15.1.6.1 released</a></h3>

<ul>
<li>The OPNsense team has released yet another version in rapid succession, but this one has some big changes</li>
<li>It's now based on FreeBSD 10.1, with all the latest security patches and driver updates (as well as some in-house patches)</li>
<li>This version also features a new tool for easily upgrading between versions, simply called "opnsense-update" (similar to freebsd-update)</li>
<li>It also includes <strong>security</strong> fixes <a href="https://kb.isc.org/article/AA-01235" rel="nofollow noopener">for BIND</a> <a href="http://php.net/ChangeLog-5.php#5.6.6" rel="nofollow noopener">and PHP</a>, as well as some other assorted bug fixes</li>
<li>The installation images have been laid out in a clean way: standard CD and USB images that default to VGA, as well as USB images that default to a console output (for things like Soekris and PCEngines APU boards that only have serial ports)</li>
<li>With the news of m0n0wall shutting down last week, they've also released bare minimum hardware specifications required to run OPNsense on embedded devices</li>
<li>Encouraged by last week's mention of PCBSD trying to cut ties with OpenSSL, OPNsense is also now providing experimental <a href="https://forum.opnsense.org/index.php?topic=78.0" rel="nofollow noopener">images built against LibreSSL</a> for testing (and have instructions on how to switch over without reinstalling)
***</li>
</ul>

<h3><a href="http://www.countersiege.com/2015/02/22/minnowboard_max_openbsd.html" rel="nofollow noopener">OpenBSD on a Minnowboard Max</a></h3>

<ul>
<li>What would our show be without at least one story about someone installing BSD on a weird device</li>
<li>For once, it's actually not NetBSD…</li>
<li>This article is about the <a href="http://www.minnowboard.org/meet-minnowboard-max/" rel="nofollow noopener">minnowboard max</a>, a very small X86-based motherboard that looks vaguely similar to a Raspberry Pi</li>
<li>It's using an Atom CPU instead of ARM, so overall application compatibility should be a bit better (and it even has AES-NI, so crypto performance will be much better than a normal Atom)</li>
<li>The author describes his entirely solid-state setup, noting that there's virtually no noise, no concern about hard drives dying and very reasonable power usage</li>
<li>You'll find instructions on how to get OpenBSD installed and going throughout the rest of the article</li>
<li>Have a look at the spec sheet if you're interested, they make for cool little BSD boxes
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054717.html" rel="nofollow noopener">Netmap for 40gbit NICs in FreeBSD</a></h3>

<ul>
<li>Luigi Rizzo posted an announcement to the -current mailing list, detailing some of the work he's just committed</li>
<li>The ixl(4) driver, that's one for the X1710 40-gigabit card, now has netmap support</li>
<li>It's currently in 11-CURRENT, but he says it works in 10-STABLE and will be committed there too</li>
<li>This should make for some serious packet-pushing power</li>
<li>If you have any network hardware like this, he would appreciate testing for the new code
***</li>
</ul>

<h2>Interview - Ken Westerback - <a href="mailto:directors@openbsdfoundation.org" rel="nofollow noopener">directors@openbsdfoundation.org</a></h2>

<p><a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">The OpenBSD foundation</a>'s activities</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150221222235" rel="nofollow noopener">s2k15 hackathon report: dhclient/dhcpd/fdisk</a></h3>

<ul>
<li>The second trip report from the recent OpenBSD hackathon has been published, from the very same guy we just talked to</li>
<li>Ken was also busy, getting a few networking-related things fixed and improved in the base system</li>
<li>He wrote a few new small additions for dhclient and beefed up the privsep security, as well as some fixes for tcpdump and dhcpd</li>
<li>The fdisk tool also got worked on a bit, enabling OpenBSD to properly wipe GPT tables on a previously-formatted disk so you can do a normal install on it</li>
<li>There's apparently plans for "dhclientng" - presumably a big improvement (rewrite?) of dhclient
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/bsdtutorial/videos" rel="nofollow noopener">FreeBSD beginner video series</a></h3>

<ul>
<li>A new series of videos has started on YouTube, aimed at helping total beginners learn about FreeBSD</li>
<li>We usually assume that people who watch the show are already familiar with basic concepts, but they'd be a great introduction to any of your friends that are looking to get started with BSD and need a helping hand</li>
<li>So far, he's covered <a href="https://www.youtube.com/watch?v=D26rOHkI-iE" rel="nofollow noopener">how to get FreeBSD</a>, <a href="https://www.youtube.com/watch?v=PCyYW19bPDU" rel="nofollow noopener">an introduction to installing in VirtualBox</a>, <a href="https://www.youtube.com/watch?v=HCE89kObutA" rel="nofollow noopener">a simple installation</a> or a more in-depth <a href="https://www.youtube.com/watch?v=OwqCjz9Fgao" rel="nofollow noopener">manual installation</a>, <a href="https://www.youtube.com/watch?v=6YJhdOGjN50" rel="nofollow noopener">navigating the filesystem</a>, <a href="https://www.youtube.com/watch?v=Yl5Bg2qz21I" rel="nofollow noopener">basic ssh use</a>, <a href="https://www.youtube.com/watch?v=ioB73i7QUjI" rel="nofollow noopener">managing users and groups</a> and finally some <a href="https://www.youtube.com/watch?v=VxxbO-gt9FA" rel="nofollow noopener">basic editing</a> <a href="https://www.youtube.com/watch?v=16FNtCj-uS4" rel="nofollow noopener">with vi</a> and a few other topics</li>
<li>Everyone's gotta start somewhere and, with a little bit of initial direction, today's newbies could be tomorrow's developers</li>
<li>It should be an ongoing series with more topics to come
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/regular_test_runs_down_to" rel="nofollow noopener">NetBSD tests: zero unexpected failures</a></h3>

<ul>
<li>The NetBSD guys have a new blog post up about their <a href="http://wiki.netbsd.org/tutorials/atf/" rel="nofollow noopener">testing suite</a> for all the CPU architectures</li>
<li>They've finally gotten the number of "expected" failures down to zero on a few select architectures</li>
<li>Results are <a href="http://releng.netbsd.org/test-results.html" rel="nofollow noopener">published</a> on a special release engineering page, so you can have a look if you're interested</li>
<li>The rest of the post links to the "top performers" (ones with less than ten failure) in the -current branch
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/b80f78d8a5d002396c28ac0e5fd6f69699beaace" rel="nofollow noopener">PCBSD switches to IPFW</a></h3>

<ul>
<li>The PCBSD crew continues their recent series of switching between major competing features</li>
<li>This time, they've switched the default firewall away from PF to FreeBSD's native IPFW firewall</li>
<li>Look forward to Kris wearing a "keep calm and use IPFW" shir- wait
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21U6Ln6wC" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Kp0xdfIb" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s216DcA8DP" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s271iJjqtQ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21zerHI9P" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142454205416445&amp;w=2" rel="nofollow noopener">VCS flamebait</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-gnome/2015-February/031561.html" rel="nofollow noopener">Hidden agenda</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>15: Kickin' NAS</title>
  <link>https://www.bsdnow.tv/15</link>
  <guid isPermaLink="false">cbf73b1a-fa1e-4acd-a1c4-ad96edb36916</guid>
  <pubDate>Wed, 11 Dec 2013 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/cbf73b1a-fa1e-4acd-a1c4-ad96edb36916.mp3" length="77923925" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be looking at the new version of FreeNAS, a BSD-based network attached storage solution, as well as talking to Josh Paetzel - one of the key developers of FreeNAS. Actually, he's on the FreeBSD release engineering team too, and does quite a lot for the project. We've got answers to your viewer-submitted questions and plenty of news to cover, so get ready for some BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:48:13</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be looking at the new version of FreeNAS, a BSD-based network attached storage solution, as well as talking to Josh Paetzel - one of the key developers of FreeNAS. Actually, he's on the FreeBSD release engineering team too, and does quite a lot for the project. We've got answers to your viewer-submitted questions and plenty of news to cover, so get ready for some BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-reid-linnemann.html" rel="nofollow noopener"&gt;More faces of FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another installment of the FoF series&lt;/li&gt;
&lt;li&gt;This time they talk with Reid Linnemann who works at Spectra Logic&lt;/li&gt;
&lt;li&gt;Gives a history of all the different jobs he's done, all the programming languages he knows&lt;/li&gt;
&lt;li&gt;Mentions how he first learned about FreeBSD, actually pretty similar to Kris' story&lt;/li&gt;
&lt;li&gt;"I used the system to build and install ports, and explored, getting actively involved in the mailing lists and forums, studying, passing on my own limited knowledge to those who could benefit from it. I pursued my career in the open source software world, learning the differences in BSD and GNU licensing and the fragmented nature of Linux distributions, realizing the FreeBSD community was more mature and well distributed about industry, education, and research. Everything steered me towards working with and on FreeBSD."&lt;/li&gt;
&lt;li&gt;Now works on FreeBSD as his day job&lt;/li&gt;
&lt;li&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-brooks-davis.html" rel="nofollow noopener"&gt;The second one&lt;/a&gt; covers Brooks Davis&lt;/li&gt;
&lt;li&gt;FreeBSD committer since 2001 and core team member from 2006 through 2012&lt;/li&gt;
&lt;li&gt;He's helped drive our transition from a GNU toolchain to a more modern LLVM-based toolchain&lt;/li&gt;
&lt;li&gt;"One of the reasons I like FreeBSD is the community involved in the process of building a principled, technically-advanced operating system platform. Not only do we produce a great product, but we have fun doing it."&lt;/li&gt;
&lt;li&gt;Lots more in the show notes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2013-09-devsummit.html#Security" rel="nofollow noopener"&gt;We cannot trust Intel and Via’s chip-based crypto&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We woke up to see FreeBSD on the front page of &lt;a href="http://www.theregister.co.uk/2013/12/09/freebsd_abandoning_hardware_randomness/" rel="nofollow noopener"&gt;The Register&lt;/a&gt;, &lt;a href="http://arstechnica.com/security/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/" rel="nofollow noopener"&gt;Ars Technica&lt;/a&gt;, &lt;a href="http://it.slashdot.org/story/13/12/11/1919201/freebsd-developers-will-not-trust-chip-based-encryption" rel="nofollow noopener"&gt;Slashdot&lt;/a&gt; and &lt;a href="https://news.ycombinator.com/item?id=6880474" rel="nofollow noopener"&gt;Hacker News&lt;/a&gt; for their strong stance on security and respecting privacy&lt;/li&gt;
&lt;li&gt;At the EuroBSDCon dev summit, there was some discussion about removing support for hardware-based random number generators.&lt;/li&gt;
&lt;li&gt;FreeBSD's /dev/random got some updates and, for 10.0, will no longer allow the use of Intel or VIA's hardware RNGs as the sole point of entropy&lt;/li&gt;
&lt;li&gt;"It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://article.gmane.org/gmane.mail.opensmtpd.general/1146" rel="nofollow noopener"&gt;OpenSMTPD 5.4.1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenBSD developers came out with major a new version&lt;/li&gt;
&lt;li&gt;Improved config syntax (please check your smtpd.conf before upgrading)&lt;/li&gt;
&lt;li&gt;Adds support for TLS Perfect Forward Secrecy and custom CA certificate&lt;/li&gt;
&lt;li&gt;MTA, Queue and SMTP server improvements&lt;/li&gt;
&lt;li&gt;SNI support confirmed for the next version&lt;/li&gt;
&lt;li&gt;Check the show notes for the full list of changes, pretty huge release&lt;/li&gt;
&lt;li&gt;Watch &lt;a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" rel="nofollow noopener"&gt;Episode 3&lt;/a&gt; for an interview we did with the developers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2013/12/02/getting-to-know-your-portmgr-thomas-abthorpe/" rel="nofollow noopener"&gt;More getting to know your portmgr&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The portmgr secretary, Thomas Abthorpe, interviews... himself!&lt;/li&gt;
&lt;li&gt;Joined as -secretary in March 2010, upgraded to full member in March 2011&lt;/li&gt;
&lt;li&gt;His inspiration for using BSD is "I wanted to run a webserver, and I wanted something free. I was going to use something linux, then met up with a former prof from university, and shared my story with him. He told me FreeBSD was the way to go."&lt;/li&gt;
&lt;li&gt;Mentions how he loves that anyone can contribute and watch it "go live"&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2013/12/09/getting-to-know-your-portmgr-baptiste-daroussin/" rel="nofollow noopener"&gt;The second one&lt;/a&gt; covers Baptiste Daroussin&lt;/li&gt;
&lt;li&gt;The reason for his nick, bapt, is "Baptiste is too long to type"&lt;/li&gt;
&lt;li&gt;There's even &lt;a href="https://www.youtube.com/watch?v=tZk__K8rqOg" rel="nofollow noopener"&gt;a video&lt;/a&gt; of bapt joining the team!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Santa Clause - &lt;a href="mailto:josh@ixsystems.com" rel="nofollow noopener"&gt;josh@ixsystems.com&lt;/a&gt; / &lt;a href="https://twitter.com/freenasteam" rel="nofollow noopener"&gt;@freenasteam&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeNAS &lt;a href="http://www.freenas.org/whats-new/2013/12/freenas-9-2-0-rc-available.html" rel="nofollow noopener"&gt;9.2.0&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Note: we originally scheduled the interview to be with Josh Paetzel, but Santa showed up instead.&lt;/strong&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;FreeNAS walkthrough&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.daemonology.net/blog/2013-12-09-FreeBSD-EC2-configinit.html" rel="nofollow noopener"&gt;Introducing configinit&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;CloudInit is "a system originally written for Ubuntu which performs configuration of a system at boot-time based on user-data provided via EC2"&lt;/li&gt;
&lt;li&gt;Wasn't ideal for FreeBSD since it requires python and is designed around the concept of configuring a system by running commands (rather than editing configuration files)&lt;/li&gt;
&lt;li&gt;Colin Percival came up with configinit, a FreeBSD alternative&lt;/li&gt;
&lt;li&gt;Alongside his new "firstboot-pkgs" port, it can spin up a webserver in 120 seconds from "launch" of the EC2 instance&lt;/li&gt;
&lt;li&gt;Check the show notes for full blog post
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.key?rev=1.1;content-type=text%2Fx-cvsweb-markup" rel="nofollow noopener"&gt;OpenSSH support for Ed25519 and bcrypt keys&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New Ed25519 key support (hostkeys and user identities) using the public domain ed25519 reference code&lt;/li&gt;
&lt;li&gt;SSH private keys were encrypted with a symmetric key that's just an MD5 of their password&lt;/li&gt;
&lt;li&gt;Now they'll be using bcrypt &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=138633721618361&amp;amp;w=2" rel="nofollow noopener"&gt;by default&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;We'll get more into this in next week's interview
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener"&gt;The FreeBSD challenge&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A member of the Linux foundation blogs about using FreeBSD&lt;/li&gt;
&lt;li&gt;Goes through all the beginner steps, has to "unlearn" some of his Linux ways&lt;/li&gt;
&lt;li&gt;Only a few posts as of this time, but it's a continuing series that may be helpful for switchers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-111513-2/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;GNOME3, cinnamon and mate desktops are in the installer&lt;/li&gt;
&lt;li&gt;Compat layer updated to CentOS 6, enables newest Skype&lt;/li&gt;
&lt;li&gt;Looking for people to test printers and hplip&lt;/li&gt;
&lt;li&gt;Continuing work on grub, but the ability to switch between bootloaders is back
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20k2gumbP" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2PM8tfKfe" rel="nofollow noopener"&gt;Jason writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2KgXIKqrJ" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20DLk8bac" rel="nofollow noopener"&gt;Kjell-Aleksander writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nmmJHvgR" rel="nofollow noopener"&gt;Alexy writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ports, freenas, ixsystems, nas, network attached storage, josh paetzel, jpaetzel, cto, zfs, zpool, encryption, 9.2.0, walkthrough, web, interface, ui, frontend, opensmtpd, bcrypt, openssh, portmgr, linux foundation, switching from linux to bsd, linux</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be looking at the new version of FreeNAS, a BSD-based network attached storage solution, as well as talking to Josh Paetzel - one of the key developers of FreeNAS. Actually, he's on the FreeBSD release engineering team too, and does quite a lot for the project. We've got answers to your viewer-submitted questions and plenty of news to cover, so get ready for some BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-reid-linnemann.html" rel="nofollow noopener">More faces of FreeBSD</a></h3>

<ul>
<li>Another installment of the FoF series</li>
<li>This time they talk with Reid Linnemann who works at Spectra Logic</li>
<li>Gives a history of all the different jobs he's done, all the programming languages he knows</li>
<li>Mentions how he first learned about FreeBSD, actually pretty similar to Kris' story</li>
<li>"I used the system to build and install ports, and explored, getting actively involved in the mailing lists and forums, studying, passing on my own limited knowledge to those who could benefit from it. I pursued my career in the open source software world, learning the differences in BSD and GNU licensing and the fragmented nature of Linux distributions, realizing the FreeBSD community was more mature and well distributed about industry, education, and research. Everything steered me towards working with and on FreeBSD."</li>
<li>Now works on FreeBSD as his day job</li>
<li><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-brooks-davis.html" rel="nofollow noopener">The second one</a> covers Brooks Davis</li>
<li>FreeBSD committer since 2001 and core team member from 2006 through 2012</li>
<li>He's helped drive our transition from a GNU toolchain to a more modern LLVM-based toolchain</li>
<li>"One of the reasons I like FreeBSD is the community involved in the process of building a principled, technically-advanced operating system platform. Not only do we produce a great product, but we have fun doing it."</li>
<li>Lots more in the show notes
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2013-09-devsummit.html#Security" rel="nofollow noopener">We cannot trust Intel and Via’s chip-based crypto</a></h3>

<ul>
<li>We woke up to see FreeBSD on the front page of <a href="http://www.theregister.co.uk/2013/12/09/freebsd_abandoning_hardware_randomness/" rel="nofollow noopener">The Register</a>, <a href="http://arstechnica.com/security/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/" rel="nofollow noopener">Ars Technica</a>, <a href="http://it.slashdot.org/story/13/12/11/1919201/freebsd-developers-will-not-trust-chip-based-encryption" rel="nofollow noopener">Slashdot</a> and <a href="https://news.ycombinator.com/item?id=6880474" rel="nofollow noopener">Hacker News</a> for their strong stance on security and respecting privacy</li>
<li>At the EuroBSDCon dev summit, there was some discussion about removing support for hardware-based random number generators.</li>
<li>FreeBSD's /dev/random got some updates and, for 10.0, will no longer allow the use of Intel or VIA's hardware RNGs as the sole point of entropy</li>
<li>"It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more"
***</li>
</ul>

<h3><a href="http://article.gmane.org/gmane.mail.opensmtpd.general/1146" rel="nofollow noopener">OpenSMTPD 5.4.1 released</a></h3>

<ul>
<li>The OpenBSD developers came out with major a new version</li>
<li>Improved config syntax (please check your smtpd.conf before upgrading)</li>
<li>Adds support for TLS Perfect Forward Secrecy and custom CA certificate</li>
<li>MTA, Queue and SMTP server improvements</li>
<li>SNI support confirmed for the next version</li>
<li>Check the show notes for the full list of changes, pretty huge release</li>
<li>Watch <a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" rel="nofollow noopener">Episode 3</a> for an interview we did with the developers
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/12/02/getting-to-know-your-portmgr-thomas-abthorpe/" rel="nofollow noopener">More getting to know your portmgr</a></h3>

<ul>
<li>The portmgr secretary, Thomas Abthorpe, interviews... himself!</li>
<li>Joined as -secretary in March 2010, upgraded to full member in March 2011</li>
<li>His inspiration for using BSD is "I wanted to run a webserver, and I wanted something free. I was going to use something linux, then met up with a former prof from university, and shared my story with him. He told me FreeBSD was the way to go."</li>
<li>Mentions how he loves that anyone can contribute and watch it "go live"</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2013/12/09/getting-to-know-your-portmgr-baptiste-daroussin/" rel="nofollow noopener">The second one</a> covers Baptiste Daroussin</li>
<li>The reason for his nick, bapt, is "Baptiste is too long to type"</li>
<li>There's even <a href="https://www.youtube.com/watch?v=tZk__K8rqOg" rel="nofollow noopener">a video</a> of bapt joining the team!
***</li>
</ul>

<h2>Interview - Santa Clause - <a href="mailto:josh@ixsystems.com" rel="nofollow noopener">josh@ixsystems.com</a> / <a href="https://twitter.com/freenasteam" rel="nofollow noopener">@freenasteam</a></h2>

<p>FreeNAS <a href="http://www.freenas.org/whats-new/2013/12/freenas-9-2-0-rc-available.html" rel="nofollow noopener">9.2.0</a></p>

<p><strong>Note: we originally scheduled the interview to be with Josh Paetzel, but Santa showed up instead.</strong></p>

<hr>

<h2>Tutorial</h2>

<h3>FreeNAS walkthrough</h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.daemonology.net/blog/2013-12-09-FreeBSD-EC2-configinit.html" rel="nofollow noopener">Introducing configinit</a></h3>

<ul>
<li>CloudInit is "a system originally written for Ubuntu which performs configuration of a system at boot-time based on user-data provided via EC2"</li>
<li>Wasn't ideal for FreeBSD since it requires python and is designed around the concept of configuring a system by running commands (rather than editing configuration files)</li>
<li>Colin Percival came up with configinit, a FreeBSD alternative</li>
<li>Alongside his new "firstboot-pkgs" port, it can spin up a webserver in 120 seconds from "launch" of the EC2 instance</li>
<li>Check the show notes for full blog post
***</li>
</ul>

<h3><a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.key?rev=1.1;content-type=text%2Fx-cvsweb-markup" rel="nofollow noopener">OpenSSH support for Ed25519 and bcrypt keys</a></h3>

<ul>
<li>New Ed25519 key support (hostkeys and user identities) using the public domain ed25519 reference code</li>
<li>SSH private keys were encrypted with a symmetric key that's just an MD5 of their password</li>
<li>Now they'll be using bcrypt <a href="http://marc.info/?l=openbsd-cvs&amp;m=138633721618361&amp;w=2" rel="nofollow noopener">by default</a></li>
<li>We'll get more into this in next week's interview
***</li>
</ul>

<h3><a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener">The FreeBSD challenge</a></h3>

<ul>
<li>A member of the Linux foundation blogs about using FreeBSD</li>
<li>Goes through all the beginner steps, has to "unlearn" some of his Linux ways</li>
<li>Only a few posts as of this time, but it's a continuing series that may be helpful for switchers
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-111513-2/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>GNOME3, cinnamon and mate desktops are in the installer</li>
<li>Compat layer updated to CentOS 6, enables newest Skype</li>
<li>Looking for people to test printers and hplip</li>
<li>Continuing work on grub, but the ability to switch between bootloaders is back
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20k2gumbP" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s2PM8tfKfe" rel="nofollow noopener">Jason writes in</a></li>
<li><a href="http://slexy.org/view/s2KgXIKqrJ" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s20DLk8bac" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s2nmmJHvgR" rel="nofollow noopener">Alexy writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be looking at the new version of FreeNAS, a BSD-based network attached storage solution, as well as talking to Josh Paetzel - one of the key developers of FreeNAS. Actually, he's on the FreeBSD release engineering team too, and does quite a lot for the project. We've got answers to your viewer-submitted questions and plenty of news to cover, so get ready for some BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-reid-linnemann.html" rel="nofollow noopener">More faces of FreeBSD</a></h3>

<ul>
<li>Another installment of the FoF series</li>
<li>This time they talk with Reid Linnemann who works at Spectra Logic</li>
<li>Gives a history of all the different jobs he's done, all the programming languages he knows</li>
<li>Mentions how he first learned about FreeBSD, actually pretty similar to Kris' story</li>
<li>"I used the system to build and install ports, and explored, getting actively involved in the mailing lists and forums, studying, passing on my own limited knowledge to those who could benefit from it. I pursued my career in the open source software world, learning the differences in BSD and GNU licensing and the fragmented nature of Linux distributions, realizing the FreeBSD community was more mature and well distributed about industry, education, and research. Everything steered me towards working with and on FreeBSD."</li>
<li>Now works on FreeBSD as his day job</li>
<li><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-brooks-davis.html" rel="nofollow noopener">The second one</a> covers Brooks Davis</li>
<li>FreeBSD committer since 2001 and core team member from 2006 through 2012</li>
<li>He's helped drive our transition from a GNU toolchain to a more modern LLVM-based toolchain</li>
<li>"One of the reasons I like FreeBSD is the community involved in the process of building a principled, technically-advanced operating system platform. Not only do we produce a great product, but we have fun doing it."</li>
<li>Lots more in the show notes
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2013-09-devsummit.html#Security" rel="nofollow noopener">We cannot trust Intel and Via’s chip-based crypto</a></h3>

<ul>
<li>We woke up to see FreeBSD on the front page of <a href="http://www.theregister.co.uk/2013/12/09/freebsd_abandoning_hardware_randomness/" rel="nofollow noopener">The Register</a>, <a href="http://arstechnica.com/security/2013/12/we-cannot-trust-intel-and-vias-chip-based-crypto-freebsd-developers-say/" rel="nofollow noopener">Ars Technica</a>, <a href="http://it.slashdot.org/story/13/12/11/1919201/freebsd-developers-will-not-trust-chip-based-encryption" rel="nofollow noopener">Slashdot</a> and <a href="https://news.ycombinator.com/item?id=6880474" rel="nofollow noopener">Hacker News</a> for their strong stance on security and respecting privacy</li>
<li>At the EuroBSDCon dev summit, there was some discussion about removing support for hardware-based random number generators.</li>
<li>FreeBSD's /dev/random got some updates and, for 10.0, will no longer allow the use of Intel or VIA's hardware RNGs as the sole point of entropy</li>
<li>"It will still be possible to access hardware random number generators, that is, RDRAND, Padlock etc., directly by inline assembly or by using OpenSSL from userland, if required, but we cannot trust them any more"
***</li>
</ul>

<h3><a href="http://article.gmane.org/gmane.mail.opensmtpd.general/1146" rel="nofollow noopener">OpenSMTPD 5.4.1 released</a></h3>

<ul>
<li>The OpenBSD developers came out with major a new version</li>
<li>Improved config syntax (please check your smtpd.conf before upgrading)</li>
<li>Adds support for TLS Perfect Forward Secrecy and custom CA certificate</li>
<li>MTA, Queue and SMTP server improvements</li>
<li>SNI support confirmed for the next version</li>
<li>Check the show notes for the full list of changes, pretty huge release</li>
<li>Watch <a href="http://www.bsdnow.tv/episodes/2013-09-18_mx_with_ttx" rel="nofollow noopener">Episode 3</a> for an interview we did with the developers
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/12/02/getting-to-know-your-portmgr-thomas-abthorpe/" rel="nofollow noopener">More getting to know your portmgr</a></h3>

<ul>
<li>The portmgr secretary, Thomas Abthorpe, interviews... himself!</li>
<li>Joined as -secretary in March 2010, upgraded to full member in March 2011</li>
<li>His inspiration for using BSD is "I wanted to run a webserver, and I wanted something free. I was going to use something linux, then met up with a former prof from university, and shared my story with him. He told me FreeBSD was the way to go."</li>
<li>Mentions how he loves that anyone can contribute and watch it "go live"</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2013/12/09/getting-to-know-your-portmgr-baptiste-daroussin/" rel="nofollow noopener">The second one</a> covers Baptiste Daroussin</li>
<li>The reason for his nick, bapt, is "Baptiste is too long to type"</li>
<li>There's even <a href="https://www.youtube.com/watch?v=tZk__K8rqOg" rel="nofollow noopener">a video</a> of bapt joining the team!
***</li>
</ul>

<h2>Interview - Santa Clause - <a href="mailto:josh@ixsystems.com" rel="nofollow noopener">josh@ixsystems.com</a> / <a href="https://twitter.com/freenasteam" rel="nofollow noopener">@freenasteam</a></h2>

<p>FreeNAS <a href="http://www.freenas.org/whats-new/2013/12/freenas-9-2-0-rc-available.html" rel="nofollow noopener">9.2.0</a></p>

<p><strong>Note: we originally scheduled the interview to be with Josh Paetzel, but Santa showed up instead.</strong></p>

<hr>

<h2>Tutorial</h2>

<h3>FreeNAS walkthrough</h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.daemonology.net/blog/2013-12-09-FreeBSD-EC2-configinit.html" rel="nofollow noopener">Introducing configinit</a></h3>

<ul>
<li>CloudInit is "a system originally written for Ubuntu which performs configuration of a system at boot-time based on user-data provided via EC2"</li>
<li>Wasn't ideal for FreeBSD since it requires python and is designed around the concept of configuring a system by running commands (rather than editing configuration files)</li>
<li>Colin Percival came up with configinit, a FreeBSD alternative</li>
<li>Alongside his new "firstboot-pkgs" port, it can spin up a webserver in 120 seconds from "launch" of the EC2 instance</li>
<li>Check the show notes for full blog post
***</li>
</ul>

<h3><a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.key?rev=1.1;content-type=text%2Fx-cvsweb-markup" rel="nofollow noopener">OpenSSH support for Ed25519 and bcrypt keys</a></h3>

<ul>
<li>New Ed25519 key support (hostkeys and user identities) using the public domain ed25519 reference code</li>
<li>SSH private keys were encrypted with a symmetric key that's just an MD5 of their password</li>
<li>Now they'll be using bcrypt <a href="http://marc.info/?l=openbsd-cvs&amp;m=138633721618361&amp;w=2" rel="nofollow noopener">by default</a></li>
<li>We'll get more into this in next week's interview
***</li>
</ul>

<h3><a href="http://thelinuxcauldron.com/2013/12/08/freebsd-challenge/" rel="nofollow noopener">The FreeBSD challenge</a></h3>

<ul>
<li>A member of the Linux foundation blogs about using FreeBSD</li>
<li>Goes through all the beginner steps, has to "unlearn" some of his Linux ways</li>
<li>Only a few posts as of this time, but it's a continuing series that may be helpful for switchers
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-111513-2/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>GNOME3, cinnamon and mate desktops are in the installer</li>
<li>Compat layer updated to CentOS 6, enables newest Skype</li>
<li>Looking for people to test printers and hplip</li>
<li>Continuing work on grub, but the ability to switch between bootloaders is back
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20k2gumbP" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s2PM8tfKfe" rel="nofollow noopener">Jason writes in</a></li>
<li><a href="http://slexy.org/view/s2KgXIKqrJ" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s20DLk8bac" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s2nmmJHvgR" rel="nofollow noopener">Alexy writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
