<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Fri, 29 May 2026 21:21:12 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Nginx”</title>
    <link>https://www.bsdnow.tv/tags/nginx</link>
    <pubDate>Thu, 17 Aug 2023 03:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>520: 4 months BSD</title>
  <link>https://www.bsdnow.tv/520</link>
  <guid isPermaLink="false">c4abf3ee-9d63-4f0a-bc8d-ea10b203a9e0</guid>
  <pubDate>Thu, 17 Aug 2023 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/c4abf3ee-9d63-4f0a-bc8d-ea10b203a9e0.mp3" length="41702784" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>4 Months of BSD, Self Hosted Calendar and address Book, Ban scanners IPs from OpenSMTP logs, Self-hosted git page, Bastille template example, Restrict nginx Access by Geographical Location on FreeBSD, and more.</itunes:subtitle>
  <itunes:duration>43:26</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;4 Months of BSD, Self Hosted Calendar and address Book, Ban scanners IPs from OpenSMTP logs, Self-hosted git page, Bastille template example, Restrict nginx Access by Geographical Location on FreeBSD, and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://danterobinson.dev/BSD/4MonthsofBSD" target="_blank" rel="nofollow noopener"&gt;4 Months of BSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.tumfatig.net/2023/self-hosted-calendar-and-addressbook-services-on-openbsd/" target="_blank" rel="nofollow noopener"&gt;Self Hosted Calendar and address Book&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://dataswamp.org/%7Esolene/2023-06-22-opensmtpd-block-attempts.html" target="_blank" rel="nofollow noopener"&gt;Ban scanners IPs from OpenSMTP logs&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://sebastiano.tronto.net/blog/2022-11-23-git-host/" target="_blank" rel="nofollow noopener"&gt;Self-hosted git page with stagit (featuring ed, the standard editor)&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://bastillebsd.org/blog/2022/01/03/bastille-template-examples-adguardhome/" target="_blank" rel="nofollow noopener"&gt;Bastille template example&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://herrbischoff.com/2021/05/nginx-how-to-restrict-access-by-geographical-location-on-freebsd/" target="_blank" rel="nofollow noopener"&gt;Nginx: How to Restrict Access by Geographical Location on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/Chris%20-%20arm.md" target="_blank" rel="nofollow noopener"&gt;Chris - ARM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/matthew%20-%20groups.md" target="_blank" rel="nofollow noopener"&gt;Matthew - Groups&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, server, shell, cli, unix, os, berkeley, software, distribution, development, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, 4 months, four, self-hosted, calendar, address book, ban, banning, opensmtp, log, log analysis, git-page, git, bastille, template, restrict, nginx, location, location-based, blocking, geo-block</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>4 Months of BSD, Self Hosted Calendar and address Book, Ban scanners IPs from OpenSMTP logs, Self-hosted git page, Bastille template example, Restrict nginx Access by Geographical Location on FreeBSD, and more.</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://danterobinson.dev/BSD/4MonthsofBSD" target="_blank" rel="nofollow noopener">4 Months of BSD</a></h3>

<hr>

<h3><a href="https://www.tumfatig.net/2023/self-hosted-calendar-and-addressbook-services-on-openbsd/" target="_blank" rel="nofollow noopener">Self Hosted Calendar and address Book</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://dataswamp.org/%7Esolene/2023-06-22-opensmtpd-block-attempts.html" target="_blank" rel="nofollow noopener">Ban scanners IPs from OpenSMTP logs</a></h3>

<hr>

<h3><a href="https://sebastiano.tronto.net/blog/2022-11-23-git-host/" target="_blank" rel="nofollow noopener">Self-hosted git page with stagit (featuring ed, the standard editor)</a></h3>

<hr>

<h3><a href="https://bastillebsd.org/blog/2022/01/03/bastille-template-examples-adguardhome/" target="_blank" rel="nofollow noopener">Bastille template example</a></h3>

<hr>

<h3><a href="https://herrbischoff.com/2021/05/nginx-how-to-restrict-access-by-geographical-location-on-freebsd/" target="_blank" rel="nofollow noopener">Nginx: How to Restrict Access by Geographical Location on FreeBSD</a></h3>

<hr>

<h2>Beastie Bits</h2>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/Chris%20-%20arm.md" target="_blank" rel="nofollow noopener">Chris - ARM</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/matthew%20-%20groups.md" target="_blank" rel="nofollow noopener">Matthew - Groups</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>4 Months of BSD, Self Hosted Calendar and address Book, Ban scanners IPs from OpenSMTP logs, Self-hosted git page, Bastille template example, Restrict nginx Access by Geographical Location on FreeBSD, and more.</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://danterobinson.dev/BSD/4MonthsofBSD" target="_blank" rel="nofollow noopener">4 Months of BSD</a></h3>

<hr>

<h3><a href="https://www.tumfatig.net/2023/self-hosted-calendar-and-addressbook-services-on-openbsd/" target="_blank" rel="nofollow noopener">Self Hosted Calendar and address Book</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://dataswamp.org/%7Esolene/2023-06-22-opensmtpd-block-attempts.html" target="_blank" rel="nofollow noopener">Ban scanners IPs from OpenSMTP logs</a></h3>

<hr>

<h3><a href="https://sebastiano.tronto.net/blog/2022-11-23-git-host/" target="_blank" rel="nofollow noopener">Self-hosted git page with stagit (featuring ed, the standard editor)</a></h3>

<hr>

<h3><a href="https://bastillebsd.org/blog/2022/01/03/bastille-template-examples-adguardhome/" target="_blank" rel="nofollow noopener">Bastille template example</a></h3>

<hr>

<h3><a href="https://herrbischoff.com/2021/05/nginx-how-to-restrict-access-by-geographical-location-on-freebsd/" target="_blank" rel="nofollow noopener">Nginx: How to Restrict Access by Geographical Location on FreeBSD</a></h3>

<hr>

<h2>Beastie Bits</h2>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/Chris%20-%20arm.md" target="_blank" rel="nofollow noopener">Chris - ARM</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/520/feedback/matthew%20-%20groups.md" target="_blank" rel="nofollow noopener">Matthew - Groups</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>516: Computer Time Origins</title>
  <link>https://www.bsdnow.tv/516</link>
  <guid isPermaLink="false">c8e97371-fb6b-48dc-97fe-8de45cd0e49c</guid>
  <pubDate>Thu, 20 Jul 2023 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/c8e97371-fb6b-48dc-97fe-8de45cd0e49c.mp3" length="44272128" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Linux and FreeBSD Firewalls Part 1, Why Netflix Chose NGINX as the Heart of Its CDN, Protect your web servers against PHP shells and malwares, Installing and running Gitlab howto, and more</itunes:subtitle>
  <itunes:duration>46:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Linux and FreeBSD Firewalls Part 1, Why Netflix Chose NGINX as the Heart of Its CDN, Protect your web servers against PHP shells and malwares, Installing and running Gitlab howto, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://klarasystems.com/articles/freebsd-linux-and-freebsd-firewalls/" target="_blank" rel="nofollow noopener"&gt;Linux vs. FreeBSD : Linux and FreeBSD Firewalls – The Ultimate Guide : Part 1&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.nginx.com/blog/why-netflix-chose-nginx-as-the-heart-of-its-cdn/" target="_blank" rel="nofollow noopener"&gt;Why Netflix Chose NGINX as the Heart of Its CDN&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://ozgurkazancci.com/freebsd-protect-your-web-server-against-php-shells-and-malwares/" target="_blank" rel="nofollow noopener"&gt;FreeBSD: Protect your web servers against PHP shells and malwares&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://forums.FreeBSD.org/threads/howto-installing-and-running-gitlab.89436/" target="_blank" rel="nofollow noopener"&gt;HowTo: Installing and running Gitlab&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;pre&gt;&lt;code&gt;• [World built in 36 hours on a Pentium 4!](https://www.reddit.com/r/freebsd/comments/13undl9/world_built_in_36_hours_on_a_pentium_4/)
• [Fart init](https://x61.sh/log/2023/05/23052023153621-fart-init.html](https://x61.sh/log/2023/05/23052023153621-fart-init.html)
• [Organized Freebies](https://mwl.io/archives/22832)
• [OpenSMTPD 7.3.0p0 released](http://undeadly.org/cgi?action=article;sid=20230617111340)
• [shutdown/reboot now require membership of group _shutdown](http://undeadly.org/cgi?action=article;sid=20230620064255)
• [Where does my computer get the time from?](https://dotat.at/@/2023-05-26-whence-time.html)
&lt;/code&gt;&lt;/pre&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/515/feedback/sam%20-%20fav%20episodes.md" target="_blank" rel="nofollow noopener"&gt;sam - fav episodes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, cli, unix, os, berkeley, software, distribution, development, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, firewalls, comparison, time, system clock, web server, php shell, malware, netflix, nginx, cdn, gitlab</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Linux and FreeBSD Firewalls Part 1, Why Netflix Chose NGINX as the Heart of Its CDN, Protect your web servers against PHP shells and malwares, Installing and running Gitlab howto, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/freebsd-linux-and-freebsd-firewalls/" target="_blank" rel="nofollow noopener">Linux vs. FreeBSD : Linux and FreeBSD Firewalls – The Ultimate Guide : Part 1</a></h3>

<hr>

<h3><a href="https://www.nginx.com/blog/why-netflix-chose-nginx-as-the-heart-of-its-cdn/" target="_blank" rel="nofollow noopener">Why Netflix Chose NGINX as the Heart of Its CDN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://ozgurkazancci.com/freebsd-protect-your-web-server-against-php-shells-and-malwares/" target="_blank" rel="nofollow noopener">FreeBSD: Protect your web servers against PHP shells and malwares</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/howto-installing-and-running-gitlab.89436/" target="_blank" rel="nofollow noopener">HowTo: Installing and running Gitlab</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [World built in 36 hours on a Pentium 4!](https://www.reddit.com/r/freebsd/comments/13undl9/world_built_in_36_hours_on_a_pentium_4/)
• [Fart init](https://x61.sh/log/2023/05/23052023153621-fart-init.html](https://x61.sh/log/2023/05/23052023153621-fart-init.html)
• [Organized Freebies](https://mwl.io/archives/22832)
• [OpenSMTPD 7.3.0p0 released](http://undeadly.org/cgi?action=article;sid=20230617111340)
• [shutdown/reboot now require membership of group _shutdown](http://undeadly.org/cgi?action=article;sid=20230620064255)
• [Where does my computer get the time from?](https://dotat.at/@/2023-05-26-whence-time.html)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/515/feedback/sam%20-%20fav%20episodes.md" target="_blank" rel="nofollow noopener">sam - fav episodes</a></li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Linux and FreeBSD Firewalls Part 1, Why Netflix Chose NGINX as the Heart of Its CDN, Protect your web servers against PHP shells and malwares, Installing and running Gitlab howto, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/freebsd-linux-and-freebsd-firewalls/" target="_blank" rel="nofollow noopener">Linux vs. FreeBSD : Linux and FreeBSD Firewalls – The Ultimate Guide : Part 1</a></h3>

<hr>

<h3><a href="https://www.nginx.com/blog/why-netflix-chose-nginx-as-the-heart-of-its-cdn/" target="_blank" rel="nofollow noopener">Why Netflix Chose NGINX as the Heart of Its CDN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://ozgurkazancci.com/freebsd-protect-your-web-server-against-php-shells-and-malwares/" target="_blank" rel="nofollow noopener">FreeBSD: Protect your web servers against PHP shells and malwares</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/howto-installing-and-running-gitlab.89436/" target="_blank" rel="nofollow noopener">HowTo: Installing and running Gitlab</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [World built in 36 hours on a Pentium 4!](https://www.reddit.com/r/freebsd/comments/13undl9/world_built_in_36_hours_on_a_pentium_4/)
• [Fart init](https://x61.sh/log/2023/05/23052023153621-fart-init.html](https://x61.sh/log/2023/05/23052023153621-fart-init.html)
• [Organized Freebies](https://mwl.io/archives/22832)
• [OpenSMTPD 7.3.0p0 released](http://undeadly.org/cgi?action=article;sid=20230617111340)
• [shutdown/reboot now require membership of group _shutdown](http://undeadly.org/cgi?action=article;sid=20230620064255)
• [Where does my computer get the time from?](https://dotat.at/@/2023-05-26-whence-time.html)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/515/feedback/sam%20-%20fav%20episodes.md" target="_blank" rel="nofollow noopener">sam - fav episodes</a></li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>461: Persistent Memory Allocation</title>
  <link>https://www.bsdnow.tv/461</link>
  <guid isPermaLink="false">8809dc88-c752-4733-9f19-4bcd7e2ca683</guid>
  <pubDate>Thu, 30 Jun 2022 03:45:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/8809dc88-c752-4733-9f19-4bcd7e2ca683.mp3" length="28160232" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Q1 FreeBSD Quarterly Status Report 2022, Nginx on OpenBSD 7.1, Persistent Memory Allocation, Colorize your BSD shell, cgit With Gitolite and Nginx on FreeBSD 13, and more</itunes:subtitle>
  <itunes:duration>49:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Q1 FreeBSD Quarterly Status Report 2022, Nginx on OpenBSD 7.1, Persistent Memory Allocation, Colorize your BSD shell, cgit With Gitolite and Nginx on FreeBSD 13, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/status/report-2022-01-2022-03/" target="_blank" rel="nofollow noopener"&gt;FreeBSD Quarterly Status Report First Quarter 2022&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://unixcop.com/installing-nginx-on-openbsd-7-1/" target="_blank" rel="nofollow noopener"&gt;Installing Nginx on OpenBSD 7.1&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://klarasystems.com/webinars/live-sessions-singup/webinar-open-source-virtualization-getting-started-with-bhyve/" target="_blank" rel="nofollow noopener"&gt;Live Webinar: Open-source Virtualization: Getting started with bhyve &lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hosted by Jim Salter and Allan Jude&lt;/li&gt;
&lt;li&gt;Live July 12th at 13:00 ET&lt;/li&gt;
&lt;li&gt;Available on-demand a few days later&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://queue.acm.org/detail.cfm?id=3534855" target="_blank" rel="nofollow noopener"&gt;Persistent Memory Allocation&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://forums.FreeBSD.org/threads/colorize-your-bsd-shell.85458/" target="_blank" rel="nofollow noopener"&gt;Colorize your BSD shell&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://herrbischoff.com/2021/10/how-to-install-cgit-with-gitolite-and-nginx-on-freebsd-13" target="_blank" rel="nofollow noopener"&gt;How to Install cgit With Gitolite and Nginx on FreeBSD 13&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://2022.eurobsdcon.org/program/" target="_blank" rel="nofollow noopener"&gt;EuroBSDCon 2022 (Austria) Program announced&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Come to Austria and learn about the latest happenings in the BSDs&lt;/li&gt;
&lt;li&gt;2 days of tutorials, and 2 days of 3 concurrent tracks of talks&lt;/li&gt;
&lt;li&gt;Registration is open now. See you there!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Brad%20-%20Drive%20question.md" target="_blank" rel="nofollow noopener"&gt;Brad - Drive question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Carl%20-%20Wiring%20question.md" target="_blank" rel="nofollow noopener"&gt;Carl - Wiring question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Jon%20-%20Jails%20question.md" target="_blank" rel="nofollow noopener"&gt;Jon - Jails question&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, filesystem, interview, ports, packages, jails, status report, quarterly, nginx, persistent memory, memory allocation, colorize, color, cgit, gitolite </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Q1 FreeBSD Quarterly Status Report 2022, Nginx on OpenBSD 7.1, Persistent Memory Allocation, Colorize your BSD shell, cgit With Gitolite and Nginx on FreeBSD 13, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/status/report-2022-01-2022-03/" target="_blank" rel="nofollow noopener">FreeBSD Quarterly Status Report First Quarter 2022</a></h3>

<hr>

<h3><a href="https://unixcop.com/installing-nginx-on-openbsd-7-1/" target="_blank" rel="nofollow noopener">Installing Nginx on OpenBSD 7.1</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://klarasystems.com/webinars/live-sessions-singup/webinar-open-source-virtualization-getting-started-with-bhyve/" target="_blank" rel="nofollow noopener">Live Webinar: Open-source Virtualization: Getting started with bhyve </a></h3>

<ul>
<li>Hosted by Jim Salter and Allan Jude</li>
<li>Live July 12th at 13:00 ET</li>
<li>Available on-demand a few days later</li>
</ul>

<hr>

<h3><a href="https://queue.acm.org/detail.cfm?id=3534855" target="_blank" rel="nofollow noopener">Persistent Memory Allocation</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/colorize-your-bsd-shell.85458/" target="_blank" rel="nofollow noopener">Colorize your BSD shell</a></h3>

<hr>

<h3><a href="https://herrbischoff.com/2021/10/how-to-install-cgit-with-gitolite-and-nginx-on-freebsd-13" target="_blank" rel="nofollow noopener">How to Install cgit With Gitolite and Nginx on FreeBSD 13</a></h3>

<hr>

<h3><a href="https://2022.eurobsdcon.org/program/" target="_blank" rel="nofollow noopener">EuroBSDCon 2022 (Austria) Program announced</a></h3>

<ul>
<li>Come to Austria and learn about the latest happenings in the BSDs</li>
<li>2 days of tutorials, and 2 days of 3 concurrent tracks of talks</li>
<li>Registration is open now. See you there!
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Brad%20-%20Drive%20question.md" target="_blank" rel="nofollow noopener">Brad - Drive question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Carl%20-%20Wiring%20question.md" target="_blank" rel="nofollow noopener">Carl - Wiring question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Jon%20-%20Jails%20question.md" target="_blank" rel="nofollow noopener">Jon - Jails question</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Q1 FreeBSD Quarterly Status Report 2022, Nginx on OpenBSD 7.1, Persistent Memory Allocation, Colorize your BSD shell, cgit With Gitolite and Nginx on FreeBSD 13, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/status/report-2022-01-2022-03/" target="_blank" rel="nofollow noopener">FreeBSD Quarterly Status Report First Quarter 2022</a></h3>

<hr>

<h3><a href="https://unixcop.com/installing-nginx-on-openbsd-7-1/" target="_blank" rel="nofollow noopener">Installing Nginx on OpenBSD 7.1</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://klarasystems.com/webinars/live-sessions-singup/webinar-open-source-virtualization-getting-started-with-bhyve/" target="_blank" rel="nofollow noopener">Live Webinar: Open-source Virtualization: Getting started with bhyve </a></h3>

<ul>
<li>Hosted by Jim Salter and Allan Jude</li>
<li>Live July 12th at 13:00 ET</li>
<li>Available on-demand a few days later</li>
</ul>

<hr>

<h3><a href="https://queue.acm.org/detail.cfm?id=3534855" target="_blank" rel="nofollow noopener">Persistent Memory Allocation</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/colorize-your-bsd-shell.85458/" target="_blank" rel="nofollow noopener">Colorize your BSD shell</a></h3>

<hr>

<h3><a href="https://herrbischoff.com/2021/10/how-to-install-cgit-with-gitolite-and-nginx-on-freebsd-13" target="_blank" rel="nofollow noopener">How to Install cgit With Gitolite and Nginx on FreeBSD 13</a></h3>

<hr>

<h3><a href="https://2022.eurobsdcon.org/program/" target="_blank" rel="nofollow noopener">EuroBSDCon 2022 (Austria) Program announced</a></h3>

<ul>
<li>Come to Austria and learn about the latest happenings in the BSDs</li>
<li>2 days of tutorials, and 2 days of 3 concurrent tracks of talks</li>
<li>Registration is open now. See you there!
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Brad%20-%20Drive%20question.md" target="_blank" rel="nofollow noopener">Brad - Drive question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Carl%20-%20Wiring%20question.md" target="_blank" rel="nofollow noopener">Carl - Wiring question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/461/feedback/Jon%20-%20Jails%20question.md" target="_blank" rel="nofollow noopener">Jon - Jails question</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>399: Comparing Sandboxes</title>
  <link>https://www.bsdnow.tv/399</link>
  <guid isPermaLink="false">3de2dd50-eca9-4729-9ef6-464aa4ec5795</guid>
  <pubDate>Thu, 22 Apr 2021 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/3de2dd50-eca9-4729-9ef6-464aa4ec5795.mp3" length="36616080" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Comparing sandboxing techniques, Statement on FreeBSD development processes, customizing FreeBSD ports and packages, the quest for a comfortable NetBSD desktop, Nginx as a TCP/UDP relay, HardenedBSD March 2021 Status Report, Detailed Behaviors of Unix Signal, and more
</itunes:subtitle>
  <itunes:duration>57:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Comparing sandboxing techniques, Statement on FreeBSD development processes, customizing FreeBSD ports and packages, the quest for a comfortable NetBSD desktop, Nginx as a TCP/UDP relay, HardenedBSD March 2021 Status Report, Detailed Behaviors of Unix Signal, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.omarpolo.com/post/gmid-sandbox.html" target="_blank" rel="nofollow noopener"&gt;Comparing sandboxing techniques&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;I had the opportunity to implement a sandbox and I'd like to write about the differences between the various sandboxing techniques available on three different operating systems: FreeBSD, Linux and OpenBSD.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2021-March/057127.html" target="_blank" rel="nofollow noopener"&gt;Statement on FreeBSD development processes&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;In light of the recent commentary on FreeBSD's development practices, members of the Core team would like to issue the following statement.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://klarasystems.com/articles/customizing-freebsd-ports-and-packages/" target="_blank" rel="nofollow noopener"&gt;Customizing FreeBSD Ports and Packages&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;A basic intro to building your own packages&lt;/p&gt;

&lt;hr&gt;
&lt;/blockquote&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.unitedbsd.com/d/442-fvwm3-and-the-quest-for-a-comfortable-netbsd-desktop" target="_blank" rel="nofollow noopener"&gt;FVWM(3) and the quest for a comfortable NetBSD desktop&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;FVWM substantially allows one to build a fully-fledged lightweight desktop environment from scratch, with an almost unparalleled degree of freedom. Although using FVWM does not require any knowledge of programming languages, it is possible to extend it with M4, C, and Perl preprocessing.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://dataswamp.org/%7Esolene/2021-02-24-nginx-stream.html" target="_blank" rel="nofollow noopener"&gt;Nginx as a TCP/UDP relay&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;In this tutorial I will explain how to use Nginx as a TCP or UDP relay as an alternative to Haproxy or Relayd. This mean nginx will be able to accept requests on a port (TCP/UDP) and relay it to another backend without knowing about the content. It also permits to negociates a TLS session with the client and relay to a non-TLS backend. In this example I will explain how to configure Nginx to accept TLS requests to transmit it to my Gemini server Vger, Gemini protocol has TLS as a requirement.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://hardenedbsd.org/article/shawn-webb/2021-03-31/hardenedbsd-march-2021-status-report" target="_blank" rel="nofollow noopener"&gt;HardenedBSD March 2021 Status Report&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;This month, I worked on finding and fixing the regression that caused kernel panics on our package builders. I think I found the issue: I made it so that the HARDENEDBSD amd64 kernel just included GENERIC so that we follow FreeBSD's toggling of features. Doing so added QUEUE_MACRO_DEBUG_TRASH to our kernel config. That option is the likely culprit. If the next package build (with the option removed) completes, I will commit the change that removes QUEUE_MACRO_DEBUG_TRASH from the HARDENEDBSD amd64 kernel.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.dyx.name/posts/essays/signal.html" target="_blank" rel="nofollow noopener"&gt;Detailed Behaviors of Unix Signal&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;When Unix is mentioned in this document it means macOS or Linux as they are the mainly used Unix at this moment. When shell is mentioned it means Bash or Zsh. Most demos are written in C for macOS with Apple libc and Linux with glibc.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/andrew%20-%20flatpak" target="_blank" rel="nofollow noopener"&gt;andrew - flatpak&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/chris%20-%20mac%20and%20truenas" target="_blank" rel="nofollow noopener"&gt;chris - mac and truenas&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/robert%20-%20some%20questions" target="_blank" rel="nofollow noopener"&gt;robert - some questions&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, sandboxing, sandbox technique, development process, statement, customizing, ports, packages, nginx, relay, tcp, udp, status report, signal</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Comparing sandboxing techniques, Statement on FreeBSD development processes, customizing FreeBSD ports and packages, the quest for a comfortable NetBSD desktop, Nginx as a TCP/UDP relay, HardenedBSD March 2021 Status Report, Detailed Behaviors of Unix Signal, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.omarpolo.com/post/gmid-sandbox.html" target="_blank" rel="nofollow noopener">Comparing sandboxing techniques</a></h3>

<blockquote>
<p>I had the opportunity to implement a sandbox and I'd like to write about the differences between the various sandboxing techniques available on three different operating systems: FreeBSD, Linux and OpenBSD.</p>

<hr>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2021-March/057127.html" target="_blank" rel="nofollow noopener">Statement on FreeBSD development processes</a></h3>

<p>In light of the recent commentary on FreeBSD's development practices, members of the Core team would like to issue the following statement.</p>

<hr>

<h3><a href="https://klarasystems.com/articles/customizing-freebsd-ports-and-packages/" target="_blank" rel="nofollow noopener">Customizing FreeBSD Ports and Packages</a></h3>

<p>A basic intro to building your own packages</p>

<hr>
</blockquote>

<h2>News Roundup</h2>

<h3><a href="https://www.unitedbsd.com/d/442-fvwm3-and-the-quest-for-a-comfortable-netbsd-desktop" target="_blank" rel="nofollow noopener">FVWM(3) and the quest for a comfortable NetBSD desktop</a></h3>

<blockquote>
<p>FVWM substantially allows one to build a fully-fledged lightweight desktop environment from scratch, with an almost unparalleled degree of freedom. Although using FVWM does not require any knowledge of programming languages, it is possible to extend it with M4, C, and Perl preprocessing.</p>

<hr>

<h3><a href="https://dataswamp.org/%7Esolene/2021-02-24-nginx-stream.html" target="_blank" rel="nofollow noopener">Nginx as a TCP/UDP relay</a></h3>

<p>In this tutorial I will explain how to use Nginx as a TCP or UDP relay as an alternative to Haproxy or Relayd. This mean nginx will be able to accept requests on a port (TCP/UDP) and relay it to another backend without knowing about the content. It also permits to negociates a TLS session with the client and relay to a non-TLS backend. In this example I will explain how to configure Nginx to accept TLS requests to transmit it to my Gemini server Vger, Gemini protocol has TLS as a requirement.</p>

<hr>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2021-03-31/hardenedbsd-march-2021-status-report" target="_blank" rel="nofollow noopener">HardenedBSD March 2021 Status Report</a></h3>

<p>This month, I worked on finding and fixing the regression that caused kernel panics on our package builders. I think I found the issue: I made it so that the HARDENEDBSD amd64 kernel just included GENERIC so that we follow FreeBSD's toggling of features. Doing so added QUEUE_MACRO_DEBUG_TRASH to our kernel config. That option is the likely culprit. If the next package build (with the option removed) completes, I will commit the change that removes QUEUE_MACRO_DEBUG_TRASH from the HARDENEDBSD amd64 kernel.</p>

<hr>

<h3><a href="https://www.dyx.name/posts/essays/signal.html" target="_blank" rel="nofollow noopener">Detailed Behaviors of Unix Signal</a></h3>

<p>When Unix is mentioned in this document it means macOS or Linux as they are the mainly used Unix at this moment. When shell is mentioned it means Bash or Zsh. Most demos are written in C for macOS with Apple libc and Linux with glibc.</p>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>
</blockquote>

<h2>Feedback/Questions</h2>

<ul>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/andrew%20-%20flatpak" target="_blank" rel="nofollow noopener">andrew - flatpak</a></p></li>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/chris%20-%20mac%20and%20truenas" target="_blank" rel="nofollow noopener">chris - mac and truenas</a></p></li>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/robert%20-%20some%20questions" target="_blank" rel="nofollow noopener">robert - some questions</a></p>

<hr></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p>

<hr></li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Comparing sandboxing techniques, Statement on FreeBSD development processes, customizing FreeBSD ports and packages, the quest for a comfortable NetBSD desktop, Nginx as a TCP/UDP relay, HardenedBSD March 2021 Status Report, Detailed Behaviors of Unix Signal, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.omarpolo.com/post/gmid-sandbox.html" target="_blank" rel="nofollow noopener">Comparing sandboxing techniques</a></h3>

<blockquote>
<p>I had the opportunity to implement a sandbox and I'd like to write about the differences between the various sandboxing techniques available on three different operating systems: FreeBSD, Linux and OpenBSD.</p>

<hr>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2021-March/057127.html" target="_blank" rel="nofollow noopener">Statement on FreeBSD development processes</a></h3>

<p>In light of the recent commentary on FreeBSD's development practices, members of the Core team would like to issue the following statement.</p>

<hr>

<h3><a href="https://klarasystems.com/articles/customizing-freebsd-ports-and-packages/" target="_blank" rel="nofollow noopener">Customizing FreeBSD Ports and Packages</a></h3>

<p>A basic intro to building your own packages</p>

<hr>
</blockquote>

<h2>News Roundup</h2>

<h3><a href="https://www.unitedbsd.com/d/442-fvwm3-and-the-quest-for-a-comfortable-netbsd-desktop" target="_blank" rel="nofollow noopener">FVWM(3) and the quest for a comfortable NetBSD desktop</a></h3>

<blockquote>
<p>FVWM substantially allows one to build a fully-fledged lightweight desktop environment from scratch, with an almost unparalleled degree of freedom. Although using FVWM does not require any knowledge of programming languages, it is possible to extend it with M4, C, and Perl preprocessing.</p>

<hr>

<h3><a href="https://dataswamp.org/%7Esolene/2021-02-24-nginx-stream.html" target="_blank" rel="nofollow noopener">Nginx as a TCP/UDP relay</a></h3>

<p>In this tutorial I will explain how to use Nginx as a TCP or UDP relay as an alternative to Haproxy or Relayd. This mean nginx will be able to accept requests on a port (TCP/UDP) and relay it to another backend without knowing about the content. It also permits to negociates a TLS session with the client and relay to a non-TLS backend. In this example I will explain how to configure Nginx to accept TLS requests to transmit it to my Gemini server Vger, Gemini protocol has TLS as a requirement.</p>

<hr>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2021-03-31/hardenedbsd-march-2021-status-report" target="_blank" rel="nofollow noopener">HardenedBSD March 2021 Status Report</a></h3>

<p>This month, I worked on finding and fixing the regression that caused kernel panics on our package builders. I think I found the issue: I made it so that the HARDENEDBSD amd64 kernel just included GENERIC so that we follow FreeBSD's toggling of features. Doing so added QUEUE_MACRO_DEBUG_TRASH to our kernel config. That option is the likely culprit. If the next package build (with the option removed) completes, I will commit the change that removes QUEUE_MACRO_DEBUG_TRASH from the HARDENEDBSD amd64 kernel.</p>

<hr>

<h3><a href="https://www.dyx.name/posts/essays/signal.html" target="_blank" rel="nofollow noopener">Detailed Behaviors of Unix Signal</a></h3>

<p>When Unix is mentioned in this document it means macOS or Linux as they are the mainly used Unix at this moment. When shell is mentioned it means Bash or Zsh. Most demos are written in C for macOS with Apple libc and Linux with glibc.</p>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>
</blockquote>

<h2>Feedback/Questions</h2>

<ul>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/andrew%20-%20flatpak" target="_blank" rel="nofollow noopener">andrew - flatpak</a></p></li>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/chris%20-%20mac%20and%20truenas" target="_blank" rel="nofollow noopener">chris - mac and truenas</a></p></li>
<li><p><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/399/feedback/robert%20-%20some%20questions" target="_blank" rel="nofollow noopener">robert - some questions</a></p>

<hr></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p>

<hr></li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>325: Cracking Rainbows</title>
  <link>https://www.bsdnow.tv/325</link>
  <guid isPermaLink="false">a971b40e-d33a-44ac-9cf8-dfaf7e4aaff7</guid>
  <pubDate>Thu, 21 Nov 2019 07:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/a971b40e-d33a-44ac-9cf8-dfaf7e4aaff7.mp3" length="41526775" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>FreeBSD 12.1 is here, A history of Unix before Berkeley, FreeBSD development setup, HardenedBSD 2019 Status Report, DNSSEC, compiling RainbowCrack on OpenBSD, and more.</itunes:subtitle>
  <itunes:duration>57:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;FreeBSD 12.1 is here, A history of Unix before Berkeley, FreeBSD development setup, HardenedBSD 2019 Status Report, DNSSEC, compiling RainbowCrack on OpenBSD, and more.&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/12.1R/announce.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD 12.1&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Some of the highlights:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;BearSSL has been imported to the base system.&lt;/li&gt;
&lt;li&gt;The clang, llvm, lld, lldb, compiler-rt utilities and libc++ have been updated to version 8.0.1.&lt;/li&gt;
&lt;li&gt;OpenSSL has been updated to version 1.1.1d.&lt;/li&gt;
&lt;li&gt;Several userland utility updates.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;For a complete list of new features and known problems, please see the online release notes and errata list, available at: &lt;a href="https://www.FreeBSD.org/releases/12.1R/relnotes.html" target="_blank" rel="nofollow noopener"&gt;https://www.FreeBSD.org/releases/12.1R/relnotes.html&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="http://www.darwinsys.com/history/hist.html" target="_blank" rel="nofollow noopener"&gt;A History of UNIX before Berkeley: UNIX Evolution: 1975-1984.&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Nobody needs to be told that UNIX is popular today. In this article we will show you a little of where it was yesterday and over the past decade. And, without meaning in the least to minimise the incredible contributions of Ken Thompson and Dennis Ritchie, we will bring to light many of the others who worked on early versions, and try to show where some of the key ideas came from, and how they got into the UNIX of today.&lt;/p&gt;

&lt;p&gt;Our title says we are talking about UNIX evolution. Evolution means different things to different people. We use the term loosely, to describe the change over time among the many different UNIX variants in use both inside and outside Bell Labs. Ideas, code, and useful programs seem to have made their way back and forth - like mutant genes - among all the many UNIXes living in the phone company over the decade in question.&lt;/p&gt;

&lt;p&gt;Part One looks at some of the major components of the current UNIX system - the text formatting tools, the compilers and program development tools, and so on. Most of the work described in Part One took place at &lt;code&gt;Research'', a part of Bell Laboratories (now AT&amp;amp;T Bell Laboratories, then as now&lt;/code&gt;the Labs''), and the ancestral home of UNIX. In planned (but not written) later parts, we would have looked at some of the myriad versions of UNIX - there are far more than one might suspect. This includes a look at Columbus and USG and at Berkeley Unix. You'll begin to get a glimpse inside the history of the major streams of development of the system during that time.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://adventurist.me/posts/00296" target="_blank" rel="nofollow noopener"&gt;My FreeBSD Development Setup&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;I do my FreeBSD development using git, tmux, vim and cscope.&lt;/p&gt;

&lt;p&gt;I keep a FreeBSD fork on my github, I have forked &lt;a href="https://github.com/freebsd/freebsd" target="_blank" rel="nofollow noopener"&gt;https://github.com/freebsd/freebsd&lt;/a&gt; to &lt;a href="https://github.com/adventureloop/freebsd" target="_blank" rel="nofollow noopener"&gt;https://github.com/adventureloop/freebsd&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://opnsense.org/opnsense-19-7-6-released/" target="_blank" rel="nofollow noopener"&gt;OPNsense 19.7.6 released&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;As we are experiencing the Suricata community first hand in Amsterdam we thought to release this version a bit earlier than planned. Included is the latest Suricata 5.0.0 release in the development version. That means later this November we will releasing version 5 to the production version as we finish up tweaking the integration and maybe pick up 5.0.1 as it becomes available.&lt;/p&gt;

&lt;p&gt;LDAP TLS connectivity is now integrated into the system trust store, which ensures that all required root and intermediate certificates will be seen by the connection setup when they have been added to the authorities section. The same is true for trusting self-signed certificates. On top of this, IPsec now supports public key authentication as contributed by Pascal Mathis.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://hardenedbsd.org/article/shawn-webb/2019-11-09/hardenedbsd-status-report" target="_blank" rel="nofollow noopener"&gt;HardenedBSD November 2019 Status Report.&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;We at HardenedBSD have a lot of news to share. On 05 Nov 2019, Oliver Pinter resigned amicably from the project. All of us at HardenedBSD owe Oliver our gratitude and appreciation. This humble project, named by Oliver, was born out of his thesis work and the collaboration with Shawn Webb. Oliver created the HardenedBSD repo on GitHub in April 2013. The HardenedBSD Foundation was formed five years later to carry on this great work. &lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://undeadly.org/cgi?action=article;sid=20191110123908" target="_blank" rel="nofollow noopener"&gt;DNSSEC enabled in default unbound(8) configuration.&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;DNSSEC validation has been enabled in the default unbound.conf(5) in -current. The relevant commits were from Job Snijders (job@)&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.howtoforge.com/how-to-install-shopware-with-nginx-and-lets-encrypt-on-freebsd-12/" target="_blank" rel="nofollow noopener"&gt;How to Install Shopware with NGINX and Let's Encrypt on FreeBSD 12&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Shopware is the next generation of open source e-commerce software. Based on bleeding edge technologies like Symfony 3, Doctrine2 and Zend Framework Shopware comes as the perfect platform for your next e-commerce project. This tutorial will walk you through the Shopware Community Edition (CE) installation on FreeBSD 12 system by using NGINX as a web server.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Requirements&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Make sure your system meets the following minimum requirements:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Linux-based operating system with NGINX or Apache 2.x (with mod_rewrite) web server installed. &lt;/li&gt;
&lt;li&gt;PHP 5.6.4 or higher with ctype, gd, curl, dom, hash, iconv, zip, json, mbstring, openssl, session, simplexml, xml, zlib, fileinfo, and pdo/mysql extensions. PHP 7.1 or above is strongly recommended.&lt;/li&gt;
&lt;li&gt;MySQL 5.5.0 or higher.&lt;/li&gt;
&lt;li&gt;Possibility to set up cron jobs.&lt;/li&gt;
&lt;li&gt;Minimum 4 GB available hard disk space.&lt;/li&gt;
&lt;li&gt;IonCube Loader version 5.0.0 or higher (optional).&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://cromwell-intl.com/open-source/compiling-rainbowcrack-on-openbsd.html" target="_blank" rel="nofollow noopener"&gt;How to Compile RainbowCrack on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Project RainbowCrack was originally Zhu Shuanglei's implementation, it's not clear to me if the project is still just his or if it's even been maintained for a while. His page seems to have been last updated in August 2007.&lt;/p&gt;

&lt;p&gt;The Project RainbowCrack web page now has just binaries for Windows XP and Linux, both 32-bit and 64-bit versions.&lt;/p&gt;

&lt;p&gt;Earlier versions were available as source code. The version 1.2 source code does not compile on OpenBSD, and in my experience it doesn't compile on Linux, either. It seems to date from 2004 at the earliest, and I think it makes some version-2.4 assumptions about Linux kernel headers.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;You might also look at ophcrack, a more modern tool, although it seems to be focused on cracking Windows XP/Vista/7/8/10 password hashes&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Reese - &lt;a href="http://dpaste.com/2RDG9K4#wrap" target="_blank" rel="nofollow noopener"&gt;Amature radio info&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chris - &lt;a href="http://dpaste.com/2K4T2FQ#wrap" target="_blank" rel="nofollow noopener"&gt;VPN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malcolm - &lt;a href="http://dpaste.com/138NEMA" target="_blank" rel="nofollow noopener"&gt;NAT&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;


    &lt;source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0325.mp4" type="video/mp4"&gt;
    Your browser does not support the HTML5 video tag.
 
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, interview, 12.1, Unix, history, berkeley, OPNsense, development, setup, dev, devel, status report, dnssec, unbound, shopware, let’s encrypt, nginx, rainbowcrack, compiling</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>FreeBSD 12.1 is here, A history of Unix before Berkeley, FreeBSD development setup, HardenedBSD 2019 Status Report, DNSSEC, compiling RainbowCrack on OpenBSD, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/12.1R/announce.html" target="_blank" rel="nofollow noopener">FreeBSD 12.1</a></h3>

<ul>
<li><p>Some of the highlights:</p>

<ul>
<li>BearSSL has been imported to the base system.</li>
<li>The clang, llvm, lld, lldb, compiler-rt utilities and libc++ have been updated to version 8.0.1.</li>
<li>OpenSSL has been updated to version 1.1.1d.</li>
<li>Several userland utility updates.</li>
</ul></li>
<li><p>For a complete list of new features and known problems, please see the online release notes and errata list, available at: <a href="https://www.FreeBSD.org/releases/12.1R/relnotes.html" target="_blank" rel="nofollow noopener">https://www.FreeBSD.org/releases/12.1R/relnotes.html</a></p></li>
</ul>

<hr>

<h3><a href="http://www.darwinsys.com/history/hist.html" target="_blank" rel="nofollow noopener">A History of UNIX before Berkeley: UNIX Evolution: 1975-1984.</a></h3>

<blockquote>
<p>Nobody needs to be told that UNIX is popular today. In this article we will show you a little of where it was yesterday and over the past decade. And, without meaning in the least to minimise the incredible contributions of Ken Thompson and Dennis Ritchie, we will bring to light many of the others who worked on early versions, and try to show where some of the key ideas came from, and how they got into the UNIX of today.</p>

<p>Our title says we are talking about UNIX evolution. Evolution means different things to different people. We use the term loosely, to describe the change over time among the many different UNIX variants in use both inside and outside Bell Labs. Ideas, code, and useful programs seem to have made their way back and forth - like mutant genes - among all the many UNIXes living in the phone company over the decade in question.</p>

<p>Part One looks at some of the major components of the current UNIX system - the text formatting tools, the compilers and program development tools, and so on. Most of the work described in Part One took place at <code>Research'', a part of Bell Laboratories (now AT&amp;T Bell Laboratories, then as now</code>the Labs''), and the ancestral home of UNIX. In planned (but not written) later parts, we would have looked at some of the myriad versions of UNIX - there are far more than one might suspect. This includes a look at Columbus and USG and at Berkeley Unix. You'll begin to get a glimpse inside the history of the major streams of development of the system during that time.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://adventurist.me/posts/00296" target="_blank" rel="nofollow noopener">My FreeBSD Development Setup</a></h3>

<blockquote>
<p>I do my FreeBSD development using git, tmux, vim and cscope.</p>

<p>I keep a FreeBSD fork on my github, I have forked <a href="https://github.com/freebsd/freebsd" target="_blank" rel="nofollow noopener">https://github.com/freebsd/freebsd</a> to <a href="https://github.com/adventureloop/freebsd" target="_blank" rel="nofollow noopener">https://github.com/adventureloop/freebsd</a></p>
</blockquote>

<hr>

<h3><a href="https://opnsense.org/opnsense-19-7-6-released/" target="_blank" rel="nofollow noopener">OPNsense 19.7.6 released</a></h3>

<blockquote>
<p>As we are experiencing the Suricata community first hand in Amsterdam we thought to release this version a bit earlier than planned. Included is the latest Suricata 5.0.0 release in the development version. That means later this November we will releasing version 5 to the production version as we finish up tweaking the integration and maybe pick up 5.0.1 as it becomes available.</p>

<p>LDAP TLS connectivity is now integrated into the system trust store, which ensures that all required root and intermediate certificates will be seen by the connection setup when they have been added to the authorities section. The same is true for trusting self-signed certificates. On top of this, IPsec now supports public key authentication as contributed by Pascal Mathis.</p>
</blockquote>

<hr>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2019-11-09/hardenedbsd-status-report" target="_blank" rel="nofollow noopener">HardenedBSD November 2019 Status Report.</a></h3>

<blockquote>
<p>We at HardenedBSD have a lot of news to share. On 05 Nov 2019, Oliver Pinter resigned amicably from the project. All of us at HardenedBSD owe Oliver our gratitude and appreciation. This humble project, named by Oliver, was born out of his thesis work and the collaboration with Shawn Webb. Oliver created the HardenedBSD repo on GitHub in April 2013. The HardenedBSD Foundation was formed five years later to carry on this great work. </p>
</blockquote>

<hr>

<h3><a href="https://undeadly.org/cgi?action=article;sid=20191110123908" target="_blank" rel="nofollow noopener">DNSSEC enabled in default unbound(8) configuration.</a></h3>

<blockquote>
<p>DNSSEC validation has been enabled in the default unbound.conf(5) in -current. The relevant commits were from Job Snijders (job@)</p>
</blockquote>

<hr>

<h3><a href="https://www.howtoforge.com/how-to-install-shopware-with-nginx-and-lets-encrypt-on-freebsd-12/" target="_blank" rel="nofollow noopener">How to Install Shopware with NGINX and Let's Encrypt on FreeBSD 12</a></h3>

<blockquote>
<p>Shopware is the next generation of open source e-commerce software. Based on bleeding edge technologies like Symfony 3, Doctrine2 and Zend Framework Shopware comes as the perfect platform for your next e-commerce project. This tutorial will walk you through the Shopware Community Edition (CE) installation on FreeBSD 12 system by using NGINX as a web server.</p>
</blockquote>

<ul>
<li>Requirements</li>
</ul>

<blockquote>
<p>Make sure your system meets the following minimum requirements:</p>

<ul>
<li>Linux-based operating system with NGINX or Apache 2.x (with mod_rewrite) web server installed. </li>
<li>PHP 5.6.4 or higher with ctype, gd, curl, dom, hash, iconv, zip, json, mbstring, openssl, session, simplexml, xml, zlib, fileinfo, and pdo/mysql extensions. PHP 7.1 or above is strongly recommended.</li>
<li>MySQL 5.5.0 or higher.</li>
<li>Possibility to set up cron jobs.</li>
<li>Minimum 4 GB available hard disk space.</li>
<li>IonCube Loader version 5.0.0 or higher (optional).</li>
</ul>
</blockquote>

<hr>

<h3><a href="https://cromwell-intl.com/open-source/compiling-rainbowcrack-on-openbsd.html" target="_blank" rel="nofollow noopener">How to Compile RainbowCrack on OpenBSD</a></h3>

<blockquote>
<p>Project RainbowCrack was originally Zhu Shuanglei's implementation, it's not clear to me if the project is still just his or if it's even been maintained for a while. His page seems to have been last updated in August 2007.</p>

<p>The Project RainbowCrack web page now has just binaries for Windows XP and Linux, both 32-bit and 64-bit versions.</p>

<p>Earlier versions were available as source code. The version 1.2 source code does not compile on OpenBSD, and in my experience it doesn't compile on Linux, either. It seems to date from 2004 at the earliest, and I think it makes some version-2.4 assumptions about Linux kernel headers.</p>
</blockquote>

<ul>
<li>You might also look at ophcrack, a more modern tool, although it seems to be focused on cracking Windows XP/Vista/7/8/10 password hashes</li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Reese - <a href="http://dpaste.com/2RDG9K4#wrap" target="_blank" rel="nofollow noopener">Amature radio info</a></li>
<li>Chris - <a href="http://dpaste.com/2K4T2FQ#wrap" target="_blank" rel="nofollow noopener">VPN</a></li>
<li>Malcolm - <a href="http://dpaste.com/138NEMA" target="_blank" rel="nofollow noopener">NAT</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0325.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>FreeBSD 12.1 is here, A history of Unix before Berkeley, FreeBSD development setup, HardenedBSD 2019 Status Report, DNSSEC, compiling RainbowCrack on OpenBSD, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/12.1R/announce.html" target="_blank" rel="nofollow noopener">FreeBSD 12.1</a></h3>

<ul>
<li><p>Some of the highlights:</p>

<ul>
<li>BearSSL has been imported to the base system.</li>
<li>The clang, llvm, lld, lldb, compiler-rt utilities and libc++ have been updated to version 8.0.1.</li>
<li>OpenSSL has been updated to version 1.1.1d.</li>
<li>Several userland utility updates.</li>
</ul></li>
<li><p>For a complete list of new features and known problems, please see the online release notes and errata list, available at: <a href="https://www.FreeBSD.org/releases/12.1R/relnotes.html" target="_blank" rel="nofollow noopener">https://www.FreeBSD.org/releases/12.1R/relnotes.html</a></p></li>
</ul>

<hr>

<h3><a href="http://www.darwinsys.com/history/hist.html" target="_blank" rel="nofollow noopener">A History of UNIX before Berkeley: UNIX Evolution: 1975-1984.</a></h3>

<blockquote>
<p>Nobody needs to be told that UNIX is popular today. In this article we will show you a little of where it was yesterday and over the past decade. And, without meaning in the least to minimise the incredible contributions of Ken Thompson and Dennis Ritchie, we will bring to light many of the others who worked on early versions, and try to show where some of the key ideas came from, and how they got into the UNIX of today.</p>

<p>Our title says we are talking about UNIX evolution. Evolution means different things to different people. We use the term loosely, to describe the change over time among the many different UNIX variants in use both inside and outside Bell Labs. Ideas, code, and useful programs seem to have made their way back and forth - like mutant genes - among all the many UNIXes living in the phone company over the decade in question.</p>

<p>Part One looks at some of the major components of the current UNIX system - the text formatting tools, the compilers and program development tools, and so on. Most of the work described in Part One took place at <code>Research'', a part of Bell Laboratories (now AT&amp;T Bell Laboratories, then as now</code>the Labs''), and the ancestral home of UNIX. In planned (but not written) later parts, we would have looked at some of the myriad versions of UNIX - there are far more than one might suspect. This includes a look at Columbus and USG and at Berkeley Unix. You'll begin to get a glimpse inside the history of the major streams of development of the system during that time.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://adventurist.me/posts/00296" target="_blank" rel="nofollow noopener">My FreeBSD Development Setup</a></h3>

<blockquote>
<p>I do my FreeBSD development using git, tmux, vim and cscope.</p>

<p>I keep a FreeBSD fork on my github, I have forked <a href="https://github.com/freebsd/freebsd" target="_blank" rel="nofollow noopener">https://github.com/freebsd/freebsd</a> to <a href="https://github.com/adventureloop/freebsd" target="_blank" rel="nofollow noopener">https://github.com/adventureloop/freebsd</a></p>
</blockquote>

<hr>

<h3><a href="https://opnsense.org/opnsense-19-7-6-released/" target="_blank" rel="nofollow noopener">OPNsense 19.7.6 released</a></h3>

<blockquote>
<p>As we are experiencing the Suricata community first hand in Amsterdam we thought to release this version a bit earlier than planned. Included is the latest Suricata 5.0.0 release in the development version. That means later this November we will releasing version 5 to the production version as we finish up tweaking the integration and maybe pick up 5.0.1 as it becomes available.</p>

<p>LDAP TLS connectivity is now integrated into the system trust store, which ensures that all required root and intermediate certificates will be seen by the connection setup when they have been added to the authorities section. The same is true for trusting self-signed certificates. On top of this, IPsec now supports public key authentication as contributed by Pascal Mathis.</p>
</blockquote>

<hr>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2019-11-09/hardenedbsd-status-report" target="_blank" rel="nofollow noopener">HardenedBSD November 2019 Status Report.</a></h3>

<blockquote>
<p>We at HardenedBSD have a lot of news to share. On 05 Nov 2019, Oliver Pinter resigned amicably from the project. All of us at HardenedBSD owe Oliver our gratitude and appreciation. This humble project, named by Oliver, was born out of his thesis work and the collaboration with Shawn Webb. Oliver created the HardenedBSD repo on GitHub in April 2013. The HardenedBSD Foundation was formed five years later to carry on this great work. </p>
</blockquote>

<hr>

<h3><a href="https://undeadly.org/cgi?action=article;sid=20191110123908" target="_blank" rel="nofollow noopener">DNSSEC enabled in default unbound(8) configuration.</a></h3>

<blockquote>
<p>DNSSEC validation has been enabled in the default unbound.conf(5) in -current. The relevant commits were from Job Snijders (job@)</p>
</blockquote>

<hr>

<h3><a href="https://www.howtoforge.com/how-to-install-shopware-with-nginx-and-lets-encrypt-on-freebsd-12/" target="_blank" rel="nofollow noopener">How to Install Shopware with NGINX and Let's Encrypt on FreeBSD 12</a></h3>

<blockquote>
<p>Shopware is the next generation of open source e-commerce software. Based on bleeding edge technologies like Symfony 3, Doctrine2 and Zend Framework Shopware comes as the perfect platform for your next e-commerce project. This tutorial will walk you through the Shopware Community Edition (CE) installation on FreeBSD 12 system by using NGINX as a web server.</p>
</blockquote>

<ul>
<li>Requirements</li>
</ul>

<blockquote>
<p>Make sure your system meets the following minimum requirements:</p>

<ul>
<li>Linux-based operating system with NGINX or Apache 2.x (with mod_rewrite) web server installed. </li>
<li>PHP 5.6.4 or higher with ctype, gd, curl, dom, hash, iconv, zip, json, mbstring, openssl, session, simplexml, xml, zlib, fileinfo, and pdo/mysql extensions. PHP 7.1 or above is strongly recommended.</li>
<li>MySQL 5.5.0 or higher.</li>
<li>Possibility to set up cron jobs.</li>
<li>Minimum 4 GB available hard disk space.</li>
<li>IonCube Loader version 5.0.0 or higher (optional).</li>
</ul>
</blockquote>

<hr>

<h3><a href="https://cromwell-intl.com/open-source/compiling-rainbowcrack-on-openbsd.html" target="_blank" rel="nofollow noopener">How to Compile RainbowCrack on OpenBSD</a></h3>

<blockquote>
<p>Project RainbowCrack was originally Zhu Shuanglei's implementation, it's not clear to me if the project is still just his or if it's even been maintained for a while. His page seems to have been last updated in August 2007.</p>

<p>The Project RainbowCrack web page now has just binaries for Windows XP and Linux, both 32-bit and 64-bit versions.</p>

<p>Earlier versions were available as source code. The version 1.2 source code does not compile on OpenBSD, and in my experience it doesn't compile on Linux, either. It seems to date from 2004 at the earliest, and I think it makes some version-2.4 assumptions about Linux kernel headers.</p>
</blockquote>

<ul>
<li>You might also look at ophcrack, a more modern tool, although it seems to be focused on cracking Windows XP/Vista/7/8/10 password hashes</li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Reese - <a href="http://dpaste.com/2RDG9K4#wrap" target="_blank" rel="nofollow noopener">Amature radio info</a></li>
<li>Chris - <a href="http://dpaste.com/2K4T2FQ#wrap" target="_blank" rel="nofollow noopener">VPN</a></li>
<li>Malcolm - <a href="http://dpaste.com/138NEMA" target="_blank" rel="nofollow noopener">NAT</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0325.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </itunes:summary>
</item>
<item>
  <title>323: OSI Burrito Guy</title>
  <link>https://www.bsdnow.tv/323</link>
  <guid isPermaLink="false">cf54c1fe-70ba-49a3-9b13-1ceb64ab896a</guid>
  <pubDate>Thu, 07 Nov 2019 07:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/cf54c1fe-70ba-49a3-9b13-1ceb64ab896a.mp3" length="35547347" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>The earliest Unix code, how to replace fail2ban with blacklistd, OpenBSD crossed 400k commits, how to install Bolt CMS on FreeBSD, optimized hammer2, appeasing the OSI 7-layer burrito guys, and more.</itunes:subtitle>
  <itunes:duration>49:22</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;The earliest Unix code, how to replace fail2ban with blacklistd, OpenBSD crossed 400k commits, how to install Bolt CMS on FreeBSD, optimized hammer2, appeasing the OSI 7-layer burrito guys, and more.&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://computerhistory.org/blog/the-earliest-unix-code-an-anniversary-source-code-release/" target="_blank" rel="nofollow noopener"&gt;The Earliest Unix Code: An Anniversary Source Code Release&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;What is it that runs the servers that hold our online world, be it the web or the cloud? What enables the mobile apps that are at the center of increasingly on-demand lives in the developed world and of mobile banking and messaging in the developing world? The answer is the operating system Unix and its many descendants: Linux, Android, BSD Unix, MacOS, iOS—the list goes on and on. Want to glimpse the Unix in your Mac? Open a Terminal window and enter “man roff” to view the Unix manual entry for an early text formatting program that lives within your operating system.&lt;/p&gt;

&lt;p&gt;2019 marks the 50th anniversary of the start of Unix. In the summer of 1969, that same summer that saw humankind’s first steps on the surface of the Moon, computer scientists at the Bell Telephone Laboratories—most centrally Ken Thompson and Dennis Ritchie—began the construction of a new operating system, using a then-aging DEC PDP-7 computer at the labs.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.cbc.ca/radio/thecurrent/the-current-for-oct-29-2019-1.5339212/this-man-sent-the-first-online-message-50-years-ago-he-s-since-seen-the-web-s-dark-side-emerge-1.5339244" target="_blank" rel="nofollow noopener"&gt;This man sent the first online message 50 years ago&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As many of you have heard in the past, the first online message ever sent between two computers was "lo", just over 50 years ago, on Oct. 29, 1969. &lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;It was supposed to say "log," but the computer sending the message — based at UCLA — crashed before the letter "g" was typed. A computer at Stanford 560 kilometres away was supposed to fill in the remaining characters "in," as in "log in."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;The CBC Radio show, “The Current” has a half-hour interview with the man who sent that message, Leonard Kleinrock, distinguished professor of computer science at UCLA&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;"The idea of the network was you could sit at one computer, log on through the network to a remote computer and use its services there,"&lt;/p&gt;

&lt;p&gt;50 years later, the internet has become so ubiquitous that it has almost been rendered invisible. There's hardly an aspect in our daily lives that hasn't been touched and transformed by it.&lt;/p&gt;

&lt;p&gt;Q: Take us back to that day 50 years ago. Did you have the sense that this was going to be something you'd be talking about a half a century later?&lt;/p&gt;

&lt;p&gt;A: Well, yes and no. Four months before that message was sent, there was a press release that came out of UCLA in which it quotes me as describing what my vision for this network would become. Basically what it said is that this network would be always on, always available. Anybody with any device could get on at anytime from any location, and it would be invisible.&lt;/p&gt;

&lt;p&gt;Well, what I missed ... was that this is going to become a social network. People talking to people. Not computers talking to computers, but [the] human element.&lt;/p&gt;

&lt;p&gt;Q: Can you briefly explain what you were working on in that lab? Why were you trying to get computers to actually talk to one another?&lt;/p&gt;

&lt;p&gt;A: As an MIT graduate student, years before, I recognized I was surrounded by computers and I realized there was no effective [or efficient] way for them to communicate. I did my dissertation, my research, on establishing a mathematical theory of how these networks would work. But there was no such network existing. AT&amp;amp;T said it won't work and, even if it does, we want nothing to do with it.&lt;/p&gt;

&lt;p&gt;So I had to wait around for years until the Advanced Research Projects Agency within the Department of Defence decided they needed a network to connect together the computer scientists they were supervising and supporting.&lt;/p&gt;

&lt;p&gt;Q: For all the promise of the internet, it has also developed some dark sides that I'm guessing pioneers like yourselves never anticipated.&lt;/p&gt;

&lt;p&gt;A: We did not. I knew everybody on the internet at that time, and they were all well-behaved and they all believed in an open, shared free network. So we did not put in any security controls.&lt;/p&gt;

&lt;p&gt;When the first spam email occurred, we began to see the dark side emerge as this network reached nefarious people sitting in basements with a high-speed connection, reaching out to millions of people instantaneously, at no cost in time or money, anonymously until all sorts of unpleasant events occurred, which we called the dark side.&lt;/p&gt;

&lt;p&gt;But in those early days, I considered the network to be going through its teenage years. Hacking to spam, annoying kinds of effects. I thought that one day this network would mature and grow up. Well, in fact, it took a turn for the worse when nation states, organized crime and extremists came in and began to abuse the network in severe ways.&lt;/p&gt;

&lt;p&gt;Q: Is there any part of you that regrets giving birth to this?&lt;/p&gt;

&lt;p&gt;A: Absolutely not. The greater good is much more important.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.unitedbsd.com/d/63-how-to-use-blacklistd8-with-npf-as-a-fail2ban-replacement" target="_blank" rel="nofollow noopener"&gt;How to use blacklistd(8) with NPF as a fail2ban replacement&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;blacklistd(8) provides an API that can be used by network daemons to communicate with a packet filter via a daemon to enforce opening and closing ports dynamically based on policy.&lt;/p&gt;

&lt;p&gt;The interface to the packet filter is in /libexec/blacklistd-helper (this is currently designed for npf) and the configuration file (inspired from inetd.conf) is in etc/blacklistd.conf&lt;/p&gt;

&lt;p&gt;Now, blacklistd(8) will require bpfjit(4) (Just-In-Time compiler for Berkeley Packet Filter) in order to properly work, in addition to, naturally, npf(7) as frontend and syslogd(8), as a backend to print diagnostic messages. Also remember npf shall rely on the npflog* virtual network interface to provide logging for tcpdump() to use.&lt;/p&gt;

&lt;p&gt;Unfortunately (dont' ask me why ??) in 8.1 all the required kernel components are still not compiled by default in the GENERIC kernel (though they are in HEAD), and are rather provided as modules. Enabling NPF and blacklistd services would normally result in them being automatically loaded as root, but predictably on securelevel=1 this is not going to happen.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls-blacklistd.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD’s handbook chapter on blacklistd&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://marc.info/?l=openbsd-tech&amp;amp;m=157059352620659&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;OpenBSD crossed 400,000 commits&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Sometime in the last week OpenBSD crossed 400,000 commits (*) upon all our repositories since starting at 1995/10/18 08:37:01 Canada/Mountain. That's a lot of commits by a lot of amazing people.&lt;/p&gt;

&lt;p&gt;(*) by one measure.  Since the repository is so large and old, there are a variety of quirks including ChangeLog missing entries and branches not convertible to other repo forms, so measuring is hard.  If you think you've got a great way of measuring, don't be so sure of yourself -- you may have overcounted or undercounted.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Subject to the notes Theo made about under and over counting, FreeBSD should hit 1 million commits (base + ports + docs) some time in 2020&lt;/li&gt;
&lt;li&gt;NetBSD + pkgsrc are approaching 600,000, but of course pkgsrc covers other operating systems too&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.howtoforge.com/how-to-install-bolt-cms-nginx-ssl-on-freebsd-12/" target="_blank" rel="nofollow noopener"&gt;How to Install Bolt CMS with Nginx and Let's Encrypt on FreeBSD 12&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Bolt is a sophisticated, lightweight and simple CMS built with PHP. It is released under the open-source MIT-license and source code is hosted as a public repository on Github. A bolt is a tool for Content Management, which strives to be as simple and straightforward as possible. It is quick to set up, easy to configure, uses elegant templates. Bolt is created using modern open-source libraries and is best suited to build sites in HTML5 with modern markup. In this tutorial, we will go through the Bolt CMS installation on FreeBSD 12 system by using Nginx as a web server, MySQL as a database server, and optionally you can secure the transport layer by using acme.sh client and Let's Encrypt certificate authority to add SSL support.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Requirements&lt;/li&gt;
&lt;li&gt;The system requirements for Bolt are modest, and it should run on any fairly modern web server:

&lt;ul&gt;
&lt;li&gt;PHP version 5.5.9 or higher with the following common PHP extensions: pdo, mysqlnd, pgsql, openssl, curl, gd, intl, json, mbstring, opcache, posix, xml, fileinfo, exif, zip.&lt;/li&gt;
&lt;li&gt;Access to SQLite (which comes bundled with PHP), or MySQL or PostgreSQL.&lt;/li&gt;
&lt;li&gt;Apache with mod_rewrite enabled (.htaccess files) or Nginx (virtual host configuration covered below).&lt;/li&gt;
&lt;li&gt;A minimum of 32MB of memory allocated to PHP.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2019-September/719632.html" target="_blank" rel="nofollow noopener"&gt;hammer2 - Optimize hammer2 support threads and dispatch&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Refactor the XOP groups in order to be able to queue strategy calls, whenever possible, to the same CPU as the issuer.  This optimizes several cases and reduces unnecessary IPI traffic between cores.  The next best thing to do would be to not queue certain XOPs to an H2 support thread at all, but I would like to keep the threads intact for later clustering work.&lt;br&gt;&lt;br&gt;
The best scaling case for this is when one has a large number of user threads doing I/O.  One instance of a single-threaded program on an otherwise idle machine might see a slightly reduction in performance but at the same time we completely avoid unnecessarily spamming all cores in the system on the behalf of a single program, so overhead is also significantly lower.&lt;/p&gt;

&lt;p&gt;This will tend to increase the number of H2 support threads since we need a certain degree of multiplication for domain separation.&lt;/p&gt;

&lt;p&gt;This should significantly increase I/O performance for multi-threaded workloads.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="http://boston.conman.org/2019/10/17.1" target="_blank" rel="nofollow noopener"&gt;You know, we might as well just run every network service over HTTPS/2 and build another six layers on top of that to appease the OSI 7-layer burrito guys&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;I've seen the writing on the wall, and while for now you can configure Firefox not to use DoH, I'm not confident enough to think it will remain that way. To that end, I've finally set up my own DoH server for use at Chez Boca. It only involved setting up my own CA to generate the appropriate certificates, install my CA certificate into Firefox, configure Apache to run over HTTP/2 (THANK YOU SO VERY XXXXX­XX MUCH GOOGLE FOR SHOVING THIS HTTP/2 XXXXX­XXX DOWN OUR THROATS!—no, I'm not bitter) and write a 150 line script that just queries my own local DNS, because, you know, it's more XXXXX­XX secure or some XXXXX­XXX reason like that.&lt;/p&gt;

&lt;p&gt;Sigh.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.princeton.edu/%7Ehos/Mahoney/unixhistory" target="_blank" rel="nofollow noopener"&gt;An Oral History of Unix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://people.freebsd.org/%7Egallatin/talks/euro2019.pdf" target="_blank" rel="nofollow noopener"&gt;NUMA Siloing in the FreeBSD Network Stack [pdf]&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/playlist?list=PLskKNopggjc6NssLc8GEGSiFYJLYdlTQx" target="_blank" rel="nofollow noopener"&gt;EuroBSDCon 2019 videos available&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/eksffa/status/1188638425567682560" target="_blank" rel="nofollow noopener"&gt;Barbie knows best&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/bob_beck/status/1188226661684301824" target="_blank" rel="nofollow noopener"&gt;For the #OpenBSD #e2k19 attendees.  I did a pre visit today.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/pasha_sh/status/1187877745499561985" target="_blank" rel="nofollow noopener"&gt;Drawer Find&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.openbsd.org/papers/asiabsdcon2019-rop-slides.pdf" target="_blank" rel="nofollow noopener"&gt;Slides - Removing ROP Gadgets from OpenBSD - AsiaBSDCon 2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Bostjan - &lt;a href="http://dpaste.com/1M5MVCX#wrap" target="_blank" rel="nofollow noopener"&gt;Open source doesn't mean secure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Malcolm - &lt;a href="http://dpaste.com/2RFNR94" target="_blank" rel="nofollow noopener"&gt;Allan is Correct.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Michael - &lt;a href="http://dpaste.com/28YW3BB#wrap" target="_blank" rel="nofollow noopener"&gt;FreeNAS inside a Jail&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;


    &lt;source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0323.mp4" type="video/mp4"&gt;
    Your browser does not support the HTML5 video tag.
 
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, interview, Unix, code, blacklistd, fail2ban, npf, bolt, cms, nginx, lets encrypt, hammer2, OSI, 7 layer, https2 </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The earliest Unix code, how to replace fail2ban with blacklistd, OpenBSD crossed 400k commits, how to install Bolt CMS on FreeBSD, optimized hammer2, appeasing the OSI 7-layer burrito guys, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://computerhistory.org/blog/the-earliest-unix-code-an-anniversary-source-code-release/" target="_blank" rel="nofollow noopener">The Earliest Unix Code: An Anniversary Source Code Release</a></h3>

<blockquote>
<p>What is it that runs the servers that hold our online world, be it the web or the cloud? What enables the mobile apps that are at the center of increasingly on-demand lives in the developed world and of mobile banking and messaging in the developing world? The answer is the operating system Unix and its many descendants: Linux, Android, BSD Unix, MacOS, iOS—the list goes on and on. Want to glimpse the Unix in your Mac? Open a Terminal window and enter “man roff” to view the Unix manual entry for an early text formatting program that lives within your operating system.</p>

<p>2019 marks the 50th anniversary of the start of Unix. In the summer of 1969, that same summer that saw humankind’s first steps on the surface of the Moon, computer scientists at the Bell Telephone Laboratories—most centrally Ken Thompson and Dennis Ritchie—began the construction of a new operating system, using a then-aging DEC PDP-7 computer at the labs.</p>
</blockquote>

<hr>

<h3><a href="https://www.cbc.ca/radio/thecurrent/the-current-for-oct-29-2019-1.5339212/this-man-sent-the-first-online-message-50-years-ago-he-s-since-seen-the-web-s-dark-side-emerge-1.5339244" target="_blank" rel="nofollow noopener">This man sent the first online message 50 years ago</a></h3>

<ul>
<li>As many of you have heard in the past, the first online message ever sent between two computers was "lo", just over 50 years ago, on Oct. 29, 1969. </li>
</ul>

<blockquote>
<p>It was supposed to say "log," but the computer sending the message — based at UCLA — crashed before the letter "g" was typed. A computer at Stanford 560 kilometres away was supposed to fill in the remaining characters "in," as in "log in."</p>
</blockquote>

<ul>
<li>The CBC Radio show, “The Current” has a half-hour interview with the man who sent that message, Leonard Kleinrock, distinguished professor of computer science at UCLA</li>
</ul>

<blockquote>
<p>"The idea of the network was you could sit at one computer, log on through the network to a remote computer and use its services there,"</p>

<p>50 years later, the internet has become so ubiquitous that it has almost been rendered invisible. There's hardly an aspect in our daily lives that hasn't been touched and transformed by it.</p>

<p>Q: Take us back to that day 50 years ago. Did you have the sense that this was going to be something you'd be talking about a half a century later?</p>

<p>A: Well, yes and no. Four months before that message was sent, there was a press release that came out of UCLA in which it quotes me as describing what my vision for this network would become. Basically what it said is that this network would be always on, always available. Anybody with any device could get on at anytime from any location, and it would be invisible.</p>

<p>Well, what I missed ... was that this is going to become a social network. People talking to people. Not computers talking to computers, but [the] human element.</p>

<p>Q: Can you briefly explain what you were working on in that lab? Why were you trying to get computers to actually talk to one another?</p>

<p>A: As an MIT graduate student, years before, I recognized I was surrounded by computers and I realized there was no effective [or efficient] way for them to communicate. I did my dissertation, my research, on establishing a mathematical theory of how these networks would work. But there was no such network existing. AT&amp;T said it won't work and, even if it does, we want nothing to do with it.</p>

<p>So I had to wait around for years until the Advanced Research Projects Agency within the Department of Defence decided they needed a network to connect together the computer scientists they were supervising and supporting.</p>

<p>Q: For all the promise of the internet, it has also developed some dark sides that I'm guessing pioneers like yourselves never anticipated.</p>

<p>A: We did not. I knew everybody on the internet at that time, and they were all well-behaved and they all believed in an open, shared free network. So we did not put in any security controls.</p>

<p>When the first spam email occurred, we began to see the dark side emerge as this network reached nefarious people sitting in basements with a high-speed connection, reaching out to millions of people instantaneously, at no cost in time or money, anonymously until all sorts of unpleasant events occurred, which we called the dark side.</p>

<p>But in those early days, I considered the network to be going through its teenage years. Hacking to spam, annoying kinds of effects. I thought that one day this network would mature and grow up. Well, in fact, it took a turn for the worse when nation states, organized crime and extremists came in and began to abuse the network in severe ways.</p>

<p>Q: Is there any part of you that regrets giving birth to this?</p>

<p>A: Absolutely not. The greater good is much more important.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.unitedbsd.com/d/63-how-to-use-blacklistd8-with-npf-as-a-fail2ban-replacement" target="_blank" rel="nofollow noopener">How to use blacklistd(8) with NPF as a fail2ban replacement</a></h3>

<blockquote>
<p>blacklistd(8) provides an API that can be used by network daemons to communicate with a packet filter via a daemon to enforce opening and closing ports dynamically based on policy.</p>

<p>The interface to the packet filter is in /libexec/blacklistd-helper (this is currently designed for npf) and the configuration file (inspired from inetd.conf) is in etc/blacklistd.conf</p>

<p>Now, blacklistd(8) will require bpfjit(4) (Just-In-Time compiler for Berkeley Packet Filter) in order to properly work, in addition to, naturally, npf(7) as frontend and syslogd(8), as a backend to print diagnostic messages. Also remember npf shall rely on the npflog* virtual network interface to provide logging for tcpdump() to use.</p>

<p>Unfortunately (dont' ask me why ??) in 8.1 all the required kernel components are still not compiled by default in the GENERIC kernel (though they are in HEAD), and are rather provided as modules. Enabling NPF and blacklistd services would normally result in them being automatically loaded as root, but predictably on securelevel=1 this is not going to happen.</p>
</blockquote>

<ul>
<li><a href="https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls-blacklistd.html" target="_blank" rel="nofollow noopener">FreeBSD’s handbook chapter on blacklistd</a></li>
</ul>

<hr>

<h3><a href="https://marc.info/?l=openbsd-tech&amp;m=157059352620659&amp;w=2" target="_blank" rel="nofollow noopener">OpenBSD crossed 400,000 commits</a></h3>

<blockquote>
<p>Sometime in the last week OpenBSD crossed 400,000 commits (*) upon all our repositories since starting at 1995/10/18 08:37:01 Canada/Mountain. That's a lot of commits by a lot of amazing people.</p>

<p>(*) by one measure.  Since the repository is so large and old, there are a variety of quirks including ChangeLog missing entries and branches not convertible to other repo forms, so measuring is hard.  If you think you've got a great way of measuring, don't be so sure of yourself -- you may have overcounted or undercounted.</p>
</blockquote>

<ul>
<li>Subject to the notes Theo made about under and over counting, FreeBSD should hit 1 million commits (base + ports + docs) some time in 2020</li>
<li>NetBSD + pkgsrc are approaching 600,000, but of course pkgsrc covers other operating systems too</li>
</ul>

<hr>

<h3><a href="https://www.howtoforge.com/how-to-install-bolt-cms-nginx-ssl-on-freebsd-12/" target="_blank" rel="nofollow noopener">How to Install Bolt CMS with Nginx and Let's Encrypt on FreeBSD 12</a></h3>

<blockquote>
<p>Bolt is a sophisticated, lightweight and simple CMS built with PHP. It is released under the open-source MIT-license and source code is hosted as a public repository on Github. A bolt is a tool for Content Management, which strives to be as simple and straightforward as possible. It is quick to set up, easy to configure, uses elegant templates. Bolt is created using modern open-source libraries and is best suited to build sites in HTML5 with modern markup. In this tutorial, we will go through the Bolt CMS installation on FreeBSD 12 system by using Nginx as a web server, MySQL as a database server, and optionally you can secure the transport layer by using acme.sh client and Let's Encrypt certificate authority to add SSL support.</p>
</blockquote>

<ul>
<li>Requirements</li>
<li>The system requirements for Bolt are modest, and it should run on any fairly modern web server:

<ul>
<li>PHP version 5.5.9 or higher with the following common PHP extensions: pdo, mysqlnd, pgsql, openssl, curl, gd, intl, json, mbstring, opcache, posix, xml, fileinfo, exif, zip.</li>
<li>Access to SQLite (which comes bundled with PHP), or MySQL or PostgreSQL.</li>
<li>Apache with mod_rewrite enabled (.htaccess files) or Nginx (virtual host configuration covered below).</li>
<li>A minimum of 32MB of memory allocated to PHP.</li>
</ul></li>
</ul>

<hr>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2019-September/719632.html" target="_blank" rel="nofollow noopener">hammer2 - Optimize hammer2 support threads and dispatch</a></h3>

<blockquote>
<p>Refactor the XOP groups in order to be able to queue strategy calls, whenever possible, to the same CPU as the issuer.  This optimizes several cases and reduces unnecessary IPI traffic between cores.  The next best thing to do would be to not queue certain XOPs to an H2 support thread at all, but I would like to keep the threads intact for later clustering work.<br><br>
The best scaling case for this is when one has a large number of user threads doing I/O.  One instance of a single-threaded program on an otherwise idle machine might see a slightly reduction in performance but at the same time we completely avoid unnecessarily spamming all cores in the system on the behalf of a single program, so overhead is also significantly lower.</p>

<p>This will tend to increase the number of H2 support threads since we need a certain degree of multiplication for domain separation.</p>

<p>This should significantly increase I/O performance for multi-threaded workloads.</p>
</blockquote>

<hr>

<h3><a href="http://boston.conman.org/2019/10/17.1" target="_blank" rel="nofollow noopener">You know, we might as well just run every network service over HTTPS/2 and build another six layers on top of that to appease the OSI 7-layer burrito guys</a></h3>

<blockquote>
<p>I've seen the writing on the wall, and while for now you can configure Firefox not to use DoH, I'm not confident enough to think it will remain that way. To that end, I've finally set up my own DoH server for use at Chez Boca. It only involved setting up my own CA to generate the appropriate certificates, install my CA certificate into Firefox, configure Apache to run over HTTP/2 (THANK YOU SO VERY XXXXX­XX MUCH GOOGLE FOR SHOVING THIS HTTP/2 XXXXX­XXX DOWN OUR THROATS!—no, I'm not bitter) and write a 150 line script that just queries my own local DNS, because, you know, it's more XXXXX­XX secure or some XXXXX­XXX reason like that.</p>

<p>Sigh.</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.princeton.edu/%7Ehos/Mahoney/unixhistory" target="_blank" rel="nofollow noopener">An Oral History of Unix</a></li>
<li><a href="https://people.freebsd.org/%7Egallatin/talks/euro2019.pdf" target="_blank" rel="nofollow noopener">NUMA Siloing in the FreeBSD Network Stack [pdf]</a></li>
<li><a href="https://www.youtube.com/playlist?list=PLskKNopggjc6NssLc8GEGSiFYJLYdlTQx" target="_blank" rel="nofollow noopener">EuroBSDCon 2019 videos available</a></li>
<li><a href="https://twitter.com/eksffa/status/1188638425567682560" target="_blank" rel="nofollow noopener">Barbie knows best</a></li>
<li><a href="https://twitter.com/bob_beck/status/1188226661684301824" target="_blank" rel="nofollow noopener">For the #OpenBSD #e2k19 attendees.  I did a pre visit today.</a></li>
<li><a href="https://twitter.com/pasha_sh/status/1187877745499561985" target="_blank" rel="nofollow noopener">Drawer Find</a></li>
<li><a href="https://www.openbsd.org/papers/asiabsdcon2019-rop-slides.pdf" target="_blank" rel="nofollow noopener">Slides - Removing ROP Gadgets from OpenBSD - AsiaBSDCon 2019</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Bostjan - <a href="http://dpaste.com/1M5MVCX#wrap" target="_blank" rel="nofollow noopener">Open source doesn't mean secure</a></li>
<li>Malcolm - <a href="http://dpaste.com/2RFNR94" target="_blank" rel="nofollow noopener">Allan is Correct.</a></li>
<li><p>Michael - <a href="http://dpaste.com/28YW3BB#wrap" target="_blank" rel="nofollow noopener">FreeNAS inside a Jail</a></p>

<hr></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0323.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The earliest Unix code, how to replace fail2ban with blacklistd, OpenBSD crossed 400k commits, how to install Bolt CMS on FreeBSD, optimized hammer2, appeasing the OSI 7-layer burrito guys, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://computerhistory.org/blog/the-earliest-unix-code-an-anniversary-source-code-release/" target="_blank" rel="nofollow noopener">The Earliest Unix Code: An Anniversary Source Code Release</a></h3>

<blockquote>
<p>What is it that runs the servers that hold our online world, be it the web or the cloud? What enables the mobile apps that are at the center of increasingly on-demand lives in the developed world and of mobile banking and messaging in the developing world? The answer is the operating system Unix and its many descendants: Linux, Android, BSD Unix, MacOS, iOS—the list goes on and on. Want to glimpse the Unix in your Mac? Open a Terminal window and enter “man roff” to view the Unix manual entry for an early text formatting program that lives within your operating system.</p>

<p>2019 marks the 50th anniversary of the start of Unix. In the summer of 1969, that same summer that saw humankind’s first steps on the surface of the Moon, computer scientists at the Bell Telephone Laboratories—most centrally Ken Thompson and Dennis Ritchie—began the construction of a new operating system, using a then-aging DEC PDP-7 computer at the labs.</p>
</blockquote>

<hr>

<h3><a href="https://www.cbc.ca/radio/thecurrent/the-current-for-oct-29-2019-1.5339212/this-man-sent-the-first-online-message-50-years-ago-he-s-since-seen-the-web-s-dark-side-emerge-1.5339244" target="_blank" rel="nofollow noopener">This man sent the first online message 50 years ago</a></h3>

<ul>
<li>As many of you have heard in the past, the first online message ever sent between two computers was "lo", just over 50 years ago, on Oct. 29, 1969. </li>
</ul>

<blockquote>
<p>It was supposed to say "log," but the computer sending the message — based at UCLA — crashed before the letter "g" was typed. A computer at Stanford 560 kilometres away was supposed to fill in the remaining characters "in," as in "log in."</p>
</blockquote>

<ul>
<li>The CBC Radio show, “The Current” has a half-hour interview with the man who sent that message, Leonard Kleinrock, distinguished professor of computer science at UCLA</li>
</ul>

<blockquote>
<p>"The idea of the network was you could sit at one computer, log on through the network to a remote computer and use its services there,"</p>

<p>50 years later, the internet has become so ubiquitous that it has almost been rendered invisible. There's hardly an aspect in our daily lives that hasn't been touched and transformed by it.</p>

<p>Q: Take us back to that day 50 years ago. Did you have the sense that this was going to be something you'd be talking about a half a century later?</p>

<p>A: Well, yes and no. Four months before that message was sent, there was a press release that came out of UCLA in which it quotes me as describing what my vision for this network would become. Basically what it said is that this network would be always on, always available. Anybody with any device could get on at anytime from any location, and it would be invisible.</p>

<p>Well, what I missed ... was that this is going to become a social network. People talking to people. Not computers talking to computers, but [the] human element.</p>

<p>Q: Can you briefly explain what you were working on in that lab? Why were you trying to get computers to actually talk to one another?</p>

<p>A: As an MIT graduate student, years before, I recognized I was surrounded by computers and I realized there was no effective [or efficient] way for them to communicate. I did my dissertation, my research, on establishing a mathematical theory of how these networks would work. But there was no such network existing. AT&amp;T said it won't work and, even if it does, we want nothing to do with it.</p>

<p>So I had to wait around for years until the Advanced Research Projects Agency within the Department of Defence decided they needed a network to connect together the computer scientists they were supervising and supporting.</p>

<p>Q: For all the promise of the internet, it has also developed some dark sides that I'm guessing pioneers like yourselves never anticipated.</p>

<p>A: We did not. I knew everybody on the internet at that time, and they were all well-behaved and they all believed in an open, shared free network. So we did not put in any security controls.</p>

<p>When the first spam email occurred, we began to see the dark side emerge as this network reached nefarious people sitting in basements with a high-speed connection, reaching out to millions of people instantaneously, at no cost in time or money, anonymously until all sorts of unpleasant events occurred, which we called the dark side.</p>

<p>But in those early days, I considered the network to be going through its teenage years. Hacking to spam, annoying kinds of effects. I thought that one day this network would mature and grow up. Well, in fact, it took a turn for the worse when nation states, organized crime and extremists came in and began to abuse the network in severe ways.</p>

<p>Q: Is there any part of you that regrets giving birth to this?</p>

<p>A: Absolutely not. The greater good is much more important.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.unitedbsd.com/d/63-how-to-use-blacklistd8-with-npf-as-a-fail2ban-replacement" target="_blank" rel="nofollow noopener">How to use blacklistd(8) with NPF as a fail2ban replacement</a></h3>

<blockquote>
<p>blacklistd(8) provides an API that can be used by network daemons to communicate with a packet filter via a daemon to enforce opening and closing ports dynamically based on policy.</p>

<p>The interface to the packet filter is in /libexec/blacklistd-helper (this is currently designed for npf) and the configuration file (inspired from inetd.conf) is in etc/blacklistd.conf</p>

<p>Now, blacklistd(8) will require bpfjit(4) (Just-In-Time compiler for Berkeley Packet Filter) in order to properly work, in addition to, naturally, npf(7) as frontend and syslogd(8), as a backend to print diagnostic messages. Also remember npf shall rely on the npflog* virtual network interface to provide logging for tcpdump() to use.</p>

<p>Unfortunately (dont' ask me why ??) in 8.1 all the required kernel components are still not compiled by default in the GENERIC kernel (though they are in HEAD), and are rather provided as modules. Enabling NPF and blacklistd services would normally result in them being automatically loaded as root, but predictably on securelevel=1 this is not going to happen.</p>
</blockquote>

<ul>
<li><a href="https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls-blacklistd.html" target="_blank" rel="nofollow noopener">FreeBSD’s handbook chapter on blacklistd</a></li>
</ul>

<hr>

<h3><a href="https://marc.info/?l=openbsd-tech&amp;m=157059352620659&amp;w=2" target="_blank" rel="nofollow noopener">OpenBSD crossed 400,000 commits</a></h3>

<blockquote>
<p>Sometime in the last week OpenBSD crossed 400,000 commits (*) upon all our repositories since starting at 1995/10/18 08:37:01 Canada/Mountain. That's a lot of commits by a lot of amazing people.</p>

<p>(*) by one measure.  Since the repository is so large and old, there are a variety of quirks including ChangeLog missing entries and branches not convertible to other repo forms, so measuring is hard.  If you think you've got a great way of measuring, don't be so sure of yourself -- you may have overcounted or undercounted.</p>
</blockquote>

<ul>
<li>Subject to the notes Theo made about under and over counting, FreeBSD should hit 1 million commits (base + ports + docs) some time in 2020</li>
<li>NetBSD + pkgsrc are approaching 600,000, but of course pkgsrc covers other operating systems too</li>
</ul>

<hr>

<h3><a href="https://www.howtoforge.com/how-to-install-bolt-cms-nginx-ssl-on-freebsd-12/" target="_blank" rel="nofollow noopener">How to Install Bolt CMS with Nginx and Let's Encrypt on FreeBSD 12</a></h3>

<blockquote>
<p>Bolt is a sophisticated, lightweight and simple CMS built with PHP. It is released under the open-source MIT-license and source code is hosted as a public repository on Github. A bolt is a tool for Content Management, which strives to be as simple and straightforward as possible. It is quick to set up, easy to configure, uses elegant templates. Bolt is created using modern open-source libraries and is best suited to build sites in HTML5 with modern markup. In this tutorial, we will go through the Bolt CMS installation on FreeBSD 12 system by using Nginx as a web server, MySQL as a database server, and optionally you can secure the transport layer by using acme.sh client and Let's Encrypt certificate authority to add SSL support.</p>
</blockquote>

<ul>
<li>Requirements</li>
<li>The system requirements for Bolt are modest, and it should run on any fairly modern web server:

<ul>
<li>PHP version 5.5.9 or higher with the following common PHP extensions: pdo, mysqlnd, pgsql, openssl, curl, gd, intl, json, mbstring, opcache, posix, xml, fileinfo, exif, zip.</li>
<li>Access to SQLite (which comes bundled with PHP), or MySQL or PostgreSQL.</li>
<li>Apache with mod_rewrite enabled (.htaccess files) or Nginx (virtual host configuration covered below).</li>
<li>A minimum of 32MB of memory allocated to PHP.</li>
</ul></li>
</ul>

<hr>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2019-September/719632.html" target="_blank" rel="nofollow noopener">hammer2 - Optimize hammer2 support threads and dispatch</a></h3>

<blockquote>
<p>Refactor the XOP groups in order to be able to queue strategy calls, whenever possible, to the same CPU as the issuer.  This optimizes several cases and reduces unnecessary IPI traffic between cores.  The next best thing to do would be to not queue certain XOPs to an H2 support thread at all, but I would like to keep the threads intact for later clustering work.<br><br>
The best scaling case for this is when one has a large number of user threads doing I/O.  One instance of a single-threaded program on an otherwise idle machine might see a slightly reduction in performance but at the same time we completely avoid unnecessarily spamming all cores in the system on the behalf of a single program, so overhead is also significantly lower.</p>

<p>This will tend to increase the number of H2 support threads since we need a certain degree of multiplication for domain separation.</p>

<p>This should significantly increase I/O performance for multi-threaded workloads.</p>
</blockquote>

<hr>

<h3><a href="http://boston.conman.org/2019/10/17.1" target="_blank" rel="nofollow noopener">You know, we might as well just run every network service over HTTPS/2 and build another six layers on top of that to appease the OSI 7-layer burrito guys</a></h3>

<blockquote>
<p>I've seen the writing on the wall, and while for now you can configure Firefox not to use DoH, I'm not confident enough to think it will remain that way. To that end, I've finally set up my own DoH server for use at Chez Boca. It only involved setting up my own CA to generate the appropriate certificates, install my CA certificate into Firefox, configure Apache to run over HTTP/2 (THANK YOU SO VERY XXXXX­XX MUCH GOOGLE FOR SHOVING THIS HTTP/2 XXXXX­XXX DOWN OUR THROATS!—no, I'm not bitter) and write a 150 line script that just queries my own local DNS, because, you know, it's more XXXXX­XX secure or some XXXXX­XXX reason like that.</p>

<p>Sigh.</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.princeton.edu/%7Ehos/Mahoney/unixhistory" target="_blank" rel="nofollow noopener">An Oral History of Unix</a></li>
<li><a href="https://people.freebsd.org/%7Egallatin/talks/euro2019.pdf" target="_blank" rel="nofollow noopener">NUMA Siloing in the FreeBSD Network Stack [pdf]</a></li>
<li><a href="https://www.youtube.com/playlist?list=PLskKNopggjc6NssLc8GEGSiFYJLYdlTQx" target="_blank" rel="nofollow noopener">EuroBSDCon 2019 videos available</a></li>
<li><a href="https://twitter.com/eksffa/status/1188638425567682560" target="_blank" rel="nofollow noopener">Barbie knows best</a></li>
<li><a href="https://twitter.com/bob_beck/status/1188226661684301824" target="_blank" rel="nofollow noopener">For the #OpenBSD #e2k19 attendees.  I did a pre visit today.</a></li>
<li><a href="https://twitter.com/pasha_sh/status/1187877745499561985" target="_blank" rel="nofollow noopener">Drawer Find</a></li>
<li><a href="https://www.openbsd.org/papers/asiabsdcon2019-rop-slides.pdf" target="_blank" rel="nofollow noopener">Slides - Removing ROP Gadgets from OpenBSD - AsiaBSDCon 2019</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Bostjan - <a href="http://dpaste.com/1M5MVCX#wrap" target="_blank" rel="nofollow noopener">Open source doesn't mean secure</a></li>
<li>Malcolm - <a href="http://dpaste.com/2RFNR94" target="_blank" rel="nofollow noopener">Allan is Correct.</a></li>
<li><p>Michael - <a href="http://dpaste.com/28YW3BB#wrap" target="_blank" rel="nofollow noopener">FreeNAS inside a Jail</a></p>

<hr></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0323.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </itunes:summary>
</item>
<item>
  <title>53: It's HAMMER Time</title>
  <link>https://www.bsdnow.tv/53</link>
  <guid isPermaLink="false">ef498915-45f4-4dbb-87fc-4f8e9ee65342</guid>
  <pubDate>Wed, 03 Sep 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/ef498915-45f4-4dbb-87fc-4f8e9ee65342.mp3" length="56493652" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's our one year anniversary episode, and we'll be talking with Reyk Floeter about the new OpenBSD webserver - why it was created and where it's going. After that, we'll show you the ins and outs of DragonFly's HAMMER FS. Answers to viewer-submitted questions and the latest headlines, on a very special BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:18:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's our one year anniversary episode, and we'll be talking with Reyk Floeter about the new OpenBSD webserver - why it was created and where it's going. After that, we'll show you the ins and outs of DragonFly's HAMMER FS. Answers to viewer-submitted questions and the latest headlines, on a very special BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/08/freebsd-foundation-announces-ipsec.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD foundation's new IPSEC project&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation, along with Netgate, is sponsoring some new work on the IPSEC code&lt;/li&gt;
&lt;li&gt;With bandwidth in the 10-40 gigabit per second range, the IPSEC stack needs to be brought up to modern standards in terms of encryption and performance&lt;/li&gt;
&lt;li&gt;This new work will add AES-CTR and AES-GCM modes to FreeBSD's implementation, borrowing some code from OpenBSD&lt;/li&gt;
&lt;li&gt;The updated stack will also support AES-NI for hardware-based encryption speed ups&lt;/li&gt;
&lt;li&gt;It's expected to be completed by the end of September, and will also be in pfSense 2.2
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/31/msg000667.html" target="_blank" rel="nofollow noopener"&gt;NetBSD at Shimane Open Source Conference 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Japanese NetBSD users group held a NetBSD booth at the Open Source Conference 2014 in Shimane on August 23&lt;/li&gt;
&lt;li&gt;One of the developers has gathered a bunch of pictures from the event and wrote a fairly lengthy summary&lt;/li&gt;
&lt;li&gt;They had NetBSD running on all sorts of devices, from Raspberry Pis to Sun Java Stations&lt;/li&gt;
&lt;li&gt;Some visitors said that NetBSD had the most chaotic booth at the conference
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1401" target="_blank" rel="nofollow noopener"&gt;pfSense 2.1.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new version of the pfSense 2.1 branch is out&lt;/li&gt;
&lt;li&gt;Mostly a security-focused release, including three web UI fixes and the most recent OpenSSL fix (which FreeBSD has &lt;a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-August/007875.html" target="_blank" rel="nofollow noopener"&gt;still not patched&lt;/a&gt; in -RELEASE after nearly a month)&lt;/li&gt;
&lt;li&gt;It also includes many other bug fixes, check the blog post for the full list
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://msrvideo.vo.msecnd.net/rmcvideos/227133/dl/227133.mp4" target="_blank" rel="nofollow noopener"&gt;Systems, Science and FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our friend &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener"&gt;George Neville-Neil&lt;/a&gt; gave a presentation at Microsoft Research&lt;/li&gt;
&lt;li&gt;It's mainly about using FreeBSD as a platform for research, inside and outside of universities&lt;/li&gt;
&lt;li&gt;The talk describes the OS and its features, ports, developer community, documentation, who uses BSD and much more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Reyk Floeter - &lt;a href="mailto:reyk@openbsd.org" target="_blank" rel="nofollow noopener"&gt;reyk@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/reykfloeter" target="_blank" rel="nofollow noopener"&gt;@reykfloeter&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's HTTP daemon&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/hammer" target="_blank" rel="nofollow noopener"&gt;A crash course on HAMMER FS&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://brynet.biz.tm/article-rcctl.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD's rcctl tool usage&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD recently &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140820090351" target="_blank" rel="nofollow noopener"&gt;got a new tool&lt;/a&gt; for managing /etc/rc.conf.local in -current&lt;/li&gt;
&lt;li&gt;Similar to FreeBSD's "sysrc" tool, it eliminates the need to manually edit rc.conf.local to enable or disable services&lt;/li&gt;
&lt;li&gt;This blog post - from a BSD Now viewer - shows the typical usage of the new tool to alter the startup services&lt;/li&gt;
&lt;li&gt;It won't make it to 5.6, but will be in 5.7 (next May)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mateh.id.au/2014/08/stream-netflix-chromecast-using-pfsense/" target="_blank" rel="nofollow noopener"&gt;pfSense mini-roundup&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We found five interesting pfSense articles throughout the week and wanted to quickly mention them&lt;/li&gt;
&lt;li&gt;The first item in our pfSense mini-roundup details how you can stream Netflix to in non-US countries using a "smart" DNS service&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://theosquest.com/2014/08/28/ipv6-with-comcast-and-pfsense/" target="_blank" rel="nofollow noopener"&gt;second post&lt;/a&gt; talks about setting ip IPv6, in particular if Comcast is your ISP&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://news.softpedia.com/news/PfSense-2-1-5-Is-Free-and-Powerful-FreeBSD-based-Firewall-Operating-System-457097.shtml" target="_blank" rel="nofollow noopener"&gt;third one&lt;/a&gt; features pfSense on Softpedia, a more mainstream tech site&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://sichent.wordpress.com/2014/02/22/filtering-https-traffic-with-squid-on-pfsense-2-1/" target="_blank" rel="nofollow noopener"&gt;fourth post&lt;/a&gt; describes how to filter HTTPS traffic with Squid and pfSense&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://pfsensesetup.com/vpn-tunneling-with-tinc/" target="_blank" rel="nofollow noopener"&gt;last article&lt;/a&gt; describes setting up a VPN using the "&lt;a href="https://en.wikipedia.org/wiki/Tinc_%28protocol%29" target="_blank" rel="nofollow noopener"&gt;tinc&lt;/a&gt;" daemon and pfSense&lt;/li&gt;
&lt;li&gt;It seems to be lesser known, compared to things like OpenVPN or SSH tunnels, so it's interesting to read about&lt;/li&gt;
&lt;li&gt;This pfSense HQ website seems to have lots of other cool pfSense items, check it out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/2Q-buffer-cache-algorithm" target="_blank" rel="nofollow noopener"&gt;OpenBSD's new buffer cache&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD has traditionally used the tried-and-true LRU algorithm for buffer cache, but it has a few problems&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has just switched to a new algorithm in -current, partially based on 2Q, and details some of his work&lt;/li&gt;
&lt;li&gt;Initial tests show positive results in terms of cache responsiveness&lt;/li&gt;
&lt;li&gt;Check the post for all the fine details
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/08/bsdtalk244-lumina-desktop-environment.html" target="_blank" rel="nofollow noopener"&gt;BSDTalk episode 244&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another new BSDTalk is up and, this time around, &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener"&gt;Will Backman&lt;/a&gt; interviews Ken Moore, the developer of the new BSD desktop environment&lt;/li&gt;
&lt;li&gt;They discuss the history of development, differences between it and other DEs, lots of topics&lt;/li&gt;
&lt;li&gt;If you're more of a visual person, fear not, because...&lt;/li&gt;
&lt;li&gt;We'll have Ken on &lt;em&gt;next week&lt;/em&gt;, including a full "virtual walkthrough" of Lumina and its applications
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21G3KL6lv" target="_blank" rel="nofollow noopener"&gt;Ghislain writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21USZdk2D" target="_blank" rel="nofollow noopener"&gt;Raynold writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2IWAfkDfX" target="_blank" rel="nofollow noopener"&gt;Van writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2OBhezoDV" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s22h9RhXUy" target="_blank" rel="nofollow noopener"&gt;Stefan writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, party, rave, dubstep, hammer, hammerfs, hammer fs, filesystem, zfs, dragonfly, matthew dillon, cluster, lumina, ipsec, rcctl, pfsense, reyk floeter, openhttpd, nginx, apache, webserver</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's our one year anniversary episode, and we'll be talking with Reyk Floeter about the new OpenBSD webserver - why it was created and where it's going. After that, we'll show you the ins and outs of DragonFly's HAMMER FS. Answers to viewer-submitted questions and the latest headlines, on a very special BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/08/freebsd-foundation-announces-ipsec.html" target="_blank" rel="nofollow noopener">FreeBSD foundation's new IPSEC project</a></h3>

<ul>
<li>The FreeBSD foundation, along with Netgate, is sponsoring some new work on the IPSEC code</li>
<li>With bandwidth in the 10-40 gigabit per second range, the IPSEC stack needs to be brought up to modern standards in terms of encryption and performance</li>
<li>This new work will add AES-CTR and AES-GCM modes to FreeBSD's implementation, borrowing some code from OpenBSD</li>
<li>The updated stack will also support AES-NI for hardware-based encryption speed ups</li>
<li>It's expected to be completed by the end of September, and will also be in pfSense 2.2
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/31/msg000667.html" target="_blank" rel="nofollow noopener">NetBSD at Shimane Open Source Conference 2014</a></h3>

<ul>
<li>The Japanese NetBSD users group held a NetBSD booth at the Open Source Conference 2014 in Shimane on August 23</li>
<li>One of the developers has gathered a bunch of pictures from the event and wrote a fairly lengthy summary</li>
<li>They had NetBSD running on all sorts of devices, from Raspberry Pis to Sun Java Stations</li>
<li>Some visitors said that NetBSD had the most chaotic booth at the conference
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1401" target="_blank" rel="nofollow noopener">pfSense 2.1.5 released</a></h3>

<ul>
<li>A new version of the pfSense 2.1 branch is out</li>
<li>Mostly a security-focused release, including three web UI fixes and the most recent OpenSSL fix (which FreeBSD has <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-August/007875.html" target="_blank" rel="nofollow noopener">still not patched</a> in -RELEASE after nearly a month)</li>
<li>It also includes many other bug fixes, check the blog post for the full list
***</li>
</ul>

<h3><a href="http://msrvideo.vo.msecnd.net/rmcvideos/227133/dl/227133.mp4" target="_blank" rel="nofollow noopener">Systems, Science and FreeBSD</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener">George Neville-Neil</a> gave a presentation at Microsoft Research</li>
<li>It's mainly about using FreeBSD as a platform for research, inside and outside of universities</li>
<li>The talk describes the OS and its features, ports, developer community, documentation, who uses BSD and much more
***</li>
</ul>

<h2>Interview - Reyk Floeter - <a href="mailto:reyk@openbsd.org" target="_blank" rel="nofollow noopener">reyk@openbsd.org</a> / <a href="https://twitter.com/reykfloeter" target="_blank" rel="nofollow noopener">@reykfloeter</a></h2>

<p>OpenBSD's HTTP daemon</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/hammer" target="_blank" rel="nofollow noopener">A crash course on HAMMER FS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://brynet.biz.tm/article-rcctl.html" target="_blank" rel="nofollow noopener">OpenBSD's rcctl tool usage</a></h3>

<ul>
<li>OpenBSD recently <a href="http://undeadly.org/cgi?action=article&amp;sid=20140820090351" target="_blank" rel="nofollow noopener">got a new tool</a> for managing /etc/rc.conf.local in -current</li>
<li>Similar to FreeBSD's "sysrc" tool, it eliminates the need to manually edit rc.conf.local to enable or disable services</li>
<li>This blog post - from a BSD Now viewer - shows the typical usage of the new tool to alter the startup services</li>
<li>It won't make it to 5.6, but will be in 5.7 (next May)
***</li>
</ul>

<h3><a href="http://mateh.id.au/2014/08/stream-netflix-chromecast-using-pfsense/" target="_blank" rel="nofollow noopener">pfSense mini-roundup</a></h3>

<ul>
<li>We found five interesting pfSense articles throughout the week and wanted to quickly mention them</li>
<li>The first item in our pfSense mini-roundup details how you can stream Netflix to in non-US countries using a "smart" DNS service</li>
<li>The <a href="http://theosquest.com/2014/08/28/ipv6-with-comcast-and-pfsense/" target="_blank" rel="nofollow noopener">second post</a> talks about setting ip IPv6, in particular if Comcast is your ISP</li>
<li>The <a href="http://news.softpedia.com/news/PfSense-2-1-5-Is-Free-and-Powerful-FreeBSD-based-Firewall-Operating-System-457097.shtml" target="_blank" rel="nofollow noopener">third one</a> features pfSense on Softpedia, a more mainstream tech site</li>
<li>The <a href="http://sichent.wordpress.com/2014/02/22/filtering-https-traffic-with-squid-on-pfsense-2-1/" target="_blank" rel="nofollow noopener">fourth post</a> describes how to filter HTTPS traffic with Squid and pfSense</li>
<li>The <a href="http://pfsensesetup.com/vpn-tunneling-with-tinc/" target="_blank" rel="nofollow noopener">last article</a> describes setting up a VPN using the "<a href="https://en.wikipedia.org/wiki/Tinc_%28protocol%29" target="_blank" rel="nofollow noopener">tinc</a>" daemon and pfSense</li>
<li>It seems to be lesser known, compared to things like OpenVPN or SSH tunnels, so it's interesting to read about</li>
<li>This pfSense HQ website seems to have lots of other cool pfSense items, check it out
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/2Q-buffer-cache-algorithm" target="_blank" rel="nofollow noopener">OpenBSD's new buffer cache</a></h3>

<ul>
<li>OpenBSD has traditionally used the tried-and-true LRU algorithm for buffer cache, but it has a few problems</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> has just switched to a new algorithm in -current, partially based on 2Q, and details some of his work</li>
<li>Initial tests show positive results in terms of cache responsiveness</li>
<li>Check the post for all the fine details
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/08/bsdtalk244-lumina-desktop-environment.html" target="_blank" rel="nofollow noopener">BSDTalk episode 244</a></h3>

<ul>
<li>Another new BSDTalk is up and, this time around, <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">Will Backman</a> interviews Ken Moore, the developer of the new BSD desktop environment</li>
<li>They discuss the history of development, differences between it and other DEs, lots of topics</li>
<li>If you're more of a visual person, fear not, because...</li>
<li>We'll have Ken on <em>next week</em>, including a full "virtual walkthrough" of Lumina and its applications
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21G3KL6lv" target="_blank" rel="nofollow noopener">Ghislain writes in</a></li>
<li><a href="http://slexy.org/view/s21USZdk2D" target="_blank" rel="nofollow noopener">Raynold writes in</a></li>
<li><a href="http://slexy.org/view/s2IWAfkDfX" target="_blank" rel="nofollow noopener">Van writes in</a></li>
<li><a href="http://slexy.org/view/s2OBhezoDV" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s22h9RhXUy" target="_blank" rel="nofollow noopener">Stefan writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's our one year anniversary episode, and we'll be talking with Reyk Floeter about the new OpenBSD webserver - why it was created and where it's going. After that, we'll show you the ins and outs of DragonFly's HAMMER FS. Answers to viewer-submitted questions and the latest headlines, on a very special BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/08/freebsd-foundation-announces-ipsec.html" target="_blank" rel="nofollow noopener">FreeBSD foundation's new IPSEC project</a></h3>

<ul>
<li>The FreeBSD foundation, along with Netgate, is sponsoring some new work on the IPSEC code</li>
<li>With bandwidth in the 10-40 gigabit per second range, the IPSEC stack needs to be brought up to modern standards in terms of encryption and performance</li>
<li>This new work will add AES-CTR and AES-GCM modes to FreeBSD's implementation, borrowing some code from OpenBSD</li>
<li>The updated stack will also support AES-NI for hardware-based encryption speed ups</li>
<li>It's expected to be completed by the end of September, and will also be in pfSense 2.2
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/31/msg000667.html" target="_blank" rel="nofollow noopener">NetBSD at Shimane Open Source Conference 2014</a></h3>

<ul>
<li>The Japanese NetBSD users group held a NetBSD booth at the Open Source Conference 2014 in Shimane on August 23</li>
<li>One of the developers has gathered a bunch of pictures from the event and wrote a fairly lengthy summary</li>
<li>They had NetBSD running on all sorts of devices, from Raspberry Pis to Sun Java Stations</li>
<li>Some visitors said that NetBSD had the most chaotic booth at the conference
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1401" target="_blank" rel="nofollow noopener">pfSense 2.1.5 released</a></h3>

<ul>
<li>A new version of the pfSense 2.1 branch is out</li>
<li>Mostly a security-focused release, including three web UI fixes and the most recent OpenSSL fix (which FreeBSD has <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-August/007875.html" target="_blank" rel="nofollow noopener">still not patched</a> in -RELEASE after nearly a month)</li>
<li>It also includes many other bug fixes, check the blog post for the full list
***</li>
</ul>

<h3><a href="http://msrvideo.vo.msecnd.net/rmcvideos/227133/dl/227133.mp4" target="_blank" rel="nofollow noopener">Systems, Science and FreeBSD</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener">George Neville-Neil</a> gave a presentation at Microsoft Research</li>
<li>It's mainly about using FreeBSD as a platform for research, inside and outside of universities</li>
<li>The talk describes the OS and its features, ports, developer community, documentation, who uses BSD and much more
***</li>
</ul>

<h2>Interview - Reyk Floeter - <a href="mailto:reyk@openbsd.org" target="_blank" rel="nofollow noopener">reyk@openbsd.org</a> / <a href="https://twitter.com/reykfloeter" target="_blank" rel="nofollow noopener">@reykfloeter</a></h2>

<p>OpenBSD's HTTP daemon</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/hammer" target="_blank" rel="nofollow noopener">A crash course on HAMMER FS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://brynet.biz.tm/article-rcctl.html" target="_blank" rel="nofollow noopener">OpenBSD's rcctl tool usage</a></h3>

<ul>
<li>OpenBSD recently <a href="http://undeadly.org/cgi?action=article&amp;sid=20140820090351" target="_blank" rel="nofollow noopener">got a new tool</a> for managing /etc/rc.conf.local in -current</li>
<li>Similar to FreeBSD's "sysrc" tool, it eliminates the need to manually edit rc.conf.local to enable or disable services</li>
<li>This blog post - from a BSD Now viewer - shows the typical usage of the new tool to alter the startup services</li>
<li>It won't make it to 5.6, but will be in 5.7 (next May)
***</li>
</ul>

<h3><a href="http://mateh.id.au/2014/08/stream-netflix-chromecast-using-pfsense/" target="_blank" rel="nofollow noopener">pfSense mini-roundup</a></h3>

<ul>
<li>We found five interesting pfSense articles throughout the week and wanted to quickly mention them</li>
<li>The first item in our pfSense mini-roundup details how you can stream Netflix to in non-US countries using a "smart" DNS service</li>
<li>The <a href="http://theosquest.com/2014/08/28/ipv6-with-comcast-and-pfsense/" target="_blank" rel="nofollow noopener">second post</a> talks about setting ip IPv6, in particular if Comcast is your ISP</li>
<li>The <a href="http://news.softpedia.com/news/PfSense-2-1-5-Is-Free-and-Powerful-FreeBSD-based-Firewall-Operating-System-457097.shtml" target="_blank" rel="nofollow noopener">third one</a> features pfSense on Softpedia, a more mainstream tech site</li>
<li>The <a href="http://sichent.wordpress.com/2014/02/22/filtering-https-traffic-with-squid-on-pfsense-2-1/" target="_blank" rel="nofollow noopener">fourth post</a> describes how to filter HTTPS traffic with Squid and pfSense</li>
<li>The <a href="http://pfsensesetup.com/vpn-tunneling-with-tinc/" target="_blank" rel="nofollow noopener">last article</a> describes setting up a VPN using the "<a href="https://en.wikipedia.org/wiki/Tinc_%28protocol%29" target="_blank" rel="nofollow noopener">tinc</a>" daemon and pfSense</li>
<li>It seems to be lesser known, compared to things like OpenVPN or SSH tunnels, so it's interesting to read about</li>
<li>This pfSense HQ website seems to have lots of other cool pfSense items, check it out
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/2Q-buffer-cache-algorithm" target="_blank" rel="nofollow noopener">OpenBSD's new buffer cache</a></h3>

<ul>
<li>OpenBSD has traditionally used the tried-and-true LRU algorithm for buffer cache, but it has a few problems</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> has just switched to a new algorithm in -current, partially based on 2Q, and details some of his work</li>
<li>Initial tests show positive results in terms of cache responsiveness</li>
<li>Check the post for all the fine details
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/08/bsdtalk244-lumina-desktop-environment.html" target="_blank" rel="nofollow noopener">BSDTalk episode 244</a></h3>

<ul>
<li>Another new BSDTalk is up and, this time around, <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">Will Backman</a> interviews Ken Moore, the developer of the new BSD desktop environment</li>
<li>They discuss the history of development, differences between it and other DEs, lots of topics</li>
<li>If you're more of a visual person, fear not, because...</li>
<li>We'll have Ken on <em>next week</em>, including a full "virtual walkthrough" of Lumina and its applications
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21G3KL6lv" target="_blank" rel="nofollow noopener">Ghislain writes in</a></li>
<li><a href="http://slexy.org/view/s21USZdk2D" target="_blank" rel="nofollow noopener">Raynold writes in</a></li>
<li><a href="http://slexy.org/view/s2IWAfkDfX" target="_blank" rel="nofollow noopener">Van writes in</a></li>
<li><a href="http://slexy.org/view/s2OBhezoDV" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s22h9RhXUy" target="_blank" rel="nofollow noopener">Stefan writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>52: Reverse Takeover</title>
  <link>https://www.bsdnow.tv/52</link>
  <guid isPermaLink="false">67ad6e78-144e-4d1c-a713-49b54e5b679e</guid>
  <pubDate>Wed, 27 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/67ad6e78-144e-4d1c-a713-49b54e5b679e.mp3" length="53663188" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be chatting with Shawn Webb about his recent work with ASLR and PIE in FreeBSD. After that, we'll be showing you how you can create a reverse SSH tunnel to a system behind a firewall... how sneaky. Answers to your emails plus the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:14:31</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be chatting with Shawn Webb about his recent work with ASLR and PIE in FreeBSD. After that, we'll be showing you how you can create a reverse SSH tunnel to a system behind a firewall... how sneaky. Answers to your emails plus the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2014augupdate.pdf" target="_blank" rel="nofollow noopener"&gt;FreeBSD foundation August update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The foundation has published a new PDF detailing some of their recent activities&lt;/li&gt;
&lt;li&gt;It includes project development updates, the 10.1-RELEASE schedule and some of its new features&lt;/li&gt;
&lt;li&gt;There is also a short interview with &lt;a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener"&gt;Dru Lavigne&lt;/a&gt; in the "voices from the community" section&lt;/li&gt;
&lt;li&gt;If you're into hardware, there's another section about some new FreeBSD server equipment&lt;/li&gt;
&lt;li&gt;In closing, there's an update on funding too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.prado.it/2014/08/20/how-to-run-master-nsd-on-freebsd-10-0/" target="_blank" rel="nofollow noopener"&gt;NSD for an authoritative nameserver&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With BIND having been removed from FreeBSD 10.0, you might be looking to replace your old DNS setup&lt;/li&gt;
&lt;li&gt;This article shows how to use NSD for an authoritative DNS nameserver&lt;/li&gt;
&lt;li&gt;It's also got a link to a similar article on Unbound, the new favorite recursive and caching resolver (they work great together)&lt;/li&gt;
&lt;li&gt;All the instructions are presented very neatly, with all the little details included&lt;/li&gt;
&lt;li&gt;Less BIND means less vulnerabilities, everybody's happy
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=140873518514033&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;BIND and Nginx removed from OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;While we're on the topic of DNS servers, BIND was finally removed from OpenBSD as well&lt;/li&gt;
&lt;li&gt;The base system contains both NSD and Unbound, so users can transition over between 5.6 (November of this year) and 5.7 (May of next year)&lt;/li&gt;
&lt;li&gt;They've also &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=140908174910713&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;removed nginx&lt;/a&gt; from the base system, in favor of the new custom HTTP daemon&lt;/li&gt;
&lt;li&gt;BIND and Nginx are still available in ports if you don't want to switch&lt;/li&gt;
&lt;li&gt;We're hoping to have Reyk Floeter on the show next week to talk about it, but scheduling might not work out, so it may be a little later on&lt;/li&gt;
&lt;li&gt;With Apache gone in the upcoming 5.6, It's also likely that sendmail will be removed before 5.7 - hooray for modern alternatives
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/user/tsutsuii/videos" target="_blank" rel="nofollow noopener"&gt;NetBSD demo videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A Japanese NetBSD developer has been uploading lots of interesting videos&lt;/li&gt;
&lt;li&gt;Unsurprisingly, they're all featuring NetBSD running on exotic and weird hardware&lt;/li&gt;
&lt;li&gt;Most of them are demoing sound or running a modern Twitter client on an ancient computer&lt;/li&gt;
&lt;li&gt;They're from the same guy that did the conference wrap-up we mentioned recently
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Shawn Webb - &lt;a href="mailto:shawn.webb@hardenedbsd.org" target="_blank" rel="nofollow noopener"&gt;shawn.webb@hardenedbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/lattera" target="_blank" rel="nofollow noopener"&gt;@lattera&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Address space layout randomization &lt;a href="http://hardenedbsd.org/" target="_blank" rel="nofollow noopener"&gt;in FreeBSD&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/reverse-ssh" target="_blank" rel="nofollow noopener"&gt;Reverse SSH tunneling&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://deuterion.net/puppet-master-agent-installation-on-freebsd/" target="_blank" rel="nofollow noopener"&gt;Puppet master-agent installation on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got a lot of BSD boxes under your control, or if you're just lazy, you've probably looked into Puppet before&lt;/li&gt;
&lt;li&gt;The author claims a lack of BSD-specific Puppet documentation, so he decided to write up some notes of his own&lt;/li&gt;
&lt;li&gt;He goes through some advantages of using this type of tool for deployments, even when you don't have a huge number of systems&lt;/li&gt;
&lt;li&gt;The rest of the post explains how to set up both the master and the agent configurations
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.mondaiji.com/blog/other/it/10175-the-hunt-for-the-ultimate-free-open-source-firewall-distro" target="_blank" rel="nofollow noopener"&gt;Misc. pfSense items&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We found a few miscellaneous pfSense articles this past week &lt;/li&gt;
&lt;li&gt;The first one is about the hunt for the "ultimate" free open source firewall, where pfSense is obviously a strong contender&lt;/li&gt;
&lt;li&gt;&lt;a href="http://willbradley.name/2014/08/20/logging-natfirewallstate-entries-in-pfsense/" target="_blank" rel="nofollow noopener"&gt;The second one&lt;/a&gt; shows how to log NAT firewall states (a good way to find out which family member has been torrenting!)&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://www.proteansec.com/linux/pfsense-automatically-backup-configuration-files/" target="_blank" rel="nofollow noopener"&gt;the third&lt;/a&gt;, you can see how to automatically back up your configuration files&lt;/li&gt;
&lt;li&gt;&lt;a href="https://vidarw.wordpress.com/2014/07/09/network-boot-with-pfsense-and-tftpd32/" target="_blank" rel="nofollow noopener"&gt;The fourth item&lt;/a&gt; shows how to set up PXE booting with pfSense, similar to one of our tutorials
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.khubla.com/freebsd/timemachine-backups-on-freebsd-10" target="_blank" rel="nofollow noopener"&gt;Time Machine backups on ZFS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got a Mac you need to keep backed up, a FreeBSD server with ZFS can take the place of an expensive "time capsule"&lt;/li&gt;
&lt;li&gt;This post walks you through setting up netatalk and mDNS for a very versatile Time Machine backup system&lt;/li&gt;
&lt;li&gt;With a single command on the OS X side, you can write to and read from the BSD box just like a regular external drive&lt;/li&gt;
&lt;li&gt;Surprisingly simple to do, recommended for anyone with Macs on their network
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/08/pc-bsd-10-0-3-preview-lumina-desktop/" target="_blank" rel="nofollow noopener"&gt;Lumina desktop preview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Lumina, the BSD-exclusive desktop environment, seems to be coming along nicely&lt;/li&gt;
&lt;li&gt;The main developer has posted an update on the PCBSD blog with some screenshots&lt;/li&gt;
&lt;li&gt;Lots of new features have been added, many of which are documented in the post&lt;/li&gt;
&lt;li&gt;There just might be a BSD Now episode about Lumina coming up.. (cough cough)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21eLBvf1l" target="_blank" rel="nofollow noopener"&gt;Gary writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20xqTKNrf" target="_blank" rel="nofollow noopener"&gt;Cedric writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21q428tPj" target="_blank" rel="nofollow noopener"&gt;Caldwell writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2uVLhqCaO" target="_blank" rel="nofollow noopener"&gt;Cary writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ssh, tunnel, reverse tunnel, encryption, aslr, pie, address space layout randomization, position-independent executables, nsd, bind, unbound, dns server, pfsense, shawn webb, time machine, os x, nginx</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be chatting with Shawn Webb about his recent work with ASLR and PIE in FreeBSD. After that, we'll be showing you how you can create a reverse SSH tunnel to a system behind a firewall... how sneaky. Answers to your emails plus the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014augupdate.pdf" target="_blank" rel="nofollow noopener">FreeBSD foundation August update</a></h3>

<ul>
<li>The foundation has published a new PDF detailing some of their recent activities</li>
<li>It includes project development updates, the 10.1-RELEASE schedule and some of its new features</li>
<li>There is also a short interview with <a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener">Dru Lavigne</a> in the "voices from the community" section</li>
<li>If you're into hardware, there's another section about some new FreeBSD server equipment</li>
<li>In closing, there's an update on funding too
***</li>
</ul>

<h3><a href="http://www.prado.it/2014/08/20/how-to-run-master-nsd-on-freebsd-10-0/" target="_blank" rel="nofollow noopener">NSD for an authoritative nameserver</a></h3>

<ul>
<li>With BIND having been removed from FreeBSD 10.0, you might be looking to replace your old DNS setup</li>
<li>This article shows how to use NSD for an authoritative DNS nameserver</li>
<li>It's also got a link to a similar article on Unbound, the new favorite recursive and caching resolver (they work great together)</li>
<li>All the instructions are presented very neatly, with all the little details included</li>
<li>Less BIND means less vulnerabilities, everybody's happy
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-cvs&amp;m=140873518514033&amp;w=2" target="_blank" rel="nofollow noopener">BIND and Nginx removed from OpenBSD</a></h3>

<ul>
<li>While we're on the topic of DNS servers, BIND was finally removed from OpenBSD as well</li>
<li>The base system contains both NSD and Unbound, so users can transition over between 5.6 (November of this year) and 5.7 (May of next year)</li>
<li>They've also <a href="http://marc.info/?l=openbsd-cvs&amp;m=140908174910713&amp;w=2" target="_blank" rel="nofollow noopener">removed nginx</a> from the base system, in favor of the new custom HTTP daemon</li>
<li>BIND and Nginx are still available in ports if you don't want to switch</li>
<li>We're hoping to have Reyk Floeter on the show next week to talk about it, but scheduling might not work out, so it may be a little later on</li>
<li>With Apache gone in the upcoming 5.6, It's also likely that sendmail will be removed before 5.7 - hooray for modern alternatives
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/tsutsuii/videos" target="_blank" rel="nofollow noopener">NetBSD demo videos</a></h3>

<ul>
<li>A Japanese NetBSD developer has been uploading lots of interesting videos</li>
<li>Unsurprisingly, they're all featuring NetBSD running on exotic and weird hardware</li>
<li>Most of them are demoing sound or running a modern Twitter client on an ancient computer</li>
<li>They're from the same guy that did the conference wrap-up we mentioned recently
***</li>
</ul>

<h2>Interview - Shawn Webb - <a href="mailto:shawn.webb@hardenedbsd.org" target="_blank" rel="nofollow noopener">shawn.webb@hardenedbsd.org</a> / <a href="https://twitter.com/lattera" target="_blank" rel="nofollow noopener">@lattera</a></h2>

<p>Address space layout randomization <a href="http://hardenedbsd.org/" target="_blank" rel="nofollow noopener">in FreeBSD</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/reverse-ssh" target="_blank" rel="nofollow noopener">Reverse SSH tunneling</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://deuterion.net/puppet-master-agent-installation-on-freebsd/" target="_blank" rel="nofollow noopener">Puppet master-agent installation on FreeBSD</a></h3>

<ul>
<li>If you've got a lot of BSD boxes under your control, or if you're just lazy, you've probably looked into Puppet before</li>
<li>The author claims a lack of BSD-specific Puppet documentation, so he decided to write up some notes of his own</li>
<li>He goes through some advantages of using this type of tool for deployments, even when you don't have a huge number of systems</li>
<li>The rest of the post explains how to set up both the master and the agent configurations
***</li>
</ul>

<h3><a href="http://www.mondaiji.com/blog/other/it/10175-the-hunt-for-the-ultimate-free-open-source-firewall-distro" target="_blank" rel="nofollow noopener">Misc. pfSense items</a></h3>

<ul>
<li>We found a few miscellaneous pfSense articles this past week </li>
<li>The first one is about the hunt for the "ultimate" free open source firewall, where pfSense is obviously a strong contender</li>
<li><a href="http://willbradley.name/2014/08/20/logging-natfirewallstate-entries-in-pfsense/" target="_blank" rel="nofollow noopener">The second one</a> shows how to log NAT firewall states (a good way to find out which family member has been torrenting!)</li>
<li>In <a href="http://www.proteansec.com/linux/pfsense-automatically-backup-configuration-files/" target="_blank" rel="nofollow noopener">the third</a>, you can see how to automatically back up your configuration files</li>
<li><a href="https://vidarw.wordpress.com/2014/07/09/network-boot-with-pfsense-and-tftpd32/" target="_blank" rel="nofollow noopener">The fourth item</a> shows how to set up PXE booting with pfSense, similar to one of our tutorials
***</li>
</ul>

<h3><a href="http://blog.khubla.com/freebsd/timemachine-backups-on-freebsd-10" target="_blank" rel="nofollow noopener">Time Machine backups on ZFS</a></h3>

<ul>
<li>If you've got a Mac you need to keep backed up, a FreeBSD server with ZFS can take the place of an expensive "time capsule"</li>
<li>This post walks you through setting up netatalk and mDNS for a very versatile Time Machine backup system</li>
<li>With a single command on the OS X side, you can write to and read from the BSD box just like a regular external drive</li>
<li>Surprisingly simple to do, recommended for anyone with Macs on their network
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/08/pc-bsd-10-0-3-preview-lumina-desktop/" target="_blank" rel="nofollow noopener">Lumina desktop preview</a></h3>

<ul>
<li>Lumina, the BSD-exclusive desktop environment, seems to be coming along nicely</li>
<li>The main developer has posted an update on the PCBSD blog with some screenshots</li>
<li>Lots of new features have been added, many of which are documented in the post</li>
<li>There just might be a BSD Now episode about Lumina coming up.. (cough cough)
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21eLBvf1l" target="_blank" rel="nofollow noopener">Gary writes in</a></li>
<li><a href="http://slexy.org/view/s20xqTKNrf" target="_blank" rel="nofollow noopener">Cedric writes in</a></li>
<li><a href="http://slexy.org/view/s21q428tPj" target="_blank" rel="nofollow noopener">Caldwell writes in</a></li>
<li><a href="http://slexy.org/view/s2uVLhqCaO" target="_blank" rel="nofollow noopener">Cary writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be chatting with Shawn Webb about his recent work with ASLR and PIE in FreeBSD. After that, we'll be showing you how you can create a reverse SSH tunnel to a system behind a firewall... how sneaky. Answers to your emails plus the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014augupdate.pdf" target="_blank" rel="nofollow noopener">FreeBSD foundation August update</a></h3>

<ul>
<li>The foundation has published a new PDF detailing some of their recent activities</li>
<li>It includes project development updates, the 10.1-RELEASE schedule and some of its new features</li>
<li>There is also a short interview with <a href="http://www.bsdnow.tv/episodes/2014_04_09-pxe_dust" target="_blank" rel="nofollow noopener">Dru Lavigne</a> in the "voices from the community" section</li>
<li>If you're into hardware, there's another section about some new FreeBSD server equipment</li>
<li>In closing, there's an update on funding too
***</li>
</ul>

<h3><a href="http://www.prado.it/2014/08/20/how-to-run-master-nsd-on-freebsd-10-0/" target="_blank" rel="nofollow noopener">NSD for an authoritative nameserver</a></h3>

<ul>
<li>With BIND having been removed from FreeBSD 10.0, you might be looking to replace your old DNS setup</li>
<li>This article shows how to use NSD for an authoritative DNS nameserver</li>
<li>It's also got a link to a similar article on Unbound, the new favorite recursive and caching resolver (they work great together)</li>
<li>All the instructions are presented very neatly, with all the little details included</li>
<li>Less BIND means less vulnerabilities, everybody's happy
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-cvs&amp;m=140873518514033&amp;w=2" target="_blank" rel="nofollow noopener">BIND and Nginx removed from OpenBSD</a></h3>

<ul>
<li>While we're on the topic of DNS servers, BIND was finally removed from OpenBSD as well</li>
<li>The base system contains both NSD and Unbound, so users can transition over between 5.6 (November of this year) and 5.7 (May of next year)</li>
<li>They've also <a href="http://marc.info/?l=openbsd-cvs&amp;m=140908174910713&amp;w=2" target="_blank" rel="nofollow noopener">removed nginx</a> from the base system, in favor of the new custom HTTP daemon</li>
<li>BIND and Nginx are still available in ports if you don't want to switch</li>
<li>We're hoping to have Reyk Floeter on the show next week to talk about it, but scheduling might not work out, so it may be a little later on</li>
<li>With Apache gone in the upcoming 5.6, It's also likely that sendmail will be removed before 5.7 - hooray for modern alternatives
***</li>
</ul>

<h3><a href="https://www.youtube.com/user/tsutsuii/videos" target="_blank" rel="nofollow noopener">NetBSD demo videos</a></h3>

<ul>
<li>A Japanese NetBSD developer has been uploading lots of interesting videos</li>
<li>Unsurprisingly, they're all featuring NetBSD running on exotic and weird hardware</li>
<li>Most of them are demoing sound or running a modern Twitter client on an ancient computer</li>
<li>They're from the same guy that did the conference wrap-up we mentioned recently
***</li>
</ul>

<h2>Interview - Shawn Webb - <a href="mailto:shawn.webb@hardenedbsd.org" target="_blank" rel="nofollow noopener">shawn.webb@hardenedbsd.org</a> / <a href="https://twitter.com/lattera" target="_blank" rel="nofollow noopener">@lattera</a></h2>

<p>Address space layout randomization <a href="http://hardenedbsd.org/" target="_blank" rel="nofollow noopener">in FreeBSD</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/reverse-ssh" target="_blank" rel="nofollow noopener">Reverse SSH tunneling</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://deuterion.net/puppet-master-agent-installation-on-freebsd/" target="_blank" rel="nofollow noopener">Puppet master-agent installation on FreeBSD</a></h3>

<ul>
<li>If you've got a lot of BSD boxes under your control, or if you're just lazy, you've probably looked into Puppet before</li>
<li>The author claims a lack of BSD-specific Puppet documentation, so he decided to write up some notes of his own</li>
<li>He goes through some advantages of using this type of tool for deployments, even when you don't have a huge number of systems</li>
<li>The rest of the post explains how to set up both the master and the agent configurations
***</li>
</ul>

<h3><a href="http://www.mondaiji.com/blog/other/it/10175-the-hunt-for-the-ultimate-free-open-source-firewall-distro" target="_blank" rel="nofollow noopener">Misc. pfSense items</a></h3>

<ul>
<li>We found a few miscellaneous pfSense articles this past week </li>
<li>The first one is about the hunt for the "ultimate" free open source firewall, where pfSense is obviously a strong contender</li>
<li><a href="http://willbradley.name/2014/08/20/logging-natfirewallstate-entries-in-pfsense/" target="_blank" rel="nofollow noopener">The second one</a> shows how to log NAT firewall states (a good way to find out which family member has been torrenting!)</li>
<li>In <a href="http://www.proteansec.com/linux/pfsense-automatically-backup-configuration-files/" target="_blank" rel="nofollow noopener">the third</a>, you can see how to automatically back up your configuration files</li>
<li><a href="https://vidarw.wordpress.com/2014/07/09/network-boot-with-pfsense-and-tftpd32/" target="_blank" rel="nofollow noopener">The fourth item</a> shows how to set up PXE booting with pfSense, similar to one of our tutorials
***</li>
</ul>

<h3><a href="http://blog.khubla.com/freebsd/timemachine-backups-on-freebsd-10" target="_blank" rel="nofollow noopener">Time Machine backups on ZFS</a></h3>

<ul>
<li>If you've got a Mac you need to keep backed up, a FreeBSD server with ZFS can take the place of an expensive "time capsule"</li>
<li>This post walks you through setting up netatalk and mDNS for a very versatile Time Machine backup system</li>
<li>With a single command on the OS X side, you can write to and read from the BSD box just like a regular external drive</li>
<li>Surprisingly simple to do, recommended for anyone with Macs on their network
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/08/pc-bsd-10-0-3-preview-lumina-desktop/" target="_blank" rel="nofollow noopener">Lumina desktop preview</a></h3>

<ul>
<li>Lumina, the BSD-exclusive desktop environment, seems to be coming along nicely</li>
<li>The main developer has posted an update on the PCBSD blog with some screenshots</li>
<li>Lots of new features have been added, many of which are documented in the post</li>
<li>There just might be a BSD Now episode about Lumina coming up.. (cough cough)
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21eLBvf1l" target="_blank" rel="nofollow noopener">Gary writes in</a></li>
<li><a href="http://slexy.org/view/s20xqTKNrf" target="_blank" rel="nofollow noopener">Cedric writes in</a></li>
<li><a href="http://slexy.org/view/s21q428tPj" target="_blank" rel="nofollow noopener">Caldwell writes in</a></li>
<li><a href="http://slexy.org/view/s2uVLhqCaO" target="_blank" rel="nofollow noopener">Cary writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>51: Engineering Nginx</title>
  <link>https://www.bsdnow.tv/51</link>
  <guid isPermaLink="false">4502bfee-e803-4a0d-bdcc-fd4420b30bb1</guid>
  <pubDate>Wed, 20 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/4502bfee-e803-4a0d-bdcc-fd4420b30bb1.mp3" length="62975956" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up on the show, we'll be showing you how to set up a secure, SSL-only webserver. There's also an interview with Eric Le Blan about community participation and FreeBSD's role in the commercial server space. All that and more, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:27:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up on the show, we'll be showing you how to set up a secure, SSL-only webserver. There's also an interview with Eric Le Blan about community participation and FreeBSD's role in the commercial server space. All that and more, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2014/08/password-gropers-take-spamtrap-bait.html" target="_blank" rel="nofollow noopener"&gt;Password gropers take spamtrap bait&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our friend &lt;a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener"&gt;Peter Hansteen&lt;/a&gt;, who keeps his eyes glued to his log files, has a new blog post&lt;/li&gt;
&lt;li&gt;He seems to have discovered another new weird phenomenon in his pop3 logs&lt;/li&gt;
&lt;li&gt;"yes, I still run one, for the same bad reasons more than a third of my readers probably do: inertia"&lt;/li&gt;
&lt;li&gt;Someone tried to log in to his service with an address that was known to be invalid&lt;/li&gt;
&lt;li&gt;The rest of the post goes into detail about his theory of why someone would use a list of invalid addresses for this purpose
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=WOcYTqoSQ68" target="_blank" rel="nofollow noopener"&gt;Inside the Atheros wifi chipset&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Adrian Chadd - sometimes known in the FreeBSD community as "the wireless guy" - gave a talk at the Defcon Wireless Village 2014&lt;/li&gt;
&lt;li&gt;He covers a lot of topics on wifi, specifically on Atheros chips and why they're so popular for open source development&lt;/li&gt;
&lt;li&gt;There's a lot of great information in the presentation, including cool (and evil) things you can do with wireless cards&lt;/li&gt;
&lt;li&gt;Very technical talk; some parts might go over your head if you're not a driver developer&lt;/li&gt;
&lt;li&gt;The raw video file is also available &lt;a href="https://archive.org/download/WirelessVillageAtDefCon22/20-Atheros.mp4" target="_blank" rel="nofollow noopener"&gt;to download&lt;/a&gt; on archive.org&lt;/li&gt;
&lt;li&gt;Adrian has also recently worked on getting Kismet and Aircrack-NG to work better with FreeBSD, including packet injection and other fun things
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener"&gt;Trip report and hackathon mini-roundup&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A few more (late) reports from BSDCan and the latest OpenBSD hackathon have been posted&lt;/li&gt;
&lt;li&gt;Mark Linimon mentions some of the future plans for FreeBSD's release engineering and ports&lt;/li&gt;
&lt;li&gt;Bapt &lt;a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-baptiste-daroussin.html" target="_blank" rel="nofollow noopener"&gt;also has a BSDCan report&lt;/a&gt; detailing his work on ports and packages&lt;/li&gt;
&lt;li&gt;Antoine Jacoutot &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140812064946" target="_blank" rel="nofollow noopener"&gt;writes about&lt;/a&gt; his work at the most recent hackathon, working with rc configuration and a new /etc/examples layout&lt;/li&gt;
&lt;li&gt;Peter Hessler, a latecomer to the hackathon, &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140806125308" target="_blank" rel="nofollow noopener"&gt;details his experience&lt;/a&gt; too, hacking on the installer and built-in upgrade function&lt;/li&gt;
&lt;li&gt;Christian Weisgerber &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140803122705" target="_blank" rel="nofollow noopener"&gt;talks about&lt;/a&gt; starting some initial improvements of OpenBSD's ports infrastructure
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2014-August/270573.html" target="_blank" rel="nofollow noopener"&gt;DragonFly BSD 3.8.2 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Although it was already branched, the release media is now available for DragonFly 3.8.2&lt;/li&gt;
&lt;li&gt;This is a minor update, mostly to fix the recent OpenSSL vulnerabilities&lt;/li&gt;
&lt;li&gt;It also includes some various other small fixes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Eric Le Blan - &lt;a href="mailto:info@xinuos.com" target="_blank" rel="nofollow noopener"&gt;info@xinuos.com&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Xinuos' recent FreeBSD integration, BSD in the commercial server space&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/nginx" target="_blank" rel="nofollow noopener"&gt;Building a hardened, feature-rich webserver&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://networkfilter.blogspot.com/2014/08/defend-your-network-and-privacy-vpn.html" target="_blank" rel="nofollow noopener"&gt;Defend your network and privacy, FreeBSD version&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back in &lt;a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" target="_blank" rel="nofollow noopener"&gt;episode 39&lt;/a&gt;, we covered a blog post about creating an OpenBSD gateway - partly based on &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;our tutorial&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This is a follow-up post, by the same author, about doing a similar thing with FreeBSD&lt;/li&gt;
&lt;li&gt;He mentions some of the advantages and disadvantages between the two operating systems, and encourages users to decide for themselves which one suits their needs&lt;/li&gt;
&lt;li&gt;The rest is pretty much the same things: firewall, VPN, DHCP server, DNSCrypt, etc.
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/dont-encrypt-all-the-things" target="_blank" rel="nofollow noopener"&gt;Don't encrypt all the things&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another couple of interesting blog posts from &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; about encryption&lt;/li&gt;
&lt;li&gt;It talks about how Google recently started ranking sites with HTTPS higher in their search results, and then reflects on how sometimes encryption does more harm than good&lt;/li&gt;
&lt;li&gt;After heartbleed, the ones who might be able to decrypt your emails went from just a three-letter agency to any script kiddie&lt;/li&gt;
&lt;li&gt;He also talks a bit about some PGP weaknesses and a possible future replacement&lt;/li&gt;
&lt;li&gt;He also has another, similar post entitled "&lt;a href="http://www.tedunangst.com/flak/post/in-defense-of-opportunistic-encryption" target="_blank" rel="nofollow noopener"&gt;in defense of opportunistic encryption&lt;/a&gt;"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=270096" target="_blank" rel="nofollow noopener"&gt;New automounter lands in FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The work on the new automounter has just landed in 11-CURRENT&lt;/li&gt;
&lt;li&gt;With help from the FreeBSD Foundation, we'll have a new "autofs" kernel option&lt;/li&gt;
&lt;li&gt;Check the SVN viewer online to read over the man pages if you're not running -CURRENT&lt;/li&gt;
&lt;li&gt;You can also read a bit about it in the &lt;a href="https://www.freebsdfoundation.org/press/2014jul-newsletter#Project3" target="_blank" rel="nofollow noopener"&gt;recent newsletter&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-August/032810.html" target="_blank" rel="nofollow noopener"&gt;OpenSSH 6.7 CFT&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;It's been a little while since the last OpenSSH release, but 6.7 is almost ready&lt;/li&gt;
&lt;li&gt;Our friend &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener"&gt;Damien Miller&lt;/a&gt; issued a call for testing for the upcoming version, which includes a fair amount of new features&lt;/li&gt;
&lt;li&gt;It includes some old code removal, some new features and some internal reworkings - we'll cover the full list in detail when it's released&lt;/li&gt;
&lt;li&gt;This version also officially supports being built with LibreSSL now&lt;/li&gt;
&lt;li&gt;Help test it out and report any findings, especially if you have access to something a little more exotic than just a BSD system
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20yIP7VXa" target="_blank" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DeeUjAn6" target="_blank" rel="nofollow noopener"&gt;Lachlan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216imwEb0" target="_blank" rel="nofollow noopener"&gt;Francis writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2oc8vavWe" target="_blank" rel="nofollow noopener"&gt;Frank writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20wL61sSr" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, xinuos, cloud computing, hosting solution, nginx, webserver, httpd, spamd, atheros, wifi, aircrack-ng, kismet, defcon, wireless, bsdcan, hackathon, autofs, automounter, https, tls, ssl, openssh</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up on the show, we'll be showing you how to set up a secure, SSL-only webserver. There's also an interview with Eric Le Blan about community participation and FreeBSD's role in the commercial server space. All that and more, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2014/08/password-gropers-take-spamtrap-bait.html" target="_blank" rel="nofollow noopener">Password gropers take spamtrap bait</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener">Peter Hansteen</a>, who keeps his eyes glued to his log files, has a new blog post</li>
<li>He seems to have discovered another new weird phenomenon in his pop3 logs</li>
<li>"yes, I still run one, for the same bad reasons more than a third of my readers probably do: inertia"</li>
<li>Someone tried to log in to his service with an address that was known to be invalid</li>
<li>The rest of the post goes into detail about his theory of why someone would use a list of invalid addresses for this purpose
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=WOcYTqoSQ68" target="_blank" rel="nofollow noopener">Inside the Atheros wifi chipset</a></h3>

<ul>
<li>Adrian Chadd - sometimes known in the FreeBSD community as "the wireless guy" - gave a talk at the Defcon Wireless Village 2014</li>
<li>He covers a lot of topics on wifi, specifically on Atheros chips and why they're so popular for open source development</li>
<li>There's a lot of great information in the presentation, including cool (and evil) things you can do with wireless cards</li>
<li>Very technical talk; some parts might go over your head if you're not a driver developer</li>
<li>The raw video file is also available <a href="https://archive.org/download/WirelessVillageAtDefCon22/20-Atheros.mp4" target="_blank" rel="nofollow noopener">to download</a> on archive.org</li>
<li>Adrian has also recently worked on getting Kismet and Aircrack-NG to work better with FreeBSD, including packet injection and other fun things
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener">Trip report and hackathon mini-roundup</a></h3>

<ul>
<li>A few more (late) reports from BSDCan and the latest OpenBSD hackathon have been posted</li>
<li>Mark Linimon mentions some of the future plans for FreeBSD's release engineering and ports</li>
<li>Bapt <a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-baptiste-daroussin.html" target="_blank" rel="nofollow noopener">also has a BSDCan report</a> detailing his work on ports and packages</li>
<li>Antoine Jacoutot <a href="http://undeadly.org/cgi?action=article&amp;sid=20140812064946" target="_blank" rel="nofollow noopener">writes about</a> his work at the most recent hackathon, working with rc configuration and a new /etc/examples layout</li>
<li>Peter Hessler, a latecomer to the hackathon, <a href="http://undeadly.org/cgi?action=article&amp;sid=20140806125308" target="_blank" rel="nofollow noopener">details his experience</a> too, hacking on the installer and built-in upgrade function</li>
<li>Christian Weisgerber <a href="http://undeadly.org/cgi?action=article&amp;sid=20140803122705" target="_blank" rel="nofollow noopener">talks about</a> starting some initial improvements of OpenBSD's ports infrastructure
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-August/270573.html" target="_blank" rel="nofollow noopener">DragonFly BSD 3.8.2 released</a></h3>

<ul>
<li>Although it was already branched, the release media is now available for DragonFly 3.8.2</li>
<li>This is a minor update, mostly to fix the recent OpenSSL vulnerabilities</li>
<li>It also includes some various other small fixes
***</li>
</ul>

<h2>Interview - Eric Le Blan - <a href="mailto:info@xinuos.com" target="_blank" rel="nofollow noopener">info@xinuos.com</a></h2>

<p>Xinuos' recent FreeBSD integration, BSD in the commercial server space</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/nginx" target="_blank" rel="nofollow noopener">Building a hardened, feature-rich webserver</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://networkfilter.blogspot.com/2014/08/defend-your-network-and-privacy-vpn.html" target="_blank" rel="nofollow noopener">Defend your network and privacy, FreeBSD version</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" target="_blank" rel="nofollow noopener">episode 39</a>, we covered a blog post about creating an OpenBSD gateway - partly based on <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">our tutorial</a></li>
<li>This is a follow-up post, by the same author, about doing a similar thing with FreeBSD</li>
<li>He mentions some of the advantages and disadvantages between the two operating systems, and encourages users to decide for themselves which one suits their needs</li>
<li>The rest is pretty much the same things: firewall, VPN, DHCP server, DNSCrypt, etc.
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/dont-encrypt-all-the-things" target="_blank" rel="nofollow noopener">Don't encrypt all the things</a></h3>

<ul>
<li>Another couple of interesting blog posts from <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> about encryption</li>
<li>It talks about how Google recently started ranking sites with HTTPS higher in their search results, and then reflects on how sometimes encryption does more harm than good</li>
<li>After heartbleed, the ones who might be able to decrypt your emails went from just a three-letter agency to any script kiddie</li>
<li>He also talks a bit about some PGP weaknesses and a possible future replacement</li>
<li>He also has another, similar post entitled "<a href="http://www.tedunangst.com/flak/post/in-defense-of-opportunistic-encryption" target="_blank" rel="nofollow noopener">in defense of opportunistic encryption</a>"
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=270096" target="_blank" rel="nofollow noopener">New automounter lands in FreeBSD</a></h3>

<ul>
<li>The work on the new automounter has just landed in 11-CURRENT</li>
<li>With help from the FreeBSD Foundation, we'll have a new "autofs" kernel option</li>
<li>Check the SVN viewer online to read over the man pages if you're not running -CURRENT</li>
<li>You can also read a bit about it in the <a href="https://www.freebsdfoundation.org/press/2014jul-newsletter#Project3" target="_blank" rel="nofollow noopener">recent newsletter</a>
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-August/032810.html" target="_blank" rel="nofollow noopener">OpenSSH 6.7 CFT</a></h3>

<ul>
<li>It's been a little while since the last OpenSSH release, but 6.7 is almost ready</li>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">Damien Miller</a> issued a call for testing for the upcoming version, which includes a fair amount of new features</li>
<li>It includes some old code removal, some new features and some internal reworkings - we'll cover the full list in detail when it's released</li>
<li>This version also officially supports being built with LibreSSL now</li>
<li>Help test it out and report any findings, especially if you have access to something a little more exotic than just a BSD system
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20yIP7VXa" target="_blank" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DeeUjAn6" target="_blank" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s216imwEb0" target="_blank" rel="nofollow noopener">Francis writes in</a></li>
<li><a href="http://slexy.org/view/s2oc8vavWe" target="_blank" rel="nofollow noopener">Frank writes in</a></li>
<li><a href="http://slexy.org/view/s20wL61sSr" target="_blank" rel="nofollow noopener">Sean writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up on the show, we'll be showing you how to set up a secure, SSL-only webserver. There's also an interview with Eric Le Blan about community participation and FreeBSD's role in the commercial server space. All that and more, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2014/08/password-gropers-take-spamtrap-bait.html" target="_blank" rel="nofollow noopener">Password gropers take spamtrap bait</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" target="_blank" rel="nofollow noopener">Peter Hansteen</a>, who keeps his eyes glued to his log files, has a new blog post</li>
<li>He seems to have discovered another new weird phenomenon in his pop3 logs</li>
<li>"yes, I still run one, for the same bad reasons more than a third of my readers probably do: inertia"</li>
<li>Someone tried to log in to his service with an address that was known to be invalid</li>
<li>The rest of the post goes into detail about his theory of why someone would use a list of invalid addresses for this purpose
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=WOcYTqoSQ68" target="_blank" rel="nofollow noopener">Inside the Atheros wifi chipset</a></h3>

<ul>
<li>Adrian Chadd - sometimes known in the FreeBSD community as "the wireless guy" - gave a talk at the Defcon Wireless Village 2014</li>
<li>He covers a lot of topics on wifi, specifically on Atheros chips and why they're so popular for open source development</li>
<li>There's a lot of great information in the presentation, including cool (and evil) things you can do with wireless cards</li>
<li>Very technical talk; some parts might go over your head if you're not a driver developer</li>
<li>The raw video file is also available <a href="https://archive.org/download/WirelessVillageAtDefCon22/20-Atheros.mp4" target="_blank" rel="nofollow noopener">to download</a> on archive.org</li>
<li>Adrian has also recently worked on getting Kismet and Aircrack-NG to work better with FreeBSD, including packet injection and other fun things
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener">Trip report and hackathon mini-roundup</a></h3>

<ul>
<li>A few more (late) reports from BSDCan and the latest OpenBSD hackathon have been posted</li>
<li>Mark Linimon mentions some of the future plans for FreeBSD's release engineering and ports</li>
<li>Bapt <a href="http://freebsdfoundation.blogspot.com/2014/08/bsdcan-trip-report-baptiste-daroussin.html" target="_blank" rel="nofollow noopener">also has a BSDCan report</a> detailing his work on ports and packages</li>
<li>Antoine Jacoutot <a href="http://undeadly.org/cgi?action=article&amp;sid=20140812064946" target="_blank" rel="nofollow noopener">writes about</a> his work at the most recent hackathon, working with rc configuration and a new /etc/examples layout</li>
<li>Peter Hessler, a latecomer to the hackathon, <a href="http://undeadly.org/cgi?action=article&amp;sid=20140806125308" target="_blank" rel="nofollow noopener">details his experience</a> too, hacking on the installer and built-in upgrade function</li>
<li>Christian Weisgerber <a href="http://undeadly.org/cgi?action=article&amp;sid=20140803122705" target="_blank" rel="nofollow noopener">talks about</a> starting some initial improvements of OpenBSD's ports infrastructure
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-August/270573.html" target="_blank" rel="nofollow noopener">DragonFly BSD 3.8.2 released</a></h3>

<ul>
<li>Although it was already branched, the release media is now available for DragonFly 3.8.2</li>
<li>This is a minor update, mostly to fix the recent OpenSSL vulnerabilities</li>
<li>It also includes some various other small fixes
***</li>
</ul>

<h2>Interview - Eric Le Blan - <a href="mailto:info@xinuos.com" target="_blank" rel="nofollow noopener">info@xinuos.com</a></h2>

<p>Xinuos' recent FreeBSD integration, BSD in the commercial server space</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/nginx" target="_blank" rel="nofollow noopener">Building a hardened, feature-rich webserver</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://networkfilter.blogspot.com/2014/08/defend-your-network-and-privacy-vpn.html" target="_blank" rel="nofollow noopener">Defend your network and privacy, FreeBSD version</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" target="_blank" rel="nofollow noopener">episode 39</a>, we covered a blog post about creating an OpenBSD gateway - partly based on <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">our tutorial</a></li>
<li>This is a follow-up post, by the same author, about doing a similar thing with FreeBSD</li>
<li>He mentions some of the advantages and disadvantages between the two operating systems, and encourages users to decide for themselves which one suits their needs</li>
<li>The rest is pretty much the same things: firewall, VPN, DHCP server, DNSCrypt, etc.
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/dont-encrypt-all-the-things" target="_blank" rel="nofollow noopener">Don't encrypt all the things</a></h3>

<ul>
<li>Another couple of interesting blog posts from <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> about encryption</li>
<li>It talks about how Google recently started ranking sites with HTTPS higher in their search results, and then reflects on how sometimes encryption does more harm than good</li>
<li>After heartbleed, the ones who might be able to decrypt your emails went from just a three-letter agency to any script kiddie</li>
<li>He also talks a bit about some PGP weaknesses and a possible future replacement</li>
<li>He also has another, similar post entitled "<a href="http://www.tedunangst.com/flak/post/in-defense-of-opportunistic-encryption" target="_blank" rel="nofollow noopener">in defense of opportunistic encryption</a>"
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=270096" target="_blank" rel="nofollow noopener">New automounter lands in FreeBSD</a></h3>

<ul>
<li>The work on the new automounter has just landed in 11-CURRENT</li>
<li>With help from the FreeBSD Foundation, we'll have a new "autofs" kernel option</li>
<li>Check the SVN viewer online to read over the man pages if you're not running -CURRENT</li>
<li>You can also read a bit about it in the <a href="https://www.freebsdfoundation.org/press/2014jul-newsletter#Project3" target="_blank" rel="nofollow noopener">recent newsletter</a>
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-August/032810.html" target="_blank" rel="nofollow noopener">OpenSSH 6.7 CFT</a></h3>

<ul>
<li>It's been a little while since the last OpenSSH release, but 6.7 is almost ready</li>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">Damien Miller</a> issued a call for testing for the upcoming version, which includes a fair amount of new features</li>
<li>It includes some old code removal, some new features and some internal reworkings - we'll cover the full list in detail when it's released</li>
<li>This version also officially supports being built with LibreSSL now</li>
<li>Help test it out and report any findings, especially if you have access to something a little more exotic than just a BSD system
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20yIP7VXa" target="_blank" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DeeUjAn6" target="_blank" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s216imwEb0" target="_blank" rel="nofollow noopener">Francis writes in</a></li>
<li><a href="http://slexy.org/view/s2oc8vavWe" target="_blank" rel="nofollow noopener">Frank writes in</a></li>
<li><a href="http://slexy.org/view/s20wL61sSr" target="_blank" rel="nofollow noopener">Sean writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
