<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app03</fireside:hostname>
    <fireside:genDate>Fri, 26 Jun 2026 22:30:55 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Openssl”</title>
    <link>https://www.bsdnow.tv/tags/openssl</link>
    <pubDate>Thu, 10 Dec 2020 06:00:00 -0500</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>380: Early ZFS-mas</title>
  <link>https://www.bsdnow.tv/380</link>
  <guid isPermaLink="false">ee24cdc7-bb47-400d-8be0-968efefa4e15</guid>
  <pubDate>Thu, 10 Dec 2020 06:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/ee24cdc7-bb47-400d-8be0-968efefa4e15.mp3" length="43761336" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We read FreeBSD’s 3rd quarter status report, OpenZFS 2.0, adding check-hash checks in UFS filesystem, OpenSSL 3.0 /dev/crypto issues on FreeBSD, and more.</itunes:subtitle>
  <itunes:duration>43:59</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We read FreeBSD’s 3rd quarter status report, OpenZFS 2.0, adding check-hash checks in UFS filesystem, OpenSSL 3.0 /dev/crypto issues on FreeBSD, and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2020-07-2020-09.html" rel="nofollow noopener"&gt;3rd Quarter FreeBSD Report&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-quarterly-calls/2020/000007.html" rel="nofollow noopener"&gt;The call for submissions for the 4th Quarter is out&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;
&lt;/blockquote&gt;

&lt;h3&gt;&lt;a href="https://arstechnica.com/gadgets/2020/12/openzfs-2-0-release-unifies-linux-bsd-and-adds-tons-of-new-features/" rel="nofollow noopener"&gt;OpenZFS 2.0&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;This Monday, ZFS on Linux lead developer Brian Behlendorf published the OpenZFS 2.0.0 release to GitHub. Along with quite a lot of new features, the announcement brings an end to the former distinction between "ZFS on Linux" and ZFS elsewhere (for example, on FreeBSD). This move has been a long time coming—the FreeBSD community laid out its side of the roadmap two years ago—but this is the release that makes it official.&lt;/p&gt;

&lt;hr&gt;
&lt;/blockquote&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/changeset/base/367034" rel="nofollow noopener"&gt;Revision 367034&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Various new check-hash checks have been added to the UFS filesystem&lt;br&gt;
over various major releases. Superblock check hashes were added for&lt;br&gt;
the 12 release and cylinder-group and inode check hashes will appear&lt;br&gt;
in the 13 release.&lt;/p&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://rubenerd.com/openssl-3-written-to-break-on-freebsd/" rel="nofollow noopener"&gt;OpenSSL 3.0 /dev/crypto issues on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;p&gt;So, just learned that the OpenSSL devs decided to break /dev/crypto on FreeBSD.&lt;/p&gt;

&lt;hr&gt;
&lt;/blockquote&gt;

&lt;h3&gt;&lt;a href="https://forums.os108.org/d/32-os108-91-xfce-amd64-released" rel="nofollow noopener"&gt;OS108-9.1 XFCE amd64 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OS108 is a fast, open and Secure Desktop Operating System built on top of NetBSD.
&amp;gt; Installing OS108 to your hard drive is done by using the sysinst utility, the process is basically the same as installing NetBSD itself.  Please refer to the NetBSD guide for installation details, &lt;a href="http://www.netbsd.org/docs/guide/en/part-install.html" rel="nofollow noopener"&gt;http://www.netbsd.org/docs/guide/en/part-install.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/cgAeY21gXR4" rel="nofollow noopener"&gt;Installation Video&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.openbgpd.org/ftp.html" rel="nofollow noopener"&gt;OpenBGPD 6.8p1 portable: released Nov 5th, 2020&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://kflu.github.io/2020/08/15/2020-08-15-awk-irc-bot/" rel="nofollow noopener"&gt;IRC Awk Bot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=ZVkJZJEdZNY" rel="nofollow noopener"&gt;Docker on FreeBSD using bhyve and sshfs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/susam/tucl" rel="nofollow noopener"&gt;The UNIX Command Language (1976)&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/santi%20-%20openrc.md" rel="nofollow noopener"&gt;santi - openrc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/trond%20-%20python2%20and%20mailmane%20and%20sshfs" rel="nofollow noopener"&gt;trond - python2 and mailman&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, status, report, third quarter 2020, openzfs 2.0, check hash, ufs, openssl, os108-9.1, xfce</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We read FreeBSD’s 3rd quarter status report, OpenZFS 2.0, adding check-hash checks in UFS filesystem, OpenSSL 3.0 /dev/crypto issues on FreeBSD, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2020-07-2020-09.html" rel="nofollow noopener">3rd Quarter FreeBSD Report</a></h3>

<blockquote>
<p><a href="https://lists.freebsd.org/pipermail/freebsd-quarterly-calls/2020/000007.html" rel="nofollow noopener">The call for submissions for the 4th Quarter is out</a></p>

<hr>
</blockquote>

<h3><a href="https://arstechnica.com/gadgets/2020/12/openzfs-2-0-release-unifies-linux-bsd-and-adds-tons-of-new-features/" rel="nofollow noopener">OpenZFS 2.0</a></h3>

<blockquote>
<p>This Monday, ZFS on Linux lead developer Brian Behlendorf published the OpenZFS 2.0.0 release to GitHub. Along with quite a lot of new features, the announcement brings an end to the former distinction between "ZFS on Linux" and ZFS elsewhere (for example, on FreeBSD). This move has been a long time coming—the FreeBSD community laid out its side of the roadmap two years ago—but this is the release that makes it official.</p>

<hr>
</blockquote>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/changeset/base/367034" rel="nofollow noopener">Revision 367034</a></h3>

<blockquote>
<p>Various new check-hash checks have been added to the UFS filesystem<br>
over various major releases. Superblock check hashes were added for<br>
the 12 release and cylinder-group and inode check hashes will appear<br>
in the 13 release.</p>

<hr>

<h3><a href="https://rubenerd.com/openssl-3-written-to-break-on-freebsd/" rel="nofollow noopener">OpenSSL 3.0 /dev/crypto issues on FreeBSD</a></h3>

<p>So, just learned that the OpenSSL devs decided to break /dev/crypto on FreeBSD.</p>

<hr>
</blockquote>

<h3><a href="https://forums.os108.org/d/32-os108-91-xfce-amd64-released" rel="nofollow noopener">OS108-9.1 XFCE amd64 released</a></h3>

<ul>
<li>OS108 is a fast, open and Secure Desktop Operating System built on top of NetBSD.
&gt; Installing OS108 to your hard drive is done by using the sysinst utility, the process is basically the same as installing NetBSD itself.  Please refer to the NetBSD guide for installation details, <a href="http://www.netbsd.org/docs/guide/en/part-install.html" rel="nofollow noopener">http://www.netbsd.org/docs/guide/en/part-install.html</a></li>
<li><a href="https://youtu.be/cgAeY21gXR4" rel="nofollow noopener">Installation Video</a>
***</li>
</ul>

<h2>Beastie Bits</h2>

<ul>
<li><a href="http://www.openbgpd.org/ftp.html" rel="nofollow noopener">OpenBGPD 6.8p1 portable: released Nov 5th, 2020</a></li>
<li><a href="http://kflu.github.io/2020/08/15/2020-08-15-awk-irc-bot/" rel="nofollow noopener">IRC Awk Bot</a></li>
<li><a href="https://www.youtube.com/watch?v=ZVkJZJEdZNY" rel="nofollow noopener">Docker on FreeBSD using bhyve and sshfs</a></li>
<li><a href="https://github.com/susam/tucl" rel="nofollow noopener">The UNIX Command Language (1976)</a>
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/santi%20-%20openrc.md" rel="nofollow noopener">santi - openrc</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/trond%20-%20python2%20and%20mailmane%20and%20sshfs" rel="nofollow noopener">trond - python2 and mailman</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We read FreeBSD’s 3rd quarter status report, OpenZFS 2.0, adding check-hash checks in UFS filesystem, OpenSSL 3.0 /dev/crypto issues on FreeBSD, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2020-07-2020-09.html" rel="nofollow noopener">3rd Quarter FreeBSD Report</a></h3>

<blockquote>
<p><a href="https://lists.freebsd.org/pipermail/freebsd-quarterly-calls/2020/000007.html" rel="nofollow noopener">The call for submissions for the 4th Quarter is out</a></p>

<hr>
</blockquote>

<h3><a href="https://arstechnica.com/gadgets/2020/12/openzfs-2-0-release-unifies-linux-bsd-and-adds-tons-of-new-features/" rel="nofollow noopener">OpenZFS 2.0</a></h3>

<blockquote>
<p>This Monday, ZFS on Linux lead developer Brian Behlendorf published the OpenZFS 2.0.0 release to GitHub. Along with quite a lot of new features, the announcement brings an end to the former distinction between "ZFS on Linux" and ZFS elsewhere (for example, on FreeBSD). This move has been a long time coming—the FreeBSD community laid out its side of the roadmap two years ago—but this is the release that makes it official.</p>

<hr>
</blockquote>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/changeset/base/367034" rel="nofollow noopener">Revision 367034</a></h3>

<blockquote>
<p>Various new check-hash checks have been added to the UFS filesystem<br>
over various major releases. Superblock check hashes were added for<br>
the 12 release and cylinder-group and inode check hashes will appear<br>
in the 13 release.</p>

<hr>

<h3><a href="https://rubenerd.com/openssl-3-written-to-break-on-freebsd/" rel="nofollow noopener">OpenSSL 3.0 /dev/crypto issues on FreeBSD</a></h3>

<p>So, just learned that the OpenSSL devs decided to break /dev/crypto on FreeBSD.</p>

<hr>
</blockquote>

<h3><a href="https://forums.os108.org/d/32-os108-91-xfce-amd64-released" rel="nofollow noopener">OS108-9.1 XFCE amd64 released</a></h3>

<ul>
<li>OS108 is a fast, open and Secure Desktop Operating System built on top of NetBSD.
&gt; Installing OS108 to your hard drive is done by using the sysinst utility, the process is basically the same as installing NetBSD itself.  Please refer to the NetBSD guide for installation details, <a href="http://www.netbsd.org/docs/guide/en/part-install.html" rel="nofollow noopener">http://www.netbsd.org/docs/guide/en/part-install.html</a></li>
<li><a href="https://youtu.be/cgAeY21gXR4" rel="nofollow noopener">Installation Video</a>
***</li>
</ul>

<h2>Beastie Bits</h2>

<ul>
<li><a href="http://www.openbgpd.org/ftp.html" rel="nofollow noopener">OpenBGPD 6.8p1 portable: released Nov 5th, 2020</a></li>
<li><a href="http://kflu.github.io/2020/08/15/2020-08-15-awk-irc-bot/" rel="nofollow noopener">IRC Awk Bot</a></li>
<li><a href="https://www.youtube.com/watch?v=ZVkJZJEdZNY" rel="nofollow noopener">Docker on FreeBSD using bhyve and sshfs</a></li>
<li><a href="https://github.com/susam/tucl" rel="nofollow noopener">The UNIX Command Language (1976)</a>
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/santi%20-%20openrc.md" rel="nofollow noopener">santi - openrc</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/380/feedback/trond%20-%20python2%20and%20mailmane%20and%20sshfs" rel="nofollow noopener">trond - python2 and mailman</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>Episode 270: Ghostly Releases | BSD Now 270</title>
  <link>https://www.bsdnow.tv/270</link>
  <guid isPermaLink="false">http://feed.jupiter.zone/bsdnow#entry-2822</guid>
  <pubDate>Thu, 01 Nov 2018 07:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/83e21562-2f8c-4810-b4c6-0e8f3e36f95b.mp3" length="41653876" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>OpenBSD 6.4 released, GhostBSD RC2 released, MeetBSD - the ultimate hallway track, DragonflyBSD desktop on a Thinkpad, Porting keybase to NetBSD, OpenSSH 7.9, and draft-ietf-6man-ipv6only-flag in FreeBSD.</itunes:subtitle>
  <itunes:duration>1:09:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;OpenBSD 6.4 released, GhostBSD RC2 released, MeetBSD - the ultimate hallway track, DragonflyBSD desktop on a Thinkpad, Porting keybase to NetBSD, OpenSSH 7.9, and draft-ietf-6man-ipv6only-flag in FreeBSD.&lt;/p&gt;

&lt;p&gt;##Headlines&lt;br&gt;
###&lt;a href="https://www.openbsd.org/64.html" rel="nofollow noopener"&gt;OpenBSD 6.4 released&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.openbsd.org/plus64.html" rel="nofollow noopener"&gt;See a detailed log of changes between the 6.3 and 6.4 releases.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.openbsd.org/ftp.html" rel="nofollow noopener"&gt;See the information on the FTP page for a list of mirror machines.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.openbsd.org/errata64.html" rel="nofollow noopener"&gt;Have a look at the 6.4 errata page for a list of bugs and workarounds.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;signify(1) pubkeys for this release:&lt;/li&gt;
&lt;li&gt;base: RWQq6XmS4eDAcQW4KsT5Ka0KwTQp2JMOP9V/DR4HTVOL5Bc0D7LeuPwA&lt;/li&gt;
&lt;li&gt;fw:   RWRoBbjnosJ/39llpve1XaNIrrQND4knG+jSBeIUYU8x4WNkxz6a2K97&lt;/li&gt;
&lt;li&gt;pkg:  RWRF5TTY+LoN/51QD5kM2hKDtMTzycQBBPmPYhyQEb1+4pff/H6fh/kA&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;p&gt;###&lt;a href="https://www.ghostbsd.org/18.10_RC2_release_announcement" rel="nofollow noopener"&gt;GhostBSD 18.10 RC2 Announced&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;This second release candidate of GhostBSD 18.10 is the second official release of GhostBSD with TrueOS under the hood. The official desktop of GhostBSD is MATE. However, in the future, there might be an XFCE community release, but for now, there is no community release yet.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;What has changed since RC1&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Removed drm-stable-kmod and we will let users installed the propper drm-*-kmod&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Douglas Joachin added libva-intel-driver libva-vdpau-driver  to supports accelerated some video driver for Intel&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Issues that got fixed&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Bug #70 Cannot run Octopi, missing libgksu error.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Bug #71 LibreOffice doesn’t start because of missing libcurl.so.4&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Bug #72 libarchive is a missing dependency&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Again thanks to iXsystems, TrueOS, Joe Maloney, Kris Moore, Ken Moore, Martin Wilke, Neville Goddard, Vester “Vic” Thacker, Douglas Joachim, Alex Lyakhov, Yetkin Degirmenci and many more who helped to make the transition from FreeBSD to TrueOS smoother.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Updating from RC1 to RC2:&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;sudo pkg update -f&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;sudo pkg install -f libarchive curl libgksu&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;sudo pkg upgrade&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Where to download:&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;All images checksum, hybrid ISO(DVD, USB) and torrent are available here: &lt;a href="https://www.ghostbsd.org/download" rel="nofollow noopener"&gt;https://www.ghostbsd.org/download&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;[ScreenShots]&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png" rel="nofollow noopener"&gt;https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png" rel="nofollow noopener"&gt;https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;p&gt;###&lt;a href="https://www.openssh.com/txt/release-7.9" rel="nofollow noopener"&gt;OpenSSH 7.9 has been released and it has support for OpenSSL 1.1&lt;/a&gt;&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;Changes since OpenSSH 7.8
=========================

This is primarily a bugfix release.

New Features
------------
 * ssh(1), sshd(8): allow most port numbers to be specified using
   service names from getservbyname(3) (typically /etc/services).
 * ssh(1): allow the IdentityAgent configuration directive to accept
   environment variable names. This supports the use of multiple
   agent sockets without needing to use fixed paths.
 * sshd(8): support signalling sessions via the SSH protocol.
   A limited subset of signals is supported and only for login or
   command sessions (i.e. not subsystems) that were not subject to
   a forced command via authorized_keys or sshd_config. bz#1424
 * ssh(1): support "ssh -Q sig" to list supported signature options.
   Also "ssh -Q help" to show the full set of supported queries.
 * ssh(1), sshd(8): add a CASignatureAlgorithms option for the
   client and server configs to allow control over which signature
   formats are allowed for CAs to sign certificates. For example,
   this allows banning CAs that sign certificates using the RSA-SHA1
   signature algorithm.
 * sshd(8), ssh-keygen(1): allow key revocation lists (KRLs) to
   revoke keys specified by SHA256 hash.
 * ssh-keygen(1): allow creation of key revocation lists directly
   from base64-encoded SHA256 fingerprints. This supports revoking
   keys using only the information contained in sshd(8)
   authentication log messages.

Bugfixes
--------

 * ssh(1), ssh-keygen(1): avoid spurious "invalid format" errors when
   attempting to load PEM private keys while using an incorrect
   passphrase. bz#2901
 * sshd(8): when a channel closed message is received from a client,
   close the stderr file descriptor at the same time stdout is
   closed. This avoids stuck processes if they were waiting for
   stderr to close and were insensitive to stdin/out closing. bz#2863
 * ssh(1): allow ForwardX11Timeout=0 to disable the untrusted X11
   forwarding timeout and support X11 forwarding indefinitely.
   Previously the behaviour of ForwardX11Timeout=0 was undefined.
 * sshd(8): when compiled with GSSAPI support, cache supported method
   OIDs regardless of whether GSSAPI authentication is enabled in the
   main section of sshd_config. This avoids sandbox violations if
   GSSAPI authentication was later enabled in a Match block. bz#2107
 * sshd(8): do not fail closed when configured with a text key
   revocation list that contains a too-short key. bz#2897
 * ssh(1): treat connections with ProxyJump specified the same as
   ones with a ProxyCommand set with regards to hostname
   canonicalisation (i.e. don't try to canonicalise the hostname
   unless CanonicalizeHostname is set to 'always'). bz#2896
 * ssh(1): fix regression in OpenSSH 7.8 that could prevent public-
   key authentication using certificates hosted in a ssh-agent(1)
   or against sshd(8) from OpenSSH &amp;lt;7.8.

Portability
-----------

 * All: support building against the openssl-1.1 API (releases 1.1.0g
   and later). The openssl-1.0 API will remain supported at least
   until OpenSSL terminates security patch support for that API version.
 * sshd(8): allow the futex(2) syscall in the Linux seccomp sandbox;
   apparently required by some glibc/OpenSSL combinations.
 * sshd(8): handle getgrouplist(3) returning more than
   _SC_NGROUPS_MAX groups. Some platforms consider this limit more
   as a guideline.
&lt;/code&gt;&lt;/pre&gt;

&lt;hr&gt;

&lt;p&gt;##News Roundup&lt;/p&gt;

&lt;p&gt;###&lt;a href="https://www.ixsystems.com/blog/meetbsd-2018/" rel="nofollow noopener"&gt;MeetBSD 2018: The Ultimate Hallway Track&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Founded in Poland in 2007 and first hosted in California in 2008, MeetBSD combines formal talks with UnConference activities to provide a level of interactivity not found at any other BSD conference. The character of each MeetBSD is determined largely by its venue, ranging from Hacker Dojo in 2010 to Intel’s Santa Clara headquarters this year. The Intel SC12 building provided a beautiful auditorium and sponsors’ room, plus a cafeteria for the Friday night social event and the Saturday night FreeBSD 25th Anniversary Celebration. The formal nature of the auditorium motivated the formation of MeetBSD’s first independent Program Committee and public Call for Participation. Together these resulted in a backbone of talks presented by speakers from the USA, Canada, and Poland, combined with UnConference activities tailored to the space.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;MeetBSD Day 0&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Day Zero of MeetBSD was a FreeBSD Developer/Vendor Summit hosted in the same auditorium where the talks would take place. Like the conference itself, this event featured a mix of scheduled talks and interactive sessions. The scheduled talks were LWPMFS: LightWeight Persistent Memory Filesystem by Ravi Pokala, Evaluating GIT for FreeBSD by Ed Maste, and NUMA by Mark Johnston. Ed’s overview of the advantages and disadvantages of using Git for FreeBSD development was of the most interest to users and developers, and the discussion continued into the following two days.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;MeetBSD Day 1&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;The first official day of MeetBSD 2018 was kicked off with introductions led by emcee JT Pennington and a keynote, “Using TrueOS to boot-strap your FreeBSD-based project” by Kris Moore. Kris described a new JSON-based release infrastructure that he has exercised with FreeBSD, TrueOS, and FreeNAS. Kris’ talk was followed by “Intel &amp;amp; FreeBSD: Better Together” by Ben Widawsky, the FreeBSD program lead at Intel, who gave an overview of Intel’s past and current efforts supporting FreeBSD. Next came lunch, followed by Kamil Rytarowski’s “Bug detecting software in the NetBSD userland: MKSANITIZER”. This was followed by 5-Minute Lightning Talks, Andrew Fengler’s “FreeBSD: What to (Not) Monitor”, and an OpenZFS Panel Discussion featuring OpenZFS experts Michael W. Lucas, Allan Jude, Alexander Motin, Pawel Dawidek, and Dan Langille. Day one concluded with a social event at the Intel cafeteria where the discussions continued into the night.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;MeetBSD Day 2&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Day Two of MeetBSD 2018 kicked off with a keynote by Michael W. Lucas entitled “Why BSD?”, where Michael detailed what makes the BSD community different and why it attracts us all. This was followed by Dr. Kirk McKusick’s “The Early Days of BSD” talk, which was followed by “DTrace/dwatch in Production” by Devin Teske. After lunch, we enjoyed “A Curmudgeon’s Language Selection Criteria: Why I Don’t Write Everything in Go, Rust, Elixir, etc” by G. Clifford Williams and, “Best practices of sandboxing applications with Capsicum” by Mariusz Zaborski. I then hosted a Virtualization Panel Discussion that featured eight developers from FreeBSD, OpenBSD, and NetBSD. We then split up for Breakout Sessions and the one on Bloomberg’s controversial article on backdoored Supermicro systems was fascinating given the experts present, all of whom were skeptical of the feasibility of the attack. The day wrapped up with a final talk, “Tales of a Daemontown Performance Peddler: Why ‘it depends’ and what you can do about it” by Nick Principe, followed by the FreeBSD 25th Anniversary Celebration.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Putting the “meet” in MeetBSD&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;I confess the other organizers and I were nervous about how well one large auditorium would suit a BSD event but the flexible personal space it gave everyone allowed for countless meetings and heated hacking that often brought about immediate results. I watched people take ideas through several iterations with the help and input of obvious and unexpected experts, all of whom were within reach. Not having to pick up and leave for a talk in another room organically resulted in essentially a series of mini hackathons that none of us anticipated but were delighted to witness, taking the “hallway track” to a whole new level. The mix of formal and UnConference activities at MeetBSD is certain to evolve. Thank you to everyone who participated with questions, Lightning Talks, and Panel participation. A huge thanks to our sponsors, including Intel for both hosting and sponsoring MeetBSD California 2018, Western Digital, Supermicro, Verisign, Jupiter Broadcasting, the FreeBSD Foundation, Bank of America Merrill Lynch, the NetBSD Foundation, and the team at iXsystems.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;blockquote&gt;
&lt;p&gt;See you at MeetBSD 2020!&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;p&gt;###&lt;a href="https://panoramacircle.com/2018/10/07/setup-dragonflybsd-with-a-desktop-on-real-hardware-thinkpad-t410/" rel="nofollow noopener"&gt;Setup DragonflyBSD with a desktop on real hardware ThinkPad T410&lt;/a&gt;&lt;br&gt;
+&lt;a href="https://youtu.be/p4KwssNY82Q" rel="nofollow noopener"&gt;Video Demo&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Linux has become too mainstream and standard BSD is a common thing now? How about DragonflyBSD which was created as a fork of FreeBSD 4.8 in conflict over system internals. This tutorial will show how to install it and set up a user-oriented desktop. It should work with DragonflyBSD, FreeBSD and probably all BSDs.&lt;br&gt;
Some background: BSD was is ultimately derived from UNIX back in the days. It is not Linux even though it is similar in many ways because Linux was designed to follow UNIX principles. Seeing is believing, so check out the video of the install!&lt;br&gt;
I did try two BSD distros before called GhostBSD and TrueOS and you can check out my short reviews. DragonflyBSD comes like FreeBSD bare bones and requires some work to get a desktop running.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Download image file and burn to USB drive or DVD&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;First installation&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Setting up the system and installing a desktop&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Inside the desktop&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Install some more programs&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;How to enable sound?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Let’s play some free games&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Setup WiFi&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Power mode settings&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;More to do?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;You can check out this blog post if you want a much more detailed tutorial. If you don’t mind standard BSD, get the GhostBSD distro instead which comes with a ready-made desktop xcfe or mate and many functional presets.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;A small summary of what we got on the upside:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Free and open source operating system with a long history&lt;/li&gt;
&lt;li&gt;Drivers worked fine including Ethernet, WiFi, video 2D &amp;amp; 3D, audio, etc&lt;/li&gt;
&lt;li&gt;Hammer2 advanced file system&lt;/li&gt;
&lt;li&gt;You are very unique if you use this OS fork&lt;/li&gt;
&lt;/ul&gt;

&lt;/li&gt;&lt;br&gt;
&lt;li&gt;

&lt;p&gt;Some downsides:&lt;/p&gt;

&lt;/li&gt;&lt;br&gt;
&lt;li&gt;

&lt;p&gt;Less driver and direct app support than Linux&lt;/p&gt;

&lt;/li&gt;&lt;br&gt;
&lt;li&gt;

&lt;p&gt;Installer and desktop have some traps and quirks and require work&lt;/p&gt;

&lt;/li&gt;&lt;br&gt;
&lt;/ul&gt;&lt;br&gt;
&lt;hr&gt;

&lt;p&gt;###&lt;a href="https://dressupgeekout.blogspot.com/2018/10/porting-keybase-to-netbsd.html" rel="nofollow noopener"&gt;Porting Keybase to NetBSD&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Keybase significantly simplifies the whole keypair/PGP thing and makes what is usually a confusing, difficult experience actually rather pleasant. At its heart is an open-source command line utility that does all of the heavy cryptographic lifting. But it’s also hooked up to the network of all other Keybase users, so you don’t have to work very hard to maintain big keychains. Pretty cool!&lt;br&gt;
So, this evening, I tried to get it to all work on NetBSD.&lt;br&gt;
The Keybase client code base is, in my opinion, not very well architected… there exist many different Keybase clients (command line apps, desktop apps, mobile apps) and for some reason the code for all of them are seemingly in this single repository, without even using Git submodules. Not sure what that’s about.&lt;br&gt;
Anyway, “go build”-ing the command line program (it’s written in Go) failed immediately because there’s some platform-specific code that just does not seem to recognize that NetBSD exists (but they do for FreeBSD and OpenBSD). Looks like the Keybase developers maintain a Golang wrapper around struct proc, which of course is different from OS to OS. So I literally just copypasted the OpenBSD wrapper, renamed it to “NetBSD”, and the build basically succeeded from there! This is of course super janky and untrustworthy, but it seems to Mostly Just Work…&lt;br&gt;
I forked the GitHub repo, you can see the diff on top of keybase 2.7.3 here: bccaaf3096a&lt;br&gt;
Eventually I ended up with a ~/go/bin/keybase which launches just fine. Meaning, I can main() okay. But the moment you try to do anything interesting, it looks super scary:&lt;/p&gt;
&lt;/blockquote&gt;

&lt;pre&gt;&lt;code&gt;charlotte@sakuracity:~/go/bin ./keybase login
▶ WARNING Running in devel mode
▶ INFO Forking background server with pid=12932
▶ ERROR unexpected error in Login: API network error: doRetry failed,
attempts: 1, timeout 5s, last err: Get
http://localhost:3000/_/api/1.0/merkle/path.json?last=3784314&amp;amp;load_deleted=1&amp;amp;load_reset_chain=1&amp;amp;poll=10&amp;amp;sig_hints_low=3&amp;amp;uid=38ae1dfa49cd6831ea2fdade5c5d0519:
dial tcp [::1]:3000: connect: connection refused
&lt;/code&gt;&lt;/pre&gt;

&lt;blockquote&gt;
&lt;p&gt;There’s a few things about this error message that stuck out to me:&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Forking a background server? What?&lt;/li&gt;
&lt;li&gt;It’s trying to connect to localhost? That must be the server that doesn’t work …&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Unfortunately, this nonfunctional “background server” sticks around even when a command as simple as ‘login’ command just failed:&lt;/p&gt;
&lt;/blockquote&gt;

&lt;pre&gt;&lt;code&gt;charlotte@sakuracity:~/go/bin ps 12932
  PID TTY STAT    TIME COMMAND
  12932 ?   Ssl  0:00.21 ./keybase --debug --log-file
  /home/charlotte/.cache/keybase.devel/keybase.service.log service --chdir
  /home/charlotte/.config/keybase.devel --auto-forked 
&lt;/code&gt;&lt;/pre&gt;

&lt;blockquote&gt;
&lt;p&gt;I’m not exactly sure what the intended purpose of the “background server” even is, but fortunately we can kill it and even tell the keybase command to not even spawn one:&lt;/p&gt;
&lt;/blockquote&gt;

&lt;pre&gt;&lt;code&gt;charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --standalone
   --standalone                         Use the client without any daemon support.
&lt;/code&gt;&lt;/pre&gt;

&lt;blockquote&gt;
&lt;p&gt;And then we can fix wanting to connect to localhost by specifying an expected Keybase API server – how about the one hosted at &lt;a href="https://keybase.io" rel="nofollow noopener"&gt;https://keybase.io&lt;/a&gt;?&lt;/p&gt;
&lt;/blockquote&gt;

&lt;pre&gt;&lt;code&gt;charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --server
   --server, -s                         Specify server API.
&lt;/code&gt;&lt;/pre&gt;

&lt;blockquote&gt;
&lt;p&gt;Basically, what I’m trying to say is that if you specify both of these options, the keybase command does what I expect on NetBSD:&lt;/p&gt;
&lt;/blockquote&gt;

&lt;pre&gt;&lt;code&gt;charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io login
▶ WARNING Running in devel mode
Please enter the Keybase passphrase for dressupgeekout (6+ characters): 

charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io id dressupgeekout
▶ WARNING Running in devel mode
▶ INFO Identifying dressupgeekout
✔ public key fingerprint: 7873 DA50 A786 9A3F 1662 3A17 20BD 8739 E82C 7F2F
✔ "dressupgeekout" on github:
https://gist.github.com/0471c7918d254425835bf5e1b4bcda00 [cached 2018-10-11
20:55:21 PDT]
✔ "dressupgeekout" on reddit:
https://www.reddit.com/r/KeybaseProofs/comments/9ng5qm/my_keybase_proof_redditdressupgeekout/
[cached 2018-10-11 20:55:21 PDT]
&lt;/code&gt;&lt;/pre&gt;

&lt;hr&gt;

&lt;p&gt;###&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=339929" rel="nofollow noopener"&gt;Initial implementation of draft-ietf-6man-ipv6only-flag&lt;/a&gt;&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;This change defines the RA "6" (IPv6-Only) flag which routers
may advertise, kernel logic to check if all routers on a link
have the flag set and accordingly update a per-interface flag.

If all routers agree that it is an IPv6-only link, ether_output_frame(),
based on the interface flag, will filter out all ETHERTYPE_IP/ARP
frames, drop them, and return EAFNOSUPPORT to upper layers.

The change also updates ndp to show the "6" flag, ifconfig to
display the IPV6_ONLY nd6 flag if set, and rtadvd to allow
announcing the flag.

Further changes to tcpdump (contrib code) are availble and will
be upstreamed.

Tested the code (slightly earlier version) with 2 FreeBSD
IPv6 routers, a FreeBSD laptop on ethernet as well as wifi,
and with Win10 and OSX clients (which did not fall over with
the "6" flag set but not understood).

We may also want to (a) implement and RX filter, and (b) over
time enahnce user space to, say, stop dhclient from running
when the interface flag is set.  Also we might want to start
IPv6 before IPv4 in the future.

All the code is hidden under the EXPERIMENTAL option and not
compiled by default as the draft is a work-in-progress and
we cannot rely on the fact that IANA will assign the bits
as requested by the draft and hence they may change.

Dear 6man, you have running code.

Discussed with: Bob Hinden, Brian E Carpenter
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;##Beastie Bits&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://dan.langille.org/2018/10/02/running-freebsd-on-osx-using-xhyve-a-port-of-bhyve/" rel="nofollow noopener"&gt;Running FreeBSD on macOS via xhyve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mwl.io/archives/3841" rel="nofollow noopener"&gt;Auction Winners&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/vedetta-com/vedetta/blob/master/src/usr/local/share/doc/vedetta/OpenSSH_Principals.md" rel="nofollow noopener"&gt;OpenSSH Principals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://undeadly.org/cgi?action=article;sid=20181018160645" rel="nofollow noopener"&gt;OpenBSD Foundation gets a second Iridium donation from Handshake&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2018/10/10/msg000786.html" rel="nofollow noopener"&gt;NetBSD machines at Open Source Conference 2018 Kagawa&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mwl.io/archives/3818" rel="nofollow noopener"&gt;Absolute FreeBSD now shipping!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://h3artbl33d.nl/blog/nextcloud-on-openbsd" rel="nofollow noopener"&gt;NextCloud on OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.freebsd.org/news/newsflash.html#event20181027:01" rel="nofollow noopener"&gt;FreeBSD 12.0-BETA2 Available&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/gvnn3/status/1049347862541344771" rel="nofollow noopener"&gt;DTrace on Windows ported from FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://dpaste.com/36DFQ1S" rel="nofollow noopener"&gt;HELBUG fall 2018 meeting scheduled - Thursday the 15th of November&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://translate.google.com/translate?hl=de&amp;amp;sl=de&amp;amp;tl=en&amp;amp;u=https%3A%2F%2Ftickets.events.ccc.de%2F35c3%2Fintro%2F" rel="nofollow noopener"&gt;35C3 pre-sale has started&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.meetup.com/BSD-Users-Stockholm/events/254235663/" rel="nofollow noopener"&gt;Stockholm BSD User Meeting: Tuesday Nov 13, 18:00 - 21:30  &lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://bsd-pl.org/en" rel="nofollow noopener"&gt;Polish BSD User Group: Thursday Nov 15, 18:30 - 21:00 &lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;p&gt;##Feedback/Questions&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Greg - &lt;a href="http://dpaste.com/1WA54CC" rel="nofollow noopener"&gt;Interview suggestion for the show&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Nelson - &lt;a href="http://dpaste.com/21KKF7Q#wrap" rel="nofollow noopener"&gt;Ghostscript vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Allison - &lt;a href="http://dpaste.com/3K6D7ST" rel="nofollow noopener"&gt;Ports and GCC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt; 
</description>
  <itunes:keywords>freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview,ghostbsd,keybase,openssh,openssl</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>OpenBSD 6.4 released, GhostBSD RC2 released, MeetBSD - the ultimate hallway track, DragonflyBSD desktop on a Thinkpad, Porting keybase to NetBSD, OpenSSH 7.9, and draft-ietf-6man-ipv6only-flag in FreeBSD.</p>

<p>##Headlines<br>
###<a href="https://www.openbsd.org/64.html" rel="nofollow noopener">OpenBSD 6.4 released</a></p>

<ul>
<li><a href="https://www.openbsd.org/plus64.html" rel="nofollow noopener">See a detailed log of changes between the 6.3 and 6.4 releases.</a></li>
<li><a href="https://www.openbsd.org/ftp.html" rel="nofollow noopener">See the information on the FTP page for a list of mirror machines.</a></li>
<li><a href="https://www.openbsd.org/errata64.html" rel="nofollow noopener">Have a look at the 6.4 errata page for a list of bugs and workarounds.</a></li>
<li>signify(1) pubkeys for this release:</li>
<li>base: RWQq6XmS4eDAcQW4KsT5Ka0KwTQp2JMOP9V/DR4HTVOL5Bc0D7LeuPwA</li>
<li>fw:   RWRoBbjnosJ/39llpve1XaNIrrQND4knG+jSBeIUYU8x4WNkxz6a2K97</li>
<li>pkg:  RWRF5TTY+LoN/51QD5kM2hKDtMTzycQBBPmPYhyQEb1+4pff/H6fh/kA</li>
</ul>

<hr>

<p>###<a href="https://www.ghostbsd.org/18.10_RC2_release_announcement" rel="nofollow noopener">GhostBSD 18.10 RC2 Announced</a></p>

<blockquote>
<p>This second release candidate of GhostBSD 18.10 is the second official release of GhostBSD with TrueOS under the hood. The official desktop of GhostBSD is MATE. However, in the future, there might be an XFCE community release, but for now, there is no community release yet.</p>
</blockquote>

<ul>
<li>
<p>What has changed since RC1</p>
</li>
<li>
<p>Removed drm-stable-kmod and we will let users installed the propper drm-*-kmod</p>
</li>
<li>
<p>Douglas Joachin added libva-intel-driver libva-vdpau-driver  to supports accelerated some video driver for Intel</p>
</li>
<li>
<p>Issues that got fixed</p>
</li>
<li>
<p>Bug #70 Cannot run Octopi, missing libgksu error.</p>
</li>
<li>
<p>Bug #71 LibreOffice doesn’t start because of missing libcurl.so.4</p>
</li>
<li>
<p>Bug #72 libarchive is a missing dependency</p>
</li>
</ul>

<blockquote>
<p>Again thanks to iXsystems, TrueOS, Joe Maloney, Kris Moore, Ken Moore, Martin Wilke, Neville Goddard, Vester “Vic” Thacker, Douglas Joachim, Alex Lyakhov, Yetkin Degirmenci and many more who helped to make the transition from FreeBSD to TrueOS smoother.</p>
</blockquote>

<ul>
<li>
<p>Updating from RC1 to RC2:</p>
</li>
<li>
<p>sudo pkg update -f</p>
</li>
<li>
<p>sudo pkg install -f libarchive curl libgksu</p>
</li>
<li>
<p>sudo pkg upgrade</p>
</li>
<li>
<p>Where to download:</p>
</li>
<li>
<p>All images checksum, hybrid ISO(DVD, USB) and torrent are available here: <a href="https://www.ghostbsd.org/download" rel="nofollow noopener">https://www.ghostbsd.org/download</a></p>
</li>
<li>
<p>[ScreenShots]</p>
</li>
<li>
<p><a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png" rel="nofollow noopener">https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png</a></p>
</li>
<li>
<p><a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png" rel="nofollow noopener">https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png</a></p>
</li>
</ul>

<hr>

<p>###<a href="https://www.openssh.com/txt/release-7.9" rel="nofollow noopener">OpenSSH 7.9 has been released and it has support for OpenSSL 1.1</a></p>

<pre><code>Changes since OpenSSH 7.8
=========================

This is primarily a bugfix release.

New Features
------------
 * ssh(1), sshd(8): allow most port numbers to be specified using
   service names from getservbyname(3) (typically /etc/services).
 * ssh(1): allow the IdentityAgent configuration directive to accept
   environment variable names. This supports the use of multiple
   agent sockets without needing to use fixed paths.
 * sshd(8): support signalling sessions via the SSH protocol.
   A limited subset of signals is supported and only for login or
   command sessions (i.e. not subsystems) that were not subject to
   a forced command via authorized_keys or sshd_config. bz#1424
 * ssh(1): support "ssh -Q sig" to list supported signature options.
   Also "ssh -Q help" to show the full set of supported queries.
 * ssh(1), sshd(8): add a CASignatureAlgorithms option for the
   client and server configs to allow control over which signature
   formats are allowed for CAs to sign certificates. For example,
   this allows banning CAs that sign certificates using the RSA-SHA1
   signature algorithm.
 * sshd(8), ssh-keygen(1): allow key revocation lists (KRLs) to
   revoke keys specified by SHA256 hash.
 * ssh-keygen(1): allow creation of key revocation lists directly
   from base64-encoded SHA256 fingerprints. This supports revoking
   keys using only the information contained in sshd(8)
   authentication log messages.

Bugfixes
--------

 * ssh(1), ssh-keygen(1): avoid spurious "invalid format" errors when
   attempting to load PEM private keys while using an incorrect
   passphrase. bz#2901
 * sshd(8): when a channel closed message is received from a client,
   close the stderr file descriptor at the same time stdout is
   closed. This avoids stuck processes if they were waiting for
   stderr to close and were insensitive to stdin/out closing. bz#2863
 * ssh(1): allow ForwardX11Timeout=0 to disable the untrusted X11
   forwarding timeout and support X11 forwarding indefinitely.
   Previously the behaviour of ForwardX11Timeout=0 was undefined.
 * sshd(8): when compiled with GSSAPI support, cache supported method
   OIDs regardless of whether GSSAPI authentication is enabled in the
   main section of sshd_config. This avoids sandbox violations if
   GSSAPI authentication was later enabled in a Match block. bz#2107
 * sshd(8): do not fail closed when configured with a text key
   revocation list that contains a too-short key. bz#2897
 * ssh(1): treat connections with ProxyJump specified the same as
   ones with a ProxyCommand set with regards to hostname
   canonicalisation (i.e. don't try to canonicalise the hostname
   unless CanonicalizeHostname is set to 'always'). bz#2896
 * ssh(1): fix regression in OpenSSH 7.8 that could prevent public-
   key authentication using certificates hosted in a ssh-agent(1)
   or against sshd(8) from OpenSSH &lt;7.8.

Portability
-----------

 * All: support building against the openssl-1.1 API (releases 1.1.0g
   and later). The openssl-1.0 API will remain supported at least
   until OpenSSL terminates security patch support for that API version.
 * sshd(8): allow the futex(2) syscall in the Linux seccomp sandbox;
   apparently required by some glibc/OpenSSL combinations.
 * sshd(8): handle getgrouplist(3) returning more than
   _SC_NGROUPS_MAX groups. Some platforms consider this limit more
   as a guideline.
</code></pre>

<hr>

<p>##News Roundup</p>

<p>###<a href="https://www.ixsystems.com/blog/meetbsd-2018/" rel="nofollow noopener">MeetBSD 2018: The Ultimate Hallway Track</a></p>

<blockquote>
<p>Founded in Poland in 2007 and first hosted in California in 2008, MeetBSD combines formal talks with UnConference activities to provide a level of interactivity not found at any other BSD conference. The character of each MeetBSD is determined largely by its venue, ranging from Hacker Dojo in 2010 to Intel’s Santa Clara headquarters this year. The Intel SC12 building provided a beautiful auditorium and sponsors’ room, plus a cafeteria for the Friday night social event and the Saturday night FreeBSD 25th Anniversary Celebration. The formal nature of the auditorium motivated the formation of MeetBSD’s first independent Program Committee and public Call for Participation. Together these resulted in a backbone of talks presented by speakers from the USA, Canada, and Poland, combined with UnConference activities tailored to the space.</p>
</blockquote>

<ul>
<li>MeetBSD Day 0</li>
</ul>

<blockquote>
<p>Day Zero of MeetBSD was a FreeBSD Developer/Vendor Summit hosted in the same auditorium where the talks would take place. Like the conference itself, this event featured a mix of scheduled talks and interactive sessions. The scheduled talks were LWPMFS: LightWeight Persistent Memory Filesystem by Ravi Pokala, Evaluating GIT for FreeBSD by Ed Maste, and NUMA by Mark Johnston. Ed’s overview of the advantages and disadvantages of using Git for FreeBSD development was of the most interest to users and developers, and the discussion continued into the following two days.</p>
</blockquote>

<ul>
<li>MeetBSD Day 1</li>
</ul>

<blockquote>
<p>The first official day of MeetBSD 2018 was kicked off with introductions led by emcee JT Pennington and a keynote, “Using TrueOS to boot-strap your FreeBSD-based project” by Kris Moore. Kris described a new JSON-based release infrastructure that he has exercised with FreeBSD, TrueOS, and FreeNAS. Kris’ talk was followed by “Intel &amp; FreeBSD: Better Together” by Ben Widawsky, the FreeBSD program lead at Intel, who gave an overview of Intel’s past and current efforts supporting FreeBSD. Next came lunch, followed by Kamil Rytarowski’s “Bug detecting software in the NetBSD userland: MKSANITIZER”. This was followed by 5-Minute Lightning Talks, Andrew Fengler’s “FreeBSD: What to (Not) Monitor”, and an OpenZFS Panel Discussion featuring OpenZFS experts Michael W. Lucas, Allan Jude, Alexander Motin, Pawel Dawidek, and Dan Langille. Day one concluded with a social event at the Intel cafeteria where the discussions continued into the night.</p>
</blockquote>

<ul>
<li>MeetBSD Day 2</li>
</ul>

<blockquote>
<p>Day Two of MeetBSD 2018 kicked off with a keynote by Michael W. Lucas entitled “Why BSD?”, where Michael detailed what makes the BSD community different and why it attracts us all. This was followed by Dr. Kirk McKusick’s “The Early Days of BSD” talk, which was followed by “DTrace/dwatch in Production” by Devin Teske. After lunch, we enjoyed “A Curmudgeon’s Language Selection Criteria: Why I Don’t Write Everything in Go, Rust, Elixir, etc” by G. Clifford Williams and, “Best practices of sandboxing applications with Capsicum” by Mariusz Zaborski. I then hosted a Virtualization Panel Discussion that featured eight developers from FreeBSD, OpenBSD, and NetBSD. We then split up for Breakout Sessions and the one on Bloomberg’s controversial article on backdoored Supermicro systems was fascinating given the experts present, all of whom were skeptical of the feasibility of the attack. The day wrapped up with a final talk, “Tales of a Daemontown Performance Peddler: Why ‘it depends’ and what you can do about it” by Nick Principe, followed by the FreeBSD 25th Anniversary Celebration.</p>
</blockquote>

<ul>
<li>Putting the “meet” in MeetBSD</li>
</ul>

<blockquote>
<p>I confess the other organizers and I were nervous about how well one large auditorium would suit a BSD event but the flexible personal space it gave everyone allowed for countless meetings and heated hacking that often brought about immediate results. I watched people take ideas through several iterations with the help and input of obvious and unexpected experts, all of whom were within reach. Not having to pick up and leave for a talk in another room organically resulted in essentially a series of mini hackathons that none of us anticipated but were delighted to witness, taking the “hallway track” to a whole new level. The mix of formal and UnConference activities at MeetBSD is certain to evolve. Thank you to everyone who participated with questions, Lightning Talks, and Panel participation. A huge thanks to our sponsors, including Intel for both hosting and sponsoring MeetBSD California 2018, Western Digital, Supermicro, Verisign, Jupiter Broadcasting, the FreeBSD Foundation, Bank of America Merrill Lynch, the NetBSD Foundation, and the team at iXsystems.</p>
</blockquote>

<blockquote>
<p>See you at MeetBSD 2020!</p>
</blockquote>

<hr>

<p>###<a href="https://panoramacircle.com/2018/10/07/setup-dragonflybsd-with-a-desktop-on-real-hardware-thinkpad-t410/" rel="nofollow noopener">Setup DragonflyBSD with a desktop on real hardware ThinkPad T410</a><br>
+<a href="https://youtu.be/p4KwssNY82Q" rel="nofollow noopener">Video Demo</a></p>

<blockquote>
<p>Linux has become too mainstream and standard BSD is a common thing now? How about DragonflyBSD which was created as a fork of FreeBSD 4.8 in conflict over system internals. This tutorial will show how to install it and set up a user-oriented desktop. It should work with DragonflyBSD, FreeBSD and probably all BSDs.<br>
Some background: BSD was is ultimately derived from UNIX back in the days. It is not Linux even though it is similar in many ways because Linux was designed to follow UNIX principles. Seeing is believing, so check out the video of the install!<br>
I did try two BSD distros before called GhostBSD and TrueOS and you can check out my short reviews. DragonflyBSD comes like FreeBSD bare bones and requires some work to get a desktop running.</p>
</blockquote>

<ul>
<li>
<p>Download image file and burn to USB drive or DVD</p>
</li>
<li>
<p>First installation</p>
</li>
<li>
<p>Setting up the system and installing a desktop</p>
</li>
<li>
<p>Inside the desktop</p>
</li>
<li>
<p>Install some more programs</p>
</li>
<li>
<p>How to enable sound?</p>
</li>
<li>
<p>Let’s play some free games</p>
</li>
<li>
<p>Setup WiFi</p>
</li>
<li>
<p>Power mode settings</p>
</li>
<li>
<p>More to do?</p>
</li>
</ul>

<blockquote>
<p>You can check out this blog post if you want a much more detailed tutorial. If you don’t mind standard BSD, get the GhostBSD distro instead which comes with a ready-made desktop xcfe or mate and many functional presets.</p>
</blockquote>

<ul>
<li>
<p>A small summary of what we got on the upside:</p>
<ul>
<li>Free and open source operating system with a long history</li>
<li>Drivers worked fine including Ethernet, WiFi, video 2D &amp; 3D, audio, etc</li>
<li>Hammer2 advanced file system</li>
<li>You are very unique if you use this OS fork</li>
</ul>

</li><br>
<li>

<p>Some downsides:</p>

</li><br>
<li>

<p>Less driver and direct app support than Linux</p>

</li><br>
<li>

<p>Installer and desktop have some traps and quirks and require work</p>

</li><br>
</ul><br>
<hr>

<p>###<a href="https://dressupgeekout.blogspot.com/2018/10/porting-keybase-to-netbsd.html" rel="nofollow noopener">Porting Keybase to NetBSD</a></p>

<blockquote>
<p>Keybase significantly simplifies the whole keypair/PGP thing and makes what is usually a confusing, difficult experience actually rather pleasant. At its heart is an open-source command line utility that does all of the heavy cryptographic lifting. But it’s also hooked up to the network of all other Keybase users, so you don’t have to work very hard to maintain big keychains. Pretty cool!<br>
So, this evening, I tried to get it to all work on NetBSD.<br>
The Keybase client code base is, in my opinion, not very well architected… there exist many different Keybase clients (command line apps, desktop apps, mobile apps) and for some reason the code for all of them are seemingly in this single repository, without even using Git submodules. Not sure what that’s about.<br>
Anyway, “go build”-ing the command line program (it’s written in Go) failed immediately because there’s some platform-specific code that just does not seem to recognize that NetBSD exists (but they do for FreeBSD and OpenBSD). Looks like the Keybase developers maintain a Golang wrapper around struct proc, which of course is different from OS to OS. So I literally just copypasted the OpenBSD wrapper, renamed it to “NetBSD”, and the build basically succeeded from there! This is of course super janky and untrustworthy, but it seems to Mostly Just Work…<br>
I forked the GitHub repo, you can see the diff on top of keybase 2.7.3 here: bccaaf3096a<br>
Eventually I ended up with a ~/go/bin/keybase which launches just fine. Meaning, I can main() okay. But the moment you try to do anything interesting, it looks super scary:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase login
▶ WARNING Running in devel mode
▶ INFO Forking background server with pid=12932
▶ ERROR unexpected error in Login: API network error: doRetry failed,
attempts: 1, timeout 5s, last err: Get
http://localhost:3000/_/api/1.0/merkle/path.json?last=3784314&amp;load_deleted=1&amp;load_reset_chain=1&amp;poll=10&amp;sig_hints_low=3&amp;uid=38ae1dfa49cd6831ea2fdade5c5d0519:
dial tcp [::1]:3000: connect: connection refused
</code></pre>

<blockquote>
<p>There’s a few things about this error message that stuck out to me:</p>
</blockquote>

<ul>
<li>Forking a background server? What?</li>
<li>It’s trying to connect to localhost? That must be the server that doesn’t work …</li>
</ul>

<blockquote>
<p>Unfortunately, this nonfunctional “background server” sticks around even when a command as simple as ‘login’ command just failed:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ps 12932
  PID TTY STAT    TIME COMMAND
  12932 ?   Ssl  0:00.21 ./keybase --debug --log-file
  /home/charlotte/.cache/keybase.devel/keybase.service.log service --chdir
  /home/charlotte/.config/keybase.devel --auto-forked 
</code></pre>

<blockquote>
<p>I’m not exactly sure what the intended purpose of the “background server” even is, but fortunately we can kill it and even tell the keybase command to not even spawn one:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --standalone
   --standalone                         Use the client without any daemon support.
</code></pre>

<blockquote>
<p>And then we can fix wanting to connect to localhost by specifying an expected Keybase API server – how about the one hosted at <a href="https://keybase.io" rel="nofollow noopener">https://keybase.io</a>?</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --server
   --server, -s                         Specify server API.
</code></pre>

<blockquote>
<p>Basically, what I’m trying to say is that if you specify both of these options, the keybase command does what I expect on NetBSD:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io login
▶ WARNING Running in devel mode
Please enter the Keybase passphrase for dressupgeekout (6+ characters): 

charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io id dressupgeekout
▶ WARNING Running in devel mode
▶ INFO Identifying dressupgeekout
✔ public key fingerprint: 7873 DA50 A786 9A3F 1662 3A17 20BD 8739 E82C 7F2F
✔ "dressupgeekout" on github:
https://gist.github.com/0471c7918d254425835bf5e1b4bcda00 [cached 2018-10-11
20:55:21 PDT]
✔ "dressupgeekout" on reddit:
https://www.reddit.com/r/KeybaseProofs/comments/9ng5qm/my_keybase_proof_redditdressupgeekout/
[cached 2018-10-11 20:55:21 PDT]
</code></pre>

<hr>

<p>###<a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=339929" rel="nofollow noopener">Initial implementation of draft-ietf-6man-ipv6only-flag</a></p>

<pre><code>This change defines the RA "6" (IPv6-Only) flag which routers
may advertise, kernel logic to check if all routers on a link
have the flag set and accordingly update a per-interface flag.

If all routers agree that it is an IPv6-only link, ether_output_frame(),
based on the interface flag, will filter out all ETHERTYPE_IP/ARP
frames, drop them, and return EAFNOSUPPORT to upper layers.

The change also updates ndp to show the "6" flag, ifconfig to
display the IPV6_ONLY nd6 flag if set, and rtadvd to allow
announcing the flag.

Further changes to tcpdump (contrib code) are availble and will
be upstreamed.

Tested the code (slightly earlier version) with 2 FreeBSD
IPv6 routers, a FreeBSD laptop on ethernet as well as wifi,
and with Win10 and OSX clients (which did not fall over with
the "6" flag set but not understood).

We may also want to (a) implement and RX filter, and (b) over
time enahnce user space to, say, stop dhclient from running
when the interface flag is set.  Also we might want to start
IPv6 before IPv4 in the future.

All the code is hidden under the EXPERIMENTAL option and not
compiled by default as the draft is a work-in-progress and
we cannot rely on the fact that IANA will assign the bits
as requested by the draft and hence they may change.

Dear 6man, you have running code.

Discussed with: Bob Hinden, Brian E Carpenter
</code></pre>

<p>##Beastie Bits</p>

<ul>
<li><a href="https://dan.langille.org/2018/10/02/running-freebsd-on-osx-using-xhyve-a-port-of-bhyve/" rel="nofollow noopener">Running FreeBSD on macOS via xhyve</a></li>
<li><a href="https://mwl.io/archives/3841" rel="nofollow noopener">Auction Winners</a></li>
<li><a href="https://github.com/vedetta-com/vedetta/blob/master/src/usr/local/share/doc/vedetta/OpenSSH_Principals.md" rel="nofollow noopener">OpenSSH Principals</a></li>
<li><a href="https://undeadly.org/cgi?action=article;sid=20181018160645" rel="nofollow noopener">OpenBSD Foundation gets a second Iridium donation from Handshake</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-advocacy/2018/10/10/msg000786.html" rel="nofollow noopener">NetBSD machines at Open Source Conference 2018 Kagawa</a></li>
<li><a href="https://mwl.io/archives/3818" rel="nofollow noopener">Absolute FreeBSD now shipping!</a></li>
<li><a href="https://h3artbl33d.nl/blog/nextcloud-on-openbsd" rel="nofollow noopener">NextCloud on OpenBSD</a></li>
<li><a href="https://www.freebsd.org/news/newsflash.html#event20181027:01" rel="nofollow noopener">FreeBSD 12.0-BETA2 Available</a></li>
<li><a href="https://twitter.com/gvnn3/status/1049347862541344771" rel="nofollow noopener">DTrace on Windows ported from FreeBSD</a></li>
<li><a href="http://dpaste.com/36DFQ1S" rel="nofollow noopener">HELBUG fall 2018 meeting scheduled - Thursday the 15th of November</a></li>
<li><a href="https://translate.google.com/translate?hl=de&amp;sl=de&amp;tl=en&amp;u=https%3A%2F%2Ftickets.events.ccc.de%2F35c3%2Fintro%2F" rel="nofollow noopener">35C3 pre-sale has started</a></li>
<li><a href="https://www.meetup.com/BSD-Users-Stockholm/events/254235663/" rel="nofollow noopener">Stockholm BSD User Meeting: Tuesday Nov 13, 18:00 - 21:30  </a></li>
<li><a href="https://bsd-pl.org/en" rel="nofollow noopener">Polish BSD User Group: Thursday Nov 15, 18:30 - 21:00 </a></li>
</ul>

<hr>

<p>##Feedback/Questions</p>

<ul>
<li>Greg - <a href="http://dpaste.com/1WA54CC" rel="nofollow noopener">Interview suggestion for the show</a></li>
<li>Nelson - <a href="http://dpaste.com/21KKF7Q#wrap" rel="nofollow noopener">Ghostscript vulnerabilities</a></li>
<li>Allison - <a href="http://dpaste.com/3K6D7ST" rel="nofollow noopener">Ports and GCC</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>OpenBSD 6.4 released, GhostBSD RC2 released, MeetBSD - the ultimate hallway track, DragonflyBSD desktop on a Thinkpad, Porting keybase to NetBSD, OpenSSH 7.9, and draft-ietf-6man-ipv6only-flag in FreeBSD.</p>

<p>##Headlines<br>
###<a href="https://www.openbsd.org/64.html" rel="nofollow noopener">OpenBSD 6.4 released</a></p>

<ul>
<li><a href="https://www.openbsd.org/plus64.html" rel="nofollow noopener">See a detailed log of changes between the 6.3 and 6.4 releases.</a></li>
<li><a href="https://www.openbsd.org/ftp.html" rel="nofollow noopener">See the information on the FTP page for a list of mirror machines.</a></li>
<li><a href="https://www.openbsd.org/errata64.html" rel="nofollow noopener">Have a look at the 6.4 errata page for a list of bugs and workarounds.</a></li>
<li>signify(1) pubkeys for this release:</li>
<li>base: RWQq6XmS4eDAcQW4KsT5Ka0KwTQp2JMOP9V/DR4HTVOL5Bc0D7LeuPwA</li>
<li>fw:   RWRoBbjnosJ/39llpve1XaNIrrQND4knG+jSBeIUYU8x4WNkxz6a2K97</li>
<li>pkg:  RWRF5TTY+LoN/51QD5kM2hKDtMTzycQBBPmPYhyQEb1+4pff/H6fh/kA</li>
</ul>

<hr>

<p>###<a href="https://www.ghostbsd.org/18.10_RC2_release_announcement" rel="nofollow noopener">GhostBSD 18.10 RC2 Announced</a></p>

<blockquote>
<p>This second release candidate of GhostBSD 18.10 is the second official release of GhostBSD with TrueOS under the hood. The official desktop of GhostBSD is MATE. However, in the future, there might be an XFCE community release, but for now, there is no community release yet.</p>
</blockquote>

<ul>
<li>
<p>What has changed since RC1</p>
</li>
<li>
<p>Removed drm-stable-kmod and we will let users installed the propper drm-*-kmod</p>
</li>
<li>
<p>Douglas Joachin added libva-intel-driver libva-vdpau-driver  to supports accelerated some video driver for Intel</p>
</li>
<li>
<p>Issues that got fixed</p>
</li>
<li>
<p>Bug #70 Cannot run Octopi, missing libgksu error.</p>
</li>
<li>
<p>Bug #71 LibreOffice doesn’t start because of missing libcurl.so.4</p>
</li>
<li>
<p>Bug #72 libarchive is a missing dependency</p>
</li>
</ul>

<blockquote>
<p>Again thanks to iXsystems, TrueOS, Joe Maloney, Kris Moore, Ken Moore, Martin Wilke, Neville Goddard, Vester “Vic” Thacker, Douglas Joachim, Alex Lyakhov, Yetkin Degirmenci and many more who helped to make the transition from FreeBSD to TrueOS smoother.</p>
</blockquote>

<ul>
<li>
<p>Updating from RC1 to RC2:</p>
</li>
<li>
<p>sudo pkg update -f</p>
</li>
<li>
<p>sudo pkg install -f libarchive curl libgksu</p>
</li>
<li>
<p>sudo pkg upgrade</p>
</li>
<li>
<p>Where to download:</p>
</li>
<li>
<p>All images checksum, hybrid ISO(DVD, USB) and torrent are available here: <a href="https://www.ghostbsd.org/download" rel="nofollow noopener">https://www.ghostbsd.org/download</a></p>
</li>
<li>
<p>[ScreenShots]</p>
</li>
<li>
<p><a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png" rel="nofollow noopener">https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-22-41.png</a></p>
</li>
<li>
<p><a href="https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png" rel="nofollow noopener">https://www.ghostbsd.org/sites/default/files/Screenshot_at_2018-10-20_13-27-26.png</a></p>
</li>
</ul>

<hr>

<p>###<a href="https://www.openssh.com/txt/release-7.9" rel="nofollow noopener">OpenSSH 7.9 has been released and it has support for OpenSSL 1.1</a></p>

<pre><code>Changes since OpenSSH 7.8
=========================

This is primarily a bugfix release.

New Features
------------
 * ssh(1), sshd(8): allow most port numbers to be specified using
   service names from getservbyname(3) (typically /etc/services).
 * ssh(1): allow the IdentityAgent configuration directive to accept
   environment variable names. This supports the use of multiple
   agent sockets without needing to use fixed paths.
 * sshd(8): support signalling sessions via the SSH protocol.
   A limited subset of signals is supported and only for login or
   command sessions (i.e. not subsystems) that were not subject to
   a forced command via authorized_keys or sshd_config. bz#1424
 * ssh(1): support "ssh -Q sig" to list supported signature options.
   Also "ssh -Q help" to show the full set of supported queries.
 * ssh(1), sshd(8): add a CASignatureAlgorithms option for the
   client and server configs to allow control over which signature
   formats are allowed for CAs to sign certificates. For example,
   this allows banning CAs that sign certificates using the RSA-SHA1
   signature algorithm.
 * sshd(8), ssh-keygen(1): allow key revocation lists (KRLs) to
   revoke keys specified by SHA256 hash.
 * ssh-keygen(1): allow creation of key revocation lists directly
   from base64-encoded SHA256 fingerprints. This supports revoking
   keys using only the information contained in sshd(8)
   authentication log messages.

Bugfixes
--------

 * ssh(1), ssh-keygen(1): avoid spurious "invalid format" errors when
   attempting to load PEM private keys while using an incorrect
   passphrase. bz#2901
 * sshd(8): when a channel closed message is received from a client,
   close the stderr file descriptor at the same time stdout is
   closed. This avoids stuck processes if they were waiting for
   stderr to close and were insensitive to stdin/out closing. bz#2863
 * ssh(1): allow ForwardX11Timeout=0 to disable the untrusted X11
   forwarding timeout and support X11 forwarding indefinitely.
   Previously the behaviour of ForwardX11Timeout=0 was undefined.
 * sshd(8): when compiled with GSSAPI support, cache supported method
   OIDs regardless of whether GSSAPI authentication is enabled in the
   main section of sshd_config. This avoids sandbox violations if
   GSSAPI authentication was later enabled in a Match block. bz#2107
 * sshd(8): do not fail closed when configured with a text key
   revocation list that contains a too-short key. bz#2897
 * ssh(1): treat connections with ProxyJump specified the same as
   ones with a ProxyCommand set with regards to hostname
   canonicalisation (i.e. don't try to canonicalise the hostname
   unless CanonicalizeHostname is set to 'always'). bz#2896
 * ssh(1): fix regression in OpenSSH 7.8 that could prevent public-
   key authentication using certificates hosted in a ssh-agent(1)
   or against sshd(8) from OpenSSH &lt;7.8.

Portability
-----------

 * All: support building against the openssl-1.1 API (releases 1.1.0g
   and later). The openssl-1.0 API will remain supported at least
   until OpenSSL terminates security patch support for that API version.
 * sshd(8): allow the futex(2) syscall in the Linux seccomp sandbox;
   apparently required by some glibc/OpenSSL combinations.
 * sshd(8): handle getgrouplist(3) returning more than
   _SC_NGROUPS_MAX groups. Some platforms consider this limit more
   as a guideline.
</code></pre>

<hr>

<p>##News Roundup</p>

<p>###<a href="https://www.ixsystems.com/blog/meetbsd-2018/" rel="nofollow noopener">MeetBSD 2018: The Ultimate Hallway Track</a></p>

<blockquote>
<p>Founded in Poland in 2007 and first hosted in California in 2008, MeetBSD combines formal talks with UnConference activities to provide a level of interactivity not found at any other BSD conference. The character of each MeetBSD is determined largely by its venue, ranging from Hacker Dojo in 2010 to Intel’s Santa Clara headquarters this year. The Intel SC12 building provided a beautiful auditorium and sponsors’ room, plus a cafeteria for the Friday night social event and the Saturday night FreeBSD 25th Anniversary Celebration. The formal nature of the auditorium motivated the formation of MeetBSD’s first independent Program Committee and public Call for Participation. Together these resulted in a backbone of talks presented by speakers from the USA, Canada, and Poland, combined with UnConference activities tailored to the space.</p>
</blockquote>

<ul>
<li>MeetBSD Day 0</li>
</ul>

<blockquote>
<p>Day Zero of MeetBSD was a FreeBSD Developer/Vendor Summit hosted in the same auditorium where the talks would take place. Like the conference itself, this event featured a mix of scheduled talks and interactive sessions. The scheduled talks were LWPMFS: LightWeight Persistent Memory Filesystem by Ravi Pokala, Evaluating GIT for FreeBSD by Ed Maste, and NUMA by Mark Johnston. Ed’s overview of the advantages and disadvantages of using Git for FreeBSD development was of the most interest to users and developers, and the discussion continued into the following two days.</p>
</blockquote>

<ul>
<li>MeetBSD Day 1</li>
</ul>

<blockquote>
<p>The first official day of MeetBSD 2018 was kicked off with introductions led by emcee JT Pennington and a keynote, “Using TrueOS to boot-strap your FreeBSD-based project” by Kris Moore. Kris described a new JSON-based release infrastructure that he has exercised with FreeBSD, TrueOS, and FreeNAS. Kris’ talk was followed by “Intel &amp; FreeBSD: Better Together” by Ben Widawsky, the FreeBSD program lead at Intel, who gave an overview of Intel’s past and current efforts supporting FreeBSD. Next came lunch, followed by Kamil Rytarowski’s “Bug detecting software in the NetBSD userland: MKSANITIZER”. This was followed by 5-Minute Lightning Talks, Andrew Fengler’s “FreeBSD: What to (Not) Monitor”, and an OpenZFS Panel Discussion featuring OpenZFS experts Michael W. Lucas, Allan Jude, Alexander Motin, Pawel Dawidek, and Dan Langille. Day one concluded with a social event at the Intel cafeteria where the discussions continued into the night.</p>
</blockquote>

<ul>
<li>MeetBSD Day 2</li>
</ul>

<blockquote>
<p>Day Two of MeetBSD 2018 kicked off with a keynote by Michael W. Lucas entitled “Why BSD?”, where Michael detailed what makes the BSD community different and why it attracts us all. This was followed by Dr. Kirk McKusick’s “The Early Days of BSD” talk, which was followed by “DTrace/dwatch in Production” by Devin Teske. After lunch, we enjoyed “A Curmudgeon’s Language Selection Criteria: Why I Don’t Write Everything in Go, Rust, Elixir, etc” by G. Clifford Williams and, “Best practices of sandboxing applications with Capsicum” by Mariusz Zaborski. I then hosted a Virtualization Panel Discussion that featured eight developers from FreeBSD, OpenBSD, and NetBSD. We then split up for Breakout Sessions and the one on Bloomberg’s controversial article on backdoored Supermicro systems was fascinating given the experts present, all of whom were skeptical of the feasibility of the attack. The day wrapped up with a final talk, “Tales of a Daemontown Performance Peddler: Why ‘it depends’ and what you can do about it” by Nick Principe, followed by the FreeBSD 25th Anniversary Celebration.</p>
</blockquote>

<ul>
<li>Putting the “meet” in MeetBSD</li>
</ul>

<blockquote>
<p>I confess the other organizers and I were nervous about how well one large auditorium would suit a BSD event but the flexible personal space it gave everyone allowed for countless meetings and heated hacking that often brought about immediate results. I watched people take ideas through several iterations with the help and input of obvious and unexpected experts, all of whom were within reach. Not having to pick up and leave for a talk in another room organically resulted in essentially a series of mini hackathons that none of us anticipated but were delighted to witness, taking the “hallway track” to a whole new level. The mix of formal and UnConference activities at MeetBSD is certain to evolve. Thank you to everyone who participated with questions, Lightning Talks, and Panel participation. A huge thanks to our sponsors, including Intel for both hosting and sponsoring MeetBSD California 2018, Western Digital, Supermicro, Verisign, Jupiter Broadcasting, the FreeBSD Foundation, Bank of America Merrill Lynch, the NetBSD Foundation, and the team at iXsystems.</p>
</blockquote>

<blockquote>
<p>See you at MeetBSD 2020!</p>
</blockquote>

<hr>

<p>###<a href="https://panoramacircle.com/2018/10/07/setup-dragonflybsd-with-a-desktop-on-real-hardware-thinkpad-t410/" rel="nofollow noopener">Setup DragonflyBSD with a desktop on real hardware ThinkPad T410</a><br>
+<a href="https://youtu.be/p4KwssNY82Q" rel="nofollow noopener">Video Demo</a></p>

<blockquote>
<p>Linux has become too mainstream and standard BSD is a common thing now? How about DragonflyBSD which was created as a fork of FreeBSD 4.8 in conflict over system internals. This tutorial will show how to install it and set up a user-oriented desktop. It should work with DragonflyBSD, FreeBSD and probably all BSDs.<br>
Some background: BSD was is ultimately derived from UNIX back in the days. It is not Linux even though it is similar in many ways because Linux was designed to follow UNIX principles. Seeing is believing, so check out the video of the install!<br>
I did try two BSD distros before called GhostBSD and TrueOS and you can check out my short reviews. DragonflyBSD comes like FreeBSD bare bones and requires some work to get a desktop running.</p>
</blockquote>

<ul>
<li>
<p>Download image file and burn to USB drive or DVD</p>
</li>
<li>
<p>First installation</p>
</li>
<li>
<p>Setting up the system and installing a desktop</p>
</li>
<li>
<p>Inside the desktop</p>
</li>
<li>
<p>Install some more programs</p>
</li>
<li>
<p>How to enable sound?</p>
</li>
<li>
<p>Let’s play some free games</p>
</li>
<li>
<p>Setup WiFi</p>
</li>
<li>
<p>Power mode settings</p>
</li>
<li>
<p>More to do?</p>
</li>
</ul>

<blockquote>
<p>You can check out this blog post if you want a much more detailed tutorial. If you don’t mind standard BSD, get the GhostBSD distro instead which comes with a ready-made desktop xcfe or mate and many functional presets.</p>
</blockquote>

<ul>
<li>
<p>A small summary of what we got on the upside:</p>
<ul>
<li>Free and open source operating system with a long history</li>
<li>Drivers worked fine including Ethernet, WiFi, video 2D &amp; 3D, audio, etc</li>
<li>Hammer2 advanced file system</li>
<li>You are very unique if you use this OS fork</li>
</ul>

</li><br>
<li>

<p>Some downsides:</p>

</li><br>
<li>

<p>Less driver and direct app support than Linux</p>

</li><br>
<li>

<p>Installer and desktop have some traps and quirks and require work</p>

</li><br>
</ul><br>
<hr>

<p>###<a href="https://dressupgeekout.blogspot.com/2018/10/porting-keybase-to-netbsd.html" rel="nofollow noopener">Porting Keybase to NetBSD</a></p>

<blockquote>
<p>Keybase significantly simplifies the whole keypair/PGP thing and makes what is usually a confusing, difficult experience actually rather pleasant. At its heart is an open-source command line utility that does all of the heavy cryptographic lifting. But it’s also hooked up to the network of all other Keybase users, so you don’t have to work very hard to maintain big keychains. Pretty cool!<br>
So, this evening, I tried to get it to all work on NetBSD.<br>
The Keybase client code base is, in my opinion, not very well architected… there exist many different Keybase clients (command line apps, desktop apps, mobile apps) and for some reason the code for all of them are seemingly in this single repository, without even using Git submodules. Not sure what that’s about.<br>
Anyway, “go build”-ing the command line program (it’s written in Go) failed immediately because there’s some platform-specific code that just does not seem to recognize that NetBSD exists (but they do for FreeBSD and OpenBSD). Looks like the Keybase developers maintain a Golang wrapper around struct proc, which of course is different from OS to OS. So I literally just copypasted the OpenBSD wrapper, renamed it to “NetBSD”, and the build basically succeeded from there! This is of course super janky and untrustworthy, but it seems to Mostly Just Work…<br>
I forked the GitHub repo, you can see the diff on top of keybase 2.7.3 here: bccaaf3096a<br>
Eventually I ended up with a ~/go/bin/keybase which launches just fine. Meaning, I can main() okay. But the moment you try to do anything interesting, it looks super scary:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase login
▶ WARNING Running in devel mode
▶ INFO Forking background server with pid=12932
▶ ERROR unexpected error in Login: API network error: doRetry failed,
attempts: 1, timeout 5s, last err: Get
http://localhost:3000/_/api/1.0/merkle/path.json?last=3784314&amp;load_deleted=1&amp;load_reset_chain=1&amp;poll=10&amp;sig_hints_low=3&amp;uid=38ae1dfa49cd6831ea2fdade5c5d0519:
dial tcp [::1]:3000: connect: connection refused
</code></pre>

<blockquote>
<p>There’s a few things about this error message that stuck out to me:</p>
</blockquote>

<ul>
<li>Forking a background server? What?</li>
<li>It’s trying to connect to localhost? That must be the server that doesn’t work …</li>
</ul>

<blockquote>
<p>Unfortunately, this nonfunctional “background server” sticks around even when a command as simple as ‘login’ command just failed:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ps 12932
  PID TTY STAT    TIME COMMAND
  12932 ?   Ssl  0:00.21 ./keybase --debug --log-file
  /home/charlotte/.cache/keybase.devel/keybase.service.log service --chdir
  /home/charlotte/.config/keybase.devel --auto-forked 
</code></pre>

<blockquote>
<p>I’m not exactly sure what the intended purpose of the “background server” even is, but fortunately we can kill it and even tell the keybase command to not even spawn one:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --standalone
   --standalone                         Use the client without any daemon support.
</code></pre>

<blockquote>
<p>And then we can fix wanting to connect to localhost by specifying an expected Keybase API server – how about the one hosted at <a href="https://keybase.io" rel="nofollow noopener">https://keybase.io</a>?</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase help advanced | grep -- --server
   --server, -s                         Specify server API.
</code></pre>

<blockquote>
<p>Basically, what I’m trying to say is that if you specify both of these options, the keybase command does what I expect on NetBSD:</p>
</blockquote>

<pre><code>charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io login
▶ WARNING Running in devel mode
Please enter the Keybase passphrase for dressupgeekout (6+ characters): 

charlotte@sakuracity:~/go/bin ./keybase --standalone -s https://keybase.io id dressupgeekout
▶ WARNING Running in devel mode
▶ INFO Identifying dressupgeekout
✔ public key fingerprint: 7873 DA50 A786 9A3F 1662 3A17 20BD 8739 E82C 7F2F
✔ "dressupgeekout" on github:
https://gist.github.com/0471c7918d254425835bf5e1b4bcda00 [cached 2018-10-11
20:55:21 PDT]
✔ "dressupgeekout" on reddit:
https://www.reddit.com/r/KeybaseProofs/comments/9ng5qm/my_keybase_proof_redditdressupgeekout/
[cached 2018-10-11 20:55:21 PDT]
</code></pre>

<hr>

<p>###<a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=339929" rel="nofollow noopener">Initial implementation of draft-ietf-6man-ipv6only-flag</a></p>

<pre><code>This change defines the RA "6" (IPv6-Only) flag which routers
may advertise, kernel logic to check if all routers on a link
have the flag set and accordingly update a per-interface flag.

If all routers agree that it is an IPv6-only link, ether_output_frame(),
based on the interface flag, will filter out all ETHERTYPE_IP/ARP
frames, drop them, and return EAFNOSUPPORT to upper layers.

The change also updates ndp to show the "6" flag, ifconfig to
display the IPV6_ONLY nd6 flag if set, and rtadvd to allow
announcing the flag.

Further changes to tcpdump (contrib code) are availble and will
be upstreamed.

Tested the code (slightly earlier version) with 2 FreeBSD
IPv6 routers, a FreeBSD laptop on ethernet as well as wifi,
and with Win10 and OSX clients (which did not fall over with
the "6" flag set but not understood).

We may also want to (a) implement and RX filter, and (b) over
time enahnce user space to, say, stop dhclient from running
when the interface flag is set.  Also we might want to start
IPv6 before IPv4 in the future.

All the code is hidden under the EXPERIMENTAL option and not
compiled by default as the draft is a work-in-progress and
we cannot rely on the fact that IANA will assign the bits
as requested by the draft and hence they may change.

Dear 6man, you have running code.

Discussed with: Bob Hinden, Brian E Carpenter
</code></pre>

<p>##Beastie Bits</p>

<ul>
<li><a href="https://dan.langille.org/2018/10/02/running-freebsd-on-osx-using-xhyve-a-port-of-bhyve/" rel="nofollow noopener">Running FreeBSD on macOS via xhyve</a></li>
<li><a href="https://mwl.io/archives/3841" rel="nofollow noopener">Auction Winners</a></li>
<li><a href="https://github.com/vedetta-com/vedetta/blob/master/src/usr/local/share/doc/vedetta/OpenSSH_Principals.md" rel="nofollow noopener">OpenSSH Principals</a></li>
<li><a href="https://undeadly.org/cgi?action=article;sid=20181018160645" rel="nofollow noopener">OpenBSD Foundation gets a second Iridium donation from Handshake</a></li>
<li><a href="https://mail-index.netbsd.org/netbsd-advocacy/2018/10/10/msg000786.html" rel="nofollow noopener">NetBSD machines at Open Source Conference 2018 Kagawa</a></li>
<li><a href="https://mwl.io/archives/3818" rel="nofollow noopener">Absolute FreeBSD now shipping!</a></li>
<li><a href="https://h3artbl33d.nl/blog/nextcloud-on-openbsd" rel="nofollow noopener">NextCloud on OpenBSD</a></li>
<li><a href="https://www.freebsd.org/news/newsflash.html#event20181027:01" rel="nofollow noopener">FreeBSD 12.0-BETA2 Available</a></li>
<li><a href="https://twitter.com/gvnn3/status/1049347862541344771" rel="nofollow noopener">DTrace on Windows ported from FreeBSD</a></li>
<li><a href="http://dpaste.com/36DFQ1S" rel="nofollow noopener">HELBUG fall 2018 meeting scheduled - Thursday the 15th of November</a></li>
<li><a href="https://translate.google.com/translate?hl=de&amp;sl=de&amp;tl=en&amp;u=https%3A%2F%2Ftickets.events.ccc.de%2F35c3%2Fintro%2F" rel="nofollow noopener">35C3 pre-sale has started</a></li>
<li><a href="https://www.meetup.com/BSD-Users-Stockholm/events/254235663/" rel="nofollow noopener">Stockholm BSD User Meeting: Tuesday Nov 13, 18:00 - 21:30  </a></li>
<li><a href="https://bsd-pl.org/en" rel="nofollow noopener">Polish BSD User Group: Thursday Nov 15, 18:30 - 21:00 </a></li>
</ul>

<hr>

<p>##Feedback/Questions</p>

<ul>
<li>Greg - <a href="http://dpaste.com/1WA54CC" rel="nofollow noopener">Interview suggestion for the show</a></li>
<li>Nelson - <a href="http://dpaste.com/21KKF7Q#wrap" rel="nofollow noopener">Ghostscript vulnerabilities</a></li>
<li>Allison - <a href="http://dpaste.com/3K6D7ST" rel="nofollow noopener">Ports and GCC</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>104: Beverly Hills 25519</title>
  <link>https://www.bsdnow.tv/104</link>
  <guid isPermaLink="false">0bc0c068-36fe-429f-b7f4-38ac01fb7f19</guid>
  <pubDate>Wed, 26 Aug 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0bc0c068-36fe-429f-b7f4-38ac01fb7f19.mp3" length="58136116" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</itunes:subtitle>
  <itunes:duration>1:20:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener"&gt;EdgeRouter Lite, meet OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it &lt;/li&gt;
&lt;li&gt;We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)&lt;/li&gt;
&lt;li&gt;Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it&lt;/li&gt;
&lt;li&gt;He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt; and &lt;a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener"&gt;various&lt;/a&gt; &lt;a href="https://www.marc.info/?t=143974140500001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;other&lt;/a&gt; &lt;a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener"&gt;places&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One thing to &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143991822827285&amp;amp;w=2" rel="nofollow noopener"&gt;note&lt;/a&gt; about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W&lt;sup&gt;X&lt;/sup&gt; at all)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener"&gt;Design and Implementation of the FreeBSD Operating System interview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development&lt;/li&gt;
&lt;li&gt;InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors&lt;/li&gt;
&lt;li&gt;"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."&lt;/li&gt;
&lt;li&gt;Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144027474117290&amp;amp;w=2" rel="nofollow noopener"&gt;Path list parameter in OpenBSD tame&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've mentioned OpenBSD's relatively new "&lt;a href="https://marc.info/?l=openbsd-tech&amp;amp;m=143725996614627&amp;amp;w=2" rel="nofollow noopener"&gt;tame&lt;/a&gt;" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges&lt;/li&gt;
&lt;li&gt;One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between&lt;/li&gt;
&lt;li&gt;Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers&lt;/li&gt;
&lt;li&gt;The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener"&gt;on Reddit&lt;/a&gt; &lt;a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener"&gt;and Hacker News&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener"&gt;FreeBSD &amp;amp; PC-BSD 10.2-RELEASE&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out&lt;/li&gt;
&lt;li&gt;The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13&lt;/li&gt;
&lt;li&gt;New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to&lt;/li&gt;
&lt;li&gt;A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet&lt;/li&gt;
&lt;li&gt;The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions&lt;/li&gt;
&lt;li&gt;ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards&lt;/li&gt;
&lt;li&gt;The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups&lt;/li&gt;
&lt;li&gt;In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener"&gt;full release notes&lt;/a&gt; for the rest of the details and changes&lt;/li&gt;
&lt;li&gt;PC-BSD also followed with &lt;a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener"&gt;their 10.2-RELEASE&lt;/a&gt;, sporting a few more additional features
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Damien Miller - &lt;a href="mailto:djm@openbsd.org" rel="nofollow noopener"&gt;djm@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/damienmiller" rel="nofollow noopener"&gt;@damienmiller&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenSSH: phasing out broken crypto, default cipher changes&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference Shimane&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another&lt;/li&gt;
&lt;li&gt;This time they had NetBSD running on some Sony NWS devices (MIPS-based)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener"&gt;JavaStations&lt;/a&gt; were also on display - something we haven't ever seen before (made between 1996-2000)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener"&gt;BAFUG videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos of their recent meetings&lt;/li&gt;
&lt;li&gt;Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works&lt;/li&gt;
&lt;li&gt;Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener"&gt;a second video&lt;/a&gt;, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"&lt;/li&gt;
&lt;li&gt;In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)&lt;/li&gt;
&lt;li&gt;People should record presentations at their BSD users groups and send them to us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener"&gt;L2TP over IPSEC on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well&lt;/li&gt;
&lt;li&gt;Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic&lt;/li&gt;
&lt;li&gt;This guide specifically covers L2TP, using npppd and pre-shared keys&lt;/li&gt;
&lt;li&gt;Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener"&gt;Reliable bare metal with TrueOS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS&lt;/li&gt;
&lt;li&gt;This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution&lt;/li&gt;
&lt;li&gt;Most importantly, he also covers how to keep everything redundant and deal with hard drives failing&lt;/li&gt;
&lt;li&gt;The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like&lt;/li&gt;
&lt;li&gt;Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144047868127049&amp;amp;w=2" rel="nofollow noopener"&gt;Kernel W&lt;sup&gt;X&lt;/sup&gt; on i386&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned some big W&lt;sup&gt;X&lt;/sup&gt; kernel changes in OpenBSD &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" rel="nofollow noopener"&gt;a while back&lt;/a&gt;, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)&lt;/li&gt;
&lt;li&gt;Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well&lt;/li&gt;
&lt;li&gt;Check out &lt;a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener"&gt;our interview with Mike&lt;/a&gt; for some more background info on memory protections like W&lt;sup&gt;X&lt;/sup&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener"&gt;Markus writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener"&gt;Theo writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssh, openssl, chacha20, chacha20-poly1305, aes, md5, hmac, cbc, gcm, cryptography, ed25519, curve25519, erl, edgerouter lite, tame, bafug</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show, we'll be talking with Damien Miller of the OpenSSH team. Their 7.0 release has some major changes, including phasing out older crypto and changing one of the defaults that might surprise you.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-ERL" rel="nofollow noopener">EdgeRouter Lite, meet OpenBSD</a></h3>

<ul>
<li>The ERL, much like the Raspberry Pi and a bunch of other cheap boards, is getting more and more popular as more things get ported to run on it </li>
<li>We've covered installing NetBSD and FreeBSD on them before, but OpenBSD has gotten a lot better support for them as well now (including the onboard storage in 5.8)</li>
<li>Ted Unangst got a hold of one recently and kindly wrote up some notes about installing and using OpenBSD on it</li>
<li>He covers doing a network install, getting the (slightly strange) bootloader working with u-boot and some final notes about the hardware</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10079210" rel="nofollow noopener">on Hacker News</a> and <a href="https://www.reddit.com/r/openbsd/comments/3hgf2c" rel="nofollow noopener">various</a> <a href="https://www.marc.info/?t=143974140500001&amp;r=1&amp;w=2" rel="nofollow noopener">other</a> <a href="https://lobste.rs/s/acz9bu/openbsd_on_edgerouter_lite" rel="nofollow noopener">places</a></li>
<li>One thing to <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143991822827285&amp;w=2" rel="nofollow noopener">note</a> about these devices: because of their MIPS64 processor, they'll have weaker ASLR than X86 CPUs (and no W<sup>X</sup> at all)
***</li>
</ul>

<h3><a href="http://www.infoq.com/articles/freebsd-design-implementation-review" rel="nofollow noopener">Design and Implementation of the FreeBSD Operating System interview</a></h3>

<ul>
<li>For those who don't know, the "Design and Implementation of the FreeBSD Operating System" is a semi-recently-revived technical reference book for FreeBSD development</li>
<li>InfoQ has a review of the book up for anyone who might be interested, but they also have an interview the authors</li>
<li>"The book takes an approach to FreeBSD from inside out, starting with kernel services, then moving to process and memory management, I/O and devices, filesystems, IPC and network protocols, and finally system startup and shutdown. The book provides dense, technical information in a clear way, with lots of pseudo-code, diagrams, and tables to illustrate the main points."</li>
<li>Aside from detailing a few of the chapters, the interview covers who the book's target audience is, some history of the project, long-term support, some of the newer features and some general OS development topics
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144027474117290&amp;w=2" rel="nofollow noopener">Path list parameter in OpenBSD tame</a></h3>

<ul>
<li>We've mentioned OpenBSD's relatively new "<a href="https://marc.info/?l=openbsd-tech&amp;m=143725996614627&amp;w=2" rel="nofollow noopener">tame</a>" subsystem a couple times before: it's an easy-to-implement "self-containment" framework, allowing programs to have a reduced feature set mode with even less privileges</li>
<li>One of the early concerns from users of other process containment tools was that tame was too broad in the way it separated disk access - you could either read/write files or not, nothing in between</li>
<li>Now there's the option to create a whitelist of specific files and directories that your binary is allowed to access, giving a much finer-grained set of controls to developers</li>
<li>The next step is to add tame restraints to the OpenBSD userland utilities, which should probably be done by 5.9</li>
<li>More discussion can be found <a href="https://www.reddit.com/r/openbsd/comments/3i2lk7" rel="nofollow noopener">on Reddit</a> <a href="https://news.ycombinator.com/item?id=10104886" rel="nofollow noopener">and Hacker News</a>
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.2R/announce.html" rel="nofollow noopener">FreeBSD &amp; PC-BSD 10.2-RELEASE</a></h3>

<ul>
<li>The FreeBSD team has released the second minor version bump to the 10.x branch, including all the fixes from 10-STABLE since 10.1 came out</li>
<li>The Linux compatibility layer has been updated to support CentOS 6, rather than the much older Fedora Core base used previously, and the DRM graphics code has been updated to match Linux 3.8.13</li>
<li>New installations (and newly-upgraded systems) will use the quarterly binary package set, rather than the rolling release model that most people are used to</li>
<li>A VXLAN driver was added, allowing you to create virtual LANs by encapsulating the ethernet frame in a UDP packet</li>
<li>The bhyve codebase is much newer, enabling support for AMD CPUs with SVM and AMD-V extensions</li>
<li>ARM and ARM64 code saw some fixes and improvements, including SMP support on a few specific boards and support for a few new boards</li>
<li>The bootloader now supports entering your GELI passphrase before loading the kernel in full disk encryption setups</li>
<li>In addition to assorted userland fixes and driver improvements, various third party tools in the base system were updated: resolvconf, ISC NTPd, netcat, file, unbound, OpenSSL, sendmail</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.2R/relnotes.html" rel="nofollow noopener">full release notes</a> for the rest of the details and changes</li>
<li>PC-BSD also followed with <a href="http://blog.pcbsd.org/2015/08/pc-bsd-10-2-release-now-available" rel="nofollow noopener">their 10.2-RELEASE</a>, sporting a few more additional features
***</li>
</ul>

<h2>Interview - Damien Miller - <a href="mailto:djm@openbsd.org" rel="nofollow noopener">djm@openbsd.org</a> / <a href="https://twitter.com/damienmiller" rel="nofollow noopener">@damienmiller</a></h2>

<p>OpenSSH: phasing out broken crypto, default cipher changes</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/08/22/msg000692.html" rel="nofollow noopener">NetBSD at Open Source Conference Shimane</a></h3>

<ul>
<li>We weren't the only ones away at conferences last week - the Japanese NetBSD guys are always raiding one event or another</li>
<li>This time they had NetBSD running on some Sony NWS devices (MIPS-based)</li>
<li><a href="https://en.wikipedia.org/wiki/JavaStation" rel="nofollow noopener">JavaStations</a> were also on display - something we haven't ever seen before (made between 1996-2000)
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=-XF20nitI90" rel="nofollow noopener">BAFUG videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos of their recent meetings</li>
<li>Devin Teske hosts the first one, discussing adding GELI support to the bootloader, including some video demonstrations of how it works</li>
<li>Shortly after beginning, Adrian Chadd takes over the conversation and they discuss various problems (and solutions) related to the bootloader - for example, how can we type encryption passwords with non-US keyboard layouts</li>
<li>In <a href="https://www.youtube.com/watch?v=49sPYHh473U" rel="nofollow noopener">a second video</a>, Jordan Hubbard and Kip Macy introduce "NeXTBSD aka FreeBSD X"</li>
<li>In it, they discuss their ideas of merging more Mac OS X features into FreeBSD (launchd to replace the init system, some APIs, etc)</li>
<li>People should record presentations at their BSD users groups and send them to us
***</li>
</ul>

<h3><a href="http://frankgroeneveld.nl/2015/08/16/configuring-l2tp-over-ipsec-on-openbsd-for-mac-os-x-clients" rel="nofollow noopener">L2TP over IPSEC on OpenBSD</a></h3>

<ul>
<li>If you've got an OpenBSD box and some Mac OS X clients that need secure communications, surprise: they can work together pretty well</li>
<li>Using only the base tools in both operating systems, you can build a nice IPSEC setup for tunneling all your traffic</li>
<li>This guide specifically covers L2TP, using npppd and pre-shared keys</li>
<li>Server setup, client setup, firewall configuration and routing-related settings are all covered in detail
***</li>
</ul>

<h3><a href="http://www.tubsta.com/2015/08/reliable-bare-metal-server-using-trueosfreebsd" rel="nofollow noopener">Reliable bare metal with TrueOS</a></h3>

<ul>
<li>Imagine a server version of PC-BSD with some useful utilities preinstalled - that's basically TrueOS</li>
<li>This article walks you through setting up a FreeBSD -CURRENT server (using TrueOS) to create a pretty solid backup solution</li>
<li>Most importantly, he also covers how to keep everything redundant and deal with hard drives failing</li>
<li>The author chose to go with the -CURRENT branch because of the delay between regular releases, and newer features not making their way to users as fast as he'd like</li>
<li>Another factor is that there are no binary snapshots of FreeBSD -CURRENT that can be easily used for in-place upgrades, but with TrueOS (and some other BSDs) there are
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144047868127049&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> on i386</a></h3>

<ul>
<li>We mentioned some big W<sup>X</sup> kernel changes in OpenBSD <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">a while back</a>, but the work was mainly for x86_64 CPU architecture (which makes sense; that's what most people run now)</li>
<li>Mike Larkin is back again, and isn't leaving the people with older hardware out, committing similar kernel work into the i386 platform now as well</li>
<li>Check out <a href="http://www.bsdnow.tv/episodes/2015_05_13-exclusive_disjunction" rel="nofollow noopener">our interview with Mike</a> for some more background info on memory protections like W<sup>X</sup>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iGoeYMyb" rel="nofollow noopener">Markus writes in</a></li>
<li><a href="http://slexy.org/view/s21bIFfmUS" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s21Hjm8Tsa" rel="nofollow noopener">Theo writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>82: SSL in the Wild</title>
  <link>https://www.bsdnow.tv/82</link>
  <guid isPermaLink="false">530c2987-381d-4c49-bfb9-b78872dd2e03</guid>
  <pubDate>Wed, 25 Mar 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/530c2987-381d-4c49-bfb9-b78872dd2e03.mp3" length="63405364" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be chatting with Bernard Spil about wider adoption of LibreSSL in other communities. He's been doing a lot of work with FreeBSD ports specifically, but also working with upstream projects. As usual, all this weeks news and answers to your questions, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:28:03</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be chatting with Bernard Spil about wider adoption of LibreSSL in other communities. He's been doing a lot of work with FreeBSD ports specifically, but also working with upstream projects. As usual, all this weeks news and answers to your questions, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://2015.eurobsdcon.org/call-for-papers/" rel="nofollow noopener"&gt;EuroBSDCon 2015 call for papers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The call for papers has been announced for the next &lt;a href="http://www.bsdnow.tv/episodes/2014_12_03-conference-connoisseur" rel="nofollow noopener"&gt;EuroBSDCon&lt;/a&gt;, which is set to be held in Sweden this year&lt;/li&gt;
&lt;li&gt;According to their site, the call for presentation proposals period will start on Monday the 23rd of March until Friday the 17th of April&lt;/li&gt;
&lt;li&gt;If giving a full talk isn't your thing, there's also a call for tutorials - if you're comfortable teaching other people about something BSD-related, this could be a great thing too&lt;/li&gt;
&lt;li&gt;You're not limited to one proposal - several speakers gave multiple in 2014 - so don't hesitate if you've got more than one thing you'd like to talk about&lt;/li&gt;
&lt;li&gt;We'd like to see a more balanced conference schedule than BSDCan's having this year, but that requires effort on both sides - if you're doing &lt;em&gt;anything&lt;/em&gt; cool with &lt;em&gt;any&lt;/em&gt; BSD, we'd encourage you submit a proposal (or two)&lt;/li&gt;
&lt;li&gt;Check the announcement for all the specific details and requirements&lt;/li&gt;
&lt;li&gt;If your talk gets accepted, the conference even pays for your travel expenses
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/making-security-sausage" rel="nofollow noopener"&gt;Making security sausage&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has a new blog post up, detailing his experiences with some recent security patches both in and out of OpenBSD&lt;/li&gt;
&lt;li&gt;"Unfortunately, I wrote the tool used for signing patches which somehow turned into a responsibility for also creating the inputs to be signed. That was not the plan!"&lt;/li&gt;
&lt;li&gt;The post first takes us through a few OpenBSD errata patches, explaining how some can get fixed very quickly, but others are more complicated and need a bit more review&lt;/li&gt;
&lt;li&gt;It also covers security in upstream codebases, and how upstream projects sometimes treat security issues as any other bug&lt;/li&gt;
&lt;li&gt;Following that, it leads to the topic of FreeType - and a much more complicated problem with backporting patches between versions&lt;/li&gt;
&lt;li&gt;The recent OpenSSL vulnerabilities were also mentioned, with an interesting story to go along with them&lt;/li&gt;
&lt;li&gt;Just 45 minutes before the agreed-upon announcement, OpenBSD devs found a problem with the patch OpenSSL planned to release - it had to be redone at the last minute&lt;/li&gt;
&lt;li&gt;It was because of this that FreeBSD actually had to release &lt;a href="https://lists.freebsd.org/pipermail/freebsd-security-notifications/2015-March/000237.html" rel="nofollow noopener"&gt;a security update to their security update&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;He concludes with "My number one wish would be that every project provide small patches for security issues. Dropping enormous feature releases along with a note 'oh, and some security too' creates downstream mayhem."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.itwire.com/business-it-news/open-source/67420-running-freebsd-on-the-server-a-sysadmin-speaks" rel="nofollow noopener"&gt;Running FreeBSD on the server, a sysadmin speaks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;More BSD content is appearing on mainstream technology sites, and, &lt;strong&gt;more importantly&lt;/strong&gt;, BSD Now is being mentioned&lt;/li&gt;
&lt;li&gt;ITWire recently did an interview with Allan about running FreeBSD on servers (possibly to go with their earlier interview with Kris about desktop usage)&lt;/li&gt;
&lt;li&gt;They discuss some of the advantages BSD brings to the table for sysadmins that might be used to Linux or some other UNIX flavor&lt;/li&gt;
&lt;li&gt;It also covers specific features like jails, ZFS, long-term support, automating tasks and even… what to name your computers&lt;/li&gt;
&lt;li&gt;If you've been considering switching your servers over from Linux to FreeBSD, but maybe wanted to hear some first-hand experience, this is the article for you
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/netbsd_ported_to_hardkernel_odroid" rel="nofollow noopener"&gt;NetBSD ported to Hardkernel ODROID-C1&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In their never-ending quest to run on every new board that comes out, NetBSD has been ported to the &lt;a href="http://www.hardkernel.com/main/products/prdt_info.php?g_code=G141578608433" rel="nofollow noopener"&gt;Hardkernel ODROID-C1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This one features a quad-core ARMv7 CPU at 1.5GHz, has a gig of ram and gigabit ethernet... all for just $35&lt;/li&gt;
&lt;li&gt;There's a special kernel config file for this board's hardware, available in both -current and the upcoming 7.0&lt;/li&gt;
&lt;li&gt;More info can be found on &lt;a href="https://wiki.netbsd.org/ports/evbarm/odroid-c1/" rel="nofollow noopener"&gt;their wiki page&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;After this was written, basic framebuffer console support was &lt;a href="http://mail-index.netbsd.org/source-changes/2015/03/21/msg064156.html" rel="nofollow noopener"&gt;also committed&lt;/a&gt;, allowing a developer to &lt;a href="https://pbs.twimg.com/media/CAqU5CnWEAAEhH2.png:large" rel="nofollow noopener"&gt;run XFCE&lt;/a&gt; on the device
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Bernard Spil - &lt;a href="mailto:brnrd@freebsd.org" rel="nofollow noopener"&gt;brnrd@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/sp1l" rel="nofollow noopener"&gt;@sp1l&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;LibreSSL adoption &lt;a href="https://wiki.freebsd.org/LibreSSL" rel="nofollow noopener"&gt;in FreeBSD ports&lt;/a&gt; and the wider software ecosystem&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.echothrust.com/blogs/monitoring-pf-logs-gource" rel="nofollow noopener"&gt;Monitoring pf logs with Gource&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you're &lt;a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener"&gt;using pf&lt;/a&gt; on any of the BSDs, maybe you've gotten bored of grepping logs and want to do something more fancy&lt;/li&gt;
&lt;li&gt;This article will show you how to get set up with Gource for a cinematic-like experience&lt;/li&gt;
&lt;li&gt;If you've never heard of Gource, it's "an OpenGL-based 3D visualization tool intended for visualizing activity on source control repositories"&lt;/li&gt;
&lt;li&gt;When you put all the tools together, you can end up with some pretty eye-catching animations of your firewall traffic&lt;/li&gt;
&lt;li&gt;One of our listeners wrote in to say that he set this up and, almost immediately, noticed his girlfriend's phone had been compromised - graphical representations of traffic could be useful for detecting suspicious network activity
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=381573" rel="nofollow noopener"&gt;pkgng 1.5.0 alpha1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The development version of pkgng was updated to 1.4.99.14, or 1.5.0 alpha1&lt;/li&gt;
&lt;li&gt;This update introduces support for provides/requires, something that we've been wanting for a long time&lt;/li&gt;
&lt;li&gt;It will also now print which package is the reason for direct dependency change&lt;/li&gt;
&lt;li&gt;Another interesting addition is the "pkg -r" switch, allowing cross installation of packages&lt;/li&gt;
&lt;li&gt;Remember this isn't the stable version, so maybe don't upgrade to it just yet on any production systems&lt;/li&gt;
&lt;li&gt;DragonFly will also likely pick up this update once it's marked stable
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://devio.us/%7Ebcallah/rcos2015.pdf" rel="nofollow noopener"&gt;Welcome to OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned last week that our listener Brian was giving a talk in the Troy, New York area&lt;/li&gt;
&lt;li&gt;The slides from that talk are now online, and they've been generating quite a bit of &lt;a href="https://news.ycombinator.com/item?id=9240533" rel="nofollow noopener"&gt;discussion&lt;/a&gt; &lt;a href="https://www.reddit.com/r/openbsd/comments/2ztokc/welcome_to_openbsd/" rel="nofollow noopener"&gt;online&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It's simply titled "Welcome to OpenBSD" and gives the reader an introduction to the OS (and how easy it is to get involved with contributing)&lt;/li&gt;
&lt;li&gt;Topics include a quick history of the project, who the developers are and what they do, some proactive security techniques and finally how to get involved&lt;/li&gt;
&lt;li&gt;As you may know, NetBSD has almost 60 &lt;a href="https://www.netbsd.org/ports/" rel="nofollow noopener"&gt;supported platforms&lt;/a&gt; and their slogan is "&lt;em&gt;of course&lt;/em&gt; it runs NetBSD" - Brian says, with &lt;a href="http://www.openbsd.org/plat.html" rel="nofollow noopener"&gt;17 platforms&lt;/a&gt; over 13 CPU architectures, "it &lt;em&gt;probably&lt;/em&gt; runs OpenBSD"&lt;/li&gt;
&lt;li&gt;No matter which BSD you might be interested in, these slides are a great read, especially for any beginners looking to get their feet wet&lt;/li&gt;
&lt;li&gt;Try to guess which font he used...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2015/03/bsdtalk252-devious-with-brian-callahan.html" rel="nofollow noopener"&gt;BSDTalk episode 252&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;And somehow Brian has snuck himself into &lt;em&gt;another&lt;/em&gt; news item this week&lt;/li&gt;
&lt;li&gt;He makes an appearance in the latest episode of &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener"&gt;BSD Talk&lt;/a&gt;, where he chats with Will about running a BSD-based shell provider&lt;/li&gt;
&lt;li&gt;If that sounds familiar, it's probably because &lt;a href="http://www.bsdnow.tv/episodes/2014_06_18-devious_methods" rel="nofollow noopener"&gt;we did the same thing&lt;/a&gt;, albeit with a different member of their team&lt;/li&gt;
&lt;li&gt;In this interview, they discuss what a shell provider does, hardware requirements and how to weed out the spammers in favor of real people&lt;/li&gt;
&lt;li&gt;They also talk a bit about the community aspect of a shared server, as opposed to just running a virtual machine by yourself
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2O81pixhq" rel="nofollow noopener"&gt;Christian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2dhr2WfVc" rel="nofollow noopener"&gt;Stefan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Kisq2EqT" rel="nofollow noopener"&gt;Possnfiffer writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Xr0e5YAJ" rel="nofollow noopener"&gt;Ruudsch writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Xz7BNoJE" rel="nofollow noopener"&gt;Shane writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-March/069679.html" rel="nofollow noopener"&gt;Accidental support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142686812913221&amp;amp;w=2" rel="nofollow noopener"&gt;Larry's tears&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-hardware/2015-March/007625.html" rel="nofollow noopener"&gt;The boy who sailed with BSD&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pkgng, poudriere, eurobsdcon, 2015, mg, emacs, libressl, openssl, ports, tls, heartbleed, freak attack, pkgng, hardkernel, gource</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be chatting with Bernard Spil about wider adoption of LibreSSL in other communities. He's been doing a lot of work with FreeBSD ports specifically, but also working with upstream projects. As usual, all this weeks news and answers to your questions, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://2015.eurobsdcon.org/call-for-papers/" rel="nofollow noopener">EuroBSDCon 2015 call for papers</a></h3>

<ul>
<li>The call for papers has been announced for the next <a href="http://www.bsdnow.tv/episodes/2014_12_03-conference-connoisseur" rel="nofollow noopener">EuroBSDCon</a>, which is set to be held in Sweden this year</li>
<li>According to their site, the call for presentation proposals period will start on Monday the 23rd of March until Friday the 17th of April</li>
<li>If giving a full talk isn't your thing, there's also a call for tutorials - if you're comfortable teaching other people about something BSD-related, this could be a great thing too</li>
<li>You're not limited to one proposal - several speakers gave multiple in 2014 - so don't hesitate if you've got more than one thing you'd like to talk about</li>
<li>We'd like to see a more balanced conference schedule than BSDCan's having this year, but that requires effort on both sides - if you're doing <em>anything</em> cool with <em>any</em> BSD, we'd encourage you submit a proposal (or two)</li>
<li>Check the announcement for all the specific details and requirements</li>
<li>If your talk gets accepted, the conference even pays for your travel expenses
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/making-security-sausage" rel="nofollow noopener">Making security sausage</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a new blog post up, detailing his experiences with some recent security patches both in and out of OpenBSD</li>
<li>"Unfortunately, I wrote the tool used for signing patches which somehow turned into a responsibility for also creating the inputs to be signed. That was not the plan!"</li>
<li>The post first takes us through a few OpenBSD errata patches, explaining how some can get fixed very quickly, but others are more complicated and need a bit more review</li>
<li>It also covers security in upstream codebases, and how upstream projects sometimes treat security issues as any other bug</li>
<li>Following that, it leads to the topic of FreeType - and a much more complicated problem with backporting patches between versions</li>
<li>The recent OpenSSL vulnerabilities were also mentioned, with an interesting story to go along with them</li>
<li>Just 45 minutes before the agreed-upon announcement, OpenBSD devs found a problem with the patch OpenSSL planned to release - it had to be redone at the last minute</li>
<li>It was because of this that FreeBSD actually had to release <a href="https://lists.freebsd.org/pipermail/freebsd-security-notifications/2015-March/000237.html" rel="nofollow noopener">a security update to their security update</a></li>
<li>He concludes with "My number one wish would be that every project provide small patches for security issues. Dropping enormous feature releases along with a note 'oh, and some security too' creates downstream mayhem."
***</li>
</ul>

<h3><a href="http://www.itwire.com/business-it-news/open-source/67420-running-freebsd-on-the-server-a-sysadmin-speaks" rel="nofollow noopener">Running FreeBSD on the server, a sysadmin speaks</a></h3>

<ul>
<li>More BSD content is appearing on mainstream technology sites, and, <strong>more importantly</strong>, BSD Now is being mentioned</li>
<li>ITWire recently did an interview with Allan about running FreeBSD on servers (possibly to go with their earlier interview with Kris about desktop usage)</li>
<li>They discuss some of the advantages BSD brings to the table for sysadmins that might be used to Linux or some other UNIX flavor</li>
<li>It also covers specific features like jails, ZFS, long-term support, automating tasks and even… what to name your computers</li>
<li>If you've been considering switching your servers over from Linux to FreeBSD, but maybe wanted to hear some first-hand experience, this is the article for you
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_ported_to_hardkernel_odroid" rel="nofollow noopener">NetBSD ported to Hardkernel ODROID-C1</a></h3>

<ul>
<li>In their never-ending quest to run on every new board that comes out, NetBSD has been ported to the <a href="http://www.hardkernel.com/main/products/prdt_info.php?g_code=G141578608433" rel="nofollow noopener">Hardkernel ODROID-C1</a></li>
<li>This one features a quad-core ARMv7 CPU at 1.5GHz, has a gig of ram and gigabit ethernet... all for just $35</li>
<li>There's a special kernel config file for this board's hardware, available in both -current and the upcoming 7.0</li>
<li>More info can be found on <a href="https://wiki.netbsd.org/ports/evbarm/odroid-c1/" rel="nofollow noopener">their wiki page</a></li>
<li>After this was written, basic framebuffer console support was <a href="http://mail-index.netbsd.org/source-changes/2015/03/21/msg064156.html" rel="nofollow noopener">also committed</a>, allowing a developer to <a href="https://pbs.twimg.com/media/CAqU5CnWEAAEhH2.png:large" rel="nofollow noopener">run XFCE</a> on the device
***</li>
</ul>

<h2>Interview - Bernard Spil - <a href="mailto:brnrd@freebsd.org" rel="nofollow noopener">brnrd@freebsd.org</a> / <a href="https://twitter.com/sp1l" rel="nofollow noopener">@sp1l</a></h2>

<p>LibreSSL adoption <a href="https://wiki.freebsd.org/LibreSSL" rel="nofollow noopener">in FreeBSD ports</a> and the wider software ecosystem</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.echothrust.com/blogs/monitoring-pf-logs-gource" rel="nofollow noopener">Monitoring pf logs with Gource</a></h3>

<ul>
<li>If you're <a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener">using pf</a> on any of the BSDs, maybe you've gotten bored of grepping logs and want to do something more fancy</li>
<li>This article will show you how to get set up with Gource for a cinematic-like experience</li>
<li>If you've never heard of Gource, it's "an OpenGL-based 3D visualization tool intended for visualizing activity on source control repositories"</li>
<li>When you put all the tools together, you can end up with some pretty eye-catching animations of your firewall traffic</li>
<li>One of our listeners wrote in to say that he set this up and, almost immediately, noticed his girlfriend's phone had been compromised - graphical representations of traffic could be useful for detecting suspicious network activity
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=381573" rel="nofollow noopener">pkgng 1.5.0 alpha1 released</a></h3>

<ul>
<li>The development version of pkgng was updated to 1.4.99.14, or 1.5.0 alpha1</li>
<li>This update introduces support for provides/requires, something that we've been wanting for a long time</li>
<li>It will also now print which package is the reason for direct dependency change</li>
<li>Another interesting addition is the "pkg -r" switch, allowing cross installation of packages</li>
<li>Remember this isn't the stable version, so maybe don't upgrade to it just yet on any production systems</li>
<li>DragonFly will also likely pick up this update once it's marked stable
***</li>
</ul>

<h3><a href="http://devio.us/%7Ebcallah/rcos2015.pdf" rel="nofollow noopener">Welcome to OpenBSD</a></h3>

<ul>
<li>We mentioned last week that our listener Brian was giving a talk in the Troy, New York area</li>
<li>The slides from that talk are now online, and they've been generating quite a bit of <a href="https://news.ycombinator.com/item?id=9240533" rel="nofollow noopener">discussion</a> <a href="https://www.reddit.com/r/openbsd/comments/2ztokc/welcome_to_openbsd/" rel="nofollow noopener">online</a></li>
<li>It's simply titled "Welcome to OpenBSD" and gives the reader an introduction to the OS (and how easy it is to get involved with contributing)</li>
<li>Topics include a quick history of the project, who the developers are and what they do, some proactive security techniques and finally how to get involved</li>
<li>As you may know, NetBSD has almost 60 <a href="https://www.netbsd.org/ports/" rel="nofollow noopener">supported platforms</a> and their slogan is "<em>of course</em> it runs NetBSD" - Brian says, with <a href="http://www.openbsd.org/plat.html" rel="nofollow noopener">17 platforms</a> over 13 CPU architectures, "it <em>probably</em> runs OpenBSD"</li>
<li>No matter which BSD you might be interested in, these slides are a great read, especially for any beginners looking to get their feet wet</li>
<li>Try to guess which font he used...
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2015/03/bsdtalk252-devious-with-brian-callahan.html" rel="nofollow noopener">BSDTalk episode 252</a></h3>

<ul>
<li>And somehow Brian has snuck himself into <em>another</em> news item this week</li>
<li>He makes an appearance in the latest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSD Talk</a>, where he chats with Will about running a BSD-based shell provider</li>
<li>If that sounds familiar, it's probably because <a href="http://www.bsdnow.tv/episodes/2014_06_18-devious_methods" rel="nofollow noopener">we did the same thing</a>, albeit with a different member of their team</li>
<li>In this interview, they discuss what a shell provider does, hardware requirements and how to weed out the spammers in favor of real people</li>
<li>They also talk a bit about the community aspect of a shared server, as opposed to just running a virtual machine by yourself
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2O81pixhq" rel="nofollow noopener">Christian writes in</a></li>
<li><a href="http://slexy.org/view/s2dhr2WfVc" rel="nofollow noopener">Stefan writes in</a></li>
<li><a href="http://slexy.org/view/s2Kisq2EqT" rel="nofollow noopener">Possnfiffer writes in</a></li>
<li><a href="http://slexy.org/view/s2Xr0e5YAJ" rel="nofollow noopener">Ruudsch writes in</a></li>
<li><a href="http://slexy.org/view/s2Xz7BNoJE" rel="nofollow noopener">Shane writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-March/069679.html" rel="nofollow noopener">Accidental support</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142686812913221&amp;w=2" rel="nofollow noopener">Larry's tears</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hardware/2015-March/007625.html" rel="nofollow noopener">The boy who sailed with BSD</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be chatting with Bernard Spil about wider adoption of LibreSSL in other communities. He's been doing a lot of work with FreeBSD ports specifically, but also working with upstream projects. As usual, all this weeks news and answers to your questions, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://2015.eurobsdcon.org/call-for-papers/" rel="nofollow noopener">EuroBSDCon 2015 call for papers</a></h3>

<ul>
<li>The call for papers has been announced for the next <a href="http://www.bsdnow.tv/episodes/2014_12_03-conference-connoisseur" rel="nofollow noopener">EuroBSDCon</a>, which is set to be held in Sweden this year</li>
<li>According to their site, the call for presentation proposals period will start on Monday the 23rd of March until Friday the 17th of April</li>
<li>If giving a full talk isn't your thing, there's also a call for tutorials - if you're comfortable teaching other people about something BSD-related, this could be a great thing too</li>
<li>You're not limited to one proposal - several speakers gave multiple in 2014 - so don't hesitate if you've got more than one thing you'd like to talk about</li>
<li>We'd like to see a more balanced conference schedule than BSDCan's having this year, but that requires effort on both sides - if you're doing <em>anything</em> cool with <em>any</em> BSD, we'd encourage you submit a proposal (or two)</li>
<li>Check the announcement for all the specific details and requirements</li>
<li>If your talk gets accepted, the conference even pays for your travel expenses
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/making-security-sausage" rel="nofollow noopener">Making security sausage</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a new blog post up, detailing his experiences with some recent security patches both in and out of OpenBSD</li>
<li>"Unfortunately, I wrote the tool used for signing patches which somehow turned into a responsibility for also creating the inputs to be signed. That was not the plan!"</li>
<li>The post first takes us through a few OpenBSD errata patches, explaining how some can get fixed very quickly, but others are more complicated and need a bit more review</li>
<li>It also covers security in upstream codebases, and how upstream projects sometimes treat security issues as any other bug</li>
<li>Following that, it leads to the topic of FreeType - and a much more complicated problem with backporting patches between versions</li>
<li>The recent OpenSSL vulnerabilities were also mentioned, with an interesting story to go along with them</li>
<li>Just 45 minutes before the agreed-upon announcement, OpenBSD devs found a problem with the patch OpenSSL planned to release - it had to be redone at the last minute</li>
<li>It was because of this that FreeBSD actually had to release <a href="https://lists.freebsd.org/pipermail/freebsd-security-notifications/2015-March/000237.html" rel="nofollow noopener">a security update to their security update</a></li>
<li>He concludes with "My number one wish would be that every project provide small patches for security issues. Dropping enormous feature releases along with a note 'oh, and some security too' creates downstream mayhem."
***</li>
</ul>

<h3><a href="http://www.itwire.com/business-it-news/open-source/67420-running-freebsd-on-the-server-a-sysadmin-speaks" rel="nofollow noopener">Running FreeBSD on the server, a sysadmin speaks</a></h3>

<ul>
<li>More BSD content is appearing on mainstream technology sites, and, <strong>more importantly</strong>, BSD Now is being mentioned</li>
<li>ITWire recently did an interview with Allan about running FreeBSD on servers (possibly to go with their earlier interview with Kris about desktop usage)</li>
<li>They discuss some of the advantages BSD brings to the table for sysadmins that might be used to Linux or some other UNIX flavor</li>
<li>It also covers specific features like jails, ZFS, long-term support, automating tasks and even… what to name your computers</li>
<li>If you've been considering switching your servers over from Linux to FreeBSD, but maybe wanted to hear some first-hand experience, this is the article for you
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_ported_to_hardkernel_odroid" rel="nofollow noopener">NetBSD ported to Hardkernel ODROID-C1</a></h3>

<ul>
<li>In their never-ending quest to run on every new board that comes out, NetBSD has been ported to the <a href="http://www.hardkernel.com/main/products/prdt_info.php?g_code=G141578608433" rel="nofollow noopener">Hardkernel ODROID-C1</a></li>
<li>This one features a quad-core ARMv7 CPU at 1.5GHz, has a gig of ram and gigabit ethernet... all for just $35</li>
<li>There's a special kernel config file for this board's hardware, available in both -current and the upcoming 7.0</li>
<li>More info can be found on <a href="https://wiki.netbsd.org/ports/evbarm/odroid-c1/" rel="nofollow noopener">their wiki page</a></li>
<li>After this was written, basic framebuffer console support was <a href="http://mail-index.netbsd.org/source-changes/2015/03/21/msg064156.html" rel="nofollow noopener">also committed</a>, allowing a developer to <a href="https://pbs.twimg.com/media/CAqU5CnWEAAEhH2.png:large" rel="nofollow noopener">run XFCE</a> on the device
***</li>
</ul>

<h2>Interview - Bernard Spil - <a href="mailto:brnrd@freebsd.org" rel="nofollow noopener">brnrd@freebsd.org</a> / <a href="https://twitter.com/sp1l" rel="nofollow noopener">@sp1l</a></h2>

<p>LibreSSL adoption <a href="https://wiki.freebsd.org/LibreSSL" rel="nofollow noopener">in FreeBSD ports</a> and the wider software ecosystem</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.echothrust.com/blogs/monitoring-pf-logs-gource" rel="nofollow noopener">Monitoring pf logs with Gource</a></h3>

<ul>
<li>If you're <a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener">using pf</a> on any of the BSDs, maybe you've gotten bored of grepping logs and want to do something more fancy</li>
<li>This article will show you how to get set up with Gource for a cinematic-like experience</li>
<li>If you've never heard of Gource, it's "an OpenGL-based 3D visualization tool intended for visualizing activity on source control repositories"</li>
<li>When you put all the tools together, you can end up with some pretty eye-catching animations of your firewall traffic</li>
<li>One of our listeners wrote in to say that he set this up and, almost immediately, noticed his girlfriend's phone had been compromised - graphical representations of traffic could be useful for detecting suspicious network activity
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=381573" rel="nofollow noopener">pkgng 1.5.0 alpha1 released</a></h3>

<ul>
<li>The development version of pkgng was updated to 1.4.99.14, or 1.5.0 alpha1</li>
<li>This update introduces support for provides/requires, something that we've been wanting for a long time</li>
<li>It will also now print which package is the reason for direct dependency change</li>
<li>Another interesting addition is the "pkg -r" switch, allowing cross installation of packages</li>
<li>Remember this isn't the stable version, so maybe don't upgrade to it just yet on any production systems</li>
<li>DragonFly will also likely pick up this update once it's marked stable
***</li>
</ul>

<h3><a href="http://devio.us/%7Ebcallah/rcos2015.pdf" rel="nofollow noopener">Welcome to OpenBSD</a></h3>

<ul>
<li>We mentioned last week that our listener Brian was giving a talk in the Troy, New York area</li>
<li>The slides from that talk are now online, and they've been generating quite a bit of <a href="https://news.ycombinator.com/item?id=9240533" rel="nofollow noopener">discussion</a> <a href="https://www.reddit.com/r/openbsd/comments/2ztokc/welcome_to_openbsd/" rel="nofollow noopener">online</a></li>
<li>It's simply titled "Welcome to OpenBSD" and gives the reader an introduction to the OS (and how easy it is to get involved with contributing)</li>
<li>Topics include a quick history of the project, who the developers are and what they do, some proactive security techniques and finally how to get involved</li>
<li>As you may know, NetBSD has almost 60 <a href="https://www.netbsd.org/ports/" rel="nofollow noopener">supported platforms</a> and their slogan is "<em>of course</em> it runs NetBSD" - Brian says, with <a href="http://www.openbsd.org/plat.html" rel="nofollow noopener">17 platforms</a> over 13 CPU architectures, "it <em>probably</em> runs OpenBSD"</li>
<li>No matter which BSD you might be interested in, these slides are a great read, especially for any beginners looking to get their feet wet</li>
<li>Try to guess which font he used...
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2015/03/bsdtalk252-devious-with-brian-callahan.html" rel="nofollow noopener">BSDTalk episode 252</a></h3>

<ul>
<li>And somehow Brian has snuck himself into <em>another</em> news item this week</li>
<li>He makes an appearance in the latest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSD Talk</a>, where he chats with Will about running a BSD-based shell provider</li>
<li>If that sounds familiar, it's probably because <a href="http://www.bsdnow.tv/episodes/2014_06_18-devious_methods" rel="nofollow noopener">we did the same thing</a>, albeit with a different member of their team</li>
<li>In this interview, they discuss what a shell provider does, hardware requirements and how to weed out the spammers in favor of real people</li>
<li>They also talk a bit about the community aspect of a shared server, as opposed to just running a virtual machine by yourself
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2O81pixhq" rel="nofollow noopener">Christian writes in</a></li>
<li><a href="http://slexy.org/view/s2dhr2WfVc" rel="nofollow noopener">Stefan writes in</a></li>
<li><a href="http://slexy.org/view/s2Kisq2EqT" rel="nofollow noopener">Possnfiffer writes in</a></li>
<li><a href="http://slexy.org/view/s2Xr0e5YAJ" rel="nofollow noopener">Ruudsch writes in</a></li>
<li><a href="http://slexy.org/view/s2Xz7BNoJE" rel="nofollow noopener">Shane writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-March/069679.html" rel="nofollow noopener">Accidental support</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142686812913221&amp;w=2" rel="nofollow noopener">Larry's tears</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hardware/2015-March/007625.html" rel="nofollow noopener">The boy who sailed with BSD</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>73: Pipe Dreams</title>
  <link>https://www.bsdnow.tv/73</link>
  <guid isPermaLink="false">bca95163-7c0b-4440-902b-594ea8c61554</guid>
  <pubDate>Wed, 21 Jan 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/bca95163-7c0b-4440-902b-594ea8c61554.mp3" length="65969428" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:31:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has posted an updated on some of their activities between October and December of 2014&lt;/li&gt;
&lt;li&gt;They put a big focus on compatibility with other systems: the Linux emulation layer, &lt;a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener"&gt;bhyve&lt;/a&gt;, WINE and Xen all got some nice improvements&lt;/li&gt;
&lt;li&gt;As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure&lt;/li&gt;
&lt;li&gt;The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs&lt;/li&gt;
&lt;li&gt;FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)&lt;/li&gt;
&lt;li&gt;Git was promoted from beta to an officially-supported version control system (Kris is happy)&lt;/li&gt;
&lt;li&gt;The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints&lt;/li&gt;
&lt;li&gt;Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements&lt;/li&gt;
&lt;li&gt;Check out the full report for all the details that we didn't cover
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener"&gt;OpenBSD package signature audit&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes&lt;/li&gt;
&lt;li&gt;They recently did an article about OpenBSD, specifically their &lt;a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener"&gt;ports and package system&lt;/a&gt; and signing infrastructure&lt;/li&gt;
&lt;li&gt;The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed&lt;/li&gt;
&lt;li&gt;Package signature formats and public key distribution methods are also touched on&lt;/li&gt;
&lt;li&gt;After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future&lt;/li&gt;
&lt;li&gt;If you haven't seen &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;our episode about signify&lt;/a&gt; with Ted Unangst, that would be a great one to check out after reading this
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener"&gt;Replacing a Linux router with BSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one&lt;/li&gt;
&lt;li&gt;The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."&lt;/li&gt;
&lt;li&gt;A lot of people were quick to recommend &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt; and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)&lt;/li&gt;
&lt;li&gt;Other commenters suggested a more hands-on approach, setting one up yourself with &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt; or &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through&lt;/li&gt;
&lt;li&gt;Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener"&gt;LibreSSL in FreeBSD and OPNsense&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)&lt;/li&gt;
&lt;li&gt;The reasoning being that updates in base &lt;a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener"&gt;tend to lag behind&lt;/a&gt;, whereas the port can be updated for security very quickly&lt;/li&gt;
&lt;li&gt;OPNsense developers are &lt;a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener"&gt;looking into&lt;/a&gt;  &lt;a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener"&gt;switching away&lt;/a&gt; from OpenSSL to &lt;a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener"&gt;LibreSSL's portable version&lt;/a&gt;, for both their ports and base system, which would be a pretty huge differentiator for their project&lt;/li&gt;
&lt;li&gt;Some ports &lt;a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;amp;query_format=advanced&amp;amp;short_desc=libressl&amp;amp;short_desc_type=allwordssubstr" rel="nofollow noopener"&gt;still need fixing&lt;/a&gt; to be compatible though, particularly &lt;a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener"&gt;a few&lt;/a&gt; &lt;a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener"&gt;python-related&lt;/a&gt; ones&lt;/li&gt;
&lt;li&gt;If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs&lt;/li&gt;
&lt;li&gt;A lot of the work has already been done &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener"&gt;in OpenBSD's ports tree&lt;/a&gt; - some patches just need to be adopted&lt;/li&gt;
&lt;li&gt;More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - David Maxwell - &lt;a href="mailto:david@netbsd.org" rel="nofollow noopener"&gt;david@netbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener"&gt;@david_w_maxwell&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener"&gt;Pipecut&lt;/a&gt;, text processing, commandline wizardry&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener"&gt;Jetpack, a new jail container system&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new project was launched to adapt FreeBSD jails to the "app container specification"&lt;/li&gt;
&lt;li&gt;While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker&lt;/li&gt;
&lt;li&gt;It's a similar project to &lt;a href="https://github.com/pannon/iocage" rel="nofollow noopener"&gt;iocage&lt;/a&gt; or &lt;a href="https://github.com/ployground/bsdploy" rel="nofollow noopener"&gt;bsdploy&lt;/a&gt;, which we haven't talked a whole lot about&lt;/li&gt;
&lt;li&gt;There was also &lt;a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener"&gt;some discussion&lt;/a&gt; about it on Hacker News
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener"&gt;Separating base and package binaries&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;All of the main BSDs make a strong separation between the base system and third party software&lt;/li&gt;
&lt;li&gt;This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory&lt;/li&gt;
&lt;li&gt;A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies&lt;/li&gt;
&lt;li&gt;Read the comments for the full explanation, but having things separated really helps keep things organized
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=277487" rel="nofollow noopener"&gt;Updated i915kms driver for FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward&lt;/li&gt;
&lt;li&gt;It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener"&gt;Year of the OpenBSD desktop&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have an article about using OpenBSD as a daily driver for regular desktop usage&lt;/li&gt;
&lt;li&gt;The author says he "ran fifty thousand different distributions, never being satisfied"&lt;/li&gt;
&lt;li&gt;After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook&lt;/li&gt;
&lt;li&gt;He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again&lt;/li&gt;
&lt;li&gt;Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201&lt;/li&gt;
&lt;li&gt;The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup&lt;/li&gt;
&lt;li&gt;He apparently used &lt;a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener"&gt;our desktop tutorial&lt;/a&gt; - thanks for watching!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener"&gt;Unattended FreeBSD installation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE&lt;/li&gt;
&lt;li&gt;His goal was to have a setup similar to Redhat's "kickstart" or &lt;a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener"&gt;OpenBSD's autoinstall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The article shows you how to set up DHCP and TFTP, with no NFS share setup required&lt;/li&gt;
&lt;li&gt;He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener"&gt;Robert writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener"&gt;l33tname writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener"&gt;Charlie writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener"&gt;Eric writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142159202606668&amp;amp;w=2" rel="nofollow noopener"&gt;Clowning around&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener"&gt;Better than succeeding in this case&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pipecut, david maxwell, commandline, shell, libressl, router, pf, cryptography, router, openssl, bhyve, digitalocean</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>55: The Promised WLAN</title>
  <link>https://www.bsdnow.tv/55</link>
  <guid isPermaLink="false">138f743e-c056-4292-9d04-7a7022b34944</guid>
  <pubDate>Wed, 17 Sep 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/138f743e-c056-4292-9d04-7a7022b34944.mp3" length="57124948" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be talking with Adrian Chadd about all things wireless, his experience with FreeBSD on various laptop hardware and a whole lot more. As usual, we've got the latest news and answers to all your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:19:20</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be talking with Adrian Chadd about all things wireless, his experience with FreeBSD on various laptop hardware and a whole lot more. As usual, we've got the latest news and answers to all your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://ftp.freebsd.org/pub/FreeBSD/releases/ISO-IMAGES/10.1/" rel="nofollow noopener"&gt;FreeBSD 10.1-BETA1 is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The first maintenance update in the 10.x series of FreeBSD is on its way&lt;/li&gt;
&lt;li&gt;Since we can't see a changelog yet, the 10-STABLE &lt;a href="https://www.freebsd.org/relnotes/10-STABLE/relnotes/article.html" rel="nofollow noopener"&gt;release notes&lt;/a&gt; offer a glimpse at some of the new features and fixes that will be included in 10.1&lt;/li&gt;
&lt;li&gt;The vt driver was merged from -CURRENT, lots of drivers were updated, lots of bugs were fixed and bhyve also got many improvements from 11&lt;/li&gt;
&lt;li&gt;Initial UEFI support, multithreaded softupdates for UFS and many more things were added&lt;/li&gt;
&lt;li&gt;You can check the &lt;a href="https://www.freebsd.org/releases/10.1R/schedule.html" rel="nofollow noopener"&gt;release schedule&lt;/a&gt; for the planned release dates&lt;/li&gt;
&lt;li&gt;Details for the various forms of release media can be found in &lt;a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-September/080106.html" rel="nofollow noopener"&gt;the announcement&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://jcs.org/notaweblog/2014/09/12/remotely_installing_openbsd_on_a/" rel="nofollow noopener"&gt;Remote headless OpenBSD installation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A lot of server providers only offer a limited number of operating systems to be easily installed on their boxes&lt;/li&gt;
&lt;li&gt;Sometimes you'll get lucky and they'll offer FreeBSD, but it's much harder to find ones that natively support other BSDs&lt;/li&gt;
&lt;li&gt;This article shows how you can use a Linux-based rescue system, a RAM disk and QEMU to install OpenBSD on the bare metal of a server, headlessly and remotely&lt;/li&gt;
&lt;li&gt;It required a few specific steps you'll want to take note of, but is &lt;strong&gt;extremely useful&lt;/strong&gt; for those pesky hosting providers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.get-virtual.net/2014/09/16/build-firewall-appliance/" rel="nofollow noopener"&gt;Building a firewall appliance with pfSense&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In this article, we learn how to easily set up a gateway and wireless access point with pfSense on a Netgate &lt;a href="http://pcengines.ch/alix2c3.htm" rel="nofollow noopener"&gt;ALIX2C3 APU&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;After the author's modem died, he decided to look into a more do-it-yourself option with pf and a tiny router board&lt;/li&gt;
&lt;li&gt;The hardware he used has gigabit ports and a BSD-compatible wireless card, as well as enough CPU power for a modest workload and a few services (OpenVPN, etc.)&lt;/li&gt;
&lt;li&gt;There's a lot of &lt;em&gt;great&lt;/em&gt; pictures of the hardware and detailed screenshots, definitely worth a look
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://adrianchadd.blogspot.com/2014/09/receive-side-scaling-testing-udp.html" rel="nofollow noopener"&gt;Receive Side Scaling - UDP testing&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Adrian Chadd has been working on RSS (Receive Side Scaling) in FreeBSD, and gives an update on the progress&lt;/li&gt;
&lt;li&gt;He's using some quad core boxes with 10 gigabit ethernet for the tests&lt;/li&gt;
&lt;li&gt;The post gives lots of stats and results from his network benchmark, as well as some interesting workarounds he had to do&lt;/li&gt;
&lt;li&gt;He also provides some system configuration options, sysctl knobs, etc. (if you want to try it out)&lt;/li&gt;
&lt;li&gt;And speaking of Adrian Chadd...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Adrian Chadd - &lt;a href="mailto:adrian@freebsd.org" rel="nofollow noopener"&gt;adrian@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/erikarn" rel="nofollow noopener"&gt;@erikarn&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;BSD on laptops, wifi, drivers, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140916084251" rel="nofollow noopener"&gt;Sendmail removed from OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Mail server admins around the world &lt;a href="https://news.ycombinator.com/item?id=8324475" rel="nofollow noopener"&gt;are rejoicing&lt;/a&gt;, because sendmail is &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=141081997917153&amp;amp;w=2" rel="nofollow noopener"&gt;finally gone&lt;/a&gt; from OpenBSD&lt;/li&gt;
&lt;li&gt;With OpenSMTPD being a part of the base system, sendmail became largely redundant and unneeded&lt;/li&gt;
&lt;li&gt;If you've ever compared a "sendmail.cf" file to an "smtpd.conf" file... the different is as clear as night and day&lt;/li&gt;
&lt;li&gt;5.6 will serve as a transitional release, including both sendmail and OpenSMTPD, but 5.7 will be the first release without it&lt;/li&gt;
&lt;li&gt;If you still need it for some reason, sendmail will live in ports from now on&lt;/li&gt;
&lt;li&gt;Hopefully FreeBSD will follow suit sometime in the future as well, possibly including DragonFly's mail transfer agent in base (instead of an entire mail server)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/zinkwazi/pfmb" rel="nofollow noopener"&gt;pfSense backups with pfmb&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've mentioned the need for a tool to back up pfSense configs a number of times on the show&lt;/li&gt;
&lt;li&gt;This script, hosted on github, does pretty much exactly that&lt;/li&gt;
&lt;li&gt;It can connect to one (or more!) pfSense installations and back up the configuration&lt;/li&gt;
&lt;li&gt;You can roll back or replace failed hardware very easily with its restore function&lt;/li&gt;
&lt;li&gt;Everything is done over SSH, so it should be pretty secure
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.amazon.com/dp/0321968972/" rel="nofollow noopener"&gt;The Design and Implementation of the FreeBSD Operating System&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned when the pre orders were up, but now "The Design and Implementation of the FreeBSD Operating System, 2nd edition" seems to be shipping out&lt;/li&gt;
&lt;li&gt;If you're interested in FreeBSD development, or learning about the operating system internals, this is a great book to buy&lt;/li&gt;
&lt;li&gt;We've even had &lt;a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener"&gt;all&lt;/a&gt; &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;three&lt;/a&gt; &lt;a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" rel="nofollow noopener"&gt;authors&lt;/a&gt; on the show before!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140915064856" rel="nofollow noopener"&gt;OpenBSD's systemd replacement updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned last week that the news of OpenBSD creating systemd wrappers was getting mainstream attention&lt;/li&gt;
&lt;li&gt;One of the developers writes in to Undeadly, detailing what's going on and what the overall status is&lt;/li&gt;
&lt;li&gt;He also clears up any confusion about "porting systemd to BSD" &lt;strong&gt;(that's not what's going on)&lt;/strong&gt; or his code ever ending up in base &lt;strong&gt;(it won't)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;The top comment as of right now is a Linux user asking if his systemd wrappers can be ported back to Linux... poor guy
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20jrx0nIf" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21hFUJ2ju" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21RgSzOv4" rel="nofollow noopener"&gt;Mathieu writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2P1mzalPh" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, bsd, interview, adrian chadd, wireless, wifi, aircrack-ng, kismet, packet injection, monitor mode, libressl, openssl, qemu, zfs, jails, headless, remote, pfsense, systemd, netgate, apu</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be talking with Adrian Chadd about all things wireless, his experience with FreeBSD on various laptop hardware and a whole lot more. As usual, we've got the latest news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://ftp.freebsd.org/pub/FreeBSD/releases/ISO-IMAGES/10.1/" rel="nofollow noopener">FreeBSD 10.1-BETA1 is out</a></h3>

<ul>
<li>The first maintenance update in the 10.x series of FreeBSD is on its way</li>
<li>Since we can't see a changelog yet, the 10-STABLE <a href="https://www.freebsd.org/relnotes/10-STABLE/relnotes/article.html" rel="nofollow noopener">release notes</a> offer a glimpse at some of the new features and fixes that will be included in 10.1</li>
<li>The vt driver was merged from -CURRENT, lots of drivers were updated, lots of bugs were fixed and bhyve also got many improvements from 11</li>
<li>Initial UEFI support, multithreaded softupdates for UFS and many more things were added</li>
<li>You can check the <a href="https://www.freebsd.org/releases/10.1R/schedule.html" rel="nofollow noopener">release schedule</a> for the planned release dates</li>
<li>Details for the various forms of release media can be found in <a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-September/080106.html" rel="nofollow noopener">the announcement</a>
***</li>
</ul>

<h3><a href="https://jcs.org/notaweblog/2014/09/12/remotely_installing_openbsd_on_a/" rel="nofollow noopener">Remote headless OpenBSD installation</a></h3>

<ul>
<li>A lot of server providers only offer a limited number of operating systems to be easily installed on their boxes</li>
<li>Sometimes you'll get lucky and they'll offer FreeBSD, but it's much harder to find ones that natively support other BSDs</li>
<li>This article shows how you can use a Linux-based rescue system, a RAM disk and QEMU to install OpenBSD on the bare metal of a server, headlessly and remotely</li>
<li>It required a few specific steps you'll want to take note of, but is <strong>extremely useful</strong> for those pesky hosting providers
***</li>
</ul>

<h3><a href="http://www.get-virtual.net/2014/09/16/build-firewall-appliance/" rel="nofollow noopener">Building a firewall appliance with pfSense</a></h3>

<ul>
<li>In this article, we learn how to easily set up a gateway and wireless access point with pfSense on a Netgate <a href="http://pcengines.ch/alix2c3.htm" rel="nofollow noopener">ALIX2C3 APU</a></li>
<li>After the author's modem died, he decided to look into a more do-it-yourself option with pf and a tiny router board</li>
<li>The hardware he used has gigabit ports and a BSD-compatible wireless card, as well as enough CPU power for a modest workload and a few services (OpenVPN, etc.)</li>
<li>There's a lot of <em>great</em> pictures of the hardware and detailed screenshots, definitely worth a look
***</li>
</ul>

<h3><a href="http://adrianchadd.blogspot.com/2014/09/receive-side-scaling-testing-udp.html" rel="nofollow noopener">Receive Side Scaling - UDP testing</a></h3>

<ul>
<li>Adrian Chadd has been working on RSS (Receive Side Scaling) in FreeBSD, and gives an update on the progress</li>
<li>He's using some quad core boxes with 10 gigabit ethernet for the tests</li>
<li>The post gives lots of stats and results from his network benchmark, as well as some interesting workarounds he had to do</li>
<li>He also provides some system configuration options, sysctl knobs, etc. (if you want to try it out)</li>
<li>And speaking of Adrian Chadd...
***</li>
</ul>

<h2>Interview - Adrian Chadd - <a href="mailto:adrian@freebsd.org" rel="nofollow noopener">adrian@freebsd.org</a> / <a href="https://twitter.com/erikarn" rel="nofollow noopener">@erikarn</a></h2>

<p>BSD on laptops, wifi, drivers, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140916084251" rel="nofollow noopener">Sendmail removed from OpenBSD</a></h3>

<ul>
<li>Mail server admins around the world <a href="https://news.ycombinator.com/item?id=8324475" rel="nofollow noopener">are rejoicing</a>, because sendmail is <a href="http://marc.info/?l=openbsd-cvs&amp;m=141081997917153&amp;w=2" rel="nofollow noopener">finally gone</a> from OpenBSD</li>
<li>With OpenSMTPD being a part of the base system, sendmail became largely redundant and unneeded</li>
<li>If you've ever compared a "sendmail.cf" file to an "smtpd.conf" file... the different is as clear as night and day</li>
<li>5.6 will serve as a transitional release, including both sendmail and OpenSMTPD, but 5.7 will be the first release without it</li>
<li>If you still need it for some reason, sendmail will live in ports from now on</li>
<li>Hopefully FreeBSD will follow suit sometime in the future as well, possibly including DragonFly's mail transfer agent in base (instead of an entire mail server)
***</li>
</ul>

<h3><a href="https://github.com/zinkwazi/pfmb" rel="nofollow noopener">pfSense backups with pfmb</a></h3>

<ul>
<li>We've mentioned the need for a tool to back up pfSense configs a number of times on the show</li>
<li>This script, hosted on github, does pretty much exactly that</li>
<li>It can connect to one (or more!) pfSense installations and back up the configuration</li>
<li>You can roll back or replace failed hardware very easily with its restore function</li>
<li>Everything is done over SSH, so it should be pretty secure
***</li>
</ul>

<h3><a href="http://www.amazon.com/dp/0321968972/" rel="nofollow noopener">The Design and Implementation of the FreeBSD Operating System</a></h3>

<ul>
<li>We mentioned when the pre orders were up, but now "The Design and Implementation of the FreeBSD Operating System, 2nd edition" seems to be shipping out</li>
<li>If you're interested in FreeBSD development, or learning about the operating system internals, this is a great book to buy</li>
<li>We've even had <a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener">all</a> <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">three</a> <a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" rel="nofollow noopener">authors</a> on the show before!
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140915064856" rel="nofollow noopener">OpenBSD's systemd replacement updates</a></h3>

<ul>
<li>We mentioned last week that the news of OpenBSD creating systemd wrappers was getting mainstream attention</li>
<li>One of the developers writes in to Undeadly, detailing what's going on and what the overall status is</li>
<li>He also clears up any confusion about "porting systemd to BSD" <strong>(that's not what's going on)</strong> or his code ever ending up in base <strong>(it won't)</strong></li>
<li>The top comment as of right now is a Linux user asking if his systemd wrappers can be ported back to Linux... poor guy
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20jrx0nIf" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21hFUJ2ju" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s21RgSzOv4" rel="nofollow noopener">Mathieu writes in</a></li>
<li><a href="http://slexy.org/view/s2P1mzalPh" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be talking with Adrian Chadd about all things wireless, his experience with FreeBSD on various laptop hardware and a whole lot more. As usual, we've got the latest news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://ftp.freebsd.org/pub/FreeBSD/releases/ISO-IMAGES/10.1/" rel="nofollow noopener">FreeBSD 10.1-BETA1 is out</a></h3>

<ul>
<li>The first maintenance update in the 10.x series of FreeBSD is on its way</li>
<li>Since we can't see a changelog yet, the 10-STABLE <a href="https://www.freebsd.org/relnotes/10-STABLE/relnotes/article.html" rel="nofollow noopener">release notes</a> offer a glimpse at some of the new features and fixes that will be included in 10.1</li>
<li>The vt driver was merged from -CURRENT, lots of drivers were updated, lots of bugs were fixed and bhyve also got many improvements from 11</li>
<li>Initial UEFI support, multithreaded softupdates for UFS and many more things were added</li>
<li>You can check the <a href="https://www.freebsd.org/releases/10.1R/schedule.html" rel="nofollow noopener">release schedule</a> for the planned release dates</li>
<li>Details for the various forms of release media can be found in <a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-September/080106.html" rel="nofollow noopener">the announcement</a>
***</li>
</ul>

<h3><a href="https://jcs.org/notaweblog/2014/09/12/remotely_installing_openbsd_on_a/" rel="nofollow noopener">Remote headless OpenBSD installation</a></h3>

<ul>
<li>A lot of server providers only offer a limited number of operating systems to be easily installed on their boxes</li>
<li>Sometimes you'll get lucky and they'll offer FreeBSD, but it's much harder to find ones that natively support other BSDs</li>
<li>This article shows how you can use a Linux-based rescue system, a RAM disk and QEMU to install OpenBSD on the bare metal of a server, headlessly and remotely</li>
<li>It required a few specific steps you'll want to take note of, but is <strong>extremely useful</strong> for those pesky hosting providers
***</li>
</ul>

<h3><a href="http://www.get-virtual.net/2014/09/16/build-firewall-appliance/" rel="nofollow noopener">Building a firewall appliance with pfSense</a></h3>

<ul>
<li>In this article, we learn how to easily set up a gateway and wireless access point with pfSense on a Netgate <a href="http://pcengines.ch/alix2c3.htm" rel="nofollow noopener">ALIX2C3 APU</a></li>
<li>After the author's modem died, he decided to look into a more do-it-yourself option with pf and a tiny router board</li>
<li>The hardware he used has gigabit ports and a BSD-compatible wireless card, as well as enough CPU power for a modest workload and a few services (OpenVPN, etc.)</li>
<li>There's a lot of <em>great</em> pictures of the hardware and detailed screenshots, definitely worth a look
***</li>
</ul>

<h3><a href="http://adrianchadd.blogspot.com/2014/09/receive-side-scaling-testing-udp.html" rel="nofollow noopener">Receive Side Scaling - UDP testing</a></h3>

<ul>
<li>Adrian Chadd has been working on RSS (Receive Side Scaling) in FreeBSD, and gives an update on the progress</li>
<li>He's using some quad core boxes with 10 gigabit ethernet for the tests</li>
<li>The post gives lots of stats and results from his network benchmark, as well as some interesting workarounds he had to do</li>
<li>He also provides some system configuration options, sysctl knobs, etc. (if you want to try it out)</li>
<li>And speaking of Adrian Chadd...
***</li>
</ul>

<h2>Interview - Adrian Chadd - <a href="mailto:adrian@freebsd.org" rel="nofollow noopener">adrian@freebsd.org</a> / <a href="https://twitter.com/erikarn" rel="nofollow noopener">@erikarn</a></h2>

<p>BSD on laptops, wifi, drivers, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140916084251" rel="nofollow noopener">Sendmail removed from OpenBSD</a></h3>

<ul>
<li>Mail server admins around the world <a href="https://news.ycombinator.com/item?id=8324475" rel="nofollow noopener">are rejoicing</a>, because sendmail is <a href="http://marc.info/?l=openbsd-cvs&amp;m=141081997917153&amp;w=2" rel="nofollow noopener">finally gone</a> from OpenBSD</li>
<li>With OpenSMTPD being a part of the base system, sendmail became largely redundant and unneeded</li>
<li>If you've ever compared a "sendmail.cf" file to an "smtpd.conf" file... the different is as clear as night and day</li>
<li>5.6 will serve as a transitional release, including both sendmail and OpenSMTPD, but 5.7 will be the first release without it</li>
<li>If you still need it for some reason, sendmail will live in ports from now on</li>
<li>Hopefully FreeBSD will follow suit sometime in the future as well, possibly including DragonFly's mail transfer agent in base (instead of an entire mail server)
***</li>
</ul>

<h3><a href="https://github.com/zinkwazi/pfmb" rel="nofollow noopener">pfSense backups with pfmb</a></h3>

<ul>
<li>We've mentioned the need for a tool to back up pfSense configs a number of times on the show</li>
<li>This script, hosted on github, does pretty much exactly that</li>
<li>It can connect to one (or more!) pfSense installations and back up the configuration</li>
<li>You can roll back or replace failed hardware very easily with its restore function</li>
<li>Everything is done over SSH, so it should be pretty secure
***</li>
</ul>

<h3><a href="http://www.amazon.com/dp/0321968972/" rel="nofollow noopener">The Design and Implementation of the FreeBSD Operating System</a></h3>

<ul>
<li>We mentioned when the pre orders were up, but now "The Design and Implementation of the FreeBSD Operating System, 2nd edition" seems to be shipping out</li>
<li>If you're interested in FreeBSD development, or learning about the operating system internals, this is a great book to buy</li>
<li>We've even had <a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener">all</a> <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">three</a> <a href="http://www.bsdnow.tv/episodes/2014_08_13-vpn_my_dear_watson" rel="nofollow noopener">authors</a> on the show before!
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140915064856" rel="nofollow noopener">OpenBSD's systemd replacement updates</a></h3>

<ul>
<li>We mentioned last week that the news of OpenBSD creating systemd wrappers was getting mainstream attention</li>
<li>One of the developers writes in to Undeadly, detailing what's going on and what the overall status is</li>
<li>He also clears up any confusion about "porting systemd to BSD" <strong>(that's not what's going on)</strong> or his code ever ending up in base <strong>(it won't)</strong></li>
<li>The top comment as of right now is a Linux user asking if his systemd wrappers can be ported back to Linux... poor guy
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20jrx0nIf" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21hFUJ2ju" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s21RgSzOv4" rel="nofollow noopener">Mathieu writes in</a></li>
<li><a href="http://slexy.org/view/s2P1mzalPh" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>50: VPN, My Dear Watson</title>
  <link>https://www.bsdnow.tv/50</link>
  <guid isPermaLink="false">b0306dc5-ee87-4a03-aeea-9a89b915ff5e</guid>
  <pubDate>Wed, 13 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b0306dc5-ee87-4a03-aeea-9a89b915ff5e.mp3" length="62998996" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:27:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener"&gt;MeetBSD 2014 is approaching&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California&lt;/li&gt;
&lt;li&gt;MeetBSD has an "unconference" format, which means there will be both planned talks and community events&lt;/li&gt;
&lt;li&gt;All the extra details will be on &lt;a href="https://www.meetbsd.com/" rel="nofollow noopener"&gt;their site&lt;/a&gt; soon&lt;/li&gt;
&lt;li&gt;It also has hotels and various other bits of useful information - hopefully with more info on the talks to come&lt;/li&gt;
&lt;li&gt;Of course, EuroBSDCon is coming up before then
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener"&gt;First experiences with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"&lt;/li&gt;
&lt;li&gt;The author read the famous "&lt;a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener"&gt;BSD for Linux users&lt;/a&gt;" series (that most of us have surely seen) and decided to give BSD a try&lt;/li&gt;
&lt;li&gt;He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"&lt;/li&gt;
&lt;li&gt;From there, it talks about how he used the OpenBSD USB image and got a fully-working system&lt;/li&gt;
&lt;li&gt;He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration&lt;/li&gt;
&lt;li&gt;Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener"&gt;NetBSD rump kernels on bare metal (and Kansai OSC report)&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right&lt;/li&gt;
&lt;li&gt;However, NetBSD's rump kernels - a very unique concept - make this process a lot easier&lt;/li&gt;
&lt;li&gt;This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week&lt;/li&gt;
&lt;li&gt;Also have a look back at &lt;a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener"&gt;episode 8&lt;/a&gt; for our interview about rump kernels and what exactly they do&lt;/li&gt;
&lt;li&gt;While on the topic of NetBSD, there were also a couple of &lt;a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener"&gt;very detailed reports&lt;/a&gt; (with lots of pictures!) of the various NetBSD-themed booths at the 2014 &lt;a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener"&gt;Kansai Open Source Conference&lt;/a&gt; that we wanted to highlight
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener"&gt;OpenSSL and LibreSSL updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)&lt;/li&gt;
&lt;li&gt;Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more&lt;/li&gt;
&lt;li&gt;&lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140752295222929&amp;amp;w=2" rel="nofollow noopener"&gt;LibreSSL released a new version&lt;/a&gt; to address most of the vulnerabilities, but wasn't affected by some of them&lt;/li&gt;
&lt;li&gt;Whichever version of whatever SSL you use, make sure it's patched for these issues&lt;/li&gt;
&lt;li&gt;DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Robert Watson - &lt;a href="mailto:rwatson@freebsd.org" rel="nofollow noopener"&gt;rwatson@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD architecture, security research techniques, exploit mitigation&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener"&gt;Protecting traffic with a BSD-based VPN&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener"&gt;A FreeBSD-based CGit server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you use git (like a certain host of this show) then you've probably considered setting up your own server&lt;/li&gt;
&lt;li&gt;This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend&lt;/li&gt;
&lt;li&gt;It even shows you how to set up multiple repos with key-based user separation and other cool things&lt;/li&gt;
&lt;li&gt;The author of the post is also a listener of the show, thanks for sending it in!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener"&gt;Backup devices for small businesses&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In this article, different methods of data storage and backup are compared&lt;/li&gt;
&lt;li&gt;After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer&lt;/li&gt;
&lt;li&gt;He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers&lt;/li&gt;
&lt;li&gt;It also goes over some of the hardware specifics in the FreeNAS Mini
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener"&gt;A new Xenocara interview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara&lt;/li&gt;
&lt;li&gt;If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches&lt;/li&gt;
&lt;li&gt;In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing&lt;/li&gt;
&lt;li&gt;Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener"&gt;Building a high performance FreeBSD samba server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?&lt;/li&gt;
&lt;li&gt;FreeBSD, ZFS and Samba obviously!&lt;/li&gt;
&lt;li&gt;The master image and related files clock in at over 20GB, and will be accessed at the same time by &lt;em&gt;all&lt;/em&gt; of those clients&lt;/li&gt;
&lt;li&gt;This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)&lt;/li&gt;
&lt;li&gt;It doesn't even require the newest or best hardware with the right changes, pretty cool
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener"&gt;An interesting Reddit thread&lt;/a&gt; (&lt;a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener"&gt;or two&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener"&gt;PB writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener"&gt;Lachlan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener"&gt;Justin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, vpn, vps, openvpn, tunnel, ssh, security, exploit mitigation, zfs, lzo, tls, xenocara, x11, xorg, freenas, freenas mini, ixsystems, network attached storage, nas, meetbsd, rump kernels, libressl, openssl, kansai</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener">MeetBSD 2014 is approaching</a></h3>

<ul>
<li>The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California</li>
<li>MeetBSD has an "unconference" format, which means there will be both planned talks and community events</li>
<li>All the extra details will be on <a href="https://www.meetbsd.com/" rel="nofollow noopener">their site</a> soon</li>
<li>It also has hotels and various other bits of useful information - hopefully with more info on the talks to come</li>
<li>Of course, EuroBSDCon is coming up before then
***</li>
</ul>

<h3><a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener">First experiences with OpenBSD</a></h3>

<ul>
<li>A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"</li>
<li>The author read the famous "<a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener">BSD for Linux users</a>" series (that most of us have surely seen) and decided to give BSD a try</li>
<li>He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"</li>
<li>From there, it talks about how he used the OpenBSD USB image and got a fully-working system</li>
<li>He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration</li>
<li>Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener">NetBSD rump kernels on bare metal (and Kansai OSC report)</a></h3>

<ul>
<li>When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right</li>
<li>However, NetBSD's rump kernels - a very unique concept - make this process a lot easier</li>
<li>This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week</li>
<li>Also have a look back at <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">episode 8</a> for our interview about rump kernels and what exactly they do</li>
<li>While on the topic of NetBSD, there were also a couple of <a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener">very detailed reports</a> (with lots of pictures!) of the various NetBSD-themed booths at the 2014 <a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener">Kansai Open Source Conference</a> that we wanted to highlight
***</li>
</ul>

<h3><a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener">OpenSSL and LibreSSL updates</a></h3>

<ul>
<li>OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)</li>
<li>Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more</li>
<li><a href="http://marc.info/?l=openbsd-tech&amp;m=140752295222929&amp;w=2" rel="nofollow noopener">LibreSSL released a new version</a> to address most of the vulnerabilities, but wasn't affected by some of them</li>
<li>Whichever version of whatever SSL you use, make sure it's patched for these issues</li>
<li>DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***</li>
</ul>

<h2>Interview - Robert Watson - <a href="mailto:rwatson@freebsd.org" rel="nofollow noopener">rwatson@freebsd.org</a></h2>

<p>FreeBSD architecture, security research techniques, exploit mitigation</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener">Protecting traffic with a BSD-based VPN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener">A FreeBSD-based CGit server</a></h3>

<ul>
<li>If you use git (like a certain host of this show) then you've probably considered setting up your own server</li>
<li>This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend</li>
<li>It even shows you how to set up multiple repos with key-based user separation and other cool things</li>
<li>The author of the post is also a listener of the show, thanks for sending it in!
***</li>
</ul>

<h3><a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener">Backup devices for small businesses</a></h3>

<ul>
<li>In this article, different methods of data storage and backup are compared</li>
<li>After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer</li>
<li>He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers</li>
<li>It also goes over some of the hardware specifics in the FreeNAS Mini
***</li>
</ul>

<h3><a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener">A new Xenocara interview</a></h3>

<ul>
<li>As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara</li>
<li>If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches</li>
<li>In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing</li>
<li>Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***</li>
</ul>

<h3><a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener">Building a high performance FreeBSD samba server</a></h3>

<ul>
<li>If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?</li>
<li>FreeBSD, ZFS and Samba obviously!</li>
<li>The master image and related files clock in at over 20GB, and will be accessed at the same time by <em>all</em> of those clients</li>
<li>This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)</li>
<li>It doesn't even require the newest or best hardware with the right changes, pretty cool
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener">An interesting Reddit thread</a> (<a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener">or two</a>)</li>
<li><a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener">PB writes in</a></li>
<li><a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener">Steve writes in</a></li>
<li><a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener">Justin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener">MeetBSD 2014 is approaching</a></h3>

<ul>
<li>The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California</li>
<li>MeetBSD has an "unconference" format, which means there will be both planned talks and community events</li>
<li>All the extra details will be on <a href="https://www.meetbsd.com/" rel="nofollow noopener">their site</a> soon</li>
<li>It also has hotels and various other bits of useful information - hopefully with more info on the talks to come</li>
<li>Of course, EuroBSDCon is coming up before then
***</li>
</ul>

<h3><a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener">First experiences with OpenBSD</a></h3>

<ul>
<li>A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"</li>
<li>The author read the famous "<a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener">BSD for Linux users</a>" series (that most of us have surely seen) and decided to give BSD a try</li>
<li>He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"</li>
<li>From there, it talks about how he used the OpenBSD USB image and got a fully-working system</li>
<li>He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration</li>
<li>Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener">NetBSD rump kernels on bare metal (and Kansai OSC report)</a></h3>

<ul>
<li>When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right</li>
<li>However, NetBSD's rump kernels - a very unique concept - make this process a lot easier</li>
<li>This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week</li>
<li>Also have a look back at <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">episode 8</a> for our interview about rump kernels and what exactly they do</li>
<li>While on the topic of NetBSD, there were also a couple of <a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener">very detailed reports</a> (with lots of pictures!) of the various NetBSD-themed booths at the 2014 <a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener">Kansai Open Source Conference</a> that we wanted to highlight
***</li>
</ul>

<h3><a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener">OpenSSL and LibreSSL updates</a></h3>

<ul>
<li>OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)</li>
<li>Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more</li>
<li><a href="http://marc.info/?l=openbsd-tech&amp;m=140752295222929&amp;w=2" rel="nofollow noopener">LibreSSL released a new version</a> to address most of the vulnerabilities, but wasn't affected by some of them</li>
<li>Whichever version of whatever SSL you use, make sure it's patched for these issues</li>
<li>DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***</li>
</ul>

<h2>Interview - Robert Watson - <a href="mailto:rwatson@freebsd.org" rel="nofollow noopener">rwatson@freebsd.org</a></h2>

<p>FreeBSD architecture, security research techniques, exploit mitigation</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener">Protecting traffic with a BSD-based VPN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener">A FreeBSD-based CGit server</a></h3>

<ul>
<li>If you use git (like a certain host of this show) then you've probably considered setting up your own server</li>
<li>This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend</li>
<li>It even shows you how to set up multiple repos with key-based user separation and other cool things</li>
<li>The author of the post is also a listener of the show, thanks for sending it in!
***</li>
</ul>

<h3><a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener">Backup devices for small businesses</a></h3>

<ul>
<li>In this article, different methods of data storage and backup are compared</li>
<li>After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer</li>
<li>He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers</li>
<li>It also goes over some of the hardware specifics in the FreeNAS Mini
***</li>
</ul>

<h3><a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener">A new Xenocara interview</a></h3>

<ul>
<li>As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara</li>
<li>If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches</li>
<li>In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing</li>
<li>Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***</li>
</ul>

<h3><a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener">Building a high performance FreeBSD samba server</a></h3>

<ul>
<li>If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?</li>
<li>FreeBSD, ZFS and Samba obviously!</li>
<li>The master image and related files clock in at over 20GB, and will be accessed at the same time by <em>all</em> of those clients</li>
<li>This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)</li>
<li>It doesn't even require the newest or best hardware with the right changes, pretty cool
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener">An interesting Reddit thread</a> (<a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener">or two</a>)</li>
<li><a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener">PB writes in</a></li>
<li><a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener">Steve writes in</a></li>
<li><a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener">Justin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>49: The PC-BSD Tour</title>
  <link>https://www.bsdnow.tv/49</link>
  <guid isPermaLink="false">ccc19842-ae62-43a9-8f82-44f3f281de42</guid>
  <pubDate>Wed, 06 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/ccc19842-ae62-43a9-8f82-44f3f281de42.mp3" length="59661652" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:22:51</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener"&gt;FreeBSD foundation semi-annual newsletter&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation&lt;/li&gt;
&lt;li&gt;"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"&lt;/li&gt;
&lt;li&gt;It talks about the &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;FreeBSD journal&lt;/a&gt; as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT&lt;/li&gt;
&lt;li&gt;The full list of funded projects is included, also with details in the financial reports&lt;/li&gt;
&lt;li&gt;There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, intel nuc, nuc, gui, ssl, tls, libressl, openssl, foundation, bafug, talk, presentation, recording, bhyve, libvirt, rss, netmap, opensmtpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation</li>
<li>"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"</li>
<li>It talks about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD journal</a> as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT</li>
<li>The full list of funded projects is included, also with details in the financial reports</li>
<li>There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation</li>
<li>"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"</li>
<li>It talks about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD journal</a> as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT</li>
<li>The full list of funded projects is included, also with details in the financial reports</li>
<li>There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>48: Liberating SSL</title>
  <link>https://www.bsdnow.tv/48</link>
  <guid isPermaLink="false">e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809</guid>
  <pubDate>Wed, 30 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809.mp3" length="43106548" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>59:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD has gotten quite a lot done this quarter&lt;/li&gt;
&lt;li&gt;Changes in the way release branches are supported - major releases will get at least five years over their lifespan&lt;/li&gt;
&lt;li&gt;A new automounter is in the works, hoping to replace amd (which has some issues)&lt;/li&gt;
&lt;li&gt;The CAM target layer and RPC stack have gotten some major optimization and speed boosts&lt;/li&gt;
&lt;li&gt;Work on ZFSGuru continues, with a large status report specifically for that&lt;/li&gt;
&lt;li&gt;The report also mentioned some new committers, both source and ports&lt;/li&gt;
&lt;li&gt;It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show&lt;/li&gt;
&lt;li&gt;"Foundation-sponsored work resulted in &lt;strong&gt;226 commits&lt;/strong&gt; to FreeBSD over the April to June period"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724094043" rel="nofollow noopener"&gt;A new OpenBSD HTTPD is born&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Work has begun on a new HTTP daemon in the OpenBSD base system&lt;/li&gt;
&lt;li&gt;A lot of people are &lt;a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener"&gt;asking&lt;/a&gt; "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?&lt;/li&gt;
&lt;li&gt;Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)&lt;/li&gt;
&lt;li&gt;It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter&lt;/li&gt;
&lt;li&gt;This has the added benefit of the usual, easy-to-understand syntax and privilege separation &lt;/li&gt;
&lt;li&gt;There's a very brief &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener"&gt;man page&lt;/a&gt; online already&lt;/li&gt;
&lt;li&gt;It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs&lt;/li&gt;
&lt;li&gt;Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener"&gt;pkgng 1.3 announced&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest version of FreeBSD's second generation &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener"&gt;package management system&lt;/a&gt; has been released, with lots of new features&lt;/li&gt;
&lt;li&gt;It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)&lt;/li&gt;
&lt;li&gt;Lots of the code has been sandboxed for extra security&lt;/li&gt;
&lt;li&gt;You'll probably notice some new changes to the UI too, making things more user friendly&lt;/li&gt;
&lt;li&gt;A few days later &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;sortby=date&amp;amp;revision=362996" rel="nofollow noopener"&gt;1.3.1&lt;/a&gt; was released to fix a few small bugs, then &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363108" rel="nofollow noopener"&gt;1.3.2&lt;/a&gt; shortly thereafter and &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363363" rel="nofollow noopener"&gt;1.3.3&lt;/a&gt; yesterday
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener"&gt;FreeBSD after-install security tasks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A number of people have written in to ask us "how do I secure my BSD box after I install it?"&lt;/li&gt;
&lt;li&gt;With this blog post, hopefully most of their questions will finally be answered in detail&lt;/li&gt;
&lt;li&gt;It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things&lt;/li&gt;
&lt;li&gt;Not only does it just list things to do, but the post also does a good job of explaining why you should do them&lt;/li&gt;
&lt;li&gt;Maybe we'll see some more posts in this series in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Brent Cook - &lt;a href="mailto:bcook@openbsd.org" rel="nofollow noopener"&gt;bcook@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/busterbcook" rel="nofollow noopener"&gt;@busterbcook&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;LibreSSL's portable version and development&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener"&gt;FreeBSD Mastery - Storage Essentials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;MWL&lt;/a&gt;'s new book about the FreeBSD storage subsystems now has an early draft available&lt;/li&gt;
&lt;li&gt;Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes&lt;/li&gt;
&lt;li&gt;Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance&lt;/li&gt;
&lt;li&gt;You'll get access to the completed (e)book when it's done if you buy the early draft&lt;/li&gt;
&lt;li&gt;The suggested price is $8
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener"&gt;Why BSD and not Linux?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another thread comes up asking why you should choose BSD over Linux or vice-versa&lt;/li&gt;
&lt;li&gt;Lots of good responses from users of the various BSDs&lt;/li&gt;
&lt;li&gt;Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."&lt;/li&gt;
&lt;li&gt;And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."&lt;/li&gt;
&lt;li&gt;Some other users share their switching experiences - worth a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" rel="nofollow noopener"&gt;More g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Following up from last week's &lt;a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener"&gt;huge list&lt;/a&gt; of hackathon reports, we have a few more&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" rel="nofollow noopener"&gt;Landry Breuil&lt;/a&gt; spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140728122850" rel="nofollow noopener"&gt;Andrew Fresh&lt;/a&gt; enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140729070721" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth&lt;/li&gt;
&lt;li&gt;Luckily we didn't have to cover 20 new ones this time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener"&gt;BSDTalk episode 243&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest episode of &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener"&gt;BSDTalk&lt;/a&gt; is out, featuring an interview with Ingo Schwarze of the OpenBSD team&lt;/li&gt;
&lt;li&gt;The main topic of discussion is mandoc, which some users might not be familiar with&lt;/li&gt;
&lt;li&gt;mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)&lt;/li&gt;
&lt;li&gt;We'll catch up to you soon, Will!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener"&gt;Thomas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener"&gt;Stephen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener"&gt;Bob Beck writes in&lt;/a&gt; - and note the "Caution" section that was added to &lt;a href="http://www.libressl.org/" rel="nofollow noopener"&gt;libressl.org&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, portable, openssh, security, linux, arc4random, intrinsic functions, rng, prng, status report, pkgng, openhttpd, relayd, httpd, web server, zfsguru, zfs, freebsd mastery, book, storage, ufs, geom, disks, presentation, talk, comparison, mandoc</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>47: DES Challenge IV</title>
  <link>https://www.bsdnow.tv/47</link>
  <guid isPermaLink="false">2c9f4e68-6474-41f9-ab80-bb40fbb76855</guid>
  <pubDate>Wed, 23 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/2c9f4e68-6474-41f9-ab80-bb40fbb76855.mp3" length="66811828" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:32:47</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener"&gt;g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon&lt;/li&gt;
&lt;li&gt;Lots of work got done - in just the first two weeks of July, there were &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;r=1&amp;amp;b=201407&amp;amp;w=2" rel="nofollow noopener"&gt;over 1000 commits&lt;/a&gt; to their CVS tree&lt;/li&gt;
&lt;li&gt;Some of the developers wrote in to document what they were up to at the event&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140713220618" rel="nofollow noopener"&gt;Bob Beck&lt;/a&gt; planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718072312" rel="nofollow noopener"&gt;Miod Vallat&lt;/a&gt; also tells about his LibreSSL experiences&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718090456" rel="nofollow noopener"&gt;Brent Cook&lt;/a&gt;, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714094454" rel="nofollow noopener"&gt;Henning Brauer&lt;/a&gt; worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714191912" rel="nofollow noopener"&gt;Martin Pieuchot&lt;/a&gt; fixed some bugs in the USB stack, softraid and misc other things&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714202157" rel="nofollow noopener"&gt;Marc Espie&lt;/a&gt; improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715120259" rel="nofollow noopener"&gt;Martin Pelikan&lt;/a&gt; integrated read-only ext4 support&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715094848" rel="nofollow noopener"&gt;Vadim Zhukov&lt;/a&gt; did lots of ports work, including working on KDE4&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715212333" rel="nofollow noopener"&gt;Theo de Raadt&lt;/a&gt; created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718134017" rel="nofollow noopener"&gt;Paul Irofti&lt;/a&gt; worked on the USB stack, specifically for the Octeon platform&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719104939" rel="nofollow noopener"&gt;Sebastian Benoit&lt;/a&gt; worked on relayd filters and IPv6 code&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719134058" rel="nofollow noopener"&gt;Jasper Lievisse Adriaanse&lt;/a&gt; did work with puppet, packages and the bootloader&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719082410" rel="nofollow noopener"&gt;Jonathan Gray&lt;/a&gt; imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125235" rel="nofollow noopener"&gt;Stefan Sperling&lt;/a&gt; fixed a lot of issues with wireless drivers&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125020" rel="nofollow noopener"&gt;Florian Obser&lt;/a&gt; did many things related to IPv6&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721090411" rel="nofollow noopener"&gt;Ingo Schwarze&lt;/a&gt; worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140722071413" rel="nofollow noopener"&gt;Ken Westerback&lt;/a&gt; hacked on dhclient and dhcpd, and also got dump working on 4k sector drives&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140723142224" rel="nofollow noopener"&gt;Matthieu Herrb&lt;/a&gt; worked on updating and modernizing parts of xenocara
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener"&gt;FreeBSD pf discussion takes off&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)&lt;/li&gt;
&lt;li&gt;Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"&lt;/li&gt;
&lt;li&gt;Searching for documentation online for pf is troublesome because there are two incompatible syntaxes&lt;/li&gt;
&lt;li&gt;FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating&lt;/li&gt;
&lt;li&gt;There's also the issue of importing patches from pfSense, but most of those still haven't been done either&lt;/li&gt;
&lt;li&gt;Lots of disagreement among developers vs. users...&lt;/li&gt;
&lt;li&gt;Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested&lt;/li&gt;
&lt;li&gt;Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions&lt;/li&gt;
&lt;li&gt;Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)&lt;/li&gt;
&lt;li&gt;Gleb had to abandon his work on FreeBSD's pf because funding ran out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener"&gt;LibreSSL progress update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140599450206255&amp;amp;w=2" rel="nofollow noopener"&gt;two days ago&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list&lt;/li&gt;
&lt;li&gt;However, there has already been some drama... with Linux users&lt;/li&gt;
&lt;li&gt;There was a problem with Linux's PRNG, and LibreSSL was &lt;a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener"&gt;unforgiving&lt;/a&gt; of it, not making an effort to randomize something that could not provide real entropy&lt;/li&gt;
&lt;li&gt;This "problem" doesn't affect OpenBSD's native implementation, only the portable version&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener"&gt;The developers&lt;/a&gt; decide to &lt;a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener"&gt;weigh in&lt;/a&gt; to calm the misinformation and rage&lt;/li&gt;
&lt;li&gt;A fix was added in 2.0.2, and Linux may even &lt;a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener"&gt;get a new system call&lt;/a&gt; to handle this properly now - remember to say thanks, guys&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has a &lt;a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener"&gt;really good post&lt;/a&gt; about the whole situation, definitely check it out&lt;/li&gt;
&lt;li&gt;As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener"&gt;Preparation for NetBSD 7&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The release process for NetBSD 7.0 is finally underway&lt;/li&gt;
&lt;li&gt;The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September&lt;/li&gt;
&lt;li&gt;If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)&lt;/li&gt;
&lt;li&gt;They're also looking for some help updating documentation and fixing any bugs that get reported&lt;/li&gt;
&lt;li&gt;Another formal announcement will be made when the beta binaries are up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Dag-Erling Smørgrav - &lt;a href="mailto:des@freebsd.org" rel="nofollow noopener"&gt;des@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/RealEvilDES" rel="nofollow noopener"&gt;@RealEvilDES&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The role of the FreeBSD Security Officer, recent ports features, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener"&gt;BSDCan ports and packages WG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages&lt;/li&gt;
&lt;li&gt;Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages&lt;/li&gt;
&lt;li&gt;There's also some detail about the signing infrastructure and different mirrors&lt;/li&gt;
&lt;li&gt;Ports people and source people need to talk more often about ABI breakage&lt;/li&gt;
&lt;li&gt;The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener"&gt;Cross-compiling ports with QEMU and poudriere&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With recent QEMU features, you can basically chroot into a completely different architecture&lt;/li&gt;
&lt;li&gt;This article goes through the process of building ARMv6 packages on a normal X86 box&lt;/li&gt;
&lt;li&gt;Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now&lt;/li&gt;
&lt;li&gt;The poudriere-devel port now has a "qemu user" option that will pull in all the requirements&lt;/li&gt;
&lt;li&gt;Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener"&gt;Cloning FreeBSD with ZFS send&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen&lt;/li&gt;
&lt;li&gt;This post shows his entire process in creating a mirror machine, using ZFS for everything&lt;/li&gt;
&lt;li&gt;The "zfs send" and "zfs snapshot" commands really come in handy for this&lt;/li&gt;
&lt;li&gt;He does the whole thing from a live CD, pretty impressive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener"&gt;FreeBSD Overview series&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog series we stumbled upon about a Linux user switching to BSD&lt;/li&gt;
&lt;li&gt;In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10&lt;/li&gt;
&lt;li&gt;He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels&lt;/li&gt;
&lt;li&gt;Most of what he was used to on Linux was already in the default FreeBSD (except bash...)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener"&gt;Part two&lt;/a&gt; documents his experiences with pkgng and ports 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener"&gt;Rick writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener"&gt;Esteban writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://imgur.com/a/Ah444" rel="nofollow noopener"&gt;Matt sends in pictures of his FreeBSD CD collection&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, prng, linux, des, aes, encryption, cryptography, Dag-Erling Smørgrav, security, hackathon, pf, packet filter, firewall, smp, multithreading, ixsystems, tarsnap, bsdcan, cheri, zfs, qemu</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>44: Base ISO 100</title>
  <link>https://www.bsdnow.tv/44</link>
  <guid isPermaLink="false">cbf5ab1d-2355-4c2c-ade8-0e66250b204e</guid>
  <pubDate>Wed, 02 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/cbf5ab1d-2355-4c2c-ade8-0e66250b204e.mp3" length="75659476" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:45:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1377" rel="nofollow noopener"&gt;pfSense 2.1.4 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;pfSense team&lt;/a&gt; has released 2.1.4, shortly after 2.1.3 - it's mainly a security release&lt;/li&gt;
&lt;li&gt;Included within are eight security fixes, most of which are pfSense-specific&lt;/li&gt;
&lt;li&gt;OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)&lt;/li&gt;
&lt;li&gt;It also includes a large number of various other bug fixes&lt;/li&gt;
&lt;li&gt;Update all your routers!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" rel="nofollow noopener"&gt;DragonflyBSD's pf gets SMP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;While we're on the topic of pf...&lt;/li&gt;
&lt;li&gt;Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas&lt;/li&gt;
&lt;li&gt;Stemming from &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" rel="nofollow noopener"&gt;a user's complaint&lt;/a&gt;, Matthew Dillon did his own work on pf to make it SMP-aware&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" rel="nofollow noopener"&gt;Altering your configuration&lt;/a&gt;'s ruleset can also help speed things up, he found&lt;/li&gt;
&lt;li&gt;When will OpenBSD, the source of pf, finally do the same?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ianix.com/pub/chacha-deployment.html" rel="nofollow noopener"&gt;ChaCha usage and deployment&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A while back, &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;we talked to djm&lt;/a&gt; about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5&lt;/li&gt;
&lt;li&gt;This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20&lt;/li&gt;
&lt;li&gt;OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it&lt;/li&gt;
&lt;li&gt;Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not&lt;/li&gt;
&lt;li&gt;Unfortunately, this article has one mistake: FreeBSD &lt;a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" rel="nofollow noopener"&gt;does not use it&lt;/a&gt; - they &lt;em&gt;still&lt;/em&gt; use the broken RC4 algorithm
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" rel="nofollow noopener"&gt;BSDMag June 2014 issue&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The monthly online BSD magazine releases their newest issue&lt;/li&gt;
&lt;li&gt;This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities&lt;/li&gt;
&lt;li&gt;The free pdf file is available for download as always
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Craig Rodrigues - &lt;a href="mailto:rodrigc@freebsd.org" rel="nofollow noopener"&gt;rodrigc@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD's &lt;a href="https://wiki.freebsd.org/Jenkins" rel="nofollow noopener"&gt;continuous&lt;/a&gt; &lt;a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" rel="nofollow noopener"&gt;testing&lt;/a&gt; &lt;a href="https://jenkins.freebsd.org/jenkins/" rel="nofollow noopener"&gt;infrastructure&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener"&gt;Creating pre-patched OpenBSD ISOs&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" rel="nofollow noopener"&gt;Preauthenticated decryption considered harmful&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Responding to &lt;a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" rel="nofollow noopener"&gt;a post&lt;/a&gt; from Adam Langley, &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; talks a little more about how signify and pkg_add handle signatures&lt;/li&gt;
&lt;li&gt;In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns&lt;/li&gt;
&lt;li&gt;With signify, now everything is fully downloaded and verified before tar is even invoked&lt;/li&gt;
&lt;li&gt;The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post&lt;/li&gt;
&lt;li&gt;Be sure to also read the original post from Adam, lots of good information
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" rel="nofollow noopener"&gt;FreeBSD 9.3-RC2 is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As the -RELEASE inches closer, release candidate 2 is out and ready for testing&lt;/li&gt;
&lt;li&gt;Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things&lt;/li&gt;
&lt;li&gt;The updated bsdconfig will use pkgng style packages now too&lt;/li&gt;
&lt;li&gt;A lesser known fact: there are also premade virtual machine images you can use too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://saveosx.org/pkgsrcCon/" rel="nofollow noopener"&gt;pkgsrcCon 2014 wrap-up&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In what may be the first real pkgsrcCon article we've ever had!&lt;/li&gt;
&lt;li&gt;Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event&lt;/li&gt;
&lt;li&gt;Unfortunately no recordings to be found...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" rel="nofollow noopener"&gt;PostgreSQL FreeBSD performance and scalability&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales&lt;/li&gt;
&lt;li&gt;On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings&lt;/li&gt;
&lt;li&gt;Lots of technical details if you're interested in getting the best performance out of your hardware&lt;/li&gt;
&lt;li&gt;It also includes specific kernel options he used and the rest of the configuration&lt;/li&gt;
&lt;li&gt;If you don't want to open the pdf file, you can &lt;a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" rel="nofollow noopener"&gt;use this link&lt;/a&gt; too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s24pFjUPe4" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21OogIgTu" rel="nofollow noopener"&gt;Klemen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21rLcemNN" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s203Qsx6CZ" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2eBj0FfSL" rel="nofollow noopener"&gt;Adam writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, iso, patch, stable, cd, dvd, cdr, pre-applied, applied, horrible puns, jenkins, testing, kyua, ixsystems, tarsnap, pfsense, freenas, tarsnap, ixsystems, pfsense, freenas, bsdmag, magazine, ssl, tls, hardening, hardened, security, pf, smp, multithreading, firewall, scalability, postgresql, mysql, sql, database, performance, openssl, libressl, boringssl, google, chacha, chacha20, salsa20, encryption, pkgsrc, pkgsrccon, signify, pkg_add, authenticated encryption, decryption, gcm</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://blog.pfsense.org/?p=1377" rel="nofollow noopener">pfSense 2.1.4 released</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense team</a> has released 2.1.4, shortly after 2.1.3 - it's mainly a security release</li>
<li>Included within are eight security fixes, most of which are pfSense-specific</li>
<li>OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)</li>
<li>It also includes a large number of various other bug fixes</li>
<li>Update all your routers!
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" rel="nofollow noopener">DragonflyBSD's pf gets SMP</a></h3>

<ul>
<li>While we're on the topic of pf...</li>
<li>Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas</li>
<li>Stemming from <a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" rel="nofollow noopener">a user's complaint</a>, Matthew Dillon did his own work on pf to make it SMP-aware</li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" rel="nofollow noopener">Altering your configuration</a>'s ruleset can also help speed things up, he found</li>
<li>When will OpenBSD, the source of pf, finally do the same?
***</li>
</ul>

<h3><a href="http://ianix.com/pub/chacha-deployment.html" rel="nofollow noopener">ChaCha usage and deployment</a></h3>

<ul>
<li>A while back, <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">we talked to djm</a> about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5</li>
<li>This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20</li>
<li>OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it</li>
<li>Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not</li>
<li>Unfortunately, this article has one mistake: FreeBSD <a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" rel="nofollow noopener">does not use it</a> - they <em>still</em> use the broken RC4 algorithm
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" rel="nofollow noopener">BSDMag June 2014 issue</a></h3>

<ul>
<li>The monthly online BSD magazine releases their newest issue</li>
<li>This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities</li>
<li>The free pdf file is available for download as always
***</li>
</ul>

<h2>Interview - Craig Rodrigues - <a href="mailto:rodrigc@freebsd.org" rel="nofollow noopener">rodrigc@freebsd.org</a></h2>

<p>FreeBSD's <a href="https://wiki.freebsd.org/Jenkins" rel="nofollow noopener">continuous</a> <a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" rel="nofollow noopener">testing</a> <a href="https://jenkins.freebsd.org/jenkins/" rel="nofollow noopener">infrastructure</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener">Creating pre-patched OpenBSD ISOs</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" rel="nofollow noopener">Preauthenticated decryption considered harmful</a></h3>

<ul>
<li>Responding to <a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" rel="nofollow noopener">a post</a> from Adam Langley, <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> talks a little more about how signify and pkg_add handle signatures</li>
<li>In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns</li>
<li>With signify, now everything is fully downloaded and verified before tar is even invoked</li>
<li>The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post</li>
<li>Be sure to also read the original post from Adam, lots of good information
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" rel="nofollow noopener">FreeBSD 9.3-RC2 is out</a></h3>

<ul>
<li>As the -RELEASE inches closer, release candidate 2 is out and ready for testing</li>
<li>Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things</li>
<li>The updated bsdconfig will use pkgng style packages now too</li>
<li>A lesser known fact: there are also premade virtual machine images you can use too
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrcCon/" rel="nofollow noopener">pkgsrcCon 2014 wrap-up</a></h3>

<ul>
<li>In what may be the first real pkgsrcCon article we've ever had!</li>
<li>Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event</li>
<li>Unfortunately no recordings to be found...
***</li>
</ul>

<h3><a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" rel="nofollow noopener">PostgreSQL FreeBSD performance and scalability</a></h3>

<ul>
<li>FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales</li>
<li>On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings</li>
<li>Lots of technical details if you're interested in getting the best performance out of your hardware</li>
<li>It also includes specific kernel options he used and the rest of the configuration</li>
<li>If you don't want to open the pdf file, you can <a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" rel="nofollow noopener">use this link</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s24pFjUPe4" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21OogIgTu" rel="nofollow noopener">Klemen writes in</a></li>
<li><a href="http://slexy.org/view/s21rLcemNN" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s203Qsx6CZ" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2eBj0FfSL" rel="nofollow noopener">Adam writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://blog.pfsense.org/?p=1377" rel="nofollow noopener">pfSense 2.1.4 released</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense team</a> has released 2.1.4, shortly after 2.1.3 - it's mainly a security release</li>
<li>Included within are eight security fixes, most of which are pfSense-specific</li>
<li>OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)</li>
<li>It also includes a large number of various other bug fixes</li>
<li>Update all your routers!
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" rel="nofollow noopener">DragonflyBSD's pf gets SMP</a></h3>

<ul>
<li>While we're on the topic of pf...</li>
<li>Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas</li>
<li>Stemming from <a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" rel="nofollow noopener">a user's complaint</a>, Matthew Dillon did his own work on pf to make it SMP-aware</li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" rel="nofollow noopener">Altering your configuration</a>'s ruleset can also help speed things up, he found</li>
<li>When will OpenBSD, the source of pf, finally do the same?
***</li>
</ul>

<h3><a href="http://ianix.com/pub/chacha-deployment.html" rel="nofollow noopener">ChaCha usage and deployment</a></h3>

<ul>
<li>A while back, <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">we talked to djm</a> about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5</li>
<li>This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20</li>
<li>OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it</li>
<li>Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not</li>
<li>Unfortunately, this article has one mistake: FreeBSD <a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" rel="nofollow noopener">does not use it</a> - they <em>still</em> use the broken RC4 algorithm
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" rel="nofollow noopener">BSDMag June 2014 issue</a></h3>

<ul>
<li>The monthly online BSD magazine releases their newest issue</li>
<li>This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities</li>
<li>The free pdf file is available for download as always
***</li>
</ul>

<h2>Interview - Craig Rodrigues - <a href="mailto:rodrigc@freebsd.org" rel="nofollow noopener">rodrigc@freebsd.org</a></h2>

<p>FreeBSD's <a href="https://wiki.freebsd.org/Jenkins" rel="nofollow noopener">continuous</a> <a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" rel="nofollow noopener">testing</a> <a href="https://jenkins.freebsd.org/jenkins/" rel="nofollow noopener">infrastructure</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener">Creating pre-patched OpenBSD ISOs</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" rel="nofollow noopener">Preauthenticated decryption considered harmful</a></h3>

<ul>
<li>Responding to <a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" rel="nofollow noopener">a post</a> from Adam Langley, <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> talks a little more about how signify and pkg_add handle signatures</li>
<li>In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns</li>
<li>With signify, now everything is fully downloaded and verified before tar is even invoked</li>
<li>The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post</li>
<li>Be sure to also read the original post from Adam, lots of good information
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" rel="nofollow noopener">FreeBSD 9.3-RC2 is out</a></h3>

<ul>
<li>As the -RELEASE inches closer, release candidate 2 is out and ready for testing</li>
<li>Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things</li>
<li>The updated bsdconfig will use pkgng style packages now too</li>
<li>A lesser known fact: there are also premade virtual machine images you can use too
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrcCon/" rel="nofollow noopener">pkgsrcCon 2014 wrap-up</a></h3>

<ul>
<li>In what may be the first real pkgsrcCon article we've ever had!</li>
<li>Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event</li>
<li>Unfortunately no recordings to be found...
***</li>
</ul>

<h3><a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" rel="nofollow noopener">PostgreSQL FreeBSD performance and scalability</a></h3>

<ul>
<li>FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales</li>
<li>On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings</li>
<li>Lots of technical details if you're interested in getting the best performance out of your hardware</li>
<li>It also includes specific kernel options he used and the rest of the configuration</li>
<li>If you don't want to open the pdf file, you can <a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" rel="nofollow noopener">use this link</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s24pFjUPe4" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21OogIgTu" rel="nofollow noopener">Klemen writes in</a></li>
<li><a href="http://slexy.org/view/s21rLcemNN" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s203Qsx6CZ" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2eBj0FfSL" rel="nofollow noopener">Adam writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>43: Package Design</title>
  <link>https://www.bsdnow.tv/43</link>
  <guid isPermaLink="false">d4b10034-d20a-44a6-a918-a57335debcae</guid>
  <pubDate>Wed, 25 Jun 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d4b10034-d20a-44a6-a918-a57335debcae.mp3" length="62389876" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:26:39</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener"&gt;EuroBSDCon 2014 talks and schedule&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The talks and schedules for EuroBSDCon 2014 are finally revealed&lt;/li&gt;
&lt;li&gt;The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh&lt;/li&gt;
&lt;li&gt;Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great&lt;/li&gt;
&lt;li&gt;It looks like Theo even has a talk, but the title isn't on the page... how mysterious&lt;/li&gt;
&lt;li&gt;There are also days dedicated to some really interesting tutorials&lt;/li&gt;
&lt;li&gt;Register now, the conference is on September 25-28th in Bulgaria&lt;/li&gt;
&lt;li&gt;If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen&lt;/li&gt;
&lt;li&gt;Why aren't the videos up from last year yet? Will this year also not have any?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener"&gt;FreeNAS vs NAS4Free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;More mainstream news covering BSD, this time with an article about different NAS solutions&lt;/li&gt;
&lt;li&gt;In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free&lt;/li&gt;
&lt;li&gt;Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect&lt;/li&gt;
&lt;li&gt;Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project&lt;/li&gt;
&lt;li&gt;"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener"&gt;Quality software costs money, heartbleed was free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener"&gt;PHK&lt;/a&gt; writes an article for ACM Queue about open source software projects' funding efforts&lt;/li&gt;
&lt;li&gt;A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc&lt;/li&gt;
&lt;li&gt;The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding&lt;/li&gt;
&lt;li&gt;The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them&lt;/li&gt;
&lt;li&gt;On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"&lt;/li&gt;
&lt;li&gt;Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener"&gt;Geoblock evasion with pf and OpenBSD rdomains&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Geoblocking is a way for websites to block visitors based on the location of their IP&lt;/li&gt;
&lt;li&gt;This is a blog post about how to get around it, using pf and rdomains&lt;/li&gt;
&lt;li&gt;It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;a tutorial about that&lt;/a&gt;...)&lt;/li&gt;
&lt;li&gt;In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia&lt;/li&gt;
&lt;li&gt;It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Marc Espie - &lt;a href="mailto:espie@openbsd.org" rel="nofollow noopener"&gt;espie@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/espie_openbsd" rel="nofollow noopener"&gt;@espie_openbsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's package system, building cluster, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener"&gt;Keeping your BSD up to date&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener"&gt;BoringSSL and LibReSSL&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another OpenSSL fork pops up, this time from Google, called BoringSSL&lt;/li&gt;
&lt;li&gt;Adam Langley has a blog post about it, why they did it and how they're going to maintain it&lt;/li&gt;
&lt;li&gt;You can easily browse &lt;a href="https://boringssl.googlesource.com/" rel="nofollow noopener"&gt;the source code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Theo de Raadt also &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140332790726752&amp;amp;w=2" rel="nofollow noopener"&gt;weighs in&lt;/a&gt; with how this effort relates to LibReSSL&lt;/li&gt;
&lt;li&gt;More eyes on the code is good, and patches will be shared between the two projects
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener"&gt;More BSD Tor nodes wanted&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener"&gt;Originally discussed&lt;/a&gt; on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network&lt;/li&gt;
&lt;li&gt;If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.&lt;/li&gt;
&lt;li&gt;The EFF is also holding a &lt;a href="https://www.eff.org/torchallenge/" rel="nofollow noopener"&gt;Tor challenge&lt;/a&gt; for people to start up new relays and keep them online for over a year&lt;/li&gt;
&lt;li&gt;Check out our &lt;a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener"&gt;Tor tutorial&lt;/a&gt; and help out the network, and promote BSD at the same time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener"&gt;FreeBSD 10 OpenStack images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."&lt;/li&gt;
&lt;li&gt;The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"&lt;/li&gt;
&lt;li&gt;The author of the article is a regular listener and emailer of the show, hey!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener"&gt;BSDday 2014 call for papers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSD Day, a conference not so well-known, is going to be held August 9th in Argentina&lt;/li&gt;
&lt;li&gt;It was created in 2008 and is the only BSD conference around that area&lt;/li&gt;
&lt;li&gt;The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk&lt;/li&gt;
&lt;li&gt;Sysadmins, developers and regular users are, of course, all welcome to come to the event
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener"&gt;Maruf writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener"&gt;Solomon writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener"&gt;Silas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener"&gt;Bert writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ports, packages, cluster, building, pkg_add, freenas, ixsystems, tarsnap, eurobsdcon, bulgaria, 2014, talks, presentation, slides, Poul-Henning Kamp, phk, schedule, freenas, nas4free, nas, geoblock, evasion, bypassing, ip ban, pf, firewall, rdomains, glusterfs, marc espie, boringssl, openssl, libressl, upgrades, how to upgrade, update, rebuild, tor, tor nodes, relays, exit node, eff, tor challenge, aslr, pie, security, bsdday, openstack, bsd-cloudinit, cloud computing</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>41: Commit This Bit</title>
  <link>https://www.bsdnow.tv/41</link>
  <guid isPermaLink="false">0017fbdd-17f8-464f-8bd5-94c6070bbd9a</guid>
  <pubDate>Wed, 11 Jun 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0017fbdd-17f8-464f-8bd5-94c6070bbd9a.mp3" length="48292564" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week in the big show, we'll be interviewing Benedict Reuschling of the FreeBSD documentation team, and he has a special surprise in store for Allan. As always, answers to your questions and all the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:07:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week in the big show, we'll be interviewing Benedict Reuschling of the FreeBSD documentation team, and he has a special surprise in store for Allan. As always, answers to your questions and all the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-June/001559.html" rel="nofollow noopener"&gt;FreeBSD moves to Bugzilla&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Historically, FreeBSD has used the old GNATS system for keeping track of bug reports&lt;/li&gt;
&lt;li&gt;After years and years of wanting to switch, they've finally moved away from GNATS to Bugzilla&lt;/li&gt;
&lt;li&gt;It offers a lot of advantages, is much more modern and actively maintained and &lt;/li&gt;
&lt;li&gt;There's a new &lt;a href="http://people.freebsd.org/%7Eeadler/bugrelocation/workflow.html" rel="nofollow noopener"&gt;workflow chart&lt;/a&gt; for developers to illustrate the new way of doing things&lt;/li&gt;
&lt;li&gt;The old "send-pr" command will still work for the time being, but will eventually be phased out in favor of native Bugzilla reporting tools (of which there are multiple in ports)&lt;/li&gt;
&lt;li&gt;This will hopefully make reporting bugs a lot less painful
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.brianmoses.net/2014/06/diy-nas-econonas-2014.html" rel="nofollow noopener"&gt;DIY NAS: EconoNAS 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We previously covered this blog last year, but the 2014 edition is up&lt;/li&gt;
&lt;li&gt;More of a hardware-focused article, the author details the parts he's using for a &lt;strong&gt;budget&lt;/strong&gt; NAS&lt;/li&gt;
&lt;li&gt;Details the motherboard, RAM, CPU, hard drives, case, etc&lt;/li&gt;
&lt;li&gt;With a set goal of $500 max, he goes just over it - $550 for all the parts&lt;/li&gt;
&lt;li&gt;Lots of nice pictures of the hardware and step by step instructions for assembly, as well as software configuration instructions
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.shiningsilence.com/dbsdlog/2014/06/04/14122.html" rel="nofollow noopener"&gt;DragonflyBSD 3.8 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener"&gt;Justin&lt;/a&gt; announced the availability of DragonflyBSD 3.8.0&lt;/li&gt;
&lt;li&gt;Binaries in /bin and /sbin are dynamic now, enabling the use of PAM and NSS to manage user accounts&lt;/li&gt;
&lt;li&gt;It includes a new HAMMER FS backup script and lots of FreeBSD tools have been synced with their latest versions&lt;/li&gt;
&lt;li&gt;Work continues on for the Intel graphics drivers, but it's currently limited to the HD4000 and Ivy Bridge series&lt;/li&gt;
&lt;li&gt;See &lt;a href="http://www.dragonflybsd.org/release38/" rel="nofollow noopener"&gt;the release page&lt;/a&gt; for more info and check the link for source-based upgrade instructions
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.open-zfs.org/wiki/Publications#2014_OpenZFS_European_Conference" rel="nofollow noopener"&gt;OpenZFS European conference 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was an OpenZFS conference held in Europe recently, and now the videos are online for your viewing pleasure&lt;/li&gt;
&lt;li&gt;Matt Ahrens, &lt;a href="http://www.youtube.com/watch?v=Mk1czZs6vkQ" rel="nofollow noopener"&gt;Introduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Michael Alexander, &lt;a href="http://www.youtube.com/watch?v=Ak1HB507-xY" rel="nofollow noopener"&gt;FhGFS performance on ZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andriy Gapon, &lt;a href="http://www.youtube.com/watch?v=oB-QDwVuBH4" rel="nofollow noopener"&gt;Testing ZFS on FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Luke Marsden, &lt;a href="http://www.youtube.com/watch?v=ISI9Ppj3kTo" rel="nofollow noopener"&gt;HybridCluster: ZFS in the cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vadim Comănescu, &lt;a href="http://www.youtube.com/watch?v=1xK94v0BedE" rel="nofollow noopener"&gt;Syneto: continuously delivering a ZFS-based OS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Chris George, &lt;a href="http://www.youtube.com/watch?v=ScNHjWBQYQ8" rel="nofollow noopener"&gt;DDRdrive ZIL accelerator: random write revelation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Grenville Whelan, &lt;a href="http://www.youtube.com/watch?v=tiTYZykCeDo" rel="nofollow noopener"&gt;High-Availability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Phil Harman, &lt;a href="https://www.youtube.com/watch?v=ApjkrBVlPXk" rel="nofollow noopener"&gt;Harman Holistic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Mark Rees, &lt;a href="http://www.youtube.com/watch?v=41yl23EACns" rel="nofollow noopener"&gt;Storiant and OpenZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andrew Holway, &lt;a href="http://www.youtube.com/watch?v=b4L0DRvKJxo" rel="nofollow noopener"&gt;EraStor ZFS appliances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Dan Vâtca, &lt;a href="http://www.youtube.com/watch?v=pPOW8bwUXxo" rel="nofollow noopener"&gt;Syneto and OpenZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Luke Marsden, &lt;a href="http://www.youtube.com/watch?v=uSM1s1aWlZE" rel="nofollow noopener"&gt;HybridCluster and OpenZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Matt Ahrens, &lt;a href="http://www.youtube.com/watch?v=UaRdzUOsieA" rel="nofollow noopener"&gt;Delphix and OpenZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Check the link for slides and other goodies
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Benedict Reuschling - &lt;a href="mailto:bcr@freebsd.org" rel="nofollow noopener"&gt;bcr@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;BSD documentation, getting commit access, unix education, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/06/04/getting-to-know-your-portmgr-steve-wills/" rel="nofollow noopener"&gt;Getting to know your portmgr, Steve Wills&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"It is my pleasure to introduce Steve Wills, the newest member of the portmgr team"&lt;/li&gt;
&lt;li&gt;swills is an all-round good guy, does a lot for ports (especially the ruby ports)&lt;/li&gt;
&lt;li&gt;In this interview, we learn why he uses FreeBSD, the most embarrassing moment in his FreeBSD career and much more&lt;/li&gt;
&lt;li&gt;He used to work for Red Hat, woah
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/06/bsdtalk242-pfsense-with-chris-buechler.html" rel="nofollow noopener"&gt;BSDTalk episode 242&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This time on BSDTalk, Will interviews &lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;Chris Buechler&lt;/a&gt; from pfSense&lt;/li&gt;
&lt;li&gt;Topics include: the heartbleed vulnerability and how it affected pfSense, how people usually leave their firewalls unpatched for a long time (or even forget about them!), changes between major versions, the upgrade process, upcoming features in their 10-based version, backporting drivers and security fixes&lt;/li&gt;
&lt;li&gt;They also touch on recent concerns in the pfSense community about their license change, that they may be "going commercial" and closing the source - so tune in to find out what their future plans are for all of that
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.pcworld.com/article/2243748/turn-old-pc-hardware-into-a-killer-home-server-with-freenas.html" rel="nofollow noopener"&gt;Turn old PC hardware into a killer home server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Lots of us have old hardware lying around doing nothing but collecting dust&lt;/li&gt;
&lt;li&gt;Why not turn that old box into a modern file server with FreeNAS and ZFS?&lt;/li&gt;
&lt;li&gt;This article goes through the process of setting up a NAS, gives a little history behind the project and highlights some of the different protocols FreeNAS can use (NFS, SMB, AFS, etc)&lt;/li&gt;
&lt;li&gt;Most of our users are already familiar with all of this stuff, nothing too advanced&lt;/li&gt;
&lt;li&gt;Good to see BSD getting some well-deserved attention on a big mainstream site
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/unbloating_the_vax_install_cd" rel="nofollow noopener"&gt;Unbloating the VAX install CD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;After a discussion on the VAX mailing list, something very important came to the attention of the developers...&lt;/li&gt;
&lt;li&gt;You can't boot NetBSD on a VAX box with 16MB of RAM from the CD image&lt;/li&gt;
&lt;li&gt;This blog post goes through the developer's adventure in trying to fix that through emulation and stripping various things out of the kernel to make it smaller&lt;/li&gt;
&lt;li&gt;In the end, he got it booting - and now all three VAX users who want to run NetBSD can do so on their systems with 16MB of RAM...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s211mNScBr" rel="nofollow noopener"&gt;Thomas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21JA8BVmZ" rel="nofollow noopener"&gt;Reynold writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2kwS3ncTY" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2VgjXUfW9" rel="nofollow noopener"&gt;Paul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s202AAQUXt" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, gnats, send-pr, sendbug, bugzilla, bug tracker, iso, cdr, dvd, patches, applied, commit bit, documentation, bsdcan, 2014, 9.3-RELEASE, 9.3, release, stable, advocacy, openssl, libressl, security, vulnerability, bsdtalk, pfsense, license, openzfs, zfs, presentation, talk, matthew ahrens, delphix, hybridcluster, freenas</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week in the big show, we'll be interviewing Benedict Reuschling of the FreeBSD documentation team, and he has a special surprise in store for Allan. As always, answers to your questions and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-June/001559.html" rel="nofollow noopener">FreeBSD moves to Bugzilla</a></h3>

<ul>
<li>Historically, FreeBSD has used the old GNATS system for keeping track of bug reports</li>
<li>After years and years of wanting to switch, they've finally moved away from GNATS to Bugzilla</li>
<li>It offers a lot of advantages, is much more modern and actively maintained and </li>
<li>There's a new <a href="http://people.freebsd.org/%7Eeadler/bugrelocation/workflow.html" rel="nofollow noopener">workflow chart</a> for developers to illustrate the new way of doing things</li>
<li>The old "send-pr" command will still work for the time being, but will eventually be phased out in favor of native Bugzilla reporting tools (of which there are multiple in ports)</li>
<li>This will hopefully make reporting bugs a lot less painful
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/06/diy-nas-econonas-2014.html" rel="nofollow noopener">DIY NAS: EconoNAS 2014</a></h3>

<ul>
<li>We previously covered this blog last year, but the 2014 edition is up</li>
<li>More of a hardware-focused article, the author details the parts he's using for a <strong>budget</strong> NAS</li>
<li>Details the motherboard, RAM, CPU, hard drives, case, etc</li>
<li>With a set goal of $500 max, he goes just over it - $550 for all the parts</li>
<li>Lots of nice pictures of the hardware and step by step instructions for assembly, as well as software configuration instructions
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2014/06/04/14122.html" rel="nofollow noopener">DragonflyBSD 3.8 released</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener">Justin</a> announced the availability of DragonflyBSD 3.8.0</li>
<li>Binaries in /bin and /sbin are dynamic now, enabling the use of PAM and NSS to manage user accounts</li>
<li>It includes a new HAMMER FS backup script and lots of FreeBSD tools have been synced with their latest versions</li>
<li>Work continues on for the Intel graphics drivers, but it's currently limited to the HD4000 and Ivy Bridge series</li>
<li>See <a href="http://www.dragonflybsd.org/release38/" rel="nofollow noopener">the release page</a> for more info and check the link for source-based upgrade instructions
***</li>
</ul>

<h3><a href="http://www.open-zfs.org/wiki/Publications#2014_OpenZFS_European_Conference" rel="nofollow noopener">OpenZFS European conference 2014</a></h3>

<ul>
<li>There was an OpenZFS conference held in Europe recently, and now the videos are online for your viewing pleasure</li>
<li>Matt Ahrens, <a href="http://www.youtube.com/watch?v=Mk1czZs6vkQ" rel="nofollow noopener">Introduction</a></li>
<li>Michael Alexander, <a href="http://www.youtube.com/watch?v=Ak1HB507-xY" rel="nofollow noopener">FhGFS performance on ZFS</a></li>
<li>Andriy Gapon, <a href="http://www.youtube.com/watch?v=oB-QDwVuBH4" rel="nofollow noopener">Testing ZFS on FreeBSD</a></li>
<li>Luke Marsden, <a href="http://www.youtube.com/watch?v=ISI9Ppj3kTo" rel="nofollow noopener">HybridCluster: ZFS in the cloud</a></li>
<li>Vadim Comănescu, <a href="http://www.youtube.com/watch?v=1xK94v0BedE" rel="nofollow noopener">Syneto: continuously delivering a ZFS-based OS</a></li>
<li>Chris George, <a href="http://www.youtube.com/watch?v=ScNHjWBQYQ8" rel="nofollow noopener">DDRdrive ZIL accelerator: random write revelation</a></li>
<li>Grenville Whelan, <a href="http://www.youtube.com/watch?v=tiTYZykCeDo" rel="nofollow noopener">High-Availability</a></li>
<li>Phil Harman, <a href="https://www.youtube.com/watch?v=ApjkrBVlPXk" rel="nofollow noopener">Harman Holistic</a></li>
<li>Mark Rees, <a href="http://www.youtube.com/watch?v=41yl23EACns" rel="nofollow noopener">Storiant and OpenZFS</a></li>
<li>Andrew Holway, <a href="http://www.youtube.com/watch?v=b4L0DRvKJxo" rel="nofollow noopener">EraStor ZFS appliances</a></li>
<li>Dan Vâtca, <a href="http://www.youtube.com/watch?v=pPOW8bwUXxo" rel="nofollow noopener">Syneto and OpenZFS</a></li>
<li>Luke Marsden, <a href="http://www.youtube.com/watch?v=uSM1s1aWlZE" rel="nofollow noopener">HybridCluster and OpenZFS</a></li>
<li>Matt Ahrens, <a href="http://www.youtube.com/watch?v=UaRdzUOsieA" rel="nofollow noopener">Delphix and OpenZFS</a></li>
<li>Check the link for slides and other goodies
***</li>
</ul>

<h2>Interview - Benedict Reuschling - <a href="mailto:bcr@freebsd.org" rel="nofollow noopener">bcr@freebsd.org</a></h2>

<p>BSD documentation, getting commit access, unix education, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/06/04/getting-to-know-your-portmgr-steve-wills/" rel="nofollow noopener">Getting to know your portmgr, Steve Wills</a></h3>

<ul>
<li>"It is my pleasure to introduce Steve Wills, the newest member of the portmgr team"</li>
<li>swills is an all-round good guy, does a lot for ports (especially the ruby ports)</li>
<li>In this interview, we learn why he uses FreeBSD, the most embarrassing moment in his FreeBSD career and much more</li>
<li>He used to work for Red Hat, woah
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/06/bsdtalk242-pfsense-with-chris-buechler.html" rel="nofollow noopener">BSDTalk episode 242</a></h3>

<ul>
<li>This time on BSDTalk, Will interviews <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">Chris Buechler</a> from pfSense</li>
<li>Topics include: the heartbleed vulnerability and how it affected pfSense, how people usually leave their firewalls unpatched for a long time (or even forget about them!), changes between major versions, the upgrade process, upcoming features in their 10-based version, backporting drivers and security fixes</li>
<li>They also touch on recent concerns in the pfSense community about their license change, that they may be "going commercial" and closing the source - so tune in to find out what their future plans are for all of that
***</li>
</ul>

<h3><a href="http://www.pcworld.com/article/2243748/turn-old-pc-hardware-into-a-killer-home-server-with-freenas.html" rel="nofollow noopener">Turn old PC hardware into a killer home server</a></h3>

<ul>
<li>Lots of us have old hardware lying around doing nothing but collecting dust</li>
<li>Why not turn that old box into a modern file server with FreeNAS and ZFS?</li>
<li>This article goes through the process of setting up a NAS, gives a little history behind the project and highlights some of the different protocols FreeNAS can use (NFS, SMB, AFS, etc)</li>
<li>Most of our users are already familiar with all of this stuff, nothing too advanced</li>
<li>Good to see BSD getting some well-deserved attention on a big mainstream site
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/unbloating_the_vax_install_cd" rel="nofollow noopener">Unbloating the VAX install CD</a></h3>

<ul>
<li>After a discussion on the VAX mailing list, something very important came to the attention of the developers...</li>
<li>You can't boot NetBSD on a VAX box with 16MB of RAM from the CD image</li>
<li>This blog post goes through the developer's adventure in trying to fix that through emulation and stripping various things out of the kernel to make it smaller</li>
<li>In the end, he got it booting - and now all three VAX users who want to run NetBSD can do so on their systems with 16MB of RAM...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s211mNScBr" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21JA8BVmZ" rel="nofollow noopener">Reynold writes in</a></li>
<li><a href="http://slexy.org/view/s2kwS3ncTY" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s2VgjXUfW9" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s202AAQUXt" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week in the big show, we'll be interviewing Benedict Reuschling of the FreeBSD documentation team, and he has a special surprise in store for Allan. As always, answers to your questions and all the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-June/001559.html" rel="nofollow noopener">FreeBSD moves to Bugzilla</a></h3>

<ul>
<li>Historically, FreeBSD has used the old GNATS system for keeping track of bug reports</li>
<li>After years and years of wanting to switch, they've finally moved away from GNATS to Bugzilla</li>
<li>It offers a lot of advantages, is much more modern and actively maintained and </li>
<li>There's a new <a href="http://people.freebsd.org/%7Eeadler/bugrelocation/workflow.html" rel="nofollow noopener">workflow chart</a> for developers to illustrate the new way of doing things</li>
<li>The old "send-pr" command will still work for the time being, but will eventually be phased out in favor of native Bugzilla reporting tools (of which there are multiple in ports)</li>
<li>This will hopefully make reporting bugs a lot less painful
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/06/diy-nas-econonas-2014.html" rel="nofollow noopener">DIY NAS: EconoNAS 2014</a></h3>

<ul>
<li>We previously covered this blog last year, but the 2014 edition is up</li>
<li>More of a hardware-focused article, the author details the parts he's using for a <strong>budget</strong> NAS</li>
<li>Details the motherboard, RAM, CPU, hard drives, case, etc</li>
<li>With a set goal of $500 max, he goes just over it - $550 for all the parts</li>
<li>Lots of nice pictures of the hardware and step by step instructions for assembly, as well as software configuration instructions
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2014/06/04/14122.html" rel="nofollow noopener">DragonflyBSD 3.8 released</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" rel="nofollow noopener">Justin</a> announced the availability of DragonflyBSD 3.8.0</li>
<li>Binaries in /bin and /sbin are dynamic now, enabling the use of PAM and NSS to manage user accounts</li>
<li>It includes a new HAMMER FS backup script and lots of FreeBSD tools have been synced with their latest versions</li>
<li>Work continues on for the Intel graphics drivers, but it's currently limited to the HD4000 and Ivy Bridge series</li>
<li>See <a href="http://www.dragonflybsd.org/release38/" rel="nofollow noopener">the release page</a> for more info and check the link for source-based upgrade instructions
***</li>
</ul>

<h3><a href="http://www.open-zfs.org/wiki/Publications#2014_OpenZFS_European_Conference" rel="nofollow noopener">OpenZFS European conference 2014</a></h3>

<ul>
<li>There was an OpenZFS conference held in Europe recently, and now the videos are online for your viewing pleasure</li>
<li>Matt Ahrens, <a href="http://www.youtube.com/watch?v=Mk1czZs6vkQ" rel="nofollow noopener">Introduction</a></li>
<li>Michael Alexander, <a href="http://www.youtube.com/watch?v=Ak1HB507-xY" rel="nofollow noopener">FhGFS performance on ZFS</a></li>
<li>Andriy Gapon, <a href="http://www.youtube.com/watch?v=oB-QDwVuBH4" rel="nofollow noopener">Testing ZFS on FreeBSD</a></li>
<li>Luke Marsden, <a href="http://www.youtube.com/watch?v=ISI9Ppj3kTo" rel="nofollow noopener">HybridCluster: ZFS in the cloud</a></li>
<li>Vadim Comănescu, <a href="http://www.youtube.com/watch?v=1xK94v0BedE" rel="nofollow noopener">Syneto: continuously delivering a ZFS-based OS</a></li>
<li>Chris George, <a href="http://www.youtube.com/watch?v=ScNHjWBQYQ8" rel="nofollow noopener">DDRdrive ZIL accelerator: random write revelation</a></li>
<li>Grenville Whelan, <a href="http://www.youtube.com/watch?v=tiTYZykCeDo" rel="nofollow noopener">High-Availability</a></li>
<li>Phil Harman, <a href="https://www.youtube.com/watch?v=ApjkrBVlPXk" rel="nofollow noopener">Harman Holistic</a></li>
<li>Mark Rees, <a href="http://www.youtube.com/watch?v=41yl23EACns" rel="nofollow noopener">Storiant and OpenZFS</a></li>
<li>Andrew Holway, <a href="http://www.youtube.com/watch?v=b4L0DRvKJxo" rel="nofollow noopener">EraStor ZFS appliances</a></li>
<li>Dan Vâtca, <a href="http://www.youtube.com/watch?v=pPOW8bwUXxo" rel="nofollow noopener">Syneto and OpenZFS</a></li>
<li>Luke Marsden, <a href="http://www.youtube.com/watch?v=uSM1s1aWlZE" rel="nofollow noopener">HybridCluster and OpenZFS</a></li>
<li>Matt Ahrens, <a href="http://www.youtube.com/watch?v=UaRdzUOsieA" rel="nofollow noopener">Delphix and OpenZFS</a></li>
<li>Check the link for slides and other goodies
***</li>
</ul>

<h2>Interview - Benedict Reuschling - <a href="mailto:bcr@freebsd.org" rel="nofollow noopener">bcr@freebsd.org</a></h2>

<p>BSD documentation, getting commit access, unix education, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/06/04/getting-to-know-your-portmgr-steve-wills/" rel="nofollow noopener">Getting to know your portmgr, Steve Wills</a></h3>

<ul>
<li>"It is my pleasure to introduce Steve Wills, the newest member of the portmgr team"</li>
<li>swills is an all-round good guy, does a lot for ports (especially the ruby ports)</li>
<li>In this interview, we learn why he uses FreeBSD, the most embarrassing moment in his FreeBSD career and much more</li>
<li>He used to work for Red Hat, woah
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/06/bsdtalk242-pfsense-with-chris-buechler.html" rel="nofollow noopener">BSDTalk episode 242</a></h3>

<ul>
<li>This time on BSDTalk, Will interviews <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">Chris Buechler</a> from pfSense</li>
<li>Topics include: the heartbleed vulnerability and how it affected pfSense, how people usually leave their firewalls unpatched for a long time (or even forget about them!), changes between major versions, the upgrade process, upcoming features in their 10-based version, backporting drivers and security fixes</li>
<li>They also touch on recent concerns in the pfSense community about their license change, that they may be "going commercial" and closing the source - so tune in to find out what their future plans are for all of that
***</li>
</ul>

<h3><a href="http://www.pcworld.com/article/2243748/turn-old-pc-hardware-into-a-killer-home-server-with-freenas.html" rel="nofollow noopener">Turn old PC hardware into a killer home server</a></h3>

<ul>
<li>Lots of us have old hardware lying around doing nothing but collecting dust</li>
<li>Why not turn that old box into a modern file server with FreeNAS and ZFS?</li>
<li>This article goes through the process of setting up a NAS, gives a little history behind the project and highlights some of the different protocols FreeNAS can use (NFS, SMB, AFS, etc)</li>
<li>Most of our users are already familiar with all of this stuff, nothing too advanced</li>
<li>Good to see BSD getting some well-deserved attention on a big mainstream site
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/unbloating_the_vax_install_cd" rel="nofollow noopener">Unbloating the VAX install CD</a></h3>

<ul>
<li>After a discussion on the VAX mailing list, something very important came to the attention of the developers...</li>
<li>You can't boot NetBSD on a VAX box with 16MB of RAM from the CD image</li>
<li>This blog post goes through the developer's adventure in trying to fix that through emulation and stripping various things out of the kernel to make it smaller</li>
<li>In the end, he got it booting - and now all three VAX users who want to run NetBSD can do so on their systems with 16MB of RAM...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s211mNScBr" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21JA8BVmZ" rel="nofollow noopener">Reynold writes in</a></li>
<li><a href="http://slexy.org/view/s2kwS3ncTY" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s2VgjXUfW9" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s202AAQUXt" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>38: A BUG's Life</title>
  <link>https://www.bsdnow.tv/38</link>
  <guid isPermaLink="false">01510b66-38e5-40ac-a282-9bff71cb55d9</guid>
  <pubDate>Wed, 21 May 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/01510b66-38e5-40ac-a282-9bff71cb55d9.mp3" length="63768244" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:28:34</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2053" rel="nofollow noopener"&gt;FreeBSD 11 goals and discussion&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Something that actually happened at BSDCan this year...&lt;/li&gt;
&lt;li&gt;During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE&lt;/li&gt;
&lt;li&gt;Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support&lt;/li&gt;
&lt;li&gt;A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more&lt;/li&gt;
&lt;li&gt;There's also some notes from the &lt;a href="http://blather.michaelwlucas.com/archives/2060" rel="nofollow noopener"&gt;devsummit virtualization session&lt;/a&gt;, mostly talking about bhyve&lt;/li&gt;
&lt;li&gt;Lastly, he also provides some notes about &lt;a href="http://blather.michaelwlucas.com/archives/2065" rel="nofollow noopener"&gt;ports and packages&lt;/a&gt; and where they're going
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" rel="nofollow noopener"&gt;An SSH honeypot with OpenBSD and Kippo&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Everyone loves messing with script kiddies, right?&lt;/li&gt;
&lt;li&gt;This blog post introduces &lt;a href="https://code.google.com/p/kippo/" rel="nofollow noopener"&gt;Kippo&lt;/a&gt;, an SSH honeypot tool, and how to use it in combination with OpenBSD&lt;/li&gt;
&lt;li&gt;It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely&lt;/li&gt;
&lt;li&gt;You can use this to get new 0day exploits or find weaknesses in your systems&lt;/li&gt;
&lt;li&gt;OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.netbsd.org/foundation/reports/financial/2013.html" rel="nofollow noopener"&gt;NetBSD foundation financial report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The NetBSD foundation has posted their 2013 financial report&lt;/li&gt;
&lt;li&gt;It's a very "no nonsense" page, pretty much only the hard numbers&lt;/li&gt;
&lt;li&gt;In 2013, they got $26,000 of income in donations&lt;/li&gt;
&lt;li&gt;The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else&lt;/li&gt;
&lt;li&gt;Be sure to donate to whichever BSDs you like and use!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" rel="nofollow noopener"&gt;Building a fully-encrypted NAS with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing&lt;/li&gt;
&lt;li&gt;This article takes a look at the OpenBSD side and &lt;a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" rel="nofollow noopener"&gt;explains how&lt;/a&gt; to build a NAS with security in mind&lt;/li&gt;
&lt;li&gt;The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected&lt;/li&gt;
&lt;li&gt;The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too&lt;/li&gt;
&lt;li&gt;There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Brian Callahan &amp;amp; Aaron Bieber - &lt;a href="mailto:admin@lists.nycbug.org" rel="nofollow noopener"&gt;admin@lists.nycbug.org&lt;/a&gt; &amp;amp; &lt;a href="mailto:admin@cobug.org" rel="nofollow noopener"&gt;admin@cobug.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Forming a local BSD Users Group&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener"&gt;The basics of pkgsrc&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" rel="nofollow noopener"&gt;FreeBSD periodic mails vs. monitoring&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email&lt;/li&gt;
&lt;li&gt;This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them&lt;/li&gt;
&lt;li&gt;From bad SSH logins to Zabbix alerts, it all adds up quickly&lt;/li&gt;
&lt;li&gt;It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.skogsrud.net/?p=44" rel="nofollow noopener"&gt;Doing cool stuff with OpenBSD routing domains&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A blog post from our viewer and regular emailer, Kjell-Aleksander!&lt;/li&gt;
&lt;li&gt;He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project&lt;/li&gt;
&lt;li&gt;This is where OpenBSD routing domains and pf come in to save the day&lt;/li&gt;
&lt;li&gt;The blog post goes through the process with all the network details you could ever dream of&lt;/li&gt;
&lt;li&gt;He even &lt;a href="http://i.imgur.com/penYQFP.jpg" rel="nofollow noopener"&gt;named his networking equipment... after us&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" rel="nofollow noopener"&gt;LibreSSL, the good and the bad&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We're all probably familiar with OpenBSD's fork of OpenSSL at this point&lt;/li&gt;
&lt;li&gt;However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"&lt;/li&gt;
&lt;li&gt;This article talks about some of the cryptographic development challenges involved with maintaining such a massive project&lt;/li&gt;
&lt;li&gt;You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled&lt;/li&gt;
&lt;li&gt;It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Lots going on in PCBSD land this week, AppCafe has been redesigned&lt;/li&gt;
&lt;li&gt;The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update&lt;/li&gt;
&lt;li&gt;In the more &lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" rel="nofollow noopener"&gt;recent post&lt;/a&gt;, there's some further explanation of the PBI system and the reason for the transition&lt;/li&gt;
&lt;li&gt;It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2UbEhgjce" rel="nofollow noopener"&gt;Antonio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21XU0y3JP" rel="nofollow noopener"&gt;Daniel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QQtuawFl" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20XrT5Q8U" rel="nofollow noopener"&gt;tsyn writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ayZ1nsdv" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pkgsrc, bug, bsd user group, users group, community, lug, uug, unix users group, packages, signing, binary, source, compile, ports, nycbug, nycbsdcon, cobug, colorado, new york, conference, presentation, 11.0, ssh, honeypot, script kiddies, kippo, foundation, financial report, encrypted, nas, network attached storage, full disk encryption, periodic, routing domains, pf, the book of pf, third edition, 3rd edition, cron, monitoring, openssl, libressl</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blather.michaelwlucas.com/archives/2053" rel="nofollow noopener">FreeBSD 11 goals and discussion</a></h3>

<ul>
<li>Something that actually happened at BSDCan this year...</li>
<li>During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE</li>
<li>Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support</li>
<li>A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more</li>
<li>There's also some notes from the <a href="http://blather.michaelwlucas.com/archives/2060" rel="nofollow noopener">devsummit virtualization session</a>, mostly talking about bhyve</li>
<li>Lastly, he also provides some notes about <a href="http://blather.michaelwlucas.com/archives/2065" rel="nofollow noopener">ports and packages</a> and where they're going
***</li>
</ul>

<h3><a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" rel="nofollow noopener">An SSH honeypot with OpenBSD and Kippo</a></h3>

<ul>
<li>Everyone loves messing with script kiddies, right?</li>
<li>This blog post introduces <a href="https://code.google.com/p/kippo/" rel="nofollow noopener">Kippo</a>, an SSH honeypot tool, and how to use it in combination with OpenBSD</li>
<li>It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely</li>
<li>You can use this to get new 0day exploits or find weaknesses in your systems</li>
<li>OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***</li>
</ul>

<h3><a href="https://www.netbsd.org/foundation/reports/financial/2013.html" rel="nofollow noopener">NetBSD foundation financial report</a></h3>

<ul>
<li>The NetBSD foundation has posted their 2013 financial report</li>
<li>It's a very "no nonsense" page, pretty much only the hard numbers</li>
<li>In 2013, they got $26,000 of income in donations</li>
<li>The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else</li>
<li>Be sure to donate to whichever BSDs you like and use!
***</li>
</ul>

<h3><a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" rel="nofollow noopener">Building a fully-encrypted NAS with OpenBSD</a></h3>

<ul>
<li>Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing</li>
<li>This article takes a look at the OpenBSD side and <a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" rel="nofollow noopener">explains how</a> to build a NAS with security in mind</li>
<li>The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected</li>
<li>The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too</li>
<li>There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***</li>
</ul>

<h2>Interview - Brian Callahan &amp; Aaron Bieber - <a href="mailto:admin@lists.nycbug.org" rel="nofollow noopener">admin@lists.nycbug.org</a> &amp; <a href="mailto:admin@cobug.org" rel="nofollow noopener">admin@cobug.org</a></h2>

<p>Forming a local BSD Users Group</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener">The basics of pkgsrc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" rel="nofollow noopener">FreeBSD periodic mails vs. monitoring</a></h3>

<ul>
<li>If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email</li>
<li>This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them</li>
<li>From bad SSH logins to Zabbix alerts, it all adds up quickly</li>
<li>It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***</li>
</ul>

<h3><a href="http://www.skogsrud.net/?p=44" rel="nofollow noopener">Doing cool stuff with OpenBSD routing domains</a></h3>

<ul>
<li>A blog post from our viewer and regular emailer, Kjell-Aleksander!</li>
<li>He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project</li>
<li>This is where OpenBSD routing domains and pf come in to save the day</li>
<li>The blog post goes through the process with all the network details you could ever dream of</li>
<li>He even <a href="http://i.imgur.com/penYQFP.jpg" rel="nofollow noopener">named his networking equipment... after us</a>
***</li>
</ul>

<h3><a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" rel="nofollow noopener">LibreSSL, the good and the bad</a></h3>

<ul>
<li>We're all probably familiar with OpenBSD's fork of OpenSSL at this point</li>
<li>However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"</li>
<li>This article talks about some of the cryptographic development challenges involved with maintaining such a massive project</li>
<li>You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled</li>
<li>It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Lots going on in PCBSD land this week, AppCafe has been redesigned</li>
<li>The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update</li>
<li>In the more <a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" rel="nofollow noopener">recent post</a>, there's some further explanation of the PBI system and the reason for the transition</li>
<li>It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UbEhgjce" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s21XU0y3JP" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2QQtuawFl" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20XrT5Q8U" rel="nofollow noopener">tsyn writes in</a></li>
<li><a href="http://slexy.org/view/s2ayZ1nsdv" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blather.michaelwlucas.com/archives/2053" rel="nofollow noopener">FreeBSD 11 goals and discussion</a></h3>

<ul>
<li>Something that actually happened at BSDCan this year...</li>
<li>During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE</li>
<li>Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support</li>
<li>A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more</li>
<li>There's also some notes from the <a href="http://blather.michaelwlucas.com/archives/2060" rel="nofollow noopener">devsummit virtualization session</a>, mostly talking about bhyve</li>
<li>Lastly, he also provides some notes about <a href="http://blather.michaelwlucas.com/archives/2065" rel="nofollow noopener">ports and packages</a> and where they're going
***</li>
</ul>

<h3><a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" rel="nofollow noopener">An SSH honeypot with OpenBSD and Kippo</a></h3>

<ul>
<li>Everyone loves messing with script kiddies, right?</li>
<li>This blog post introduces <a href="https://code.google.com/p/kippo/" rel="nofollow noopener">Kippo</a>, an SSH honeypot tool, and how to use it in combination with OpenBSD</li>
<li>It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely</li>
<li>You can use this to get new 0day exploits or find weaknesses in your systems</li>
<li>OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***</li>
</ul>

<h3><a href="https://www.netbsd.org/foundation/reports/financial/2013.html" rel="nofollow noopener">NetBSD foundation financial report</a></h3>

<ul>
<li>The NetBSD foundation has posted their 2013 financial report</li>
<li>It's a very "no nonsense" page, pretty much only the hard numbers</li>
<li>In 2013, they got $26,000 of income in donations</li>
<li>The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else</li>
<li>Be sure to donate to whichever BSDs you like and use!
***</li>
</ul>

<h3><a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" rel="nofollow noopener">Building a fully-encrypted NAS with OpenBSD</a></h3>

<ul>
<li>Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing</li>
<li>This article takes a look at the OpenBSD side and <a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" rel="nofollow noopener">explains how</a> to build a NAS with security in mind</li>
<li>The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected</li>
<li>The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too</li>
<li>There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***</li>
</ul>

<h2>Interview - Brian Callahan &amp; Aaron Bieber - <a href="mailto:admin@lists.nycbug.org" rel="nofollow noopener">admin@lists.nycbug.org</a> &amp; <a href="mailto:admin@cobug.org" rel="nofollow noopener">admin@cobug.org</a></h2>

<p>Forming a local BSD Users Group</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pkgsrc" rel="nofollow noopener">The basics of pkgsrc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" rel="nofollow noopener">FreeBSD periodic mails vs. monitoring</a></h3>

<ul>
<li>If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email</li>
<li>This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them</li>
<li>From bad SSH logins to Zabbix alerts, it all adds up quickly</li>
<li>It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***</li>
</ul>

<h3><a href="http://www.skogsrud.net/?p=44" rel="nofollow noopener">Doing cool stuff with OpenBSD routing domains</a></h3>

<ul>
<li>A blog post from our viewer and regular emailer, Kjell-Aleksander!</li>
<li>He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project</li>
<li>This is where OpenBSD routing domains and pf come in to save the day</li>
<li>The blog post goes through the process with all the network details you could ever dream of</li>
<li>He even <a href="http://i.imgur.com/penYQFP.jpg" rel="nofollow noopener">named his networking equipment... after us</a>
***</li>
</ul>

<h3><a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" rel="nofollow noopener">LibreSSL, the good and the bad</a></h3>

<ul>
<li>We're all probably familiar with OpenBSD's fork of OpenSSL at this point</li>
<li>However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"</li>
<li>This article talks about some of the cryptographic development challenges involved with maintaining such a massive project</li>
<li>You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled</li>
<li>It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Lots going on in PCBSD land this week, AppCafe has been redesigned</li>
<li>The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update</li>
<li>In the more <a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" rel="nofollow noopener">recent post</a>, there's some further explanation of the PBI system and the reason for the transition</li>
<li>It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UbEhgjce" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s21XU0y3JP" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2QQtuawFl" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20XrT5Q8U" rel="nofollow noopener">tsyn writes in</a></li>
<li><a href="http://slexy.org/view/s2ayZ1nsdv" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>35: Puffy Firewall</title>
  <link>https://www.bsdnow.tv/35</link>
  <guid isPermaLink="false">203904d9-509c-4727-918f-d5e6a6276cf8</guid>
  <pubDate>Wed, 30 Apr 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/203904d9-509c-4727-918f-d5e6a6276cf8.mp3" length="57157492" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:19:23</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140419151959" rel="nofollow noopener"&gt;ALTQ removed from PF&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Kicking off our big PF episode...&lt;/li&gt;
&lt;li&gt;The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current&lt;/li&gt;
&lt;li&gt;There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf&lt;/li&gt;
&lt;li&gt;As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping&lt;/li&gt;
&lt;li&gt;After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem&lt;/li&gt;
&lt;li&gt;This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" rel="nofollow noopener"&gt;FreeBSD Quarterly Status Report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks&lt;/li&gt;
&lt;li&gt;Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added&lt;/li&gt;
&lt;li&gt;We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team&lt;/li&gt;
&lt;li&gt;LOTS of details and LOTS of topics to cover, give it a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140417184158" rel="nofollow noopener"&gt;OpenBSD's OpenSSL rewrite continues with m2k14&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A mini OpenBSD &lt;a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener"&gt;hackathon&lt;/a&gt; begins in Morocco, Africa&lt;/li&gt;
&lt;li&gt;You can follow the changes in &lt;a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" rel="nofollow noopener"&gt;the -current CVS log&lt;/a&gt;, but &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140418063443" rel="nofollow noopener"&gt;a lot of work&lt;/a&gt; is mainly going towards the OpenSSL cleaning&lt;/li&gt;
&lt;li&gt;We've got two &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140429121423" rel="nofollow noopener"&gt;trip&lt;/a&gt; &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140425115340" rel="nofollow noopener"&gt;reports&lt;/a&gt; so far, hopefully we'll have some more to show you in a future episode&lt;/li&gt;
&lt;li&gt;You can see some of the &lt;a href="http://opensslrampage.org/" rel="nofollow noopener"&gt;more interesting quotes&lt;/a&gt; from the tear-down or &lt;a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener"&gt;see everything&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140423045847" rel="nofollow noopener"&gt;Apparently&lt;/a&gt; they are going to call the fork "&lt;a href="https://news.ycombinator.com/item?id=7623789" rel="nofollow noopener"&gt;LibreSSL&lt;/a&gt;" ....&lt;/li&gt;
&lt;li&gt;&lt;a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener"&gt;What were the OpenSSL developers thinking&lt;/a&gt;? The RSA private key was used to seed the entropy!&lt;/li&gt;
&lt;li&gt;We also got &lt;a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" rel="nofollow noopener"&gt;some mainstream news coverage&lt;/a&gt; and &lt;a href="http://www.tedunangst.com/flak/post/origins-of-libressl" rel="nofollow noopener"&gt;another post from Ted&lt;/a&gt; about the history of the fork&lt;/li&gt;
&lt;li&gt;Definitely consider &lt;a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener"&gt;donating to the OpenBSD foundation&lt;/a&gt;, this fork will benefit all the other BSDs too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" rel="nofollow noopener"&gt;NetBSD 6.1.4 and 6.0.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes&lt;/li&gt;
&lt;li&gt;The main update is - of course - the heartbleed vulnerability&lt;/li&gt;
&lt;li&gt;Also includes fixes for other security issues and even a kernel panic... on Atari&lt;/li&gt;
&lt;li&gt;Patch your Ataris right now, this is serious business
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Peter Hansteen - &lt;a href="mailto:peter@bsdly.net" rel="nofollow noopener"&gt;peter@bsdly.net&lt;/a&gt; / &lt;a href="https://twitter.com/pitrh" rel="nofollow noopener"&gt;@pitrh&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The Book of PF: 3rd edition&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener"&gt;BSD Firewalls: PF&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=351411" rel="nofollow noopener"&gt;New Xorg now the default in FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For quite a while now, FreeBSD has had two versions of X11 in ports&lt;/li&gt;
&lt;li&gt;The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf&lt;/li&gt;
&lt;li&gt;They've finally made the switch for 10-STABLE and 9-STABLE&lt;/li&gt;
&lt;li&gt;Check &lt;a href="https://wiki.freebsd.org/Graphics" rel="nofollow noopener"&gt;this wiki page&lt;/a&gt; for more info
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" rel="nofollow noopener"&gt;GSoC-accepted BSD projects&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned&lt;/li&gt;
&lt;li&gt;OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" rel="nofollow noopener"&gt;FreeBSD list&lt;/a&gt; was also posted&lt;/li&gt;
&lt;li&gt;Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more&lt;/li&gt;
&lt;li&gt;Good luck to all the students participating, hopefully they become full time BSD users
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" rel="nofollow noopener"&gt;Complexity of FreeBSD VFS using ZFS as an example&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;HybridCluster posted the second part of their VFS and ZFS series&lt;/li&gt;
&lt;li&gt;This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy&lt;/li&gt;
&lt;li&gt;Of course, also watch &lt;a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" rel="nofollow noopener"&gt;episode 24&lt;/a&gt; for our interview with HybridCluster - they do really interesting stuff
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Preload has been ported over, it's a daemon that prefetches applications&lt;/li&gt;
&lt;li&gt;PCBSD is developing their own desktop environment, Lumina (&lt;a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" rel="nofollow noopener"&gt;there's also an FAQ&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;It's still in active development, but you can try it out by installing from ports&lt;/li&gt;
&lt;li&gt;We'll be showing a live demo of it in a few weeks (when development settles down a bit)&lt;/li&gt;
&lt;li&gt;Some kid in Australia &lt;a href="https://www.youtube.com/watch?v=ETxhbf3-z18" rel="nofollow noopener"&gt;subjects his poor mother to being on camera&lt;/a&gt; while she tries out PCBSD and gives her impressions of it
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pf, firewall, pfsense, ipfw, ipfilter, router, packet filter, book of pf, third edition, 3rd, bsdcan, presentation, security, peter hansteen, peter n.m. hansteen, pitrh, iptables, npf, nostarch, no starch press, m2k14, hackathon, libressl, openssl, fork</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">ALTQ removed from PF</a></h3>

<ul>
<li>Kicking off our big PF episode...</li>
<li>The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current</li>
<li>There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf</li>
<li>As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping</li>
<li>After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem</li>
<li>This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" rel="nofollow noopener">FreeBSD Quarterly Status Report</a></h3>

<ul>
<li>The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks</li>
<li>Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added</li>
<li>We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team</li>
<li>LOTS of details and LOTS of topics to cover, give it a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140417184158" rel="nofollow noopener">OpenBSD's OpenSSL rewrite continues with m2k14</a></h3>

<ul>
<li>A mini OpenBSD <a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">hackathon</a> begins in Morocco, Africa</li>
<li>You can follow the changes in <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" rel="nofollow noopener">the -current CVS log</a>, but <a href="http://undeadly.org/cgi?action=article&amp;sid=20140418063443" rel="nofollow noopener">a lot of work</a> is mainly going towards the OpenSSL cleaning</li>
<li>We've got two <a href="http://undeadly.org/cgi?action=article&amp;sid=20140429121423" rel="nofollow noopener">trip</a> <a href="http://undeadly.org/cgi?action=article&amp;sid=20140425115340" rel="nofollow noopener">reports</a> so far, hopefully we'll have some more to show you in a future episode</li>
<li>You can see some of the <a href="http://opensslrampage.org/" rel="nofollow noopener">more interesting quotes</a> from the tear-down or <a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener">see everything</a></li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140423045847" rel="nofollow noopener">Apparently</a> they are going to call the fork "<a href="https://news.ycombinator.com/item?id=7623789" rel="nofollow noopener">LibreSSL</a>" ....</li>
<li><a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener">What were the OpenSSL developers thinking</a>? The RSA private key was used to seed the entropy!</li>
<li>We also got <a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" rel="nofollow noopener">some mainstream news coverage</a> and <a href="http://www.tedunangst.com/flak/post/origins-of-libressl" rel="nofollow noopener">another post from Ted</a> about the history of the fork</li>
<li>Definitely consider <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">donating to the OpenBSD foundation</a>, this fork will benefit all the other BSDs too
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" rel="nofollow noopener">NetBSD 6.1.4 and 6.0.5 released</a></h3>

<ul>
<li>New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes</li>
<li>The main update is - of course - the heartbleed vulnerability</li>
<li>Also includes fixes for other security issues and even a kernel panic... on Atari</li>
<li>Patch your Ataris right now, this is serious business
***</li>
</ul>

<h2>Interview - Peter Hansteen - <a href="mailto:peter@bsdly.net" rel="nofollow noopener">peter@bsdly.net</a> / <a href="https://twitter.com/pitrh" rel="nofollow noopener">@pitrh</a></h2>

<p>The Book of PF: 3rd edition</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener">BSD Firewalls: PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=351411" rel="nofollow noopener">New Xorg now the default in FreeBSD</a></h3>

<ul>
<li>For quite a while now, FreeBSD has had two versions of X11 in ports</li>
<li>The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf</li>
<li>They've finally made the switch for 10-STABLE and 9-STABLE</li>
<li>Check <a href="https://wiki.freebsd.org/Graphics" rel="nofollow noopener">this wiki page</a> for more info
***</li>
</ul>

<h3><a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" rel="nofollow noopener">GSoC-accepted BSD projects</a></h3>

<ul>
<li>The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned</li>
<li>OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon</li>
<li>The <a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" rel="nofollow noopener">FreeBSD list</a> was also posted</li>
<li>Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more</li>
<li>Good luck to all the students participating, hopefully they become full time BSD users
***</li>
</ul>

<h3><a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" rel="nofollow noopener">Complexity of FreeBSD VFS using ZFS as an example</a></h3>

<ul>
<li>HybridCluster posted the second part of their VFS and ZFS series</li>
<li>This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy</li>
<li>Of course, also watch <a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" rel="nofollow noopener">episode 24</a> for our interview with HybridCluster - they do really interesting stuff
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Preload has been ported over, it's a daemon that prefetches applications</li>
<li>PCBSD is developing their own desktop environment, Lumina (<a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" rel="nofollow noopener">there's also an FAQ</a>)</li>
<li>It's still in active development, but you can try it out by installing from ports</li>
<li>We'll be showing a live demo of it in a few weeks (when development settles down a bit)</li>
<li>Some kid in Australia <a href="https://www.youtube.com/watch?v=ETxhbf3-z18" rel="nofollow noopener">subjects his poor mother to being on camera</a> while she tries out PCBSD and gives her impressions of it
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">ALTQ removed from PF</a></h3>

<ul>
<li>Kicking off our big PF episode...</li>
<li>The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current</li>
<li>There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf</li>
<li>As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping</li>
<li>After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem</li>
<li>This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" rel="nofollow noopener">FreeBSD Quarterly Status Report</a></h3>

<ul>
<li>The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks</li>
<li>Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added</li>
<li>We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team</li>
<li>LOTS of details and LOTS of topics to cover, give it a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140417184158" rel="nofollow noopener">OpenBSD's OpenSSL rewrite continues with m2k14</a></h3>

<ul>
<li>A mini OpenBSD <a href="http://www.openbsd.org/hackathons.html" rel="nofollow noopener">hackathon</a> begins in Morocco, Africa</li>
<li>You can follow the changes in <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" rel="nofollow noopener">the -current CVS log</a>, but <a href="http://undeadly.org/cgi?action=article&amp;sid=20140418063443" rel="nofollow noopener">a lot of work</a> is mainly going towards the OpenSSL cleaning</li>
<li>We've got two <a href="http://undeadly.org/cgi?action=article&amp;sid=20140429121423" rel="nofollow noopener">trip</a> <a href="http://undeadly.org/cgi?action=article&amp;sid=20140425115340" rel="nofollow noopener">reports</a> so far, hopefully we'll have some more to show you in a future episode</li>
<li>You can see some of the <a href="http://opensslrampage.org/" rel="nofollow noopener">more interesting quotes</a> from the tear-down or <a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener">see everything</a></li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140423045847" rel="nofollow noopener">Apparently</a> they are going to call the fork "<a href="https://news.ycombinator.com/item?id=7623789" rel="nofollow noopener">LibreSSL</a>" ....</li>
<li><a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" rel="nofollow noopener">What were the OpenSSL developers thinking</a>? The RSA private key was used to seed the entropy!</li>
<li>We also got <a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" rel="nofollow noopener">some mainstream news coverage</a> and <a href="http://www.tedunangst.com/flak/post/origins-of-libressl" rel="nofollow noopener">another post from Ted</a> about the history of the fork</li>
<li>Definitely consider <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">donating to the OpenBSD foundation</a>, this fork will benefit all the other BSDs too
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" rel="nofollow noopener">NetBSD 6.1.4 and 6.0.5 released</a></h3>

<ul>
<li>New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes</li>
<li>The main update is - of course - the heartbleed vulnerability</li>
<li>Also includes fixes for other security issues and even a kernel panic... on Atari</li>
<li>Patch your Ataris right now, this is serious business
***</li>
</ul>

<h2>Interview - Peter Hansteen - <a href="mailto:peter@bsdly.net" rel="nofollow noopener">peter@bsdly.net</a> / <a href="https://twitter.com/pitrh" rel="nofollow noopener">@pitrh</a></h2>

<p>The Book of PF: 3rd edition</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pf" rel="nofollow noopener">BSD Firewalls: PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=351411" rel="nofollow noopener">New Xorg now the default in FreeBSD</a></h3>

<ul>
<li>For quite a while now, FreeBSD has had two versions of X11 in ports</li>
<li>The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf</li>
<li>They've finally made the switch for 10-STABLE and 9-STABLE</li>
<li>Check <a href="https://wiki.freebsd.org/Graphics" rel="nofollow noopener">this wiki page</a> for more info
***</li>
</ul>

<h3><a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" rel="nofollow noopener">GSoC-accepted BSD projects</a></h3>

<ul>
<li>The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned</li>
<li>OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon</li>
<li>The <a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" rel="nofollow noopener">FreeBSD list</a> was also posted</li>
<li>Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more</li>
<li>Good luck to all the students participating, hopefully they become full time BSD users
***</li>
</ul>

<h3><a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" rel="nofollow noopener">Complexity of FreeBSD VFS using ZFS as an example</a></h3>

<ul>
<li>HybridCluster posted the second part of their VFS and ZFS series</li>
<li>This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy</li>
<li>Of course, also watch <a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" rel="nofollow noopener">episode 24</a> for our interview with HybridCluster - they do really interesting stuff
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Preload has been ported over, it's a daemon that prefetches applications</li>
<li>PCBSD is developing their own desktop environment, Lumina (<a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" rel="nofollow noopener">there's also an FAQ</a>)</li>
<li>It's still in active development, but you can try it out by installing from ports</li>
<li>We'll be showing a live demo of it in a few weeks (when development settles down a bit)</li>
<li>Some kid in Australia <a href="https://www.youtube.com/watch?v=ETxhbf3-z18" rel="nofollow noopener">subjects his poor mother to being on camera</a> while she tries out PCBSD and gives her impressions of it
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>33: Certified Package Delivery</title>
  <link>https://www.bsdnow.tv/33</link>
  <guid isPermaLink="false">f0c15113-8ade-464b-a89f-3398734256dc</guid>
  <pubDate>Wed, 16 Apr 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/f0c15113-8ade-464b-a89f-3398734256dc.mp3" length="57837748" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:19</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener"&gt;BSDCan schedule, speakers and talks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's BSDCan will kick off on May 14th in Ottawa&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener"&gt;list of speakers&lt;/a&gt; is also out&lt;/li&gt;
&lt;li&gt;And finally &lt;a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener"&gt;the talks&lt;/a&gt; everyone's looking forward to&lt;/li&gt;
&lt;li&gt;Lots of great tutorials and talks, spanning a wide range of topics of interest&lt;/li&gt;
&lt;li&gt;Be sure to come by so you can and meet Allan and Kris in person &lt;a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener"&gt;and get BSDCan shirts&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener"&gt;NYCBSDCon talks uploaded&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon&lt;/li&gt;
&lt;li&gt;Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener"&gt;Dru Lavigne's talk&lt;/a&gt;, "ZFS Management Tools in FreeNAS and PC-BSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener"&gt;Scott Long's talk&lt;/a&gt;, "Serving one third of the Internet via FreeBSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener"&gt;Michael W. Lucas' talk&lt;/a&gt;, "BSD Breaking Barriers"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener"&gt;FreeBSD Journal, issue 2&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The bi-monthly FreeBSD journal's second issue is out&lt;/li&gt;
&lt;li&gt;Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates&lt;/li&gt;
&lt;li&gt;In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc&lt;/li&gt;
&lt;li&gt;"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"&lt;/li&gt;
&lt;li&gt;Check &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;our interview with GNN&lt;/a&gt; for more information about the journal
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener"&gt;OpenSSL, more like OpenSS-Hell&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy&lt;/li&gt;
&lt;li&gt;There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so&lt;/li&gt;
&lt;li&gt;We finally have &lt;a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener"&gt;a timeline of events&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reactions from &lt;a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener"&gt;ISC&lt;/a&gt;, &lt;a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener"&gt;PCBSD&lt;/a&gt;, &lt;a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;, the &lt;a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener"&gt;Tor&lt;/a&gt; &lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener"&gt;project&lt;/a&gt;, &lt;a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener"&gt;NetBSD&lt;/a&gt;, &lt;a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener"&gt;oss-sec&lt;/a&gt;, &lt;a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener"&gt;PHK&lt;/a&gt;, &lt;a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener"&gt;Varnish&lt;/a&gt; and &lt;a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener"&gt;Akamai&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;pfSense&lt;/a&gt; released &lt;a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener"&gt;a new version to fix it&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenBSD &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139715336230455&amp;amp;w=2" rel="nofollow noopener"&gt;disabled heartbeat entirely&lt;/a&gt; and is very &lt;a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener"&gt;unforgiving of the IETF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has two &lt;a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener"&gt;good&lt;/a&gt; &lt;a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener"&gt;write-ups&lt;/a&gt; about the issue and how horrible the OpenSSL codebase is&lt;/li&gt;
&lt;li&gt;A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"&lt;/li&gt;
&lt;li&gt;Sounds like &lt;a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener"&gt;someone else&lt;/a&gt; was having fun with the bug for a while too&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;There's also another OpenSSL bug&lt;/strong&gt; that &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139732441810737&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD patched&lt;/a&gt; - it allows an attacker to &lt;strong&gt;inject data from one connection into another&lt;/strong&gt; &lt;/li&gt;
&lt;li&gt;OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140415093252" rel="nofollow noopener"&gt;seeing a fork&lt;/a&gt; in real time
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jim Brown - &lt;a href="mailto:info@bsdcertification.org" rel="nofollow noopener"&gt;info@bsdcertification.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href="http://bsdcertification.org/" rel="nofollow noopener"&gt;BSD Certification&lt;/a&gt; exams&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener"&gt;Building OpenBSD binary packages in bulk&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/aperezdc/signify" rel="nofollow noopener"&gt;Portable signify&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back in &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;episode 23&lt;/a&gt; we talked with Ted Unangst about the new "signify" tool in OpenBSD&lt;/li&gt;
&lt;li&gt;Now there's a (completely unofficial) portable version of it on github&lt;/li&gt;
&lt;li&gt;If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it&lt;/li&gt;
&lt;li&gt;Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener"&gt;Foundation goals and updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenBSD foundation has reached their 2014 goal of $150,000&lt;/li&gt;
&lt;li&gt;You can check &lt;a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener"&gt;their activities and goals&lt;/a&gt; to see where the money is going&lt;/li&gt;
&lt;li&gt;Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data&lt;/li&gt;
&lt;li&gt;The FreeBSD foundation has kicked off their &lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener"&gt;spring fundraising&lt;/a&gt; campaign&lt;/li&gt;
&lt;li&gt;There's also a list of their activities and goals available to read through&lt;/li&gt;
&lt;li&gt;Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New PBI runtime that fixes stability issues and decreases load times&lt;/li&gt;
&lt;li&gt;"Update Center" is getting a lot of development and improvements&lt;/li&gt;
&lt;li&gt;Lots of misc. bug fixes and updates
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener"&gt;There's a reddit thread&lt;/a&gt; we wanted to highlight - a user wants to show his friend BSD and why it's great&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener"&gt;iGibbs writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener"&gt;Matt writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, dpb, distributed ports builder, marc espie, poudriere, package builds, jim brown, bsdcertification, bsd certification, exam, test, openssl, heartbleed, exploit, ssl, tls, heartbeat, openssh, theo de raadt, hole, 0day, zero day, bsdcan, nycbsdcon, presentations, talks, conference, recording, netflix, tarsnap, mitigation, ixsystems, foundation, journal, cve</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>11: The Gateway Drug</title>
  <link>https://www.bsdnow.tv/11</link>
  <guid isPermaLink="false">43438bdb-8de0-4237-81e2-da2f448be5ef</guid>
  <pubDate>Wed, 13 Nov 2013 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/43438bdb-8de0-4237-81e2-da2f448be5ef.mp3" length="78628291" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we sit down to chat with Justin Sherrill of the DragonflyBSD project about their new 3.6 release. Later on, we'll be showing you a huge tutorial that's been baking for over a month - how to build an OpenBSD router that'll destroy any consumer router on the market! There's lots of news to get caught up on as well, so sit back and enjoy some BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:49:12</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we sit down to chat with Justin Sherrill of the DragonflyBSD project about their new 3.6 release. Later on, we'll be showing you a huge tutorial that's been baking for over a month - how to build an OpenBSD router that'll destroy any consumer router on the market! There's lots of news to get caught up on as well, so sit back and enjoy some BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://openssh.com/txt/release-6.4" rel="nofollow noopener"&gt;OpenSSH 6.4 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Security fixes in &lt;a href="http://openssh.com/" rel="nofollow noopener"&gt;OpenSSH&lt;/a&gt; don't happen very often&lt;/li&gt;
&lt;li&gt;6.4 fixes a memory corruption problem, no new features&lt;/li&gt;
&lt;li&gt;If exploited, this vulnerability might permit code execution with the privileges of the authenticated user and may therefore allow bypassing restricted shell/command configurations.&lt;/li&gt;
&lt;li&gt;Disabling AES-GCM in the server configuration is a workaround&lt;/li&gt;
&lt;li&gt;Only affects 6.2 and 6.3 if compiled against a newer OpenSSL (so FreeBSD 9's base OpenSSL is unaffected, for example)&lt;/li&gt;
&lt;li&gt;Full details &lt;a href="http://www.openssh.com/txt/gcmrekey.adv" rel="nofollow noopener"&gt;here&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2013/11/04/getting-to-know-your-portmgr-mathieu-arnold/" rel="nofollow noopener"&gt;Getting to know your portmgr-lurkers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Next entry in portmgr interview series&lt;/li&gt;
&lt;li&gt;This time they chat with Mathieu Arnold, one of the portmgr-lurkers we mentioned previously&lt;/li&gt;
&lt;li&gt;Lots of questions ranging from why he uses BSD to what he had for breakfast&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2013/11/11/getting-to-know-your-portmgr-antoine-brodin/" rel="nofollow noopener"&gt;Another one&lt;/a&gt; was since released, with Antoine Brodin aka antoine@
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20131108082749" rel="nofollow noopener"&gt;FUSE in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As we glossed over last week, FUSE was recently added to OpenBSD&lt;/li&gt;
&lt;li&gt;Now the guys from the OpenBSD Journal have tracked down more information&lt;/li&gt;
&lt;li&gt;This version is released under an ISC license&lt;/li&gt;
&lt;li&gt;Should be in OpenBSD 5.5, released a little less than 6 months from now&lt;/li&gt;
&lt;li&gt;Will finally enable things like SSHFS to work in OpenBSD
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2013-November/046175.html" rel="nofollow noopener"&gt;Automated submission of kernel panic reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New tool from Colin Percival&lt;/li&gt;
&lt;li&gt;Saves information about kernel panics and emails it to FreeBSD&lt;/li&gt;
&lt;li&gt;Lets you review before sending so you can edit out any private info&lt;/li&gt;
&lt;li&gt;Automatically encrypted before being sent&lt;/li&gt;
&lt;li&gt;FreeBSD never kernel panics so this won't get much use
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Justin Sherrill - &lt;a href="mailto:justin@dragonflybsd.org" rel="nofollow noopener"&gt;justin@dragonflybsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/dragonflybsd" rel="nofollow noopener"&gt;@dragonflybsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;DragonflyBSD 3.6 and the &lt;a href="http://www.shiningsilence.com/dbsdlog/" rel="nofollow noopener"&gt;Dragonfly Digest&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;Building an OpenBSD Router&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://sourceforge.net/projects/bsdrp/files/BSD_Router_Project/1.5/" rel="nofollow noopener"&gt;BSD router project 1.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Nice timing for our router tutorial; TBRP is a FreeBSD distribution for installing on a router&lt;/li&gt;
&lt;li&gt;It's an alternative to pfSense, but not nearly as well known or popular&lt;/li&gt;
&lt;li&gt;New version is based on 9.2-RELEASE, includes lots of general updates and bugfixes&lt;/li&gt;
&lt;li&gt;Fits on a 256MB Compact Flash/USB drive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freshbsd.org/commit/openbsd/5cfc11a2aa3696190b675b6e3e1da7e8ff28582e" rel="nofollow noopener"&gt;Curve25519 now default key exchange&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned in an earlier episode about a patch for &lt;a href="http://cr.yp.to/ecdh.html" rel="nofollow noopener"&gt;curve25519&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Now it's become the default for key exchange&lt;/li&gt;
&lt;li&gt;Will probably make its way into OpenSSH 6.5, would've been in 6.4 if we didn't have that security vulnerability&lt;/li&gt;
&lt;li&gt;It's interesting to see all these big changes in cryptography in OpenBSD lately
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=257650" rel="nofollow noopener"&gt;FreeBSD kernel selection in boot menu&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Adds a kernel selection menu to the beastie menu&lt;/li&gt;
&lt;li&gt;List of kernels is taken from 'kernels' in loader.conf as a space or comma separated list of names to display (up to 9)&lt;/li&gt;
&lt;li&gt;From our good buddy &lt;a href="http://www.bsdnow.tv/episodes/2013-09-25_teskeing_the_possibilities" rel="nofollow noopener"&gt;Devin Teske&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2013/11/pc-bsd-weekly-feature-digest-11813/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;PCDM has officially replaced GDM as the default login manager&lt;/li&gt;
&lt;li&gt;New ISO build scripts (we got a sneak preview last week)&lt;/li&gt;
&lt;li&gt;Lots of bug fixes&lt;/li&gt;
&lt;li&gt;Second set of 10-STABLE ISOs available with new artwork and much more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20131113074042&amp;amp;mode=expanded&amp;amp;count=0" rel="nofollow noopener"&gt;Theo de Raadt speaking at MUUG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Theo will be speaking at Manitoba UNIX User Group in Winnipeg&lt;/li&gt;
&lt;li&gt;On Friday, Nov 15, 2013 at 5:30PM (see show notes for the address)&lt;/li&gt;
&lt;li&gt;If you're watching the show live you have time to make plans, if you're watching the downloaded version it might be happening right now!&lt;/li&gt;
&lt;li&gt;No agenda, but expect some OpenBSD discussion
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21YXhiLRB" rel="nofollow noopener"&gt;Dave writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s215EjcgdM" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21mCP2ecL" rel="nofollow noopener"&gt;Allen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s207ePFrna" rel="nofollow noopener"&gt;Chess writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20iVFXJve" rel="nofollow noopener"&gt;Frank writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, building, bsd, router, gateway, soho, small home office, pcbsd, server, tutorial, guide, howto, interview, firewall, network, hammer fs, dragonfly, openssh, 6.4, dragonfly digest, aes gcm, openssl, bsd router project, tbrp, portmgr, fuse, filesystem in userspace, kernel panic, automatic</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we sit down to chat with Justin Sherrill of the DragonflyBSD project about their new 3.6 release. Later on, we'll be showing you a huge tutorial that's been baking for over a month - how to build an OpenBSD router that'll destroy any consumer router on the market! There's lots of news to get caught up on as well, so sit back and enjoy some BSD Now - the place to B.. SD.</p>

<h2>Headlines</h2>

<h3><a href="http://openssh.com/txt/release-6.4" rel="nofollow noopener">OpenSSH 6.4 released</a></h3>

<ul>
<li>Security fixes in <a href="http://openssh.com/" rel="nofollow noopener">OpenSSH</a> don't happen very often</li>
<li>6.4 fixes a memory corruption problem, no new features</li>
<li>If exploited, this vulnerability might permit code execution with the privileges of the authenticated user and may therefore allow bypassing restricted shell/command configurations.</li>
<li>Disabling AES-GCM in the server configuration is a workaround</li>
<li>Only affects 6.2 and 6.3 if compiled against a newer OpenSSL (so FreeBSD 9's base OpenSSL is unaffected, for example)</li>
<li>Full details <a href="http://www.openssh.com/txt/gcmrekey.adv" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/11/04/getting-to-know-your-portmgr-mathieu-arnold/" rel="nofollow noopener">Getting to know your portmgr-lurkers</a></h3>

<ul>
<li>Next entry in portmgr interview series</li>
<li>This time they chat with Mathieu Arnold, one of the portmgr-lurkers we mentioned previously</li>
<li>Lots of questions ranging from why he uses BSD to what he had for breakfast</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2013/11/11/getting-to-know-your-portmgr-antoine-brodin/" rel="nofollow noopener">Another one</a> was since released, with Antoine Brodin aka antoine@
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131108082749" rel="nofollow noopener">FUSE in OpenBSD</a></h3>

<ul>
<li>As we glossed over last week, FUSE was recently added to OpenBSD</li>
<li>Now the guys from the OpenBSD Journal have tracked down more information</li>
<li>This version is released under an ISC license</li>
<li>Should be in OpenBSD 5.5, released a little less than 6 months from now</li>
<li>Will finally enable things like SSHFS to work in OpenBSD
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2013-November/046175.html" rel="nofollow noopener">Automated submission of kernel panic reports</a></h3>

<ul>
<li>New tool from Colin Percival</li>
<li>Saves information about kernel panics and emails it to FreeBSD</li>
<li>Lets you review before sending so you can edit out any private info</li>
<li>Automatically encrypted before being sent</li>
<li>FreeBSD never kernel panics so this won't get much use
***</li>
</ul>

<h2>Interview - Justin Sherrill - <a href="mailto:justin@dragonflybsd.org" rel="nofollow noopener">justin@dragonflybsd.org</a> / <a href="https://twitter.com/dragonflybsd" rel="nofollow noopener">@dragonflybsd</a></h2>

<p>DragonflyBSD 3.6 and the <a href="http://www.shiningsilence.com/dbsdlog/" rel="nofollow noopener">Dragonfly Digest</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">Building an OpenBSD Router</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://sourceforge.net/projects/bsdrp/files/BSD_Router_Project/1.5/" rel="nofollow noopener">BSD router project 1.5 released</a></h3>

<ul>
<li>Nice timing for our router tutorial; TBRP is a FreeBSD distribution for installing on a router</li>
<li>It's an alternative to pfSense, but not nearly as well known or popular</li>
<li>New version is based on 9.2-RELEASE, includes lots of general updates and bugfixes</li>
<li>Fits on a 256MB Compact Flash/USB drive
***</li>
</ul>

<h3><a href="http://freshbsd.org/commit/openbsd/5cfc11a2aa3696190b675b6e3e1da7e8ff28582e" rel="nofollow noopener">Curve25519 now default key exchange</a></h3>

<ul>
<li>We mentioned in an earlier episode about a patch for <a href="http://cr.yp.to/ecdh.html" rel="nofollow noopener">curve25519</a></li>
<li>Now it's become the default for key exchange</li>
<li>Will probably make its way into OpenSSH 6.5, would've been in 6.4 if we didn't have that security vulnerability</li>
<li>It's interesting to see all these big changes in cryptography in OpenBSD lately
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=257650" rel="nofollow noopener">FreeBSD kernel selection in boot menu</a></h3>

<ul>
<li>Adds a kernel selection menu to the beastie menu</li>
<li>List of kernels is taken from 'kernels' in loader.conf as a space or comma separated list of names to display (up to 9)</li>
<li>From our good buddy <a href="http://www.bsdnow.tv/episodes/2013-09-25_teskeing_the_possibilities" rel="nofollow noopener">Devin Teske</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/11/pc-bsd-weekly-feature-digest-11813/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>PCDM has officially replaced GDM as the default login manager</li>
<li>New ISO build scripts (we got a sneak preview last week)</li>
<li>Lots of bug fixes</li>
<li>Second set of 10-STABLE ISOs available with new artwork and much more
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131113074042&amp;mode=expanded&amp;count=0" rel="nofollow noopener">Theo de Raadt speaking at MUUG</a></h3>

<ul>
<li>Theo will be speaking at Manitoba UNIX User Group in Winnipeg</li>
<li>On Friday, Nov 15, 2013 at 5:30PM (see show notes for the address)</li>
<li>If you're watching the show live you have time to make plans, if you're watching the downloaded version it might be happening right now!</li>
<li>No agenda, but expect some OpenBSD discussion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21YXhiLRB" rel="nofollow noopener">Dave writes in</a></li>
<li><a href="http://slexy.org/view/s215EjcgdM" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21mCP2ecL" rel="nofollow noopener">Allen writes in</a></li>
<li><a href="http://slexy.org/view/s207ePFrna" rel="nofollow noopener">Chess writes in</a></li>
<li><a href="http://slexy.org/view/s20iVFXJve" rel="nofollow noopener">Frank writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we sit down to chat with Justin Sherrill of the DragonflyBSD project about their new 3.6 release. Later on, we'll be showing you a huge tutorial that's been baking for over a month - how to build an OpenBSD router that'll destroy any consumer router on the market! There's lots of news to get caught up on as well, so sit back and enjoy some BSD Now - the place to B.. SD.</p>

<h2>Headlines</h2>

<h3><a href="http://openssh.com/txt/release-6.4" rel="nofollow noopener">OpenSSH 6.4 released</a></h3>

<ul>
<li>Security fixes in <a href="http://openssh.com/" rel="nofollow noopener">OpenSSH</a> don't happen very often</li>
<li>6.4 fixes a memory corruption problem, no new features</li>
<li>If exploited, this vulnerability might permit code execution with the privileges of the authenticated user and may therefore allow bypassing restricted shell/command configurations.</li>
<li>Disabling AES-GCM in the server configuration is a workaround</li>
<li>Only affects 6.2 and 6.3 if compiled against a newer OpenSSL (so FreeBSD 9's base OpenSSL is unaffected, for example)</li>
<li>Full details <a href="http://www.openssh.com/txt/gcmrekey.adv" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/11/04/getting-to-know-your-portmgr-mathieu-arnold/" rel="nofollow noopener">Getting to know your portmgr-lurkers</a></h3>

<ul>
<li>Next entry in portmgr interview series</li>
<li>This time they chat with Mathieu Arnold, one of the portmgr-lurkers we mentioned previously</li>
<li>Lots of questions ranging from why he uses BSD to what he had for breakfast</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2013/11/11/getting-to-know-your-portmgr-antoine-brodin/" rel="nofollow noopener">Another one</a> was since released, with Antoine Brodin aka antoine@
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131108082749" rel="nofollow noopener">FUSE in OpenBSD</a></h3>

<ul>
<li>As we glossed over last week, FUSE was recently added to OpenBSD</li>
<li>Now the guys from the OpenBSD Journal have tracked down more information</li>
<li>This version is released under an ISC license</li>
<li>Should be in OpenBSD 5.5, released a little less than 6 months from now</li>
<li>Will finally enable things like SSHFS to work in OpenBSD
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2013-November/046175.html" rel="nofollow noopener">Automated submission of kernel panic reports</a></h3>

<ul>
<li>New tool from Colin Percival</li>
<li>Saves information about kernel panics and emails it to FreeBSD</li>
<li>Lets you review before sending so you can edit out any private info</li>
<li>Automatically encrypted before being sent</li>
<li>FreeBSD never kernel panics so this won't get much use
***</li>
</ul>

<h2>Interview - Justin Sherrill - <a href="mailto:justin@dragonflybsd.org" rel="nofollow noopener">justin@dragonflybsd.org</a> / <a href="https://twitter.com/dragonflybsd" rel="nofollow noopener">@dragonflybsd</a></h2>

<p>DragonflyBSD 3.6 and the <a href="http://www.shiningsilence.com/dbsdlog/" rel="nofollow noopener">Dragonfly Digest</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">Building an OpenBSD Router</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://sourceforge.net/projects/bsdrp/files/BSD_Router_Project/1.5/" rel="nofollow noopener">BSD router project 1.5 released</a></h3>

<ul>
<li>Nice timing for our router tutorial; TBRP is a FreeBSD distribution for installing on a router</li>
<li>It's an alternative to pfSense, but not nearly as well known or popular</li>
<li>New version is based on 9.2-RELEASE, includes lots of general updates and bugfixes</li>
<li>Fits on a 256MB Compact Flash/USB drive
***</li>
</ul>

<h3><a href="http://freshbsd.org/commit/openbsd/5cfc11a2aa3696190b675b6e3e1da7e8ff28582e" rel="nofollow noopener">Curve25519 now default key exchange</a></h3>

<ul>
<li>We mentioned in an earlier episode about a patch for <a href="http://cr.yp.to/ecdh.html" rel="nofollow noopener">curve25519</a></li>
<li>Now it's become the default for key exchange</li>
<li>Will probably make its way into OpenSSH 6.5, would've been in 6.4 if we didn't have that security vulnerability</li>
<li>It's interesting to see all these big changes in cryptography in OpenBSD lately
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=257650" rel="nofollow noopener">FreeBSD kernel selection in boot menu</a></h3>

<ul>
<li>Adds a kernel selection menu to the beastie menu</li>
<li>List of kernels is taken from 'kernels' in loader.conf as a space or comma separated list of names to display (up to 9)</li>
<li>From our good buddy <a href="http://www.bsdnow.tv/episodes/2013-09-25_teskeing_the_possibilities" rel="nofollow noopener">Devin Teske</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/11/pc-bsd-weekly-feature-digest-11813/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>PCDM has officially replaced GDM as the default login manager</li>
<li>New ISO build scripts (we got a sneak preview last week)</li>
<li>Lots of bug fixes</li>
<li>Second set of 10-STABLE ISOs available with new artwork and much more
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131113074042&amp;mode=expanded&amp;count=0" rel="nofollow noopener">Theo de Raadt speaking at MUUG</a></h3>

<ul>
<li>Theo will be speaking at Manitoba UNIX User Group in Winnipeg</li>
<li>On Friday, Nov 15, 2013 at 5:30PM (see show notes for the address)</li>
<li>If you're watching the show live you have time to make plans, if you're watching the downloaded version it might be happening right now!</li>
<li>No agenda, but expect some OpenBSD discussion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21YXhiLRB" rel="nofollow noopener">Dave writes in</a></li>
<li><a href="http://slexy.org/view/s215EjcgdM" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21mCP2ecL" rel="nofollow noopener">Allen writes in</a></li>
<li><a href="http://slexy.org/view/s207ePFrna" rel="nofollow noopener">Chess writes in</a></li>
<li><a href="http://slexy.org/view/s20iVFXJve" rel="nofollow noopener">Frank writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
