<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Thu, 11 Jun 2026 23:22:16 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Pf”</title>
    <link>https://www.bsdnow.tv/tags/pf</link>
    <pubDate>Thu, 17 Apr 2025 18:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>607: Sign those commits</title>
  <link>https://www.bsdnow.tv/607</link>
  <guid isPermaLink="false">8c8a9cb9-441e-40a7-9655-ee7d148ef6eb</guid>
  <pubDate>Thu, 17 Apr 2025 18:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/8c8a9cb9-441e-40a7-9655-ee7d148ef6eb.mp3" length="54202368" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We should improve libzfs somewhat, Accurate Effective Storage Performance Benchmark, Debugging aids for pf firewall rules on FreeBSD, OpenBSD and Thunderbolt issue on ThinkPad T480s, Signing Git Commits with an SSH key, Pgrep, LibreOffice downloads on the rise, and more</itunes:subtitle>
  <itunes:duration>56:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We should improve libzfs somewhat, Accurate Effective Storage Performance Benchmark, Debugging aids for pf firewall rules on FreeBSD, OpenBSD and Thunderbolt issue on ThinkPad T480s, Signing Git Commits with an SSH key, Pgrep, LibreOffice downloads on the rise, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://despairlabs.com/blog/posts/2025-03-12-we-should-improve-libzfs-somewhat/" target="_blank" rel="nofollow noopener"&gt;We should improve libzfs somewhat&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://klarasystems.com/articles/accurate-effective-storage-performance-benchmark/?utm_source=BSD%20Now&amp;amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener"&gt;Accurate Effective Storage Performance Benchmark&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://dan.langille.org/2025/02/24/debugging-aids-for-pf-firewall-rules-on-freebsd/" target="_blank" rel="nofollow noopener"&gt;Debugging aids for pf firewall rules on FreeBSD&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://www.tumfatig.net/2025/openbsd-and-thunderbolt-issue-on-thinkpad-t480s/" target="_blank" rel="nofollow noopener"&gt;OpenBSD and Thunderbolt issue on ThinkPad T480s&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://jpmens.net/2025/02/26/signing-git-commits-with-an-ssh-key/" target="_blank" rel="nofollow noopener"&gt;Signing Git Commits with an SSH key&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://www.c0t0d0s0.org/blog/pgrep-z-r.html" target="_blank" rel="nofollow noopener"&gt;Pgrep&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://www.computerworld.com/article/3840480/libreoffice-downloads-on-the-rise-as-users-look-to-avoid-subscription-costs.html" target="_blank" rel="nofollow noopener"&gt;LibreOffice downloads on the rise as users look to avoid subscription costs&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tarsnap&lt;/h2&gt;

&lt;p&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/p&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/607/feedback/Felix%20-%20bhyve%20and%20nvme.md" target="_blank" rel="nofollow noopener"&gt;Felix - Bhyve and NVME&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Join us and other BSD Fans in our &lt;a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSD Now Telegram channel&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, hardenedbsd, tutorial, howto, guide, bsd, operating system, os, open source, foss, shell, cli, unix, tools, utility, berkeley, software, distribution, development, code, programming, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, improve, improvement, libzfs, effective storage performance benchmark, debugging, aid, firewall rules, pf, thunderbolt, thinkpad T480s, git commit, signing, ssh key, pgrep, libreoffice</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We should improve libzfs somewhat, Accurate Effective Storage Performance Benchmark, Debugging aids for pf firewall rules on FreeBSD, OpenBSD and Thunderbolt issue on ThinkPad T480s, Signing Git Commits with an SSH key, Pgrep, LibreOffice downloads on the rise, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://despairlabs.com/blog/posts/2025-03-12-we-should-improve-libzfs-somewhat/" target="_blank" rel="nofollow noopener">We should improve libzfs somewhat</a></p>

<hr>

<p><a href="https://klarasystems.com/articles/accurate-effective-storage-performance-benchmark/?utm_source=BSD%20Now&amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener">Accurate Effective Storage Performance Benchmark</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://dan.langille.org/2025/02/24/debugging-aids-for-pf-firewall-rules-on-freebsd/" target="_blank" rel="nofollow noopener">Debugging aids for pf firewall rules on FreeBSD</a></p>

<hr>

<p><a href="https://www.tumfatig.net/2025/openbsd-and-thunderbolt-issue-on-thinkpad-t480s/" target="_blank" rel="nofollow noopener">OpenBSD and Thunderbolt issue on ThinkPad T480s</a></p>

<hr>

<p><a href="https://jpmens.net/2025/02/26/signing-git-commits-with-an-ssh-key/" target="_blank" rel="nofollow noopener">Signing Git Commits with an SSH key</a></p>

<hr>

<p><a href="https://www.c0t0d0s0.org/blog/pgrep-z-r.html" target="_blank" rel="nofollow noopener">Pgrep</a></p>

<hr>

<p><a href="https://www.computerworld.com/article/3840480/libreoffice-downloads-on-the-rise-as-users-look-to-avoid-subscription-costs.html" target="_blank" rel="nofollow noopener">LibreOffice downloads on the rise as users look to avoid subscription costs</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/607/feedback/Felix%20-%20bhyve%20and%20nvme.md" target="_blank" rel="nofollow noopener">Felix - Bhyve and NVME</a></li>
</ul>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We should improve libzfs somewhat, Accurate Effective Storage Performance Benchmark, Debugging aids for pf firewall rules on FreeBSD, OpenBSD and Thunderbolt issue on ThinkPad T480s, Signing Git Commits with an SSH key, Pgrep, LibreOffice downloads on the rise, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://despairlabs.com/blog/posts/2025-03-12-we-should-improve-libzfs-somewhat/" target="_blank" rel="nofollow noopener">We should improve libzfs somewhat</a></p>

<hr>

<p><a href="https://klarasystems.com/articles/accurate-effective-storage-performance-benchmark/?utm_source=BSD%20Now&amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener">Accurate Effective Storage Performance Benchmark</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://dan.langille.org/2025/02/24/debugging-aids-for-pf-firewall-rules-on-freebsd/" target="_blank" rel="nofollow noopener">Debugging aids for pf firewall rules on FreeBSD</a></p>

<hr>

<p><a href="https://www.tumfatig.net/2025/openbsd-and-thunderbolt-issue-on-thinkpad-t480s/" target="_blank" rel="nofollow noopener">OpenBSD and Thunderbolt issue on ThinkPad T480s</a></p>

<hr>

<p><a href="https://jpmens.net/2025/02/26/signing-git-commits-with-an-ssh-key/" target="_blank" rel="nofollow noopener">Signing Git Commits with an SSH key</a></p>

<hr>

<p><a href="https://www.c0t0d0s0.org/blog/pgrep-z-r.html" target="_blank" rel="nofollow noopener">Pgrep</a></p>

<hr>

<p><a href="https://www.computerworld.com/article/3840480/libreoffice-downloads-on-the-rise-as-users-look-to-avoid-subscription-costs.html" target="_blank" rel="nofollow noopener">LibreOffice downloads on the rise as users look to avoid subscription costs</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/607/feedback/Felix%20-%20bhyve%20and%20nvme.md" target="_blank" rel="nofollow noopener">Felix - Bhyve and NVME</a></li>
</ul>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>595: Arc: the Triumph</title>
  <link>https://www.bsdnow.tv/595</link>
  <guid isPermaLink="false">2773a8f7-f763-4055-a36b-f722e1b273e6</guid>
  <pubDate>Thu, 23 Jan 2025 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/2773a8f7-f763-4055-a36b-f722e1b273e6.mp3" length="104050944" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Applying the ARC Algorithm to the ARC, Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights, Running Web Browsers in FreeBSD Jail, Fixing pf not allowing IPv6 traffic on FreeBSD, Minitel: The Online World France Built Before the Web, Why Google Stores Billions of Lines of Code in a Single Repository, and more</itunes:subtitle>
  <itunes:duration>1:48:23</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Applying the ARC Algorithm to the ARC, Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights, Running Web Browsers in FreeBSD Jail, Fixing pf not allowing IPv6 traffic on FreeBSD, Minitel: The Online World France Built Before the Web, Why Google Stores Billions of Lines of Code in a Single Repository, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://klarasystems.com/articles/applying-the-arc-algorithm-to-the-arc/?utm_source=BSD%20Now&amp;amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener"&gt;Applying the ARC Algorithm to the ARC&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://freebsdfoundation.org/blog/advancing-cloud-native-containers-on-freebsd-podman-testing-highlights/" target="_blank" rel="nofollow noopener"&gt;Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://tumfatig.net/2024/running-web-browsers-in-freebsd-jail/" target="_blank" rel="nofollow noopener"&gt;Running Web Browsers in FreeBSD Jail&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://www.ncartron.org/fixing-pf-not-allowing-ipv6-traffic-on-freebsd.html" target="_blank" rel="nofollow noopener"&gt;Fixing pf not allowing IPv6 traffic on FreeBSD&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://spectrum.ieee.org/minitel-the-online-world-france-built-before-the-web" target="_blank" rel="nofollow noopener"&gt;Minitel: The Online World France Built Before the Web&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://cacm.acm.org/research/why-google-stores-billions-of-lines-of-code-in-a-single-repository/" target="_blank" rel="nofollow noopener"&gt;Why Google Stores Billions of Lines of Code in a Single Repository&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tarsnap&lt;/h2&gt;

&lt;p&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/p&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/595/feedback/Sam%20-%20EDR%20Support.md" target="_blank" rel="nofollow noopener"&gt;Sam - EDR Support&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Join us and other BSD Fans in our &lt;a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSD Now Telegram channel&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, hardenedbsd, tutorial, howto, guide, bsd, operating system, os, open source, foss, shell, cli, unix, tools, utility, berkeley, software, distribution, development, code, programming, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, arc, adaptive replacement cache, Algorithm, cloud native, Containers, podman, testing, browser, jailed browser, pf, packet filter, firewall, ipv6 traffic, minitel, france, google inc. repository</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Applying the ARC Algorithm to the ARC, Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights, Running Web Browsers in FreeBSD Jail, Fixing pf not allowing IPv6 traffic on FreeBSD, Minitel: The Online World France Built Before the Web, Why Google Stores Billions of Lines of Code in a Single Repository, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://klarasystems.com/articles/applying-the-arc-algorithm-to-the-arc/?utm_source=BSD%20Now&amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener">Applying the ARC Algorithm to the ARC</a></p>

<hr>

<p><a href="https://freebsdfoundation.org/blog/advancing-cloud-native-containers-on-freebsd-podman-testing-highlights/" target="_blank" rel="nofollow noopener">Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://tumfatig.net/2024/running-web-browsers-in-freebsd-jail/" target="_blank" rel="nofollow noopener">Running Web Browsers in FreeBSD Jail</a></p>

<hr>

<p><a href="https://www.ncartron.org/fixing-pf-not-allowing-ipv6-traffic-on-freebsd.html" target="_blank" rel="nofollow noopener">Fixing pf not allowing IPv6 traffic on FreeBSD</a></p>

<hr>

<p><a href="https://spectrum.ieee.org/minitel-the-online-world-france-built-before-the-web" target="_blank" rel="nofollow noopener">Minitel: The Online World France Built Before the Web</a></p>

<hr>

<p><a href="https://cacm.acm.org/research/why-google-stores-billions-of-lines-of-code-in-a-single-repository/" target="_blank" rel="nofollow noopener">Why Google Stores Billions of Lines of Code in a Single Repository</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/595/feedback/Sam%20-%20EDR%20Support.md" target="_blank" rel="nofollow noopener">Sam - EDR Support</a></li>
</ul>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Applying the ARC Algorithm to the ARC, Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights, Running Web Browsers in FreeBSD Jail, Fixing pf not allowing IPv6 traffic on FreeBSD, Minitel: The Online World France Built Before the Web, Why Google Stores Billions of Lines of Code in a Single Repository, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://klarasystems.com/articles/applying-the-arc-algorithm-to-the-arc/?utm_source=BSD%20Now&amp;utm_medium=Podcast" target="_blank" rel="nofollow noopener">Applying the ARC Algorithm to the ARC</a></p>

<hr>

<p><a href="https://freebsdfoundation.org/blog/advancing-cloud-native-containers-on-freebsd-podman-testing-highlights/" target="_blank" rel="nofollow noopener">Advancing Cloud Native Containers on FreeBSD: Podman Testing Highlights</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://tumfatig.net/2024/running-web-browsers-in-freebsd-jail/" target="_blank" rel="nofollow noopener">Running Web Browsers in FreeBSD Jail</a></p>

<hr>

<p><a href="https://www.ncartron.org/fixing-pf-not-allowing-ipv6-traffic-on-freebsd.html" target="_blank" rel="nofollow noopener">Fixing pf not allowing IPv6 traffic on FreeBSD</a></p>

<hr>

<p><a href="https://spectrum.ieee.org/minitel-the-online-world-france-built-before-the-web" target="_blank" rel="nofollow noopener">Minitel: The Online World France Built Before the Web</a></p>

<hr>

<p><a href="https://cacm.acm.org/research/why-google-stores-billions-of-lines-of-code-in-a-single-repository/" target="_blank" rel="nofollow noopener">Why Google Stores Billions of Lines of Code in a Single Repository</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/595/feedback/Sam%20-%20EDR%20Support.md" target="_blank" rel="nofollow noopener">Sam - EDR Support</a></li>
</ul>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>565: Secure by default</title>
  <link>https://www.bsdnow.tv/565</link>
  <guid isPermaLink="false">0e1b5cea-6e44-44e4-ac3a-f6f0fe49814c</guid>
  <pubDate>Thu, 27 Jun 2024 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0e1b5cea-6e44-44e4-ac3a-f6f0fe49814c.mp3" length="74142504" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>NetBSD 10 on a Pinebook Pro, OpenBSD extreme privacy setup, Version 256 of systemd boasts '42% less Unix philosophy', Posix.1 2024 is out, Blocking Access From or to Specific Countries Using FreeBSD and Pf, and more.
Date: 2024.06.17</itunes:subtitle>
  <itunes:duration>51:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;NetBSD 10 on a Pinebook Pro, OpenBSD extreme privacy setup, Version 256 of systemd boasts '42% less Unix philosophy', Posix.1 2024 is out, Blocking Access From or to Specific Countries Using FreeBSD and Pf, and more.&lt;br&gt;
Date: 2024.06.17&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.idatum.net/netbsd-10-on-a-pinebook-pro-laptop.html" target="_blank" rel="nofollow noopener"&gt;NetBSD 10 on a Pinebook Pro&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://dataswamp.org/%7Esolene/2024-06-08-openbsd-privacy-setup.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD extreme privacy setup&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.theregister.com/2024/06/13/version_256_systemd/" target="_blank" rel="nofollow noopener"&gt;Version 256 of systemd boasts '42% less Unix philosophy'&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://ieeexplore.ieee.org/document/10555529" target="_blank" rel="nofollow noopener"&gt;Posix.1 2024 is out&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://it-notes.dragas.net/2024/06/16/freebsd-blocking-country-access/" target="_blank" rel="nofollow noopener"&gt;Blocking Access From or to Specific Countries Using FreeBSD and Pf&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.meetup.com/de-DE/bsd-user-group-dusseldorf-bsd-nrw/events/301557512/" target="_blank" rel="nofollow noopener"&gt;BSD User Group Düsseldorf Juli 2024&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.reddit.com/r/unix/comments/1dd60re/another_cool_unix_workstation_that_was_never/" target="_blank" rel="nofollow noopener"&gt;Another cool UNIX workstation, that was never released&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h2&gt;Tarsnap&lt;/h2&gt;

&lt;p&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/p&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Join us and other BSD Fans in our &lt;a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSD Now Telegram channel&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, hardenedbsd, tutorial, howto, guide, bsd, operating system, os, open source, foss, shell, cli, unix, tools, utility, berkeley, software, distribution, development, code, programming, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, pinebook pro, extreme privacy setup, penalize undesirable behavior, systemd, less Unix philosophy, posix, blocking access, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>NetBSD 10 on a Pinebook Pro, OpenBSD extreme privacy setup, Version 256 of systemd boasts '42% less Unix philosophy', Posix.1 2024 is out, Blocking Access From or to Specific Countries Using FreeBSD and Pf, and more.<br>
Date: 2024.06.17</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://www.idatum.net/netbsd-10-on-a-pinebook-pro-laptop.html" target="_blank" rel="nofollow noopener">NetBSD 10 on a Pinebook Pro</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-06-08-openbsd-privacy-setup.html" target="_blank" rel="nofollow noopener">OpenBSD extreme privacy setup</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://www.theregister.com/2024/06/13/version_256_systemd/" target="_blank" rel="nofollow noopener">Version 256 of systemd boasts '42% less Unix philosophy'</a></p>

<hr>

<p><a href="https://ieeexplore.ieee.org/document/10555529" target="_blank" rel="nofollow noopener">Posix.1 2024 is out</a></p>

<hr>

<p><a href="https://it-notes.dragas.net/2024/06/16/freebsd-blocking-country-access/" target="_blank" rel="nofollow noopener">Blocking Access From or to Specific Countries Using FreeBSD and Pf</a></p>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.meetup.com/de-DE/bsd-user-group-dusseldorf-bsd-nrw/events/301557512/" target="_blank" rel="nofollow noopener">BSD User Group Düsseldorf Juli 2024</a></li>
<li><a href="https://www.reddit.com/r/unix/comments/1dd60re/another_cool_unix_workstation_that_was_never/" target="_blank" rel="nofollow noopener">Another cool UNIX workstation, that was never released</a></li>
</ul>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>NetBSD 10 on a Pinebook Pro, OpenBSD extreme privacy setup, Version 256 of systemd boasts '42% less Unix philosophy', Posix.1 2024 is out, Blocking Access From or to Specific Countries Using FreeBSD and Pf, and more.<br>
Date: 2024.06.17</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://www.idatum.net/netbsd-10-on-a-pinebook-pro-laptop.html" target="_blank" rel="nofollow noopener">NetBSD 10 on a Pinebook Pro</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-06-08-openbsd-privacy-setup.html" target="_blank" rel="nofollow noopener">OpenBSD extreme privacy setup</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://www.theregister.com/2024/06/13/version_256_systemd/" target="_blank" rel="nofollow noopener">Version 256 of systemd boasts '42% less Unix philosophy'</a></p>

<hr>

<p><a href="https://ieeexplore.ieee.org/document/10555529" target="_blank" rel="nofollow noopener">Posix.1 2024 is out</a></p>

<hr>

<p><a href="https://it-notes.dragas.net/2024/06/16/freebsd-blocking-country-access/" target="_blank" rel="nofollow noopener">Blocking Access From or to Specific Countries Using FreeBSD and Pf</a></p>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.meetup.com/de-DE/bsd-user-group-dusseldorf-bsd-nrw/events/301557512/" target="_blank" rel="nofollow noopener">BSD User Group Düsseldorf Juli 2024</a></li>
<li><a href="https://www.reddit.com/r/unix/comments/1dd60re/another_cool_unix_workstation_that_was_never/" target="_blank" rel="nofollow noopener">Another cool UNIX workstation, that was never released</a></li>
</ul>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<h2>Feedback/Questions</h2>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" target="_blank" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>465: Deep Space Debugging</title>
  <link>https://www.bsdnow.tv/465</link>
  <guid isPermaLink="false">f6b15e42-bd5a-47de-9df4-b207d0becb33</guid>
  <pubDate>Thu, 28 Jul 2022 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/f6b15e42-bd5a-47de-9df4-b207d0becb33.mp3" length="24400296" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Debugging Lisp in Deep Space, 0 Dependency Websites with OpenBSD &amp; AsciiDoc, Deleting old snapshots on FreeBSD, Full multiprocess support in lldb-server, Basic fix between pf tables and macros, and more</itunes:subtitle>
  <itunes:duration>38:45</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Debugging Lisp in Deep Space, 0 Dependency Websites with OpenBSD &amp;amp; AsciiDoc, Deleting old snapshots on FreeBSD, Full multiprocess support in lldb-server, Basic fix between pf tables and macros, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://thenewstack.io/nasa-programmer-remembers-debugging-lisp-in-deep-space/" target="_blank" rel="nofollow noopener"&gt;NASA Programmer Remembers Debugging Lisp in Deep Space&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://blog.passwordclass.xyz/blogs/2022/06/0-dependency-websites-with-openbsd-asciidoc.html" target="_blank" rel="nofollow noopener"&gt;0 Dependency Websites with OpenBSD &amp;amp; AsciiDoc&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.jan0sch.de/post/deleting-old-zfs-snapshots/" target="_blank" rel="nofollow noopener"&gt;FreeBSD - Deleting old snapshots&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.moritz.systems/blog/full-multiprocess-support-in-lldb-server/" target="_blank" rel="nofollow noopener"&gt;Full multiprocess support in lldb-server&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://rubenerd.com/basic-fix-between-pf-tables-and-macros-on-freebsd/" target="_blank" rel="nofollow noopener"&gt;Basic fix between pf tables and macros on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Ben%20-%20Jail%20Question.md" target="_blank" rel="nofollow noopener"&gt;Ben - Jail Question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Malcolm%20-%20encryption.md" target="_blank" rel="nofollow noopener"&gt;Malcolm - encryption&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, filesystem, interview, ports, packages, jails, debug, debugging, lisp, nasa, deep space, zero dependencies, website, asciidoc, snapshot, multiprocess support, lldb, lldb-server, pf, pf tables, pf macros, firewall </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Debugging Lisp in Deep Space, 0 Dependency Websites with OpenBSD &amp; AsciiDoc, Deleting old snapshots on FreeBSD, Full multiprocess support in lldb-server, Basic fix between pf tables and macros, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://thenewstack.io/nasa-programmer-remembers-debugging-lisp-in-deep-space/" target="_blank" rel="nofollow noopener">NASA Programmer Remembers Debugging Lisp in Deep Space</a></h3>

<hr>

<h3><a href="https://blog.passwordclass.xyz/blogs/2022/06/0-dependency-websites-with-openbsd-asciidoc.html" target="_blank" rel="nofollow noopener">0 Dependency Websites with OpenBSD &amp; AsciiDoc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.jan0sch.de/post/deleting-old-zfs-snapshots/" target="_blank" rel="nofollow noopener">FreeBSD - Deleting old snapshots</a></h3>

<hr>

<h3><a href="https://www.moritz.systems/blog/full-multiprocess-support-in-lldb-server/" target="_blank" rel="nofollow noopener">Full multiprocess support in lldb-server</a></h3>

<hr>

<h3><a href="https://rubenerd.com/basic-fix-between-pf-tables-and-macros-on-freebsd/" target="_blank" rel="nofollow noopener">Basic fix between pf tables and macros on FreeBSD</a></h3>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Ben%20-%20Jail%20Question.md" target="_blank" rel="nofollow noopener">Ben - Jail Question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Malcolm%20-%20encryption.md" target="_blank" rel="nofollow noopener">Malcolm - encryption</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Debugging Lisp in Deep Space, 0 Dependency Websites with OpenBSD &amp; AsciiDoc, Deleting old snapshots on FreeBSD, Full multiprocess support in lldb-server, Basic fix between pf tables and macros, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://thenewstack.io/nasa-programmer-remembers-debugging-lisp-in-deep-space/" target="_blank" rel="nofollow noopener">NASA Programmer Remembers Debugging Lisp in Deep Space</a></h3>

<hr>

<h3><a href="https://blog.passwordclass.xyz/blogs/2022/06/0-dependency-websites-with-openbsd-asciidoc.html" target="_blank" rel="nofollow noopener">0 Dependency Websites with OpenBSD &amp; AsciiDoc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.jan0sch.de/post/deleting-old-zfs-snapshots/" target="_blank" rel="nofollow noopener">FreeBSD - Deleting old snapshots</a></h3>

<hr>

<h3><a href="https://www.moritz.systems/blog/full-multiprocess-support-in-lldb-server/" target="_blank" rel="nofollow noopener">Full multiprocess support in lldb-server</a></h3>

<hr>

<h3><a href="https://rubenerd.com/basic-fix-between-pf-tables-and-macros-on-freebsd/" target="_blank" rel="nofollow noopener">Basic fix between pf tables and macros on FreeBSD</a></h3>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Ben%20-%20Jail%20Question.md" target="_blank" rel="nofollow noopener">Ben - Jail Question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/464/feedback/Malcolm%20-%20encryption.md" target="_blank" rel="nofollow noopener">Malcolm - encryption</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>459: NetBSD Kernel benchmark</title>
  <link>https://www.bsdnow.tv/459</link>
  <guid isPermaLink="false">111c15bd-3906-4d2b-aaec-9d29bc06672a</guid>
  <pubDate>Thu, 16 Jun 2022 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/111c15bd-3906-4d2b-aaec-9d29bc06672a.mp3" length="32577552" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Evaluating FreeBSD CURRENT for Production Use, Time Machine-like Backups on OpenBSD, FreeBSD on the Graviton 3, Compiling the NetBSD kernel as a benchmark, Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022, Hardware Detection &amp; Diagnostics for New FreeBSD Users, and more</itunes:subtitle>
  <itunes:duration>54:05</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Evaluating FreeBSD CURRENT for Production Use, Time Machine-like Backups on OpenBSD, FreeBSD on the Graviton 3, Compiling the NetBSD kernel as a benchmark, Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022, Hardware Detection &amp;amp; Diagnostics for New FreeBSD Users, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://klarasystems.com/articles/evaluating-freebsd-current-for-production-use/" target="_blank" rel="nofollow noopener"&gt;Evaluating FreeBSD CURRENT for Production Use&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://xosc.org/timemachine.html" target="_blank" rel="nofollow noopener"&gt;Time Machine like Backups on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.daemonology.net/blog/2022-05-23-FreeBSD-Graviton-3.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD on the Graviton 3&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://blog.anotherhomepage.org/post/2022/05/25/Compiling-the-NetBSD-kernel-as-a-benchmark/" target="_blank" rel="nofollow noopener"&gt;Compiling the NetBSD kernel as a benchmark&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article;sid=20220607112236" target="_blank" rel="nofollow noopener"&gt;Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://forums.FreeBSD.org/threads/hardware-detection-diagnostics-for-new-freebsd-users-pcs.84596/" target="_blank" rel="nofollow noopener"&gt;Hardware Detection &amp;amp; Diagnostics for New FreeBSD Users &amp;amp; PCs&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;pre&gt;&lt;code&gt;• [NetBSD - Announcing Google Summer of Code 2022 projects](https://blog.netbsd.org/tnf/entry/announcing_google_summer_of_code3)
• [Welcome FreeBSD Google Summer of Code Participants](https://freebsdfoundation.org/blog/welcome-freebsd-google-summer-of-code-participants/)
• [Network from Scratch](https://www.networksfromscratch.com)
&lt;/code&gt;&lt;/pre&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, filesystem, interview, ports, packages, jails, production use, time machine, backups, backup, graviton 3, compiling, compiler benchmark, kernel compile, benchmark, network management, pf, packet filter, hardware detection, diagnostics</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Evaluating FreeBSD CURRENT for Production Use, Time Machine-like Backups on OpenBSD, FreeBSD on the Graviton 3, Compiling the NetBSD kernel as a benchmark, Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022, Hardware Detection &amp; Diagnostics for New FreeBSD Users, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/evaluating-freebsd-current-for-production-use/" target="_blank" rel="nofollow noopener">Evaluating FreeBSD CURRENT for Production Use</a></h3>

<hr>

<h3><a href="https://xosc.org/timemachine.html" target="_blank" rel="nofollow noopener">Time Machine like Backups on OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.daemonology.net/blog/2022-05-23-FreeBSD-Graviton-3.html" target="_blank" rel="nofollow noopener">FreeBSD on the Graviton 3</a></h3>

<hr>

<h3><a href="https://blog.anotherhomepage.org/post/2022/05/25/Compiling-the-NetBSD-kernel-as-a-benchmark/" target="_blank" rel="nofollow noopener">Compiling the NetBSD kernel as a benchmark</a></h3>

<hr>

<h3><a href="http://undeadly.org/cgi?action=article;sid=20220607112236" target="_blank" rel="nofollow noopener">Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/hardware-detection-diagnostics-for-new-freebsd-users-pcs.84596/" target="_blank" rel="nofollow noopener">Hardware Detection &amp; Diagnostics for New FreeBSD Users &amp; PCs</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [NetBSD - Announcing Google Summer of Code 2022 projects](https://blog.netbsd.org/tnf/entry/announcing_google_summer_of_code3)
• [Welcome FreeBSD Google Summer of Code Participants](https://freebsdfoundation.org/blog/welcome-freebsd-google-summer-of-code-participants/)
• [Network from Scratch](https://www.networksfromscratch.com)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Evaluating FreeBSD CURRENT for Production Use, Time Machine-like Backups on OpenBSD, FreeBSD on the Graviton 3, Compiling the NetBSD kernel as a benchmark, Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022, Hardware Detection &amp; Diagnostics for New FreeBSD Users, and more</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/evaluating-freebsd-current-for-production-use/" target="_blank" rel="nofollow noopener">Evaluating FreeBSD CURRENT for Production Use</a></h3>

<hr>

<h3><a href="https://xosc.org/timemachine.html" target="_blank" rel="nofollow noopener">Time Machine like Backups on OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.daemonology.net/blog/2022-05-23-FreeBSD-Graviton-3.html" target="_blank" rel="nofollow noopener">FreeBSD on the Graviton 3</a></h3>

<hr>

<h3><a href="https://blog.anotherhomepage.org/post/2022/05/25/Compiling-the-NetBSD-kernel-as-a-benchmark/" target="_blank" rel="nofollow noopener">Compiling the NetBSD kernel as a benchmark</a></h3>

<hr>

<h3><a href="http://undeadly.org/cgi?action=article;sid=20220607112236" target="_blank" rel="nofollow noopener">Network Management with the OpenBSD Packet Filter Toolset from BSDCan 2022</a></h3>

<hr>

<h3><a href="https://forums.FreeBSD.org/threads/hardware-detection-diagnostics-for-new-freebsd-users-pcs.84596/" target="_blank" rel="nofollow noopener">Hardware Detection &amp; Diagnostics for New FreeBSD Users &amp; PCs</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [NetBSD - Announcing Google Summer of Code 2022 projects](https://blog.netbsd.org/tnf/entry/announcing_google_summer_of_code3)
• [Welcome FreeBSD Google Summer of Code Participants](https://freebsdfoundation.org/blog/welcome-freebsd-google-summer-of-code-participants/)
• [Network from Scratch](https://www.networksfromscratch.com)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>436: Unix Standards Battle</title>
  <link>https://www.bsdnow.tv/436</link>
  <guid isPermaLink="false">5603c389-e7e5-4b55-ae6e-9ba425abfb2b</guid>
  <pubDate>Thu, 06 Jan 2022 03:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/5603c389-e7e5-4b55-ae6e-9ba425abfb2b.mp3" length="27911640" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>UNIX Wars, What every IT person needs to know about OpenBSD Part 3, FreeBSD 12.3 is here, TrueNAS 13 begins, what Unix pre-boot envs looked liked, run Unix on Microcontrollers with PDP-11 emulators and more.</itunes:subtitle>
  <itunes:duration>43:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;UNIX Wars, What every IT person needs to know about OpenBSD Part 3, FreeBSD 12.3 is here, TrueNAS 13 begins, what Unix pre-boot envs looked liked, run Unix on Microcontrollers with PDP-11 emulators and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://klarasystems.com/articles/unix-wars-the-battle-for-standards/" target="_blank" rel="nofollow noopener"&gt;UNIX Wars – The Battle for Standards&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://blog.apnic.net/2021/11/11/openbsd-part-3-that-packet-filter/" target="_blank" rel="nofollow noopener"&gt;What every IT person needs to know about OpenBSD Part 3: That packet filter&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/12.3R/relnotes/" target="_blank" rel="nofollow noopener"&gt;FreeBSD 12.3-RELEASE Release Notes&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.ixsystems.com/blog/truenas-12-0-u7-is-released-truenas-13-0-begins/" target="_blank" rel="nofollow noopener"&gt;TrueNAS 12.0-U7 is Released &amp;amp; TrueNAS 13.0 Begins&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://utcc.utoronto.ca/%7Ecks/space/blog/unix/UnixPreBootEnvironments" target="_blank" rel="nofollow noopener"&gt;A bit on what Unix system pre-boot environments used to look like&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://hackaday.com/2021/11/19/run-unix-on-microcontrollers-with-pdp-11-emulator/" target="_blank" rel="nofollow noopener"&gt;RUN UNIX ON MICROCONTROLLERS WITH PDP-11 EMULATOR&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;pre&gt;&lt;code&gt;• [BSDCan 2022 is a go.](https://www.bsdcan.org/2022/)
&lt;/code&gt;&lt;/pre&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, ports, packages, wars, standards, battle, pf, packet filter, FreeBSD 12.3, truenas 13, pre-boot environment, microcontroller, pdp-11, emulator</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>UNIX Wars, What every IT person needs to know about OpenBSD Part 3, FreeBSD 12.3 is here, TrueNAS 13 begins, what Unix pre-boot envs looked liked, run Unix on Microcontrollers with PDP-11 emulators and more.</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/unix-wars-the-battle-for-standards/" target="_blank" rel="nofollow noopener">UNIX Wars – The Battle for Standards</a></h3>

<hr>

<h3><a href="https://blog.apnic.net/2021/11/11/openbsd-part-3-that-packet-filter/" target="_blank" rel="nofollow noopener">What every IT person needs to know about OpenBSD Part 3: That packet filter</a></h3>

<hr>

<h3><a href="https://www.freebsd.org/releases/12.3R/relnotes/" target="_blank" rel="nofollow noopener">FreeBSD 12.3-RELEASE Release Notes</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.ixsystems.com/blog/truenas-12-0-u7-is-released-truenas-13-0-begins/" target="_blank" rel="nofollow noopener">TrueNAS 12.0-U7 is Released &amp; TrueNAS 13.0 Begins</a></h3>

<hr>

<h3><a href="https://utcc.utoronto.ca/%7Ecks/space/blog/unix/UnixPreBootEnvironments" target="_blank" rel="nofollow noopener">A bit on what Unix system pre-boot environments used to look like</a></h3>

<hr>

<h3><a href="https://hackaday.com/2021/11/19/run-unix-on-microcontrollers-with-pdp-11-emulator/" target="_blank" rel="nofollow noopener">RUN UNIX ON MICROCONTROLLERS WITH PDP-11 EMULATOR</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [BSDCan 2022 is a go.](https://www.bsdcan.org/2022/)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li><p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p>

<hr></li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>UNIX Wars, What every IT person needs to know about OpenBSD Part 3, FreeBSD 12.3 is here, TrueNAS 13 begins, what Unix pre-boot envs looked liked, run Unix on Microcontrollers with PDP-11 emulators and more.</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" target="_blank" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<h3><a href="https://klarasystems.com/articles/unix-wars-the-battle-for-standards/" target="_blank" rel="nofollow noopener">UNIX Wars – The Battle for Standards</a></h3>

<hr>

<h3><a href="https://blog.apnic.net/2021/11/11/openbsd-part-3-that-packet-filter/" target="_blank" rel="nofollow noopener">What every IT person needs to know about OpenBSD Part 3: That packet filter</a></h3>

<hr>

<h3><a href="https://www.freebsd.org/releases/12.3R/relnotes/" target="_blank" rel="nofollow noopener">FreeBSD 12.3-RELEASE Release Notes</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.ixsystems.com/blog/truenas-12-0-u7-is-released-truenas-13-0-begins/" target="_blank" rel="nofollow noopener">TrueNAS 12.0-U7 is Released &amp; TrueNAS 13.0 Begins</a></h3>

<hr>

<h3><a href="https://utcc.utoronto.ca/%7Ecks/space/blog/unix/UnixPreBootEnvironments" target="_blank" rel="nofollow noopener">A bit on what Unix system pre-boot environments used to look like</a></h3>

<hr>

<h3><a href="https://hackaday.com/2021/11/19/run-unix-on-microcontrollers-with-pdp-11-emulator/" target="_blank" rel="nofollow noopener">RUN UNIX ON MICROCONTROLLERS WITH PDP-11 EMULATOR</a></h3>

<hr>

<h2>Beastie Bits</h2>

<pre><code>• [BSDCan 2022 is a go.](https://www.bsdcan.org/2022/)
</code></pre>

<hr>

<h3>Tarsnap</h3>

<ul>
<li><p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p></li>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></p>

<hr></li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>407: The jail Detail</title>
  <link>https://www.bsdnow.tv/407</link>
  <guid isPermaLink="false">ffb08bc6-ffde-4b63-bd68-9f70872557ef</guid>
  <pubDate>Thu, 17 Jun 2021 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/ffb08bc6-ffde-4b63-bd68-9f70872557ef.mp3" length="27481848" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Confining the omnipotent root, Jails with ZFS and PF on DigitalOcean, NomadBSD 130R is out, KDE Plasma Wayland on FreeBSD, Firefox under FreeBSD with Privacy, Using NetBSD’s pkgsrc everywhere, and more.</itunes:subtitle>
  <itunes:duration>45:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Confining the omnipotent root, Jails with ZFS and PF on DigitalOcean, NomadBSD 130R is out, KDE Plasma Wayland on FreeBSD, Firefox under FreeBSD with Privacy, Using NetBSD’s pkgsrc everywhere, and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://phk.freebsd.dk/pubs/sane2000-jail.pdf" target="_blank" rel="nofollow noopener"&gt;Jails: Confining the omnipotent root&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A dramatic reading of portions of the paper: &lt;a href="https://paperswelove.org/2016/video/bryan-cantrill-jails-and-solaris-zones/" target="_blank" rel="nofollow noopener"&gt;Papers We Love: FreeBSD Jails and Solaris Zones&lt;/a&gt;
***
### 
&lt;a href="https://medium.com/chris-opperwall/using-jails-with-zfs-and-pf-on-digitalocean-b25b1da82e20" target="_blank" rel="nofollow noopener"&gt;Using Jails with ZFS and PF on DigitalOcean&lt;/a&gt;
***
## News Roundup
### &lt;a href="https://www.itsfoss.net/nomadbsd-130r-is-now-available-to-download-based-on-freebsd-13-0/" target="_blank" rel="nofollow noopener"&gt;NomadBSD 130R is out&lt;/a&gt;
***
### &lt;a href="https://euroquis.nl//kde/2021/05/09/wayland.html" target="_blank" rel="nofollow noopener"&gt;KDE Plasma Wayland - a week in FreeBSD&lt;/a&gt;
***
### &lt;a href="https://danschmid.de/en/blog/install-firefox-under-freebsd-and-set-it-up-with-privacy" target="_blank" rel="nofollow noopener"&gt;Install Firefox under FreeBSD and Set it Up with Privacy&lt;/a&gt;
***
&lt;a href="https://rubenerd.com/using-netbsds-pkgsrc-everywhere-i-can/" target="_blank" rel="nofollow noopener"&gt;Using NetBSD’s pkgsrc everywhere I can&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Malcolm%20-%20restoring%20a%20single%20file" target="_blank" rel="nofollow noopener"&gt;Malcolm - restoring a single file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Nathan%20-%20wireless%20support" target="_blank" rel="nofollow noopener"&gt;Nathan - wireless support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/bluefire%20-%20zfs%20special%20vdev" target="_blank" rel="nofollow noopener"&gt;bluefire - zfs special vdev&lt;/a&gt;
Push to next show with Allan&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, ports, packages, jail, root, pf, digitalocean, nomadbsd, kde plasma, wayland, firefox, privacy, pkgsrc </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Confining the omnipotent root, Jails with ZFS and PF on DigitalOcean, NomadBSD 130R is out, KDE Plasma Wayland on FreeBSD, Firefox under FreeBSD with Privacy, Using NetBSD’s pkgsrc everywhere, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="http://phk.freebsd.dk/pubs/sane2000-jail.pdf" target="_blank" rel="nofollow noopener">Jails: Confining the omnipotent root</a></h3>

<ul>
<li>A dramatic reading of portions of the paper: <a href="https://paperswelove.org/2016/video/bryan-cantrill-jails-and-solaris-zones/" target="_blank" rel="nofollow noopener">Papers We Love: FreeBSD Jails and Solaris Zones</a>
***
### 
<a href="https://medium.com/chris-opperwall/using-jails-with-zfs-and-pf-on-digitalocean-b25b1da82e20" target="_blank" rel="nofollow noopener">Using Jails with ZFS and PF on DigitalOcean</a>
***
## News Roundup
### <a href="https://www.itsfoss.net/nomadbsd-130r-is-now-available-to-download-based-on-freebsd-13-0/" target="_blank" rel="nofollow noopener">NomadBSD 130R is out</a>
***
### <a href="https://euroquis.nl//kde/2021/05/09/wayland.html" target="_blank" rel="nofollow noopener">KDE Plasma Wayland - a week in FreeBSD</a>
***
### <a href="https://danschmid.de/en/blog/install-firefox-under-freebsd-and-set-it-up-with-privacy" target="_blank" rel="nofollow noopener">Install Firefox under FreeBSD and Set it Up with Privacy</a>
***
<a href="https://rubenerd.com/using-netbsds-pkgsrc-everywhere-i-can/" target="_blank" rel="nofollow noopener">Using NetBSD’s pkgsrc everywhere I can</a>
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Malcolm%20-%20restoring%20a%20single%20file" target="_blank" rel="nofollow noopener">Malcolm - restoring a single file</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Nathan%20-%20wireless%20support" target="_blank" rel="nofollow noopener">Nathan - wireless support</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/bluefire%20-%20zfs%20special%20vdev" target="_blank" rel="nofollow noopener">bluefire - zfs special vdev</a>
Push to next show with Allan</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Confining the omnipotent root, Jails with ZFS and PF on DigitalOcean, NomadBSD 130R is out, KDE Plasma Wayland on FreeBSD, Firefox under FreeBSD with Privacy, Using NetBSD’s pkgsrc everywhere, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="http://phk.freebsd.dk/pubs/sane2000-jail.pdf" target="_blank" rel="nofollow noopener">Jails: Confining the omnipotent root</a></h3>

<ul>
<li>A dramatic reading of portions of the paper: <a href="https://paperswelove.org/2016/video/bryan-cantrill-jails-and-solaris-zones/" target="_blank" rel="nofollow noopener">Papers We Love: FreeBSD Jails and Solaris Zones</a>
***
### 
<a href="https://medium.com/chris-opperwall/using-jails-with-zfs-and-pf-on-digitalocean-b25b1da82e20" target="_blank" rel="nofollow noopener">Using Jails with ZFS and PF on DigitalOcean</a>
***
## News Roundup
### <a href="https://www.itsfoss.net/nomadbsd-130r-is-now-available-to-download-based-on-freebsd-13-0/" target="_blank" rel="nofollow noopener">NomadBSD 130R is out</a>
***
### <a href="https://euroquis.nl//kde/2021/05/09/wayland.html" target="_blank" rel="nofollow noopener">KDE Plasma Wayland - a week in FreeBSD</a>
***
### <a href="https://danschmid.de/en/blog/install-firefox-under-freebsd-and-set-it-up-with-privacy" target="_blank" rel="nofollow noopener">Install Firefox under FreeBSD and Set it Up with Privacy</a>
***
<a href="https://rubenerd.com/using-netbsds-pkgsrc-everywhere-i-can/" target="_blank" rel="nofollow noopener">Using NetBSD’s pkgsrc everywhere I can</a>
***</li>
</ul>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Malcolm%20-%20restoring%20a%20single%20file" target="_blank" rel="nofollow noopener">Malcolm - restoring a single file</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/Nathan%20-%20wireless%20support" target="_blank" rel="nofollow noopener">Nathan - wireless support</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/407/feedback/bluefire%20-%20zfs%20special%20vdev" target="_blank" rel="nofollow noopener">bluefire - zfs special vdev</a>
Push to next show with Allan</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>360: Full circle</title>
  <link>https://www.bsdnow.tv/360</link>
  <guid isPermaLink="false">69d88af7-54da-4612-9fc2-84ffae001c46</guid>
  <pubDate>Thu, 23 Jul 2020 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/69d88af7-54da-4612-9fc2-84ffae001c46.mp3" length="42925160" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Chasing a bad commit, New FreeBSD Core Team elected, Getting Started with NetBSD on the Pinebook Pro, FreeBSD on the Intel 10th Gen i3 NUC, pf table size check and change, and more.</itunes:subtitle>
  <itunes:duration>42:27</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Chasing a bad commit, New FreeBSD Core Team elected, Getting Started with NetBSD on the Pinebook Pro, FreeBSD on the Intel 10th Gen i3 NUC, pf table size check and change, and more.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://vishaltelangre.com/chasing-a-bad-commit/" target="_blank" rel="nofollow noopener"&gt;Chasing a bad commit&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;While working on a big project where multiple teams merge their feature branches frequently into a release Git branch, developers often run into situations where they find that some of their work have been either removed, modified or affected by someone else's work accidentally. It can happen in smaller teams as well. Two features could have been working perfectly fine until they got merged together and broke something. That's a highly possible case. There are many other cases which could cause such hard to understand and subtle bugs which even continuous integration (CI) systems running the entire test suite of our projects couldn't catch.&lt;br&gt;
We are not going to discuss how such subtle bugs can get into our release branch because that's just a wild territory out there. Instead, we can definitely discuss about how to find a commit that deviated from an expected outcome of a certain feature. The deviation could be any behaviour of our code that we can measure distinctively — either good or bad in general.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdnews.com/2020/07/14/new-freebsd-core-team-elected/" target="_blank" rel="nofollow noopener"&gt;New FreeBSD Core Team Elected&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;The FreeBSD Project is pleased to announce the completion of the 2020 Core Team election. Active committers to the project have elected your Eleventh FreeBSD Core Team.!&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Baptiste Daroussin (bapt)&lt;/li&gt;
&lt;li&gt;Ed Maste (emaste)&lt;/li&gt;
&lt;li&gt;George V. Neville-Neil (gnn)&lt;/li&gt;
&lt;li&gt;Hiroki Sato (hrs)&lt;/li&gt;
&lt;li&gt;Kyle Evans (kevans)&lt;/li&gt;
&lt;li&gt;Mark Johnston (markj)&lt;/li&gt;
&lt;li&gt;Scott Long (scottl)&lt;/li&gt;
&lt;li&gt;Sean Chittenden (seanc)&lt;/li&gt;
&lt;li&gt;Warner Losh (imp)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://bentsukun.ch/posts/pinebook-pro-netbsd/" target="_blank" rel="nofollow noopener"&gt;Getting Started with NetBSD on the Pinebook Pro&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;If you buy a Pinebook Pro now, it comes with Manjaro Linux on the internal eMMC storage. Let’s install NetBSD instead!&lt;br&gt;
The easiest way to get started is to buy a decent micro-SD card (what sort of markings it should have is a science of its own, by the way) and install NetBSD on that. On a warm boot (i.e. when rebooting a running system), the micro-SD card has priority compared to the eMMC, so the system will boot from there.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A FreeBSD developer has borrowed some of the NetBSD code to get audio working on RockPro64 and Pinebook Pro: &lt;a href="https://twitter.com/kernelnomicon/status/1282790609778905088" target="_blank" rel="nofollow noopener"&gt;https://twitter.com/kernelnomicon/status/1282790609778905088&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;h3&gt;&lt;a href="https://adventurist.me/posts/00300" target="_blank" rel="nofollow noopener"&gt;FreeBSD on the Intel 10th Gen i3 NUC&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;I have ended up with some 10th Gen i3 NUC's (NUC10i3FNH to be specific) to put to work in my testbed. These are quite new devices, the build date on the boxes is 13APR2020. Before I figure out what their true role is (one of them might have to run linux) I need to install FreeBSD -CURRENT and see how performance and hardware support is.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.dragonflydigest.com/2020/06/29/24698.html" target="_blank" rel="nofollow noopener"&gt;pf table size check and change&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Did you know there’s a default size limit to pf’s state table?  I did not, but it makes sense that there is one.  If for some reason you bump into this limit (difficult for home use, I’d think), &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2020-June/381261.html" target="_blank" rel="nofollow noopener"&gt;here’s how you change it&lt;/a&gt;&lt;br&gt;
There is a table-entries limit specified, you can see current settings with&lt;br&gt;
'pfctl -s all'.  You can adjust the limits in the /etc/pf.conf file&lt;br&gt;
containing the rules with a line like this near the top:&lt;br&gt;
&lt;code&gt;set limit table-entries 100000&lt;/code&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;In the original mail thread, there is mention of the FreeBSD sysctl net.pf.request_maxcount, which controls the maximum number of entries that can be sent as a single ioctl(). This allows the user to adjust the memory limit for how big of a list the kernel is willing to allocate memory for.
***&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://callfortesting.org/tmux/" target="_blank" rel="nofollow noopener"&gt;tmux and bhyve&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/thefreebsdfoundation.freebsd-12_1" target="_blank" rel="nofollow noopener"&gt;Azure and FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=bvkmnK6-qao&amp;amp;feature=youtu.be" target="_blank" rel="nofollow noopener"&gt;Groff Tutorial&lt;/a&gt;
***
###Tarsnap&lt;/li&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
&lt;a href="https://mwl.io/nonfiction/tools#tarsnap" target="_blank" rel="nofollow noopener"&gt;Tarsnap Mastery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Chris%20-%20zfs%20question.md" target="_blank" rel="nofollow noopener"&gt;Chris - ZFS Question&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Patrick%20-%20Tarsnap.md" target="_blank" rel="nofollow noopener"&gt;Patrick - Tarsnap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/pin%20-%20pkgsrc.md" target="_blank" rel="nofollow noopener"&gt;Pin - pkgsrc&lt;/a&gt;
***&lt;/li&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, os, berkeley, software, distribution, zfs, interview, commit, core team, freebsd core team, election, elected, pinebook, pinebook pro, i3, Intel, Intel i3, i3 NUC, pf, packet filter, table size, table size check</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Chasing a bad commit, New FreeBSD Core Team elected, Getting Started with NetBSD on the Pinebook Pro, FreeBSD on the Intel 10th Gen i3 NUC, pf table size check and change, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://vishaltelangre.com/chasing-a-bad-commit/" target="_blank" rel="nofollow noopener">Chasing a bad commit</a></h3>

<blockquote>
<p>While working on a big project where multiple teams merge their feature branches frequently into a release Git branch, developers often run into situations where they find that some of their work have been either removed, modified or affected by someone else's work accidentally. It can happen in smaller teams as well. Two features could have been working perfectly fine until they got merged together and broke something. That's a highly possible case. There are many other cases which could cause such hard to understand and subtle bugs which even continuous integration (CI) systems running the entire test suite of our projects couldn't catch.<br>
We are not going to discuss how such subtle bugs can get into our release branch because that's just a wild territory out there. Instead, we can definitely discuss about how to find a commit that deviated from an expected outcome of a certain feature. The deviation could be any behaviour of our code that we can measure distinctively — either good or bad in general.</p>
</blockquote>

<hr>

<h3><a href="https://www.freebsdnews.com/2020/07/14/new-freebsd-core-team-elected/" target="_blank" rel="nofollow noopener">New FreeBSD Core Team Elected</a></h3>

<blockquote>
<p>The FreeBSD Project is pleased to announce the completion of the 2020 Core Team election. Active committers to the project have elected your Eleventh FreeBSD Core Team.!</p>
</blockquote>

<ul>
<li>Baptiste Daroussin (bapt)</li>
<li>Ed Maste (emaste)</li>
<li>George V. Neville-Neil (gnn)</li>
<li>Hiroki Sato (hrs)</li>
<li>Kyle Evans (kevans)</li>
<li>Mark Johnston (markj)</li>
<li>Scott Long (scottl)</li>
<li>Sean Chittenden (seanc)</li>
<li>Warner Losh (imp)
***</li>
</ul>

<h2>News Roundup</h2>

<h3><a href="https://bentsukun.ch/posts/pinebook-pro-netbsd/" target="_blank" rel="nofollow noopener">Getting Started with NetBSD on the Pinebook Pro</a></h3>

<blockquote>
<p>If you buy a Pinebook Pro now, it comes with Manjaro Linux on the internal eMMC storage. Let’s install NetBSD instead!<br>
The easiest way to get started is to buy a decent micro-SD card (what sort of markings it should have is a science of its own, by the way) and install NetBSD on that. On a warm boot (i.e. when rebooting a running system), the micro-SD card has priority compared to the eMMC, so the system will boot from there.</p>

<ul>
<li>A FreeBSD developer has borrowed some of the NetBSD code to get audio working on RockPro64 and Pinebook Pro: <a href="https://twitter.com/kernelnomicon/status/1282790609778905088" target="_blank" rel="nofollow noopener">https://twitter.com/kernelnomicon/status/1282790609778905088</a>
***</li>
</ul>
</blockquote>

<h3><a href="https://adventurist.me/posts/00300" target="_blank" rel="nofollow noopener">FreeBSD on the Intel 10th Gen i3 NUC</a></h3>

<blockquote>
<p>I have ended up with some 10th Gen i3 NUC's (NUC10i3FNH to be specific) to put to work in my testbed. These are quite new devices, the build date on the boxes is 13APR2020. Before I figure out what their true role is (one of them might have to run linux) I need to install FreeBSD -CURRENT and see how performance and hardware support is.</p>
</blockquote>

<hr>

<h3><a href="https://www.dragonflydigest.com/2020/06/29/24698.html" target="_blank" rel="nofollow noopener">pf table size check and change</a></h3>

<blockquote>
<p>Did you know there’s a default size limit to pf’s state table?  I did not, but it makes sense that there is one.  If for some reason you bump into this limit (difficult for home use, I’d think), <a href="http://lists.dragonflybsd.org/pipermail/users/2020-June/381261.html" target="_blank" rel="nofollow noopener">here’s how you change it</a><br>
There is a table-entries limit specified, you can see current settings with<br>
'pfctl -s all'.  You can adjust the limits in the /etc/pf.conf file<br>
containing the rules with a line like this near the top:<br>
<code>set limit table-entries 100000</code></p>

<ul>
<li>In the original mail thread, there is mention of the FreeBSD sysctl net.pf.request_maxcount, which controls the maximum number of entries that can be sent as a single ioctl(). This allows the user to adjust the memory limit for how big of a list the kernel is willing to allocate memory for.
***</li>
</ul>
</blockquote>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://callfortesting.org/tmux/" target="_blank" rel="nofollow noopener">tmux and bhyve</a></li>
<li><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/thefreebsdfoundation.freebsd-12_1" target="_blank" rel="nofollow noopener">Azure and FreeBSD</a></li>
<li><a href="https://www.youtube.com/watch?v=bvkmnK6-qao&amp;feature=youtu.be" target="_blank" rel="nofollow noopener">Groff Tutorial</a>
***
###Tarsnap</li>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
<a href="https://mwl.io/nonfiction/tools#tarsnap" target="_blank" rel="nofollow noopener">Tarsnap Mastery</a></li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Chris%20-%20zfs%20question.md" target="_blank" rel="nofollow noopener">Chris - ZFS Question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Patrick%20-%20Tarsnap.md" target="_blank" rel="nofollow noopener">Patrick - Tarsnap</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/pin%20-%20pkgsrc.md" target="_blank" rel="nofollow noopener">Pin - pkgsrc</a>
***</li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Chasing a bad commit, New FreeBSD Core Team elected, Getting Started with NetBSD on the Pinebook Pro, FreeBSD on the Intel 10th Gen i3 NUC, pf table size check and change, and more.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Headlines</h2>

<h3><a href="https://vishaltelangre.com/chasing-a-bad-commit/" target="_blank" rel="nofollow noopener">Chasing a bad commit</a></h3>

<blockquote>
<p>While working on a big project where multiple teams merge their feature branches frequently into a release Git branch, developers often run into situations where they find that some of their work have been either removed, modified or affected by someone else's work accidentally. It can happen in smaller teams as well. Two features could have been working perfectly fine until they got merged together and broke something. That's a highly possible case. There are many other cases which could cause such hard to understand and subtle bugs which even continuous integration (CI) systems running the entire test suite of our projects couldn't catch.<br>
We are not going to discuss how such subtle bugs can get into our release branch because that's just a wild territory out there. Instead, we can definitely discuss about how to find a commit that deviated from an expected outcome of a certain feature. The deviation could be any behaviour of our code that we can measure distinctively — either good or bad in general.</p>
</blockquote>

<hr>

<h3><a href="https://www.freebsdnews.com/2020/07/14/new-freebsd-core-team-elected/" target="_blank" rel="nofollow noopener">New FreeBSD Core Team Elected</a></h3>

<blockquote>
<p>The FreeBSD Project is pleased to announce the completion of the 2020 Core Team election. Active committers to the project have elected your Eleventh FreeBSD Core Team.!</p>
</blockquote>

<ul>
<li>Baptiste Daroussin (bapt)</li>
<li>Ed Maste (emaste)</li>
<li>George V. Neville-Neil (gnn)</li>
<li>Hiroki Sato (hrs)</li>
<li>Kyle Evans (kevans)</li>
<li>Mark Johnston (markj)</li>
<li>Scott Long (scottl)</li>
<li>Sean Chittenden (seanc)</li>
<li>Warner Losh (imp)
***</li>
</ul>

<h2>News Roundup</h2>

<h3><a href="https://bentsukun.ch/posts/pinebook-pro-netbsd/" target="_blank" rel="nofollow noopener">Getting Started with NetBSD on the Pinebook Pro</a></h3>

<blockquote>
<p>If you buy a Pinebook Pro now, it comes with Manjaro Linux on the internal eMMC storage. Let’s install NetBSD instead!<br>
The easiest way to get started is to buy a decent micro-SD card (what sort of markings it should have is a science of its own, by the way) and install NetBSD on that. On a warm boot (i.e. when rebooting a running system), the micro-SD card has priority compared to the eMMC, so the system will boot from there.</p>

<ul>
<li>A FreeBSD developer has borrowed some of the NetBSD code to get audio working on RockPro64 and Pinebook Pro: <a href="https://twitter.com/kernelnomicon/status/1282790609778905088" target="_blank" rel="nofollow noopener">https://twitter.com/kernelnomicon/status/1282790609778905088</a>
***</li>
</ul>
</blockquote>

<h3><a href="https://adventurist.me/posts/00300" target="_blank" rel="nofollow noopener">FreeBSD on the Intel 10th Gen i3 NUC</a></h3>

<blockquote>
<p>I have ended up with some 10th Gen i3 NUC's (NUC10i3FNH to be specific) to put to work in my testbed. These are quite new devices, the build date on the boxes is 13APR2020. Before I figure out what their true role is (one of them might have to run linux) I need to install FreeBSD -CURRENT and see how performance and hardware support is.</p>
</blockquote>

<hr>

<h3><a href="https://www.dragonflydigest.com/2020/06/29/24698.html" target="_blank" rel="nofollow noopener">pf table size check and change</a></h3>

<blockquote>
<p>Did you know there’s a default size limit to pf’s state table?  I did not, but it makes sense that there is one.  If for some reason you bump into this limit (difficult for home use, I’d think), <a href="http://lists.dragonflybsd.org/pipermail/users/2020-June/381261.html" target="_blank" rel="nofollow noopener">here’s how you change it</a><br>
There is a table-entries limit specified, you can see current settings with<br>
'pfctl -s all'.  You can adjust the limits in the /etc/pf.conf file<br>
containing the rules with a line like this near the top:<br>
<code>set limit table-entries 100000</code></p>

<ul>
<li>In the original mail thread, there is mention of the FreeBSD sysctl net.pf.request_maxcount, which controls the maximum number of entries that can be sent as a single ioctl(). This allows the user to adjust the memory limit for how big of a list the kernel is willing to allocate memory for.
***</li>
</ul>
</blockquote>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://callfortesting.org/tmux/" target="_blank" rel="nofollow noopener">tmux and bhyve</a></li>
<li><a href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/thefreebsdfoundation.freebsd-12_1" target="_blank" rel="nofollow noopener">Azure and FreeBSD</a></li>
<li><a href="https://www.youtube.com/watch?v=bvkmnK6-qao&amp;feature=youtu.be" target="_blank" rel="nofollow noopener">Groff Tutorial</a>
***
###Tarsnap</li>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.
<a href="https://mwl.io/nonfiction/tools#tarsnap" target="_blank" rel="nofollow noopener">Tarsnap Mastery</a></li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Chris%20-%20zfs%20question.md" target="_blank" rel="nofollow noopener">Chris - ZFS Question</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/Patrick%20-%20Tarsnap.md" target="_blank" rel="nofollow noopener">Patrick - Tarsnap</a></li>
<li><a href="https://github.com/BSDNow/bsdnow.tv/blob/master/episodes/360/feedback/pin%20-%20pkgsrc.md" target="_blank" rel="nofollow noopener">Pin - pkgsrc</a>
***</li>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>343: FreeBSD, Corona: Fight!</title>
  <link>https://www.bsdnow.tv/343</link>
  <guid isPermaLink="false">1752e8c2-3d6e-40dc-8bd9-5c7654660b15</guid>
  <pubDate>Thu, 26 Mar 2020 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/1752e8c2-3d6e-40dc-8bd9-5c7654660b15.mp3" length="28131915" type="audio/mp3"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Fighting the Coronavirus with FreeBSD, Wireguard VPN Howto in OPNsense, NomadBSD 1.3.1 available, fresh GhostBSD 20.02, New FuryBSD XFCE and KDE images, pf-badhost 0.3 released, and more.</itunes:subtitle>
  <itunes:duration>39:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Fighting the Coronavirus with FreeBSD, Wireguard VPN Howto in OPNsense, NomadBSD 1.3.1 available, fresh GhostBSD 20.02, New FuryBSD XFCE and KDE images, pf-badhost 0.3 released, and more.&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.leidinger.net/blog/2020/03/19/fighting-the-coronavirus-with-freebsd-foldinghome/" target="_blank" rel="nofollow noopener"&gt;Fighting the Coronavirus with FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Here is a quick HOWTO for those who want to provide some FreeBSD based compute resources to help finding vaccines.&lt;/p&gt;

&lt;p&gt;UPDATE 2020-03-22: 0mp@ made a port out of this, it is in “biology/linux-foldingathome”.&lt;/p&gt;

&lt;p&gt;Per default it will now pick up some SARS-CoV‑2 (COVID-19) related folding tasks. There are some more config options (e.g. how much of the system resources are used). Please refer to the official Folding@Home site for more information about that. Be also aware that there is a big rise in compute resources donated to Folding@Home, so the pool of available work units may be empty from time to time, but they are working on adding more work units. Be patient.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://homenetworkguy.com/how-to/configure-wireguard-opnsense/" target="_blank" rel="nofollow noopener"&gt;How to configure the Wireguard VPN in OPNsense&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;WireGuard is a modern designed VPN that uses the latest cryptography for stronger security, is very lightweight, and is relatively easy to set up (mostly). I say ‘mostly’ because I found setting up WireGuard in OPNsense to be more difficult than I anticipated. The basic setup of the WireGuard VPN itself was as easy as the authors claim on their website, but I came across a few gotcha's. The gotcha's occur with functionality that is beyond the scope of the WireGuard protocol so I cannot fault them for that. My greatest struggle was configuring WireGuard to function similarly to my OpenVPN server. I want the ability to connect remotely to my home network from my iPhone or iPad, tunnel all traffic through the VPN, have access to certain devices and services on my network, and have the VPN devices use my home's Internet connection.&lt;/p&gt;

&lt;p&gt;WireGuard behaves more like a SSH server than a typical VPN server. With WireGuard, devices which have shared their cryptographic keys with each other are able to connect via an encrypted tunnel (like a SSH server configured to use keys instead of passwords). The devices that are connecting to one another are referred to as “peer” devices. When the peer device is an OPNsense router with WireGuard installed, for instance, it can be configured to allow access to various resources on your network. It becomes a tunnel into your network similar to OpenVPN (with the appropriate firewall rules enabled). I will refer to the WireGuard installation on OPNsense as the server rather than a “peer” to make it more clear which device I am configuring unless I am describing the user interface because that is the terminology used interchangeably by WireGuard.&lt;/p&gt;

&lt;p&gt;The documentation I found on WireGuard in OPNsense is straightforward and relatively easy to understand, but I had to wrestle with it for a little while to gain a better understanding on how it should be configured. I believe it was partially due to differing end goals – I was trying to achieve something a little different than the authors of other wiki/blog/forum posts. Piecing together various sources of information, I finally ended up with a configuration that met the goals stated above.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://nomadbsd.org/index.html#1.3.1" target="_blank" rel="nofollow noopener"&gt;NomadBSD 1.3.1&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;NomadBSD 1.3.1 has recently been made available. NomadBSD is a lightweight and portable FreeBSD distribution, designed to run on live on a USB flash drive, allowing you to plug, test, and play on different hardware. They have also started a forum as of yesterday, where you can ask questions and mingle with the NomadBSD community. Notable changes in 1.3.1 are base system upgraded to FreeBSD 12.1-p2. automatic network interface setup improved, image size increased to over 4GB, Thunderbird, Zeroconf, and some more listed below.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://ghostbsd.org/20.02_release_announcement" target="_blank" rel="nofollow noopener"&gt;GhostBSD 20.02&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;Eric Turgeon, main developer of GhostBSD, has announced version 20.02 of the FreeBSD based operating system. Notable changes are ZFS partition into the custom partition editor installer, allowing you to install alongside with Windows, Linux, or macOS. Other changes are force upgrade all packages on system upgrade, improved update station, and powerd by default for laptop battery performance.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.furybsd.org/new-furybsd-12-1-based-images-are-available-for-xfce-and-kde/" target="_blank" rel="nofollow noopener"&gt;New FuryBSD XFCE and KDE images&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;This new release is now based on FreeBSD 12.1 with the latest FreeBSD quarterly packages. This brings XFCE up to 4.14, and KDE up to 5.17. In addition to updates this new ISO mostly addresses community bugs, community enhancement requests, and community pull requests. Due to the overwhelming amount of reports with GitHub hosting all new releases are now being pushed to SourceForge only for the time being. Previous releases will still be kept for archive purposes.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h3&gt;&lt;a href="https://www.geoghegan.ca/pfbadhost.html" target="_blank" rel="nofollow noopener"&gt;pf-badhost 0.3 Released&lt;/a&gt;&lt;/h3&gt;

&lt;blockquote&gt;
&lt;p&gt;pf-badhost is a simple, easy to use badhost blocker that uses the power of the pf firewall to block many of the internet's biggest irritants. Annoyances such as SSH and SMTP bruteforcers are largely eliminated. Shodan scans and bots looking for webservers to abuse are stopped dead in their tracks. When used to filter outbound traffic, pf-badhost blocks many seedy, spooky malware containing and/or compromised webhosts.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;hr&gt;

&lt;h2&gt;Beastie Bits&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.dragonflydigest.com/2020/03/23/24324.html" target="_blank" rel="nofollow noopener"&gt;DragonFly i915 drm update&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.snailtext.com/posts/cshell-is-punk-rock.html" target="_blank" rel="nofollow noopener"&gt;CShell is punk rock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://minnie.tuhs.org/pipermail/tuhs/2020-March/020664.html" target="_blank" rel="nofollow noopener"&gt;The most surprising Unix programs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Master One - &lt;a href="http://dpaste.com/102HKF5#wrap" target="_blank" rel="nofollow noopener"&gt;Torn between OpenBSD and FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brad - &lt;a href="http://dpaste.com/1VXQA2Y#wrap" target="_blank" rel="nofollow noopener"&gt;Follow up to Linus ZFS story&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Filipe Carvalho - &lt;a href="http://dpaste.com/2H7S8YP" target="_blank" rel="nofollow noopener"&gt;Call for Portuguese BSD User Groups&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;


    &lt;source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0343.mp4" type="video/mp4"&gt;
    Your browser does not support the HTML5 video tag.
 
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, interview, corona, corona virus, covid-19, foldingathome, folding at home, wireguard, vpn, opnsense, nomadbsd, ghostbsd, furybsd, xfce, kde, pf, pf-badhost </itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Fighting the Coronavirus with FreeBSD, Wireguard VPN Howto in OPNsense, NomadBSD 1.3.1 available, fresh GhostBSD 20.02, New FuryBSD XFCE and KDE images, pf-badhost 0.3 released, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://www.leidinger.net/blog/2020/03/19/fighting-the-coronavirus-with-freebsd-foldinghome/" target="_blank" rel="nofollow noopener">Fighting the Coronavirus with FreeBSD</a></h3>

<blockquote>
<p>Here is a quick HOWTO for those who want to provide some FreeBSD based compute resources to help finding vaccines.</p>

<p>UPDATE 2020-03-22: 0mp@ made a port out of this, it is in “biology/linux-foldingathome”.</p>

<p>Per default it will now pick up some SARS-CoV‑2 (COVID-19) related folding tasks. There are some more config options (e.g. how much of the system resources are used). Please refer to the official Folding@Home site for more information about that. Be also aware that there is a big rise in compute resources donated to Folding@Home, so the pool of available work units may be empty from time to time, but they are working on adding more work units. Be patient.</p>
</blockquote>

<hr>

<h3><a href="https://homenetworkguy.com/how-to/configure-wireguard-opnsense/" target="_blank" rel="nofollow noopener">How to configure the Wireguard VPN in OPNsense</a></h3>

<blockquote>
<p>WireGuard is a modern designed VPN that uses the latest cryptography for stronger security, is very lightweight, and is relatively easy to set up (mostly). I say ‘mostly’ because I found setting up WireGuard in OPNsense to be more difficult than I anticipated. The basic setup of the WireGuard VPN itself was as easy as the authors claim on their website, but I came across a few gotcha's. The gotcha's occur with functionality that is beyond the scope of the WireGuard protocol so I cannot fault them for that. My greatest struggle was configuring WireGuard to function similarly to my OpenVPN server. I want the ability to connect remotely to my home network from my iPhone or iPad, tunnel all traffic through the VPN, have access to certain devices and services on my network, and have the VPN devices use my home's Internet connection.</p>

<p>WireGuard behaves more like a SSH server than a typical VPN server. With WireGuard, devices which have shared their cryptographic keys with each other are able to connect via an encrypted tunnel (like a SSH server configured to use keys instead of passwords). The devices that are connecting to one another are referred to as “peer” devices. When the peer device is an OPNsense router with WireGuard installed, for instance, it can be configured to allow access to various resources on your network. It becomes a tunnel into your network similar to OpenVPN (with the appropriate firewall rules enabled). I will refer to the WireGuard installation on OPNsense as the server rather than a “peer” to make it more clear which device I am configuring unless I am describing the user interface because that is the terminology used interchangeably by WireGuard.</p>

<p>The documentation I found on WireGuard in OPNsense is straightforward and relatively easy to understand, but I had to wrestle with it for a little while to gain a better understanding on how it should be configured. I believe it was partially due to differing end goals – I was trying to achieve something a little different than the authors of other wiki/blog/forum posts. Piecing together various sources of information, I finally ended up with a configuration that met the goals stated above.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://nomadbsd.org/index.html#1.3.1" target="_blank" rel="nofollow noopener">NomadBSD 1.3.1</a></h3>

<blockquote>
<p>NomadBSD 1.3.1 has recently been made available. NomadBSD is a lightweight and portable FreeBSD distribution, designed to run on live on a USB flash drive, allowing you to plug, test, and play on different hardware. They have also started a forum as of yesterday, where you can ask questions and mingle with the NomadBSD community. Notable changes in 1.3.1 are base system upgraded to FreeBSD 12.1-p2. automatic network interface setup improved, image size increased to over 4GB, Thunderbird, Zeroconf, and some more listed below.</p>
</blockquote>

<hr>

<h3><a href="https://ghostbsd.org/20.02_release_announcement" target="_blank" rel="nofollow noopener">GhostBSD 20.02</a></h3>

<blockquote>
<p>Eric Turgeon, main developer of GhostBSD, has announced version 20.02 of the FreeBSD based operating system. Notable changes are ZFS partition into the custom partition editor installer, allowing you to install alongside with Windows, Linux, or macOS. Other changes are force upgrade all packages on system upgrade, improved update station, and powerd by default for laptop battery performance.</p>
</blockquote>

<hr>

<h3><a href="https://www.furybsd.org/new-furybsd-12-1-based-images-are-available-for-xfce-and-kde/" target="_blank" rel="nofollow noopener">New FuryBSD XFCE and KDE images</a></h3>

<blockquote>
<p>This new release is now based on FreeBSD 12.1 with the latest FreeBSD quarterly packages. This brings XFCE up to 4.14, and KDE up to 5.17. In addition to updates this new ISO mostly addresses community bugs, community enhancement requests, and community pull requests. Due to the overwhelming amount of reports with GitHub hosting all new releases are now being pushed to SourceForge only for the time being. Previous releases will still be kept for archive purposes.</p>
</blockquote>

<hr>

<h3><a href="https://www.geoghegan.ca/pfbadhost.html" target="_blank" rel="nofollow noopener">pf-badhost 0.3 Released</a></h3>

<blockquote>
<p>pf-badhost is a simple, easy to use badhost blocker that uses the power of the pf firewall to block many of the internet's biggest irritants. Annoyances such as SSH and SMTP bruteforcers are largely eliminated. Shodan scans and bots looking for webservers to abuse are stopped dead in their tracks. When used to filter outbound traffic, pf-badhost blocks many seedy, spooky malware containing and/or compromised webhosts.</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.dragonflydigest.com/2020/03/23/24324.html" target="_blank" rel="nofollow noopener">DragonFly i915 drm update</a></li>
<li><a href="http://blog.snailtext.com/posts/cshell-is-punk-rock.html" target="_blank" rel="nofollow noopener">CShell is punk rock</a></li>
<li><a href="https://minnie.tuhs.org/pipermail/tuhs/2020-March/020664.html" target="_blank" rel="nofollow noopener">The most surprising Unix programs</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Master One - <a href="http://dpaste.com/102HKF5#wrap" target="_blank" rel="nofollow noopener">Torn between OpenBSD and FreeBSD</a></li>
<li>Brad - <a href="http://dpaste.com/1VXQA2Y#wrap" target="_blank" rel="nofollow noopener">Follow up to Linus ZFS story</a></li>
<li>Filipe Carvalho - <a href="http://dpaste.com/2H7S8YP" target="_blank" rel="nofollow noopener">Call for Portuguese BSD User Groups</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0343.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Fighting the Coronavirus with FreeBSD, Wireguard VPN Howto in OPNsense, NomadBSD 1.3.1 available, fresh GhostBSD 20.02, New FuryBSD XFCE and KDE images, pf-badhost 0.3 released, and more.</p>

<h2>Headlines</h2>

<h3><a href="https://www.leidinger.net/blog/2020/03/19/fighting-the-coronavirus-with-freebsd-foldinghome/" target="_blank" rel="nofollow noopener">Fighting the Coronavirus with FreeBSD</a></h3>

<blockquote>
<p>Here is a quick HOWTO for those who want to provide some FreeBSD based compute resources to help finding vaccines.</p>

<p>UPDATE 2020-03-22: 0mp@ made a port out of this, it is in “biology/linux-foldingathome”.</p>

<p>Per default it will now pick up some SARS-CoV‑2 (COVID-19) related folding tasks. There are some more config options (e.g. how much of the system resources are used). Please refer to the official Folding@Home site for more information about that. Be also aware that there is a big rise in compute resources donated to Folding@Home, so the pool of available work units may be empty from time to time, but they are working on adding more work units. Be patient.</p>
</blockquote>

<hr>

<h3><a href="https://homenetworkguy.com/how-to/configure-wireguard-opnsense/" target="_blank" rel="nofollow noopener">How to configure the Wireguard VPN in OPNsense</a></h3>

<blockquote>
<p>WireGuard is a modern designed VPN that uses the latest cryptography for stronger security, is very lightweight, and is relatively easy to set up (mostly). I say ‘mostly’ because I found setting up WireGuard in OPNsense to be more difficult than I anticipated. The basic setup of the WireGuard VPN itself was as easy as the authors claim on their website, but I came across a few gotcha's. The gotcha's occur with functionality that is beyond the scope of the WireGuard protocol so I cannot fault them for that. My greatest struggle was configuring WireGuard to function similarly to my OpenVPN server. I want the ability to connect remotely to my home network from my iPhone or iPad, tunnel all traffic through the VPN, have access to certain devices and services on my network, and have the VPN devices use my home's Internet connection.</p>

<p>WireGuard behaves more like a SSH server than a typical VPN server. With WireGuard, devices which have shared their cryptographic keys with each other are able to connect via an encrypted tunnel (like a SSH server configured to use keys instead of passwords). The devices that are connecting to one another are referred to as “peer” devices. When the peer device is an OPNsense router with WireGuard installed, for instance, it can be configured to allow access to various resources on your network. It becomes a tunnel into your network similar to OpenVPN (with the appropriate firewall rules enabled). I will refer to the WireGuard installation on OPNsense as the server rather than a “peer” to make it more clear which device I am configuring unless I am describing the user interface because that is the terminology used interchangeably by WireGuard.</p>

<p>The documentation I found on WireGuard in OPNsense is straightforward and relatively easy to understand, but I had to wrestle with it for a little while to gain a better understanding on how it should be configured. I believe it was partially due to differing end goals – I was trying to achieve something a little different than the authors of other wiki/blog/forum posts. Piecing together various sources of information, I finally ended up with a configuration that met the goals stated above.</p>
</blockquote>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://nomadbsd.org/index.html#1.3.1" target="_blank" rel="nofollow noopener">NomadBSD 1.3.1</a></h3>

<blockquote>
<p>NomadBSD 1.3.1 has recently been made available. NomadBSD is a lightweight and portable FreeBSD distribution, designed to run on live on a USB flash drive, allowing you to plug, test, and play on different hardware. They have also started a forum as of yesterday, where you can ask questions and mingle with the NomadBSD community. Notable changes in 1.3.1 are base system upgraded to FreeBSD 12.1-p2. automatic network interface setup improved, image size increased to over 4GB, Thunderbird, Zeroconf, and some more listed below.</p>
</blockquote>

<hr>

<h3><a href="https://ghostbsd.org/20.02_release_announcement" target="_blank" rel="nofollow noopener">GhostBSD 20.02</a></h3>

<blockquote>
<p>Eric Turgeon, main developer of GhostBSD, has announced version 20.02 of the FreeBSD based operating system. Notable changes are ZFS partition into the custom partition editor installer, allowing you to install alongside with Windows, Linux, or macOS. Other changes are force upgrade all packages on system upgrade, improved update station, and powerd by default for laptop battery performance.</p>
</blockquote>

<hr>

<h3><a href="https://www.furybsd.org/new-furybsd-12-1-based-images-are-available-for-xfce-and-kde/" target="_blank" rel="nofollow noopener">New FuryBSD XFCE and KDE images</a></h3>

<blockquote>
<p>This new release is now based on FreeBSD 12.1 with the latest FreeBSD quarterly packages. This brings XFCE up to 4.14, and KDE up to 5.17. In addition to updates this new ISO mostly addresses community bugs, community enhancement requests, and community pull requests. Due to the overwhelming amount of reports with GitHub hosting all new releases are now being pushed to SourceForge only for the time being. Previous releases will still be kept for archive purposes.</p>
</blockquote>

<hr>

<h3><a href="https://www.geoghegan.ca/pfbadhost.html" target="_blank" rel="nofollow noopener">pf-badhost 0.3 Released</a></h3>

<blockquote>
<p>pf-badhost is a simple, easy to use badhost blocker that uses the power of the pf firewall to block many of the internet's biggest irritants. Annoyances such as SSH and SMTP bruteforcers are largely eliminated. Shodan scans and bots looking for webservers to abuse are stopped dead in their tracks. When used to filter outbound traffic, pf-badhost blocks many seedy, spooky malware containing and/or compromised webhosts.</p>
</blockquote>

<hr>

<h2>Beastie Bits</h2>

<ul>
<li><a href="https://www.dragonflydigest.com/2020/03/23/24324.html" target="_blank" rel="nofollow noopener">DragonFly i915 drm update</a></li>
<li><a href="http://blog.snailtext.com/posts/cshell-is-punk-rock.html" target="_blank" rel="nofollow noopener">CShell is punk rock</a></li>
<li><a href="https://minnie.tuhs.org/pipermail/tuhs/2020-March/020664.html" target="_blank" rel="nofollow noopener">The most surprising Unix programs</a></li>
</ul>

<hr>

<h2>Feedback/Questions</h2>

<ul>
<li>Master One - <a href="http://dpaste.com/102HKF5#wrap" target="_blank" rel="nofollow noopener">Torn between OpenBSD and FreeBSD</a></li>
<li>Brad - <a href="http://dpaste.com/1VXQA2Y#wrap" target="_blank" rel="nofollow noopener">Follow up to Linus ZFS story</a></li>
<li>Filipe Carvalho - <a href="http://dpaste.com/2H7S8YP" target="_blank" rel="nofollow noopener">Call for Portuguese BSD User Groups</a></li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a></li>
</ul>

<hr>


    <source src="http://201406.jb-dl.cdn.scaleengine.net/bsdnow/2019/bsd-0343.mp4" type="video/mp4">
    Your browser does not support the HTML5 video tag.
]]>
  </itunes:summary>
</item>
<item>
  <title>101: I'll Fix Everything</title>
  <link>https://www.bsdnow.tv/101</link>
  <guid isPermaLink="false">b0fef23d-9748-4e29-9419-eb23bd948f84</guid>
  <pubDate>Wed, 05 Aug 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b0fef23d-9748-4e29-9419-eb23bd948f84.mp3" length="67071892" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be talking with Adrian Chadd about an infamous reddit thread he made. With a title like "what would you like to see in FreeBSD?" and hundreds of responses, well, we've got a lot to cover...</itunes:subtitle>
  <itunes:duration>1:33:09</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be talking with Adrian Chadd about an infamous reddit thread he made. With a title like "what would you like to see in FreeBSD?" and hundreds of responses, well, we've got a lot to cover...&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/from-distribution-to-project" target="_blank" rel="nofollow noopener"&gt;OpenBSD, from distribution to project&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Ted Unangst has yet another interesting blog post up, this time covering a bit of BSD history and some different phases OpenBSD has been through&lt;/li&gt;
&lt;li&gt;It's the third part of his &lt;a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener"&gt;ongoing&lt;/a&gt; &lt;a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener"&gt;series&lt;/a&gt; of posts about OpenBSD removing large bits of code in favor of smaller replacements&lt;/li&gt;
&lt;li&gt;In the earliest days, OpenBSD collected and maintained code from lots of other projects (Apache, lynx, perl..)&lt;/li&gt;
&lt;li&gt;After importing new updates every release cycle, they eventually hit a transitional phase - things were updated, but nothing new was imported&lt;/li&gt;
&lt;li&gt;When the need arose, instead of importing a known tool to do the job, homemade replacements (OpenNTPD, OpenBGPD, etc) were slowly developed&lt;/li&gt;
&lt;li&gt;In more recent times, a lot of the imported code has been completely removed in favor of the homegrown daemons&lt;/li&gt;
&lt;li&gt;More discussion &lt;a href="https://news.ycombinator.com/item?id=9980373" target="_blank" rel="nofollow noopener"&gt;on HN&lt;/a&gt; &lt;a href="https://www.reddit.com/r/openbsd/comments/3f9o19/from_distribution_to_project/" target="_blank" rel="nofollow noopener"&gt;and reddit&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/hughobrien/zfs-remote-mirror" target="_blank" rel="nofollow noopener"&gt;Remote ZFS mirrors, the hard way&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Backups to "the cloud" have become a hot topic in recent years, but most of them require trade-offs between convenience and security&lt;/li&gt;
&lt;li&gt;You have to trust (some of) the providers not to snoop on your data, but even the ones who allow you to locally encrypt files aren't without some compromise&lt;/li&gt;
&lt;li&gt;As the author puts it: "We don't need live synchronisation, cloud scaling, SLAs, NSAs, terms of service, lock-ins, buy-outs, up-sells, shut-downs, DoSs, fail whales, pay-us-or-we'll-deletes, or any of the noise that comes with using someone else's infrastructure."&lt;/li&gt;
&lt;li&gt;This guide walks you through setting up a FreeBSD server with ZFS to do secure offsite backups yourself&lt;/li&gt;
&lt;li&gt;The end result is an automatic system for incremental backups that's backed (pun intended) by ZFS&lt;/li&gt;
&lt;li&gt;If you're serious about keeping your important data safe and sound, you'll want to give this one a read - lots of detailed instructions
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419064.html" target="_blank" rel="nofollow noopener"&gt;Various DragonFlyBSD updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The DragonFly guys have been quite busy this week, making an assortment of improvements throughout the tree&lt;/li&gt;
&lt;li&gt;Intel ValleyView graphics support was finally committed to the main repository&lt;/li&gt;
&lt;li&gt;While on the topic of graphics, they've also issued &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-July/207923.html" target="_blank" rel="nofollow noopener"&gt;a call for testing&lt;/a&gt; for a DRM update (matching Linux 3.16's and including some more Broadwell fixes)&lt;/li&gt;
&lt;li&gt;Their base GCC compiler is also now &lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419045.html" target="_blank" rel="nofollow noopener"&gt;upgraded to version 5.2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;If your hardware supports it, DragonFly will now &lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419070.html" target="_blank" rel="nofollow noopener"&gt;use an accelerated console by default&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://youtu.be/mOv62lBdlXU?t=292" target="_blank" rel="nofollow noopener"&gt;QuakeCon runs on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/QuakeCon" target="_blank" rel="nofollow noopener"&gt;QuakeCon&lt;/a&gt;, everyone's favorite event full of rocket launchers, recently gave a mini-tour of their network setup&lt;/li&gt;
&lt;li&gt;For such a crazy network, unsurprisingly, they seem to be big fans of OpenBSD and PF&lt;/li&gt;
&lt;li&gt;In this video interview, one of the sysadmins discusses why he chose OpenBSD, what he likes about it, different packet queueing systems, how their firewalls and servers are laid out and much more&lt;/li&gt;
&lt;li&gt;He also talks about why they went with vanilla PF, writing their ruleset from the ground up rather than relying on a prebuilt solution&lt;/li&gt;
&lt;li&gt;There's also some general networking talk about nginx, reverse proxies, caching, fiber links and all that good stuff&lt;/li&gt;
&lt;li&gt;Follow-up questions can be asked in &lt;a href="https://www.reddit.com/r/BSD/comments/3f43fh/bsd_runs_quakecon/" target="_blank" rel="nofollow noopener"&gt;this reddit thread&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The host doesn't seem to be that familiar with the topics at hand, mentioning "OpenPF" multiple times among other things, so our listeners should get a kick out of it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Adrian Chadd - &lt;a href="mailto:adrian@freebsd.org" target="_blank" rel="nofollow noopener"&gt;adrian@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/erikarn" target="_blank" rel="nofollow noopener"&gt;@erikarn&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Rethinking &lt;a href="https://www.reddit.com/r/freebsd/comments/3d80vt" target="_blank" rel="nofollow noopener"&gt;ways to improve FreeBSD&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150804161939" target="_blank" rel="nofollow noopener"&gt;CII contributes to OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you recall back to &lt;a href="http://www.bsdnow.tv/episodes/2015_02_25-from_the_foundation_2" target="_blank" rel="nofollow noopener"&gt;when we talked to the OpenBSD foundation&lt;/a&gt;, one of the things Ken mentioned was the &lt;a href="https://www.coreinfrastructure.org" target="_blank" rel="nofollow noopener"&gt;Core Infrastructure Initiative&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://www.coreinfrastructure.org/faq" target="_blank" rel="nofollow noopener"&gt;a nutshell&lt;/a&gt;, it's an organization of security experts that helps facilitate (with money, in most cases) the advancement of the more critical open source components of the internet&lt;/li&gt;
&lt;li&gt;The group is organized by the Linux foundation, and gets its multi-million dollar backing from various big companies in the technology space (and donations from volunteers) &lt;/li&gt;
&lt;li&gt;To ensure that OpenBSD and its related projects (OpenSSH, LibreSSL and PF likely being the main ones here) remain healthy, they've just made a large donation to the foundation - this makes them &lt;a href="http://www.openbsdfoundation.org/contributors.html" target="_blank" rel="nofollow noopener"&gt;the first&lt;/a&gt; "platinum" level donor as well&lt;/li&gt;
&lt;li&gt;While the exact amount wasn't disclosed, it was somewhere between $50,000 and $100,000&lt;/li&gt;
&lt;li&gt;The donation comes less than a month after &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150708134520" target="_blank" rel="nofollow noopener"&gt;Microsoft's big donation&lt;/a&gt;, so it's good to see these large organizations helping out important open source projects that we depend on every day
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2015/07/bsdcan-2015-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener"&gt;Another BSDCan report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation is still getting trip reports from BSDCan, and this one comes from Mark Linimon&lt;/li&gt;
&lt;li&gt;In his report, he mainly covers the devsummit and some discussion with the portmgr team&lt;/li&gt;
&lt;li&gt;One notable change for the upcoming 10.2 release is that the default binary repository is now the quarterly branch - Mark talks a bit about this as well&lt;/li&gt;
&lt;li&gt;He also gives his thoughts on using &lt;a href="http://www.bsdnow.tv/episodes/2015_03_04-just_add_qemu" target="_blank" rel="nofollow noopener"&gt;QEMU for cross-compiling packages&lt;/a&gt; and network performance testing
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/08/lumina-desktop-0-8-6-released/" target="_blank" rel="nofollow noopener"&gt;Lumina 0.8.6 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The PC-BSD team has released another version of &lt;a href="http://www.lumina-desktop.org/" target="_blank" rel="nofollow noopener"&gt;Lumina&lt;/a&gt;, their BSD-licensed desktop environment&lt;/li&gt;
&lt;li&gt;This is mainly a bugfix and performance improvement release, rather than one with lots of new features&lt;/li&gt;
&lt;li&gt;The on-screen display widget should be much faster now, and the configuration now allows for easier selection of default applications (which browser, which terminal, etc)&lt;/li&gt;
&lt;li&gt;Lots of non-English translation updates and assorted fixes are included as well&lt;/li&gt;
&lt;li&gt;If you haven't given it a try yet, or maybe you're looking for a new window manager, Lumina runs on all the BSDs
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150730180506" target="_blank" rel="nofollow noopener"&gt;More c2k15 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Even more reports from OpenBSD's latest hackathon are starting to pour in&lt;/li&gt;
&lt;li&gt;The first one is from Alexandr Nedvedicky, one of their brand new developers (the guy from Oracle)&lt;/li&gt;
&lt;li&gt;He talks about his experience going to a hackathon for the first time, and lays out some of the plans for integrating their (very large) SMP PF patch into OpenBSD&lt;/li&gt;
&lt;li&gt;Second up &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150731191156&amp;amp;mode=flat" target="_blank" rel="nofollow noopener"&gt;is Andrew Fresh&lt;/a&gt;, who went without any specific plans, but still ended up getting some UTF8 work done&lt;/li&gt;
&lt;li&gt;On the topic of ARMv7, "I did enjoy being there when things weren't working so [Brandon Mercer] could futilely try to explain the problem to me (I wasn't much help with kernel memory layouts). Fortunately others overheard and provided words of encouragement and some help which was one of my favorite parts of attending this hackathon."&lt;/li&gt;
&lt;li&gt;Florian Obser sent in a report that includes &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150805151453" target="_blank" rel="nofollow noopener"&gt;a little bit of everything&lt;/a&gt;: setting up the hackathon's network, relayd and httpd work, bidirectional forwarding detection, airplane stories and even lots of food&lt;/li&gt;
&lt;li&gt;Paul Irofti &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150801100002&amp;amp;mode=flat" target="_blank" rel="nofollow noopener"&gt;wrote in as well&lt;/a&gt; about his activities, which were mainly focused on the Octeon CPU architecture&lt;/li&gt;
&lt;li&gt;He wrote a new driver for the onboard flash of a DSR-500 machine, which was built following the Common Flash Interface specification&lt;/li&gt;
&lt;li&gt;This means that, going forward, OpenBSD will have out-of-the-box support for any flash memory device (often the case for MIPS and ARM-based embedded devices)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s205kqTEIj" target="_blank" rel="nofollow noopener"&gt;Hamza writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ogIP6cEf" target="_blank" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s214xE9ulK" target="_blank" rel="nofollow noopener"&gt;Dominik writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, quakecon, pf, firewall, gateway, server, reddit, c2k15, hackathon, octeon, zfs, backups, offsite, valleyview, bsdcan, cii</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be talking with Adrian Chadd about an infamous reddit thread he made. With a title like "what would you like to see in FreeBSD?" and hundreds of responses, well, we've got a lot to cover...</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/from-distribution-to-project" target="_blank" rel="nofollow noopener">OpenBSD, from distribution to project</a></h3>

<ul>
<li>Ted Unangst has yet another interesting blog post up, this time covering a bit of BSD history and some different phases OpenBSD has been through</li>
<li>It's the third part of his <a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener">ongoing</a> <a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener">series</a> of posts about OpenBSD removing large bits of code in favor of smaller replacements</li>
<li>In the earliest days, OpenBSD collected and maintained code from lots of other projects (Apache, lynx, perl..)</li>
<li>After importing new updates every release cycle, they eventually hit a transitional phase - things were updated, but nothing new was imported</li>
<li>When the need arose, instead of importing a known tool to do the job, homemade replacements (OpenNTPD, OpenBGPD, etc) were slowly developed</li>
<li>In more recent times, a lot of the imported code has been completely removed in favor of the homegrown daemons</li>
<li>More discussion <a href="https://news.ycombinator.com/item?id=9980373" target="_blank" rel="nofollow noopener">on HN</a> <a href="https://www.reddit.com/r/openbsd/comments/3f9o19/from_distribution_to_project/" target="_blank" rel="nofollow noopener">and reddit</a>
***</li>
</ul>

<h3><a href="https://github.com/hughobrien/zfs-remote-mirror" target="_blank" rel="nofollow noopener">Remote ZFS mirrors, the hard way</a></h3>

<ul>
<li>Backups to "the cloud" have become a hot topic in recent years, but most of them require trade-offs between convenience and security</li>
<li>You have to trust (some of) the providers not to snoop on your data, but even the ones who allow you to locally encrypt files aren't without some compromise</li>
<li>As the author puts it: "We don't need live synchronisation, cloud scaling, SLAs, NSAs, terms of service, lock-ins, buy-outs, up-sells, shut-downs, DoSs, fail whales, pay-us-or-we'll-deletes, or any of the noise that comes with using someone else's infrastructure."</li>
<li>This guide walks you through setting up a FreeBSD server with ZFS to do secure offsite backups yourself</li>
<li>The end result is an automatic system for incremental backups that's backed (pun intended) by ZFS</li>
<li>If you're serious about keeping your important data safe and sound, you'll want to give this one a read - lots of detailed instructions
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419064.html" target="_blank" rel="nofollow noopener">Various DragonFlyBSD updates</a></h3>

<ul>
<li>The DragonFly guys have been quite busy this week, making an assortment of improvements throughout the tree</li>
<li>Intel ValleyView graphics support was finally committed to the main repository</li>
<li>While on the topic of graphics, they've also issued <a href="http://lists.dragonflybsd.org/pipermail/users/2015-July/207923.html" target="_blank" rel="nofollow noopener">a call for testing</a> for a DRM update (matching Linux 3.16's and including some more Broadwell fixes)</li>
<li>Their base GCC compiler is also now <a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419045.html" target="_blank" rel="nofollow noopener">upgraded to version 5.2</a></li>
<li>If your hardware supports it, DragonFly will now <a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419070.html" target="_blank" rel="nofollow noopener">use an accelerated console by default</a>
***</li>
</ul>

<h3><a href="https://youtu.be/mOv62lBdlXU?t=292" target="_blank" rel="nofollow noopener">QuakeCon runs on OpenBSD</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/QuakeCon" target="_blank" rel="nofollow noopener">QuakeCon</a>, everyone's favorite event full of rocket launchers, recently gave a mini-tour of their network setup</li>
<li>For such a crazy network, unsurprisingly, they seem to be big fans of OpenBSD and PF</li>
<li>In this video interview, one of the sysadmins discusses why he chose OpenBSD, what he likes about it, different packet queueing systems, how their firewalls and servers are laid out and much more</li>
<li>He also talks about why they went with vanilla PF, writing their ruleset from the ground up rather than relying on a prebuilt solution</li>
<li>There's also some general networking talk about nginx, reverse proxies, caching, fiber links and all that good stuff</li>
<li>Follow-up questions can be asked in <a href="https://www.reddit.com/r/BSD/comments/3f43fh/bsd_runs_quakecon/" target="_blank" rel="nofollow noopener">this reddit thread</a></li>
<li>The host doesn't seem to be that familiar with the topics at hand, mentioning "OpenPF" multiple times among other things, so our listeners should get a kick out of it
***</li>
</ul>

<h2>Interview - Adrian Chadd - <a href="mailto:adrian@freebsd.org" target="_blank" rel="nofollow noopener">adrian@freebsd.org</a> / <a href="https://twitter.com/erikarn" target="_blank" rel="nofollow noopener">@erikarn</a></h2>

<p>Rethinking <a href="https://www.reddit.com/r/freebsd/comments/3d80vt" target="_blank" rel="nofollow noopener">ways to improve FreeBSD</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150804161939" target="_blank" rel="nofollow noopener">CII contributes to OpenBSD</a></h3>

<ul>
<li>If you recall back to <a href="http://www.bsdnow.tv/episodes/2015_02_25-from_the_foundation_2" target="_blank" rel="nofollow noopener">when we talked to the OpenBSD foundation</a>, one of the things Ken mentioned was the <a href="https://www.coreinfrastructure.org" target="_blank" rel="nofollow noopener">Core Infrastructure Initiative</a></li>
<li>In <a href="https://www.coreinfrastructure.org/faq" target="_blank" rel="nofollow noopener">a nutshell</a>, it's an organization of security experts that helps facilitate (with money, in most cases) the advancement of the more critical open source components of the internet</li>
<li>The group is organized by the Linux foundation, and gets its multi-million dollar backing from various big companies in the technology space (and donations from volunteers) </li>
<li>To ensure that OpenBSD and its related projects (OpenSSH, LibreSSL and PF likely being the main ones here) remain healthy, they've just made a large donation to the foundation - this makes them <a href="http://www.openbsdfoundation.org/contributors.html" target="_blank" rel="nofollow noopener">the first</a> "platinum" level donor as well</li>
<li>While the exact amount wasn't disclosed, it was somewhere between $50,000 and $100,000</li>
<li>The donation comes less than a month after <a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520" target="_blank" rel="nofollow noopener">Microsoft's big donation</a>, so it's good to see these large organizations helping out important open source projects that we depend on every day
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/07/bsdcan-2015-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener">Another BSDCan report</a></h3>

<ul>
<li>The FreeBSD foundation is still getting trip reports from BSDCan, and this one comes from Mark Linimon</li>
<li>In his report, he mainly covers the devsummit and some discussion with the portmgr team</li>
<li>One notable change for the upcoming 10.2 release is that the default binary repository is now the quarterly branch - Mark talks a bit about this as well</li>
<li>He also gives his thoughts on using <a href="http://www.bsdnow.tv/episodes/2015_03_04-just_add_qemu" target="_blank" rel="nofollow noopener">QEMU for cross-compiling packages</a> and network performance testing
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/08/lumina-desktop-0-8-6-released/" target="_blank" rel="nofollow noopener">Lumina 0.8.6 released</a></h3>

<ul>
<li>The PC-BSD team has released another version of <a href="http://www.lumina-desktop.org/" target="_blank" rel="nofollow noopener">Lumina</a>, their BSD-licensed desktop environment</li>
<li>This is mainly a bugfix and performance improvement release, rather than one with lots of new features</li>
<li>The on-screen display widget should be much faster now, and the configuration now allows for easier selection of default applications (which browser, which terminal, etc)</li>
<li>Lots of non-English translation updates and assorted fixes are included as well</li>
<li>If you haven't given it a try yet, or maybe you're looking for a new window manager, Lumina runs on all the BSDs
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150730180506" target="_blank" rel="nofollow noopener">More c2k15 hackathon reports</a></h3>

<ul>
<li>Even more reports from OpenBSD's latest hackathon are starting to pour in</li>
<li>The first one is from Alexandr Nedvedicky, one of their brand new developers (the guy from Oracle)</li>
<li>He talks about his experience going to a hackathon for the first time, and lays out some of the plans for integrating their (very large) SMP PF patch into OpenBSD</li>
<li>Second up <a href="http://undeadly.org/cgi?action=article&amp;sid=20150731191156&amp;mode=flat" target="_blank" rel="nofollow noopener">is Andrew Fresh</a>, who went without any specific plans, but still ended up getting some UTF8 work done</li>
<li>On the topic of ARMv7, "I did enjoy being there when things weren't working so [Brandon Mercer] could futilely try to explain the problem to me (I wasn't much help with kernel memory layouts). Fortunately others overheard and provided words of encouragement and some help which was one of my favorite parts of attending this hackathon."</li>
<li>Florian Obser sent in a report that includes <a href="http://undeadly.org/cgi?action=article&amp;sid=20150805151453" target="_blank" rel="nofollow noopener">a little bit of everything</a>: setting up the hackathon's network, relayd and httpd work, bidirectional forwarding detection, airplane stories and even lots of food</li>
<li>Paul Irofti <a href="http://undeadly.org/cgi?action=article&amp;sid=20150801100002&amp;mode=flat" target="_blank" rel="nofollow noopener">wrote in as well</a> about his activities, which were mainly focused on the Octeon CPU architecture</li>
<li>He wrote a new driver for the onboard flash of a DSR-500 machine, which was built following the Common Flash Interface specification</li>
<li>This means that, going forward, OpenBSD will have out-of-the-box support for any flash memory device (often the case for MIPS and ARM-based embedded devices)
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s205kqTEIj" target="_blank" rel="nofollow noopener">Hamza writes in</a></li>
<li><a href="http://slexy.org/view/s2ogIP6cEf" target="_blank" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s214xE9ulK" target="_blank" rel="nofollow noopener">Dominik writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be talking with Adrian Chadd about an infamous reddit thread he made. With a title like "what would you like to see in FreeBSD?" and hundreds of responses, well, we've got a lot to cover...</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/from-distribution-to-project" target="_blank" rel="nofollow noopener">OpenBSD, from distribution to project</a></h3>

<ul>
<li>Ted Unangst has yet another interesting blog post up, this time covering a bit of BSD history and some different phases OpenBSD has been through</li>
<li>It's the third part of his <a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener">ongoing</a> <a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener">series</a> of posts about OpenBSD removing large bits of code in favor of smaller replacements</li>
<li>In the earliest days, OpenBSD collected and maintained code from lots of other projects (Apache, lynx, perl..)</li>
<li>After importing new updates every release cycle, they eventually hit a transitional phase - things were updated, but nothing new was imported</li>
<li>When the need arose, instead of importing a known tool to do the job, homemade replacements (OpenNTPD, OpenBGPD, etc) were slowly developed</li>
<li>In more recent times, a lot of the imported code has been completely removed in favor of the homegrown daemons</li>
<li>More discussion <a href="https://news.ycombinator.com/item?id=9980373" target="_blank" rel="nofollow noopener">on HN</a> <a href="https://www.reddit.com/r/openbsd/comments/3f9o19/from_distribution_to_project/" target="_blank" rel="nofollow noopener">and reddit</a>
***</li>
</ul>

<h3><a href="https://github.com/hughobrien/zfs-remote-mirror" target="_blank" rel="nofollow noopener">Remote ZFS mirrors, the hard way</a></h3>

<ul>
<li>Backups to "the cloud" have become a hot topic in recent years, but most of them require trade-offs between convenience and security</li>
<li>You have to trust (some of) the providers not to snoop on your data, but even the ones who allow you to locally encrypt files aren't without some compromise</li>
<li>As the author puts it: "We don't need live synchronisation, cloud scaling, SLAs, NSAs, terms of service, lock-ins, buy-outs, up-sells, shut-downs, DoSs, fail whales, pay-us-or-we'll-deletes, or any of the noise that comes with using someone else's infrastructure."</li>
<li>This guide walks you through setting up a FreeBSD server with ZFS to do secure offsite backups yourself</li>
<li>The end result is an automatic system for incremental backups that's backed (pun intended) by ZFS</li>
<li>If you're serious about keeping your important data safe and sound, you'll want to give this one a read - lots of detailed instructions
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419064.html" target="_blank" rel="nofollow noopener">Various DragonFlyBSD updates</a></h3>

<ul>
<li>The DragonFly guys have been quite busy this week, making an assortment of improvements throughout the tree</li>
<li>Intel ValleyView graphics support was finally committed to the main repository</li>
<li>While on the topic of graphics, they've also issued <a href="http://lists.dragonflybsd.org/pipermail/users/2015-July/207923.html" target="_blank" rel="nofollow noopener">a call for testing</a> for a DRM update (matching Linux 3.16's and including some more Broadwell fixes)</li>
<li>Their base GCC compiler is also now <a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419045.html" target="_blank" rel="nofollow noopener">upgraded to version 5.2</a></li>
<li>If your hardware supports it, DragonFly will now <a href="http://lists.dragonflybsd.org/pipermail/commits/2015-July/419070.html" target="_blank" rel="nofollow noopener">use an accelerated console by default</a>
***</li>
</ul>

<h3><a href="https://youtu.be/mOv62lBdlXU?t=292" target="_blank" rel="nofollow noopener">QuakeCon runs on OpenBSD</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/QuakeCon" target="_blank" rel="nofollow noopener">QuakeCon</a>, everyone's favorite event full of rocket launchers, recently gave a mini-tour of their network setup</li>
<li>For such a crazy network, unsurprisingly, they seem to be big fans of OpenBSD and PF</li>
<li>In this video interview, one of the sysadmins discusses why he chose OpenBSD, what he likes about it, different packet queueing systems, how their firewalls and servers are laid out and much more</li>
<li>He also talks about why they went with vanilla PF, writing their ruleset from the ground up rather than relying on a prebuilt solution</li>
<li>There's also some general networking talk about nginx, reverse proxies, caching, fiber links and all that good stuff</li>
<li>Follow-up questions can be asked in <a href="https://www.reddit.com/r/BSD/comments/3f43fh/bsd_runs_quakecon/" target="_blank" rel="nofollow noopener">this reddit thread</a></li>
<li>The host doesn't seem to be that familiar with the topics at hand, mentioning "OpenPF" multiple times among other things, so our listeners should get a kick out of it
***</li>
</ul>

<h2>Interview - Adrian Chadd - <a href="mailto:adrian@freebsd.org" target="_blank" rel="nofollow noopener">adrian@freebsd.org</a> / <a href="https://twitter.com/erikarn" target="_blank" rel="nofollow noopener">@erikarn</a></h2>

<p>Rethinking <a href="https://www.reddit.com/r/freebsd/comments/3d80vt" target="_blank" rel="nofollow noopener">ways to improve FreeBSD</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150804161939" target="_blank" rel="nofollow noopener">CII contributes to OpenBSD</a></h3>

<ul>
<li>If you recall back to <a href="http://www.bsdnow.tv/episodes/2015_02_25-from_the_foundation_2" target="_blank" rel="nofollow noopener">when we talked to the OpenBSD foundation</a>, one of the things Ken mentioned was the <a href="https://www.coreinfrastructure.org" target="_blank" rel="nofollow noopener">Core Infrastructure Initiative</a></li>
<li>In <a href="https://www.coreinfrastructure.org/faq" target="_blank" rel="nofollow noopener">a nutshell</a>, it's an organization of security experts that helps facilitate (with money, in most cases) the advancement of the more critical open source components of the internet</li>
<li>The group is organized by the Linux foundation, and gets its multi-million dollar backing from various big companies in the technology space (and donations from volunteers) </li>
<li>To ensure that OpenBSD and its related projects (OpenSSH, LibreSSL and PF likely being the main ones here) remain healthy, they've just made a large donation to the foundation - this makes them <a href="http://www.openbsdfoundation.org/contributors.html" target="_blank" rel="nofollow noopener">the first</a> "platinum" level donor as well</li>
<li>While the exact amount wasn't disclosed, it was somewhere between $50,000 and $100,000</li>
<li>The donation comes less than a month after <a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520" target="_blank" rel="nofollow noopener">Microsoft's big donation</a>, so it's good to see these large organizations helping out important open source projects that we depend on every day
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/07/bsdcan-2015-trip-report-mark-linimon.html" target="_blank" rel="nofollow noopener">Another BSDCan report</a></h3>

<ul>
<li>The FreeBSD foundation is still getting trip reports from BSDCan, and this one comes from Mark Linimon</li>
<li>In his report, he mainly covers the devsummit and some discussion with the portmgr team</li>
<li>One notable change for the upcoming 10.2 release is that the default binary repository is now the quarterly branch - Mark talks a bit about this as well</li>
<li>He also gives his thoughts on using <a href="http://www.bsdnow.tv/episodes/2015_03_04-just_add_qemu" target="_blank" rel="nofollow noopener">QEMU for cross-compiling packages</a> and network performance testing
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/08/lumina-desktop-0-8-6-released/" target="_blank" rel="nofollow noopener">Lumina 0.8.6 released</a></h3>

<ul>
<li>The PC-BSD team has released another version of <a href="http://www.lumina-desktop.org/" target="_blank" rel="nofollow noopener">Lumina</a>, their BSD-licensed desktop environment</li>
<li>This is mainly a bugfix and performance improvement release, rather than one with lots of new features</li>
<li>The on-screen display widget should be much faster now, and the configuration now allows for easier selection of default applications (which browser, which terminal, etc)</li>
<li>Lots of non-English translation updates and assorted fixes are included as well</li>
<li>If you haven't given it a try yet, or maybe you're looking for a new window manager, Lumina runs on all the BSDs
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150730180506" target="_blank" rel="nofollow noopener">More c2k15 hackathon reports</a></h3>

<ul>
<li>Even more reports from OpenBSD's latest hackathon are starting to pour in</li>
<li>The first one is from Alexandr Nedvedicky, one of their brand new developers (the guy from Oracle)</li>
<li>He talks about his experience going to a hackathon for the first time, and lays out some of the plans for integrating their (very large) SMP PF patch into OpenBSD</li>
<li>Second up <a href="http://undeadly.org/cgi?action=article&amp;sid=20150731191156&amp;mode=flat" target="_blank" rel="nofollow noopener">is Andrew Fresh</a>, who went without any specific plans, but still ended up getting some UTF8 work done</li>
<li>On the topic of ARMv7, "I did enjoy being there when things weren't working so [Brandon Mercer] could futilely try to explain the problem to me (I wasn't much help with kernel memory layouts). Fortunately others overheard and provided words of encouragement and some help which was one of my favorite parts of attending this hackathon."</li>
<li>Florian Obser sent in a report that includes <a href="http://undeadly.org/cgi?action=article&amp;sid=20150805151453" target="_blank" rel="nofollow noopener">a little bit of everything</a>: setting up the hackathon's network, relayd and httpd work, bidirectional forwarding detection, airplane stories and even lots of food</li>
<li>Paul Irofti <a href="http://undeadly.org/cgi?action=article&amp;sid=20150801100002&amp;mode=flat" target="_blank" rel="nofollow noopener">wrote in as well</a> about his activities, which were mainly focused on the Octeon CPU architecture</li>
<li>He wrote a new driver for the onboard flash of a DSR-500 machine, which was built following the Common Flash Interface specification</li>
<li>This means that, going forward, OpenBSD will have out-of-the-box support for any flash memory device (often the case for MIPS and ARM-based embedded devices)
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s205kqTEIj" target="_blank" rel="nofollow noopener">Hamza writes in</a></li>
<li><a href="http://slexy.org/view/s2ogIP6cEf" target="_blank" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s214xE9ulK" target="_blank" rel="nofollow noopener">Dominik writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>96: Lost Technology</title>
  <link>https://www.bsdnow.tv/96</link>
  <guid isPermaLink="false">a1813e16-466a-4617-9bb0-24dbdc1cb5f2</guid>
  <pubDate>Wed, 01 Jul 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/a1813e16-466a-4617-9bb0-24dbdc1cb5f2.mp3" length="52701844" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week, we'll be talking with Jun Ebihara about some lesser-known CPU architectures in NetBSD. He'll tell us what makes these old (and often forgotten) machines so interesting. As usual, we've also got answers to your emails and all this week's news on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:13:11</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week, we'll be talking with Jun Ebihara about some lesser-known CPU architectures in NetBSD. He'll tell us what makes these old (and often forgotten) machines so interesting. As usual, we've also got answers to your emails and all this week's news on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener"&gt;Out with the old, in with the less&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our friend Ted Unangst has a new article up, talking about "various OpenBSD replacements and reductions"&lt;/li&gt;
&lt;li&gt;"Instead of trying to fix known bugs, we’re trying to fix unknown bugs. It’s not based on the current buggy state of the code, but the anticipated future buggy state of the code. Past bugs are a bigger factor than current bugs."&lt;/li&gt;
&lt;li&gt;In the post, he goes through some of the bigger (and smaller) examples of OpenBSD rewriting tools to be simpler and more secure&lt;/li&gt;
&lt;li&gt;It starts off with a lesser-known SCSI driver that "tried to do too much" being replaced with three separate drivers&lt;/li&gt;
&lt;li&gt;"Each driver can now be modified in isolation without unintentional side effects on other hardware, or the need to consider if and where further special cases need to be added. Despite the fact that these three drivers duplicate all the common boilerplate code, combined they only amount to about half as much code as the old driver."&lt;/li&gt;
&lt;li&gt;In contrast to that example, he goes on to cite mandoc as taking a very non "unixy" direction, but at the same time being smaller and simpler than all the tools it replaced&lt;/li&gt;
&lt;li&gt;The next case is the new http daemon, and he talks a bit about the recently-added rewrite support being done in a simple and secure way (as opposed to regex and its craziness)&lt;/li&gt;
&lt;li&gt;He also talks about the rewritten "file" utility: "Almost by definition, its sole input will be untrusted input. Perversely, people will then trust what file tells them and then go about using that input, as if file somehow sanitized it."&lt;/li&gt;
&lt;li&gt;Finally, sudo in OpenBSD's base system is moving to ports soon, and the article briefly describes a new tool that &lt;a href="https://marc.info/?l=openbsd-ports&amp;amp;m=143481227122523&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;may or may not replace it&lt;/a&gt;, called "doas"&lt;/li&gt;
&lt;li&gt;There's also a nice wrap-up of all the examples at the end, and the "&lt;a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener"&gt;Pruning and Polishing&lt;/a&gt;" talk is good complementary reading material
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/channel/UC0IK6Y4Go2KtRueHDiQcxow/videos" target="_blank" rel="nofollow noopener"&gt;More OpenZFS and BSDCan videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned &lt;a href="http://www.bsdnow.tv/episodes/2015_06_24-bitrot_group_therapy" target="_blank" rel="nofollow noopener"&gt;last week&lt;/a&gt; that some of the videos from the second OpenZFS conference in Europe were being uploaded - here's some more&lt;/li&gt;
&lt;li&gt;Matt Ahrens did &lt;a href="https://www.youtube.com/watch?v=I6fXZ_6OT5c" target="_blank" rel="nofollow noopener"&gt;a Q&amp;amp;A session&lt;/a&gt; and talked about ZFS &lt;a href="https://www.youtube.com/watch?v=iY44jPMvxog" target="_blank" rel="nofollow noopener"&gt;send and receive&lt;/a&gt;, as well as giving an &lt;a href="https://www.youtube.com/watch?v=RQlMDmnty80" target="_blank" rel="nofollow noopener"&gt;overview of OpenZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;George Wilson talked about a &lt;a href="https://www.youtube.com/watch?v=KBI6rRGUv4E" target="_blank" rel="nofollow noopener"&gt;performance retrospective&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=sSi47-k78IM" target="_blank" rel="nofollow noopener"&gt;Toshiba&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=Hhje5KEF5cE" target="_blank" rel="nofollow noopener"&gt;Syneto&lt;/a&gt; and &lt;a href="https://www.youtube.com/watch?v=aKgxXipss8k" target="_blank" rel="nofollow noopener"&gt;HGST&lt;/a&gt; also gave some talks about their companies and how they're using ZFS&lt;/li&gt;
&lt;li&gt;As for BSDCan, more of their BSD presentations have been uploaded too...&lt;/li&gt;
&lt;li&gt;Ryan Stone, &lt;a href="https://www.youtube.com/watch?v=INeMd-i5jzM" target="_blank" rel="nofollow noopener"&gt;PCI SR-IOV on FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;George Neville-Neil, &lt;a href="https://www.youtube.com/watch?v=LE4wMsP7zeA" target="_blank" rel="nofollow noopener"&gt;Measure Twice, Code Once&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kris Moore, &lt;a href="https://www.youtube.com/watch?v=qNYXqpJiFN0" target="_blank" rel="nofollow noopener"&gt;Unifying jail and package management for PC-BSD, FreeNAS and FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Warner Losh, &lt;a href="https://www.youtube.com/watch?v=3WqOLolj5EU" target="_blank" rel="nofollow noopener"&gt;I/O Scheduling in CAM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kirk McKusick, &lt;a href="https://www.youtube.com/watch?v=l-RCLgLxuSc" target="_blank" rel="nofollow noopener"&gt;An Introduction to the Implementation of ZFS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Midori Kato, &lt;a href="https://www.youtube.com/watch?v=zZXvjhWcg_4" target="_blank" rel="nofollow noopener"&gt;Extensions to FreeBSD Datacenter TCP for Incremental Deployment Support&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Baptiste Daroussin, &lt;a href="https://www.youtube.com/watch?v=Br6izhH5P1I" target="_blank" rel="nofollow noopener"&gt;Packaging FreeBSD's&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=v7px6ktoDAI" target="_blank" rel="nofollow noopener"&gt;base system&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Matt Ahrens, &lt;a href="https://www.youtube.com/watch?v=UOX7WDAjqso" target="_blank" rel="nofollow noopener"&gt;New OpenZFS features supporting remote replication&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ed Schouten, &lt;a href="https://www.youtube.com/watch?v=SVdF84x1EdA" target="_blank" rel="nofollow noopener"&gt;CloudABI Cloud computing meets fine-grained capabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The audio of Ingo Schwarze's talk "mandoc: becoming the main BSD manual toolbox" got messed up, but there's an alternate recording &lt;a href="http://www.bsdcan.org/2015/audio/mandoc.mp3" target="_blank" rel="nofollow noopener"&gt;here&lt;/a&gt;, and the slides are &lt;a href="http://www.openbsd.org/papers/bsdcan15-mandoc.pdf" target="_blank" rel="nofollow noopener"&gt;here&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=143526329006942&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;SMP steroids for PF&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;An Oracle employee that's been porting OpenBSD's PF to an upcoming Solaris release has sent in an interesting patch for review&lt;/li&gt;
&lt;li&gt;Attached to the mail was what may be the beginnings of making native PF SMP-aware&lt;/li&gt;
&lt;li&gt;Before you start partying, the road to SMP (specifically, giant lock removal) is a long and very complicated one, requiring every relevant bit of the stack to be written with it in mind - this is just one piece of the puzzle&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=143532243322281&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;initial response&lt;/a&gt; has been quite positive though, with some &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=143532963824548&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;back and forth&lt;/a&gt; between developers and the submitter&lt;/li&gt;
&lt;li&gt;For now, let's be patient and see what happens
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.dragonflybsd.org/release42/" target="_blank" rel="nofollow noopener"&gt;DragonFly 4.2.0 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DragonFlyBSD has released the next big update of their 4.x branch, complete with a decent amount of new features and fixes&lt;/li&gt;
&lt;li&gt;i915 and Radeon graphics have been updated, and DragonFly can claim the title of first BSD with Broadwell support in a release&lt;/li&gt;
&lt;li&gt;Sendmail in the base system has been replaced with their homegrown DragonFly Mail Agent, and there's &lt;a href="http://www.dragonflybsd.com/docs/docs/newhandbook/mta/" target="_blank" rel="nofollow noopener"&gt;a wiki page&lt;/a&gt; about configuring it&lt;/li&gt;
&lt;li&gt;They've also switched the default compiler to GCC 5, though why they've gone in that direction instead of embracing Clang is a mystery&lt;/li&gt;
&lt;li&gt;The announcement page also contains a list of kernel changes, details on the audio and graphics updates, removal of the SCTP protocol, improvements to the temperature sensors, various userland utility fixes and a list of updates to third party tools&lt;/li&gt;
&lt;li&gt;Work is continuing on the second generation HAMMER filesystem, and Matt Dillon provides a status update in the release announcement&lt;/li&gt;
&lt;li&gt;There was also some &lt;a href="https://news.ycombinator.com/item?id=9797932" target="_blank" rel="nofollow noopener"&gt;hacker news discussion&lt;/a&gt; you can check out, as well as &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-June/207801.html" target="_blank" rel="nofollow noopener"&gt;upgrade instructions&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://opensmtpd.org/announces/release-5.7.1.txt" target="_blank" rel="nofollow noopener"&gt;OpenSMTPD 5.7.1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenSMTPD guys have just released version 5.7.1, a major milestone version that we mentioned recently&lt;/li&gt;
&lt;li&gt;Crypto-related bits have been vastly improved: the RSA engine is now privilege-separated, TLS errors are handled more gracefully, ciphers and curve preferences can now be specified, the PKI interface has been reworked to allow custom CAs, SNI and certificate verification have been simplified and the DH parameters are now 2048 bit by default&lt;/li&gt;
&lt;li&gt;The long-awaited filter API is now enabled by default, though still considered slightly experimental&lt;/li&gt;
&lt;li&gt;Documentation has been improved quite a bit, with more examples and common use cases (as well as exotic ones)&lt;/li&gt;
&lt;li&gt;Many more small additions and bugfixes were made, so check the changelog for the full list&lt;/li&gt;
&lt;li&gt;Starting with 5.7.1, releases are now &lt;a href="https://twitter.com/OpenSMTPD/status/613257722574839808" target="_blank" rel="nofollow noopener"&gt;cryptographically&lt;/a&gt; &lt;a href="https://www.opensmtpd.org/archives/opensmtpd-5.7.1.sum.sig" target="_blank" rel="nofollow noopener"&gt;signed&lt;/a&gt; to ensure integrity&lt;/li&gt;
&lt;li&gt;This release has gone through some major stress testing to ensure stability - Gilles regularly asks their Twitter followers to &lt;a href="https://twitter.com/OpenSMTPD/status/608399272447471616" target="_blank" rel="nofollow noopener"&gt;flood a test server&lt;/a&gt; with thousands of emails per second, even &lt;a href="https://twitter.com/OpenSMTPD/status/608235180839567360" target="_blank" rel="nofollow noopener"&gt;offering prizes&lt;/a&gt; to whoever can DDoS them the hardest&lt;/li&gt;
&lt;li&gt;OpenSMTPD runs on all the BSDs of course, and seems to be getting pretty popular lately&lt;/li&gt;
&lt;li&gt;Let's all &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;encourage&lt;/a&gt; Kris to stop procrastinating on switching from Postfix
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jun Ebihara (蛯原純) - &lt;a href="mailto:jun@netbsd.org" target="_blank" rel="nofollow noopener"&gt;jun@netbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/ebijun" target="_blank" rel="nofollow noopener"&gt;@ebijun&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Lesser-known CPU architectures, embedded NetBSD devices&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-steven-douglas.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD foundation at BSDCan&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation has posted a few BSDCan summaries on their blog&lt;/li&gt;
&lt;li&gt;The first, from Steven Douglas, begins with a sentiment a lot of us can probably identify with: "Where I live, there are only a handful of people that even know what BSD is, let alone can talk at a high level about it. That was one of my favorite things, being around like minded people."&lt;/li&gt;
&lt;li&gt;He got to meet a lot of the people working on big-name projects, and enjoyed being able to ask them questions so easily&lt;/li&gt;
&lt;li&gt;Their &lt;a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-ahmed-kamal.html" target="_blank" rel="nofollow noopener"&gt;second&lt;/a&gt; trip report is from Ahmed Kamal, who flew in all the way from Egypt&lt;/li&gt;
&lt;li&gt;A bit starstruck, he seems to have enjoyed all the talks, particularly Andrew Tanenbaum's about MINIX and NetBSD&lt;/li&gt;
&lt;li&gt;There are also two more wrap-ups from &lt;a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-zbigniew-bodek.html" target="_blank" rel="nofollow noopener"&gt;Zbigniew Bodek&lt;/a&gt; and &lt;a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-vsevolod-stakhov.html" target="_blank" rel="nofollow noopener"&gt;Vsevolod Stakhov&lt;/a&gt;, so you've got plenty to read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://cfenollosa.com/blog/openbsd-from-a-veteran-linux-user-perspective.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD from a veteran Linux user perspective&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In a new series of blog posts, a self-proclaimed veteran Linux user is giving OpenBSD a try for the first time&lt;/li&gt;
&lt;li&gt;"For the first time I installed a BSD box on a machine I control. The experience has been eye-opening, especially since I consider myself an 'old-school' Linux admin, and I've felt out of place with the latest changes on the system administration."&lt;/li&gt;
&lt;li&gt;The post is a collection of his thoughts about what's different between Linux and BSD, what surprised him as a beginner - admittedly, a lot of his knowledge carried over, and there were just minor differences in command flags&lt;/li&gt;
&lt;li&gt;One of the things that surprised him (in a positive way) was the documentation: "OpenBSD's man pages are so nice that RTFMing somebody on the internet is not condescending but selfless."&lt;/li&gt;
&lt;li&gt;He also goes through some of the basics, installing and updating software, following different branches&lt;/li&gt;
&lt;li&gt;It concludes with "If you like UNIX, it will open your eyes to the fact that there is more than one way to do things, and that system administration can still be simple while modern."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://sysconfig.org.uk/freebsd-on-the-desktop-am-i-crazy.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD on the desktop, am I crazy&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Similar to the previous article, the guy that wrote the SSH two factor authentication post we covered last week has another new article up - this time about FreeBSD on the desktop&lt;/li&gt;
&lt;li&gt;He begins with a bit of forewarning for potential Linux switchers: "It certainly wasn't an easy journey, and I'm tempted to say do not try this at home to anybody who isn't going to leverage any of FreeBSD's strong points. Definitely don't try FreeBSD on the desktop if you haven't used it on servers or virtual machines before. It's got less in common with Linux than you might think."&lt;/li&gt;
&lt;li&gt;With that out of the way, the list of positives is pretty large: a tidy base system, separation between base and ports, having the option to choose binary packages or ports, ZFS, jails, licensing and of course the lack of systemd&lt;/li&gt;
&lt;li&gt;The rest of the post talks about some of the hurdles he had to overcome, namely with graphics and the infamous Adobe Flash&lt;/li&gt;
&lt;li&gt;Also worth noting is that he found jails to be not only good for isolating daemons on a server, but pretty useful for desktop applications as well&lt;/li&gt;
&lt;li&gt;In the end, he says it was worth all the trouble, and is even planning on converting his laptop to FreeBSD soon too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.netflask.net/ipsec-ikev2-cisco-csr1000v-openiked/" target="_blank" rel="nofollow noopener"&gt;OpenIKED and Cisco CSR 1000v IPSEC&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This article covers setting up a site-to-site IPSEC tunnel between a Cisco CSR 1000v router and an OpenBSD gateway running OpenIKED&lt;/li&gt;
&lt;li&gt;What kind of networking blog post would be complete without a diagram where the internet is represented by a big cloud&lt;/li&gt;
&lt;li&gt;There are lots of details (and example configuration files) for using IKEv2 and OpenBSD's built-in IKE daemon&lt;/li&gt;
&lt;li&gt;It also goes to show that the BSDs generally play well with existing network infrastructure, so if you were a business that's afraid to try them… don't be
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/HardenedBSD/hardenedBSD/commit/bd5cecb4dc7947a5e214fc100834399b4bffdee8" target="_blank" rel="nofollow noopener"&gt;HardenedBSD improves stack randomization&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The HardenedBSD guys have improved their FreeBSD ASLR patchset, specifically in the stack randomization area&lt;/li&gt;
&lt;li&gt;In their initial implementation, the stack randomization was a random gap - this update makes the base address randomized as well&lt;/li&gt;
&lt;li&gt;They're now stacking the new on top of the old as well, with the goal being even more entropy&lt;/li&gt;
&lt;li&gt;This change triggered an ABI and API incompatibility, so their major version has been bumped
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2015-July/000121.html" target="_blank" rel="nofollow noopener"&gt;OpenSSH 6.9 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenSSH team has announced the release of a new version which, following their tick/tock major/minor release cycle, is focused mainly on bug fixes&lt;/li&gt;
&lt;li&gt;There are a couple new things though - the "AuthorizedKeysCommand" config option now takes custom arguments&lt;/li&gt;
&lt;li&gt;One very notable change is that &lt;strong&gt;the default cipher has changed&lt;/strong&gt; as of this release&lt;/li&gt;
&lt;li&gt;The traditional pairing of AES128 in counter mode with MD5 HMAC has been &lt;em&gt;replaced&lt;/em&gt; by the ever-trendy ChaCha20-Poly1305 combo&lt;/li&gt;
&lt;li&gt;Their next release, 7.0, is set to get rid a number of legacy items: PermitRootLogin will be switched to "no" by default, SSHv1 support will be totally disabled, the 1024bit diffie-hellman-group1-sha1 KEX will be disabled, old ssh-dss and v00 certs will be removed, a number of weak ciphers will be disabled by default (including all CBC ones) and RSA keys will be refused if they're under 1024 bits&lt;/li&gt;
&lt;li&gt;Many small bugs fixes and improvements were also made, so check the announcement for everything else&lt;/li&gt;
&lt;li&gt;The native version is in OpenBSD -current, and an update to the portable version should be hitting a ports or pkgsrc tree near you soon
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Ws6Y2rZy" target="_blank" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21GvZ5xbs" target="_blank" rel="nofollow noopener"&gt;Mason writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s209TrPK4e" target="_blank" rel="nofollow noopener"&gt;Jochen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21TQjUjxv" target="_blank" rel="nofollow noopener"&gt;Simon writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, osc, embedded, japanese, users group, pf, smp, multithreading, file, solaris, httpd, leap second, openzfs, zfs, opensmtpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week, we'll be talking with Jun Ebihara about some lesser-known CPU architectures in NetBSD. He'll tell us what makes these old (and often forgotten) machines so interesting. As usual, we've also got answers to your emails and all this week's news on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener">Out with the old, in with the less</a></h3>

<ul>
<li>Our friend Ted Unangst has a new article up, talking about "various OpenBSD replacements and reductions"</li>
<li>"Instead of trying to fix known bugs, we’re trying to fix unknown bugs. It’s not based on the current buggy state of the code, but the anticipated future buggy state of the code. Past bugs are a bigger factor than current bugs."</li>
<li>In the post, he goes through some of the bigger (and smaller) examples of OpenBSD rewriting tools to be simpler and more secure</li>
<li>It starts off with a lesser-known SCSI driver that "tried to do too much" being replaced with three separate drivers</li>
<li>"Each driver can now be modified in isolation without unintentional side effects on other hardware, or the need to consider if and where further special cases need to be added. Despite the fact that these three drivers duplicate all the common boilerplate code, combined they only amount to about half as much code as the old driver."</li>
<li>In contrast to that example, he goes on to cite mandoc as taking a very non "unixy" direction, but at the same time being smaller and simpler than all the tools it replaced</li>
<li>The next case is the new http daemon, and he talks a bit about the recently-added rewrite support being done in a simple and secure way (as opposed to regex and its craziness)</li>
<li>He also talks about the rewritten "file" utility: "Almost by definition, its sole input will be untrusted input. Perversely, people will then trust what file tells them and then go about using that input, as if file somehow sanitized it."</li>
<li>Finally, sudo in OpenBSD's base system is moving to ports soon, and the article briefly describes a new tool that <a href="https://marc.info/?l=openbsd-ports&amp;m=143481227122523&amp;w=2" target="_blank" rel="nofollow noopener">may or may not replace it</a>, called "doas"</li>
<li>There's also a nice wrap-up of all the examples at the end, and the "<a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener">Pruning and Polishing</a>" talk is good complementary reading material
***</li>
</ul>

<h3><a href="https://www.youtube.com/channel/UC0IK6Y4Go2KtRueHDiQcxow/videos" target="_blank" rel="nofollow noopener">More OpenZFS and BSDCan videos</a></h3>

<ul>
<li>We mentioned <a href="http://www.bsdnow.tv/episodes/2015_06_24-bitrot_group_therapy" target="_blank" rel="nofollow noopener">last week</a> that some of the videos from the second OpenZFS conference in Europe were being uploaded - here's some more</li>
<li>Matt Ahrens did <a href="https://www.youtube.com/watch?v=I6fXZ_6OT5c" target="_blank" rel="nofollow noopener">a Q&amp;A session</a> and talked about ZFS <a href="https://www.youtube.com/watch?v=iY44jPMvxog" target="_blank" rel="nofollow noopener">send and receive</a>, as well as giving an <a href="https://www.youtube.com/watch?v=RQlMDmnty80" target="_blank" rel="nofollow noopener">overview of OpenZFS</a></li>
<li>George Wilson talked about a <a href="https://www.youtube.com/watch?v=KBI6rRGUv4E" target="_blank" rel="nofollow noopener">performance retrospective</a></li>
<li><a href="https://www.youtube.com/watch?v=sSi47-k78IM" target="_blank" rel="nofollow noopener">Toshiba</a>, <a href="https://www.youtube.com/watch?v=Hhje5KEF5cE" target="_blank" rel="nofollow noopener">Syneto</a> and <a href="https://www.youtube.com/watch?v=aKgxXipss8k" target="_blank" rel="nofollow noopener">HGST</a> also gave some talks about their companies and how they're using ZFS</li>
<li>As for BSDCan, more of their BSD presentations have been uploaded too...</li>
<li>Ryan Stone, <a href="https://www.youtube.com/watch?v=INeMd-i5jzM" target="_blank" rel="nofollow noopener">PCI SR-IOV on FreeBSD</a></li>
<li>George Neville-Neil, <a href="https://www.youtube.com/watch?v=LE4wMsP7zeA" target="_blank" rel="nofollow noopener">Measure Twice, Code Once</a></li>
<li>Kris Moore, <a href="https://www.youtube.com/watch?v=qNYXqpJiFN0" target="_blank" rel="nofollow noopener">Unifying jail and package management for PC-BSD, FreeNAS and FreeBSD</a></li>
<li>Warner Losh, <a href="https://www.youtube.com/watch?v=3WqOLolj5EU" target="_blank" rel="nofollow noopener">I/O Scheduling in CAM</a></li>
<li>Kirk McKusick, <a href="https://www.youtube.com/watch?v=l-RCLgLxuSc" target="_blank" rel="nofollow noopener">An Introduction to the Implementation of ZFS</a></li>
<li>Midori Kato, <a href="https://www.youtube.com/watch?v=zZXvjhWcg_4" target="_blank" rel="nofollow noopener">Extensions to FreeBSD Datacenter TCP for Incremental Deployment Support</a></li>
<li>Baptiste Daroussin, <a href="https://www.youtube.com/watch?v=Br6izhH5P1I" target="_blank" rel="nofollow noopener">Packaging FreeBSD's</a> <a href="https://www.youtube.com/watch?v=v7px6ktoDAI" target="_blank" rel="nofollow noopener">base system</a></li>
<li>Matt Ahrens, <a href="https://www.youtube.com/watch?v=UOX7WDAjqso" target="_blank" rel="nofollow noopener">New OpenZFS features supporting remote replication</a></li>
<li>Ed Schouten, <a href="https://www.youtube.com/watch?v=SVdF84x1EdA" target="_blank" rel="nofollow noopener">CloudABI Cloud computing meets fine-grained capabilities</a></li>
<li>The audio of Ingo Schwarze's talk "mandoc: becoming the main BSD manual toolbox" got messed up, but there's an alternate recording <a href="http://www.bsdcan.org/2015/audio/mandoc.mp3" target="_blank" rel="nofollow noopener">here</a>, and the slides are <a href="http://www.openbsd.org/papers/bsdcan15-mandoc.pdf" target="_blank" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=143526329006942&amp;w=2" target="_blank" rel="nofollow noopener">SMP steroids for PF</a></h3>

<ul>
<li>An Oracle employee that's been porting OpenBSD's PF to an upcoming Solaris release has sent in an interesting patch for review</li>
<li>Attached to the mail was what may be the beginnings of making native PF SMP-aware</li>
<li>Before you start partying, the road to SMP (specifically, giant lock removal) is a long and very complicated one, requiring every relevant bit of the stack to be written with it in mind - this is just one piece of the puzzle</li>
<li>The <a href="https://www.marc.info/?l=openbsd-tech&amp;m=143532243322281&amp;w=2" target="_blank" rel="nofollow noopener">initial response</a> has been quite positive though, with some <a href="https://www.marc.info/?l=openbsd-tech&amp;m=143532963824548&amp;w=2" target="_blank" rel="nofollow noopener">back and forth</a> between developers and the submitter</li>
<li>For now, let's be patient and see what happens
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/release42/" target="_blank" rel="nofollow noopener">DragonFly 4.2.0 released</a></h3>

<ul>
<li>DragonFlyBSD has released the next big update of their 4.x branch, complete with a decent amount of new features and fixes</li>
<li>i915 and Radeon graphics have been updated, and DragonFly can claim the title of first BSD with Broadwell support in a release</li>
<li>Sendmail in the base system has been replaced with their homegrown DragonFly Mail Agent, and there's <a href="http://www.dragonflybsd.com/docs/docs/newhandbook/mta/" target="_blank" rel="nofollow noopener">a wiki page</a> about configuring it</li>
<li>They've also switched the default compiler to GCC 5, though why they've gone in that direction instead of embracing Clang is a mystery</li>
<li>The announcement page also contains a list of kernel changes, details on the audio and graphics updates, removal of the SCTP protocol, improvements to the temperature sensors, various userland utility fixes and a list of updates to third party tools</li>
<li>Work is continuing on the second generation HAMMER filesystem, and Matt Dillon provides a status update in the release announcement</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9797932" target="_blank" rel="nofollow noopener">hacker news discussion</a> you can check out, as well as <a href="http://lists.dragonflybsd.org/pipermail/users/2015-June/207801.html" target="_blank" rel="nofollow noopener">upgrade instructions</a>
***</li>
</ul>

<h3><a href="https://opensmtpd.org/announces/release-5.7.1.txt" target="_blank" rel="nofollow noopener">OpenSMTPD 5.7.1 released</a></h3>

<ul>
<li>The OpenSMTPD guys have just released version 5.7.1, a major milestone version that we mentioned recently</li>
<li>Crypto-related bits have been vastly improved: the RSA engine is now privilege-separated, TLS errors are handled more gracefully, ciphers and curve preferences can now be specified, the PKI interface has been reworked to allow custom CAs, SNI and certificate verification have been simplified and the DH parameters are now 2048 bit by default</li>
<li>The long-awaited filter API is now enabled by default, though still considered slightly experimental</li>
<li>Documentation has been improved quite a bit, with more examples and common use cases (as well as exotic ones)</li>
<li>Many more small additions and bugfixes were made, so check the changelog for the full list</li>
<li>Starting with 5.7.1, releases are now <a href="https://twitter.com/OpenSMTPD/status/613257722574839808" target="_blank" rel="nofollow noopener">cryptographically</a> <a href="https://www.opensmtpd.org/archives/opensmtpd-5.7.1.sum.sig" target="_blank" rel="nofollow noopener">signed</a> to ensure integrity</li>
<li>This release has gone through some major stress testing to ensure stability - Gilles regularly asks their Twitter followers to <a href="https://twitter.com/OpenSMTPD/status/608399272447471616" target="_blank" rel="nofollow noopener">flood a test server</a> with thousands of emails per second, even <a href="https://twitter.com/OpenSMTPD/status/608235180839567360" target="_blank" rel="nofollow noopener">offering prizes</a> to whoever can DDoS them the hardest</li>
<li>OpenSMTPD runs on all the BSDs of course, and seems to be getting pretty popular lately</li>
<li>Let's all <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">encourage</a> Kris to stop procrastinating on switching from Postfix
***</li>
</ul>

<h2>Interview - Jun Ebihara (蛯原純) - <a href="mailto:jun@netbsd.org" target="_blank" rel="nofollow noopener">jun@netbsd.org</a> / <a href="https://twitter.com/ebijun" target="_blank" rel="nofollow noopener">@ebijun</a></h2>

<p>Lesser-known CPU architectures, embedded NetBSD devices</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-steven-douglas.html" target="_blank" rel="nofollow noopener">FreeBSD foundation at BSDCan</a></h3>

<ul>
<li>The FreeBSD foundation has posted a few BSDCan summaries on their blog</li>
<li>The first, from Steven Douglas, begins with a sentiment a lot of us can probably identify with: "Where I live, there are only a handful of people that even know what BSD is, let alone can talk at a high level about it. That was one of my favorite things, being around like minded people."</li>
<li>He got to meet a lot of the people working on big-name projects, and enjoyed being able to ask them questions so easily</li>
<li>Their <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-ahmed-kamal.html" target="_blank" rel="nofollow noopener">second</a> trip report is from Ahmed Kamal, who flew in all the way from Egypt</li>
<li>A bit starstruck, he seems to have enjoyed all the talks, particularly Andrew Tanenbaum's about MINIX and NetBSD</li>
<li>There are also two more wrap-ups from <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-zbigniew-bodek.html" target="_blank" rel="nofollow noopener">Zbigniew Bodek</a> and <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-vsevolod-stakhov.html" target="_blank" rel="nofollow noopener">Vsevolod Stakhov</a>, so you've got plenty to read
***</li>
</ul>

<h3><a href="http://cfenollosa.com/blog/openbsd-from-a-veteran-linux-user-perspective.html" target="_blank" rel="nofollow noopener">OpenBSD from a veteran Linux user perspective</a></h3>

<ul>
<li>In a new series of blog posts, a self-proclaimed veteran Linux user is giving OpenBSD a try for the first time</li>
<li>"For the first time I installed a BSD box on a machine I control. The experience has been eye-opening, especially since I consider myself an 'old-school' Linux admin, and I've felt out of place with the latest changes on the system administration."</li>
<li>The post is a collection of his thoughts about what's different between Linux and BSD, what surprised him as a beginner - admittedly, a lot of his knowledge carried over, and there were just minor differences in command flags</li>
<li>One of the things that surprised him (in a positive way) was the documentation: "OpenBSD's man pages are so nice that RTFMing somebody on the internet is not condescending but selfless."</li>
<li>He also goes through some of the basics, installing and updating software, following different branches</li>
<li>It concludes with "If you like UNIX, it will open your eyes to the fact that there is more than one way to do things, and that system administration can still be simple while modern."
***</li>
</ul>

<h3><a href="http://sysconfig.org.uk/freebsd-on-the-desktop-am-i-crazy.html" target="_blank" rel="nofollow noopener">FreeBSD on the desktop, am I crazy</a></h3>

<ul>
<li>Similar to the previous article, the guy that wrote the SSH two factor authentication post we covered last week has another new article up - this time about FreeBSD on the desktop</li>
<li>He begins with a bit of forewarning for potential Linux switchers: "It certainly wasn't an easy journey, and I'm tempted to say do not try this at home to anybody who isn't going to leverage any of FreeBSD's strong points. Definitely don't try FreeBSD on the desktop if you haven't used it on servers or virtual machines before. It's got less in common with Linux than you might think."</li>
<li>With that out of the way, the list of positives is pretty large: a tidy base system, separation between base and ports, having the option to choose binary packages or ports, ZFS, jails, licensing and of course the lack of systemd</li>
<li>The rest of the post talks about some of the hurdles he had to overcome, namely with graphics and the infamous Adobe Flash</li>
<li>Also worth noting is that he found jails to be not only good for isolating daemons on a server, but pretty useful for desktop applications as well</li>
<li>In the end, he says it was worth all the trouble, and is even planning on converting his laptop to FreeBSD soon too
***</li>
</ul>

<h3><a href="https://www.netflask.net/ipsec-ikev2-cisco-csr1000v-openiked/" target="_blank" rel="nofollow noopener">OpenIKED and Cisco CSR 1000v IPSEC</a></h3>

<ul>
<li>This article covers setting up a site-to-site IPSEC tunnel between a Cisco CSR 1000v router and an OpenBSD gateway running OpenIKED</li>
<li>What kind of networking blog post would be complete without a diagram where the internet is represented by a big cloud</li>
<li>There are lots of details (and example configuration files) for using IKEv2 and OpenBSD's built-in IKE daemon</li>
<li>It also goes to show that the BSDs generally play well with existing network infrastructure, so if you were a business that's afraid to try them… don't be
***</li>
</ul>

<h3><a href="https://github.com/HardenedBSD/hardenedBSD/commit/bd5cecb4dc7947a5e214fc100834399b4bffdee8" target="_blank" rel="nofollow noopener">HardenedBSD improves stack randomization</a></h3>

<ul>
<li>The HardenedBSD guys have improved their FreeBSD ASLR patchset, specifically in the stack randomization area</li>
<li>In their initial implementation, the stack randomization was a random gap - this update makes the base address randomized as well</li>
<li>They're now stacking the new on top of the old as well, with the goal being even more entropy</li>
<li>This change triggered an ABI and API incompatibility, so their major version has been bumped
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2015-July/000121.html" target="_blank" rel="nofollow noopener">OpenSSH 6.9 released</a></h3>

<ul>
<li>The OpenSSH team has announced the release of a new version which, following their tick/tock major/minor release cycle, is focused mainly on bug fixes</li>
<li>There are a couple new things though - the "AuthorizedKeysCommand" config option now takes custom arguments</li>
<li>One very notable change is that <strong>the default cipher has changed</strong> as of this release</li>
<li>The traditional pairing of AES128 in counter mode with MD5 HMAC has been <em>replaced</em> by the ever-trendy ChaCha20-Poly1305 combo</li>
<li>Their next release, 7.0, is set to get rid a number of legacy items: PermitRootLogin will be switched to "no" by default, SSHv1 support will be totally disabled, the 1024bit diffie-hellman-group1-sha1 KEX will be disabled, old ssh-dss and v00 certs will be removed, a number of weak ciphers will be disabled by default (including all CBC ones) and RSA keys will be refused if they're under 1024 bits</li>
<li>Many small bugs fixes and improvements were also made, so check the announcement for everything else</li>
<li>The native version is in OpenBSD -current, and an update to the portable version should be hitting a ports or pkgsrc tree near you soon
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2Ws6Y2rZy" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21GvZ5xbs" target="_blank" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s209TrPK4e" target="_blank" rel="nofollow noopener">Jochen writes in</a></li>
<li><a href="http://slexy.org/view/s21TQjUjxv" target="_blank" rel="nofollow noopener">Simon writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week, we'll be talking with Jun Ebihara about some lesser-known CPU architectures in NetBSD. He'll tell us what makes these old (and often forgotten) machines so interesting. As usual, we've also got answers to your emails and all this week's news on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.tedunangst.com/flak/post/out-with-the-old-in-with-the-less" target="_blank" rel="nofollow noopener">Out with the old, in with the less</a></h3>

<ul>
<li>Our friend Ted Unangst has a new article up, talking about "various OpenBSD replacements and reductions"</li>
<li>"Instead of trying to fix known bugs, we’re trying to fix unknown bugs. It’s not based on the current buggy state of the code, but the anticipated future buggy state of the code. Past bugs are a bigger factor than current bugs."</li>
<li>In the post, he goes through some of the bigger (and smaller) examples of OpenBSD rewriting tools to be simpler and more secure</li>
<li>It starts off with a lesser-known SCSI driver that "tried to do too much" being replaced with three separate drivers</li>
<li>"Each driver can now be modified in isolation without unintentional side effects on other hardware, or the need to consider if and where further special cases need to be added. Despite the fact that these three drivers duplicate all the common boilerplate code, combined they only amount to about half as much code as the old driver."</li>
<li>In contrast to that example, he goes on to cite mandoc as taking a very non "unixy" direction, but at the same time being smaller and simpler than all the tools it replaced</li>
<li>The next case is the new http daemon, and he talks a bit about the recently-added rewrite support being done in a simple and secure way (as opposed to regex and its craziness)</li>
<li>He also talks about the rewritten "file" utility: "Almost by definition, its sole input will be untrusted input. Perversely, people will then trust what file tells them and then go about using that input, as if file somehow sanitized it."</li>
<li>Finally, sudo in OpenBSD's base system is moving to ports soon, and the article briefly describes a new tool that <a href="https://marc.info/?l=openbsd-ports&amp;m=143481227122523&amp;w=2" target="_blank" rel="nofollow noopener">may or may not replace it</a>, called "doas"</li>
<li>There's also a nice wrap-up of all the examples at the end, and the "<a href="http://www.openbsd.org/papers/pruning.html" target="_blank" rel="nofollow noopener">Pruning and Polishing</a>" talk is good complementary reading material
***</li>
</ul>

<h3><a href="https://www.youtube.com/channel/UC0IK6Y4Go2KtRueHDiQcxow/videos" target="_blank" rel="nofollow noopener">More OpenZFS and BSDCan videos</a></h3>

<ul>
<li>We mentioned <a href="http://www.bsdnow.tv/episodes/2015_06_24-bitrot_group_therapy" target="_blank" rel="nofollow noopener">last week</a> that some of the videos from the second OpenZFS conference in Europe were being uploaded - here's some more</li>
<li>Matt Ahrens did <a href="https://www.youtube.com/watch?v=I6fXZ_6OT5c" target="_blank" rel="nofollow noopener">a Q&amp;A session</a> and talked about ZFS <a href="https://www.youtube.com/watch?v=iY44jPMvxog" target="_blank" rel="nofollow noopener">send and receive</a>, as well as giving an <a href="https://www.youtube.com/watch?v=RQlMDmnty80" target="_blank" rel="nofollow noopener">overview of OpenZFS</a></li>
<li>George Wilson talked about a <a href="https://www.youtube.com/watch?v=KBI6rRGUv4E" target="_blank" rel="nofollow noopener">performance retrospective</a></li>
<li><a href="https://www.youtube.com/watch?v=sSi47-k78IM" target="_blank" rel="nofollow noopener">Toshiba</a>, <a href="https://www.youtube.com/watch?v=Hhje5KEF5cE" target="_blank" rel="nofollow noopener">Syneto</a> and <a href="https://www.youtube.com/watch?v=aKgxXipss8k" target="_blank" rel="nofollow noopener">HGST</a> also gave some talks about their companies and how they're using ZFS</li>
<li>As for BSDCan, more of their BSD presentations have been uploaded too...</li>
<li>Ryan Stone, <a href="https://www.youtube.com/watch?v=INeMd-i5jzM" target="_blank" rel="nofollow noopener">PCI SR-IOV on FreeBSD</a></li>
<li>George Neville-Neil, <a href="https://www.youtube.com/watch?v=LE4wMsP7zeA" target="_blank" rel="nofollow noopener">Measure Twice, Code Once</a></li>
<li>Kris Moore, <a href="https://www.youtube.com/watch?v=qNYXqpJiFN0" target="_blank" rel="nofollow noopener">Unifying jail and package management for PC-BSD, FreeNAS and FreeBSD</a></li>
<li>Warner Losh, <a href="https://www.youtube.com/watch?v=3WqOLolj5EU" target="_blank" rel="nofollow noopener">I/O Scheduling in CAM</a></li>
<li>Kirk McKusick, <a href="https://www.youtube.com/watch?v=l-RCLgLxuSc" target="_blank" rel="nofollow noopener">An Introduction to the Implementation of ZFS</a></li>
<li>Midori Kato, <a href="https://www.youtube.com/watch?v=zZXvjhWcg_4" target="_blank" rel="nofollow noopener">Extensions to FreeBSD Datacenter TCP for Incremental Deployment Support</a></li>
<li>Baptiste Daroussin, <a href="https://www.youtube.com/watch?v=Br6izhH5P1I" target="_blank" rel="nofollow noopener">Packaging FreeBSD's</a> <a href="https://www.youtube.com/watch?v=v7px6ktoDAI" target="_blank" rel="nofollow noopener">base system</a></li>
<li>Matt Ahrens, <a href="https://www.youtube.com/watch?v=UOX7WDAjqso" target="_blank" rel="nofollow noopener">New OpenZFS features supporting remote replication</a></li>
<li>Ed Schouten, <a href="https://www.youtube.com/watch?v=SVdF84x1EdA" target="_blank" rel="nofollow noopener">CloudABI Cloud computing meets fine-grained capabilities</a></li>
<li>The audio of Ingo Schwarze's talk "mandoc: becoming the main BSD manual toolbox" got messed up, but there's an alternate recording <a href="http://www.bsdcan.org/2015/audio/mandoc.mp3" target="_blank" rel="nofollow noopener">here</a>, and the slides are <a href="http://www.openbsd.org/papers/bsdcan15-mandoc.pdf" target="_blank" rel="nofollow noopener">here</a>
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=143526329006942&amp;w=2" target="_blank" rel="nofollow noopener">SMP steroids for PF</a></h3>

<ul>
<li>An Oracle employee that's been porting OpenBSD's PF to an upcoming Solaris release has sent in an interesting patch for review</li>
<li>Attached to the mail was what may be the beginnings of making native PF SMP-aware</li>
<li>Before you start partying, the road to SMP (specifically, giant lock removal) is a long and very complicated one, requiring every relevant bit of the stack to be written with it in mind - this is just one piece of the puzzle</li>
<li>The <a href="https://www.marc.info/?l=openbsd-tech&amp;m=143532243322281&amp;w=2" target="_blank" rel="nofollow noopener">initial response</a> has been quite positive though, with some <a href="https://www.marc.info/?l=openbsd-tech&amp;m=143532963824548&amp;w=2" target="_blank" rel="nofollow noopener">back and forth</a> between developers and the submitter</li>
<li>For now, let's be patient and see what happens
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/release42/" target="_blank" rel="nofollow noopener">DragonFly 4.2.0 released</a></h3>

<ul>
<li>DragonFlyBSD has released the next big update of their 4.x branch, complete with a decent amount of new features and fixes</li>
<li>i915 and Radeon graphics have been updated, and DragonFly can claim the title of first BSD with Broadwell support in a release</li>
<li>Sendmail in the base system has been replaced with their homegrown DragonFly Mail Agent, and there's <a href="http://www.dragonflybsd.com/docs/docs/newhandbook/mta/" target="_blank" rel="nofollow noopener">a wiki page</a> about configuring it</li>
<li>They've also switched the default compiler to GCC 5, though why they've gone in that direction instead of embracing Clang is a mystery</li>
<li>The announcement page also contains a list of kernel changes, details on the audio and graphics updates, removal of the SCTP protocol, improvements to the temperature sensors, various userland utility fixes and a list of updates to third party tools</li>
<li>Work is continuing on the second generation HAMMER filesystem, and Matt Dillon provides a status update in the release announcement</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9797932" target="_blank" rel="nofollow noopener">hacker news discussion</a> you can check out, as well as <a href="http://lists.dragonflybsd.org/pipermail/users/2015-June/207801.html" target="_blank" rel="nofollow noopener">upgrade instructions</a>
***</li>
</ul>

<h3><a href="https://opensmtpd.org/announces/release-5.7.1.txt" target="_blank" rel="nofollow noopener">OpenSMTPD 5.7.1 released</a></h3>

<ul>
<li>The OpenSMTPD guys have just released version 5.7.1, a major milestone version that we mentioned recently</li>
<li>Crypto-related bits have been vastly improved: the RSA engine is now privilege-separated, TLS errors are handled more gracefully, ciphers and curve preferences can now be specified, the PKI interface has been reworked to allow custom CAs, SNI and certificate verification have been simplified and the DH parameters are now 2048 bit by default</li>
<li>The long-awaited filter API is now enabled by default, though still considered slightly experimental</li>
<li>Documentation has been improved quite a bit, with more examples and common use cases (as well as exotic ones)</li>
<li>Many more small additions and bugfixes were made, so check the changelog for the full list</li>
<li>Starting with 5.7.1, releases are now <a href="https://twitter.com/OpenSMTPD/status/613257722574839808" target="_blank" rel="nofollow noopener">cryptographically</a> <a href="https://www.opensmtpd.org/archives/opensmtpd-5.7.1.sum.sig" target="_blank" rel="nofollow noopener">signed</a> to ensure integrity</li>
<li>This release has gone through some major stress testing to ensure stability - Gilles regularly asks their Twitter followers to <a href="https://twitter.com/OpenSMTPD/status/608399272447471616" target="_blank" rel="nofollow noopener">flood a test server</a> with thousands of emails per second, even <a href="https://twitter.com/OpenSMTPD/status/608235180839567360" target="_blank" rel="nofollow noopener">offering prizes</a> to whoever can DDoS them the hardest</li>
<li>OpenSMTPD runs on all the BSDs of course, and seems to be getting pretty popular lately</li>
<li>Let's all <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">encourage</a> Kris to stop procrastinating on switching from Postfix
***</li>
</ul>

<h2>Interview - Jun Ebihara (蛯原純) - <a href="mailto:jun@netbsd.org" target="_blank" rel="nofollow noopener">jun@netbsd.org</a> / <a href="https://twitter.com/ebijun" target="_blank" rel="nofollow noopener">@ebijun</a></h2>

<p>Lesser-known CPU architectures, embedded NetBSD devices</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-steven-douglas.html" target="_blank" rel="nofollow noopener">FreeBSD foundation at BSDCan</a></h3>

<ul>
<li>The FreeBSD foundation has posted a few BSDCan summaries on their blog</li>
<li>The first, from Steven Douglas, begins with a sentiment a lot of us can probably identify with: "Where I live, there are only a handful of people that even know what BSD is, let alone can talk at a high level about it. That was one of my favorite things, being around like minded people."</li>
<li>He got to meet a lot of the people working on big-name projects, and enjoyed being able to ask them questions so easily</li>
<li>Their <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-ahmed-kamal.html" target="_blank" rel="nofollow noopener">second</a> trip report is from Ahmed Kamal, who flew in all the way from Egypt</li>
<li>A bit starstruck, he seems to have enjoyed all the talks, particularly Andrew Tanenbaum's about MINIX and NetBSD</li>
<li>There are also two more wrap-ups from <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-zbigniew-bodek.html" target="_blank" rel="nofollow noopener">Zbigniew Bodek</a> and <a href="http://freebsdfoundation.blogspot.com/2015/06/bsdcan-2015-trip-report-vsevolod-stakhov.html" target="_blank" rel="nofollow noopener">Vsevolod Stakhov</a>, so you've got plenty to read
***</li>
</ul>

<h3><a href="http://cfenollosa.com/blog/openbsd-from-a-veteran-linux-user-perspective.html" target="_blank" rel="nofollow noopener">OpenBSD from a veteran Linux user perspective</a></h3>

<ul>
<li>In a new series of blog posts, a self-proclaimed veteran Linux user is giving OpenBSD a try for the first time</li>
<li>"For the first time I installed a BSD box on a machine I control. The experience has been eye-opening, especially since I consider myself an 'old-school' Linux admin, and I've felt out of place with the latest changes on the system administration."</li>
<li>The post is a collection of his thoughts about what's different between Linux and BSD, what surprised him as a beginner - admittedly, a lot of his knowledge carried over, and there were just minor differences in command flags</li>
<li>One of the things that surprised him (in a positive way) was the documentation: "OpenBSD's man pages are so nice that RTFMing somebody on the internet is not condescending but selfless."</li>
<li>He also goes through some of the basics, installing and updating software, following different branches</li>
<li>It concludes with "If you like UNIX, it will open your eyes to the fact that there is more than one way to do things, and that system administration can still be simple while modern."
***</li>
</ul>

<h3><a href="http://sysconfig.org.uk/freebsd-on-the-desktop-am-i-crazy.html" target="_blank" rel="nofollow noopener">FreeBSD on the desktop, am I crazy</a></h3>

<ul>
<li>Similar to the previous article, the guy that wrote the SSH two factor authentication post we covered last week has another new article up - this time about FreeBSD on the desktop</li>
<li>He begins with a bit of forewarning for potential Linux switchers: "It certainly wasn't an easy journey, and I'm tempted to say do not try this at home to anybody who isn't going to leverage any of FreeBSD's strong points. Definitely don't try FreeBSD on the desktop if you haven't used it on servers or virtual machines before. It's got less in common with Linux than you might think."</li>
<li>With that out of the way, the list of positives is pretty large: a tidy base system, separation between base and ports, having the option to choose binary packages or ports, ZFS, jails, licensing and of course the lack of systemd</li>
<li>The rest of the post talks about some of the hurdles he had to overcome, namely with graphics and the infamous Adobe Flash</li>
<li>Also worth noting is that he found jails to be not only good for isolating daemons on a server, but pretty useful for desktop applications as well</li>
<li>In the end, he says it was worth all the trouble, and is even planning on converting his laptop to FreeBSD soon too
***</li>
</ul>

<h3><a href="https://www.netflask.net/ipsec-ikev2-cisco-csr1000v-openiked/" target="_blank" rel="nofollow noopener">OpenIKED and Cisco CSR 1000v IPSEC</a></h3>

<ul>
<li>This article covers setting up a site-to-site IPSEC tunnel between a Cisco CSR 1000v router and an OpenBSD gateway running OpenIKED</li>
<li>What kind of networking blog post would be complete without a diagram where the internet is represented by a big cloud</li>
<li>There are lots of details (and example configuration files) for using IKEv2 and OpenBSD's built-in IKE daemon</li>
<li>It also goes to show that the BSDs generally play well with existing network infrastructure, so if you were a business that's afraid to try them… don't be
***</li>
</ul>

<h3><a href="https://github.com/HardenedBSD/hardenedBSD/commit/bd5cecb4dc7947a5e214fc100834399b4bffdee8" target="_blank" rel="nofollow noopener">HardenedBSD improves stack randomization</a></h3>

<ul>
<li>The HardenedBSD guys have improved their FreeBSD ASLR patchset, specifically in the stack randomization area</li>
<li>In their initial implementation, the stack randomization was a random gap - this update makes the base address randomized as well</li>
<li>They're now stacking the new on top of the old as well, with the goal being even more entropy</li>
<li>This change triggered an ABI and API incompatibility, so their major version has been bumped
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-announce/2015-July/000121.html" target="_blank" rel="nofollow noopener">OpenSSH 6.9 released</a></h3>

<ul>
<li>The OpenSSH team has announced the release of a new version which, following their tick/tock major/minor release cycle, is focused mainly on bug fixes</li>
<li>There are a couple new things though - the "AuthorizedKeysCommand" config option now takes custom arguments</li>
<li>One very notable change is that <strong>the default cipher has changed</strong> as of this release</li>
<li>The traditional pairing of AES128 in counter mode with MD5 HMAC has been <em>replaced</em> by the ever-trendy ChaCha20-Poly1305 combo</li>
<li>Their next release, 7.0, is set to get rid a number of legacy items: PermitRootLogin will be switched to "no" by default, SSHv1 support will be totally disabled, the 1024bit diffie-hellman-group1-sha1 KEX will be disabled, old ssh-dss and v00 certs will be removed, a number of weak ciphers will be disabled by default (including all CBC ones) and RSA keys will be refused if they're under 1024 bits</li>
<li>Many small bugs fixes and improvements were also made, so check the announcement for everything else</li>
<li>The native version is in OpenBSD -current, and an update to the portable version should be hitting a ports or pkgsrc tree near you soon
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2Ws6Y2rZy" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21GvZ5xbs" target="_blank" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s209TrPK4e" target="_blank" rel="nofollow noopener">Jochen writes in</a></li>
<li><a href="http://slexy.org/view/s21TQjUjxv" target="_blank" rel="nofollow noopener">Simon writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>94: Builder's Insurance</title>
  <link>https://www.bsdnow.tv/94</link>
  <guid isPermaLink="false">62d29419-94fa-4252-89a9-581546c7e61d</guid>
  <pubDate>Wed, 17 Jun 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/62d29419-94fa-4252-89a9-581546c7e61d.mp3" length="61384180" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:25:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2015/schedule/" target="_blank" rel="nofollow noopener"&gt;BSDCan 2015 videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSDCan just ended last week, but some of the BSD-related presentation videos are already online&lt;/li&gt;
&lt;li&gt;Allan Jude, &lt;a href="https://www.youtube.com/watch?v=8l6bhKIDecg" target="_blank" rel="nofollow noopener"&gt;UCL for FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andrew Cagney, &lt;a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" target="_blank" rel="nofollow noopener"&gt;What happens when a dwarf and a daemon start dancing by the light of the silvery moon?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andy Tanenbaum, &lt;a href="https://www.youtube.com/watch?v=0pebP891V0c" target="_blank" rel="nofollow noopener"&gt;A reimplementation of NetBSD&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" target="_blank" rel="nofollow noopener"&gt;using a MicroKernel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brooks Davis, &lt;a href="https://www.youtube.com/watch?v=DwCg-51vFAs" target="_blank" rel="nofollow noopener"&gt;CheriBSD: A research fork of FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Giuseppe Lettieri, &lt;a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" target="_blank" rel="nofollow noopener"&gt;Even faster VM networking with virtual passthrough&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Joseph Mingrone, &lt;a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" target="_blank" rel="nofollow noopener"&gt;Molecular Evolution, Genomic Analysis and FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Olivier Cochard-Labbe, &lt;a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" target="_blank" rel="nofollow noopener"&gt;Large-scale plug&amp;amp;play x86 network appliance deployment over Internet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Peter Hessler, &lt;a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" target="_blank" rel="nofollow noopener"&gt;Using routing domains / routing tables in a production network&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ryan Lortie, &lt;a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" target="_blank" rel="nofollow noopener"&gt;a stitch in time: jhbuild&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ted Unangst, &lt;a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" target="_blank" rel="nofollow noopener"&gt;signify: Securing OpenBSD From Us To You&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Many more still to come...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://pid1.com/posts/post1.html" target="_blank" rel="nofollow noopener"&gt;Documenting my BSD experience&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try&lt;/li&gt;
&lt;li&gt;"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."&lt;/li&gt;
&lt;li&gt;In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks&lt;/li&gt;
&lt;li&gt;The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)&lt;/li&gt;
&lt;li&gt;You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into&lt;/li&gt;
&lt;li&gt;He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon&lt;/li&gt;
&lt;li&gt;His &lt;a href="http://pid1.com/posts/post2.html" target="_blank" rel="nofollow noopener"&gt;second post&lt;/a&gt; explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box&lt;/li&gt;
&lt;li&gt;After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing&lt;/li&gt;
&lt;li&gt;All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand&lt;/li&gt;
&lt;li&gt;Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/pcbsd/hardenedBSD-stable" target="_blank" rel="nofollow noopener"&gt;PC-BSD tries HardenedBSD builds&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated&lt;/li&gt;
&lt;li&gt;They're not the first major FreeBSD-based project to offer an alternate build - OPNsense &lt;a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" target="_blank" rel="nofollow noopener"&gt;did that&lt;/a&gt; a few weeks ago - but this might open the door for more projects to give it a try as well&lt;/li&gt;
&lt;li&gt;With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have&lt;/li&gt;
&lt;li&gt;Time will tell if more projects and products like FreeNAS might be interested too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=143423172522625&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;C-states in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;People who run BSD on their notebooks, you'll want to pay attention to this one&lt;/li&gt;
&lt;li&gt;OpenBSD has recently committed some ACPI improvements for &lt;a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" target="_blank" rel="nofollow noopener"&gt;deep C-states&lt;/a&gt;, enabling the processor to enter a low-power mode&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/StevenUniq/status/610586711358316545" target="_blank" rel="nofollow noopener"&gt;According&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143430996602802&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;to a&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143429914700826&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;few users&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143425943026225&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;so far&lt;/a&gt;, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life&lt;/li&gt;
&lt;li&gt;If you're running OpenBSD -current on a laptop, try out the latest snapshot and &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143423391222952&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;report back&lt;/a&gt; with your findings
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" target="_blank" rel="nofollow noopener"&gt;NetBSD at Open Source Conference 2015 Hokkaido&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference&lt;/li&gt;
&lt;li&gt;As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)&lt;/li&gt;
&lt;li&gt;We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Marc Espie - &lt;a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener"&gt;espie@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener"&gt;@espie_openbsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=143051151521627&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;Recent&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=143151777209226&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;improvements&lt;/a&gt; to OpenBSD's &lt;a href="http://www.bsdnow.tv/tutorials/dpb" target="_blank" rel="nofollow noopener"&gt;dpb&lt;/a&gt; tool&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/mist64/xhyve/blob/master/README.md" target="_blank" rel="nofollow noopener"&gt;Introducing xhyve, bhyve on OS X&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS&lt;/li&gt;
&lt;li&gt;As the name "xhyve" might imply, it's a port of bhyve to Mac OS X &lt;/li&gt;
&lt;li&gt;Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future&lt;/li&gt;
&lt;li&gt;It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer&lt;/li&gt;
&lt;li&gt;There are also &lt;a href="http://www.pagetable.com/?p=831" target="_blank" rel="nofollow noopener"&gt;a few examples&lt;/a&gt; on how to use it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" target="_blank" rel="nofollow noopener"&gt;4K displays on DragonFlyBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine&lt;/li&gt;
&lt;li&gt;Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas&lt;/li&gt;
&lt;li&gt;Some GUI applications might look weird on such a huge resolution, &lt;/li&gt;
&lt;li&gt;HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" target="_blank" rel="nofollow noopener"&gt;Sandboxing port daemons on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment&lt;/li&gt;
&lt;li&gt;This blog post uses a mumble server as an example, but you can apply it to &lt;em&gt;any&lt;/em&gt; service from ports that doesn't chroot by default&lt;/li&gt;
&lt;li&gt;It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it&lt;/li&gt;
&lt;li&gt;With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" target="_blank" rel="nofollow noopener"&gt;SmallWall 1.8.2 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SmallWall is a relatively new BSD-based project that we've never covered before&lt;/li&gt;
&lt;li&gt;It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits&lt;/li&gt;
&lt;li&gt;They've just released &lt;a href="http://www.smallwall.org/download.html" target="_blank" rel="nofollow noopener"&gt;the first official version&lt;/a&gt;, so you can give it a try now&lt;/li&gt;
&lt;li&gt;If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21gRTNnk7" target="_blank" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DdiMvELg" target="_blank" rel="nofollow noopener"&gt;Brian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2h4ZS6SMd" target="_blank" rel="nofollow noopener"&gt;Dan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20kA1jeXY" target="_blank" rel="nofollow noopener"&gt;Joel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2wJ9HP1bs" target="_blank" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, dpb, poudriere, pbulk, packages, ports, distributed, bsdcan, pf, zfs, opnsense, pfsense, hardenedbsd, aslr, smallwall, m0n0wall, xhyve, bhyve</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" target="_blank" rel="nofollow noopener">BSDCan 2015 videos</a></h3>

<ul>
<li>BSDCan just ended last week, but some of the BSD-related presentation videos are already online</li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=8l6bhKIDecg" target="_blank" rel="nofollow noopener">UCL for FreeBSD</a></li>
<li>Andrew Cagney, <a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" target="_blank" rel="nofollow noopener">What happens when a dwarf and a daemon start dancing by the light of the silvery moon?</a></li>
<li>Andy Tanenbaum, <a href="https://www.youtube.com/watch?v=0pebP891V0c" target="_blank" rel="nofollow noopener">A reimplementation of NetBSD</a> <a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" target="_blank" rel="nofollow noopener">using a MicroKernel</a></li>
<li>Brooks Davis, <a href="https://www.youtube.com/watch?v=DwCg-51vFAs" target="_blank" rel="nofollow noopener">CheriBSD: A research fork of FreeBSD</a></li>
<li>Giuseppe Lettieri, <a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" target="_blank" rel="nofollow noopener">Even faster VM networking with virtual passthrough</a></li>
<li>Joseph Mingrone, <a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" target="_blank" rel="nofollow noopener">Molecular Evolution, Genomic Analysis and FreeBSD</a></li>
<li>Olivier Cochard-Labbe, <a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" target="_blank" rel="nofollow noopener">Large-scale plug&amp;play x86 network appliance deployment over Internet</a></li>
<li>Peter Hessler, <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" target="_blank" rel="nofollow noopener">Using routing domains / routing tables in a production network</a></li>
<li>Ryan Lortie, <a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" target="_blank" rel="nofollow noopener">a stitch in time: jhbuild</a></li>
<li>Ted Unangst, <a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" target="_blank" rel="nofollow noopener">signify: Securing OpenBSD From Us To You</a></li>
<li>Many more still to come...
***</li>
</ul>

<h3><a href="http://pid1.com/posts/post1.html" target="_blank" rel="nofollow noopener">Documenting my BSD experience</a></h3>

<ul>
<li>Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try</li>
<li>"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."</li>
<li>In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks</li>
<li>The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)</li>
<li>You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into</li>
<li>He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon</li>
<li>His <a href="http://pid1.com/posts/post2.html" target="_blank" rel="nofollow noopener">second post</a> explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box</li>
<li>After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing</li>
<li>All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand</li>
<li>Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/hardenedBSD-stable" target="_blank" rel="nofollow noopener">PC-BSD tries HardenedBSD builds</a></h3>

<ul>
<li>The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated</li>
<li>They're not the first major FreeBSD-based project to offer an alternate build - OPNsense <a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" target="_blank" rel="nofollow noopener">did that</a> a few weeks ago - but this might open the door for more projects to give it a try as well</li>
<li>With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have</li>
<li>Time will tell if more projects and products like FreeNAS might be interested too
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143423172522625&amp;w=2" target="_blank" rel="nofollow noopener">C-states in OpenBSD</a></h3>

<ul>
<li>People who run BSD on their notebooks, you'll want to pay attention to this one</li>
<li>OpenBSD has recently committed some ACPI improvements for <a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" target="_blank" rel="nofollow noopener">deep C-states</a>, enabling the processor to enter a low-power mode</li>
<li><a href="https://twitter.com/StevenUniq/status/610586711358316545" target="_blank" rel="nofollow noopener">According</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143430996602802&amp;w=2" target="_blank" rel="nofollow noopener">to a</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143429914700826&amp;w=2" target="_blank" rel="nofollow noopener">few users</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143425943026225&amp;w=2" target="_blank" rel="nofollow noopener">so far</a>, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life</li>
<li>If you're running OpenBSD -current on a laptop, try out the latest snapshot and <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143423391222952&amp;w=2" target="_blank" rel="nofollow noopener">report back</a> with your findings
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" target="_blank" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Hokkaido</a></h3>

<ul>
<li>The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference</li>
<li>As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)</li>
<li>We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener">@espie_openbsd</a></h2>

<p><a href="https://www.marc.info/?l=openbsd-ports&amp;m=143051151521627&amp;w=2" target="_blank" rel="nofollow noopener">Recent</a> <a href="https://www.marc.info/?l=openbsd-ports&amp;m=143151777209226&amp;w=2" target="_blank" rel="nofollow noopener">improvements</a> to OpenBSD's <a href="http://www.bsdnow.tv/tutorials/dpb" target="_blank" rel="nofollow noopener">dpb</a> tool</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/mist64/xhyve/blob/master/README.md" target="_blank" rel="nofollow noopener">Introducing xhyve, bhyve on OS X</a></h3>

<ul>
<li>We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS</li>
<li>As the name "xhyve" might imply, it's a port of bhyve to Mac OS X </li>
<li>Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future</li>
<li>It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer</li>
<li>There are also <a href="http://www.pagetable.com/?p=831" target="_blank" rel="nofollow noopener">a few examples</a> on how to use it
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" target="_blank" rel="nofollow noopener">4K displays on DragonFlyBSD</a></h3>

<ul>
<li>If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine</li>
<li>Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas</li>
<li>Some GUI applications might look weird on such a huge resolution, </li>
<li>HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***</li>
</ul>

<h3><a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" target="_blank" rel="nofollow noopener">Sandboxing port daemons on OpenBSD</a></h3>

<ul>
<li>We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment</li>
<li>This blog post uses a mumble server as an example, but you can apply it to <em>any</em> service from ports that doesn't chroot by default</li>
<li>It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it</li>
<li>With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***</li>
</ul>

<h3><a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" target="_blank" rel="nofollow noopener">SmallWall 1.8.2 released</a></h3>

<ul>
<li>SmallWall is a relatively new BSD-based project that we've never covered before</li>
<li>It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits</li>
<li>They've just released <a href="http://www.smallwall.org/download.html" target="_blank" rel="nofollow noopener">the first official version</a>, so you can give it a try now</li>
<li>If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21gRTNnk7" target="_blank" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DdiMvELg" target="_blank" rel="nofollow noopener">Brian writes in</a></li>
<li><a href="http://slexy.org/view/s2h4ZS6SMd" target="_blank" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s20kA1jeXY" target="_blank" rel="nofollow noopener">Joel writes in</a></li>
<li><a href="http://slexy.org/view/s2wJ9HP1bs" target="_blank" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" target="_blank" rel="nofollow noopener">BSDCan 2015 videos</a></h3>

<ul>
<li>BSDCan just ended last week, but some of the BSD-related presentation videos are already online</li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=8l6bhKIDecg" target="_blank" rel="nofollow noopener">UCL for FreeBSD</a></li>
<li>Andrew Cagney, <a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" target="_blank" rel="nofollow noopener">What happens when a dwarf and a daemon start dancing by the light of the silvery moon?</a></li>
<li>Andy Tanenbaum, <a href="https://www.youtube.com/watch?v=0pebP891V0c" target="_blank" rel="nofollow noopener">A reimplementation of NetBSD</a> <a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" target="_blank" rel="nofollow noopener">using a MicroKernel</a></li>
<li>Brooks Davis, <a href="https://www.youtube.com/watch?v=DwCg-51vFAs" target="_blank" rel="nofollow noopener">CheriBSD: A research fork of FreeBSD</a></li>
<li>Giuseppe Lettieri, <a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" target="_blank" rel="nofollow noopener">Even faster VM networking with virtual passthrough</a></li>
<li>Joseph Mingrone, <a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" target="_blank" rel="nofollow noopener">Molecular Evolution, Genomic Analysis and FreeBSD</a></li>
<li>Olivier Cochard-Labbe, <a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" target="_blank" rel="nofollow noopener">Large-scale plug&amp;play x86 network appliance deployment over Internet</a></li>
<li>Peter Hessler, <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" target="_blank" rel="nofollow noopener">Using routing domains / routing tables in a production network</a></li>
<li>Ryan Lortie, <a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" target="_blank" rel="nofollow noopener">a stitch in time: jhbuild</a></li>
<li>Ted Unangst, <a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" target="_blank" rel="nofollow noopener">signify: Securing OpenBSD From Us To You</a></li>
<li>Many more still to come...
***</li>
</ul>

<h3><a href="http://pid1.com/posts/post1.html" target="_blank" rel="nofollow noopener">Documenting my BSD experience</a></h3>

<ul>
<li>Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try</li>
<li>"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."</li>
<li>In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks</li>
<li>The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)</li>
<li>You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into</li>
<li>He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon</li>
<li>His <a href="http://pid1.com/posts/post2.html" target="_blank" rel="nofollow noopener">second post</a> explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box</li>
<li>After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing</li>
<li>All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand</li>
<li>Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/hardenedBSD-stable" target="_blank" rel="nofollow noopener">PC-BSD tries HardenedBSD builds</a></h3>

<ul>
<li>The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated</li>
<li>They're not the first major FreeBSD-based project to offer an alternate build - OPNsense <a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" target="_blank" rel="nofollow noopener">did that</a> a few weeks ago - but this might open the door for more projects to give it a try as well</li>
<li>With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have</li>
<li>Time will tell if more projects and products like FreeNAS might be interested too
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143423172522625&amp;w=2" target="_blank" rel="nofollow noopener">C-states in OpenBSD</a></h3>

<ul>
<li>People who run BSD on their notebooks, you'll want to pay attention to this one</li>
<li>OpenBSD has recently committed some ACPI improvements for <a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" target="_blank" rel="nofollow noopener">deep C-states</a>, enabling the processor to enter a low-power mode</li>
<li><a href="https://twitter.com/StevenUniq/status/610586711358316545" target="_blank" rel="nofollow noopener">According</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143430996602802&amp;w=2" target="_blank" rel="nofollow noopener">to a</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143429914700826&amp;w=2" target="_blank" rel="nofollow noopener">few users</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143425943026225&amp;w=2" target="_blank" rel="nofollow noopener">so far</a>, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life</li>
<li>If you're running OpenBSD -current on a laptop, try out the latest snapshot and <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143423391222952&amp;w=2" target="_blank" rel="nofollow noopener">report back</a> with your findings
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" target="_blank" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Hokkaido</a></h3>

<ul>
<li>The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference</li>
<li>As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)</li>
<li>We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener">@espie_openbsd</a></h2>

<p><a href="https://www.marc.info/?l=openbsd-ports&amp;m=143051151521627&amp;w=2" target="_blank" rel="nofollow noopener">Recent</a> <a href="https://www.marc.info/?l=openbsd-ports&amp;m=143151777209226&amp;w=2" target="_blank" rel="nofollow noopener">improvements</a> to OpenBSD's <a href="http://www.bsdnow.tv/tutorials/dpb" target="_blank" rel="nofollow noopener">dpb</a> tool</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/mist64/xhyve/blob/master/README.md" target="_blank" rel="nofollow noopener">Introducing xhyve, bhyve on OS X</a></h3>

<ul>
<li>We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS</li>
<li>As the name "xhyve" might imply, it's a port of bhyve to Mac OS X </li>
<li>Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future</li>
<li>It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer</li>
<li>There are also <a href="http://www.pagetable.com/?p=831" target="_blank" rel="nofollow noopener">a few examples</a> on how to use it
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" target="_blank" rel="nofollow noopener">4K displays on DragonFlyBSD</a></h3>

<ul>
<li>If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine</li>
<li>Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas</li>
<li>Some GUI applications might look weird on such a huge resolution, </li>
<li>HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***</li>
</ul>

<h3><a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" target="_blank" rel="nofollow noopener">Sandboxing port daemons on OpenBSD</a></h3>

<ul>
<li>We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment</li>
<li>This blog post uses a mumble server as an example, but you can apply it to <em>any</em> service from ports that doesn't chroot by default</li>
<li>It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it</li>
<li>With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***</li>
</ul>

<h3><a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" target="_blank" rel="nofollow noopener">SmallWall 1.8.2 released</a></h3>

<ul>
<li>SmallWall is a relatively new BSD-based project that we've never covered before</li>
<li>It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits</li>
<li>They've just released <a href="http://www.smallwall.org/download.html" target="_blank" rel="nofollow noopener">the first official version</a>, so you can give it a try now</li>
<li>If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21gRTNnk7" target="_blank" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DdiMvELg" target="_blank" rel="nofollow noopener">Brian writes in</a></li>
<li><a href="http://slexy.org/view/s2h4ZS6SMd" target="_blank" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s20kA1jeXY" target="_blank" rel="nofollow noopener">Joel writes in</a></li>
<li><a href="http://slexy.org/view/s2wJ9HP1bs" target="_blank" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>85: PIE in the Sky</title>
  <link>https://www.bsdnow.tv/85</link>
  <guid isPermaLink="false">7b947cd6-04e4-4210-a3a1-3f80d96ccc79</guid>
  <pubDate>Wed, 15 Apr 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/7b947cd6-04e4-4210-a3a1-3f80d96ccc79.mp3" length="58114516" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" target="_blank" rel="nofollow noopener"&gt;Solaris' networking future is with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A curious patch from someone with an Oracle email address was &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142822852613581&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;recently sent in&lt;/a&gt; to one of the OpenBSD mailing lists&lt;/li&gt;
&lt;li&gt;It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the &lt;strong&gt;current&lt;/strong&gt; version of PF&lt;/li&gt;
&lt;li&gt;For anyone unfamiliar with the history of PF, it was actually made &lt;em&gt;as a replacement for&lt;/em&gt; IPFilter in OpenBSD, due to some licensing issues&lt;/li&gt;
&lt;li&gt;What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting&lt;/li&gt;
&lt;li&gt;This blog post goes through some of the backstory of the two firewalls&lt;/li&gt;
&lt;li&gt;PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too&lt;/li&gt;
&lt;li&gt;"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"&lt;/li&gt;
&lt;li&gt;You're welcome, Oracle
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" target="_blank" rel="nofollow noopener"&gt;BAFUG discussion videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos from their recent meetings&lt;/li&gt;
&lt;li&gt;Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)&lt;/li&gt;
&lt;li&gt;Craig Rodrigues also gave &lt;a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" target="_blank" rel="nofollow noopener"&gt;a talk&lt;/a&gt; about Kyua and the FreeBSD testing framework&lt;/li&gt;
&lt;li&gt;Lastly, Kip Macy gave &lt;a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" target="_blank" rel="nofollow noopener"&gt;a talk&lt;/a&gt; titled "network stack changes, user-level FreeBSD"&lt;/li&gt;
&lt;li&gt;The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics&lt;/li&gt;
&lt;li&gt;If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" target="_blank" rel="nofollow noopener"&gt;More than just a makefile&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux&lt;/li&gt;
&lt;li&gt;This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs&lt;/li&gt;
&lt;li&gt;As it turns out, the ports system really isn't that different from a binary package manager - they are what's &lt;em&gt;used&lt;/em&gt; to create binary packages, after all&lt;/li&gt;
&lt;li&gt;The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream&lt;/li&gt;
&lt;li&gt;After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community&lt;/li&gt;
&lt;li&gt;This post is very long and there's a lot more to it, so check it out (and more discussion &lt;a href="https://news.ycombinator.com/item?id=9360827" target="_blank" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt;)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.scip.ch/en/?labs.20150409" target="_blank" rel="nofollow noopener"&gt;Securing your home fences&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a &lt;a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" target="_blank" rel="nofollow noopener"&gt;bad&lt;/a&gt; &lt;a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" target="_blank" rel="nofollow noopener"&gt;idea&lt;/a&gt; by now&lt;/li&gt;
&lt;li&gt;We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now&lt;/li&gt;
&lt;li&gt;In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines &lt;a href="http://www.pcengines.ch/apu1d4.htm" target="_blank" rel="nofollow noopener"&gt;APU board&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;He notes that you have a lot of options software-wise, including vanilla &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt; or even Linux, but decided to go with OPNsense because of the easy interface and configuration&lt;/li&gt;
&lt;li&gt;The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process&lt;/li&gt;
&lt;li&gt;Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up&lt;/li&gt;
&lt;li&gt;If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)&lt;/li&gt;
&lt;li&gt;We love super-detailed guides like this, so everyone should write more and send them to us immediately
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Pascal Stumpf - &lt;a href="mailto:pascal@openbsd.org" target="_blank" rel="nofollow noopener"&gt;pascal@openbsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Static PIE in OpenBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" target="_blank" rel="nofollow noopener"&gt;LLVM's new libFuzzer&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility&lt;/li&gt;
&lt;li&gt;It looks like LLVM is going to have their own fuzzing tool too now&lt;/li&gt;
&lt;li&gt;The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself&lt;/li&gt;
&lt;li&gt;With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" target="_blank" rel="nofollow noopener"&gt;HardenedBSD upgrades secadm&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support&lt;/li&gt;
&lt;li&gt;We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)&lt;/li&gt;
&lt;li&gt;Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142877132517229&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;RAID5 returns to OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD's &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" target="_blank" rel="nofollow noopener"&gt;softraid&lt;/a&gt; subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while&lt;/li&gt;
&lt;li&gt;However, it was exactly that - experimental - and required a recompile to enable&lt;/li&gt;
&lt;li&gt;With some work from recent hackathons, the &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142876943116907&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;final piece&lt;/a&gt; was added to enable resuming partial array rebuilds&lt;/li&gt;
&lt;li&gt;Now it's &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877026917030&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;on by default&lt;/a&gt;, and there's a call for testing being put out, so grab a snapshot and put the code through its paces&lt;/li&gt;
&lt;li&gt;The bioctl softraid command also &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877223817406&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;now supports&lt;/a&gt; DUIDs during pseudo-device detachment, possibly paving the way for the installer to &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142643313416298&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;drop&lt;/a&gt; the "do you want to enable DUIDs?" question entirely
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" target="_blank" rel="nofollow noopener"&gt;pkgng 1.5.0 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Going back to what we &lt;a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" target="_blank" rel="nofollow noopener"&gt;talked about last week&lt;/a&gt;, the final version of pkgng 1.5.0 is out&lt;/li&gt;
&lt;li&gt;The "provides" and "requires" support is finally in a regular release&lt;/li&gt;
&lt;li&gt;A new "-r" switch will allow for direct installation to a chroot or alternate root directory&lt;/li&gt;
&lt;li&gt;Memory usage should be much better now, and some general code speed-ups were added&lt;/li&gt;
&lt;li&gt;This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that&lt;/li&gt;
&lt;li&gt;Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150411160247" target="_blank" rel="nofollow noopener"&gt;p2k15 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work&lt;/li&gt;
&lt;li&gt;As usual, the developers sent in reports of some of the things they got done at the event&lt;/li&gt;
&lt;li&gt;Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit&lt;/li&gt;
&lt;li&gt;Stefan Sperling &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150414064710" target="_blank" rel="nofollow noopener"&gt;wrote in&lt;/a&gt;, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports&lt;/li&gt;
&lt;li&gt;Ken Westerback &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150413163333" target="_blank" rel="nofollow noopener"&gt;also sent in a report&lt;/a&gt;, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iNBo2swq" target="_blank" rel="nofollow noopener"&gt;Shaun writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s202BRLwrd" target="_blank" rel="nofollow noopener"&gt;Hrishi writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2KT7M35uY" target="_blank" rel="nofollow noopener"&gt;Randy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Q5lOoxzl" target="_blank" rel="nofollow noopener"&gt;Zach writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ynDjuzVi" target="_blank" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=142884995931428&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;Gstreamer hates us&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" target="_blank" rel="nofollow noopener"&gt;At least he's honest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" target="_blank" rel="nofollow noopener"&gt;I find myself in a situation&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, aslr, pie, position-independent executable, static, binary, dynamic, linking, security, llvm, fuzzing, clang, opnsense, pcengines, apu, alix, hammer2, zfs, oracle, solaris, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" target="_blank" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" target="_blank" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" target="_blank" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" target="_blank" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" target="_blank" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" target="_blank" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" target="_blank" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" target="_blank" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" target="_blank" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" target="_blank" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" target="_blank" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" target="_blank" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" target="_blank" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" target="_blank" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" target="_blank" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" target="_blank" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" target="_blank" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" target="_blank" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" target="_blank" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" target="_blank" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" target="_blank" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" target="_blank" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" target="_blank" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" target="_blank" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" target="_blank" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" target="_blank" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" target="_blank" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" target="_blank" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" target="_blank" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" target="_blank" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" target="_blank" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" target="_blank" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" target="_blank" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" target="_blank" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" target="_blank" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" target="_blank" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" target="_blank" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" target="_blank" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" target="_blank" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" target="_blank" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" target="_blank" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" target="_blank" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" target="_blank" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" target="_blank" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" target="_blank" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" target="_blank" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" target="_blank" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" target="_blank" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" target="_blank" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" target="_blank" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" target="_blank" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" target="_blank" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" target="_blank" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" target="_blank" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" target="_blank" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" target="_blank" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" target="_blank" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" target="_blank" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" target="_blank" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" target="_blank" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" target="_blank" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" target="_blank" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" target="_blank" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" target="_blank" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" target="_blank" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" target="_blank" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>73: Pipe Dreams</title>
  <link>https://www.bsdnow.tv/73</link>
  <guid isPermaLink="false">bca95163-7c0b-4440-902b-594ea8c61554</guid>
  <pubDate>Wed, 21 Jan 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/bca95163-7c0b-4440-902b-594ea8c61554.mp3" length="65969428" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:31:37</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has posted an updated on some of their activities between October and December of 2014&lt;/li&gt;
&lt;li&gt;They put a big focus on compatibility with other systems: the Linux emulation layer, &lt;a href="http://www.bsdnow.tv/tutorials/bhyve" target="_blank" rel="nofollow noopener"&gt;bhyve&lt;/a&gt;, WINE and Xen all got some nice improvements&lt;/li&gt;
&lt;li&gt;As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure&lt;/li&gt;
&lt;li&gt;The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs&lt;/li&gt;
&lt;li&gt;FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)&lt;/li&gt;
&lt;li&gt;Git was promoted from beta to an officially-supported version control system (Kris is happy)&lt;/li&gt;
&lt;li&gt;The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints&lt;/li&gt;
&lt;li&gt;Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements&lt;/li&gt;
&lt;li&gt;Check out the full report for all the details that we didn't cover
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" target="_blank" rel="nofollow noopener"&gt;OpenBSD package signature audit&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes&lt;/li&gt;
&lt;li&gt;They recently did an article about OpenBSD, specifically their &lt;a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener"&gt;ports and package system&lt;/a&gt; and signing infrastructure&lt;/li&gt;
&lt;li&gt;The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed&lt;/li&gt;
&lt;li&gt;Package signature formats and public key distribution methods are also touched on&lt;/li&gt;
&lt;li&gt;After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future&lt;/li&gt;
&lt;li&gt;If you haven't seen &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener"&gt;our episode about signify&lt;/a&gt; with Ted Unangst, that would be a great one to check out after reading this
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" target="_blank" rel="nofollow noopener"&gt;Replacing a Linux router with BSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one&lt;/li&gt;
&lt;li&gt;The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."&lt;/li&gt;
&lt;li&gt;A lot of people were quick to recommend &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" target="_blank" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt; and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)&lt;/li&gt;
&lt;li&gt;Other commenters suggested a more hands-on approach, setting one up yourself with &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt; or &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through&lt;/li&gt;
&lt;li&gt;Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" target="_blank" rel="nofollow noopener"&gt;LibreSSL in FreeBSD and OPNsense&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)&lt;/li&gt;
&lt;li&gt;The reasoning being that updates in base &lt;a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" target="_blank" rel="nofollow noopener"&gt;tend to lag behind&lt;/a&gt;, whereas the port can be updated for security very quickly&lt;/li&gt;
&lt;li&gt;OPNsense developers are &lt;a href="https://twitter.com/fitchitis/status/555625679614521345" target="_blank" rel="nofollow noopener"&gt;looking into&lt;/a&gt;  &lt;a href="http://forum.opnsense.org/index.php?topic=21.0" target="_blank" rel="nofollow noopener"&gt;switching away&lt;/a&gt; from OpenSSL to &lt;a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" target="_blank" rel="nofollow noopener"&gt;LibreSSL's portable version&lt;/a&gt;, for both their ports and base system, which would be a pretty huge differentiator for their project&lt;/li&gt;
&lt;li&gt;Some ports &lt;a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;amp;query_format=advanced&amp;amp;short_desc=libressl&amp;amp;short_desc_type=allwordssubstr" target="_blank" rel="nofollow noopener"&gt;still need fixing&lt;/a&gt; to be compatible though, particularly &lt;a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" target="_blank" rel="nofollow noopener"&gt;a few&lt;/a&gt; &lt;a href="https://github.com/pyca/cryptography/issues/928" target="_blank" rel="nofollow noopener"&gt;python-related&lt;/a&gt; ones&lt;/li&gt;
&lt;li&gt;If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs&lt;/li&gt;
&lt;li&gt;A lot of the work has already been done &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" target="_blank" rel="nofollow noopener"&gt;in OpenBSD's ports tree&lt;/a&gt; - some patches just need to be adopted&lt;/li&gt;
&lt;li&gt;More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - David Maxwell - &lt;a href="mailto:david@netbsd.org" target="_blank" rel="nofollow noopener"&gt;david@netbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/david_w_maxwell" target="_blank" rel="nofollow noopener"&gt;@david_w_maxwell&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" target="_blank" rel="nofollow noopener"&gt;Pipecut&lt;/a&gt;, text processing, commandline wizardry&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/3ofcoins/jetpack" target="_blank" rel="nofollow noopener"&gt;Jetpack, a new jail container system&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new project was launched to adapt FreeBSD jails to the "app container specification"&lt;/li&gt;
&lt;li&gt;While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker&lt;/li&gt;
&lt;li&gt;It's a similar project to &lt;a href="https://github.com/pannon/iocage" target="_blank" rel="nofollow noopener"&gt;iocage&lt;/a&gt; or &lt;a href="https://github.com/ployground/bsdploy" target="_blank" rel="nofollow noopener"&gt;bsdploy&lt;/a&gt;, which we haven't talked a whole lot about&lt;/li&gt;
&lt;li&gt;There was also &lt;a href="https://news.ycombinator.com/item?id=8893630" target="_blank" rel="nofollow noopener"&gt;some discussion&lt;/a&gt; about it on Hacker News
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2szofc" target="_blank" rel="nofollow noopener"&gt;Separating base and package binaries&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;All of the main BSDs make a strong separation between the base system and third party software&lt;/li&gt;
&lt;li&gt;This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory&lt;/li&gt;
&lt;li&gt;A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies&lt;/li&gt;
&lt;li&gt;Read the comments for the full explanation, but having things separated really helps keep things organized
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=277487" target="_blank" rel="nofollow noopener"&gt;Updated i915kms driver for FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward&lt;/li&gt;
&lt;li&gt;It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" target="_blank" rel="nofollow noopener"&gt;Year of the OpenBSD desktop&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have an article about using OpenBSD as a daily driver for regular desktop usage&lt;/li&gt;
&lt;li&gt;The author says he "ran fifty thousand different distributions, never being satisfied"&lt;/li&gt;
&lt;li&gt;After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook&lt;/li&gt;
&lt;li&gt;He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again&lt;/li&gt;
&lt;li&gt;Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201&lt;/li&gt;
&lt;li&gt;The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup&lt;/li&gt;
&lt;li&gt;He apparently used &lt;a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener"&gt;our desktop tutorial&lt;/a&gt; - thanks for watching!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" target="_blank" rel="nofollow noopener"&gt;Unattended FreeBSD installation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE&lt;/li&gt;
&lt;li&gt;His goal was to have a setup similar to Redhat's "kickstart" or &lt;a href="http://www.bsdnow.tv/tutorials/autoinstall" target="_blank" rel="nofollow noopener"&gt;OpenBSD's autoinstall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The article shows you how to set up DHCP and TFTP, with no NFS share setup required&lt;/li&gt;
&lt;li&gt;He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20UsZjN4h" target="_blank" rel="nofollow noopener"&gt;Robert writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s219cMQz3U" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2EkzMUMyb" target="_blank" rel="nofollow noopener"&gt;l33tname writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nq6L6H1n" target="_blank" rel="nofollow noopener"&gt;Charlie writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21EGqUYLd" target="_blank" rel="nofollow noopener"&gt;Eric writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142159202606668&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;Clowning around&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" target="_blank" rel="nofollow noopener"&gt;Better than succeeding in this case&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pipecut, david maxwell, commandline, shell, libressl, router, pf, cryptography, router, openssl, bhyve, digitalocean</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" target="_blank" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" target="_blank" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" target="_blank" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" target="_blank" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" target="_blank" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" target="_blank" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" target="_blank" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" target="_blank" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" target="_blank" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" target="_blank" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" target="_blank" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" target="_blank" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" target="_blank" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" target="_blank" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" target="_blank" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" target="_blank" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" target="_blank" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" target="_blank" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" target="_blank" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" target="_blank" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" target="_blank" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" target="_blank" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" target="_blank" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" target="_blank" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" target="_blank" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" target="_blank" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" target="_blank" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" target="_blank" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" target="_blank" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" target="_blank" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" target="_blank" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show we'll be chatting with David Maxwell, a former NetBSD security officer. He's got an interesting project called Pipecut that takes a whole new approach to the commandline. We've also got answers to viewer-submitted questions and all this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-10-2014-12.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted an updated on some of their activities between October and December of 2014</li>
<li>They put a big focus on compatibility with other systems: the Linux emulation layer, <a href="http://www.bsdnow.tv/tutorials/bhyve" target="_blank" rel="nofollow noopener">bhyve</a>, WINE and Xen all got some nice improvements</li>
<li>As always, the report has lots of updates from the various teams working on different parts of the OS and ports infrastructure</li>
<li>The release engineering team got 10.1 out the door, the ports team shuffled a few members in and out and continued working on closing more PRs</li>
<li>FreeBSD's forums underwent a huge change, and discussion about the new support model for release cycles continues (hopefully taking effect after 11.0 is released)</li>
<li>Git was promoted from beta to an officially-supported version control system (Kris is happy)</li>
<li>The core team is also assembling a new QA team to ensure better code quality in critical areas, such as security and release engineering, after getting a number of complaints</li>
<li>Other notable entries include: lots of bhyve fixes, Clang/LLVM being updated to 3.5.0, ongoing work to the external toolchain, adding FreeBSD support to more "cloud" services, pkgng updates, work on SecureBoot, more ARM support and graphics stack improvements</li>
<li>Check out the full report for all the details that we didn't cover
***</li>
</ul>

<h3><a href="http://linux-audit.com/vulnerabilities-and-digital-signatures-for-openbsd-software-packages/" target="_blank" rel="nofollow noopener">OpenBSD package signature audit</a></h3>

<ul>
<li>"Linux Audit" is a website focused on auditing and hardening systems, as well as educating people about securing their boxes</li>
<li>They recently did an article about OpenBSD, specifically their <a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener">ports and package system</a> and signing infrastructure</li>
<li>The author gives a little background on the difference between ports and binary packages, then goes through the technical details of how releases and packages are cryptographically signed</li>
<li>Package signature formats and public key distribution methods are also touched on</li>
<li>After some heckling, the author of the post said he plans to write more BSD security articles, so look forward to them in the future</li>
<li>If you haven't seen <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">our episode about signify</a> with Ted Unangst, that would be a great one to check out after reading this
***</li>
</ul>

<h3><a href="http://ask.slashdot.org/story/15/01/15/1547209/ask-slashdot-migrating-a-router-from-linux-to-bsd" target="_blank" rel="nofollow noopener">Replacing a Linux router with BSD</a></h3>

<ul>
<li>There was recently a Slashdot discussion about migrating a Linux-based router to a BSD-based one</li>
<li>The poster begins with "I'm in the camp that doesn't trust systemd. You can discuss the technical merits of all init solutions all you want, but if I wanted to run Windows NT I'd run Windows NT, not Linux. So I've decided to migrate my homebrew router/firewall/samba server to one of the BSDs."</li>
<li>A lot of people were quick to recommend <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" target="_blank" rel="nofollow noopener">OPNsense</a> and pfSense, being that they're very easy to administer (requiring basically no BSD knowledge at all)</li>
<li>Other commenters suggested a more hands-on approach, setting one up yourself with <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" target="_blank" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">OpenBSD</a></li>
<li>If you've been thinking about moving some routers over from Linux or other commercial solution, this might be a good discussion to read through</li>
<li>Unfortunately, a lot of the comments are just Linux users bickering about systemd, so you'll have to wade through some of that to get to the good information
***</li>
</ul>

<h3><a href="http://bsdxbsdx.blogspot.com/2015/01/switching-to-openssl-from-ports-in.html" target="_blank" rel="nofollow noopener">LibreSSL in FreeBSD and OPNsense</a></h3>

<ul>
<li>A FreeBSD sysadmin has started documenting his experience replacing OpenSSL in the base system with the one from ports (and also experimenting with LibreSSL)</li>
<li>The reasoning being that updates in base <a href="http://www.openbsd.org/papers/eurobsdcon2014-libressl.html" target="_blank" rel="nofollow noopener">tend to lag behind</a>, whereas the port can be updated for security very quickly</li>
<li>OPNsense developers are <a href="https://twitter.com/fitchitis/status/555625679614521345" target="_blank" rel="nofollow noopener">looking into</a>  <a href="http://forum.opnsense.org/index.php?topic=21.0" target="_blank" rel="nofollow noopener">switching away</a> from OpenSSL to <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" target="_blank" rel="nofollow noopener">LibreSSL's portable version</a>, for both their ports and base system, which would be a pretty huge differentiator for their project</li>
<li>Some ports <a href="https://bugs.freebsd.org/bugzilla/buglist.cgi?order=Importance&amp;query_format=advanced&amp;short_desc=libressl&amp;short_desc_type=allwordssubstr" target="_blank" rel="nofollow noopener">still need fixing</a> to be compatible though, particularly <a href="https://github.com/opnsense/ports/commit/c15af648e9d5fcecf0ae666292e8f41c08979057" target="_blank" rel="nofollow noopener">a few</a> <a href="https://github.com/pyca/cryptography/issues/928" target="_blank" rel="nofollow noopener">python-related</a> ones</li>
<li>If you're a FreeBSD ports person, get involved and help squash some of the last remaining bugs</li>
<li>A lot of the work has already been done <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/" target="_blank" rel="nofollow noopener">in OpenBSD's ports tree</a> - some patches just need to be adopted</li>
<li>More and more upstream projects are incorporating LibreSSL patches in their code - let your favorite software vendor know that you're using it
***</li>
</ul>

<h2>Interview - David Maxwell - <a href="mailto:david@netbsd.org" target="_blank" rel="nofollow noopener">david@netbsd.org</a> / <a href="https://twitter.com/david_w_maxwell" target="_blank" rel="nofollow noopener">@david_w_maxwell</a></h2>

<p><a href="https://www.youtube.com/watch?v=CZHEZHK4jRc" target="_blank" rel="nofollow noopener">Pipecut</a>, text processing, commandline wizardry</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/3ofcoins/jetpack" target="_blank" rel="nofollow noopener">Jetpack, a new jail container system</a></h3>

<ul>
<li>A new project was launched to adapt FreeBSD jails to the "app container specification"</li>
<li>While still pretty experimental in terms of the development phase, this might be something to show your Linux friends who are in love with docker</li>
<li>It's a similar project to <a href="https://github.com/pannon/iocage" target="_blank" rel="nofollow noopener">iocage</a> or <a href="https://github.com/ployground/bsdploy" target="_blank" rel="nofollow noopener">bsdploy</a>, which we haven't talked a whole lot about</li>
<li>There was also <a href="https://news.ycombinator.com/item?id=8893630" target="_blank" rel="nofollow noopener">some discussion</a> about it on Hacker News
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2szofc" target="_blank" rel="nofollow noopener">Separating base and package binaries</a></h3>

<ul>
<li>All of the main BSDs make a strong separation between the base system and third party software</li>
<li>This is in contrast to Linux where there's no real concept of a "base system" - more recently, some distros have even merged all the binaries into a single directory</li>
<li>A user asks the community about the BSD way of doing it, trying to find out the advantages and disadvantages of both hierarchies</li>
<li>Read the comments for the full explanation, but having things separated really helps keep things organized
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=277487" target="_blank" rel="nofollow noopener">Updated i915kms driver for FreeBSD</a></h3>

<ul>
<li>This update brings the FreeBSD code closer inline with the Linux code, to make it easier to update going forward</li>
<li>It doesn't introduce Haswell support just yet, but was required before the Haswell bits can be added
***</li>
</ul>

<h3><a href="http://zacbrown.org/2015/01/18/openbsd-as-a-desktop/" target="_blank" rel="nofollow noopener">Year of the OpenBSD desktop</a></h3>

<ul>
<li>Here we have an article about using OpenBSD as a daily driver for regular desktop usage</li>
<li>The author says he "ran fifty thousand different distributions, never being satisfied"</li>
<li>After dealing with the problems of Linux and fragmentation, he eventually gave up and bought a Macbook</li>
<li>He also used FreeBSD between versions 7 and 9, finding a "a mostly harmonious environment," but regressions lead him to give up on desktop *nix once again</li>
<li>Starting with 2015, he's back and is using OpenBSD on a Thinkpad x201</li>
<li>The rest of the article covers some of his configuration tweaks and gives an overall conclusion on his current setup</li>
<li>He apparently used <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener">our desktop tutorial</a> - thanks for watching!
***</li>
</ul>

<h3><a href="http://louwrentius.com/freebsd-101-unattended-install-over-pxe-http-no-nfs.html" target="_blank" rel="nofollow noopener">Unattended FreeBSD installation</a></h3>

<ul>
<li>A new BSD user was looking to get some more experience, so he documented how to install FreeBSD over PXE</li>
<li>His goal was to have a setup similar to Redhat's "kickstart" or <a href="http://www.bsdnow.tv/tutorials/autoinstall" target="_blank" rel="nofollow noopener">OpenBSD's autoinstall</a></li>
<li>The article shows you how to set up DHCP and TFTP, with no NFS share setup required</li>
<li>He also gives a mention to mfsbsd, showing how you can customize its startup script to do most of the work for you
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20UsZjN4h" target="_blank" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s219cMQz3U" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2EkzMUMyb" target="_blank" rel="nofollow noopener">l33tname writes in</a></li>
<li><a href="http://slexy.org/view/s2nq6L6H1n" target="_blank" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21EGqUYLd" target="_blank" rel="nofollow noopener">Eric writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142159202606668&amp;w=2" target="_blank" rel="nofollow noopener">Clowning around</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097734.html" target="_blank" rel="nofollow noopener">Better than succeeding in this case</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>63: A Man's man(1)</title>
  <link>https://www.bsdnow.tv/63</link>
  <guid isPermaLink="false">0dbe70cc-bfdd-4af8-b67f-a5d1e85b7115</guid>
  <pubDate>Wed, 12 Nov 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0dbe70cc-bfdd-4af8-b67f-a5d1e85b7115.mp3" length="70356244" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:37:43</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=273872" target="_blank" rel="nofollow noopener"&gt;Updates to FreeBSD's random(4)&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD's random device, which presents itself as "/dev/random" to &lt;a href="https://news.ycombinator.com/item?id=8550457" target="_blank" rel="nofollow noopener"&gt;users&lt;/a&gt;, has gotten a fairly major overhaul in -CURRENT&lt;/li&gt;
&lt;li&gt;The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna&lt;/li&gt;
&lt;li&gt;Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)&lt;/li&gt;
&lt;li&gt;Pluggable modules can now be written to add more sources of entropy&lt;/li&gt;
&lt;li&gt;These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD Tor relays and network diversity&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about getting &lt;a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" target="_blank" rel="nofollow noopener"&gt;more BSD-based Tor nodes&lt;/a&gt; a few times in previous episodes&lt;/li&gt;
&lt;li&gt;The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes&lt;/li&gt;
&lt;li&gt;With the security features and attention to detail, it makes for an excellent dedicated Tor box&lt;/li&gt;
&lt;li&gt;More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large&lt;/li&gt;
&lt;li&gt;A few users are even saying they'll &lt;em&gt;convert their Linux nodes&lt;/em&gt; to OpenBSD to help out&lt;/li&gt;
&lt;li&gt;Check the archive for the full conversation, and maybe &lt;a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener"&gt;run a node yourself&lt;/a&gt; on any of the BSDs&lt;/li&gt;
&lt;li&gt;The Tor wiki page on OpenBSD is pretty &lt;a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" target="_blank" rel="nofollow noopener"&gt;out of date&lt;/a&gt; (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" target="_blank" rel="nofollow noopener"&gt;SSP now default for FreeBSD ports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SSP, or &lt;a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" target="_blank" rel="nofollow noopener"&gt;Stack Smashing Protection&lt;/a&gt;, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces&lt;/li&gt;
&lt;li&gt;It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)&lt;/li&gt;
&lt;li&gt;This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates&lt;/li&gt;
&lt;li&gt;If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over&lt;/li&gt;
&lt;li&gt;NetBSD made this the default on i386 and amd64 &lt;a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" target="_blank" rel="nofollow noopener"&gt;two years ago&lt;/a&gt; and OpenBSD made this the default on all architectures &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=103881967909595&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;twelve years ago&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" target="_blank" rel="nofollow noopener"&gt;Building an OpenBSD firewall and router&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side&lt;/li&gt;
&lt;li&gt;The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris&lt;/li&gt;
&lt;li&gt;Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community&lt;/li&gt;
&lt;li&gt;They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.&lt;/li&gt;
&lt;li&gt;Through the comments, we also find out that &lt;strong&gt;QuakeCon runs OpenBSD&lt;/strong&gt; on their network&lt;/li&gt;
&lt;li&gt;Hopefully most of our listeners are running some kind of BSD as their gateway - &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;try it out&lt;/a&gt; if you haven't already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Kristaps Džonsons - &lt;a href="mailto:kristaps@bsd.lv" target="_blank" rel="nofollow noopener"&gt;kristaps@bsd.lv&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Mandoc, historical man pages, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" target="_blank" rel="nofollow noopener"&gt;Throttling bandwidth with PF&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" target="_blank" rel="nofollow noopener"&gt;NetBSD at Kansai Open Forum 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Japanese NetBSD users invade yet another conference, demonstrating that they &lt;strong&gt;can and will&lt;/strong&gt; install NetBSD &lt;em&gt;on everything&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all&lt;/li&gt;
&lt;li&gt;As always, you can find lots of pictures in the trip report
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" target="_blank" rel="nofollow noopener"&gt;Getting to know your portmgr lurkers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The lovable "getting to know your portmgr" series makes its triumphant return&lt;/li&gt;
&lt;li&gt;This time around, they interview Alex, one of the portmgr lurkers that joined just this month&lt;/li&gt;
&lt;li&gt;"How would you describe yourself?" "Too lazy."&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" target="_blank" rel="nofollow noopener"&gt;Another post&lt;/a&gt; includes a short interview with Emanuel, another new lurker&lt;/li&gt;
&lt;li&gt;We discussed the portmgr lurkers initiative with Steve Wills &lt;a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" target="_blank" rel="nofollow noopener"&gt;a while back&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" target="_blank" rel="nofollow noopener"&gt;NetBSD's ARM port gets SMP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used&lt;/li&gt;
&lt;li&gt;This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X&lt;/li&gt;
&lt;li&gt;NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released&lt;/li&gt;
&lt;li&gt;There are also a few nice pictures in the article
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" target="_blank" rel="nofollow noopener"&gt;A high performance mid-range NAS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This blog post is about FreeNAS and optimizing iSCSI performance&lt;/li&gt;
&lt;li&gt;It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance&lt;/li&gt;
&lt;li&gt;There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings&lt;/li&gt;
&lt;li&gt;They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2xGCUj8mC" target="_blank" rel="nofollow noopener"&gt;Heto writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2SJ8xppDJ" target="_blank" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Ktl6BMk" target="_blank" rel="nofollow noopener"&gt;Tyler writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2AsrxU0ZQ" target="_blank" rel="nofollow noopener"&gt;Tim writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21yn0xLv2" target="_blank" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141379917200003&amp;amp;r=1&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;Suspicious contributions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141538800019451&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;La puissance du fromage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" target="_blank" rel="nofollow noopener"&gt;Nothing unusual here&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, mandoc, sysjail, mdocml, mdoc, mancgi, mult, random, arc4random, libressl, meetbsd, fortuna, yarrow, soekris, alix, apu, altq, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=273872" target="_blank" rel="nofollow noopener">Updates to FreeBSD's random(4)</a></h3>

<ul>
<li>FreeBSD's random device, which presents itself as "/dev/random" to <a href="https://news.ycombinator.com/item?id=8550457" target="_blank" rel="nofollow noopener">users</a>, has gotten a fairly major overhaul in -CURRENT</li>
<li>The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna</li>
<li>Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)</li>
<li>Pluggable modules can now be written to add more sources of entropy</li>
<li>These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***</li>
</ul>

<h3><a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" target="_blank" rel="nofollow noopener">OpenBSD Tor relays and network diversity</a></h3>

<ul>
<li>We've talked about getting <a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" target="_blank" rel="nofollow noopener">more BSD-based Tor nodes</a> a few times in previous episodes</li>
<li>The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes</li>
<li>With the security features and attention to detail, it makes for an excellent dedicated Tor box</li>
<li>More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large</li>
<li>A few users are even saying they'll <em>convert their Linux nodes</em> to OpenBSD to help out</li>
<li>Check the archive for the full conversation, and maybe <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">run a node yourself</a> on any of the BSDs</li>
<li>The Tor wiki page on OpenBSD is pretty <a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" target="_blank" rel="nofollow noopener">out of date</a> (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" target="_blank" rel="nofollow noopener">SSP now default for FreeBSD ports</a></h3>

<ul>
<li>SSP, or <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" target="_blank" rel="nofollow noopener">Stack Smashing Protection</a>, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces</li>
<li>It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)</li>
<li>This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates</li>
<li>If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over</li>
<li>NetBSD made this the default on i386 and amd64 <a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" target="_blank" rel="nofollow noopener">two years ago</a> and OpenBSD made this the default on all architectures <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=103881967909595&amp;w=2" target="_blank" rel="nofollow noopener">twelve years ago</a></li>
<li>Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" target="_blank" rel="nofollow noopener">Building an OpenBSD firewall and router</a></h3>

<ul>
<li>While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side</li>
<li>The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris</li>
<li>Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community</li>
<li>They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.</li>
<li>Through the comments, we also find out that <strong>QuakeCon runs OpenBSD</strong> on their network</li>
<li>Hopefully most of our listeners are running some kind of BSD as their gateway - <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">try it out</a> if you haven't already
***</li>
</ul>

<h2>Interview - Kristaps Džonsons - <a href="mailto:kristaps@bsd.lv" target="_blank" rel="nofollow noopener">kristaps@bsd.lv</a></h2>

<p>Mandoc, historical man pages, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" target="_blank" rel="nofollow noopener">Throttling bandwidth with PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" target="_blank" rel="nofollow noopener">NetBSD at Kansai Open Forum 2014</a></h3>

<ul>
<li>Japanese NetBSD users invade yet another conference, demonstrating that they <strong>can and will</strong> install NetBSD <em>on everything</em></li>
<li>From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all</li>
<li>As always, you can find lots of pictures in the trip report
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" target="_blank" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The lovable "getting to know your portmgr" series makes its triumphant return</li>
<li>This time around, they interview Alex, one of the portmgr lurkers that joined just this month</li>
<li>"How would you describe yourself?" "Too lazy."</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" target="_blank" rel="nofollow noopener">Another post</a> includes a short interview with Emanuel, another new lurker</li>
<li>We discussed the portmgr lurkers initiative with Steve Wills <a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" target="_blank" rel="nofollow noopener">a while back</a>
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" target="_blank" rel="nofollow noopener">NetBSD's ARM port gets SMP</a></h3>

<ul>
<li>The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used</li>
<li>This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X</li>
<li>NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released</li>
<li>There are also a few nice pictures in the article
***</li>
</ul>

<h3><a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" target="_blank" rel="nofollow noopener">A high performance mid-range NAS</a></h3>

<ul>
<li>This blog post is about FreeNAS and optimizing iSCSI performance</li>
<li>It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance</li>
<li>There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings</li>
<li>They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xGCUj8mC" target="_blank" rel="nofollow noopener">Heto writes in</a></li>
<li><a href="http://slexy.org/view/s2SJ8xppDJ" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s20Ktl6BMk" target="_blank" rel="nofollow noopener">Tyler writes in</a></li>
<li><a href="http://slexy.org/view/s2AsrxU0ZQ" target="_blank" rel="nofollow noopener">Tim writes in</a></li>
<li><a href="http://slexy.org/view/s21yn0xLv2" target="_blank" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141379917200003&amp;r=1&amp;w=2" target="_blank" rel="nofollow noopener">Suspicious contributions</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141538800019451&amp;w=2" target="_blank" rel="nofollow noopener">La puissance du fromage</a></li>
<li><a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" target="_blank" rel="nofollow noopener">Nothing unusual here</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=273872" target="_blank" rel="nofollow noopener">Updates to FreeBSD's random(4)</a></h3>

<ul>
<li>FreeBSD's random device, which presents itself as "/dev/random" to <a href="https://news.ycombinator.com/item?id=8550457" target="_blank" rel="nofollow noopener">users</a>, has gotten a fairly major overhaul in -CURRENT</li>
<li>The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna</li>
<li>Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)</li>
<li>Pluggable modules can now be written to add more sources of entropy</li>
<li>These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***</li>
</ul>

<h3><a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" target="_blank" rel="nofollow noopener">OpenBSD Tor relays and network diversity</a></h3>

<ul>
<li>We've talked about getting <a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" target="_blank" rel="nofollow noopener">more BSD-based Tor nodes</a> a few times in previous episodes</li>
<li>The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes</li>
<li>With the security features and attention to detail, it makes for an excellent dedicated Tor box</li>
<li>More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large</li>
<li>A few users are even saying they'll <em>convert their Linux nodes</em> to OpenBSD to help out</li>
<li>Check the archive for the full conversation, and maybe <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">run a node yourself</a> on any of the BSDs</li>
<li>The Tor wiki page on OpenBSD is pretty <a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" target="_blank" rel="nofollow noopener">out of date</a> (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" target="_blank" rel="nofollow noopener">SSP now default for FreeBSD ports</a></h3>

<ul>
<li>SSP, or <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" target="_blank" rel="nofollow noopener">Stack Smashing Protection</a>, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces</li>
<li>It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)</li>
<li>This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates</li>
<li>If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over</li>
<li>NetBSD made this the default on i386 and amd64 <a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" target="_blank" rel="nofollow noopener">two years ago</a> and OpenBSD made this the default on all architectures <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=103881967909595&amp;w=2" target="_blank" rel="nofollow noopener">twelve years ago</a></li>
<li>Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" target="_blank" rel="nofollow noopener">Building an OpenBSD firewall and router</a></h3>

<ul>
<li>While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side</li>
<li>The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris</li>
<li>Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community</li>
<li>They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.</li>
<li>Through the comments, we also find out that <strong>QuakeCon runs OpenBSD</strong> on their network</li>
<li>Hopefully most of our listeners are running some kind of BSD as their gateway - <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">try it out</a> if you haven't already
***</li>
</ul>

<h2>Interview - Kristaps Džonsons - <a href="mailto:kristaps@bsd.lv" target="_blank" rel="nofollow noopener">kristaps@bsd.lv</a></h2>

<p>Mandoc, historical man pages, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" target="_blank" rel="nofollow noopener">Throttling bandwidth with PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" target="_blank" rel="nofollow noopener">NetBSD at Kansai Open Forum 2014</a></h3>

<ul>
<li>Japanese NetBSD users invade yet another conference, demonstrating that they <strong>can and will</strong> install NetBSD <em>on everything</em></li>
<li>From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all</li>
<li>As always, you can find lots of pictures in the trip report
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" target="_blank" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The lovable "getting to know your portmgr" series makes its triumphant return</li>
<li>This time around, they interview Alex, one of the portmgr lurkers that joined just this month</li>
<li>"How would you describe yourself?" "Too lazy."</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" target="_blank" rel="nofollow noopener">Another post</a> includes a short interview with Emanuel, another new lurker</li>
<li>We discussed the portmgr lurkers initiative with Steve Wills <a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" target="_blank" rel="nofollow noopener">a while back</a>
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" target="_blank" rel="nofollow noopener">NetBSD's ARM port gets SMP</a></h3>

<ul>
<li>The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used</li>
<li>This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X</li>
<li>NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released</li>
<li>There are also a few nice pictures in the article
***</li>
</ul>

<h3><a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" target="_blank" rel="nofollow noopener">A high performance mid-range NAS</a></h3>

<ul>
<li>This blog post is about FreeNAS and optimizing iSCSI performance</li>
<li>It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance</li>
<li>There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings</li>
<li>They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xGCUj8mC" target="_blank" rel="nofollow noopener">Heto writes in</a></li>
<li><a href="http://slexy.org/view/s2SJ8xppDJ" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s20Ktl6BMk" target="_blank" rel="nofollow noopener">Tyler writes in</a></li>
<li><a href="http://slexy.org/view/s2AsrxU0ZQ" target="_blank" rel="nofollow noopener">Tim writes in</a></li>
<li><a href="http://slexy.org/view/s21yn0xLv2" target="_blank" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141379917200003&amp;r=1&amp;w=2" target="_blank" rel="nofollow noopener">Suspicious contributions</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141538800019451&amp;w=2" target="_blank" rel="nofollow noopener">La puissance du fromage</a></li>
<li><a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" target="_blank" rel="nofollow noopener">Nothing unusual here</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>47: DES Challenge IV</title>
  <link>https://www.bsdnow.tv/47</link>
  <guid isPermaLink="false">2c9f4e68-6474-41f9-ab80-bb40fbb76855</guid>
  <pubDate>Wed, 23 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/2c9f4e68-6474-41f9-ab80-bb40fbb76855.mp3" length="66811828" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:32:47</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener"&gt;g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon&lt;/li&gt;
&lt;li&gt;Lots of work got done - in just the first two weeks of July, there were &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;r=1&amp;amp;b=201407&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;over 1000 commits&lt;/a&gt; to their CVS tree&lt;/li&gt;
&lt;li&gt;Some of the developers wrote in to document what they were up to at the event&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140713220618" target="_blank" rel="nofollow noopener"&gt;Bob Beck&lt;/a&gt; planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718072312" target="_blank" rel="nofollow noopener"&gt;Miod Vallat&lt;/a&gt; also tells about his LibreSSL experiences&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718090456" target="_blank" rel="nofollow noopener"&gt;Brent Cook&lt;/a&gt;, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714094454" target="_blank" rel="nofollow noopener"&gt;Henning Brauer&lt;/a&gt; worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714191912" target="_blank" rel="nofollow noopener"&gt;Martin Pieuchot&lt;/a&gt; fixed some bugs in the USB stack, softraid and misc other things&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140714202157" target="_blank" rel="nofollow noopener"&gt;Marc Espie&lt;/a&gt; improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715120259" target="_blank" rel="nofollow noopener"&gt;Martin Pelikan&lt;/a&gt; integrated read-only ext4 support&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715094848" target="_blank" rel="nofollow noopener"&gt;Vadim Zhukov&lt;/a&gt; did lots of ports work, including working on KDE4&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140715212333" target="_blank" rel="nofollow noopener"&gt;Theo de Raadt&lt;/a&gt; created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140718134017" target="_blank" rel="nofollow noopener"&gt;Paul Irofti&lt;/a&gt; worked on the USB stack, specifically for the Octeon platform&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719104939" target="_blank" rel="nofollow noopener"&gt;Sebastian Benoit&lt;/a&gt; worked on relayd filters and IPv6 code&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719134058" target="_blank" rel="nofollow noopener"&gt;Jasper Lievisse Adriaanse&lt;/a&gt; did work with puppet, packages and the bootloader&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140719082410" target="_blank" rel="nofollow noopener"&gt;Jonathan Gray&lt;/a&gt; imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125235" target="_blank" rel="nofollow noopener"&gt;Stefan Sperling&lt;/a&gt; fixed a lot of issues with wireless drivers&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721125020" target="_blank" rel="nofollow noopener"&gt;Florian Obser&lt;/a&gt; did many things related to IPv6&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140721090411" target="_blank" rel="nofollow noopener"&gt;Ingo Schwarze&lt;/a&gt; worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140722071413" target="_blank" rel="nofollow noopener"&gt;Ken Westerback&lt;/a&gt; hacked on dhclient and dhcpd, and also got dump working on 4k sector drives&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140723142224" target="_blank" rel="nofollow noopener"&gt;Matthieu Herrb&lt;/a&gt; worked on updating and modernizing parts of xenocara
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD pf discussion takes off&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)&lt;/li&gt;
&lt;li&gt;Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"&lt;/li&gt;
&lt;li&gt;Searching for documentation online for pf is troublesome because there are two incompatible syntaxes&lt;/li&gt;
&lt;li&gt;FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating&lt;/li&gt;
&lt;li&gt;There's also the issue of importing patches from pfSense, but most of those still haven't been done either&lt;/li&gt;
&lt;li&gt;Lots of disagreement among developers vs. users...&lt;/li&gt;
&lt;li&gt;Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested&lt;/li&gt;
&lt;li&gt;Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions&lt;/li&gt;
&lt;li&gt;Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)&lt;/li&gt;
&lt;li&gt;Gleb had to abandon his work on FreeBSD's pf because funding ran out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" target="_blank" rel="nofollow noopener"&gt;LibreSSL progress update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140599450206255&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;two days ago&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list&lt;/li&gt;
&lt;li&gt;However, there has already been some drama... with Linux users&lt;/li&gt;
&lt;li&gt;There was a problem with Linux's PRNG, and LibreSSL was &lt;a href="https://twitter.com/MiodVallat/status/489122763610021888" target="_blank" rel="nofollow noopener"&gt;unforgiving&lt;/a&gt; of it, not making an effort to randomize something that could not provide real entropy&lt;/li&gt;
&lt;li&gt;This "problem" doesn't affect OpenBSD's native implementation, only the portable version&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" target="_blank" rel="nofollow noopener"&gt;The developers&lt;/a&gt; decide to &lt;a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" target="_blank" rel="nofollow noopener"&gt;weigh in&lt;/a&gt; to calm the misinformation and rage&lt;/li&gt;
&lt;li&gt;A fix was added in 2.0.2, and Linux may even &lt;a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" target="_blank" rel="nofollow noopener"&gt;get a new system call&lt;/a&gt; to handle this properly now - remember to say thanks, guys&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has a &lt;a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" target="_blank" rel="nofollow noopener"&gt;really good post&lt;/a&gt; about the whole situation, definitely check it out&lt;/li&gt;
&lt;li&gt;As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" target="_blank" rel="nofollow noopener"&gt;Preparation for NetBSD 7&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The release process for NetBSD 7.0 is finally underway&lt;/li&gt;
&lt;li&gt;The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September&lt;/li&gt;
&lt;li&gt;If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)&lt;/li&gt;
&lt;li&gt;They're also looking for some help updating documentation and fixing any bugs that get reported&lt;/li&gt;
&lt;li&gt;Another formal announcement will be made when the beta binaries are up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Dag-Erling Smørgrav - &lt;a href="mailto:des@freebsd.org" target="_blank" rel="nofollow noopener"&gt;des@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/RealEvilDES" target="_blank" rel="nofollow noopener"&gt;@RealEvilDES&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The role of the FreeBSD Security Officer, recent ports features, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" target="_blank" rel="nofollow noopener"&gt;BSDCan ports and packages WG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages&lt;/li&gt;
&lt;li&gt;Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages&lt;/li&gt;
&lt;li&gt;There's also some detail about the signing infrastructure and different mirrors&lt;/li&gt;
&lt;li&gt;Ports people and source people need to talk more often about ABI breakage&lt;/li&gt;
&lt;li&gt;The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.ignoranthack.me/?p=212" target="_blank" rel="nofollow noopener"&gt;Cross-compiling ports with QEMU and poudriere&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With recent QEMU features, you can basically chroot into a completely different architecture&lt;/li&gt;
&lt;li&gt;This article goes through the process of building ARMv6 packages on a normal X86 box&lt;/li&gt;
&lt;li&gt;Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now&lt;/li&gt;
&lt;li&gt;The poudriere-devel port now has a "qemu user" option that will pull in all the requirements&lt;/li&gt;
&lt;li&gt;Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2108" target="_blank" rel="nofollow noopener"&gt;Cloning FreeBSD with ZFS send&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen&lt;/li&gt;
&lt;li&gt;This post shows his entire process in creating a mirror machine, using ZFS for everything&lt;/li&gt;
&lt;li&gt;The "zfs send" and "zfs snapshot" commands really come in handy for this&lt;/li&gt;
&lt;li&gt;He does the whole thing from a live CD, pretty impressive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" target="_blank" rel="nofollow noopener"&gt;FreeBSD Overview series&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog series we stumbled upon about a Linux user switching to BSD&lt;/li&gt;
&lt;li&gt;In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10&lt;/li&gt;
&lt;li&gt;He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels&lt;/li&gt;
&lt;li&gt;Most of what he was used to on Linux was already in the default FreeBSD (except bash...)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" target="_blank" rel="nofollow noopener"&gt;Part two&lt;/a&gt; documents his experiences with pkgng and ports 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s214FYbOKL" target="_blank" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cWLhzj4" target="_blank" rel="nofollow noopener"&gt;Rick writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21A4grtH0" target="_blank" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s27fQHz8Se" target="_blank" rel="nofollow noopener"&gt;Esteban writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21QscO4Cr" target="_blank" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://imgur.com/a/Ah444" target="_blank" rel="nofollow noopener"&gt;Matt sends in pictures of his FreeBSD CD collection&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, prng, linux, des, aes, encryption, cryptography, Dag-Erling Smørgrav, security, hackathon, pf, packet filter, firewall, smp, multithreading, ixsystems, tarsnap, bsdcan, cheri, zfs, qemu</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" target="_blank" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" target="_blank" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" target="_blank" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" target="_blank" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" target="_blank" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" target="_blank" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" target="_blank" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" target="_blank" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" target="_blank" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" target="_blank" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" target="_blank" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" target="_blank" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" target="_blank" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" target="_blank" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" target="_blank" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" target="_blank" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" target="_blank" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" target="_blank" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" target="_blank" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" target="_blank" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" target="_blank" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" target="_blank" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" target="_blank" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" target="_blank" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" target="_blank" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" target="_blank" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" target="_blank" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" target="_blank" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" target="_blank" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" target="_blank" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" target="_blank" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" target="_blank" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" target="_blank" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" target="_blank" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" target="_blank" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" target="_blank" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" target="_blank" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" target="_blank" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" target="_blank" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" target="_blank" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" target="_blank" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show! We've got an interview with Dag-Erling Smørgrav, the current security officer of FreeBSD, to discuss what exactly being in such an important position is like. The latest news, answers to your emails and even some LibreSSL drama, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener">g2k14 hackathon reports</a></h3>

<ul>
<li>Nearly 50 OpenBSD developers gathered in Ljubljana, Slovenia from July 8-14 for a hackathon</li>
<li>Lots of work got done - in just the first two weeks of July, there were <a href="http://marc.info/?l=openbsd-cvs&amp;r=1&amp;b=201407&amp;w=2" target="_blank" rel="nofollow noopener">over 1000 commits</a> to their CVS tree</li>
<li>Some of the developers wrote in to document what they were up to at the event</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140713220618" target="_blank" rel="nofollow noopener">Bob Beck</a> planned to work on kernel stuff, but then "LibreSSL happened" and he spent most of his time working on that</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718072312" target="_blank" rel="nofollow noopener">Miod Vallat</a> also tells about his LibreSSL experiences</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718090456" target="_blank" rel="nofollow noopener">Brent Cook</a>, a new developer, worked mainly on the portable version of LibreSSL (and we'll be interviewing him next week!)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714094454" target="_blank" rel="nofollow noopener">Henning Brauer</a> worked on VLAN bpf and various things related to IPv6 and network interfaces (and he still hates IPv6)</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714191912" target="_blank" rel="nofollow noopener">Martin Pieuchot</a> fixed some bugs in the USB stack, softraid and misc other things</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140714202157" target="_blank" rel="nofollow noopener">Marc Espie</a> improved the package code, enabling some speed ups, fixed some ports that broke with LibreSSL and some of the new changes and also did some work on ensuring snapshot consistency</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715120259" target="_blank" rel="nofollow noopener">Martin Pelikan</a> integrated read-only ext4 support</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715094848" target="_blank" rel="nofollow noopener">Vadim Zhukov</a> did lots of ports work, including working on KDE4</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140715212333" target="_blank" rel="nofollow noopener">Theo de Raadt</a> created a new, more secure system call, "sendsyslog" and did a lot of work with /etc, sysmerge and the rc scripts</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140718134017" target="_blank" rel="nofollow noopener">Paul Irofti</a> worked on the USB stack, specifically for the Octeon platform</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719104939" target="_blank" rel="nofollow noopener">Sebastian Benoit</a> worked on relayd filters and IPv6 code</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719134058" target="_blank" rel="nofollow noopener">Jasper Lievisse Adriaanse</a> did work with puppet, packages and the bootloader</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140719082410" target="_blank" rel="nofollow noopener">Jonathan Gray</a> imported newer Mesa libraries and did a lot with Xenocara, including work in the installer for autodetection</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125235" target="_blank" rel="nofollow noopener">Stefan Sperling</a> fixed a lot of issues with wireless drivers</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721125020" target="_blank" rel="nofollow noopener">Florian Obser</a> did many things related to IPv6</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140721090411" target="_blank" rel="nofollow noopener">Ingo Schwarze</a> worked on mandoc, as usual, and also rewrote the openbsd.org man.cgi interface</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140722071413" target="_blank" rel="nofollow noopener">Ken Westerback</a> hacked on dhclient and dhcpd, and also got dump working on 4k sector drives</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140723142224" target="_blank" rel="nofollow noopener">Matthieu Herrb</a> worked on updating and modernizing parts of xenocara
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2014-July/259292.html" target="_blank" rel="nofollow noopener">FreeBSD pf discussion takes off</a></h3>

<ul>
<li>Concerns from last week, about FreeBSD's packet filter being old and unmaintained, seemed to have finally sparked some conversation about the topic on the "questions" and "current" mailing lists (unfortunately people didn't always use reply-all so you have to cross-reference the two lists to follow the whole conversation sometimes)</li>
<li>Straight from the SMP FreeBSD pf maintainer: "no one right now [is actively developing pf on FreeBSD]"</li>
<li>Searching for documentation online for pf is troublesome because there are two incompatible syntaxes</li>
<li>FreeBSD's pf man pages are lacking, and some of FreeBSD's documentation still links to OpenBSD's pages, which won't work anymore - possibly turning away would-be BSD converts because it's frustrating</li>
<li>There's also the issue of importing patches from pfSense, but most of those still haven't been done either</li>
<li>Lots of disagreement among developers vs. users...</li>
<li>Many users are very vocal about wanting it updated, saying the syntax change is no big deal and is worth the benefits - developers aren't interested</li>
<li>Henning Brauer, the main developer of pf on OpenBSD, has been very nice and offered to help the other BSDs get their pf fixed on multiple occasions</li>
<li>Gleb Smirnoff, author of the FreeBSD-specific SMP patches, questions Henning's claims about OpenBSD's improved speed as "uncorroborated claims" (but neither side has provided any public benchmarks)</li>
<li>Gleb had to abandon his work on FreeBSD's pf because funding ran out
***</li>
</ul>

<h3><a href="http://linux.slashdot.org/story/14/07/16/1950235/libressl-prng-vulnerability-patched" target="_blank" rel="nofollow noopener">LibreSSL progress update</a></h3>

<ul>
<li>LibreSSL's first few portable releases have come out and they're making great progress, releasing 2.0.3 <a href="http://marc.info/?l=openbsd-tech&amp;m=140599450206255&amp;w=2" target="_blank" rel="nofollow noopener">two days ago</a></li>
<li>Lots of non-OpenBSD people are starting to contribute, sending in patches via the tech mailing list</li>
<li>However, there has already been some drama... with Linux users</li>
<li>There was a problem with Linux's PRNG, and LibreSSL was <a href="https://twitter.com/MiodVallat/status/489122763610021888" target="_blank" rel="nofollow noopener">unforgiving</a> of it, not making an effort to randomize something that could not provide real entropy</li>
<li>This "problem" doesn't affect OpenBSD's native implementation, only the portable version</li>
<li><a href="http://www.securityweek.com/openbsd-downplays-prng-vulnerability-libressl" target="_blank" rel="nofollow noopener">The developers</a> decide to <a href="http://www.tedunangst.com/flak/post/wrapping-pids-for-fun-and-profit" target="_blank" rel="nofollow noopener">weigh in</a> to calm the misinformation and rage</li>
<li>A fix was added in 2.0.2, and Linux may even <a href="http://thread.gmane.org/gmane.linux.kernel.cryptoapi/11666" target="_blank" rel="nofollow noopener">get a new system call</a> to handle this properly now - remember to say thanks, guys</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> has a <a href="http://www.tedunangst.com/flak/post/this-is-why-software-sucks" target="_blank" rel="nofollow noopener">really good post</a> about the whole situation, definitely check it out</li>
<li>As a follow-up from last week, bapt says they're working on building the whole FreeBSD ports tree against LibreSSL, but lots of things still need some patching to work properly - if you're a port maintainer, please test your ports against it
***</li>
</ul>

<h3><a href="http://mail-index.netbsd.org/current-users/2014/07/13/msg025234.html" target="_blank" rel="nofollow noopener">Preparation for NetBSD 7</a></h3>

<ul>
<li>The release process for NetBSD 7.0 is finally underway</li>
<li>The netbsd-7 CVS branch should be created around July 26th, which marks the start of the first beta period, which will be lasting until September</li>
<li>If you run NetBSD, that'll be a great time to help test on as many platforms as you can (this is especially true on custom embedded applications)</li>
<li>They're also looking for some help updating documentation and fixing any bugs that get reported</li>
<li>Another formal announcement will be made when the beta binaries are up
***</li>
</ul>

<h2>Interview - Dag-Erling Smørgrav - <a href="mailto:des@freebsd.org" target="_blank" rel="nofollow noopener">des@freebsd.org</a> / <a href="https://twitter.com/RealEvilDES" target="_blank" rel="nofollow noopener">@RealEvilDES</a></h2>

<p>The role of the FreeBSD Security Officer, recent ports features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/07/18/bsdcan-2014-ports-and-packages-wg/" target="_blank" rel="nofollow noopener">BSDCan ports and packages WG</a></h3>

<ul>
<li>Back at BSDCan this year, there was a special event for discussion of FreeBSD ports and packages</li>
<li>Bapt talked about package building, poudriere and the systems the foundation funded for compiling packages</li>
<li>There's also some detail about the signing infrastructure and different mirrors</li>
<li>Ports people and source people need to talk more often about ABI breakage</li>
<li>The post also includes information about pkg 1.3, the old pkg tools' EOL, the quarterly stable package sets and a lot more (it's a huge post!)
***</li>
</ul>

<h3><a href="http://blog.ignoranthack.me/?p=212" target="_blank" rel="nofollow noopener">Cross-compiling ports with QEMU and poudriere</a></h3>

<ul>
<li>With recent QEMU features, you can basically chroot into a completely different architecture</li>
<li>This article goes through the process of building ARMv6 packages on a normal X86 box</li>
<li>Note though that this requires 10-STABLE or 11-CURRENT and an extra patch for QEMU right now</li>
<li>The poudriere-devel port now has a "qemu user" option that will pull in all the requirements</li>
<li>Hopefully this will pave the way for official pkgng packages on those lesser-used architectures
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2108" target="_blank" rel="nofollow noopener">Cloning FreeBSD with ZFS send</a></h3>

<ul>
<li>For a FreeBSD mail server that MWL runs, he wanted to have a way to easily restore the whole system if something were to happen</li>
<li>This post shows his entire process in creating a mirror machine, using ZFS for everything</li>
<li>The "zfs send" and "zfs snapshot" commands really come in handy for this</li>
<li>He does the whole thing from a live CD, pretty impressive
***</li>
</ul>

<h3><a href="http://thiagoperrotta.wordpress.com/2014/07/20/here-be-dragons-freebsd-overview-part-i/" target="_blank" rel="nofollow noopener">FreeBSD Overview series</a></h3>

<ul>
<li>A new blog series we stumbled upon about a Linux user switching to BSD</li>
<li>In part one, he gives a little background on being "done with Linux distros" and documents his initial experience getting and installing FreeBSD 10</li>
<li>He was pleasantly surprised to be able to use ZFS without jumping through hoops and doing custom kernels</li>
<li>Most of what he was used to on Linux was already in the default FreeBSD (except bash...)</li>
<li><a href="http://thiagoperrotta.wordpress.com/2014/07/21/here-be-packages-freebsd-overview-part-ii/" target="_blank" rel="nofollow noopener">Part two</a> documents his experiences with pkgng and ports 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s214FYbOKL" target="_blank" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21cWLhzj4" target="_blank" rel="nofollow noopener">Rick writes in</a></li>
<li><a href="http://slexy.org/view/s21A4grtH0" target="_blank" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s27fQHz8Se" target="_blank" rel="nofollow noopener">Esteban writes in</a></li>
<li><a href="http://slexy.org/view/s21QscO4Cr" target="_blank" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="https://imgur.com/a/Ah444" target="_blank" rel="nofollow noopener">Matt sends in pictures of his FreeBSD CD collection</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>46: Network Iodometry</title>
  <link>https://www.bsdnow.tv/46</link>
  <guid isPermaLink="false">e23303c8-31f0-4706-817c-1618e08cd149</guid>
  <pubDate>Wed, 16 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e23303c8-31f0-4706-817c-1618e08cd149.mp3" length="76226260" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back, and this week we'll be showing you how to tunnel out of a restrictive network using only DNS queries. We also sat down with Bryan Drewery, from the FreeBSD portmgr team, to talk all about their building cluster and some recent changes. All the latest news and answers to your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:45:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back, and this week we'll be showing you how to tunnel out of a restrictive network using only DNS queries. We also sat down with Bryan Drewery, from the FreeBSD portmgr team, to talk all about their building cluster and some recent changes. All the latest news and answers to your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/registration/" target="_blank" rel="nofollow noopener"&gt;EuroBSDCon 2014 registration open&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;September is getting closer, and that means it's time for EuroBSDCon - held in Bulgaria this year&lt;/li&gt;
&lt;li&gt;Registration is finally open to the public, with prices for businesses ($287), individuals ($217) and students ($82) for the main conference until August 18th&lt;/li&gt;
&lt;li&gt;Tutorials, sessions, dev summits and everything else all have their own pricing as well&lt;/li&gt;
&lt;li&gt;Registering between August 18th - September 12th will cost more for everything&lt;/li&gt;
&lt;li&gt;You can &lt;a href="http://registration.eurobsdcon.org/" target="_blank" rel="nofollow noopener"&gt;register online here&lt;/a&gt; and &lt;a href="http://2014.eurobsdcon.org/registration/travel-and-stay/hotels" target="_blank" rel="nofollow noopener"&gt;check hotels in the area&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The FreeBSD foundation is also &lt;a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-July/001577.html" target="_blank" rel="nofollow noopener"&gt;accepting applications&lt;/a&gt; for travel grants
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://marc.info/?t=140440541000002&amp;amp;r=1&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;OpenBSD SMP PF update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A couple weeks ago we talked about how DragonflyBSD updated their PF to be multithreaded&lt;/li&gt;
&lt;li&gt;With them joining the SMP ranks along with FreeBSD, a lot of users have been asking about when OpenBSD is going to make the jump&lt;/li&gt;
&lt;li&gt;In a recent mailing list thread, &lt;a href="http://www.bsdnow.tv/episodes/2013_10_30-current_events" target="_blank" rel="nofollow noopener"&gt;Henning Brauer&lt;/a&gt; addresses some of the concerns&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://marc.info/?l=openbsd-misc&amp;amp;m=140479174521071&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;short version&lt;/a&gt; is that too many things in OpenBSD are currently single-threaded for it to matter - just reworking PF by itself would be useless&lt;/li&gt;
&lt;li&gt;He &lt;a href="http://marc.info/?l=openbsd-misc&amp;amp;m=140481012425889&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;also says&lt;/a&gt; PF on OpenBSD is over four times faster than FreeBSD's old version, presumably due to those extra years of development it's gone through&lt;/li&gt;
&lt;li&gt;There's also been &lt;a href="https://lists.freebsd.org/pipermail/freebsd-pf/2014-July/thread.html" target="_blank" rel="nofollow noopener"&gt;even more recent concern&lt;/a&gt; about the uncertain future of FreeBSD's PF, being mostly unmaintained since their SMP patches&lt;/li&gt;
&lt;li&gt;We reached out to four developers (over week ago) about coming on the show to talk about OpenBSD network performance and SMP, but they all ignored us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://saveosx.org/pkgsrc-intro/" target="_blank" rel="nofollow noopener"&gt;Introduction to NetBSD pkgsrc&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;An article from one of our listeners about how to create a new pkgsrc port or fix one that you need&lt;/li&gt;
&lt;li&gt;The post starts off with how to get the pkgsrc tree, shows how to get the developer tools and finally goes through the Makefile format&lt;/li&gt;
&lt;li&gt;It also lists all the different bmake targets and their functions in relation to the porting process&lt;/li&gt;
&lt;li&gt;Finally, the post details the whole process of creating a new port
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD 9.3-RELEASE&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;After three RCs, FreeBSD 9.3 was scheduled to be finalized and announced &lt;a href="https://www.freebsd.org/releases/9.3R/schedule.html" target="_blank" rel="nofollow noopener"&gt;today&lt;/a&gt; but actually came out yesterday&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener"&gt;The full list of changes&lt;/a&gt; is available, but it's mostly a smaller maintenance release&lt;/li&gt;
&lt;li&gt;Lots of driver updates, ZFS issues fixed, hardware RNGs are entirely disabled by default, netmap framework updates, read-only ext4 support was added, the vt driver was merged from -CURRENT, new hardware support (including radeon KMS), various userland tools got new features, OpenSSL and OpenSSH were updated... and much more&lt;/li&gt;
&lt;li&gt;If you haven't jumped to the 10.x branch yet (and there are a lot of people who haven't!) this is a worthwhile upgrade - 9.2-RELEASE will reach EOL soon&lt;/li&gt;
&lt;li&gt;Good news, this will be &lt;a href="https://twitter.com/evilgjb/status/485909719522222080" target="_blank" rel="nofollow noopener"&gt;the first release&lt;/a&gt; with PGP-signed checksums on the FTP mirrors - a very welcome change&lt;/li&gt;
&lt;li&gt;With that out of the way, the 10.1-RELEASE schedule &lt;a href="https://www.freebsd.org/releases/10.1R/schedule.html" target="_blank" rel="nofollow noopener"&gt;was posted&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Bryan Drewery - &lt;a href="mailto:bdrewery@freebsd.org" target="_blank" rel="nofollow noopener"&gt;bdrewery@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/bdrewery" target="_blank" rel="nofollow noopener"&gt;@bdrewery&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The FreeBSD package building cluster, pkgng, ports, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/ssh-dns" target="_blank" rel="nofollow noopener"&gt;Tunneling traffic through DNS&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.feld.me/posts/2014/07/ssh-two-factor-authentication-on-freebsd/" target="_blank" rel="nofollow noopener"&gt;SSH two-factor authentication on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've previously mentioned stories on how to do two-factor authentication with a Yubikey or via a third party website&lt;/li&gt;
&lt;li&gt;This blog post tells you how to do exactly that, but with your Google account and the pam_google_authenticator port&lt;/li&gt;
&lt;li&gt;Using this setup, every user that logs in with a password will have an extra requirement before they can gain access - but users with public keys can login normally&lt;/li&gt;
&lt;li&gt;It's a really, really simple process once you have the port installed - full details on the page
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.darvilleit.com/why-i-ditched-tape-backup-for-a-custom-made-freenas-backup/" target="_blank" rel="nofollow noopener"&gt;Ditch tape backup in favor of FreeNAS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The author of this post shares some of his horrible experiences with tape backups for a client&lt;/li&gt;
&lt;li&gt;Having constant, daily errors and failed backups, he needed to find another solution&lt;/li&gt;
&lt;li&gt;With 1TB of backups, tapes just weren't a good option anymore - so he switched to FreeNAS (after also ruling out a pre-built NAS)&lt;/li&gt;
&lt;li&gt;The rest of the article details his experiences with it and tells about his setup
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://imil.net/wp/2014/07/02/back-to-2000-2005-freebsd-desktop-2/" target="_blank" rel="nofollow noopener"&gt;NetBSD vs FreeBSD, desktop experiences&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A NetBSD and pkgsrc developer details his experiences running NetBSD on a workstation at his job&lt;/li&gt;
&lt;li&gt;Becoming more and more disappointed with graphics performance, he finally decides to give FreeBSD 10 a try - especially since it has a native nVidia driver&lt;/li&gt;
&lt;li&gt;"Running on VAX, PlayStation 2 and Amiga is fun, but I’ll tell you a little secret: nobody cares anymore about VAX, PlayStation 2 and Amiga."&lt;/li&gt;
&lt;li&gt;He's become pretty satisfied with FreeBSD, a modern choice for a 2014 desktop system 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/07/pc-bsd-feature-digest-31-warden-cli-upgrade-irc-announcement/" target="_blank" rel="nofollow noopener"&gt;PCBSD not-so-weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Speaking of choices for a desktop system, it's the return of the PCBSD digest!&lt;/li&gt;
&lt;li&gt;Warden and PBI_add have gotten some interesting new features&lt;/li&gt;
&lt;li&gt;You can now create jails "on the fly" when adding a new PBI to your application library&lt;/li&gt;
&lt;li&gt;Bulk jail creation is also possible now, and it's really easy&lt;/li&gt;
&lt;li&gt;New Jenkins integration, with public access to &lt;a href="http://builds.pcbsd.org" target="_blank" rel="nofollow noopener"&gt;poudriere logs as well&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;PkgNG 1.3.0.rc2 testing for EDGE users
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21D05MP0t" target="_blank" rel="nofollow noopener"&gt;Jeff writes in&lt;/a&gt; - &lt;a href="http://allanjude.com/zfs_handbook/zfs-zfs.html#zfs-send-ssh" target="_blank" rel="nofollow noopener"&gt;Sending Encrypted Backups over SSH&lt;/a&gt; + &lt;a href="http://wiki.pcbsd.org/index.php/Life_Preserver/10.0#Backing_Up_to_a_FreeNAS_System" target="_blank" rel="nofollow noopener"&gt;Sending ZFS snapshots via user&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2lzo1swzo" target="_blank" rel="nofollow noopener"&gt;Bruce writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20z841ean" target="_blank" rel="nofollow noopener"&gt;Richard writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QYc8BOAo" target="_blank" rel="nofollow noopener"&gt;Jeff writes in&lt;/a&gt; - &lt;a href="http://www.nycbug.org/index.cgi?action=dmesgd" target="_blank" rel="nofollow noopener"&gt;NYCBUG dmesg list&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2V2e1m7S7" target="_blank" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonfly bsd, pc-bsd, tutorial, howto, guide, bsd, interview, iodine, dns, tunnel, ssh, encryption, vpn, ids, bypass, detection, portmgr, pkgng, bypassing, firewall, pkgsrccon, pkgsrc, pf, smp, eurobsdcon, 2014, multithreaded, presentations, talks, two factor authentication, freenas, 9.3</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back, and this week we'll be showing you how to tunnel out of a restrictive network using only DNS queries. We also sat down with Bryan Drewery, from the FreeBSD portmgr team, to talk all about their building cluster and some recent changes. All the latest news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/registration/" target="_blank" rel="nofollow noopener">EuroBSDCon 2014 registration open</a></h3>

<ul>
<li>September is getting closer, and that means it's time for EuroBSDCon - held in Bulgaria this year</li>
<li>Registration is finally open to the public, with prices for businesses ($287), individuals ($217) and students ($82) for the main conference until August 18th</li>
<li>Tutorials, sessions, dev summits and everything else all have their own pricing as well</li>
<li>Registering between August 18th - September 12th will cost more for everything</li>
<li>You can <a href="http://registration.eurobsdcon.org/" target="_blank" rel="nofollow noopener">register online here</a> and <a href="http://2014.eurobsdcon.org/registration/travel-and-stay/hotels" target="_blank" rel="nofollow noopener">check hotels in the area</a></li>
<li>The FreeBSD foundation is also <a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-July/001577.html" target="_blank" rel="nofollow noopener">accepting applications</a> for travel grants
***</li>
</ul>

<h3><a href="http://marc.info/?t=140440541000002&amp;r=1&amp;w=2" target="_blank" rel="nofollow noopener">OpenBSD SMP PF update</a></h3>

<ul>
<li>A couple weeks ago we talked about how DragonflyBSD updated their PF to be multithreaded</li>
<li>With them joining the SMP ranks along with FreeBSD, a lot of users have been asking about when OpenBSD is going to make the jump</li>
<li>In a recent mailing list thread, <a href="http://www.bsdnow.tv/episodes/2013_10_30-current_events" target="_blank" rel="nofollow noopener">Henning Brauer</a> addresses some of the concerns</li>
<li>The <a href="http://marc.info/?l=openbsd-misc&amp;m=140479174521071&amp;w=2" target="_blank" rel="nofollow noopener">short version</a> is that too many things in OpenBSD are currently single-threaded for it to matter - just reworking PF by itself would be useless</li>
<li>He <a href="http://marc.info/?l=openbsd-misc&amp;m=140481012425889&amp;w=2" target="_blank" rel="nofollow noopener">also says</a> PF on OpenBSD is over four times faster than FreeBSD's old version, presumably due to those extra years of development it's gone through</li>
<li>There's also been <a href="https://lists.freebsd.org/pipermail/freebsd-pf/2014-July/thread.html" target="_blank" rel="nofollow noopener">even more recent concern</a> about the uncertain future of FreeBSD's PF, being mostly unmaintained since their SMP patches</li>
<li>We reached out to four developers (over week ago) about coming on the show to talk about OpenBSD network performance and SMP, but they all ignored us
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrc-intro/" target="_blank" rel="nofollow noopener">Introduction to NetBSD pkgsrc</a></h3>

<ul>
<li>An article from one of our listeners about how to create a new pkgsrc port or fix one that you need</li>
<li>The post starts off with how to get the pkgsrc tree, shows how to get the developer tools and finally goes through the Makefile format</li>
<li>It also lists all the different bmake targets and their functions in relation to the porting process</li>
<li>Finally, the post details the whole process of creating a new port
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener">FreeBSD 9.3-RELEASE</a></h3>

<ul>
<li>After three RCs, FreeBSD 9.3 was scheduled to be finalized and announced <a href="https://www.freebsd.org/releases/9.3R/schedule.html" target="_blank" rel="nofollow noopener">today</a> but actually came out yesterday</li>
<li><a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener">The full list of changes</a> is available, but it's mostly a smaller maintenance release</li>
<li>Lots of driver updates, ZFS issues fixed, hardware RNGs are entirely disabled by default, netmap framework updates, read-only ext4 support was added, the vt driver was merged from -CURRENT, new hardware support (including radeon KMS), various userland tools got new features, OpenSSL and OpenSSH were updated... and much more</li>
<li>If you haven't jumped to the 10.x branch yet (and there are a lot of people who haven't!) this is a worthwhile upgrade - 9.2-RELEASE will reach EOL soon</li>
<li>Good news, this will be <a href="https://twitter.com/evilgjb/status/485909719522222080" target="_blank" rel="nofollow noopener">the first release</a> with PGP-signed checksums on the FTP mirrors - a very welcome change</li>
<li>With that out of the way, the 10.1-RELEASE schedule <a href="https://www.freebsd.org/releases/10.1R/schedule.html" target="_blank" rel="nofollow noopener">was posted</a>
***</li>
</ul>

<h2>Interview - Bryan Drewery - <a href="mailto:bdrewery@freebsd.org" target="_blank" rel="nofollow noopener">bdrewery@freebsd.org</a> / <a href="https://twitter.com/bdrewery" target="_blank" rel="nofollow noopener">@bdrewery</a></h2>

<p>The FreeBSD package building cluster, pkgng, ports, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ssh-dns" target="_blank" rel="nofollow noopener">Tunneling traffic through DNS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.feld.me/posts/2014/07/ssh-two-factor-authentication-on-freebsd/" target="_blank" rel="nofollow noopener">SSH two-factor authentication on FreeBSD</a></h3>

<ul>
<li>We've previously mentioned stories on how to do two-factor authentication with a Yubikey or via a third party website</li>
<li>This blog post tells you how to do exactly that, but with your Google account and the pam_google_authenticator port</li>
<li>Using this setup, every user that logs in with a password will have an extra requirement before they can gain access - but users with public keys can login normally</li>
<li>It's a really, really simple process once you have the port installed - full details on the page
***</li>
</ul>

<h3><a href="http://www.darvilleit.com/why-i-ditched-tape-backup-for-a-custom-made-freenas-backup/" target="_blank" rel="nofollow noopener">Ditch tape backup in favor of FreeNAS</a></h3>

<ul>
<li>The author of this post shares some of his horrible experiences with tape backups for a client</li>
<li>Having constant, daily errors and failed backups, he needed to find another solution</li>
<li>With 1TB of backups, tapes just weren't a good option anymore - so he switched to FreeNAS (after also ruling out a pre-built NAS)</li>
<li>The rest of the article details his experiences with it and tells about his setup
***</li>
</ul>

<h3><a href="http://imil.net/wp/2014/07/02/back-to-2000-2005-freebsd-desktop-2/" target="_blank" rel="nofollow noopener">NetBSD vs FreeBSD, desktop experiences</a></h3>

<ul>
<li>A NetBSD and pkgsrc developer details his experiences running NetBSD on a workstation at his job</li>
<li>Becoming more and more disappointed with graphics performance, he finally decides to give FreeBSD 10 a try - especially since it has a native nVidia driver</li>
<li>"Running on VAX, PlayStation 2 and Amiga is fun, but I’ll tell you a little secret: nobody cares anymore about VAX, PlayStation 2 and Amiga."</li>
<li>He's become pretty satisfied with FreeBSD, a modern choice for a 2014 desktop system 
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/07/pc-bsd-feature-digest-31-warden-cli-upgrade-irc-announcement/" target="_blank" rel="nofollow noopener">PCBSD not-so-weekly digest</a></h3>

<ul>
<li>Speaking of choices for a desktop system, it's the return of the PCBSD digest!</li>
<li>Warden and PBI_add have gotten some interesting new features</li>
<li>You can now create jails "on the fly" when adding a new PBI to your application library</li>
<li>Bulk jail creation is also possible now, and it's really easy</li>
<li>New Jenkins integration, with public access to <a href="http://builds.pcbsd.org" target="_blank" rel="nofollow noopener">poudriere logs as well</a></li>
<li>PkgNG 1.3.0.rc2 testing for EDGE users
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21D05MP0t" target="_blank" rel="nofollow noopener">Jeff writes in</a> - <a href="http://allanjude.com/zfs_handbook/zfs-zfs.html#zfs-send-ssh" target="_blank" rel="nofollow noopener">Sending Encrypted Backups over SSH</a> + <a href="http://wiki.pcbsd.org/index.php/Life_Preserver/10.0#Backing_Up_to_a_FreeNAS_System" target="_blank" rel="nofollow noopener">Sending ZFS snapshots via user</a></li>
<li><a href="http://slexy.org/view/s2lzo1swzo" target="_blank" rel="nofollow noopener">Bruce writes in</a></li>
<li><a href="http://slexy.org/view/s20z841ean" target="_blank" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s2QYc8BOAo" target="_blank" rel="nofollow noopener">Jeff writes in</a> - <a href="http://www.nycbug.org/index.cgi?action=dmesgd" target="_blank" rel="nofollow noopener">NYCBUG dmesg list</a></li>
<li><a href="http://slexy.org/view/s2V2e1m7S7" target="_blank" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back, and this week we'll be showing you how to tunnel out of a restrictive network using only DNS queries. We also sat down with Bryan Drewery, from the FreeBSD portmgr team, to talk all about their building cluster and some recent changes. All the latest news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/registration/" target="_blank" rel="nofollow noopener">EuroBSDCon 2014 registration open</a></h3>

<ul>
<li>September is getting closer, and that means it's time for EuroBSDCon - held in Bulgaria this year</li>
<li>Registration is finally open to the public, with prices for businesses ($287), individuals ($217) and students ($82) for the main conference until August 18th</li>
<li>Tutorials, sessions, dev summits and everything else all have their own pricing as well</li>
<li>Registering between August 18th - September 12th will cost more for everything</li>
<li>You can <a href="http://registration.eurobsdcon.org/" target="_blank" rel="nofollow noopener">register online here</a> and <a href="http://2014.eurobsdcon.org/registration/travel-and-stay/hotels" target="_blank" rel="nofollow noopener">check hotels in the area</a></li>
<li>The FreeBSD foundation is also <a href="https://lists.freebsd.org/pipermail/freebsd-announce/2014-July/001577.html" target="_blank" rel="nofollow noopener">accepting applications</a> for travel grants
***</li>
</ul>

<h3><a href="http://marc.info/?t=140440541000002&amp;r=1&amp;w=2" target="_blank" rel="nofollow noopener">OpenBSD SMP PF update</a></h3>

<ul>
<li>A couple weeks ago we talked about how DragonflyBSD updated their PF to be multithreaded</li>
<li>With them joining the SMP ranks along with FreeBSD, a lot of users have been asking about when OpenBSD is going to make the jump</li>
<li>In a recent mailing list thread, <a href="http://www.bsdnow.tv/episodes/2013_10_30-current_events" target="_blank" rel="nofollow noopener">Henning Brauer</a> addresses some of the concerns</li>
<li>The <a href="http://marc.info/?l=openbsd-misc&amp;m=140479174521071&amp;w=2" target="_blank" rel="nofollow noopener">short version</a> is that too many things in OpenBSD are currently single-threaded for it to matter - just reworking PF by itself would be useless</li>
<li>He <a href="http://marc.info/?l=openbsd-misc&amp;m=140481012425889&amp;w=2" target="_blank" rel="nofollow noopener">also says</a> PF on OpenBSD is over four times faster than FreeBSD's old version, presumably due to those extra years of development it's gone through</li>
<li>There's also been <a href="https://lists.freebsd.org/pipermail/freebsd-pf/2014-July/thread.html" target="_blank" rel="nofollow noopener">even more recent concern</a> about the uncertain future of FreeBSD's PF, being mostly unmaintained since their SMP patches</li>
<li>We reached out to four developers (over week ago) about coming on the show to talk about OpenBSD network performance and SMP, but they all ignored us
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrc-intro/" target="_blank" rel="nofollow noopener">Introduction to NetBSD pkgsrc</a></h3>

<ul>
<li>An article from one of our listeners about how to create a new pkgsrc port or fix one that you need</li>
<li>The post starts off with how to get the pkgsrc tree, shows how to get the developer tools and finally goes through the Makefile format</li>
<li>It also lists all the different bmake targets and their functions in relation to the porting process</li>
<li>Finally, the post details the whole process of creating a new port
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener">FreeBSD 9.3-RELEASE</a></h3>

<ul>
<li>After three RCs, FreeBSD 9.3 was scheduled to be finalized and announced <a href="https://www.freebsd.org/releases/9.3R/schedule.html" target="_blank" rel="nofollow noopener">today</a> but actually came out yesterday</li>
<li><a href="https://www.freebsd.org/releases/9.3R/relnotes.html" target="_blank" rel="nofollow noopener">The full list of changes</a> is available, but it's mostly a smaller maintenance release</li>
<li>Lots of driver updates, ZFS issues fixed, hardware RNGs are entirely disabled by default, netmap framework updates, read-only ext4 support was added, the vt driver was merged from -CURRENT, new hardware support (including radeon KMS), various userland tools got new features, OpenSSL and OpenSSH were updated... and much more</li>
<li>If you haven't jumped to the 10.x branch yet (and there are a lot of people who haven't!) this is a worthwhile upgrade - 9.2-RELEASE will reach EOL soon</li>
<li>Good news, this will be <a href="https://twitter.com/evilgjb/status/485909719522222080" target="_blank" rel="nofollow noopener">the first release</a> with PGP-signed checksums on the FTP mirrors - a very welcome change</li>
<li>With that out of the way, the 10.1-RELEASE schedule <a href="https://www.freebsd.org/releases/10.1R/schedule.html" target="_blank" rel="nofollow noopener">was posted</a>
***</li>
</ul>

<h2>Interview - Bryan Drewery - <a href="mailto:bdrewery@freebsd.org" target="_blank" rel="nofollow noopener">bdrewery@freebsd.org</a> / <a href="https://twitter.com/bdrewery" target="_blank" rel="nofollow noopener">@bdrewery</a></h2>

<p>The FreeBSD package building cluster, pkgng, ports, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ssh-dns" target="_blank" rel="nofollow noopener">Tunneling traffic through DNS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.feld.me/posts/2014/07/ssh-two-factor-authentication-on-freebsd/" target="_blank" rel="nofollow noopener">SSH two-factor authentication on FreeBSD</a></h3>

<ul>
<li>We've previously mentioned stories on how to do two-factor authentication with a Yubikey or via a third party website</li>
<li>This blog post tells you how to do exactly that, but with your Google account and the pam_google_authenticator port</li>
<li>Using this setup, every user that logs in with a password will have an extra requirement before they can gain access - but users with public keys can login normally</li>
<li>It's a really, really simple process once you have the port installed - full details on the page
***</li>
</ul>

<h3><a href="http://www.darvilleit.com/why-i-ditched-tape-backup-for-a-custom-made-freenas-backup/" target="_blank" rel="nofollow noopener">Ditch tape backup in favor of FreeNAS</a></h3>

<ul>
<li>The author of this post shares some of his horrible experiences with tape backups for a client</li>
<li>Having constant, daily errors and failed backups, he needed to find another solution</li>
<li>With 1TB of backups, tapes just weren't a good option anymore - so he switched to FreeNAS (after also ruling out a pre-built NAS)</li>
<li>The rest of the article details his experiences with it and tells about his setup
***</li>
</ul>

<h3><a href="http://imil.net/wp/2014/07/02/back-to-2000-2005-freebsd-desktop-2/" target="_blank" rel="nofollow noopener">NetBSD vs FreeBSD, desktop experiences</a></h3>

<ul>
<li>A NetBSD and pkgsrc developer details his experiences running NetBSD on a workstation at his job</li>
<li>Becoming more and more disappointed with graphics performance, he finally decides to give FreeBSD 10 a try - especially since it has a native nVidia driver</li>
<li>"Running on VAX, PlayStation 2 and Amiga is fun, but I’ll tell you a little secret: nobody cares anymore about VAX, PlayStation 2 and Amiga."</li>
<li>He's become pretty satisfied with FreeBSD, a modern choice for a 2014 desktop system 
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/07/pc-bsd-feature-digest-31-warden-cli-upgrade-irc-announcement/" target="_blank" rel="nofollow noopener">PCBSD not-so-weekly digest</a></h3>

<ul>
<li>Speaking of choices for a desktop system, it's the return of the PCBSD digest!</li>
<li>Warden and PBI_add have gotten some interesting new features</li>
<li>You can now create jails "on the fly" when adding a new PBI to your application library</li>
<li>Bulk jail creation is also possible now, and it's really easy</li>
<li>New Jenkins integration, with public access to <a href="http://builds.pcbsd.org" target="_blank" rel="nofollow noopener">poudriere logs as well</a></li>
<li>PkgNG 1.3.0.rc2 testing for EDGE users
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21D05MP0t" target="_blank" rel="nofollow noopener">Jeff writes in</a> - <a href="http://allanjude.com/zfs_handbook/zfs-zfs.html#zfs-send-ssh" target="_blank" rel="nofollow noopener">Sending Encrypted Backups over SSH</a> + <a href="http://wiki.pcbsd.org/index.php/Life_Preserver/10.0#Backing_Up_to_a_FreeNAS_System" target="_blank" rel="nofollow noopener">Sending ZFS snapshots via user</a></li>
<li><a href="http://slexy.org/view/s2lzo1swzo" target="_blank" rel="nofollow noopener">Bruce writes in</a></li>
<li><a href="http://slexy.org/view/s20z841ean" target="_blank" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s2QYc8BOAo" target="_blank" rel="nofollow noopener">Jeff writes in</a> - <a href="http://www.nycbug.org/index.cgi?action=dmesgd" target="_blank" rel="nofollow noopener">NYCBUG dmesg list</a></li>
<li><a href="http://slexy.org/view/s2V2e1m7S7" target="_blank" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>44: Base ISO 100</title>
  <link>https://www.bsdnow.tv/44</link>
  <guid isPermaLink="false">cbf5ab1d-2355-4c2c-ade8-0e66250b204e</guid>
  <pubDate>Wed, 02 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/cbf5ab1d-2355-4c2c-ade8-0e66250b204e.mp3" length="75659476" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:45:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1377" target="_blank" rel="nofollow noopener"&gt;pfSense 2.1.4 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" target="_blank" rel="nofollow noopener"&gt;pfSense team&lt;/a&gt; has released 2.1.4, shortly after 2.1.3 - it's mainly a security release&lt;/li&gt;
&lt;li&gt;Included within are eight security fixes, most of which are pfSense-specific&lt;/li&gt;
&lt;li&gt;OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)&lt;/li&gt;
&lt;li&gt;It also includes a large number of various other bug fixes&lt;/li&gt;
&lt;li&gt;Update all your routers!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" target="_blank" rel="nofollow noopener"&gt;DragonflyBSD's pf gets SMP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;While we're on the topic of pf...&lt;/li&gt;
&lt;li&gt;Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas&lt;/li&gt;
&lt;li&gt;Stemming from &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" target="_blank" rel="nofollow noopener"&gt;a user's complaint&lt;/a&gt;, Matthew Dillon did his own work on pf to make it SMP-aware&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" target="_blank" rel="nofollow noopener"&gt;Altering your configuration&lt;/a&gt;'s ruleset can also help speed things up, he found&lt;/li&gt;
&lt;li&gt;When will OpenBSD, the source of pf, finally do the same?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ianix.com/pub/chacha-deployment.html" target="_blank" rel="nofollow noopener"&gt;ChaCha usage and deployment&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A while back, &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener"&gt;we talked to djm&lt;/a&gt; about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5&lt;/li&gt;
&lt;li&gt;This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20&lt;/li&gt;
&lt;li&gt;OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it&lt;/li&gt;
&lt;li&gt;Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not&lt;/li&gt;
&lt;li&gt;Unfortunately, this article has one mistake: FreeBSD &lt;a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" target="_blank" rel="nofollow noopener"&gt;does not use it&lt;/a&gt; - they &lt;em&gt;still&lt;/em&gt; use the broken RC4 algorithm
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" target="_blank" rel="nofollow noopener"&gt;BSDMag June 2014 issue&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The monthly online BSD magazine releases their newest issue&lt;/li&gt;
&lt;li&gt;This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities&lt;/li&gt;
&lt;li&gt;The free pdf file is available for download as always
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Craig Rodrigues - &lt;a href="mailto:rodrigc@freebsd.org" target="_blank" rel="nofollow noopener"&gt;rodrigc@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD's &lt;a href="https://wiki.freebsd.org/Jenkins" target="_blank" rel="nofollow noopener"&gt;continuous&lt;/a&gt; &lt;a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" target="_blank" rel="nofollow noopener"&gt;testing&lt;/a&gt; &lt;a href="https://jenkins.freebsd.org/jenkins/" target="_blank" rel="nofollow noopener"&gt;infrastructure&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/stable-iso" target="_blank" rel="nofollow noopener"&gt;Creating pre-patched OpenBSD ISOs&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" target="_blank" rel="nofollow noopener"&gt;Preauthenticated decryption considered harmful&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Responding to &lt;a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" target="_blank" rel="nofollow noopener"&gt;a post&lt;/a&gt; from Adam Langley, &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; talks a little more about how signify and pkg_add handle signatures&lt;/li&gt;
&lt;li&gt;In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns&lt;/li&gt;
&lt;li&gt;With signify, now everything is fully downloaded and verified before tar is even invoked&lt;/li&gt;
&lt;li&gt;The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post&lt;/li&gt;
&lt;li&gt;Be sure to also read the original post from Adam, lots of good information
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD 9.3-RC2 is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As the -RELEASE inches closer, release candidate 2 is out and ready for testing&lt;/li&gt;
&lt;li&gt;Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things&lt;/li&gt;
&lt;li&gt;The updated bsdconfig will use pkgng style packages now too&lt;/li&gt;
&lt;li&gt;A lesser known fact: there are also premade virtual machine images you can use too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://saveosx.org/pkgsrcCon/" target="_blank" rel="nofollow noopener"&gt;pkgsrcCon 2014 wrap-up&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In what may be the first real pkgsrcCon article we've ever had!&lt;/li&gt;
&lt;li&gt;Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event&lt;/li&gt;
&lt;li&gt;Unfortunately no recordings to be found...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" target="_blank" rel="nofollow noopener"&gt;PostgreSQL FreeBSD performance and scalability&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales&lt;/li&gt;
&lt;li&gt;On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings&lt;/li&gt;
&lt;li&gt;Lots of technical details if you're interested in getting the best performance out of your hardware&lt;/li&gt;
&lt;li&gt;It also includes specific kernel options he used and the rest of the configuration&lt;/li&gt;
&lt;li&gt;If you don't want to open the pdf file, you can &lt;a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" target="_blank" rel="nofollow noopener"&gt;use this link&lt;/a&gt; too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s24pFjUPe4" target="_blank" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21OogIgTu" target="_blank" rel="nofollow noopener"&gt;Klemen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21rLcemNN" target="_blank" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s203Qsx6CZ" target="_blank" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2eBj0FfSL" target="_blank" rel="nofollow noopener"&gt;Adam writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, iso, patch, stable, cd, dvd, cdr, pre-applied, applied, horrible puns, jenkins, testing, kyua, ixsystems, tarsnap, pfsense, freenas, tarsnap, ixsystems, pfsense, freenas, bsdmag, magazine, ssl, tls, hardening, hardened, security, pf, smp, multithreading, firewall, scalability, postgresql, mysql, sql, database, performance, openssl, libressl, boringssl, google, chacha, chacha20, salsa20, encryption, pkgsrc, pkgsrccon, signify, pkg_add, authenticated encryption, decryption, gcm</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://blog.pfsense.org/?p=1377" target="_blank" rel="nofollow noopener">pfSense 2.1.4 released</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" target="_blank" rel="nofollow noopener">pfSense team</a> has released 2.1.4, shortly after 2.1.3 - it's mainly a security release</li>
<li>Included within are eight security fixes, most of which are pfSense-specific</li>
<li>OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)</li>
<li>It also includes a large number of various other bug fixes</li>
<li>Update all your routers!
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" target="_blank" rel="nofollow noopener">DragonflyBSD's pf gets SMP</a></h3>

<ul>
<li>While we're on the topic of pf...</li>
<li>Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas</li>
<li>Stemming from <a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" target="_blank" rel="nofollow noopener">a user's complaint</a>, Matthew Dillon did his own work on pf to make it SMP-aware</li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" target="_blank" rel="nofollow noopener">Altering your configuration</a>'s ruleset can also help speed things up, he found</li>
<li>When will OpenBSD, the source of pf, finally do the same?
***</li>
</ul>

<h3><a href="http://ianix.com/pub/chacha-deployment.html" target="_blank" rel="nofollow noopener">ChaCha usage and deployment</a></h3>

<ul>
<li>A while back, <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">we talked to djm</a> about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5</li>
<li>This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20</li>
<li>OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it</li>
<li>Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not</li>
<li>Unfortunately, this article has one mistake: FreeBSD <a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" target="_blank" rel="nofollow noopener">does not use it</a> - they <em>still</em> use the broken RC4 algorithm
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" target="_blank" rel="nofollow noopener">BSDMag June 2014 issue</a></h3>

<ul>
<li>The monthly online BSD magazine releases their newest issue</li>
<li>This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities</li>
<li>The free pdf file is available for download as always
***</li>
</ul>

<h2>Interview - Craig Rodrigues - <a href="mailto:rodrigc@freebsd.org" target="_blank" rel="nofollow noopener">rodrigc@freebsd.org</a></h2>

<p>FreeBSD's <a href="https://wiki.freebsd.org/Jenkins" target="_blank" rel="nofollow noopener">continuous</a> <a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" target="_blank" rel="nofollow noopener">testing</a> <a href="https://jenkins.freebsd.org/jenkins/" target="_blank" rel="nofollow noopener">infrastructure</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/stable-iso" target="_blank" rel="nofollow noopener">Creating pre-patched OpenBSD ISOs</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" target="_blank" rel="nofollow noopener">Preauthenticated decryption considered harmful</a></h3>

<ul>
<li>Responding to <a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" target="_blank" rel="nofollow noopener">a post</a> from Adam Langley, <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> talks a little more about how signify and pkg_add handle signatures</li>
<li>In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns</li>
<li>With signify, now everything is fully downloaded and verified before tar is even invoked</li>
<li>The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post</li>
<li>Be sure to also read the original post from Adam, lots of good information
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" target="_blank" rel="nofollow noopener">FreeBSD 9.3-RC2 is out</a></h3>

<ul>
<li>As the -RELEASE inches closer, release candidate 2 is out and ready for testing</li>
<li>Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things</li>
<li>The updated bsdconfig will use pkgng style packages now too</li>
<li>A lesser known fact: there are also premade virtual machine images you can use too
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrcCon/" target="_blank" rel="nofollow noopener">pkgsrcCon 2014 wrap-up</a></h3>

<ul>
<li>In what may be the first real pkgsrcCon article we've ever had!</li>
<li>Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event</li>
<li>Unfortunately no recordings to be found...
***</li>
</ul>

<h3><a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" target="_blank" rel="nofollow noopener">PostgreSQL FreeBSD performance and scalability</a></h3>

<ul>
<li>FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales</li>
<li>On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings</li>
<li>Lots of technical details if you're interested in getting the best performance out of your hardware</li>
<li>It also includes specific kernel options he used and the rest of the configuration</li>
<li>If you don't want to open the pdf file, you can <a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" target="_blank" rel="nofollow noopener">use this link</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s24pFjUPe4" target="_blank" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21OogIgTu" target="_blank" rel="nofollow noopener">Klemen writes in</a></li>
<li><a href="http://slexy.org/view/s21rLcemNN" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s203Qsx6CZ" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2eBj0FfSL" target="_blank" rel="nofollow noopener">Adam writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be sitting down to talk with Craig Rodrigues about Jenkins and the FreeBSD testing infrastructure. Following that, we'll show you how to roll your own OpenBSD ISOs with all the patches already applied... ISO can't wait! This week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://blog.pfsense.org/?p=1377" target="_blank" rel="nofollow noopener">pfSense 2.1.4 released</a></h3>

<ul>
<li>The <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" target="_blank" rel="nofollow noopener">pfSense team</a> has released 2.1.4, shortly after 2.1.3 - it's mainly a security release</li>
<li>Included within are eight security fixes, most of which are pfSense-specific</li>
<li>OpenSSL, the WebUI and some packages all need to be patched (and there are instructions on how to do so)</li>
<li>It also includes a large number of various other bug fixes</li>
<li>Update all your routers!
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2014-June/270300.html" target="_blank" rel="nofollow noopener">DragonflyBSD's pf gets SMP</a></h3>

<ul>
<li>While we're on the topic of pf...</li>
<li>Dragonfly patches their old[er than even FreeBSD's] pf to support multithreading in many areas</li>
<li>Stemming from <a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128664.html" target="_blank" rel="nofollow noopener">a user's complaint</a>, Matthew Dillon did his own work on pf to make it SMP-aware</li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2014-June/128671.html" target="_blank" rel="nofollow noopener">Altering your configuration</a>'s ruleset can also help speed things up, he found</li>
<li>When will OpenBSD, the source of pf, finally do the same?
***</li>
</ul>

<h3><a href="http://ianix.com/pub/chacha-deployment.html" target="_blank" rel="nofollow noopener">ChaCha usage and deployment</a></h3>

<ul>
<li>A while back, <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">we talked to djm</a> about some cryptography changes in OpenBSD 5.5 and OpenSSH 6.5</li>
<li>This article is sort of an interesting follow-up to that, showing which projects have adopted ChaCha20</li>
<li>OpenSSH offers it as a stream cipher now, OpenBSD uses it for it's random number generator, Google offers it in TLS for Chromium and some of their services and lots of other projects seem to be adopting it</li>
<li>Both Google's fork of OpenSSL and LibReSSL have upcoming implementations, while vanilla OpenSSL does not</li>
<li>Unfortunately, this article has one mistake: FreeBSD <a href="https://lists.freebsd.org/pipermail/freebsd-bugs/2013-October/054018.html" target="_blank" rel="nofollow noopener">does not use it</a> - they <em>still</em> use the broken RC4 algorithm
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1864-tls-hardening-june-bsd-magazine-issue" target="_blank" rel="nofollow noopener">BSDMag June 2014 issue</a></h3>

<ul>
<li>The monthly online BSD magazine releases their newest issue</li>
<li>This one includes the following articles: TLS hardening, setting up a package cluster in MidnightBSD, more GIMP tutorials, "saving time and headaches using the robot framework for testing," an interview and an article about the increasing number of security vulnerabilities</li>
<li>The free pdf file is available for download as always
***</li>
</ul>

<h2>Interview - Craig Rodrigues - <a href="mailto:rodrigc@freebsd.org" target="_blank" rel="nofollow noopener">rodrigc@freebsd.org</a></h2>

<p>FreeBSD's <a href="https://wiki.freebsd.org/Jenkins" target="_blank" rel="nofollow noopener">continuous</a> <a href="https://docs.google.com/presentation/d/1yBiPxS1nKnVwRlAEsYeAOzYdpG5uzXTv1_7i7jwVCfU/edit#slide=id.p" target="_blank" rel="nofollow noopener">testing</a> <a href="https://jenkins.freebsd.org/jenkins/" target="_blank" rel="nofollow noopener">infrastructure</a></p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/stable-iso" target="_blank" rel="nofollow noopener">Creating pre-patched OpenBSD ISOs</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.tedunangst.com/flak/post/preauthenticated-decryption-considered-harmful" target="_blank" rel="nofollow noopener">Preauthenticated decryption considered harmful</a></h3>

<ul>
<li>Responding to <a href="https://www.imperialviolet.org/2014/06/27/streamingencryption.html" target="_blank" rel="nofollow noopener">a post</a> from Adam Langley, <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" target="_blank" rel="nofollow noopener">Ted Unangst</a> talks a little more about how signify and pkg_add handle signatures</li>
<li>In the past, the OpenBSD installer would pipe the output of ftp straight to tar, but then verify the SHA256 at the end - this had the advantage of not requiring any extra disk space, but raised some security concerns</li>
<li>With signify, now everything is fully downloaded and verified before tar is even invoked</li>
<li>The pkg_add utility works a little bit differently, but it's also been improved in this area - details in the post</li>
<li>Be sure to also read the original post from Adam, lots of good information
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-June/079092.html" target="_blank" rel="nofollow noopener">FreeBSD 9.3-RC2 is out</a></h3>

<ul>
<li>As the -RELEASE inches closer, release candidate 2 is out and ready for testing</li>
<li>Since the last one, it's got some fixes for NIC drivers, the latest file and libmagic security fixes, some serial port workarounds and various other small things</li>
<li>The updated bsdconfig will use pkgng style packages now too</li>
<li>A lesser known fact: there are also premade virtual machine images you can use too
***</li>
</ul>

<h3><a href="http://saveosx.org/pkgsrcCon/" target="_blank" rel="nofollow noopener">pkgsrcCon 2014 wrap-up</a></h3>

<ul>
<li>In what may be the first real pkgsrcCon article we've ever had!</li>
<li>Includes wrap-up discussion about the event, the talks, the speakers themselves, what they use pkgsrc for, the hackathon and basically the whole event</li>
<li>Unfortunately no recordings to be found...
***</li>
</ul>

<h3><a href="https://kib.kiev.ua/kib/pgsql_perf.pdf" target="_blank" rel="nofollow noopener">PostgreSQL FreeBSD performance and scalability</a></h3>

<ul>
<li>FreeBSD developer kib@ writes a report on PostgreSQL on FreeBSD, and how it scales</li>
<li>On his monster 40-core box with 1TB of RAM, he runs lots of benchmarks and posts the findings</li>
<li>Lots of technical details if you're interested in getting the best performance out of your hardware</li>
<li>It also includes specific kernel options he used and the rest of the configuration</li>
<li>If you don't want to open the pdf file, you can <a href="https://docs.google.com/viewer?url=https%3A%2F%2Fkib.kiev.ua%2Fkib%2Fpgsql_perf.pdf" target="_blank" rel="nofollow noopener">use this link</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s24pFjUPe4" target="_blank" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s21OogIgTu" target="_blank" rel="nofollow noopener">Klemen writes in</a></li>
<li><a href="http://slexy.org/view/s21rLcemNN" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s203Qsx6CZ" target="_blank" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2eBj0FfSL" target="_blank" rel="nofollow noopener">Adam writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>43: Package Design</title>
  <link>https://www.bsdnow.tv/43</link>
  <guid isPermaLink="false">d4b10034-d20a-44a6-a918-a57335debcae</guid>
  <pubDate>Wed, 25 Jun 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d4b10034-d20a-44a6-a918-a57335debcae.mp3" length="62389876" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:26:39</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/talks-and-schedule/" target="_blank" rel="nofollow noopener"&gt;EuroBSDCon 2014 talks and schedule&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The talks and schedules for EuroBSDCon 2014 are finally revealed&lt;/li&gt;
&lt;li&gt;The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh&lt;/li&gt;
&lt;li&gt;Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great&lt;/li&gt;
&lt;li&gt;It looks like Theo even has a talk, but the title isn't on the page... how mysterious&lt;/li&gt;
&lt;li&gt;There are also days dedicated to some really interesting tutorials&lt;/li&gt;
&lt;li&gt;Register now, the conference is on September 25-28th in Bulgaria&lt;/li&gt;
&lt;li&gt;If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen&lt;/li&gt;
&lt;li&gt;Why aren't the videos up from last year yet? Will this year also not have any?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" target="_blank" rel="nofollow noopener"&gt;FreeNAS vs NAS4Free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;More mainstream news covering BSD, this time with an article about different NAS solutions&lt;/li&gt;
&lt;li&gt;In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free&lt;/li&gt;
&lt;li&gt;Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect&lt;/li&gt;
&lt;li&gt;Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project&lt;/li&gt;
&lt;li&gt;"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://queue.acm.org/detail.cfm?id=2636165" target="_blank" rel="nofollow noopener"&gt;Quality software costs money, heartbleed was free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" target="_blank" rel="nofollow noopener"&gt;PHK&lt;/a&gt; writes an article for ACM Queue about open source software projects' funding efforts&lt;/li&gt;
&lt;li&gt;A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc&lt;/li&gt;
&lt;li&gt;The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding&lt;/li&gt;
&lt;li&gt;The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them&lt;/li&gt;
&lt;li&gt;On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"&lt;/li&gt;
&lt;li&gt;Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" target="_blank" rel="nofollow noopener"&gt;Geoblock evasion with pf and OpenBSD rdomains&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Geoblocking is a way for websites to block visitors based on the location of their IP&lt;/li&gt;
&lt;li&gt;This is a blog post about how to get around it, using pf and rdomains&lt;/li&gt;
&lt;li&gt;It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;a tutorial about that&lt;/a&gt;...)&lt;/li&gt;
&lt;li&gt;In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia&lt;/li&gt;
&lt;li&gt;It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Marc Espie - &lt;a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener"&gt;espie@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener"&gt;@espie_openbsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's package system, building cluster, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/upgrade" target="_blank" rel="nofollow noopener"&gt;Keeping your BSD up to date&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" target="_blank" rel="nofollow noopener"&gt;BoringSSL and LibReSSL&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another OpenSSL fork pops up, this time from Google, called BoringSSL&lt;/li&gt;
&lt;li&gt;Adam Langley has a blog post about it, why they did it and how they're going to maintain it&lt;/li&gt;
&lt;li&gt;You can easily browse &lt;a href="https://boringssl.googlesource.com/" target="_blank" rel="nofollow noopener"&gt;the source code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Theo de Raadt also &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140332790726752&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;weighs in&lt;/a&gt; with how this effort relates to LibReSSL&lt;/li&gt;
&lt;li&gt;More eyes on the code is good, and patches will be shared between the two projects
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" target="_blank" rel="nofollow noopener"&gt;More BSD Tor nodes wanted&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" target="_blank" rel="nofollow noopener"&gt;Originally discussed&lt;/a&gt; on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network&lt;/li&gt;
&lt;li&gt;If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.&lt;/li&gt;
&lt;li&gt;The EFF is also holding a &lt;a href="https://www.eff.org/torchallenge/" target="_blank" rel="nofollow noopener"&gt;Tor challenge&lt;/a&gt; for people to start up new relays and keep them online for over a year&lt;/li&gt;
&lt;li&gt;Check out our &lt;a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener"&gt;Tor tutorial&lt;/a&gt; and help out the network, and promote BSD at the same time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD 10 OpenStack images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."&lt;/li&gt;
&lt;li&gt;The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"&lt;/li&gt;
&lt;li&gt;The author of the article is a regular listener and emailer of the show, hey!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" target="_blank" rel="nofollow noopener"&gt;BSDday 2014 call for papers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSD Day, a conference not so well-known, is going to be held August 9th in Argentina&lt;/li&gt;
&lt;li&gt;It was created in 2008 and is the only BSD conference around that area&lt;/li&gt;
&lt;li&gt;The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk&lt;/li&gt;
&lt;li&gt;Sysadmins, developers and regular users are, of course, all welcome to come to the event
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20nTYO2w1" target="_blank" rel="nofollow noopener"&gt;Maruf writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cvV6mRP" target="_blank" rel="nofollow noopener"&gt;Solomon writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2MK8sbea0" target="_blank" rel="nofollow noopener"&gt;Silas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Yz97YlzI" target="_blank" rel="nofollow noopener"&gt;Bert writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ports, packages, cluster, building, pkg_add, freenas, ixsystems, tarsnap, eurobsdcon, bulgaria, 2014, talks, presentation, slides, Poul-Henning Kamp, phk, schedule, freenas, nas4free, nas, geoblock, evasion, bypassing, ip ban, pf, firewall, rdomains, glusterfs, marc espie, boringssl, openssl, libressl, upgrades, how to upgrade, update, rebuild, tor, tor nodes, relays, exit node, eff, tor challenge, aslr, pie, security, bsdday, openstack, bsd-cloudinit, cloud computing</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" target="_blank" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" target="_blank" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" target="_blank" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" target="_blank" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" target="_blank" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" target="_blank" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" target="_blank" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" target="_blank" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" target="_blank" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" target="_blank" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" target="_blank" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" target="_blank" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" target="_blank" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" target="_blank" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" target="_blank" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" target="_blank" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" target="_blank" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" target="_blank" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" target="_blank" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" target="_blank" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" target="_blank" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" target="_blank" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" target="_blank" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" target="_blank" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" target="_blank" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" target="_blank" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" target="_blank" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" target="_blank" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" target="_blank" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" target="_blank" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" target="_blank" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" target="_blank" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" target="_blank" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" target="_blank" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" target="_blank" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" target="_blank" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" target="_blank" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" target="_blank" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>40: AirPorts &amp; Packages</title>
  <link>https://www.bsdnow.tv/40</link>
  <guid isPermaLink="false">f9c8a284-4fd9-4c5d-9137-77062c5814b4</guid>
  <pubDate>Wed, 04 Jun 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/f9c8a284-4fd9-4c5d-9137-77062c5814b4.mp3" length="52844692" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>On this week's episode, we'll be giving you an introductory guide on OpenBSD's ports and package system. There's also a pretty fly interview with Karl Lehenbauer, about how they use FreeBSD at FlightAware. Lots of interesting news and answers to all your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:13:23</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;On this week's episode, we'll be giving you an introductory guide on OpenBSD's ports and package system. There's also a pretty fly interview with Karl Lehenbauer, about how they use FreeBSD at FlightAware. Lots of interesting news and answers to all your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2014/schedule/" target="_blank" rel="nofollow noopener"&gt;BSDCan 2014 talks and reports, part 2&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;More presentations and trip reports are still being uploaded&lt;/li&gt;
&lt;li&gt;Ingo Schwarze, &lt;a href="https://www.youtube.com/watch?v=oifYhwTaOuw" target="_blank" rel="nofollow noopener"&gt;New Trends in mandoc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Vsevolod Stakhov, &lt;a href="https://www.youtube.com/watch?v=3SOKFz2UUQ4" target="_blank" rel="nofollow noopener"&gt;The Architecture of the New Solver in pkg
&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Julio Merino, &lt;a href="https://www.youtube.com/watch?v=nf-bFeKaZsY" target="_blank" rel="nofollow noopener"&gt;The FreeBSD Test Suite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Zbigniew Bodek, &lt;a href="https://www.youtube.com/watch?v=s5iIKEHtbX8" target="_blank" rel="nofollow noopener"&gt;Transparent Superpages for FreeBSD on ARM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="http://freebsdfoundation.blogspot.com/2014/06/bsdcan-trip-report-michael-dexter.html" target="_blank" rel="nofollow noopener"&gt;trip report from Michael Dexter&lt;/a&gt; and another (very long and detailed) &lt;a href="http://freebsdfoundation.blogspot.com/2014/05/bsdcan-trip-report-warren-block.html" target="_blank" rel="nofollow noopener"&gt;trip report&lt;/a&gt; from our friend &lt;a href="http://www.bsdnow.tv/episodes/2014_03_26-documentation_is_king" target="_blank" rel="nofollow noopener"&gt;Warren Block&lt;/a&gt; that even gives us some linkage, thanks!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=JrFfrrY-yOo" target="_blank" rel="nofollow noopener"&gt;Beyond security, getting to know OpenBSD's real purpose&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener"&gt;Michael W Lucas&lt;/a&gt; (who, we learn through this video, has been using BSD since 1986) gave a "webcast" last week, and the audio and slides are finally up&lt;/li&gt;
&lt;li&gt;It clocks in at just over 30 minutes, managing to touch on a lot of OpenBSD topics&lt;/li&gt;
&lt;li&gt;Some of those topics include: what is OpenBSD and why you should care, the philosophy of the project, how it serves as a "pressure cooker for ideas," briefly touches on GPL vs BSDL, their "do it right or don't do it at all" attitude, their stance on NDAs and blobs, recent LibreSSL development, some of the security functions that OpenBSD enabled before anyone else (and the ripple effect that had) and, of course, their disturbing preference for comic sans&lt;/li&gt;
&lt;li&gt;Here's a direct link to &lt;a href="https://wcc.on24.com/event/76/67/12/rt/1/documents/resourceList1400781110933/20140527_beyond_security_openbsd.pdf" target="_blank" rel="nofollow noopener"&gt;the slides&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Great presentation if you'd like to learn a bit about OpenBSD, but also contains a bit of information that long-time users might not know too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://brioteam.com/linux-versus-freebsd-comprehensive-comparison" target="_blank" rel="nofollow noopener"&gt;FreeBSD vs Linux, a comprehensive comparison&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another blog post covering something people seem to be obsessed with - FreeBSD vs Linux&lt;/li&gt;
&lt;li&gt;This one was worth mentioning because it's very thorough in regards to how things are done behind the scenes, not just the usual technical differences&lt;/li&gt;
&lt;li&gt;It highlights the concept of a "core team" and their role vs "contributors" and "committers" (similar to a presentation Kirk McKusick did not long ago)&lt;/li&gt;
&lt;li&gt;While a lot of things will be the same on both platforms, you might still be asking "which one is right for me?" - this article weighs in with some points for both sides and different use cases&lt;/li&gt;
&lt;li&gt;Pretty well-written and unbiased article that also mentions areas where Linux might be better, so don't hate us for linking it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.openlogic.com/wazi/bid/345617/Expand-FreeNAS-with-plugins" target="_blank" rel="nofollow noopener"&gt;Expand FreeNAS with plugins&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the things people love the most about FreeNAS (other than ZFS) is their cool plugin framework&lt;/li&gt;
&lt;li&gt;With these plugins, you can greatly expand the feature set of your NAS via third party programs&lt;/li&gt;
&lt;li&gt;This page talks about a few of the more popular ones and how they can be used to improve your NAS or media box experience&lt;/li&gt;
&lt;li&gt;Some examples include setting up an OwnCloud server, Bacula for backups, Maraschino for managing a home theater PC, Plex Media Server for an easy to use video experience and a few more&lt;/li&gt;
&lt;li&gt;It then goes into more detail about each of them, how to actually install plugins and then how to set them up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Karl Lehenbauer - &lt;a href="mailto:karl@flightaware.com" target="_blank" rel="nofollow noopener"&gt;karl@flightaware.com&lt;/a&gt; / &lt;a href="https://twitter.com/flightaware" target="_blank" rel="nofollow noopener"&gt;@flightaware&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD at FlightAware, BSD history, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener"&gt;Ports and packages in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://julipedia.meroh.net/2014/05/code-review-culture-meets-freebsd.html" target="_blank" rel="nofollow noopener"&gt;Code review culture meets FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In most of the BSDs, changes need to be reviewed by more than one person before being committed to the tree&lt;/li&gt;
&lt;li&gt;This article describes Phabricator, an open source code review system that we briefly mentioned last week&lt;/li&gt;
&lt;li&gt;Instructions for using it are on &lt;a href="https://wiki.freebsd.org/CodeReview" target="_blank" rel="nofollow noopener"&gt;the wiki&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;While not approved by the core team yet for anything official, it's in a testing phase and developers are encouraged to try it out and get their patches reviewed&lt;/li&gt;
&lt;li&gt;&lt;a href="http://phabric.freebsd.org/" target="_blank" rel="nofollow noopener"&gt;Just look at that fancy interface!!&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2088" target="_blank" rel="nofollow noopener"&gt;Upcoming BSD books&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Sneaky MWL somehow finds his way into both our headlines and the news roundup&lt;/li&gt;
&lt;li&gt;He gives us an update on the next BSD books that he's planning to release&lt;/li&gt;
&lt;li&gt;The plan is to release three (or so) books based on different aspects of FreeBSD's storage system(s) - GEOM, UFS, ZFS, etc.&lt;/li&gt;
&lt;li&gt;This has the advantage of only requiring you to buy the one(s) you're specifically interested in&lt;/li&gt;
&lt;li&gt;"When will they be released? When I'm done writing them. How much will they cost? Dunno."&lt;/li&gt;
&lt;li&gt;It's not Absolute FreeBSD 3rd edition...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=VjYb9mKB4jU" target="_blank" rel="nofollow noopener"&gt;CARP failover and high availability on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you're running a cluster or a group of servers, you should have some sort of failover in place&lt;/li&gt;
&lt;li&gt;But the question comes up, "how do you load balance the load balancers!?"&lt;/li&gt;
&lt;li&gt;This video goes through the process of giving more than one machine the same IP, how to set up CARP, securing it and demonstrates a node dying&lt;/li&gt;
&lt;li&gt;Also mentions DNS-based load balancing as another option
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-30/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This time in PCBSD land, we're getting ready for the 10.0.2 release &lt;a href="http://download.pcbsd.org/iso/10.0-RELEASE/testing/amd64/" target="_blank" rel="nofollow noopener"&gt;(ISOs here)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;AppCafe got a good number of fixes, and now shows 10 random highlighted applications&lt;/li&gt;
&lt;li&gt;EasyPBI added a "bulk" mode to create PBIs of an entire FreeBSD port category&lt;/li&gt;
&lt;li&gt;Lumina, the new desktop environment, is still being worked on and got some bug fixes too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s205iiKiWp" target="_blank" rel="nofollow noopener"&gt;Paul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2060bkTNl" target="_blank" rel="nofollow noopener"&gt;Matt writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2G7eMC6oP" target="_blank" rel="nofollow noopener"&gt;Kjell writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2REfzMFGK" target="_blank" rel="nofollow noopener"&gt;Paul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21nvJtXY6" target="_blank" rel="nofollow noopener"&gt;Tom writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, flightaware, karl lehenbauer, keynote, bsdcan, 2014, webcast, beyond security, libressl, linux, bsd vs linux, freenas, plugins, jails, plex media server, plex, owncloud, tarsnap, ixsystems, code review, kyua, geom, ufs, zfs, books, absolute freebsd, carp, failover, high availability, firewalls, pf, ipfw, load balancing</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>On this week's episode, we'll be giving you an introductory guide on OpenBSD's ports and package system. There's also a pretty fly interview with Karl Lehenbauer, about how they use FreeBSD at FlightAware. Lots of interesting news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" target="_blank" rel="nofollow noopener">BSDCan 2014 talks and reports, part 2</a></h3>

<ul>
<li>More presentations and trip reports are still being uploaded</li>
<li>Ingo Schwarze, <a href="https://www.youtube.com/watch?v=oifYhwTaOuw" target="_blank" rel="nofollow noopener">New Trends in mandoc</a></li>
<li>Vsevolod Stakhov, <a href="https://www.youtube.com/watch?v=3SOKFz2UUQ4" target="_blank" rel="nofollow noopener">The Architecture of the New Solver in pkg
</a></li>
<li>Julio Merino, <a href="https://www.youtube.com/watch?v=nf-bFeKaZsY" target="_blank" rel="nofollow noopener">The FreeBSD Test Suite</a></li>
<li>Zbigniew Bodek, <a href="https://www.youtube.com/watch?v=s5iIKEHtbX8" target="_blank" rel="nofollow noopener">Transparent Superpages for FreeBSD on ARM</a></li>
<li>There's also a <a href="http://freebsdfoundation.blogspot.com/2014/06/bsdcan-trip-report-michael-dexter.html" target="_blank" rel="nofollow noopener">trip report from Michael Dexter</a> and another (very long and detailed) <a href="http://freebsdfoundation.blogspot.com/2014/05/bsdcan-trip-report-warren-block.html" target="_blank" rel="nofollow noopener">trip report</a> from our friend <a href="http://www.bsdnow.tv/episodes/2014_03_26-documentation_is_king" target="_blank" rel="nofollow noopener">Warren Block</a> that even gives us some linkage, thanks!
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=JrFfrrY-yOo" target="_blank" rel="nofollow noopener">Beyond security, getting to know OpenBSD's real purpose</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael W Lucas</a> (who, we learn through this video, has been using BSD since 1986) gave a "webcast" last week, and the audio and slides are finally up</li>
<li>It clocks in at just over 30 minutes, managing to touch on a lot of OpenBSD topics</li>
<li>Some of those topics include: what is OpenBSD and why you should care, the philosophy of the project, how it serves as a "pressure cooker for ideas," briefly touches on GPL vs BSDL, their "do it right or don't do it at all" attitude, their stance on NDAs and blobs, recent LibreSSL development, some of the security functions that OpenBSD enabled before anyone else (and the ripple effect that had) and, of course, their disturbing preference for comic sans</li>
<li>Here's a direct link to <a href="https://wcc.on24.com/event/76/67/12/rt/1/documents/resourceList1400781110933/20140527_beyond_security_openbsd.pdf" target="_blank" rel="nofollow noopener">the slides</a></li>
<li>Great presentation if you'd like to learn a bit about OpenBSD, but also contains a bit of information that long-time users might not know too
***</li>
</ul>

<h3><a href="http://brioteam.com/linux-versus-freebsd-comprehensive-comparison" target="_blank" rel="nofollow noopener">FreeBSD vs Linux, a comprehensive comparison</a></h3>

<ul>
<li>Another blog post covering something people seem to be obsessed with - FreeBSD vs Linux</li>
<li>This one was worth mentioning because it's very thorough in regards to how things are done behind the scenes, not just the usual technical differences</li>
<li>It highlights the concept of a "core team" and their role vs "contributors" and "committers" (similar to a presentation Kirk McKusick did not long ago)</li>
<li>While a lot of things will be the same on both platforms, you might still be asking "which one is right for me?" - this article weighs in with some points for both sides and different use cases</li>
<li>Pretty well-written and unbiased article that also mentions areas where Linux might be better, so don't hate us for linking it
***</li>
</ul>

<h3><a href="http://www.openlogic.com/wazi/bid/345617/Expand-FreeNAS-with-plugins" target="_blank" rel="nofollow noopener">Expand FreeNAS with plugins</a></h3>

<ul>
<li>One of the things people love the most about FreeNAS (other than ZFS) is their cool plugin framework</li>
<li>With these plugins, you can greatly expand the feature set of your NAS via third party programs</li>
<li>This page talks about a few of the more popular ones and how they can be used to improve your NAS or media box experience</li>
<li>Some examples include setting up an OwnCloud server, Bacula for backups, Maraschino for managing a home theater PC, Plex Media Server for an easy to use video experience and a few more</li>
<li>It then goes into more detail about each of them, how to actually install plugins and then how to set them up
***</li>
</ul>

<h2>Interview - Karl Lehenbauer - <a href="mailto:karl@flightaware.com" target="_blank" rel="nofollow noopener">karl@flightaware.com</a> / <a href="https://twitter.com/flightaware" target="_blank" rel="nofollow noopener">@flightaware</a></h2>

<p>FreeBSD at FlightAware, BSD history, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener">Ports and packages in OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://julipedia.meroh.net/2014/05/code-review-culture-meets-freebsd.html" target="_blank" rel="nofollow noopener">Code review culture meets FreeBSD</a></h3>

<ul>
<li>In most of the BSDs, changes need to be reviewed by more than one person before being committed to the tree</li>
<li>This article describes Phabricator, an open source code review system that we briefly mentioned last week</li>
<li>Instructions for using it are on <a href="https://wiki.freebsd.org/CodeReview" target="_blank" rel="nofollow noopener">the wiki</a></li>
<li>While not approved by the core team yet for anything official, it's in a testing phase and developers are encouraged to try it out and get their patches reviewed</li>
<li><a href="http://phabric.freebsd.org/" target="_blank" rel="nofollow noopener">Just look at that fancy interface!!</a>
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2088" target="_blank" rel="nofollow noopener">Upcoming BSD books</a></h3>

<ul>
<li>Sneaky MWL somehow finds his way into both our headlines and the news roundup</li>
<li>He gives us an update on the next BSD books that he's planning to release</li>
<li>The plan is to release three (or so) books based on different aspects of FreeBSD's storage system(s) - GEOM, UFS, ZFS, etc.</li>
<li>This has the advantage of only requiring you to buy the one(s) you're specifically interested in</li>
<li>"When will they be released? When I'm done writing them. How much will they cost? Dunno."</li>
<li>It's not Absolute FreeBSD 3rd edition...
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=VjYb9mKB4jU" target="_blank" rel="nofollow noopener">CARP failover and high availability on FreeBSD</a></h3>

<ul>
<li>If you're running a cluster or a group of servers, you should have some sort of failover in place</li>
<li>But the question comes up, "how do you load balance the load balancers!?"</li>
<li>This video goes through the process of giving more than one machine the same IP, how to set up CARP, securing it and demonstrates a node dying</li>
<li>Also mentions DNS-based load balancing as another option
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-30/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>This time in PCBSD land, we're getting ready for the 10.0.2 release <a href="http://download.pcbsd.org/iso/10.0-RELEASE/testing/amd64/" target="_blank" rel="nofollow noopener">(ISOs here)</a></li>
<li>AppCafe got a good number of fixes, and now shows 10 random highlighted applications</li>
<li>EasyPBI added a "bulk" mode to create PBIs of an entire FreeBSD port category</li>
<li>Lumina, the new desktop environment, is still being worked on and got some bug fixes too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s205iiKiWp" target="_blank" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s2060bkTNl" target="_blank" rel="nofollow noopener">Matt writes in</a></li>
<li><a href="http://slexy.org/view/s2G7eMC6oP" target="_blank" rel="nofollow noopener">Kjell writes in</a></li>
<li><a href="http://slexy.org/view/s2REfzMFGK" target="_blank" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s21nvJtXY6" target="_blank" rel="nofollow noopener">Tom writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>On this week's episode, we'll be giving you an introductory guide on OpenBSD's ports and package system. There's also a pretty fly interview with Karl Lehenbauer, about how they use FreeBSD at FlightAware. Lots of interesting news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" target="_blank" rel="nofollow noopener">BSDCan 2014 talks and reports, part 2</a></h3>

<ul>
<li>More presentations and trip reports are still being uploaded</li>
<li>Ingo Schwarze, <a href="https://www.youtube.com/watch?v=oifYhwTaOuw" target="_blank" rel="nofollow noopener">New Trends in mandoc</a></li>
<li>Vsevolod Stakhov, <a href="https://www.youtube.com/watch?v=3SOKFz2UUQ4" target="_blank" rel="nofollow noopener">The Architecture of the New Solver in pkg
</a></li>
<li>Julio Merino, <a href="https://www.youtube.com/watch?v=nf-bFeKaZsY" target="_blank" rel="nofollow noopener">The FreeBSD Test Suite</a></li>
<li>Zbigniew Bodek, <a href="https://www.youtube.com/watch?v=s5iIKEHtbX8" target="_blank" rel="nofollow noopener">Transparent Superpages for FreeBSD on ARM</a></li>
<li>There's also a <a href="http://freebsdfoundation.blogspot.com/2014/06/bsdcan-trip-report-michael-dexter.html" target="_blank" rel="nofollow noopener">trip report from Michael Dexter</a> and another (very long and detailed) <a href="http://freebsdfoundation.blogspot.com/2014/05/bsdcan-trip-report-warren-block.html" target="_blank" rel="nofollow noopener">trip report</a> from our friend <a href="http://www.bsdnow.tv/episodes/2014_03_26-documentation_is_king" target="_blank" rel="nofollow noopener">Warren Block</a> that even gives us some linkage, thanks!
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=JrFfrrY-yOo" target="_blank" rel="nofollow noopener">Beyond security, getting to know OpenBSD's real purpose</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael W Lucas</a> (who, we learn through this video, has been using BSD since 1986) gave a "webcast" last week, and the audio and slides are finally up</li>
<li>It clocks in at just over 30 minutes, managing to touch on a lot of OpenBSD topics</li>
<li>Some of those topics include: what is OpenBSD and why you should care, the philosophy of the project, how it serves as a "pressure cooker for ideas," briefly touches on GPL vs BSDL, their "do it right or don't do it at all" attitude, their stance on NDAs and blobs, recent LibreSSL development, some of the security functions that OpenBSD enabled before anyone else (and the ripple effect that had) and, of course, their disturbing preference for comic sans</li>
<li>Here's a direct link to <a href="https://wcc.on24.com/event/76/67/12/rt/1/documents/resourceList1400781110933/20140527_beyond_security_openbsd.pdf" target="_blank" rel="nofollow noopener">the slides</a></li>
<li>Great presentation if you'd like to learn a bit about OpenBSD, but also contains a bit of information that long-time users might not know too
***</li>
</ul>

<h3><a href="http://brioteam.com/linux-versus-freebsd-comprehensive-comparison" target="_blank" rel="nofollow noopener">FreeBSD vs Linux, a comprehensive comparison</a></h3>

<ul>
<li>Another blog post covering something people seem to be obsessed with - FreeBSD vs Linux</li>
<li>This one was worth mentioning because it's very thorough in regards to how things are done behind the scenes, not just the usual technical differences</li>
<li>It highlights the concept of a "core team" and their role vs "contributors" and "committers" (similar to a presentation Kirk McKusick did not long ago)</li>
<li>While a lot of things will be the same on both platforms, you might still be asking "which one is right for me?" - this article weighs in with some points for both sides and different use cases</li>
<li>Pretty well-written and unbiased article that also mentions areas where Linux might be better, so don't hate us for linking it
***</li>
</ul>

<h3><a href="http://www.openlogic.com/wazi/bid/345617/Expand-FreeNAS-with-plugins" target="_blank" rel="nofollow noopener">Expand FreeNAS with plugins</a></h3>

<ul>
<li>One of the things people love the most about FreeNAS (other than ZFS) is their cool plugin framework</li>
<li>With these plugins, you can greatly expand the feature set of your NAS via third party programs</li>
<li>This page talks about a few of the more popular ones and how they can be used to improve your NAS or media box experience</li>
<li>Some examples include setting up an OwnCloud server, Bacula for backups, Maraschino for managing a home theater PC, Plex Media Server for an easy to use video experience and a few more</li>
<li>It then goes into more detail about each of them, how to actually install plugins and then how to set them up
***</li>
</ul>

<h2>Interview - Karl Lehenbauer - <a href="mailto:karl@flightaware.com" target="_blank" rel="nofollow noopener">karl@flightaware.com</a> / <a href="https://twitter.com/flightaware" target="_blank" rel="nofollow noopener">@flightaware</a></h2>

<p>FreeBSD at FlightAware, BSD history, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ports-obsd" target="_blank" rel="nofollow noopener">Ports and packages in OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://julipedia.meroh.net/2014/05/code-review-culture-meets-freebsd.html" target="_blank" rel="nofollow noopener">Code review culture meets FreeBSD</a></h3>

<ul>
<li>In most of the BSDs, changes need to be reviewed by more than one person before being committed to the tree</li>
<li>This article describes Phabricator, an open source code review system that we briefly mentioned last week</li>
<li>Instructions for using it are on <a href="https://wiki.freebsd.org/CodeReview" target="_blank" rel="nofollow noopener">the wiki</a></li>
<li>While not approved by the core team yet for anything official, it's in a testing phase and developers are encouraged to try it out and get their patches reviewed</li>
<li><a href="http://phabric.freebsd.org/" target="_blank" rel="nofollow noopener">Just look at that fancy interface!!</a>
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/2088" target="_blank" rel="nofollow noopener">Upcoming BSD books</a></h3>

<ul>
<li>Sneaky MWL somehow finds his way into both our headlines and the news roundup</li>
<li>He gives us an update on the next BSD books that he's planning to release</li>
<li>The plan is to release three (or so) books based on different aspects of FreeBSD's storage system(s) - GEOM, UFS, ZFS, etc.</li>
<li>This has the advantage of only requiring you to buy the one(s) you're specifically interested in</li>
<li>"When will they be released? When I'm done writing them. How much will they cost? Dunno."</li>
<li>It's not Absolute FreeBSD 3rd edition...
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=VjYb9mKB4jU" target="_blank" rel="nofollow noopener">CARP failover and high availability on FreeBSD</a></h3>

<ul>
<li>If you're running a cluster or a group of servers, you should have some sort of failover in place</li>
<li>But the question comes up, "how do you load balance the load balancers!?"</li>
<li>This video goes through the process of giving more than one machine the same IP, how to set up CARP, securing it and demonstrates a node dying</li>
<li>Also mentions DNS-based load balancing as another option
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-30/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>This time in PCBSD land, we're getting ready for the 10.0.2 release <a href="http://download.pcbsd.org/iso/10.0-RELEASE/testing/amd64/" target="_blank" rel="nofollow noopener">(ISOs here)</a></li>
<li>AppCafe got a good number of fixes, and now shows 10 random highlighted applications</li>
<li>EasyPBI added a "bulk" mode to create PBIs of an entire FreeBSD port category</li>
<li>Lumina, the new desktop environment, is still being worked on and got some bug fixes too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s205iiKiWp" target="_blank" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s2060bkTNl" target="_blank" rel="nofollow noopener">Matt writes in</a></li>
<li><a href="http://slexy.org/view/s2G7eMC6oP" target="_blank" rel="nofollow noopener">Kjell writes in</a></li>
<li><a href="http://slexy.org/view/s2REfzMFGK" target="_blank" rel="nofollow noopener">Paul writes in</a></li>
<li><a href="http://slexy.org/view/s21nvJtXY6" target="_blank" rel="nofollow noopener">Tom writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>38: A BUG's Life</title>
  <link>https://www.bsdnow.tv/38</link>
  <guid isPermaLink="false">01510b66-38e5-40ac-a282-9bff71cb55d9</guid>
  <pubDate>Wed, 21 May 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/01510b66-38e5-40ac-a282-9bff71cb55d9.mp3" length="63768244" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:28:34</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/2053" target="_blank" rel="nofollow noopener"&gt;FreeBSD 11 goals and discussion&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Something that actually happened at BSDCan this year...&lt;/li&gt;
&lt;li&gt;During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE&lt;/li&gt;
&lt;li&gt;Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support&lt;/li&gt;
&lt;li&gt;A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more&lt;/li&gt;
&lt;li&gt;There's also some notes from the &lt;a href="http://blather.michaelwlucas.com/archives/2060" target="_blank" rel="nofollow noopener"&gt;devsummit virtualization session&lt;/a&gt;, mostly talking about bhyve&lt;/li&gt;
&lt;li&gt;Lastly, he also provides some notes about &lt;a href="http://blather.michaelwlucas.com/archives/2065" target="_blank" rel="nofollow noopener"&gt;ports and packages&lt;/a&gt; and where they're going
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" target="_blank" rel="nofollow noopener"&gt;An SSH honeypot with OpenBSD and Kippo&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Everyone loves messing with script kiddies, right?&lt;/li&gt;
&lt;li&gt;This blog post introduces &lt;a href="https://code.google.com/p/kippo/" target="_blank" rel="nofollow noopener"&gt;Kippo&lt;/a&gt;, an SSH honeypot tool, and how to use it in combination with OpenBSD&lt;/li&gt;
&lt;li&gt;It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely&lt;/li&gt;
&lt;li&gt;You can use this to get new 0day exploits or find weaknesses in your systems&lt;/li&gt;
&lt;li&gt;OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.netbsd.org/foundation/reports/financial/2013.html" target="_blank" rel="nofollow noopener"&gt;NetBSD foundation financial report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The NetBSD foundation has posted their 2013 financial report&lt;/li&gt;
&lt;li&gt;It's a very "no nonsense" page, pretty much only the hard numbers&lt;/li&gt;
&lt;li&gt;In 2013, they got $26,000 of income in donations&lt;/li&gt;
&lt;li&gt;The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else&lt;/li&gt;
&lt;li&gt;Be sure to donate to whichever BSDs you like and use!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" target="_blank" rel="nofollow noopener"&gt;Building a fully-encrypted NAS with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing&lt;/li&gt;
&lt;li&gt;This article takes a look at the OpenBSD side and &lt;a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" target="_blank" rel="nofollow noopener"&gt;explains how&lt;/a&gt; to build a NAS with security in mind&lt;/li&gt;
&lt;li&gt;The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected&lt;/li&gt;
&lt;li&gt;The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too&lt;/li&gt;
&lt;li&gt;There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Brian Callahan &amp;amp; Aaron Bieber - &lt;a href="mailto:admin@lists.nycbug.org" target="_blank" rel="nofollow noopener"&gt;admin@lists.nycbug.org&lt;/a&gt; &amp;amp; &lt;a href="mailto:admin@cobug.org" target="_blank" rel="nofollow noopener"&gt;admin@cobug.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Forming a local BSD Users Group&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/pkgsrc" target="_blank" rel="nofollow noopener"&gt;The basics of pkgsrc&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" target="_blank" rel="nofollow noopener"&gt;FreeBSD periodic mails vs. monitoring&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email&lt;/li&gt;
&lt;li&gt;This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them&lt;/li&gt;
&lt;li&gt;From bad SSH logins to Zabbix alerts, it all adds up quickly&lt;/li&gt;
&lt;li&gt;It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.skogsrud.net/?p=44" target="_blank" rel="nofollow noopener"&gt;Doing cool stuff with OpenBSD routing domains&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A blog post from our viewer and regular emailer, Kjell-Aleksander!&lt;/li&gt;
&lt;li&gt;He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project&lt;/li&gt;
&lt;li&gt;This is where OpenBSD routing domains and pf come in to save the day&lt;/li&gt;
&lt;li&gt;The blog post goes through the process with all the network details you could ever dream of&lt;/li&gt;
&lt;li&gt;He even &lt;a href="http://i.imgur.com/penYQFP.jpg" target="_blank" rel="nofollow noopener"&gt;named his networking equipment... after us&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" target="_blank" rel="nofollow noopener"&gt;LibreSSL, the good and the bad&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We're all probably familiar with OpenBSD's fork of OpenSSL at this point&lt;/li&gt;
&lt;li&gt;However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"&lt;/li&gt;
&lt;li&gt;This article talks about some of the cryptographic development challenges involved with maintaining such a massive project&lt;/li&gt;
&lt;li&gt;You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled&lt;/li&gt;
&lt;li&gt;It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Lots going on in PCBSD land this week, AppCafe has been redesigned&lt;/li&gt;
&lt;li&gt;The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update&lt;/li&gt;
&lt;li&gt;In the more &lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" target="_blank" rel="nofollow noopener"&gt;recent post&lt;/a&gt;, there's some further explanation of the PBI system and the reason for the transition&lt;/li&gt;
&lt;li&gt;It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2UbEhgjce" target="_blank" rel="nofollow noopener"&gt;Antonio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21XU0y3JP" target="_blank" rel="nofollow noopener"&gt;Daniel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QQtuawFl" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20XrT5Q8U" target="_blank" rel="nofollow noopener"&gt;tsyn writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ayZ1nsdv" target="_blank" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pkgsrc, bug, bsd user group, users group, community, lug, uug, unix users group, packages, signing, binary, source, compile, ports, nycbug, nycbsdcon, cobug, colorado, new york, conference, presentation, 11.0, ssh, honeypot, script kiddies, kippo, foundation, financial report, encrypted, nas, network attached storage, full disk encryption, periodic, routing domains, pf, the book of pf, third edition, 3rd edition, cron, monitoring, openssl, libressl</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blather.michaelwlucas.com/archives/2053" target="_blank" rel="nofollow noopener">FreeBSD 11 goals and discussion</a></h3>

<ul>
<li>Something that actually happened at BSDCan this year...</li>
<li>During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE</li>
<li>Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support</li>
<li>A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more</li>
<li>There's also some notes from the <a href="http://blather.michaelwlucas.com/archives/2060" target="_blank" rel="nofollow noopener">devsummit virtualization session</a>, mostly talking about bhyve</li>
<li>Lastly, he also provides some notes about <a href="http://blather.michaelwlucas.com/archives/2065" target="_blank" rel="nofollow noopener">ports and packages</a> and where they're going
***</li>
</ul>

<h3><a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" target="_blank" rel="nofollow noopener">An SSH honeypot with OpenBSD and Kippo</a></h3>

<ul>
<li>Everyone loves messing with script kiddies, right?</li>
<li>This blog post introduces <a href="https://code.google.com/p/kippo/" target="_blank" rel="nofollow noopener">Kippo</a>, an SSH honeypot tool, and how to use it in combination with OpenBSD</li>
<li>It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely</li>
<li>You can use this to get new 0day exploits or find weaknesses in your systems</li>
<li>OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***</li>
</ul>

<h3><a href="https://www.netbsd.org/foundation/reports/financial/2013.html" target="_blank" rel="nofollow noopener">NetBSD foundation financial report</a></h3>

<ul>
<li>The NetBSD foundation has posted their 2013 financial report</li>
<li>It's a very "no nonsense" page, pretty much only the hard numbers</li>
<li>In 2013, they got $26,000 of income in donations</li>
<li>The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else</li>
<li>Be sure to donate to whichever BSDs you like and use!
***</li>
</ul>

<h3><a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" target="_blank" rel="nofollow noopener">Building a fully-encrypted NAS with OpenBSD</a></h3>

<ul>
<li>Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing</li>
<li>This article takes a look at the OpenBSD side and <a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" target="_blank" rel="nofollow noopener">explains how</a> to build a NAS with security in mind</li>
<li>The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected</li>
<li>The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too</li>
<li>There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***</li>
</ul>

<h2>Interview - Brian Callahan &amp; Aaron Bieber - <a href="mailto:admin@lists.nycbug.org" target="_blank" rel="nofollow noopener">admin@lists.nycbug.org</a> &amp; <a href="mailto:admin@cobug.org" target="_blank" rel="nofollow noopener">admin@cobug.org</a></h2>

<p>Forming a local BSD Users Group</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pkgsrc" target="_blank" rel="nofollow noopener">The basics of pkgsrc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" target="_blank" rel="nofollow noopener">FreeBSD periodic mails vs. monitoring</a></h3>

<ul>
<li>If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email</li>
<li>This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them</li>
<li>From bad SSH logins to Zabbix alerts, it all adds up quickly</li>
<li>It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***</li>
</ul>

<h3><a href="http://www.skogsrud.net/?p=44" target="_blank" rel="nofollow noopener">Doing cool stuff with OpenBSD routing domains</a></h3>

<ul>
<li>A blog post from our viewer and regular emailer, Kjell-Aleksander!</li>
<li>He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project</li>
<li>This is where OpenBSD routing domains and pf come in to save the day</li>
<li>The blog post goes through the process with all the network details you could ever dream of</li>
<li>He even <a href="http://i.imgur.com/penYQFP.jpg" target="_blank" rel="nofollow noopener">named his networking equipment... after us</a>
***</li>
</ul>

<h3><a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" target="_blank" rel="nofollow noopener">LibreSSL, the good and the bad</a></h3>

<ul>
<li>We're all probably familiar with OpenBSD's fork of OpenSSL at this point</li>
<li>However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"</li>
<li>This article talks about some of the cryptographic development challenges involved with maintaining such a massive project</li>
<li>You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled</li>
<li>It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Lots going on in PCBSD land this week, AppCafe has been redesigned</li>
<li>The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update</li>
<li>In the more <a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" target="_blank" rel="nofollow noopener">recent post</a>, there's some further explanation of the PBI system and the reason for the transition</li>
<li>It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UbEhgjce" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s21XU0y3JP" target="_blank" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2QQtuawFl" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20XrT5Q8U" target="_blank" rel="nofollow noopener">tsyn writes in</a></li>
<li><a href="http://slexy.org/view/s2ayZ1nsdv" target="_blank" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back from BSDCan! This week on the show we'll be chatting with Brian Callahan and Aaron Bieber about forming a local BSD users group. We'll get to hear their experiences of running one and maybe encourage some of you to start your own! After that, we've got a tutorial on the basics of NetBSD's package manager, pkgsrc. Answers to your emails and the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blather.michaelwlucas.com/archives/2053" target="_blank" rel="nofollow noopener">FreeBSD 11 goals and discussion</a></h3>

<ul>
<li>Something that actually happened at BSDCan this year...</li>
<li>During the FreeBSD devsummit, there was some discussion about what changes will be made in 11.0-RELEASE</li>
<li>Some of MWL's notes include: the test suite will be merged to 10-STABLE, more work on the MIPS platforms, LLDB getting more attention, UEFI boot and install support</li>
<li>A large list of possibilities was also included and open for discussion, including AES-GCM in IPSEC, ASLR, OpenMP, ICC, in-place kernel upgrades, Capsicum improvements, TCP performance improvements and A LOT more</li>
<li>There's also some notes from the <a href="http://blather.michaelwlucas.com/archives/2060" target="_blank" rel="nofollow noopener">devsummit virtualization session</a>, mostly talking about bhyve</li>
<li>Lastly, he also provides some notes about <a href="http://blather.michaelwlucas.com/archives/2065" target="_blank" rel="nofollow noopener">ports and packages</a> and where they're going
***</li>
</ul>

<h3><a href="http://securit.se/2014/05/how-to-install-kippo-ssh-honeypot-on-openbsd-5-5-with-chroot/" target="_blank" rel="nofollow noopener">An SSH honeypot with OpenBSD and Kippo</a></h3>

<ul>
<li>Everyone loves messing with script kiddies, right?</li>
<li>This blog post introduces <a href="https://code.google.com/p/kippo/" target="_blank" rel="nofollow noopener">Kippo</a>, an SSH honeypot tool, and how to use it in combination with OpenBSD</li>
<li>It includes a step by step (or rather, command by command) guide and some tips for running a honeypot securely</li>
<li>You can use this to get new 0day exploits or find weaknesses in your systems</li>
<li>OpenBSD makes a great companion for security testing tools like this with all its exploit mitigation techniques that protect all running applications
***</li>
</ul>

<h3><a href="https://www.netbsd.org/foundation/reports/financial/2013.html" target="_blank" rel="nofollow noopener">NetBSD foundation financial report</a></h3>

<ul>
<li>The NetBSD foundation has posted their 2013 financial report</li>
<li>It's a very "no nonsense" page, pretty much only the hard numbers</li>
<li>In 2013, they got $26,000 of income in donations</li>
<li>The rest of the page shows all the details, how they spent it on hardware, consulting, conference fees, legal costs and everything else</li>
<li>Be sure to donate to whichever BSDs you like and use!
***</li>
</ul>

<h3><a href="http://www.geektechnique.org/projectlab/796/how-to-build-a-fully-encrypted-nas-on-openbsd.html" target="_blank" rel="nofollow noopener">Building a fully-encrypted NAS with OpenBSD</a></h3>

<ul>
<li>Usually the popular choice for a NAS system is FreeNAS, or plain FreeBSD if you know what you're doing</li>
<li>This article takes a look at the OpenBSD side and <a href="http://www.geektechnique.org/projectlab/797/openbsd-encrypted-nas-howto.html" target="_blank" rel="nofollow noopener">explains how</a> to build a NAS with security in mind</li>
<li>The NAS will be fully encrypted, no separate /boot partition like FreeBSD and FreeNAS require - this means the kernel itself is even protected</li>
<li>The obvious trade-off is the lack of ZFS support for storage, but this is an interesting idea that would fit most people's needs too</li>
<li>There's also a bit of background information on NAS systems in general, some NAS-specific security tips and even some nice graphs and pictures of the hardware - fantastic write up!
***</li>
</ul>

<h2>Interview - Brian Callahan &amp; Aaron Bieber - <a href="mailto:admin@lists.nycbug.org" target="_blank" rel="nofollow noopener">admin@lists.nycbug.org</a> &amp; <a href="mailto:admin@cobug.org" target="_blank" rel="nofollow noopener">admin@cobug.org</a></h2>

<p>Forming a local BSD Users Group</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pkgsrc" target="_blank" rel="nofollow noopener">The basics of pkgsrc</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://deranfangvomende.wordpress.com/2014/05/11/freebsd-periodic-mails-vs-monitoring/" target="_blank" rel="nofollow noopener">FreeBSD periodic mails vs. monitoring</a></h3>

<ul>
<li>If you've ever been an admin for a lot of FreeBSD boxes, you've probably noticed that you get a lot of email</li>
<li>This page tells about all the different alert emails, cron emails and other reports you might end up getting, as well as how to manage them</li>
<li>From bad SSH logins to Zabbix alerts, it all adds up quickly</li>
<li>It highlights the periodic.conf file and FreeBSD's periodic daemon, as well as some third party monitoring tools you can use to keep track of your servers
***</li>
</ul>

<h3><a href="http://www.skogsrud.net/?p=44" target="_blank" rel="nofollow noopener">Doing cool stuff with OpenBSD routing domains</a></h3>

<ul>
<li>A blog post from our viewer and regular emailer, Kjell-Aleksander!</li>
<li>He manages some internally-routed IP ranges at his work, but didn't want to have equipment for each separate project</li>
<li>This is where OpenBSD routing domains and pf come in to save the day</li>
<li>The blog post goes through the process with all the network details you could ever dream of</li>
<li>He even <a href="http://i.imgur.com/penYQFP.jpg" target="_blank" rel="nofollow noopener">named his networking equipment... after us</a>
***</li>
</ul>

<h3><a href="http://insanecoding.blogspot.com/2014/04/libressl-good-and-bad.html" target="_blank" rel="nofollow noopener">LibreSSL, the good and the bad</a></h3>

<ul>
<li>We're all probably familiar with OpenBSD's fork of OpenSSL at this point</li>
<li>However, "for those of you that don't know it, OpenSSL is at the same time the best and most popular SSL/TLS library available, and utter junk"</li>
<li>This article talks about some of the cryptographic development challenges involved with maintaining such a massive project</li>
<li>You need cryptographers, software engineers, software optimization specialists - there are a lot of roles that need to be filled</li>
<li>It also mentions some OpenSSL alternatives and recent LibreSSL progress, as well as some downsides to the fork - the main one being their aim for backwards compatibility
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-28-photos-of-the-new-appcafe-re-design/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Lots going on in PCBSD land this week, AppCafe has been redesigned</li>
<li>The PBI system is being replaced with pkgng, PBIs will be automatically converted once you update</li>
<li>In the more <a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-29-pbing/" target="_blank" rel="nofollow noopener">recent post</a>, there's some further explanation of the PBI system and the reason for the transition</li>
<li>It's got lots of details on the different ways to install software, so hopefully it will clear up any possible confusion
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UbEhgjce" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s21XU0y3JP" target="_blank" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2QQtuawFl" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20XrT5Q8U" target="_blank" rel="nofollow noopener">tsyn writes in</a></li>
<li><a href="http://slexy.org/view/s2ayZ1nsdv" target="_blank" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>36: Let's Get RAID</title>
  <link>https://www.bsdnow.tv/36</link>
  <guid isPermaLink="false">485b12e9-ea67-4bc6-9709-4b0e38a76184</guid>
  <pubDate>Wed, 07 May 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/485b12e9-ea67-4bc6-9709-4b0e38a76184.mp3" length="65368948" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show we'll be showing you how to set up RAID arrays in both FreeBSD and OpenBSD. There's also an interview with David Chisnall - of the FreeBSD core team - about the switch to Clang and a lot more. As usual, we'll be dropping the latest news and answering your emails, so sit back and enjoy some BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:30:47</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show we'll be showing you how to set up RAID arrays in both FreeBSD and OpenBSD. There's also an interview with David Chisnall - of the FreeBSD core team - about the switch to Clang and a lot more. As usual, we'll be dropping the latest news and answering your emails, so sit back and enjoy some BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/55.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD 5.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you &lt;a href="https://https.openbsd.org/cgi-bin/order" target="_blank" rel="nofollow noopener"&gt;ordered&lt;/a&gt; a &lt;a href="https://twitter.com/blakkheim/status/461909893813784576" target="_blank" rel="nofollow noopener"&gt;CD set&lt;/a&gt; then you've probably had it for a little while already, but OpenBSD has formally announced the &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140501153339" target="_blank" rel="nofollow noopener"&gt;public release&lt;/a&gt; of 5.5&lt;/li&gt;
&lt;li&gt;This is one of the biggest releases to date, with a very long list of changes and improvements&lt;/li&gt;
&lt;li&gt;Some of the highlights include: time_t being 64 bit on all platforms, release sets and binary packages being signed with the new signify tool, a new autoinstall feature of the installer, SMP support on Alpha, a new AViiON port, lots of new hardware drivers including newer NICs, the new vxlan driver, relayd improvements, a new pf queue system for bandwidth shaping, dhcpd and dhclient fixes, OpenSMTPD 5.4.2 and all its new features, position-independent executables being default for i386, the RNG has been replaced with ChaCha20 as well as some other security improvements, FUSE support, tmpfs, softraid partitions larger than 2TB and a RAID 5 implementation, OpenSSH 6.6 with all its new features and fixes... and a lot more&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://www.openbsd.org/plus55.html" target="_blank" rel="nofollow noopener"&gt;full list of changes&lt;/a&gt; is HUGE, be sure to read through it all if you're interested in the details&lt;/li&gt;
&lt;li&gt;If you're doing an upgrade from 5.4 instead of a fresh install, pay careful attention to &lt;a href="http://www.openbsd.org/faq/upgrade55.html" target="_blank" rel="nofollow noopener"&gt;the upgrade guide&lt;/a&gt; as there are some very specific steps for this version&lt;/li&gt;
&lt;li&gt;Also be sure to apply the &lt;a href="http://www.openbsd.org/errata55.html" target="_blank" rel="nofollow noopener"&gt;errata patches&lt;/a&gt; on your new installations... especially those OpenSSL ones (some of which &lt;a href="http://marc.info/?l=oss-security&amp;amp;m=139906348230995&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;still aren't fixed&lt;/a&gt; in the other BSDs yet)&lt;/li&gt;
&lt;li&gt;On the topic of errata patches, the project is now going to also send them out (&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140502103355" target="_blank" rel="nofollow noopener"&gt;signed&lt;/a&gt;) via the &lt;a href="http://lists.openbsd.org/cgi-bin/mj_wwwusr?user=&amp;amp;passw=&amp;amp;func=lists-long-full&amp;amp;extra=announce" target="_blank" rel="nofollow noopener"&gt;announce mailing list&lt;/a&gt;, a very welcome change&lt;/li&gt;
&lt;li&gt;Congrats to the whole team on this great release - 5.6 is going to be even more awesome with "Libre"SSL and lots of other stuff that's currently in development
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising_28.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD foundation funding highlights&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation posts a new update on how they're spending the money that everyone donates&lt;/li&gt;
&lt;li&gt;"As we embark on our 15th year of serving the FreeBSD Project and community, we are proud of what we've done to help FreeBSD become the most innovative, reliable, and high-performance operation system"&lt;/li&gt;
&lt;li&gt;During this spring, they want to highlight the new UEFI boot support &lt;a href="http://freebsdfoundation.blogspot.com/2014/05/freebsd-foundation-newcons-project.html" target="_blank" rel="nofollow noopener"&gt;and newcons&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;There's a lot of details about what exactly UEFI is and why we need it going forward&lt;/li&gt;
&lt;li&gt;FreeBSD has also needed some updates to its console to support UTF8 and wide characters&lt;/li&gt;
&lt;li&gt;Hopefully this series will continue and we'll get to see what other work is being sponsored
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139879453001957&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;OpenSSH without OpenSSL&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenSSH team has been hard at work, making it even better, and now OpenSSL is completely optional&lt;/li&gt;
&lt;li&gt;Since it won't have access to the primitives OpenSSL uses, there will be a trade-off of features vs. security&lt;/li&gt;
&lt;li&gt;This version will drop support for legacy SSH v1, and the only two cryptographic algorithms supported are an in-house implementation of AES in counter mode and the &lt;a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.chacha20poly1305?rev=HEAD;content-type=text%2Fplain" target="_blank" rel="nofollow noopener"&gt;new combination&lt;/a&gt; of the Chacha20 stream cipher with Poly1305 for packet integrity&lt;/li&gt;
&lt;li&gt;Key exchange is limited to elliptic curve Diffie-Hellman and the newer Curve25519 KEXs&lt;/li&gt;
&lt;li&gt;No support for RSA, DSA or ECDSA public keys - only Ed25519&lt;/li&gt;
&lt;li&gt;It also includes a &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139883582313750&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;new buffer API&lt;/a&gt; and a set of wrappers to make it compatible with the existing API&lt;/li&gt;
&lt;li&gt;Believe it or not, this was planned before all the heartbleed craziness&lt;/li&gt;
&lt;li&gt;Maybe someday soon we'll have a mini-openssh-portable in FreeBSD ports and NetBSD pkgsrc, would be really neat
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdmag.org/magazine/1861-free-pascal-on-bsd-april-bsd-issue" target="_blank" rel="nofollow noopener"&gt;BSDMag's April 2014 issue is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The free monthly BSD magazine has got a new issue available for download&lt;/li&gt;
&lt;li&gt;This time the articles include: pascal on BSD, an introduction to revision control systems and configuration management, deploying NetBSD on AWS EC2, more GIMP tutorials, an AsiaBSDCon 2014 report and a piece about how easily credit cards are stolen online&lt;/li&gt;
&lt;li&gt;Anyone can contribute to the magazine, just send the editors an email about what you want to write&lt;/li&gt;
&lt;li&gt;No Linux articles this time around, good
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - David Chisnall - &lt;a href="mailto:theraven@freebsd.org" target="_blank" rel="nofollow noopener"&gt;theraven@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The LLVM/Clang switch, FreeBSD's core team, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/raid" target="_blank" rel="nofollow noopener"&gt;RAID in FreeBSD and OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/04/bsdtalk240-about-time-with-george.html" target="_blank" rel="nofollow noopener"&gt;BSDTalk episode 240&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy Will Backman has uploaded a new episode of BSDTalk, this time with our other buddy GNN as the guest - mainly to talk about NTP and keeping reliable time&lt;/li&gt;
&lt;li&gt;Topics include the specific details of crystals used in watches and computers to keep time, how temperature affects the quality, different sources of inaccuracy, some general NTP information, why you might want extremely precise time, different time sources (GPS, satellite, etc), differences in stratum levels, the problem of packet delay and estimating the round trip time, some of the recent NTP amplification attacks, the downsides to using UDP instead of TCP and... much more&lt;/li&gt;
&lt;li&gt;GNN also talks a little about the &lt;a href="https://en.wikipedia.org/wiki/Precision_Time_Protocol" target="_blank" rel="nofollow noopener"&gt;Precision Time Protocol&lt;/a&gt; and how it's different than NTP&lt;/li&gt;
&lt;li&gt;Two &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener"&gt;people&lt;/a&gt; we've &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener"&gt;interviewed&lt;/a&gt; talking to each other, awesome&lt;/li&gt;
&lt;li&gt;If you're interested in NTP, be sure to see our &lt;a href="http://www.bsdnow.tv/tutorials/ntpd" target="_blank" rel="nofollow noopener"&gt;tutorial&lt;/a&gt; too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140502092427" target="_blank" rel="nofollow noopener"&gt;m2k14 trip reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've got a few more reports from the recent OpenBSD hackathon in Morocco&lt;/li&gt;
&lt;li&gt;The first one is from Antoine Jacoutot (who is a key GNOME porter and gave us the screenshots for the &lt;a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener"&gt;OpenBSD desktop tutorial&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;"Since I always fail at actually doing whatever I have planned for a hackathon, this time I decided to come to m2k14 unprepared about what I was going to do"&lt;/li&gt;
&lt;li&gt;He got lots of work done with ports and pushing GNOME-related patches back up to the main project, then worked on fixing ports' compatibility with LibreSSL&lt;/li&gt;
&lt;li&gt;Speaking of LibreSSL, there's &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140505062023" target="_blank" rel="nofollow noopener"&gt;an article&lt;/a&gt; all would-be portable version writers should probably read and take into consideration&lt;/li&gt;
&lt;li&gt;Jasper Adriaanse &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140501185019" target="_blank" rel="nofollow noopener"&gt;also writes&lt;/a&gt; about what he got done over there&lt;/li&gt;
&lt;li&gt;He cleaned up and fixed the puppet port to work better with OpenBSD
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.atlantic.net/blog/2014/04/08/freebsd-ssd-cloud-vps-hosting-10-reasons/" target="_blank" rel="nofollow noopener"&gt;Why you should use FreeBSD on your cloud VPS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have a blog post from Atlantic, a VPS and hosting provider, about 10 reasons for using FreeBSD&lt;/li&gt;
&lt;li&gt;Starts off with a little bit of BSD history for those who are unfamiliar with it and only know Linux and Windows&lt;/li&gt;
&lt;li&gt;The 10 reasons are: community, stability, collaboration, ease of use, ports, security, ZFS, GEOM, sound and having lots of options&lt;/li&gt;
&lt;li&gt;The post goes into detail about each of them and why FreeBSD makes a great choice for a VPS OS
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-27-software-system-redesign/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Big changes coming in the way PCBSD manages software&lt;/li&gt;
&lt;li&gt;The PBI system, AppCafe and related tools are all going to use pkgng now&lt;/li&gt;
&lt;li&gt;The AppCafe will no longer be limited to PBIs, so much more software will be easily available from the ports tree&lt;/li&gt;
&lt;li&gt;New rating system coming soon and much more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21bk2oPuQ" target="_blank" rel="nofollow noopener"&gt;Martin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2n9fx1Rpw" target="_blank" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2rBBKLA4u" target="_blank" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20JY6ZI71" target="_blank" rel="nofollow noopener"&gt;Goetz writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20YV5Ohpa" target="_blank" rel="nofollow noopener"&gt;Jarrad writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, theraven, david chisnall, core, core team, clang, gcc, llvm, raid, stripe, mirror, bioctl, gstripe, zfs, gmirror, graid, ufs, ffs, disks, the worst pun i've done so far, i regret this already, redundancy, raid0, raid1, raid5, raidz, raid-z, filesystem, 5.5, pie, aslr, cd set, demo, tour, opensmtpd, pf, gnome, gnome3, marcusports, ports, router, signify, hackathon</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show we'll be showing you how to set up RAID arrays in both FreeBSD and OpenBSD. There's also an interview with David Chisnall - of the FreeBSD core team - about the switch to Clang and a lot more. As usual, we'll be dropping the latest news and answering your emails, so sit back and enjoy some BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/55.html" target="_blank" rel="nofollow noopener">OpenBSD 5.5 released</a></h3>

<ul>
<li>If you <a href="https://https.openbsd.org/cgi-bin/order" target="_blank" rel="nofollow noopener">ordered</a> a <a href="https://twitter.com/blakkheim/status/461909893813784576" target="_blank" rel="nofollow noopener">CD set</a> then you've probably had it for a little while already, but OpenBSD has formally announced the <a href="http://undeadly.org/cgi?action=article&amp;sid=20140501153339" target="_blank" rel="nofollow noopener">public release</a> of 5.5</li>
<li>This is one of the biggest releases to date, with a very long list of changes and improvements</li>
<li>Some of the highlights include: time_t being 64 bit on all platforms, release sets and binary packages being signed with the new signify tool, a new autoinstall feature of the installer, SMP support on Alpha, a new AViiON port, lots of new hardware drivers including newer NICs, the new vxlan driver, relayd improvements, a new pf queue system for bandwidth shaping, dhcpd and dhclient fixes, OpenSMTPD 5.4.2 and all its new features, position-independent executables being default for i386, the RNG has been replaced with ChaCha20 as well as some other security improvements, FUSE support, tmpfs, softraid partitions larger than 2TB and a RAID 5 implementation, OpenSSH 6.6 with all its new features and fixes... and a lot more</li>
<li>The <a href="http://www.openbsd.org/plus55.html" target="_blank" rel="nofollow noopener">full list of changes</a> is HUGE, be sure to read through it all if you're interested in the details</li>
<li>If you're doing an upgrade from 5.4 instead of a fresh install, pay careful attention to <a href="http://www.openbsd.org/faq/upgrade55.html" target="_blank" rel="nofollow noopener">the upgrade guide</a> as there are some very specific steps for this version</li>
<li>Also be sure to apply the <a href="http://www.openbsd.org/errata55.html" target="_blank" rel="nofollow noopener">errata patches</a> on your new installations... especially those OpenSSL ones (some of which <a href="http://marc.info/?l=oss-security&amp;m=139906348230995&amp;w=2" target="_blank" rel="nofollow noopener">still aren't fixed</a> in the other BSDs yet)</li>
<li>On the topic of errata patches, the project is now going to also send them out (<a href="http://undeadly.org/cgi?action=article&amp;sid=20140502103355" target="_blank" rel="nofollow noopener">signed</a>) via the <a href="http://lists.openbsd.org/cgi-bin/mj_wwwusr?user=&amp;passw=&amp;func=lists-long-full&amp;extra=announce" target="_blank" rel="nofollow noopener">announce mailing list</a>, a very welcome change</li>
<li>Congrats to the whole team on this great release - 5.6 is going to be even more awesome with "Libre"SSL and lots of other stuff that's currently in development
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising_28.html" target="_blank" rel="nofollow noopener">FreeBSD foundation funding highlights</a></h3>

<ul>
<li>The FreeBSD foundation posts a new update on how they're spending the money that everyone donates</li>
<li>"As we embark on our 15th year of serving the FreeBSD Project and community, we are proud of what we've done to help FreeBSD become the most innovative, reliable, and high-performance operation system"</li>
<li>During this spring, they want to highlight the new UEFI boot support <a href="http://freebsdfoundation.blogspot.com/2014/05/freebsd-foundation-newcons-project.html" target="_blank" rel="nofollow noopener">and newcons</a></li>
<li>There's a lot of details about what exactly UEFI is and why we need it going forward</li>
<li>FreeBSD has also needed some updates to its console to support UTF8 and wide characters</li>
<li>Hopefully this series will continue and we'll get to see what other work is being sponsored
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-cvs&amp;m=139879453001957&amp;w=2" target="_blank" rel="nofollow noopener">OpenSSH without OpenSSL</a></h3>

<ul>
<li>The OpenSSH team has been hard at work, making it even better, and now OpenSSL is completely optional</li>
<li>Since it won't have access to the primitives OpenSSL uses, there will be a trade-off of features vs. security</li>
<li>This version will drop support for legacy SSH v1, and the only two cryptographic algorithms supported are an in-house implementation of AES in counter mode and the <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.chacha20poly1305?rev=HEAD;content-type=text%2Fplain" target="_blank" rel="nofollow noopener">new combination</a> of the Chacha20 stream cipher with Poly1305 for packet integrity</li>
<li>Key exchange is limited to elliptic curve Diffie-Hellman and the newer Curve25519 KEXs</li>
<li>No support for RSA, DSA or ECDSA public keys - only Ed25519</li>
<li>It also includes a <a href="http://marc.info/?l=openbsd-cvs&amp;m=139883582313750&amp;w=2" target="_blank" rel="nofollow noopener">new buffer API</a> and a set of wrappers to make it compatible with the existing API</li>
<li>Believe it or not, this was planned before all the heartbleed craziness</li>
<li>Maybe someday soon we'll have a mini-openssh-portable in FreeBSD ports and NetBSD pkgsrc, would be really neat
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1861-free-pascal-on-bsd-april-bsd-issue" target="_blank" rel="nofollow noopener">BSDMag's April 2014 issue is out</a></h3>

<ul>
<li>The free monthly BSD magazine has got a new issue available for download</li>
<li>This time the articles include: pascal on BSD, an introduction to revision control systems and configuration management, deploying NetBSD on AWS EC2, more GIMP tutorials, an AsiaBSDCon 2014 report and a piece about how easily credit cards are stolen online</li>
<li>Anyone can contribute to the magazine, just send the editors an email about what you want to write</li>
<li>No Linux articles this time around, good
***</li>
</ul>

<h2>Interview - David Chisnall - <a href="mailto:theraven@freebsd.org" target="_blank" rel="nofollow noopener">theraven@freebsd.org</a></h2>

<p>The LLVM/Clang switch, FreeBSD's core team, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/raid" target="_blank" rel="nofollow noopener">RAID in FreeBSD and OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://bsdtalk.blogspot.com/2014/04/bsdtalk240-about-time-with-george.html" target="_blank" rel="nofollow noopener">BSDTalk episode 240</a></h3>

<ul>
<li>Our buddy Will Backman has uploaded a new episode of BSDTalk, this time with our other buddy GNN as the guest - mainly to talk about NTP and keeping reliable time</li>
<li>Topics include the specific details of crystals used in watches and computers to keep time, how temperature affects the quality, different sources of inaccuracy, some general NTP information, why you might want extremely precise time, different time sources (GPS, satellite, etc), differences in stratum levels, the problem of packet delay and estimating the round trip time, some of the recent NTP amplification attacks, the downsides to using UDP instead of TCP and... much more</li>
<li>GNN also talks a little about the <a href="https://en.wikipedia.org/wiki/Precision_Time_Protocol" target="_blank" rel="nofollow noopener">Precision Time Protocol</a> and how it's different than NTP</li>
<li>Two <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener">people</a> we've <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">interviewed</a> talking to each other, awesome</li>
<li>If you're interested in NTP, be sure to see our <a href="http://www.bsdnow.tv/tutorials/ntpd" target="_blank" rel="nofollow noopener">tutorial</a> too
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140502092427" target="_blank" rel="nofollow noopener">m2k14 trip reports</a></h3>

<ul>
<li>We've got a few more reports from the recent OpenBSD hackathon in Morocco</li>
<li>The first one is from Antoine Jacoutot (who is a key GNOME porter and gave us the screenshots for the <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener">OpenBSD desktop tutorial</a>)</li>
<li>"Since I always fail at actually doing whatever I have planned for a hackathon, this time I decided to come to m2k14 unprepared about what I was going to do"</li>
<li>He got lots of work done with ports and pushing GNOME-related patches back up to the main project, then worked on fixing ports' compatibility with LibreSSL</li>
<li>Speaking of LibreSSL, there's <a href="http://undeadly.org/cgi?action=article&amp;sid=20140505062023" target="_blank" rel="nofollow noopener">an article</a> all would-be portable version writers should probably read and take into consideration</li>
<li>Jasper Adriaanse <a href="http://undeadly.org/cgi?action=article&amp;sid=20140501185019" target="_blank" rel="nofollow noopener">also writes</a> about what he got done over there</li>
<li>He cleaned up and fixed the puppet port to work better with OpenBSD
***</li>
</ul>

<h3><a href="https://www.atlantic.net/blog/2014/04/08/freebsd-ssd-cloud-vps-hosting-10-reasons/" target="_blank" rel="nofollow noopener">Why you should use FreeBSD on your cloud VPS</a></h3>

<ul>
<li>Here we have a blog post from Atlantic, a VPS and hosting provider, about 10 reasons for using FreeBSD</li>
<li>Starts off with a little bit of BSD history for those who are unfamiliar with it and only know Linux and Windows</li>
<li>The 10 reasons are: community, stability, collaboration, ease of use, ports, security, ZFS, GEOM, sound and having lots of options</li>
<li>The post goes into detail about each of them and why FreeBSD makes a great choice for a VPS OS
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-27-software-system-redesign/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Big changes coming in the way PCBSD manages software</li>
<li>The PBI system, AppCafe and related tools are all going to use pkgng now</li>
<li>The AppCafe will no longer be limited to PBIs, so much more software will be easily available from the ports tree</li>
<li>New rating system coming soon and much more
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21bk2oPuQ" target="_blank" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s2n9fx1Rpw" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2rBBKLA4u" target="_blank" rel="nofollow noopener">Alex writes in</a></li>
<li><a href="http://slexy.org/view/s20JY6ZI71" target="_blank" rel="nofollow noopener">Goetz writes in</a></li>
<li><a href="http://slexy.org/view/s20YV5Ohpa" target="_blank" rel="nofollow noopener">Jarrad writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show we'll be showing you how to set up RAID arrays in both FreeBSD and OpenBSD. There's also an interview with David Chisnall - of the FreeBSD core team - about the switch to Clang and a lot more. As usual, we'll be dropping the latest news and answering your emails, so sit back and enjoy some BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.openbsd.org/55.html" target="_blank" rel="nofollow noopener">OpenBSD 5.5 released</a></h3>

<ul>
<li>If you <a href="https://https.openbsd.org/cgi-bin/order" target="_blank" rel="nofollow noopener">ordered</a> a <a href="https://twitter.com/blakkheim/status/461909893813784576" target="_blank" rel="nofollow noopener">CD set</a> then you've probably had it for a little while already, but OpenBSD has formally announced the <a href="http://undeadly.org/cgi?action=article&amp;sid=20140501153339" target="_blank" rel="nofollow noopener">public release</a> of 5.5</li>
<li>This is one of the biggest releases to date, with a very long list of changes and improvements</li>
<li>Some of the highlights include: time_t being 64 bit on all platforms, release sets and binary packages being signed with the new signify tool, a new autoinstall feature of the installer, SMP support on Alpha, a new AViiON port, lots of new hardware drivers including newer NICs, the new vxlan driver, relayd improvements, a new pf queue system for bandwidth shaping, dhcpd and dhclient fixes, OpenSMTPD 5.4.2 and all its new features, position-independent executables being default for i386, the RNG has been replaced with ChaCha20 as well as some other security improvements, FUSE support, tmpfs, softraid partitions larger than 2TB and a RAID 5 implementation, OpenSSH 6.6 with all its new features and fixes... and a lot more</li>
<li>The <a href="http://www.openbsd.org/plus55.html" target="_blank" rel="nofollow noopener">full list of changes</a> is HUGE, be sure to read through it all if you're interested in the details</li>
<li>If you're doing an upgrade from 5.4 instead of a fresh install, pay careful attention to <a href="http://www.openbsd.org/faq/upgrade55.html" target="_blank" rel="nofollow noopener">the upgrade guide</a> as there are some very specific steps for this version</li>
<li>Also be sure to apply the <a href="http://www.openbsd.org/errata55.html" target="_blank" rel="nofollow noopener">errata patches</a> on your new installations... especially those OpenSSL ones (some of which <a href="http://marc.info/?l=oss-security&amp;m=139906348230995&amp;w=2" target="_blank" rel="nofollow noopener">still aren't fixed</a> in the other BSDs yet)</li>
<li>On the topic of errata patches, the project is now going to also send them out (<a href="http://undeadly.org/cgi?action=article&amp;sid=20140502103355" target="_blank" rel="nofollow noopener">signed</a>) via the <a href="http://lists.openbsd.org/cgi-bin/mj_wwwusr?user=&amp;passw=&amp;func=lists-long-full&amp;extra=announce" target="_blank" rel="nofollow noopener">announce mailing list</a>, a very welcome change</li>
<li>Congrats to the whole team on this great release - 5.6 is going to be even more awesome with "Libre"SSL and lots of other stuff that's currently in development
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising_28.html" target="_blank" rel="nofollow noopener">FreeBSD foundation funding highlights</a></h3>

<ul>
<li>The FreeBSD foundation posts a new update on how they're spending the money that everyone donates</li>
<li>"As we embark on our 15th year of serving the FreeBSD Project and community, we are proud of what we've done to help FreeBSD become the most innovative, reliable, and high-performance operation system"</li>
<li>During this spring, they want to highlight the new UEFI boot support <a href="http://freebsdfoundation.blogspot.com/2014/05/freebsd-foundation-newcons-project.html" target="_blank" rel="nofollow noopener">and newcons</a></li>
<li>There's a lot of details about what exactly UEFI is and why we need it going forward</li>
<li>FreeBSD has also needed some updates to its console to support UTF8 and wide characters</li>
<li>Hopefully this series will continue and we'll get to see what other work is being sponsored
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-cvs&amp;m=139879453001957&amp;w=2" target="_blank" rel="nofollow noopener">OpenSSH without OpenSSL</a></h3>

<ul>
<li>The OpenSSH team has been hard at work, making it even better, and now OpenSSL is completely optional</li>
<li>Since it won't have access to the primitives OpenSSL uses, there will be a trade-off of features vs. security</li>
<li>This version will drop support for legacy SSH v1, and the only two cryptographic algorithms supported are an in-house implementation of AES in counter mode and the <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/PROTOCOL.chacha20poly1305?rev=HEAD;content-type=text%2Fplain" target="_blank" rel="nofollow noopener">new combination</a> of the Chacha20 stream cipher with Poly1305 for packet integrity</li>
<li>Key exchange is limited to elliptic curve Diffie-Hellman and the newer Curve25519 KEXs</li>
<li>No support for RSA, DSA or ECDSA public keys - only Ed25519</li>
<li>It also includes a <a href="http://marc.info/?l=openbsd-cvs&amp;m=139883582313750&amp;w=2" target="_blank" rel="nofollow noopener">new buffer API</a> and a set of wrappers to make it compatible with the existing API</li>
<li>Believe it or not, this was planned before all the heartbleed craziness</li>
<li>Maybe someday soon we'll have a mini-openssh-portable in FreeBSD ports and NetBSD pkgsrc, would be really neat
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1861-free-pascal-on-bsd-april-bsd-issue" target="_blank" rel="nofollow noopener">BSDMag's April 2014 issue is out</a></h3>

<ul>
<li>The free monthly BSD magazine has got a new issue available for download</li>
<li>This time the articles include: pascal on BSD, an introduction to revision control systems and configuration management, deploying NetBSD on AWS EC2, more GIMP tutorials, an AsiaBSDCon 2014 report and a piece about how easily credit cards are stolen online</li>
<li>Anyone can contribute to the magazine, just send the editors an email about what you want to write</li>
<li>No Linux articles this time around, good
***</li>
</ul>

<h2>Interview - David Chisnall - <a href="mailto:theraven@freebsd.org" target="_blank" rel="nofollow noopener">theraven@freebsd.org</a></h2>

<p>The LLVM/Clang switch, FreeBSD's core team, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/raid" target="_blank" rel="nofollow noopener">RAID in FreeBSD and OpenBSD</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://bsdtalk.blogspot.com/2014/04/bsdtalk240-about-time-with-george.html" target="_blank" rel="nofollow noopener">BSDTalk episode 240</a></h3>

<ul>
<li>Our buddy Will Backman has uploaded a new episode of BSDTalk, this time with our other buddy GNN as the guest - mainly to talk about NTP and keeping reliable time</li>
<li>Topics include the specific details of crystals used in watches and computers to keep time, how temperature affects the quality, different sources of inaccuracy, some general NTP information, why you might want extremely precise time, different time sources (GPS, satellite, etc), differences in stratum levels, the problem of packet delay and estimating the round trip time, some of the recent NTP amplification attacks, the downsides to using UDP instead of TCP and... much more</li>
<li>GNN also talks a little about the <a href="https://en.wikipedia.org/wiki/Precision_Time_Protocol" target="_blank" rel="nofollow noopener">Precision Time Protocol</a> and how it's different than NTP</li>
<li>Two <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" target="_blank" rel="nofollow noopener">people</a> we've <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" target="_blank" rel="nofollow noopener">interviewed</a> talking to each other, awesome</li>
<li>If you're interested in NTP, be sure to see our <a href="http://www.bsdnow.tv/tutorials/ntpd" target="_blank" rel="nofollow noopener">tutorial</a> too
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140502092427" target="_blank" rel="nofollow noopener">m2k14 trip reports</a></h3>

<ul>
<li>We've got a few more reports from the recent OpenBSD hackathon in Morocco</li>
<li>The first one is from Antoine Jacoutot (who is a key GNOME porter and gave us the screenshots for the <a href="http://www.bsdnow.tv/tutorials/the-desktop-obsd" target="_blank" rel="nofollow noopener">OpenBSD desktop tutorial</a>)</li>
<li>"Since I always fail at actually doing whatever I have planned for a hackathon, this time I decided to come to m2k14 unprepared about what I was going to do"</li>
<li>He got lots of work done with ports and pushing GNOME-related patches back up to the main project, then worked on fixing ports' compatibility with LibreSSL</li>
<li>Speaking of LibreSSL, there's <a href="http://undeadly.org/cgi?action=article&amp;sid=20140505062023" target="_blank" rel="nofollow noopener">an article</a> all would-be portable version writers should probably read and take into consideration</li>
<li>Jasper Adriaanse <a href="http://undeadly.org/cgi?action=article&amp;sid=20140501185019" target="_blank" rel="nofollow noopener">also writes</a> about what he got done over there</li>
<li>He cleaned up and fixed the puppet port to work better with OpenBSD
***</li>
</ul>

<h3><a href="https://www.atlantic.net/blog/2014/04/08/freebsd-ssd-cloud-vps-hosting-10-reasons/" target="_blank" rel="nofollow noopener">Why you should use FreeBSD on your cloud VPS</a></h3>

<ul>
<li>Here we have a blog post from Atlantic, a VPS and hosting provider, about 10 reasons for using FreeBSD</li>
<li>Starts off with a little bit of BSD history for those who are unfamiliar with it and only know Linux and Windows</li>
<li>The 10 reasons are: community, stability, collaboration, ease of use, ports, security, ZFS, GEOM, sound and having lots of options</li>
<li>The post goes into detail about each of them and why FreeBSD makes a great choice for a VPS OS
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/05/weekly-feature-digest-27-software-system-redesign/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Big changes coming in the way PCBSD manages software</li>
<li>The PBI system, AppCafe and related tools are all going to use pkgng now</li>
<li>The AppCafe will no longer be limited to PBIs, so much more software will be easily available from the ports tree</li>
<li>New rating system coming soon and much more
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21bk2oPuQ" target="_blank" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s2n9fx1Rpw" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2rBBKLA4u" target="_blank" rel="nofollow noopener">Alex writes in</a></li>
<li><a href="http://slexy.org/view/s20JY6ZI71" target="_blank" rel="nofollow noopener">Goetz writes in</a></li>
<li><a href="http://slexy.org/view/s20YV5Ohpa" target="_blank" rel="nofollow noopener">Jarrad writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>35: Puffy Firewall</title>
  <link>https://www.bsdnow.tv/35</link>
  <guid isPermaLink="false">203904d9-509c-4727-918f-d5e6a6276cf8</guid>
  <pubDate>Wed, 30 Apr 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/203904d9-509c-4727-918f-d5e6a6276cf8.mp3" length="57157492" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:19:23</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140419151959" target="_blank" rel="nofollow noopener"&gt;ALTQ removed from PF&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Kicking off our big PF episode...&lt;/li&gt;
&lt;li&gt;The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current&lt;/li&gt;
&lt;li&gt;There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf&lt;/li&gt;
&lt;li&gt;As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping&lt;/li&gt;
&lt;li&gt;After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem&lt;/li&gt;
&lt;li&gt;This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD Quarterly Status Report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks&lt;/li&gt;
&lt;li&gt;Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added&lt;/li&gt;
&lt;li&gt;We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team&lt;/li&gt;
&lt;li&gt;LOTS of details and LOTS of topics to cover, give it a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140417184158" target="_blank" rel="nofollow noopener"&gt;OpenBSD's OpenSSL rewrite continues with m2k14&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A mini OpenBSD &lt;a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener"&gt;hackathon&lt;/a&gt; begins in Morocco, Africa&lt;/li&gt;
&lt;li&gt;You can follow the changes in &lt;a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" target="_blank" rel="nofollow noopener"&gt;the -current CVS log&lt;/a&gt;, but &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140418063443" target="_blank" rel="nofollow noopener"&gt;a lot of work&lt;/a&gt; is mainly going towards the OpenSSL cleaning&lt;/li&gt;
&lt;li&gt;We've got two &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140429121423" target="_blank" rel="nofollow noopener"&gt;trip&lt;/a&gt; &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140425115340" target="_blank" rel="nofollow noopener"&gt;reports&lt;/a&gt; so far, hopefully we'll have some more to show you in a future episode&lt;/li&gt;
&lt;li&gt;You can see some of the &lt;a href="http://opensslrampage.org/" target="_blank" rel="nofollow noopener"&gt;more interesting quotes&lt;/a&gt; from the tear-down or &lt;a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener"&gt;see everything&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140423045847" target="_blank" rel="nofollow noopener"&gt;Apparently&lt;/a&gt; they are going to call the fork "&lt;a href="https://news.ycombinator.com/item?id=7623789" target="_blank" rel="nofollow noopener"&gt;LibreSSL&lt;/a&gt;" ....&lt;/li&gt;
&lt;li&gt;&lt;a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener"&gt;What were the OpenSSL developers thinking&lt;/a&gt;? The RSA private key was used to seed the entropy!&lt;/li&gt;
&lt;li&gt;We also got &lt;a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" target="_blank" rel="nofollow noopener"&gt;some mainstream news coverage&lt;/a&gt; and &lt;a href="http://www.tedunangst.com/flak/post/origins-of-libressl" target="_blank" rel="nofollow noopener"&gt;another post from Ted&lt;/a&gt; about the history of the fork&lt;/li&gt;
&lt;li&gt;Definitely consider &lt;a href="http://www.openbsdfoundation.org/donations.html" target="_blank" rel="nofollow noopener"&gt;donating to the OpenBSD foundation&lt;/a&gt;, this fork will benefit all the other BSDs too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" target="_blank" rel="nofollow noopener"&gt;NetBSD 6.1.4 and 6.0.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes&lt;/li&gt;
&lt;li&gt;The main update is - of course - the heartbleed vulnerability&lt;/li&gt;
&lt;li&gt;Also includes fixes for other security issues and even a kernel panic... on Atari&lt;/li&gt;
&lt;li&gt;Patch your Ataris right now, this is serious business
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Peter Hansteen - &lt;a href="mailto:peter@bsdly.net" target="_blank" rel="nofollow noopener"&gt;peter@bsdly.net&lt;/a&gt; / &lt;a href="https://twitter.com/pitrh" target="_blank" rel="nofollow noopener"&gt;@pitrh&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The Book of PF: 3rd edition&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/pf" target="_blank" rel="nofollow noopener"&gt;BSD Firewalls: PF&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=351411" target="_blank" rel="nofollow noopener"&gt;New Xorg now the default in FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For quite a while now, FreeBSD has had two versions of X11 in ports&lt;/li&gt;
&lt;li&gt;The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf&lt;/li&gt;
&lt;li&gt;They've finally made the switch for 10-STABLE and 9-STABLE&lt;/li&gt;
&lt;li&gt;Check &lt;a href="https://wiki.freebsd.org/Graphics" target="_blank" rel="nofollow noopener"&gt;this wiki page&lt;/a&gt; for more info
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" target="_blank" rel="nofollow noopener"&gt;GSoC-accepted BSD projects&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned&lt;/li&gt;
&lt;li&gt;OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" target="_blank" rel="nofollow noopener"&gt;FreeBSD list&lt;/a&gt; was also posted&lt;/li&gt;
&lt;li&gt;Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more&lt;/li&gt;
&lt;li&gt;Good luck to all the students participating, hopefully they become full time BSD users
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" target="_blank" rel="nofollow noopener"&gt;Complexity of FreeBSD VFS using ZFS as an example&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;HybridCluster posted the second part of their VFS and ZFS series&lt;/li&gt;
&lt;li&gt;This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy&lt;/li&gt;
&lt;li&gt;Of course, also watch &lt;a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" target="_blank" rel="nofollow noopener"&gt;episode 24&lt;/a&gt; for our interview with HybridCluster - they do really interesting stuff
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Preload has been ported over, it's a daemon that prefetches applications&lt;/li&gt;
&lt;li&gt;PCBSD is developing their own desktop environment, Lumina (&lt;a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" target="_blank" rel="nofollow noopener"&gt;there's also an FAQ&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;It's still in active development, but you can try it out by installing from ports&lt;/li&gt;
&lt;li&gt;We'll be showing a live demo of it in a few weeks (when development settles down a bit)&lt;/li&gt;
&lt;li&gt;Some kid in Australia &lt;a href="https://www.youtube.com/watch?v=ETxhbf3-z18" target="_blank" rel="nofollow noopener"&gt;subjects his poor mother to being on camera&lt;/a&gt; while she tries out PCBSD and gives her impressions of it
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pf, firewall, pfsense, ipfw, ipfilter, router, packet filter, book of pf, third edition, 3rd, bsdcan, presentation, security, peter hansteen, peter n.m. hansteen, pitrh, iptables, npf, nostarch, no starch press, m2k14, hackathon, libressl, openssl, fork</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" target="_blank" rel="nofollow noopener">ALTQ removed from PF</a></h3>

<ul>
<li>Kicking off our big PF episode...</li>
<li>The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current</li>
<li>There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf</li>
<li>As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping</li>
<li>After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem</li>
<li>This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" target="_blank" rel="nofollow noopener">FreeBSD Quarterly Status Report</a></h3>

<ul>
<li>The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks</li>
<li>Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added</li>
<li>We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team</li>
<li>LOTS of details and LOTS of topics to cover, give it a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140417184158" target="_blank" rel="nofollow noopener">OpenBSD's OpenSSL rewrite continues with m2k14</a></h3>

<ul>
<li>A mini OpenBSD <a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener">hackathon</a> begins in Morocco, Africa</li>
<li>You can follow the changes in <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" target="_blank" rel="nofollow noopener">the -current CVS log</a>, but <a href="http://undeadly.org/cgi?action=article&amp;sid=20140418063443" target="_blank" rel="nofollow noopener">a lot of work</a> is mainly going towards the OpenSSL cleaning</li>
<li>We've got two <a href="http://undeadly.org/cgi?action=article&amp;sid=20140429121423" target="_blank" rel="nofollow noopener">trip</a> <a href="http://undeadly.org/cgi?action=article&amp;sid=20140425115340" target="_blank" rel="nofollow noopener">reports</a> so far, hopefully we'll have some more to show you in a future episode</li>
<li>You can see some of the <a href="http://opensslrampage.org/" target="_blank" rel="nofollow noopener">more interesting quotes</a> from the tear-down or <a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener">see everything</a></li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140423045847" target="_blank" rel="nofollow noopener">Apparently</a> they are going to call the fork "<a href="https://news.ycombinator.com/item?id=7623789" target="_blank" rel="nofollow noopener">LibreSSL</a>" ....</li>
<li><a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener">What were the OpenSSL developers thinking</a>? The RSA private key was used to seed the entropy!</li>
<li>We also got <a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" target="_blank" rel="nofollow noopener">some mainstream news coverage</a> and <a href="http://www.tedunangst.com/flak/post/origins-of-libressl" target="_blank" rel="nofollow noopener">another post from Ted</a> about the history of the fork</li>
<li>Definitely consider <a href="http://www.openbsdfoundation.org/donations.html" target="_blank" rel="nofollow noopener">donating to the OpenBSD foundation</a>, this fork will benefit all the other BSDs too
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" target="_blank" rel="nofollow noopener">NetBSD 6.1.4 and 6.0.5 released</a></h3>

<ul>
<li>New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes</li>
<li>The main update is - of course - the heartbleed vulnerability</li>
<li>Also includes fixes for other security issues and even a kernel panic... on Atari</li>
<li>Patch your Ataris right now, this is serious business
***</li>
</ul>

<h2>Interview - Peter Hansteen - <a href="mailto:peter@bsdly.net" target="_blank" rel="nofollow noopener">peter@bsdly.net</a> / <a href="https://twitter.com/pitrh" target="_blank" rel="nofollow noopener">@pitrh</a></h2>

<p>The Book of PF: 3rd edition</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pf" target="_blank" rel="nofollow noopener">BSD Firewalls: PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=351411" target="_blank" rel="nofollow noopener">New Xorg now the default in FreeBSD</a></h3>

<ul>
<li>For quite a while now, FreeBSD has had two versions of X11 in ports</li>
<li>The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf</li>
<li>They've finally made the switch for 10-STABLE and 9-STABLE</li>
<li>Check <a href="https://wiki.freebsd.org/Graphics" target="_blank" rel="nofollow noopener">this wiki page</a> for more info
***</li>
</ul>

<h3><a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" target="_blank" rel="nofollow noopener">GSoC-accepted BSD projects</a></h3>

<ul>
<li>The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned</li>
<li>OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon</li>
<li>The <a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" target="_blank" rel="nofollow noopener">FreeBSD list</a> was also posted</li>
<li>Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more</li>
<li>Good luck to all the students participating, hopefully they become full time BSD users
***</li>
</ul>

<h3><a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" target="_blank" rel="nofollow noopener">Complexity of FreeBSD VFS using ZFS as an example</a></h3>

<ul>
<li>HybridCluster posted the second part of their VFS and ZFS series</li>
<li>This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy</li>
<li>Of course, also watch <a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" target="_blank" rel="nofollow noopener">episode 24</a> for our interview with HybridCluster - they do really interesting stuff
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Preload has been ported over, it's a daemon that prefetches applications</li>
<li>PCBSD is developing their own desktop environment, Lumina (<a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" target="_blank" rel="nofollow noopener">there's also an FAQ</a>)</li>
<li>It's still in active development, but you can try it out by installing from ports</li>
<li>We'll be showing a live demo of it in a few weeks (when development settles down a bit)</li>
<li>Some kid in Australia <a href="https://www.youtube.com/watch?v=ETxhbf3-z18" target="_blank" rel="nofollow noopener">subjects his poor mother to being on camera</a> while she tries out PCBSD and gives her impressions of it
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back again! On this week's packed show, we've got one of the biggest tutorials we've done in a while. It's an in-depth look at PF, OpenBSD's firewall, with some practical examples and different use cases. We'll also be talking to Peter Hansteen about the new edition of "The Book of PF." Of course, we've got news and answers to your emails too, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" target="_blank" rel="nofollow noopener">ALTQ removed from PF</a></h3>

<ul>
<li>Kicking off our big PF episode...</li>
<li>The classic packet queueing system, ALTQ, was recently removed from OpenBSD -current</li>
<li>There will be a transitional phase between 5.5 and 5.6 where you can still use it by replacing the "queue" keyword with "oldqueue" in your pf.conf</li>
<li>As of 5.6, due about six months from now, you'll have to change your ruleset to the new syntax if you're using it for bandwidth shaping</li>
<li>After more than ten years, bandwidth queueing has matured quite a bit and we can finally put ALTQ to rest, in favor of the new queueing subsystem</li>
<li>This doesn't affect FreeBSD, PCBSD, NetBSD or DragonflyBSD since all of their PFs are older and maintained separately.
***</li>
</ul>

<h3><a href="https://www.freebsd.org/news/status/report-2014-01-2014-03.html" target="_blank" rel="nofollow noopener">FreeBSD Quarterly Status Report</a></h3>

<ul>
<li>The quarterly status report from FreeBSD is out, detailing some of the project's ongoing tasks</li>
<li>Some highlights include the first "stable" branch of ports, ARM improvements (including SMP), bhyve improvements, more work on the test suite, desktop improvements including the new vt console driver and UEFI booting support finally being added</li>
<li>We've got some specific updates from the cluster admin team, core team, documentation team, portmgr team, email team and release engineering team</li>
<li>LOTS of details and LOTS of topics to cover, give it a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140417184158" target="_blank" rel="nofollow noopener">OpenBSD's OpenSSL rewrite continues with m2k14</a></h3>

<ul>
<li>A mini OpenBSD <a href="http://www.openbsd.org/hackathons.html" target="_blank" rel="nofollow noopener">hackathon</a> begins in Morocco, Africa</li>
<li>You can follow the changes in <a href="http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libssl/src/ssl/" target="_blank" rel="nofollow noopener">the -current CVS log</a>, but <a href="http://undeadly.org/cgi?action=article&amp;sid=20140418063443" target="_blank" rel="nofollow noopener">a lot of work</a> is mainly going towards the OpenSSL cleaning</li>
<li>We've got two <a href="http://undeadly.org/cgi?action=article&amp;sid=20140429121423" target="_blank" rel="nofollow noopener">trip</a> <a href="http://undeadly.org/cgi?action=article&amp;sid=20140425115340" target="_blank" rel="nofollow noopener">reports</a> so far, hopefully we'll have some more to show you in a future episode</li>
<li>You can see some of the <a href="http://opensslrampage.org/" target="_blank" rel="nofollow noopener">more interesting quotes</a> from the tear-down or <a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener">see everything</a></li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140423045847" target="_blank" rel="nofollow noopener">Apparently</a> they are going to call the fork "<a href="https://news.ycombinator.com/item?id=7623789" target="_blank" rel="nofollow noopener">LibreSSL</a>" ....</li>
<li><a href="http://freshbsd.org/commit/openbsd/e5136d69ece4682e6167c8f4a8122270236898bf" target="_blank" rel="nofollow noopener">What were the OpenSSL developers thinking</a>? The RSA private key was used to seed the entropy!</li>
<li>We also got <a href="http://www.zdnet.com/openbsd-forks-prunes-fixes-openssl-7000028613/" target="_blank" rel="nofollow noopener">some mainstream news coverage</a> and <a href="http://www.tedunangst.com/flak/post/origins-of-libressl" target="_blank" rel="nofollow noopener">another post from Ted</a> about the history of the fork</li>
<li>Definitely consider <a href="http://www.openbsdfoundation.org/donations.html" target="_blank" rel="nofollow noopener">donating to the OpenBSD foundation</a>, this fork will benefit all the other BSDs too
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/netbsd_6_1_4_and" target="_blank" rel="nofollow noopener">NetBSD 6.1.4 and 6.0.5 released</a></h3>

<ul>
<li>New updates for the 6.1 and 6.0 branches of NetBSD, focusing on bugfixes</li>
<li>The main update is - of course - the heartbleed vulnerability</li>
<li>Also includes fixes for other security issues and even a kernel panic... on Atari</li>
<li>Patch your Ataris right now, this is serious business
***</li>
</ul>

<h2>Interview - Peter Hansteen - <a href="mailto:peter@bsdly.net" target="_blank" rel="nofollow noopener">peter@bsdly.net</a> / <a href="https://twitter.com/pitrh" target="_blank" rel="nofollow noopener">@pitrh</a></h2>

<p>The Book of PF: 3rd edition</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pf" target="_blank" rel="nofollow noopener">BSD Firewalls: PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=351411" target="_blank" rel="nofollow noopener">New Xorg now the default in FreeBSD</a></h3>

<ul>
<li>For quite a while now, FreeBSD has had two versions of X11 in ports</li>
<li>The older, stable version was the default, but you could install a newer one by having "WITH_NEW_XORG" in /etc/make.conf</li>
<li>They've finally made the switch for 10-STABLE and 9-STABLE</li>
<li>Check <a href="https://wiki.freebsd.org/Graphics" target="_blank" rel="nofollow noopener">this wiki page</a> for more info
***</li>
</ul>

<h3><a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/openbsdfoundation" target="_blank" rel="nofollow noopener">GSoC-accepted BSD projects</a></h3>

<ul>
<li>The Google Summer of Code team has got the list of accepted project proposals uploaded so we can see what's planned</li>
<li>OpenBSD's list includes DHCP configuration parsing improvements, systemd replacements, porting capsicum, GPT and UEFI support, and modernizing the DHCP daemon</li>
<li>The <a href="https://www.google-melange.com/gsoc/org2/google/gsoc2014/freebsd" target="_blank" rel="nofollow noopener">FreeBSD list</a> was also posted</li>
<li>Theirs includes porting FreeBSD to the Android emulator, CTF in the kernel debugger, improved unicode support, converting firewall rules to a C module, pkgng improvements, MicroBlaze support, PXE fixes, bhyve caching, bootsplash and lots more</li>
<li>Good luck to all the students participating, hopefully they become full time BSD users
***</li>
</ul>

<h3><a href="http://www.hybridcluster.com/blog/complexity-freebsd-vfs-using-zfs-example-part-2/" target="_blank" rel="nofollow noopener">Complexity of FreeBSD VFS using ZFS as an example</a></h3>

<ul>
<li>HybridCluster posted the second part of their VFS and ZFS series</li>
<li>This new post has lots of technical details once again, definitely worth reading if you're a ZFS guy</li>
<li>Of course, also watch <a href="http://www.bsdnow.tv/episodes/2014_02_12-the_cluster_the_cloud" target="_blank" rel="nofollow noopener">episode 24</a> for our interview with HybridCluster - they do really interesting stuff
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/weekly-feature-digest-26-the-lumina-project-and-preload/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Preload has been ported over, it's a daemon that prefetches applications</li>
<li>PCBSD is developing their own desktop environment, Lumina (<a href="http://blog.pcbsd.org/2014/04/quick-lumina-desktop-faq/" target="_blank" rel="nofollow noopener">there's also an FAQ</a>)</li>
<li>It's still in active development, but you can try it out by installing from ports</li>
<li>We'll be showing a live demo of it in a few weeks (when development settles down a bit)</li>
<li>Some kid in Australia <a href="https://www.youtube.com/watch?v=ETxhbf3-z18" target="_blank" rel="nofollow noopener">subjects his poor mother to being on camera</a> while she tries out PCBSD and gives her impressions of it
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>27: BSD Now vs. BSDTalk</title>
  <link>https://www.bsdnow.tv/27</link>
  <guid isPermaLink="false">9c2ed198-48a2-4ed6-988c-6d5ce1ed66c7</guid>
  <pubDate>Wed, 05 Mar 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/9c2ed198-48a2-4ed6-988c-6d5ce1ed66c7.mp3" length="73930325" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>The long-awaited meetup is finally happening on today's show. We're going to be interviewing the original BSD podcaster, Will Backman, to discuss what he's been up to and what the future of BSD advocacy looks like. After that, we'll be showing you how to track (and even cross-compile!) the -CURRENT branch of NetBSD. We've got answers to user-submitted questions and the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:42:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;The long-awaited meetup is finally happening on today's show. We're going to be interviewing the original BSD podcaster, Will Backman, to discuss what he's been up to and what the future of BSD advocacy looks like. After that, we'll be showing you how to track (and even cross-compile!) the -CURRENT branch of NetBSD. We've got answers to user-submitted questions and the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://wiki.freebsd.org/SummerOfCode2014" target="_blank" rel="nofollow noopener"&gt;FreeBSD and OpenBSD in GSOC2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Google Summer of Code is a way to encourage students to write code for open source projects and make some money&lt;/li&gt;
&lt;li&gt;Both FreeBSD and OpenBSD were accepted, and we'd love for anyone listening to check out their GSOC pages&lt;/li&gt;
&lt;li&gt;The FreeBSD wiki has a list of things that they'd be interested in someone helping out with&lt;/li&gt;
&lt;li&gt;OpenBSD's want list was &lt;a href="http://www.openbsdfoundation.org/gsoc2014.html" target="_blank" rel="nofollow noopener"&gt;also posted&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;DragonflyBSD and NetBSD were sadly not accepted this year
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2014/02/yes-you-too-can-be-evil-network.html" target="_blank" rel="nofollow noopener"&gt;Yes, you too can be an evil network overlord&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog post about monitoring your network using only free tools&lt;/li&gt;
&lt;li&gt;OpenBSD is a great fit, and has all the stuff you need in the base system or via packages&lt;/li&gt;
&lt;li&gt;It talks about the pflow pseudo-interface, its capabilities and relation to NetFlow (also goes well with pf)&lt;/li&gt;
&lt;li&gt;There's also details about flowd and nfsen, more great tools to make network monitoring easy&lt;/li&gt;
&lt;li&gt;If you're listening, Peter... stop ignoring our emails and come on the show! We know you're watching!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdmag.org/magazine/1858-openbsd-5-4-configure-openbsd-basic-services" target="_blank" rel="nofollow noopener"&gt;BSDMag's February issue is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The theme is "configuring basic services on OpenBSD 5.4"&lt;/li&gt;
&lt;li&gt;There's also an interview with Peter Hansteen (oh hey...)&lt;/li&gt;
&lt;li&gt;Topics also include locking down SSH, a GIMP lesson, user/group management, and...&lt;/li&gt;
&lt;li&gt;Linux and Solaris articles? Why??
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://marc.info/?l=openbsd-misc&amp;amp;m=139320023202696&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;Changes in bcrypt&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Not specific to any OS, but the OpenBSD team is updating their bcrypt implementation&lt;/li&gt;
&lt;li&gt;There is a bug in bcrypt when hashing long passwords - other OSes need to update theirs too! (FreeBSD already has)&lt;/li&gt;
&lt;li&gt;"The length is stored in an unsigned char type, which will overflow and wrap at 256. Although we consider the existence of affected hashes very rare, in order to differentiate hashes generated before and after the fix, we are introducing a new minor 'b'."&lt;/li&gt;
&lt;li&gt;As long as you upgrade your OpenBSD system in order (without skipping versions) you should be ok going forward&lt;/li&gt;
&lt;li&gt;Lots of specifics in the email, check the full thing
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Will Backman - &lt;a href="mailto:bitgeist@yahoo.com" target="_blank" rel="nofollow noopener"&gt;bitgeist@yahoo.com&lt;/a&gt; / &lt;a href="https://twitter.com/bsdtalk" target="_blank" rel="nofollow noopener"&gt;@bsdtalk&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The BSDTalk podcast, BSD advocacy, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/current-nbsd" target="_blank" rel="nofollow noopener"&gt;Tracking and cross-compiling -CURRENT (NetBSD)&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140223112426" target="_blank" rel="nofollow noopener"&gt;X11 no longer needs root&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Xorg has long since required root privileges to run the main server&lt;/li&gt;
&lt;li&gt;With &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;;m=139245772023497&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;recent work&lt;/a&gt; from the OpenBSD team, now everything (even KMS) can run as a regular user&lt;/li&gt;
&lt;li&gt;Now you can set the "machdep.allowaperture" sysctl to 0 and still use a GUI
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-March/032259.html" target="_blank" rel="nofollow noopener"&gt;OpenSSH 6.6 CFT&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Shortly after the huge 6.5 release, we get a routine bugfix update&lt;/li&gt;
&lt;li&gt;Test it out on as many systems as you can&lt;/li&gt;
&lt;li&gt;Check the mailing list for the full bug list
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140225072408" target="_blank" rel="nofollow noopener"&gt;Creating an OpenBSD USB drive&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Since OpenBSD doesn't distribute any official USB images, here are some instructions on how to do it&lt;/li&gt;
&lt;li&gt;Step by step guide on how you can make your very own&lt;/li&gt;
&lt;li&gt;However, there's some &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140228231258" target="_blank" rel="nofollow noopener"&gt;recent emails&lt;/a&gt; that suggest official USB images may be coming soon... &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139377587526463&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;oh wait&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-19/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New PBI updates that allow separate ports from /usr/local&lt;/li&gt;
&lt;li&gt;You need to rebuild pbi-manager if you want to try it out&lt;/li&gt;
&lt;li&gt;Updates and changes to Life Preserver, App Cafe, PCDM
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2JpJ5EaZp" target="_blank" rel="nofollow noopener"&gt;espressowar writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QpPevJ3J" target="_blank" rel="nofollow noopener"&gt;Antonio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2EZLxDfWh" target="_blank" rel="nofollow noopener"&gt;Christian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21gEBZbmG" target="_blank" rel="nofollow noopener"&gt;Adam writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2RnCO1p9c" target="_blank" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, will backman, bsdtalk, podcast, cross compile, build.sh, portable, portability, cross-build, building a release, google summer of code, gsoc, gsoc2014, 2014, spamd, dd, opensmtpd, tcpdump, packet filtering, monitoring, network, bcrypt, solar designer, ixsystems, usb, bootable, jails, openbsd usb drive, ezjail, jails, bsd jail, x11, openssh, pflow, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>The long-awaited meetup is finally happening on today's show. We're going to be interviewing the original BSD podcaster, Will Backman, to discuss what he's been up to and what the future of BSD advocacy looks like. After that, we'll be showing you how to track (and even cross-compile!) the -CURRENT branch of NetBSD. We've got answers to user-submitted questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://wiki.freebsd.org/SummerOfCode2014" target="_blank" rel="nofollow noopener">FreeBSD and OpenBSD in GSOC2014</a></h3>

<ul>
<li>The Google Summer of Code is a way to encourage students to write code for open source projects and make some money</li>
<li>Both FreeBSD and OpenBSD were accepted, and we'd love for anyone listening to check out their GSOC pages</li>
<li>The FreeBSD wiki has a list of things that they'd be interested in someone helping out with</li>
<li>OpenBSD's want list was <a href="http://www.openbsdfoundation.org/gsoc2014.html" target="_blank" rel="nofollow noopener">also posted</a></li>
<li>DragonflyBSD and NetBSD were sadly not accepted this year
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/02/yes-you-too-can-be-evil-network.html" target="_blank" rel="nofollow noopener">Yes, you too can be an evil network overlord</a></h3>

<ul>
<li>A new blog post about monitoring your network using only free tools</li>
<li>OpenBSD is a great fit, and has all the stuff you need in the base system or via packages</li>
<li>It talks about the pflow pseudo-interface, its capabilities and relation to NetFlow (also goes well with pf)</li>
<li>There's also details about flowd and nfsen, more great tools to make network monitoring easy</li>
<li>If you're listening, Peter... stop ignoring our emails and come on the show! We know you're watching!
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1858-openbsd-5-4-configure-openbsd-basic-services" target="_blank" rel="nofollow noopener">BSDMag's February issue is out</a></h3>

<ul>
<li>The theme is "configuring basic services on OpenBSD 5.4"</li>
<li>There's also an interview with Peter Hansteen (oh hey...)</li>
<li>Topics also include locking down SSH, a GIMP lesson, user/group management, and...</li>
<li>Linux and Solaris articles? Why??
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-misc&amp;m=139320023202696&amp;w=2" target="_blank" rel="nofollow noopener">Changes in bcrypt</a></h3>

<ul>
<li>Not specific to any OS, but the OpenBSD team is updating their bcrypt implementation</li>
<li>There is a bug in bcrypt when hashing long passwords - other OSes need to update theirs too! (FreeBSD already has)</li>
<li>"The length is stored in an unsigned char type, which will overflow and wrap at 256. Although we consider the existence of affected hashes very rare, in order to differentiate hashes generated before and after the fix, we are introducing a new minor 'b'."</li>
<li>As long as you upgrade your OpenBSD system in order (without skipping versions) you should be ok going forward</li>
<li>Lots of specifics in the email, check the full thing
***</li>
</ul>

<h2>Interview - Will Backman - <a href="mailto:bitgeist@yahoo.com" target="_blank" rel="nofollow noopener">bitgeist@yahoo.com</a> / <a href="https://twitter.com/bsdtalk" target="_blank" rel="nofollow noopener">@bsdtalk</a></h2>

<p>The BSDTalk podcast, BSD advocacy, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/current-nbsd" target="_blank" rel="nofollow noopener">Tracking and cross-compiling -CURRENT (NetBSD)</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140223112426" target="_blank" rel="nofollow noopener">X11 no longer needs root</a></h3>

<ul>
<li>Xorg has long since required root privileges to run the main server</li>
<li>With <a href="http://marc.info/?l=openbsd-cvs&amp;;m=139245772023497&amp;w=2" target="_blank" rel="nofollow noopener">recent work</a> from the OpenBSD team, now everything (even KMS) can run as a regular user</li>
<li>Now you can set the "machdep.allowaperture" sysctl to 0 and still use a GUI
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-March/032259.html" target="_blank" rel="nofollow noopener">OpenSSH 6.6 CFT</a></h3>

<ul>
<li>Shortly after the huge 6.5 release, we get a routine bugfix update</li>
<li>Test it out on as many systems as you can</li>
<li>Check the mailing list for the full bug list
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140225072408" target="_blank" rel="nofollow noopener">Creating an OpenBSD USB drive</a></h3>

<ul>
<li>Since OpenBSD doesn't distribute any official USB images, here are some instructions on how to do it</li>
<li>Step by step guide on how you can make your very own</li>
<li>However, there's some <a href="http://undeadly.org/cgi?action=article&amp;sid=20140228231258" target="_blank" rel="nofollow noopener">recent emails</a> that suggest official USB images may be coming soon... <a href="http://marc.info/?l=openbsd-cvs&amp;m=139377587526463&amp;w=2" target="_blank" rel="nofollow noopener">oh wait</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-19/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI updates that allow separate ports from /usr/local</li>
<li>You need to rebuild pbi-manager if you want to try it out</li>
<li>Updates and changes to Life Preserver, App Cafe, PCDM
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2JpJ5EaZp" target="_blank" rel="nofollow noopener">espressowar writes in</a></li>
<li><a href="http://slexy.org/view/s2QpPevJ3J" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2EZLxDfWh" target="_blank" rel="nofollow noopener">Christian writes in</a></li>
<li><a href="http://slexy.org/view/s21gEBZbmG" target="_blank" rel="nofollow noopener">Adam writes in</a></li>
<li><a href="http://slexy.org/view/s2RnCO1p9c" target="_blank" rel="nofollow noopener">Alex writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>The long-awaited meetup is finally happening on today's show. We're going to be interviewing the original BSD podcaster, Will Backman, to discuss what he's been up to and what the future of BSD advocacy looks like. After that, we'll be showing you how to track (and even cross-compile!) the -CURRENT branch of NetBSD. We've got answers to user-submitted questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://wiki.freebsd.org/SummerOfCode2014" target="_blank" rel="nofollow noopener">FreeBSD and OpenBSD in GSOC2014</a></h3>

<ul>
<li>The Google Summer of Code is a way to encourage students to write code for open source projects and make some money</li>
<li>Both FreeBSD and OpenBSD were accepted, and we'd love for anyone listening to check out their GSOC pages</li>
<li>The FreeBSD wiki has a list of things that they'd be interested in someone helping out with</li>
<li>OpenBSD's want list was <a href="http://www.openbsdfoundation.org/gsoc2014.html" target="_blank" rel="nofollow noopener">also posted</a></li>
<li>DragonflyBSD and NetBSD were sadly not accepted this year
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/02/yes-you-too-can-be-evil-network.html" target="_blank" rel="nofollow noopener">Yes, you too can be an evil network overlord</a></h3>

<ul>
<li>A new blog post about monitoring your network using only free tools</li>
<li>OpenBSD is a great fit, and has all the stuff you need in the base system or via packages</li>
<li>It talks about the pflow pseudo-interface, its capabilities and relation to NetFlow (also goes well with pf)</li>
<li>There's also details about flowd and nfsen, more great tools to make network monitoring easy</li>
<li>If you're listening, Peter... stop ignoring our emails and come on the show! We know you're watching!
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1858-openbsd-5-4-configure-openbsd-basic-services" target="_blank" rel="nofollow noopener">BSDMag's February issue is out</a></h3>

<ul>
<li>The theme is "configuring basic services on OpenBSD 5.4"</li>
<li>There's also an interview with Peter Hansteen (oh hey...)</li>
<li>Topics also include locking down SSH, a GIMP lesson, user/group management, and...</li>
<li>Linux and Solaris articles? Why??
***</li>
</ul>

<h3><a href="http://marc.info/?l=openbsd-misc&amp;m=139320023202696&amp;w=2" target="_blank" rel="nofollow noopener">Changes in bcrypt</a></h3>

<ul>
<li>Not specific to any OS, but the OpenBSD team is updating their bcrypt implementation</li>
<li>There is a bug in bcrypt when hashing long passwords - other OSes need to update theirs too! (FreeBSD already has)</li>
<li>"The length is stored in an unsigned char type, which will overflow and wrap at 256. Although we consider the existence of affected hashes very rare, in order to differentiate hashes generated before and after the fix, we are introducing a new minor 'b'."</li>
<li>As long as you upgrade your OpenBSD system in order (without skipping versions) you should be ok going forward</li>
<li>Lots of specifics in the email, check the full thing
***</li>
</ul>

<h2>Interview - Will Backman - <a href="mailto:bitgeist@yahoo.com" target="_blank" rel="nofollow noopener">bitgeist@yahoo.com</a> / <a href="https://twitter.com/bsdtalk" target="_blank" rel="nofollow noopener">@bsdtalk</a></h2>

<p>The BSDTalk podcast, BSD advocacy, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/current-nbsd" target="_blank" rel="nofollow noopener">Tracking and cross-compiling -CURRENT (NetBSD)</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140223112426" target="_blank" rel="nofollow noopener">X11 no longer needs root</a></h3>

<ul>
<li>Xorg has long since required root privileges to run the main server</li>
<li>With <a href="http://marc.info/?l=openbsd-cvs&amp;;m=139245772023497&amp;w=2" target="_blank" rel="nofollow noopener">recent work</a> from the OpenBSD team, now everything (even KMS) can run as a regular user</li>
<li>Now you can set the "machdep.allowaperture" sysctl to 0 and still use a GUI
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-March/032259.html" target="_blank" rel="nofollow noopener">OpenSSH 6.6 CFT</a></h3>

<ul>
<li>Shortly after the huge 6.5 release, we get a routine bugfix update</li>
<li>Test it out on as many systems as you can</li>
<li>Check the mailing list for the full bug list
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140225072408" target="_blank" rel="nofollow noopener">Creating an OpenBSD USB drive</a></h3>

<ul>
<li>Since OpenBSD doesn't distribute any official USB images, here are some instructions on how to do it</li>
<li>Step by step guide on how you can make your very own</li>
<li>However, there's some <a href="http://undeadly.org/cgi?action=article&amp;sid=20140228231258" target="_blank" rel="nofollow noopener">recent emails</a> that suggest official USB images may be coming soon... <a href="http://marc.info/?l=openbsd-cvs&amp;m=139377587526463&amp;w=2" target="_blank" rel="nofollow noopener">oh wait</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-19/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI updates that allow separate ports from /usr/local</li>
<li>You need to rebuild pbi-manager if you want to try it out</li>
<li>Updates and changes to Life Preserver, App Cafe, PCDM
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2JpJ5EaZp" target="_blank" rel="nofollow noopener">espressowar writes in</a></li>
<li><a href="http://slexy.org/view/s2QpPevJ3J" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2EZLxDfWh" target="_blank" rel="nofollow noopener">Christian writes in</a></li>
<li><a href="http://slexy.org/view/s21gEBZbmG" target="_blank" rel="nofollow noopener">Adam writes in</a></li>
<li><a href="http://slexy.org/view/s2RnCO1p9c" target="_blank" rel="nofollow noopener">Alex writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>25: A Sixth pfSense</title>
  <link>https://www.bsdnow.tv/25</link>
  <guid isPermaLink="false">dad040a2-8866-4876-88fb-43b036b3e691</guid>
  <pubDate>Wed, 19 Feb 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/dad040a2-8866-4876-88fb-43b036b3e691.mp3" length="48903556" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We have a packed show for you this week! We'll sit down for an interview with Chris Buechler, from the pfSense project, to learn just how easy it can be to deploy a BSD firewall. We'll also be showing you a walkthrough of the pfSense interface so you can get an idea of just how convenient and powerful it is. Answers to your questions and the latest headlines, here on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:07:55</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We have a packed show for you this week! We'll sit down for an interview with Chris Buechler, from the pfSense project, to learn just how easy it can be to deploy a BSD firewall. We'll also be showing you a walkthrough of the pfSense interface so you can get an idea of just how convenient and powerful it is. Answers to your questions and the latest headlines, here on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/calendar/call-for-papers/" target="_blank" rel="nofollow noopener"&gt;EuroBSDCon and AsiaBSDCon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year, EuroBSDCon will be in September in Sofia, Bulgaria&lt;/li&gt;
&lt;li&gt;They've got a call for papers up now, so everyone can submit the talks they want to present&lt;/li&gt;
&lt;li&gt;There will also be a tutorial section of the conference&lt;/li&gt;
&lt;li&gt;&lt;a href="http://2014.asiabsdcon.org/timetable.html.en" target="_blank" rel="nofollow noopener"&gt;AsiaBSDCon&lt;/a&gt; will be next month, in March!&lt;/li&gt;
&lt;li&gt;All the info about the registration, tutorials, hotels, timetable and location have been posted&lt;/li&gt;
&lt;li&gt;Check the link for all the details on the talks - if you plan on going to Tokyo next month, hang out with Allan and Kris and lots of BSD developers!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://rtfm.net/FreeBSD/ERL/" target="_blank" rel="nofollow noopener"&gt;FreeBSD 10 on Ubiquiti EdgeRouter Lite&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Ubiquiti EdgeRouter Lite is a router that costs less than $100 and has a MIPS CPU&lt;/li&gt;
&lt;li&gt;This article goes through the process of installing and configuring FreeBSD on it to use as a home router&lt;/li&gt;
&lt;li&gt;Lots of good pictures of the hardware and specific details needed to get you set up&lt;/li&gt;
&lt;li&gt;It also includes the scripts to create your own images if you don't want to use the ones rolled by someone else&lt;/li&gt;
&lt;li&gt;For such a cheap price, might be a really fun weekend project to replace your shitty consumer router&lt;/li&gt;
&lt;li&gt;Of course if you're more of an OpenBSD guy, you can always see &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener"&gt;our tutorial&lt;/a&gt; for that too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.saveosx.org/signed-packages/" target="_blank" rel="nofollow noopener"&gt;Signed pkgsrc package guide&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We got a request on IRC for more pkgsrc stuff on the show, and a listener provided a nice write-up&lt;/li&gt;
&lt;li&gt;It shows you how to set up signed packages with pkgsrc, which works on quite a few OSes (not just NetBSD)&lt;/li&gt;
&lt;li&gt;He goes through the process of signing packages with a public key and how to verify the packages when you install them&lt;/li&gt;
&lt;li&gt;The author also happens to be an EdgeBSD developer
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140212083627" target="_blank" rel="nofollow noopener"&gt;Big batch of OpenBSD hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Five trip reports from the OpenBSD hackathon in New Zealand! In the first one, jmatthew details his work on fiber channel controller drivers, some octeon USB work and ARM fixes for AHCI&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140213065843" target="_blank" rel="nofollow noopener"&gt;the second&lt;/a&gt;, ketennis gets into his work with running interrupt handlers without holding the kernel lock, some SPARC64 improvements and a few other things&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140213173808" target="_blank" rel="nofollow noopener"&gt;the third&lt;/a&gt;, jsg updated libdrm and mesa and did various work on xenocara&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140214070023" target="_blank" rel="nofollow noopener"&gt;the fourth&lt;/a&gt;, dlg came with the intention to improve SMP support, but got distracted and did SCSI stuff instead - but he talks a little bit about the struggle OpenBSD has with SMP and some of the work he's done&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140214130039" target="_blank" rel="nofollow noopener"&gt;the fifth&lt;/a&gt;, claudio talks about some stuff he did for routing tables and misc. other things
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Chris Buechler - &lt;a href="mailto:cmb@pfsense.com" target="_blank" rel="nofollow noopener"&gt;cmb@pfsense.com&lt;/a&gt; / &lt;a href="https://twitter.com/cbuechler" target="_blank" rel="nofollow noopener"&gt;@cbuechler&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;pfSense&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;pfSense walkthrough&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.thelinuxcauldron.com/2014/02/13/freebsd-challenge-day-13-30/" target="_blank" rel="nofollow noopener"&gt;FreeBSD challenge continues&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy from the Linux foundation continues his switching to BSD journey&lt;/li&gt;
&lt;li&gt;In day 13, he covers some tips for new users, mentions trying things out in a VM first&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-14-30/" target="_blank" rel="nofollow noopener"&gt;day 14&lt;/a&gt;, he starts setting up XFCE and X11, feels like he's starting over as a new Linux user learning the ropes again - concludes that ports are the way to go&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-15-30/" target="_blank" rel="nofollow noopener"&gt;day 15&lt;/a&gt;, he finishes up his XFCE configuration and details different versions of ports with different names, as well as learns how to apply his first patch&lt;/li&gt;
&lt;li&gt;In &lt;a href="http://www.thelinuxcauldron.com/2014/02/17/freebsd-challenge-day-16-30/" target="_blank" rel="nofollow noopener"&gt;day 16&lt;/a&gt;, he dives into the world of &lt;a href="http://www.bsdnow.tv/tutorials/jails" target="_blank" rel="nofollow noopener"&gt;FreeBSD jails&lt;/a&gt;!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/1962" target="_blank" rel="nofollow noopener"&gt;BSD books in 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSD books are some of the highest quality technical writings available, and MWL has written a good number of them&lt;/li&gt;
&lt;li&gt;In this post, he details some of his plans for 2014&lt;/li&gt;
&lt;li&gt;In includes at least one OpenBSD book, at least one FreeBSD book and...&lt;/li&gt;
&lt;li&gt;Very strong possibility of Absolute FreeBSD 3rd edition (watch &lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener"&gt;our interview with him&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Check the link for all the details
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.daemonology.net/blog/2014-02-16-FreeBSD-EC2-build.html" target="_blank" rel="nofollow noopener"&gt;How to build FreeBSD/EC2 images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our friend &lt;a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" target="_blank" rel="nofollow noopener"&gt;Colin Percival&lt;/a&gt; details how to build EC2 images in a new blog post&lt;/li&gt;
&lt;li&gt;Most people just use the images he makes on their instances, but some people will want to make their own &lt;a href="https://svnweb.freebsd.org/base/user/cperciva/EC2-build/" target="_blank" rel="nofollow noopener"&gt;from scratch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;You build a regular disk image and then turn it into an AMI&lt;/li&gt;
&lt;li&gt;It requires a couple ports be installed on your system, but the whole process is pretty straightforward
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-17/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This time around we discuss how you can become a developer&lt;/li&gt;
&lt;li&gt;Kris also details the length of supported releases&lt;/li&gt;
&lt;li&gt;Expect lots of new features in 10.1
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216xJoCVG" target="_blank" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2gLrR3VVf" target="_blank" rel="nofollow noopener"&gt;Jake writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21gfG3Iho" target="_blank" rel="nofollow noopener"&gt;Niclas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2JNyw5BCn" target="_blank" rel="nofollow noopener"&gt;Steffan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2kg3zoRfm" target="_blank" rel="nofollow noopener"&gt;Antonio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ZwSIfRjm" target="_blank" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, pfsense, pf, firewall, gateway, router, hangout, webui, web interface, php, ipfw, ipfilter, gateway, graphs, bandwidth, edgerouter, edgerouter lite, eurobsdcon, eurobsdcon2014, edge router, 2014, books, michael w lucas, freebsd journal, fosdem, asiabsdcon, mips, hackathon, new zealand, pkgsrc, signed packages, edgebsd, smp, ec2, amazon, images, instance, build, custom</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We have a packed show for you this week! We'll sit down for an interview with Chris Buechler, from the pfSense project, to learn just how easy it can be to deploy a BSD firewall. We'll also be showing you a walkthrough of the pfSense interface so you can get an idea of just how convenient and powerful it is. Answers to your questions and the latest headlines, here on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/calendar/call-for-papers/" target="_blank" rel="nofollow noopener">EuroBSDCon and AsiaBSDCon</a></h3>

<ul>
<li>This year, EuroBSDCon will be in September in Sofia, Bulgaria</li>
<li>They've got a call for papers up now, so everyone can submit the talks they want to present</li>
<li>There will also be a tutorial section of the conference</li>
<li><a href="http://2014.asiabsdcon.org/timetable.html.en" target="_blank" rel="nofollow noopener">AsiaBSDCon</a> will be next month, in March!</li>
<li>All the info about the registration, tutorials, hotels, timetable and location have been posted</li>
<li>Check the link for all the details on the talks - if you plan on going to Tokyo next month, hang out with Allan and Kris and lots of BSD developers!
***</li>
</ul>

<h3><a href="http://rtfm.net/FreeBSD/ERL/" target="_blank" rel="nofollow noopener">FreeBSD 10 on Ubiquiti EdgeRouter Lite</a></h3>

<ul>
<li>The Ubiquiti EdgeRouter Lite is a router that costs less than $100 and has a MIPS CPU</li>
<li>This article goes through the process of installing and configuring FreeBSD on it to use as a home router</li>
<li>Lots of good pictures of the hardware and specific details needed to get you set up</li>
<li>It also includes the scripts to create your own images if you don't want to use the ones rolled by someone else</li>
<li>For such a cheap price, might be a really fun weekend project to replace your shitty consumer router</li>
<li>Of course if you're more of an OpenBSD guy, you can always see <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">our tutorial</a> for that too
***</li>
</ul>

<h3><a href="http://blog.saveosx.org/signed-packages/" target="_blank" rel="nofollow noopener">Signed pkgsrc package guide</a></h3>

<ul>
<li>We got a request on IRC for more pkgsrc stuff on the show, and a listener provided a nice write-up</li>
<li>It shows you how to set up signed packages with pkgsrc, which works on quite a few OSes (not just NetBSD)</li>
<li>He goes through the process of signing packages with a public key and how to verify the packages when you install them</li>
<li>The author also happens to be an EdgeBSD developer
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140212083627" target="_blank" rel="nofollow noopener">Big batch of OpenBSD hackathon reports</a></h3>

<ul>
<li>Five trip reports from the OpenBSD hackathon in New Zealand! In the first one, jmatthew details his work on fiber channel controller drivers, some octeon USB work and ARM fixes for AHCI</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140213065843" target="_blank" rel="nofollow noopener">the second</a>, ketennis gets into his work with running interrupt handlers without holding the kernel lock, some SPARC64 improvements and a few other things</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140213173808" target="_blank" rel="nofollow noopener">the third</a>, jsg updated libdrm and mesa and did various work on xenocara</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140214070023" target="_blank" rel="nofollow noopener">the fourth</a>, dlg came with the intention to improve SMP support, but got distracted and did SCSI stuff instead - but he talks a little bit about the struggle OpenBSD has with SMP and some of the work he's done</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140214130039" target="_blank" rel="nofollow noopener">the fifth</a>, claudio talks about some stuff he did for routing tables and misc. other things
***</li>
</ul>

<h2>Interview - Chris Buechler - <a href="mailto:cmb@pfsense.com" target="_blank" rel="nofollow noopener">cmb@pfsense.com</a> / <a href="https://twitter.com/cbuechler" target="_blank" rel="nofollow noopener">@cbuechler</a></h2>

<p>pfSense</p>

<hr>

<h2>Tutorial</h2>

<h3>pfSense walkthrough</h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.thelinuxcauldron.com/2014/02/13/freebsd-challenge-day-13-30/" target="_blank" rel="nofollow noopener">FreeBSD challenge continues</a></h3>

<ul>
<li>Our buddy from the Linux foundation continues his switching to BSD journey</li>
<li>In day 13, he covers some tips for new users, mentions trying things out in a VM first</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-14-30/" target="_blank" rel="nofollow noopener">day 14</a>, he starts setting up XFCE and X11, feels like he's starting over as a new Linux user learning the ropes again - concludes that ports are the way to go</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-15-30/" target="_blank" rel="nofollow noopener">day 15</a>, he finishes up his XFCE configuration and details different versions of ports with different names, as well as learns how to apply his first patch</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/17/freebsd-challenge-day-16-30/" target="_blank" rel="nofollow noopener">day 16</a>, he dives into the world of <a href="http://www.bsdnow.tv/tutorials/jails" target="_blank" rel="nofollow noopener">FreeBSD jails</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1962" target="_blank" rel="nofollow noopener">BSD books in 2014</a></h3>

<ul>
<li>BSD books are some of the highest quality technical writings available, and MWL has written a good number of them</li>
<li>In this post, he details some of his plans for 2014</li>
<li>In includes at least one OpenBSD book, at least one FreeBSD book and...</li>
<li>Very strong possibility of Absolute FreeBSD 3rd edition (watch <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">our interview with him</a>)</li>
<li>Check the link for all the details
***</li>
</ul>

<h3><a href="http://www.daemonology.net/blog/2014-02-16-FreeBSD-EC2-build.html" target="_blank" rel="nofollow noopener">How to build FreeBSD/EC2 images</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" target="_blank" rel="nofollow noopener">Colin Percival</a> details how to build EC2 images in a new blog post</li>
<li>Most people just use the images he makes on their instances, but some people will want to make their own <a href="https://svnweb.freebsd.org/base/user/cperciva/EC2-build/" target="_blank" rel="nofollow noopener">from scratch</a></li>
<li>You build a regular disk image and then turn it into an AMI</li>
<li>It requires a couple ports be installed on your system, but the whole process is pretty straightforward
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-17/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>This time around we discuss how you can become a developer</li>
<li>Kris also details the length of supported releases</li>
<li>Expect lots of new features in 10.1
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216xJoCVG" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2gLrR3VVf" target="_blank" rel="nofollow noopener">Jake writes in</a></li>
<li><a href="http://slexy.org/view/s21gfG3Iho" target="_blank" rel="nofollow noopener">Niclas writes in</a></li>
<li><a href="http://slexy.org/view/s2JNyw5BCn" target="_blank" rel="nofollow noopener">Steffan writes in</a></li>
<li><a href="http://slexy.org/view/s2kg3zoRfm" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2ZwSIfRjm" target="_blank" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We have a packed show for you this week! We'll sit down for an interview with Chris Buechler, from the pfSense project, to learn just how easy it can be to deploy a BSD firewall. We'll also be showing you a walkthrough of the pfSense interface so you can get an idea of just how convenient and powerful it is. Answers to your questions and the latest headlines, here on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/calendar/call-for-papers/" target="_blank" rel="nofollow noopener">EuroBSDCon and AsiaBSDCon</a></h3>

<ul>
<li>This year, EuroBSDCon will be in September in Sofia, Bulgaria</li>
<li>They've got a call for papers up now, so everyone can submit the talks they want to present</li>
<li>There will also be a tutorial section of the conference</li>
<li><a href="http://2014.asiabsdcon.org/timetable.html.en" target="_blank" rel="nofollow noopener">AsiaBSDCon</a> will be next month, in March!</li>
<li>All the info about the registration, tutorials, hotels, timetable and location have been posted</li>
<li>Check the link for all the details on the talks - if you plan on going to Tokyo next month, hang out with Allan and Kris and lots of BSD developers!
***</li>
</ul>

<h3><a href="http://rtfm.net/FreeBSD/ERL/" target="_blank" rel="nofollow noopener">FreeBSD 10 on Ubiquiti EdgeRouter Lite</a></h3>

<ul>
<li>The Ubiquiti EdgeRouter Lite is a router that costs less than $100 and has a MIPS CPU</li>
<li>This article goes through the process of installing and configuring FreeBSD on it to use as a home router</li>
<li>Lots of good pictures of the hardware and specific details needed to get you set up</li>
<li>It also includes the scripts to create your own images if you don't want to use the ones rolled by someone else</li>
<li>For such a cheap price, might be a really fun weekend project to replace your shitty consumer router</li>
<li>Of course if you're more of an OpenBSD guy, you can always see <a href="http://www.bsdnow.tv/tutorials/openbsd-router" target="_blank" rel="nofollow noopener">our tutorial</a> for that too
***</li>
</ul>

<h3><a href="http://blog.saveosx.org/signed-packages/" target="_blank" rel="nofollow noopener">Signed pkgsrc package guide</a></h3>

<ul>
<li>We got a request on IRC for more pkgsrc stuff on the show, and a listener provided a nice write-up</li>
<li>It shows you how to set up signed packages with pkgsrc, which works on quite a few OSes (not just NetBSD)</li>
<li>He goes through the process of signing packages with a public key and how to verify the packages when you install them</li>
<li>The author also happens to be an EdgeBSD developer
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140212083627" target="_blank" rel="nofollow noopener">Big batch of OpenBSD hackathon reports</a></h3>

<ul>
<li>Five trip reports from the OpenBSD hackathon in New Zealand! In the first one, jmatthew details his work on fiber channel controller drivers, some octeon USB work and ARM fixes for AHCI</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140213065843" target="_blank" rel="nofollow noopener">the second</a>, ketennis gets into his work with running interrupt handlers without holding the kernel lock, some SPARC64 improvements and a few other things</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140213173808" target="_blank" rel="nofollow noopener">the third</a>, jsg updated libdrm and mesa and did various work on xenocara</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140214070023" target="_blank" rel="nofollow noopener">the fourth</a>, dlg came with the intention to improve SMP support, but got distracted and did SCSI stuff instead - but he talks a little bit about the struggle OpenBSD has with SMP and some of the work he's done</li>
<li>In <a href="http://undeadly.org/cgi?action=article&amp;sid=20140214130039" target="_blank" rel="nofollow noopener">the fifth</a>, claudio talks about some stuff he did for routing tables and misc. other things
***</li>
</ul>

<h2>Interview - Chris Buechler - <a href="mailto:cmb@pfsense.com" target="_blank" rel="nofollow noopener">cmb@pfsense.com</a> / <a href="https://twitter.com/cbuechler" target="_blank" rel="nofollow noopener">@cbuechler</a></h2>

<p>pfSense</p>

<hr>

<h2>Tutorial</h2>

<h3>pfSense walkthrough</h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.thelinuxcauldron.com/2014/02/13/freebsd-challenge-day-13-30/" target="_blank" rel="nofollow noopener">FreeBSD challenge continues</a></h3>

<ul>
<li>Our buddy from the Linux foundation continues his switching to BSD journey</li>
<li>In day 13, he covers some tips for new users, mentions trying things out in a VM first</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-14-30/" target="_blank" rel="nofollow noopener">day 14</a>, he starts setting up XFCE and X11, feels like he's starting over as a new Linux user learning the ropes again - concludes that ports are the way to go</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/14/freebsd-challenge-day-15-30/" target="_blank" rel="nofollow noopener">day 15</a>, he finishes up his XFCE configuration and details different versions of ports with different names, as well as learns how to apply his first patch</li>
<li>In <a href="http://www.thelinuxcauldron.com/2014/02/17/freebsd-challenge-day-16-30/" target="_blank" rel="nofollow noopener">day 16</a>, he dives into the world of <a href="http://www.bsdnow.tv/tutorials/jails" target="_blank" rel="nofollow noopener">FreeBSD jails</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1962" target="_blank" rel="nofollow noopener">BSD books in 2014</a></h3>

<ul>
<li>BSD books are some of the highest quality technical writings available, and MWL has written a good number of them</li>
<li>In this post, he details some of his plans for 2014</li>
<li>In includes at least one OpenBSD book, at least one FreeBSD book and...</li>
<li>Very strong possibility of Absolute FreeBSD 3rd edition (watch <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">our interview with him</a>)</li>
<li>Check the link for all the details
***</li>
</ul>

<h3><a href="http://www.daemonology.net/blog/2014-02-16-FreeBSD-EC2-build.html" target="_blank" rel="nofollow noopener">How to build FreeBSD/EC2 images</a></h3>

<ul>
<li>Our friend <a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" target="_blank" rel="nofollow noopener">Colin Percival</a> details how to build EC2 images in a new blog post</li>
<li>Most people just use the images he makes on their instances, but some people will want to make their own <a href="https://svnweb.freebsd.org/base/user/cperciva/EC2-build/" target="_blank" rel="nofollow noopener">from scratch</a></li>
<li>You build a regular disk image and then turn it into an AMI</li>
<li>It requires a couple ports be installed on your system, but the whole process is pretty straightforward
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/02/pc-bsd-weekly-feature-digest-17/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>This time around we discuss how you can become a developer</li>
<li>Kris also details the length of supported releases</li>
<li>Expect lots of new features in 10.1
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216xJoCVG" target="_blank" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2gLrR3VVf" target="_blank" rel="nofollow noopener">Jake writes in</a></li>
<li><a href="http://slexy.org/view/s21gfG3Iho" target="_blank" rel="nofollow noopener">Niclas writes in</a></li>
<li><a href="http://slexy.org/view/s2JNyw5BCn" target="_blank" rel="nofollow noopener">Steffan writes in</a></li>
<li><a href="http://slexy.org/view/s2kg3zoRfm" target="_blank" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2ZwSIfRjm" target="_blank" rel="nofollow noopener">Chris writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>21: Tendresse for Ten</title>
  <link>https://www.bsdnow.tv/21</link>
  <guid isPermaLink="false">353e6a60-9bd0-494f-ac34-4337e3dfa734</guid>
  <pubDate>Wed, 22 Jan 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/353e6a60-9bd0-494f-ac34-4337e3dfa734.mp3" length="77103576" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:47:05</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.0R/announce.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD 10.0-RELEASE is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The long awaited, giant release of FreeBSD is now official and &lt;a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" target="_blank" rel="nofollow noopener"&gt;ready to be downloaded&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One of the biggest releases in FreeBSD history, with tons of new updates&lt;/li&gt;
&lt;li&gt;Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... &lt;a href="https://www.freebsd.org/releases/10.0R/relnotes.html" target="_blank" rel="nofollow noopener"&gt;the list goes on and on&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Start up your freebsd-update or do a source-based upgrade
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" target="_blank" rel="nofollow noopener"&gt;OpenSSH 6.5 CFT&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener"&gt;Damien Miller&lt;/a&gt; announced a Call For Testing for OpenSSH 6.5&lt;/li&gt;
&lt;li&gt;Huge, huge release, focused on new features rather than bugfixes (but it includes those too)&lt;/li&gt;
&lt;li&gt;New ciphers, new key formats, new config options, see the mailing list for all the details&lt;/li&gt;
&lt;li&gt;Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" target="_blank" rel="nofollow noopener"&gt;DIY NAS story, FreeNAS 9.2.1-BETA&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another new blog post about FreeNAS!&lt;/li&gt;
&lt;li&gt;Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014&lt;/li&gt;
&lt;li&gt;"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"&lt;/li&gt;
&lt;li&gt;Really long article with lots of nice details about his setup, why you might want a NAS, etc.&lt;/li&gt;
&lt;li&gt;Speaking of FreeNAS, they released &lt;a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" target="_blank" rel="nofollow noopener"&gt;9.2.1-BETA&lt;/a&gt; with lots of bugfixes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://news.ycombinator.com/item?id=7069889" target="_blank" rel="nofollow noopener"&gt;OpenBSD needed funding for electricity.. and they got it&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Briefly mentioned at the end of last week's show, but has blown up over the internet since&lt;/li&gt;
&lt;li&gt;OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments&lt;/li&gt;
&lt;li&gt;They needed about $20,000 to cover electric costs for the &lt;a href="http://www.openbsd.org/images/rack2009.jpg" target="_blank" rel="nofollow noopener"&gt;server rack in Theo's basement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of positive reaction from the community helping out so far, and it appears they have &lt;a href="http://www.openbsdfoundation.org/campaign2104.html" target="_blank" rel="nofollow noopener"&gt;reached their goal&lt;/a&gt; and got $100,000 in donations&lt;/li&gt;
&lt;li&gt;From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"&lt;/li&gt;
&lt;li&gt;This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Colin Percival - &lt;a href="mailto:cperciva@freebsd.org" target="_blank" rel="nofollow noopener"&gt;cperciva@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/cperciva" target="_blank" rel="nofollow noopener"&gt;@cperciva&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD &lt;a href="http://www.daemonology.net/freebsd-on-ec2/" target="_blank" rel="nofollow noopener"&gt;on Amazon EC2&lt;/a&gt;, backups with &lt;a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;, 10.0-RELEASE, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" target="_blank" rel="nofollow noopener"&gt;Bandwidth monitoring and testing&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1176" target="_blank" rel="nofollow noopener"&gt;pfSense talk at Tokyo FreeBSD Benkyoukai&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"&lt;/li&gt;
&lt;li&gt;He's also going to be looking for help to translate the pfSense documentation into Japanese&lt;/li&gt;
&lt;li&gt;The event is on February 17, 2014 if you're in the Tokyo area
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://m0n0.ch/wall/downloads.php" target="_blank" rel="nofollow noopener"&gt;m0n0wall 1.8.1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications&lt;/li&gt;
&lt;li&gt;pfSense was forked from it in 2004, and has a lot more active development now&lt;/li&gt;
&lt;li&gt;They switched to FreeBSD 8.4 for this new version&lt;/li&gt;
&lt;li&gt;Full list of updates in the changelog&lt;/li&gt;
&lt;li&gt;This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/1933" target="_blank" rel="nofollow noopener"&gt;Ansible and PF, plus NTP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another blog post from our buddy &lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener"&gt;Michael Lucas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;There've been some NTP amplification attacks &lt;a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" target="_blank" rel="nofollow noopener"&gt;recently&lt;/a&gt; in the news&lt;/li&gt;
&lt;li&gt;The post describes how he configured ntpd on a lot of servers without a lot of work&lt;/li&gt;
&lt;li&gt;He leverages pf and ansible for the configuration&lt;/li&gt;
&lt;li&gt;OpenNTPD is, not surprisingly, unaffected - use it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140115054839" target="_blank" rel="nofollow noopener"&gt;ruBSD videos online&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Just a quick followup from a few weeks ago&lt;/li&gt;
&lt;li&gt;Theo and Henning's talks from ruBSD are now available for download&lt;/li&gt;
&lt;li&gt;There's also a nice interview with Theo
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;10.0-RC4 images are available&lt;/li&gt;
&lt;li&gt;Wine PBI is now available for 10&lt;/li&gt;
&lt;li&gt;9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2WQXwMASZ" target="_blank" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2H0FURAtZ" target="_blank" rel="nofollow noopener"&gt;Kjell-Aleksander writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21eKKPgqh" target="_blank" rel="nofollow noopener"&gt;Mike writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21UMLnV0G" target="_blank" rel="nofollow noopener"&gt;Charlie writes in (and gets a reply)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2SuazcfoR" target="_blank" rel="nofollow noopener"&gt;Kevin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ec2, colin percival, cperciva, amazon, cloud, aws, instance, vm, virtual machine, xen, hypervisor, generic, 10.0, in the cloud, custom kernel, tarsnap, backup, backups, encrypted, dropbox, offsite, off site, crashplan, vnstat, iperf, performance, network, sysctl, throughput, speed, download, upload, check, test, freenas, m0n0wall, pfsense, zfs, vfs, tokyo, benkyokai, benkyoukai, ansible, nas, freenas, pf, ntp, openntpd, vulnerability, ntpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/10.0R/announce.html" target="_blank" rel="nofollow noopener">FreeBSD 10.0-RELEASE is out</a></h3>

<ul>
<li>The long awaited, giant release of FreeBSD is now official and <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" target="_blank" rel="nofollow noopener">ready to be downloaded</a></li>
<li>One of the biggest releases in FreeBSD history, with tons of new updates</li>
<li>Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... <a href="https://www.freebsd.org/releases/10.0R/relnotes.html" target="_blank" rel="nofollow noopener">the list goes on and on</a></li>
<li>Start up your freebsd-update or do a source-based upgrade
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" target="_blank" rel="nofollow noopener">OpenSSH 6.5 CFT</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">Damien Miller</a> announced a Call For Testing for OpenSSH 6.5</li>
<li>Huge, huge release, focused on new features rather than bugfixes (but it includes those too)</li>
<li>New ciphers, new key formats, new config options, see the mailing list for all the details</li>
<li>Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" target="_blank" rel="nofollow noopener">DIY NAS story, FreeNAS 9.2.1-BETA</a></h3>

<ul>
<li>Another new blog post about FreeNAS!</li>
<li>Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014</li>
<li>"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"</li>
<li>Really long article with lots of nice details about his setup, why you might want a NAS, etc.</li>
<li>Speaking of FreeNAS, they released <a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" target="_blank" rel="nofollow noopener">9.2.1-BETA</a> with lots of bugfixes
***</li>
</ul>

<h3><a href="https://news.ycombinator.com/item?id=7069889" target="_blank" rel="nofollow noopener">OpenBSD needed funding for electricity.. and they got it</a></h3>

<ul>
<li>Briefly mentioned at the end of last week's show, but has blown up over the internet since</li>
<li>OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments</li>
<li>They needed about $20,000 to cover electric costs for the <a href="http://www.openbsd.org/images/rack2009.jpg" target="_blank" rel="nofollow noopener">server rack in Theo's basement</a></li>
<li>Lots of positive reaction from the community helping out so far, and it appears they have <a href="http://www.openbsdfoundation.org/campaign2104.html" target="_blank" rel="nofollow noopener">reached their goal</a> and got $100,000 in donations</li>
<li>From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"</li>
<li>This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***</li>
</ul>

<h2>Interview - Colin Percival - <a href="mailto:cperciva@freebsd.org" target="_blank" rel="nofollow noopener">cperciva@freebsd.org</a> / <a href="https://twitter.com/cperciva" target="_blank" rel="nofollow noopener">@cperciva</a></h2>

<p>FreeBSD <a href="http://www.daemonology.net/freebsd-on-ec2/" target="_blank" rel="nofollow noopener">on Amazon EC2</a>, backups with <a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener">Tarsnap</a>, 10.0-RELEASE, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" target="_blank" rel="nofollow noopener">Bandwidth monitoring and testing</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blog.pfsense.org/?p=1176" target="_blank" rel="nofollow noopener">pfSense talk at Tokyo FreeBSD Benkyoukai</a></h3>

<ul>
<li>Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"</li>
<li>He's also going to be looking for help to translate the pfSense documentation into Japanese</li>
<li>The event is on February 17, 2014 if you're in the Tokyo area
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/downloads.php" target="_blank" rel="nofollow noopener">m0n0wall 1.8.1 released</a></h3>

<ul>
<li>For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications</li>
<li>pfSense was forked from it in 2004, and has a lot more active development now</li>
<li>They switched to FreeBSD 8.4 for this new version</li>
<li>Full list of updates in the changelog</li>
<li>This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1933" target="_blank" rel="nofollow noopener">Ansible and PF, plus NTP</a></h3>

<ul>
<li>Another blog post from our buddy <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael Lucas</a></li>
<li>There've been some NTP amplification attacks <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" target="_blank" rel="nofollow noopener">recently</a> in the news</li>
<li>The post describes how he configured ntpd on a lot of servers without a lot of work</li>
<li>He leverages pf and ansible for the configuration</li>
<li>OpenNTPD is, not surprisingly, unaffected - use it
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140115054839" target="_blank" rel="nofollow noopener">ruBSD videos online</a></h3>

<ul>
<li>Just a quick followup from a few weeks ago</li>
<li>Theo and Henning's talks from ruBSD are now available for download</li>
<li>There's also a nice interview with Theo
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0-RC4 images are available</li>
<li>Wine PBI is now available for 10</li>
<li>9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2WQXwMASZ" target="_blank" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2H0FURAtZ" target="_blank" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s21eKKPgqh" target="_blank" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s21UMLnV0G" target="_blank" rel="nofollow noopener">Charlie writes in (and gets a reply)</a></li>
<li><a href="http://slexy.org/view/s2SuazcfoR" target="_blank" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/10.0R/announce.html" target="_blank" rel="nofollow noopener">FreeBSD 10.0-RELEASE is out</a></h3>

<ul>
<li>The long awaited, giant release of FreeBSD is now official and <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" target="_blank" rel="nofollow noopener">ready to be downloaded</a></li>
<li>One of the biggest releases in FreeBSD history, with tons of new updates</li>
<li>Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... <a href="https://www.freebsd.org/releases/10.0R/relnotes.html" target="_blank" rel="nofollow noopener">the list goes on and on</a></li>
<li>Start up your freebsd-update or do a source-based upgrade
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" target="_blank" rel="nofollow noopener">OpenSSH 6.5 CFT</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">Damien Miller</a> announced a Call For Testing for OpenSSH 6.5</li>
<li>Huge, huge release, focused on new features rather than bugfixes (but it includes those too)</li>
<li>New ciphers, new key formats, new config options, see the mailing list for all the details</li>
<li>Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" target="_blank" rel="nofollow noopener">DIY NAS story, FreeNAS 9.2.1-BETA</a></h3>

<ul>
<li>Another new blog post about FreeNAS!</li>
<li>Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014</li>
<li>"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"</li>
<li>Really long article with lots of nice details about his setup, why you might want a NAS, etc.</li>
<li>Speaking of FreeNAS, they released <a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" target="_blank" rel="nofollow noopener">9.2.1-BETA</a> with lots of bugfixes
***</li>
</ul>

<h3><a href="https://news.ycombinator.com/item?id=7069889" target="_blank" rel="nofollow noopener">OpenBSD needed funding for electricity.. and they got it</a></h3>

<ul>
<li>Briefly mentioned at the end of last week's show, but has blown up over the internet since</li>
<li>OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments</li>
<li>They needed about $20,000 to cover electric costs for the <a href="http://www.openbsd.org/images/rack2009.jpg" target="_blank" rel="nofollow noopener">server rack in Theo's basement</a></li>
<li>Lots of positive reaction from the community helping out so far, and it appears they have <a href="http://www.openbsdfoundation.org/campaign2104.html" target="_blank" rel="nofollow noopener">reached their goal</a> and got $100,000 in donations</li>
<li>From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"</li>
<li>This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***</li>
</ul>

<h2>Interview - Colin Percival - <a href="mailto:cperciva@freebsd.org" target="_blank" rel="nofollow noopener">cperciva@freebsd.org</a> / <a href="https://twitter.com/cperciva" target="_blank" rel="nofollow noopener">@cperciva</a></h2>

<p>FreeBSD <a href="http://www.daemonology.net/freebsd-on-ec2/" target="_blank" rel="nofollow noopener">on Amazon EC2</a>, backups with <a href="https://www.tarsnap.com/" target="_blank" rel="nofollow noopener">Tarsnap</a>, 10.0-RELEASE, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" target="_blank" rel="nofollow noopener">Bandwidth monitoring and testing</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blog.pfsense.org/?p=1176" target="_blank" rel="nofollow noopener">pfSense talk at Tokyo FreeBSD Benkyoukai</a></h3>

<ul>
<li>Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"</li>
<li>He's also going to be looking for help to translate the pfSense documentation into Japanese</li>
<li>The event is on February 17, 2014 if you're in the Tokyo area
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/downloads.php" target="_blank" rel="nofollow noopener">m0n0wall 1.8.1 released</a></h3>

<ul>
<li>For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications</li>
<li>pfSense was forked from it in 2004, and has a lot more active development now</li>
<li>They switched to FreeBSD 8.4 for this new version</li>
<li>Full list of updates in the changelog</li>
<li>This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1933" target="_blank" rel="nofollow noopener">Ansible and PF, plus NTP</a></h3>

<ul>
<li>Another blog post from our buddy <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" target="_blank" rel="nofollow noopener">Michael Lucas</a></li>
<li>There've been some NTP amplification attacks <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" target="_blank" rel="nofollow noopener">recently</a> in the news</li>
<li>The post describes how he configured ntpd on a lot of servers without a lot of work</li>
<li>He leverages pf and ansible for the configuration</li>
<li>OpenNTPD is, not surprisingly, unaffected - use it
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140115054839" target="_blank" rel="nofollow noopener">ruBSD videos online</a></h3>

<ul>
<li>Just a quick followup from a few weeks ago</li>
<li>Theo and Henning's talks from ruBSD are now available for download</li>
<li>There's also a nice interview with Theo
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" target="_blank" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0-RC4 images are available</li>
<li>Wine PBI is now available for 10</li>
<li>9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2WQXwMASZ" target="_blank" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2H0FURAtZ" target="_blank" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s21eKKPgqh" target="_blank" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s21UMLnV0G" target="_blank" rel="nofollow noopener">Charlie writes in (and gets a reply)</a></li>
<li><a href="http://slexy.org/view/s2SuazcfoR" target="_blank" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>18: Eclipsing Binaries</title>
  <link>https://www.bsdnow.tv/18</link>
  <guid isPermaLink="false">96a80a26-313b-4891-a505-fa71245e4e84</guid>
  <pubDate>Wed, 01 Jan 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/96a80a26-313b-4891-a505-fa71245e4e84.mp3" length="50662433" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Put away the Christmas trees and update your ports trees! We're back with the first show of 2014, and we've got some catching up to do. This time on the show, we have an interview with Baptiste Daroussin about the future of FreeBSD binary packages. Following that, we'll be highlighting a cool script to do binary upgrades on OpenBSD. Lots of holiday news and listener feedback, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:10:21</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Put away the Christmas trees and update your ports trees! We're back with the first show of 2014, and we've got some catching up to do. This time on the show, we have an interview with Baptiste Daroussin about the future of FreeBSD binary packages. Following that, we'll be highlighting a cool script to do binary upgrades on OpenBSD. Lots of holiday news and listener feedback, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-shteryana-shopova.html" target="_blank" rel="nofollow noopener"&gt;Faces of FreeBSD continues&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our first one details Shteryana Shopova, the local organizer for EuroBSDCon 2014 in Sophia&lt;/li&gt;
&lt;li&gt;Gives some information about how she got into BSD&lt;/li&gt;
&lt;li&gt;"I installed FreeBSD on my laptop, alongside the Windows and Slackware Linux I was running on it at the time. Several months later I realized that apart from FreeBSD, I hadn't booted the other two operating systems in months. So I wiped them out."&lt;/li&gt;
&lt;li&gt;She wrote bsnmpd and extended it with the help of a grant from the FreeBSD Foundation&lt;/li&gt;
&lt;li&gt;We've also got one for &lt;a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-kevin-martin.html" target="_blank" rel="nofollow noopener"&gt;Kevin Martin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Started off with a pinball website, ended up learning about FreeBSD from an ISP and starting his own hosting company&lt;/li&gt;
&lt;li&gt;"FreeBSD has been an asset to our operations, and while we have branched out a bit, we still primarily use FreeBSD and promote it whenever possible.  FreeBSD is a terrific technology with a terrific community."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.shiningsilence.com/dbsdlog/2013/12/19/13008.html" target="_blank" rel="nofollow noopener"&gt;OpenPF?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A blog post over at the &lt;a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" target="_blank" rel="nofollow noopener"&gt;Dragonfly digest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;What if we had some cross platform development of OpenBSD's firewall?&lt;/li&gt;
&lt;li&gt;Similar to portable &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener"&gt;OpenSSH&lt;/a&gt; or &lt;a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" target="_blank" rel="nofollow noopener"&gt;OpenZFS&lt;/a&gt;, there could be a centrally-developed version with compatibility glue&lt;/li&gt;
&lt;li&gt;Right now FreeBSD 9's pf is old, FreeBSD 10's pf is old (but has the best performance of any implementation due to custom patches), NetBSD's pf is old (but they're working on a fork) and Dragonfly's pf is old&lt;/li&gt;
&lt;li&gt;Further complicated by the fact that PF itself doesn’t have a version number, since it was designed to just be ‘the pf that came with OpenBSD 5.4’&lt;/li&gt;
&lt;li&gt;Not likely to happen any time soon, but it's good food for thought
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mxey.net/the-year-of-freebsd-on-the-server/" target="_blank" rel="nofollow noopener"&gt;Year of BSD on the server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A good blog post about switching servers from Linux to BSD&lt;/li&gt;
&lt;li&gt;2014 is going to be the year of a lot of switching, due to FreeBSD 10's amazing new features&lt;/li&gt;
&lt;li&gt;This author was particularly taken with &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener"&gt;pkgng&lt;/a&gt; and the more coherent layout of BSD systems&lt;/li&gt;
&lt;li&gt;Similarly, there was also a recent &lt;a href="http://www.reddit.com/r/BSD/comments/1tdrz1/why_did_you_choose_bsd_over_linux/" target="_blank" rel="nofollow noopener"&gt;reddit thread&lt;/a&gt;, "Why did you choose BSD over Linux?"&lt;/li&gt;
&lt;li&gt;Both are excellent reads for Linux users that are thinking about making the switch, send 'em to your friends
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2013/12/24/getting-to-know-your-portmgr-bryan-drewery/" target="_blank" rel="nofollow noopener"&gt;Getting to know your portmgr&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This time in the series they interview Bryan Drewery, a fairly new addition to the team&lt;/li&gt;
&lt;li&gt;He started maintaining portupgrade and portmaster, and eventually ended up on the ports management team&lt;/li&gt;
&lt;li&gt;Believe it or not, his wife actually had a lot to do with him getting into FreeBSD full-time&lt;/li&gt;
&lt;li&gt;Lots of fun trivia and background about him&lt;/li&gt;
&lt;li&gt;Speaking of portmgr, our interview for today is...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Baptiste Daroussin - &lt;a href="mailto:bapt@freebsd.org" target="_blank" rel="nofollow noopener"&gt;bapt@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The future of FreeBSD's &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener"&gt;binary packages&lt;/a&gt;, ports' features, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=aD-2e9u3tug" target="_blank" rel="nofollow noopener"&gt;pfSense december hang out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Interview/presentation from pfSense developer Chris Buechler with an &lt;a href="http://blog.pfsense.org/?p=1146" target="_blank" rel="nofollow noopener"&gt;accompanying blog post&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;"This is the first in what will be a monthly recurring series. Each month, we’ll have a how to tutorial on a specific topic or area of the system, and updates on development and other happenings with the project. We have several topics in mind, but also welcome community suggestions on topics"&lt;/li&gt;
&lt;li&gt;Speaking of pfSense, they recently opened an &lt;a href="http://blog.pfsense.org/?p=1156" target="_blank" rel="nofollow noopener"&gt;online store&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;We're planning on having a pfSense episode next month!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdmag.org/magazine/1854-carp-on-freebsd-how-to-use-devd-to-take-action-on-kernel-events" target="_blank" rel="nofollow noopener"&gt;BSDMag December issue is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The free monthly BSD magazine gets a new release for December&lt;/li&gt;
&lt;li&gt;Topics include CARP on FreeBSD, more BSD programming, "unix basics for security professionals," some kernel introductions, using OpenBSD as a transparent proxy with relayd, GhostBSD overview and some stuff about SSH
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20131217081921" target="_blank" rel="nofollow noopener"&gt;OpenBSD gets tmpfs&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In addition to the recently-added FUSE support, OpenBSD now has tmpfs&lt;/li&gt;
&lt;li&gt;To get more testing, it was enabled by default in -current&lt;/li&gt;
&lt;li&gt;Should make its way into 5.5 if everything goes according to plan&lt;/li&gt;
&lt;li&gt;Enables lots of new possibilities, like our &lt;a href="http://www.bsdnow.tv/tutorials/ccache" target="_blank" rel="nofollow noopener"&gt;ccache and tmpfs guide&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-122013/" target="_blank" rel="nofollow noopener"&gt;PCBSD weekly digests&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Catching up with all the work going on in PCBSD land..&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.pcbsd.org/2013/12/weekly-feature-digest-122713/" target="_blank" rel="nofollow noopener"&gt;10.0-RC2 is now available&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The big pkgng 1.2 problems seem to have been worked out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2UrUzlnf6" target="_blank" rel="nofollow noopener"&gt;Remy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iqnywwKX" target="_blank" rel="nofollow noopener"&gt;Jason writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2IUcPySbh" target="_blank" rel="nofollow noopener"&gt;Rob writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21aYlbXz2" target="_blank" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21vrYSqU8" target="_blank" rel="nofollow noopener"&gt;Stuart writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, binary, upgrade, update, openbsd-binary-upgrade, freebsd-update, patches, signed, bapt, portmgr, ports, binary star, packages, pkgng, tmpfs, pkg_add, pf, firewall, pfsense, hangout, switching from linux to bsd, linux bsd differences, bsdmag</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Put away the Christmas trees and update your ports trees! We're back with the first show of 2014, and we've got some catching up to do. This time on the show, we have an interview with Baptiste Daroussin about the future of FreeBSD binary packages. Following that, we'll be highlighting a cool script to do binary upgrades on OpenBSD. Lots of holiday news and listener feedback, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-shteryana-shopova.html" target="_blank" rel="nofollow noopener">Faces of FreeBSD continues</a></h3>

<ul>
<li>Our first one details Shteryana Shopova, the local organizer for EuroBSDCon 2014 in Sophia</li>
<li>Gives some information about how she got into BSD</li>
<li>"I installed FreeBSD on my laptop, alongside the Windows and Slackware Linux I was running on it at the time. Several months later I realized that apart from FreeBSD, I hadn't booted the other two operating systems in months. So I wiped them out."</li>
<li>She wrote bsnmpd and extended it with the help of a grant from the FreeBSD Foundation</li>
<li>We've also got one for <a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-kevin-martin.html" target="_blank" rel="nofollow noopener">Kevin Martin</a></li>
<li>Started off with a pinball website, ended up learning about FreeBSD from an ISP and starting his own hosting company</li>
<li>"FreeBSD has been an asset to our operations, and while we have branched out a bit, we still primarily use FreeBSD and promote it whenever possible.  FreeBSD is a terrific technology with a terrific community."
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2013/12/19/13008.html" target="_blank" rel="nofollow noopener">OpenPF?</a></h3>

<ul>
<li>A blog post over at the <a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" target="_blank" rel="nofollow noopener">Dragonfly digest</a></li>
<li>What if we had some cross platform development of OpenBSD's firewall?</li>
<li>Similar to portable <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">OpenSSH</a> or <a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" target="_blank" rel="nofollow noopener">OpenZFS</a>, there could be a centrally-developed version with compatibility glue</li>
<li>Right now FreeBSD 9's pf is old, FreeBSD 10's pf is old (but has the best performance of any implementation due to custom patches), NetBSD's pf is old (but they're working on a fork) and Dragonfly's pf is old</li>
<li>Further complicated by the fact that PF itself doesn’t have a version number, since it was designed to just be ‘the pf that came with OpenBSD 5.4’</li>
<li>Not likely to happen any time soon, but it's good food for thought
***</li>
</ul>

<h3><a href="http://mxey.net/the-year-of-freebsd-on-the-server/" target="_blank" rel="nofollow noopener">Year of BSD on the server</a></h3>

<ul>
<li>A good blog post about switching servers from Linux to BSD</li>
<li>2014 is going to be the year of a lot of switching, due to FreeBSD 10's amazing new features</li>
<li>This author was particularly taken with <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">pkgng</a> and the more coherent layout of BSD systems</li>
<li>Similarly, there was also a recent <a href="http://www.reddit.com/r/BSD/comments/1tdrz1/why_did_you_choose_bsd_over_linux/" target="_blank" rel="nofollow noopener">reddit thread</a>, "Why did you choose BSD over Linux?"</li>
<li>Both are excellent reads for Linux users that are thinking about making the switch, send 'em to your friends
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/12/24/getting-to-know-your-portmgr-bryan-drewery/" target="_blank" rel="nofollow noopener">Getting to know your portmgr</a></h3>

<ul>
<li>This time in the series they interview Bryan Drewery, a fairly new addition to the team</li>
<li>He started maintaining portupgrade and portmaster, and eventually ended up on the ports management team</li>
<li>Believe it or not, his wife actually had a lot to do with him getting into FreeBSD full-time</li>
<li>Lots of fun trivia and background about him</li>
<li>Speaking of portmgr, our interview for today is...
***</li>
</ul>

<h2>Interview - Baptiste Daroussin - <a href="mailto:bapt@freebsd.org" target="_blank" rel="nofollow noopener">bapt@freebsd.org</a></h2>

<p>The future of FreeBSD's <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">binary packages</a>, ports' features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.youtube.com/watch?v=aD-2e9u3tug" target="_blank" rel="nofollow noopener">pfSense december hang out</a></h3>

<ul>
<li>Interview/presentation from pfSense developer Chris Buechler with an <a href="http://blog.pfsense.org/?p=1146" target="_blank" rel="nofollow noopener">accompanying blog post</a></li>
<li>"This is the first in what will be a monthly recurring series. Each month, we’ll have a how to tutorial on a specific topic or area of the system, and updates on development and other happenings with the project. We have several topics in mind, but also welcome community suggestions on topics"</li>
<li>Speaking of pfSense, they recently opened an <a href="http://blog.pfsense.org/?p=1156" target="_blank" rel="nofollow noopener">online store</a></li>
<li>We're planning on having a pfSense episode next month!
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1854-carp-on-freebsd-how-to-use-devd-to-take-action-on-kernel-events" target="_blank" rel="nofollow noopener">BSDMag December issue is out</a></h3>

<ul>
<li>The free monthly BSD magazine gets a new release for December</li>
<li>Topics include CARP on FreeBSD, more BSD programming, "unix basics for security professionals," some kernel introductions, using OpenBSD as a transparent proxy with relayd, GhostBSD overview and some stuff about SSH
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131217081921" target="_blank" rel="nofollow noopener">OpenBSD gets tmpfs</a></h3>

<ul>
<li>In addition to the recently-added FUSE support, OpenBSD now has tmpfs</li>
<li>To get more testing, it was enabled by default in -current</li>
<li>Should make its way into 5.5 if everything goes according to plan</li>
<li>Enables lots of new possibilities, like our <a href="http://www.bsdnow.tv/tutorials/ccache" target="_blank" rel="nofollow noopener">ccache and tmpfs guide</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-122013/" target="_blank" rel="nofollow noopener">PCBSD weekly digests</a></h3>

<ul>
<li>Catching up with all the work going on in PCBSD land..</li>
<li><a href="http://blog.pcbsd.org/2013/12/weekly-feature-digest-122713/" target="_blank" rel="nofollow noopener">10.0-RC2 is now available</a></li>
<li>The big pkgng 1.2 problems seem to have been worked out
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UrUzlnf6" target="_blank" rel="nofollow noopener">Remy writes in</a></li>
<li><a href="http://slexy.org/view/s2iqnywwKX" target="_blank" rel="nofollow noopener">Jason writes in</a></li>
<li><a href="http://slexy.org/view/s2IUcPySbh" target="_blank" rel="nofollow noopener">Rob writes in</a></li>
<li><a href="http://slexy.org/view/s21aYlbXz2" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s21vrYSqU8" target="_blank" rel="nofollow noopener">Stuart writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Put away the Christmas trees and update your ports trees! We're back with the first show of 2014, and we've got some catching up to do. This time on the show, we have an interview with Baptiste Daroussin about the future of FreeBSD binary packages. Following that, we'll be highlighting a cool script to do binary upgrades on OpenBSD. Lots of holiday news and listener feedback, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-shteryana-shopova.html" target="_blank" rel="nofollow noopener">Faces of FreeBSD continues</a></h3>

<ul>
<li>Our first one details Shteryana Shopova, the local organizer for EuroBSDCon 2014 in Sophia</li>
<li>Gives some information about how she got into BSD</li>
<li>"I installed FreeBSD on my laptop, alongside the Windows and Slackware Linux I was running on it at the time. Several months later I realized that apart from FreeBSD, I hadn't booted the other two operating systems in months. So I wiped them out."</li>
<li>She wrote bsnmpd and extended it with the help of a grant from the FreeBSD Foundation</li>
<li>We've also got one for <a href="http://freebsdfoundation.blogspot.com/2013/12/faces-of-freebsd-kevin-martin.html" target="_blank" rel="nofollow noopener">Kevin Martin</a></li>
<li>Started off with a pinball website, ended up learning about FreeBSD from an ISP and starting his own hosting company</li>
<li>"FreeBSD has been an asset to our operations, and while we have branched out a bit, we still primarily use FreeBSD and promote it whenever possible.  FreeBSD is a terrific technology with a terrific community."
***</li>
</ul>

<h3><a href="http://www.shiningsilence.com/dbsdlog/2013/12/19/13008.html" target="_blank" rel="nofollow noopener">OpenPF?</a></h3>

<ul>
<li>A blog post over at the <a href="http://www.bsdnow.tv/episodes/2013_11_13-the_gateway_drug" target="_blank" rel="nofollow noopener">Dragonfly digest</a></li>
<li>What if we had some cross platform development of OpenBSD's firewall?</li>
<li>Similar to portable <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" target="_blank" rel="nofollow noopener">OpenSSH</a> or <a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" target="_blank" rel="nofollow noopener">OpenZFS</a>, there could be a centrally-developed version with compatibility glue</li>
<li>Right now FreeBSD 9's pf is old, FreeBSD 10's pf is old (but has the best performance of any implementation due to custom patches), NetBSD's pf is old (but they're working on a fork) and Dragonfly's pf is old</li>
<li>Further complicated by the fact that PF itself doesn’t have a version number, since it was designed to just be ‘the pf that came with OpenBSD 5.4’</li>
<li>Not likely to happen any time soon, but it's good food for thought
***</li>
</ul>

<h3><a href="http://mxey.net/the-year-of-freebsd-on-the-server/" target="_blank" rel="nofollow noopener">Year of BSD on the server</a></h3>

<ul>
<li>A good blog post about switching servers from Linux to BSD</li>
<li>2014 is going to be the year of a lot of switching, due to FreeBSD 10's amazing new features</li>
<li>This author was particularly taken with <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">pkgng</a> and the more coherent layout of BSD systems</li>
<li>Similarly, there was also a recent <a href="http://www.reddit.com/r/BSD/comments/1tdrz1/why_did_you_choose_bsd_over_linux/" target="_blank" rel="nofollow noopener">reddit thread</a>, "Why did you choose BSD over Linux?"</li>
<li>Both are excellent reads for Linux users that are thinking about making the switch, send 'em to your friends
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2013/12/24/getting-to-know-your-portmgr-bryan-drewery/" target="_blank" rel="nofollow noopener">Getting to know your portmgr</a></h3>

<ul>
<li>This time in the series they interview Bryan Drewery, a fairly new addition to the team</li>
<li>He started maintaining portupgrade and portmaster, and eventually ended up on the ports management team</li>
<li>Believe it or not, his wife actually had a lot to do with him getting into FreeBSD full-time</li>
<li>Lots of fun trivia and background about him</li>
<li>Speaking of portmgr, our interview for today is...
***</li>
</ul>

<h2>Interview - Baptiste Daroussin - <a href="mailto:bapt@freebsd.org" target="_blank" rel="nofollow noopener">bapt@freebsd.org</a></h2>

<p>The future of FreeBSD's <a href="http://www.bsdnow.tv/tutorials/pkgng" target="_blank" rel="nofollow noopener">binary packages</a>, ports' features, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.youtube.com/watch?v=aD-2e9u3tug" target="_blank" rel="nofollow noopener">pfSense december hang out</a></h3>

<ul>
<li>Interview/presentation from pfSense developer Chris Buechler with an <a href="http://blog.pfsense.org/?p=1146" target="_blank" rel="nofollow noopener">accompanying blog post</a></li>
<li>"This is the first in what will be a monthly recurring series. Each month, we’ll have a how to tutorial on a specific topic or area of the system, and updates on development and other happenings with the project. We have several topics in mind, but also welcome community suggestions on topics"</li>
<li>Speaking of pfSense, they recently opened an <a href="http://blog.pfsense.org/?p=1156" target="_blank" rel="nofollow noopener">online store</a></li>
<li>We're planning on having a pfSense episode next month!
***</li>
</ul>

<h3><a href="http://bsdmag.org/magazine/1854-carp-on-freebsd-how-to-use-devd-to-take-action-on-kernel-events" target="_blank" rel="nofollow noopener">BSDMag December issue is out</a></h3>

<ul>
<li>The free monthly BSD magazine gets a new release for December</li>
<li>Topics include CARP on FreeBSD, more BSD programming, "unix basics for security professionals," some kernel introductions, using OpenBSD as a transparent proxy with relayd, GhostBSD overview and some stuff about SSH
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20131217081921" target="_blank" rel="nofollow noopener">OpenBSD gets tmpfs</a></h3>

<ul>
<li>In addition to the recently-added FUSE support, OpenBSD now has tmpfs</li>
<li>To get more testing, it was enabled by default in -current</li>
<li>Should make its way into 5.5 if everything goes according to plan</li>
<li>Enables lots of new possibilities, like our <a href="http://www.bsdnow.tv/tutorials/ccache" target="_blank" rel="nofollow noopener">ccache and tmpfs guide</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2013/12/pc-bsd-weekly-feature-digest-122013/" target="_blank" rel="nofollow noopener">PCBSD weekly digests</a></h3>

<ul>
<li>Catching up with all the work going on in PCBSD land..</li>
<li><a href="http://blog.pcbsd.org/2013/12/weekly-feature-digest-122713/" target="_blank" rel="nofollow noopener">10.0-RC2 is now available</a></li>
<li>The big pkgng 1.2 problems seem to have been worked out
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2UrUzlnf6" target="_blank" rel="nofollow noopener">Remy writes in</a></li>
<li><a href="http://slexy.org/view/s2iqnywwKX" target="_blank" rel="nofollow noopener">Jason writes in</a></li>
<li><a href="http://slexy.org/view/s2IUcPySbh" target="_blank" rel="nofollow noopener">Rob writes in</a></li>
<li><a href="http://slexy.org/view/s21aYlbXz2" target="_blank" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s21vrYSqU8" target="_blank" rel="nofollow noopener">Stuart writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
