<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app01</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 08:06:04 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Rng”</title>
    <link>https://www.bsdnow.tv/tags/rng</link>
    <pubDate>Thu, 16 May 2024 11:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>559: Rainy WiFi Days</title>
  <link>https://www.bsdnow.tv/559</link>
  <guid isPermaLink="false">9e7884ae-e36e-4f7f-8c73-96cd70d35b45</guid>
  <pubDate>Thu, 16 May 2024 11:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/9e7884ae-e36e-4f7f-8c73-96cd70d35b45.mp3" length="54996864" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>An RNG that runs in your brain, Going Stateless, SmolBSD, The Wi-Fi only works when it's raining, Wayland, where are we in 2024?, Omnios pxe booting, OpenBSD scripts to convert wg-quick VPN files, and more</itunes:subtitle>
  <itunes:duration>57:17</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;An RNG that runs in your brain, Going Stateless, SmolBSD, The Wi-Fi only works when it's raining, Wayland, where are we in 2024?, Omnios pxe booting, OpenBSD scripts to convert wg-quick VPN files, and more&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt; and the &lt;a href="https://www.patreon.com/bsdnow" rel="nofollow noopener"&gt;BSDNow Patreon&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.hillelwayne.com/post/randomness/" rel="nofollow noopener"&gt;An RNG that runs in your brain&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://dataswamp.org/%7Esolene/2024-04-20-workstation-going-stateless.html" rel="nofollow noopener"&gt;Going Stateless&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://smolbsd.org" rel="nofollow noopener"&gt;SmolBSD&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://predr.ag/blog/wifi-only-works-when-its-raining/" rel="nofollow noopener"&gt;The Wi-Fi only works when it's raining&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://www.dedoimedo.com/computers/wayland-2024.html" rel="nofollow noopener"&gt;Wayland, where are we in 2024? Any good for being the default?&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://neirac.srht.site/posts/ipxe_boot.html" rel="nofollow noopener"&gt;Omnios pxe booting&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;p&gt;&lt;a href="https://dataswamp.org/%7Esolene/2024-04-27-openbsd-wg-quick-converter.html" rel="nofollow noopener"&gt;OpenBSD scripts to convert wg-quick VPN files&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tarsnap&lt;/h2&gt;

&lt;p&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/p&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Join us and other BSD Fans in our &lt;a href="https://t.me/bsdnow" rel="nofollow noopener"&gt;BSD Now Telegram channel&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, hardenedbsd, tutorial, howto, guide, bsd, operating system, os, open source, foss, shell, cli, unix, tools, utility, berkeley, software, distribution, development, code, programming, release, zfs, zpool, dataset, filesystem, storage, ports, packages, jails, interview, RNG, brain, stateless, smolbsd, rain, wifi, wayland, omnios, pxe, booting, wg-quick, VPN, wireguard,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>An RNG that runs in your brain, Going Stateless, SmolBSD, The Wi-Fi only works when it's raining, Wayland, where are we in 2024?, Omnios pxe booting, OpenBSD scripts to convert wg-quick VPN files, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://www.hillelwayne.com/post/randomness/" rel="nofollow noopener">An RNG that runs in your brain</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-04-20-workstation-going-stateless.html" rel="nofollow noopener">Going Stateless</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://smolbsd.org" rel="nofollow noopener">SmolBSD</a></p>

<hr>

<p><a href="https://predr.ag/blog/wifi-only-works-when-its-raining/" rel="nofollow noopener">The Wi-Fi only works when it's raining</a></p>

<hr>

<p><a href="https://www.dedoimedo.com/computers/wayland-2024.html" rel="nofollow noopener">Wayland, where are we in 2024? Any good for being the default?</a></p>

<hr>

<p><a href="https://neirac.srht.site/posts/ipxe_boot.html" rel="nofollow noopener">Omnios pxe booting</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-04-27-openbsd-wg-quick-converter.html" rel="nofollow noopener">OpenBSD scripts to convert wg-quick VPN files</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>An RNG that runs in your brain, Going Stateless, SmolBSD, The Wi-Fi only works when it's raining, Wayland, where are we in 2024?, Omnios pxe booting, OpenBSD scripts to convert wg-quick VPN files, and more</p>

<p><strong><em>NOTES</em></strong></p>

<p>This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" rel="nofollow noopener">Tarsnap</a> and the <a href="https://www.patreon.com/bsdnow" rel="nofollow noopener">BSDNow Patreon</a></p>

<h2>Headlines</h2>

<p><a href="https://www.hillelwayne.com/post/randomness/" rel="nofollow noopener">An RNG that runs in your brain</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-04-20-workstation-going-stateless.html" rel="nofollow noopener">Going Stateless</a></p>

<hr>

<h2>News Roundup</h2>

<p><a href="https://smolbsd.org" rel="nofollow noopener">SmolBSD</a></p>

<hr>

<p><a href="https://predr.ag/blog/wifi-only-works-when-its-raining/" rel="nofollow noopener">The Wi-Fi only works when it's raining</a></p>

<hr>

<p><a href="https://www.dedoimedo.com/computers/wayland-2024.html" rel="nofollow noopener">Wayland, where are we in 2024? Any good for being the default?</a></p>

<hr>

<p><a href="https://neirac.srht.site/posts/ipxe_boot.html" rel="nofollow noopener">Omnios pxe booting</a></p>

<hr>

<p><a href="https://dataswamp.org/%7Esolene/2024-04-27-openbsd-wg-quick-converter.html" rel="nofollow noopener">OpenBSD scripts to convert wg-quick VPN files</a></p>

<hr>

<h2>Tarsnap</h2>

<p>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</p>

<hr>

<ul>
<li><p>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">feedback@bsdnow.tv</a></p></li>
<li><p>Join us and other BSD Fans in our <a href="https://t.me/bsdnow" rel="nofollow noopener">BSD Now Telegram channel</a></p></li>
</ul>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>77: Noah's L2ARC</title>
  <link>https://www.bsdnow.tv/77</link>
  <guid isPermaLink="false">7f831a01-7c9e-48e5-8400-717e0198fc07</guid>
  <pubDate>Wed, 18 Feb 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/7f831a01-7c9e-48e5-8400-717e0198fc07.mp3" length="62093524" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be chatting with Alex Reece and Matt Ahrens about what's new in the world of OpenZFS. After that, we're starting a new tutorial series on submitting your first patch. All the latest BSD news and answers to your emails, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:26:14</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be chatting with Alex Reece and Matt Ahrens about what's new in the world of OpenZFS. After that, we're starting a new tutorial series on submitting your first patch. All the latest BSD news and answers to your emails, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://changelog.complete.org/archives/9317-has-linux-lost-its-way-comments-prompt-a-debian-developer-to-revisit-freebsd-after-20-years" rel="nofollow noopener"&gt;Revisiting FreeBSD after 20 years&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With comments like "has Linux lost its way?" floating around, a Debian developer was prompted to revisit FreeBSD after nearly two decades&lt;/li&gt;
&lt;li&gt;This blog post goes through his experiences trying out a modern BSD variant, and includes the good, the bad and the ugly - not just praise this time&lt;/li&gt;
&lt;li&gt;He loves ZFS and the beadm tool, and finds the FreeBSD implementation to be much more stable than ZoL&lt;/li&gt;
&lt;li&gt;On the topic of jails, he summarizes: "Linux has tried so hard to get this right, and fallen on its face so many times, a person just wants to take pity sometimes. We’ve had linux-vserver, openvz, lxc, and still none of them match what FreeBSD jails have done for a long time."&lt;/li&gt;
&lt;li&gt;The post also goes through the "just plain different" aspects of a complete OS vs. a distribution of various things pieced together&lt;/li&gt;
&lt;li&gt;Finally, he includes some things he wasn't so happy about: subpar laptop support, virtualization being a bit behind, a &lt;em&gt;myriad&lt;/em&gt; of complaints about pkgng and a few other things&lt;/li&gt;
&lt;li&gt;There was some &lt;a href="https://news.ycombinator.com/item?id=9063216" rel="nofollow noopener"&gt;decent discussion&lt;/a&gt; on Hacker News about this article too, with counterpoints from both sides
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150218085759" rel="nofollow noopener"&gt;s2k15 hackathon report: network stack SMP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The first trip report from the recent OpenBSD hackathon in Australia has finally been submitted&lt;/li&gt;
&lt;li&gt;One of the themes of this hackathon was SMP (symmetric multiprocessing) improvement, and Martin Pieuchot did some hacking on the network stack&lt;/li&gt;
&lt;li&gt;If you're not familiar with him, he gave a &lt;a href="http://www.openbsd.org/papers/tamingdragons.pdf" rel="nofollow noopener"&gt;presentation&lt;/a&gt; at EuroBSDCon last year, titled &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener"&gt;Taming OpenBSD Network Stack Dragons&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Teaming up with David Gwynne, they worked on getting some bits of the networking code out of the &lt;a href="https://en.wikipedia.org/wiki/Giant_lock" rel="nofollow noopener"&gt;big lock&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Hopefully more trip reports will be sent in during the coming weeks&lt;/li&gt;
&lt;li&gt;Most of the big code changes should probably appear after the 5.7-release testing period
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.tumfatig.net/20150215/bind-nsd-unbound-openbsd-5-6/" rel="nofollow noopener"&gt;From BIND to NSD and Unbound&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've been running a DNS server on any of the BSDs, you've probably noticed a semi-recent trend: BIND being replaced with Unbound&lt;/li&gt;
&lt;li&gt;BIND was ripped out in FreeBSD 10.0 and will be gone in OpenBSD 5.7, but both systems include Unbound now as an alternative&lt;/li&gt;
&lt;li&gt;OpenBSD goes a step further, also including NSD in the base system, whereas you'll need to install that from ports on FreeBSD&lt;/li&gt;
&lt;li&gt;Instead of one daemon doing everything like BIND tried to do, this new setup splits the authoritative nameserver and the caching resolver into two separate daemons &lt;/li&gt;
&lt;li&gt;This post takes you through the transitional phase of going from a single BIND setup to a combination of NSD and Unbound&lt;/li&gt;
&lt;li&gt;All in all, everyone wins here, as there will be a lot less security advisories in both BSDs because of it...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://m0n0.ch/wall/end_announcement.php" rel="nofollow noopener"&gt;m0n0wall calls it quits&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The original, classic BSD firewall distribution &lt;a href="https://en.wikipedia.org/wiki/M0n0wall" rel="nofollow noopener"&gt;m0n0wall&lt;/a&gt; has finally decided to close up shop&lt;/li&gt;
&lt;li&gt;For those unfamiliar, m0n0wall was a FreeBSD-based firewall project that put a lot of focus on embedded devices: running from a CF card, CD, USB drive or &lt;strong&gt;even a floppy disk&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;It started over twelve years ago, which is pretty amazing when you consider that's around half of FreeBSD itself's lifespan&lt;/li&gt;
&lt;li&gt;The project was probably a lot of people's first encounter with BSD in any form&lt;/li&gt;
&lt;li&gt;If you were a m0n0wall user, fear not, you've got &lt;em&gt;plenty&lt;/em&gt; of choices for a potential replacement: doing it yourself with something like &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt; or &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt;, or going the premade route with something like &lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;pfSense&lt;/a&gt;, &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt; or the &lt;a href="http://www.bsdnow.tv/episodes/2014_10_22-dont_buy_a_router" rel="nofollow noopener"&gt;BSD Router Project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The founder's announcement includes these closing words: "m0n0wall has served as the seed for several other well known open source projects, like pfSense, FreeNAS and AskoziaPBX. The newest offspring, OPNsense, aims to continue the open source spirit of m0n0wall while updating the technology to be ready for the future. In my view, it is the perfect way to bring the m0n0wall idea into 2015, and I encourage all current m0n0wall users to check out OPNsense and contribute if they can."&lt;/li&gt;
&lt;li&gt;While m0n0wall didn't get a lot of on-air mention, surely a lot of our listeners will remember it fondly
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Alex Reece &amp;amp; Matt Ahrens - &lt;a href="mailto:alex@delphix.com" rel="nofollow noopener"&gt;alex@delphix.com&lt;/a&gt; &amp;amp; &lt;a href="mailto:matt@delphix.com" rel="nofollow noopener"&gt;matt@delphix.com&lt;/a&gt; / &lt;a href="https://twitter.com/openzfs" rel="nofollow noopener"&gt;@openzfs&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;What's new in OpenZFS&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/patching-obsd" rel="nofollow noopener"&gt;Making your first patch (OpenBSD)&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.echothrust.com/blogs/using-openbsd-and-vxlan-overlay-remote-lans" rel="nofollow noopener"&gt;Overlaying remote LANs with OpenBSD's VXLAN&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Have you ever wanted to "merge" multiple remote LANs? OpenBSD's &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/vxlan.4" rel="nofollow noopener"&gt;vxlan(4)&lt;/a&gt; is exactly what you need&lt;/li&gt;
&lt;li&gt;This article talks about using it to connect two virtualized infrastructures on different ESXi servers&lt;/li&gt;
&lt;li&gt;It gives a bit of networking background first, in case you're not quite up to speed on all this stuff&lt;/li&gt;
&lt;li&gt;This tool opens up a lot of very cool possibilities, even possibly doing a "remote" LAN party&lt;/li&gt;
&lt;li&gt;Be sure to check the &lt;a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener"&gt;AsiaBSDCon talk&lt;/a&gt; about VXLANs if you haven't already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lukewolf.blogspot.com/2015/02/a-prediction-2020-year-of-pc-bsd-on.html" rel="nofollow noopener"&gt;2020, year of the PCBSD desktop&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have a blog post about BSD on the desktop, straight from a KDE developer&lt;/li&gt;
&lt;li&gt;He predicts that PCBSD is going to take off before the year 2020, possibly even overtaking Linux's desktop market share (small as it may be)&lt;/li&gt;
&lt;li&gt;With PCBSD making a preconfigured FreeBSD desktop a reality, and the new KMS work, the author is impressed with how far BSD has come as a viable desktop option&lt;/li&gt;
&lt;li&gt;ZFS and easy-to-use boot environments top the list of things he says differentiate the BSD desktop experience from the Linux one&lt;/li&gt;
&lt;li&gt;There was also some &lt;a href="http://bsd.slashdot.org/story/15/02/16/2355236/pc-bsd-set-for-serious-growth" rel="nofollow noopener"&gt;discussion on Slashdot&lt;/a&gt; that might be worth reading
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.djm.net.au/2015/02/hostkey-rotation-redux.html" rel="nofollow noopener"&gt;OpenSSH host key rotation, redux&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned the new OpenSSH host key rotation and other goodies in &lt;a href="http://www.bsdnow.tv/episodes/2015_02_04-from_the_foundation_1" rel="nofollow noopener"&gt;a previous episode&lt;/a&gt;, but things have changed a little bit since then&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;djm&lt;/a&gt; says "almost immediately after smugly declaring 'mission accomplished', the bug reports started rolling in."&lt;/li&gt;
&lt;li&gt;There were some initial complaints from developers about the new options, and a serious bug shortly thereafter&lt;/li&gt;
&lt;li&gt;After going back to the drawing board, he refactored some of the new code (and API) and added some more regression tests&lt;/li&gt;
&lt;li&gt;Most importantly, the bigger big fix was described as: "a malicious server (say, "host-a") could advertise the public key of another server (say, "host-b"). Then, when the client subsequently connects back to host-a, instead of answering the connection as usual itself, host-a could proxy the connection to host-b. This would cause the user to connect to host-b when they think they are connecting to host-a, which is a violation of the authentication the host key is supposed to provide."&lt;/li&gt;
&lt;li&gt;None of this code has been in a formal OpenSSH release just yet, but hopefully it will soon
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/pcbsd/pcbsd/commit/6ede13117dcee1272d7a7060b16818506874286e" rel="nofollow noopener"&gt;PCBSD tries out LibreSSL&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;PCBSD users may soon be seeing a lot less security problems because of two recent changes&lt;/li&gt;
&lt;li&gt;After switching over to OpenNTPD &lt;a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener"&gt;last week&lt;/a&gt;, PCBSD decides to give the &lt;a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener"&gt;portable LibreSSL&lt;/a&gt; a try too&lt;/li&gt;
&lt;li&gt;Note that this is only for the packages built from ports, not the base system unfortunately&lt;/li&gt;
&lt;li&gt;They're not the first ones to do this - OPNsense has been experimenting with replacing OpenSSL in their ports tree for a little while now, and of course all of OpenBSD's ports are built against it&lt;/li&gt;
&lt;li&gt;A good &lt;a href="https://github.com/pcbsd/freebsd-ports/commit/2eee669f4d6ab9a641162ecda29b62ab921438eb" rel="nofollow noopener"&gt;number of patches&lt;/a&gt; are still not committed in vanilla FreeBSD ports, so they had to borrow some from Bugzilla&lt;/li&gt;
&lt;li&gt;Look forward to Kris wearing a "&lt;a href="https://www.openbsdstore.com/cgi-bin/live/ecommerce.pl?site=shop_openbsdeurope_com&amp;amp;state=item&amp;amp;dept_id=01&amp;amp;sub_dept_id=01&amp;amp;product_id=TSHIRTOSSL" rel="nofollow noopener"&gt;keep calm and abandon OpenSSL&lt;/a&gt;" shirt in the near future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s28nyJ5omV" rel="nofollow noopener"&gt;Benjamin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2wYUmUmh0" rel="nofollow noopener"&gt;Mike writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2BAKAQvMt" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/068405.html" rel="nofollow noopener"&gt;Debian&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054580.html" rel="nofollow noopener"&gt;Dejavu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-February/207475.html" rel="nofollow noopener"&gt;Package gone missing&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, zfs, raid, openzfs, illumos, solaris, openindiana, opensolaris, omnios, smartos, m0n0wall, opnsense, rng, libressl</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be chatting with Alex Reece and Matt Ahrens about what's new in the world of OpenZFS. After that, we're starting a new tutorial series on submitting your first patch. All the latest BSD news and answers to your emails, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://changelog.complete.org/archives/9317-has-linux-lost-its-way-comments-prompt-a-debian-developer-to-revisit-freebsd-after-20-years" rel="nofollow noopener">Revisiting FreeBSD after 20 years</a></h3>

<ul>
<li>With comments like "has Linux lost its way?" floating around, a Debian developer was prompted to revisit FreeBSD after nearly two decades</li>
<li>This blog post goes through his experiences trying out a modern BSD variant, and includes the good, the bad and the ugly - not just praise this time</li>
<li>He loves ZFS and the beadm tool, and finds the FreeBSD implementation to be much more stable than ZoL</li>
<li>On the topic of jails, he summarizes: "Linux has tried so hard to get this right, and fallen on its face so many times, a person just wants to take pity sometimes. We’ve had linux-vserver, openvz, lxc, and still none of them match what FreeBSD jails have done for a long time."</li>
<li>The post also goes through the "just plain different" aspects of a complete OS vs. a distribution of various things pieced together</li>
<li>Finally, he includes some things he wasn't so happy about: subpar laptop support, virtualization being a bit behind, a <em>myriad</em> of complaints about pkgng and a few other things</li>
<li>There was some <a href="https://news.ycombinator.com/item?id=9063216" rel="nofollow noopener">decent discussion</a> on Hacker News about this article too, with counterpoints from both sides
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150218085759" rel="nofollow noopener">s2k15 hackathon report: network stack SMP</a></h3>

<ul>
<li>The first trip report from the recent OpenBSD hackathon in Australia has finally been submitted</li>
<li>One of the themes of this hackathon was SMP (symmetric multiprocessing) improvement, and Martin Pieuchot did some hacking on the network stack</li>
<li>If you're not familiar with him, he gave a <a href="http://www.openbsd.org/papers/tamingdragons.pdf" rel="nofollow noopener">presentation</a> at EuroBSDCon last year, titled <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener">Taming OpenBSD Network Stack Dragons</a></li>
<li>Teaming up with David Gwynne, they worked on getting some bits of the networking code out of the <a href="https://en.wikipedia.org/wiki/Giant_lock" rel="nofollow noopener">big lock</a></li>
<li>Hopefully more trip reports will be sent in during the coming weeks</li>
<li>Most of the big code changes should probably appear after the 5.7-release testing period
***</li>
</ul>

<h3><a href="https://www.tumfatig.net/20150215/bind-nsd-unbound-openbsd-5-6/" rel="nofollow noopener">From BIND to NSD and Unbound</a></h3>

<ul>
<li>If you've been running a DNS server on any of the BSDs, you've probably noticed a semi-recent trend: BIND being replaced with Unbound</li>
<li>BIND was ripped out in FreeBSD 10.0 and will be gone in OpenBSD 5.7, but both systems include Unbound now as an alternative</li>
<li>OpenBSD goes a step further, also including NSD in the base system, whereas you'll need to install that from ports on FreeBSD</li>
<li>Instead of one daemon doing everything like BIND tried to do, this new setup splits the authoritative nameserver and the caching resolver into two separate daemons </li>
<li>This post takes you through the transitional phase of going from a single BIND setup to a combination of NSD and Unbound</li>
<li>All in all, everyone wins here, as there will be a lot less security advisories in both BSDs because of it...
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/end_announcement.php" rel="nofollow noopener">m0n0wall calls it quits</a></h3>

<ul>
<li>The original, classic BSD firewall distribution <a href="https://en.wikipedia.org/wiki/M0n0wall" rel="nofollow noopener">m0n0wall</a> has finally decided to close up shop</li>
<li>For those unfamiliar, m0n0wall was a FreeBSD-based firewall project that put a lot of focus on embedded devices: running from a CF card, CD, USB drive or <strong>even a floppy disk</strong></li>
<li>It started over twelve years ago, which is pretty amazing when you consider that's around half of FreeBSD itself's lifespan</li>
<li>The project was probably a lot of people's first encounter with BSD in any form</li>
<li>If you were a m0n0wall user, fear not, you've got <em>plenty</em> of choices for a potential replacement: doing it yourself with something like <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a>, or going the premade route with something like <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a>, <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> or the <a href="http://www.bsdnow.tv/episodes/2014_10_22-dont_buy_a_router" rel="nofollow noopener">BSD Router Project</a></li>
<li>The founder's announcement includes these closing words: "m0n0wall has served as the seed for several other well known open source projects, like pfSense, FreeNAS and AskoziaPBX. The newest offspring, OPNsense, aims to continue the open source spirit of m0n0wall while updating the technology to be ready for the future. In my view, it is the perfect way to bring the m0n0wall idea into 2015, and I encourage all current m0n0wall users to check out OPNsense and contribute if they can."</li>
<li>While m0n0wall didn't get a lot of on-air mention, surely a lot of our listeners will remember it fondly
***</li>
</ul>

<h2>Interview - Alex Reece &amp; Matt Ahrens - <a href="mailto:alex@delphix.com" rel="nofollow noopener">alex@delphix.com</a> &amp; <a href="mailto:matt@delphix.com" rel="nofollow noopener">matt@delphix.com</a> / <a href="https://twitter.com/openzfs" rel="nofollow noopener">@openzfs</a></h2>

<p>What's new in OpenZFS</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/patching-obsd" rel="nofollow noopener">Making your first patch (OpenBSD)</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.echothrust.com/blogs/using-openbsd-and-vxlan-overlay-remote-lans" rel="nofollow noopener">Overlaying remote LANs with OpenBSD's VXLAN</a></h3>

<ul>
<li>Have you ever wanted to "merge" multiple remote LANs? OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/vxlan.4" rel="nofollow noopener">vxlan(4)</a> is exactly what you need</li>
<li>This article talks about using it to connect two virtualized infrastructures on different ESXi servers</li>
<li>It gives a bit of networking background first, in case you're not quite up to speed on all this stuff</li>
<li>This tool opens up a lot of very cool possibilities, even possibly doing a "remote" LAN party</li>
<li>Be sure to check the <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">AsiaBSDCon talk</a> about VXLANs if you haven't already
***</li>
</ul>

<h3><a href="http://lukewolf.blogspot.com/2015/02/a-prediction-2020-year-of-pc-bsd-on.html" rel="nofollow noopener">2020, year of the PCBSD desktop</a></h3>

<ul>
<li>Here we have a blog post about BSD on the desktop, straight from a KDE developer</li>
<li>He predicts that PCBSD is going to take off before the year 2020, possibly even overtaking Linux's desktop market share (small as it may be)</li>
<li>With PCBSD making a preconfigured FreeBSD desktop a reality, and the new KMS work, the author is impressed with how far BSD has come as a viable desktop option</li>
<li>ZFS and easy-to-use boot environments top the list of things he says differentiate the BSD desktop experience from the Linux one</li>
<li>There was also some <a href="http://bsd.slashdot.org/story/15/02/16/2355236/pc-bsd-set-for-serious-growth" rel="nofollow noopener">discussion on Slashdot</a> that might be worth reading
***</li>
</ul>

<h3><a href="http://blog.djm.net.au/2015/02/hostkey-rotation-redux.html" rel="nofollow noopener">OpenSSH host key rotation, redux</a></h3>

<ul>
<li>We mentioned the new OpenSSH host key rotation and other goodies in <a href="http://www.bsdnow.tv/episodes/2015_02_04-from_the_foundation_1" rel="nofollow noopener">a previous episode</a>, but things have changed a little bit since then</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">djm</a> says "almost immediately after smugly declaring 'mission accomplished', the bug reports started rolling in."</li>
<li>There were some initial complaints from developers about the new options, and a serious bug shortly thereafter</li>
<li>After going back to the drawing board, he refactored some of the new code (and API) and added some more regression tests</li>
<li>Most importantly, the bigger big fix was described as: "a malicious server (say, "host-a") could advertise the public key of another server (say, "host-b"). Then, when the client subsequently connects back to host-a, instead of answering the connection as usual itself, host-a could proxy the connection to host-b. This would cause the user to connect to host-b when they think they are connecting to host-a, which is a violation of the authentication the host key is supposed to provide."</li>
<li>None of this code has been in a formal OpenSSH release just yet, but hopefully it will soon
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/6ede13117dcee1272d7a7060b16818506874286e" rel="nofollow noopener">PCBSD tries out LibreSSL</a></h3>

<ul>
<li>PCBSD users may soon be seeing a lot less security problems because of two recent changes</li>
<li>After switching over to OpenNTPD <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">last week</a>, PCBSD decides to give the <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">portable LibreSSL</a> a try too</li>
<li>Note that this is only for the packages built from ports, not the base system unfortunately</li>
<li>They're not the first ones to do this - OPNsense has been experimenting with replacing OpenSSL in their ports tree for a little while now, and of course all of OpenBSD's ports are built against it</li>
<li>A good <a href="https://github.com/pcbsd/freebsd-ports/commit/2eee669f4d6ab9a641162ecda29b62ab921438eb" rel="nofollow noopener">number of patches</a> are still not committed in vanilla FreeBSD ports, so they had to borrow some from Bugzilla</li>
<li>Look forward to Kris wearing a "<a href="https://www.openbsdstore.com/cgi-bin/live/ecommerce.pl?site=shop_openbsdeurope_com&amp;state=item&amp;dept_id=01&amp;sub_dept_id=01&amp;product_id=TSHIRTOSSL" rel="nofollow noopener">keep calm and abandon OpenSSL</a>" shirt in the near future
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s28nyJ5omV" rel="nofollow noopener">Benjamin writes in</a></li>
<li><a href="http://slexy.org/view/s2wYUmUmh0" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s2BAKAQvMt" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/068405.html" rel="nofollow noopener">Debian</a> <a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054580.html" rel="nofollow noopener">Dejavu</a></li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2015-February/207475.html" rel="nofollow noopener">Package gone missing</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be chatting with Alex Reece and Matt Ahrens about what's new in the world of OpenZFS. After that, we're starting a new tutorial series on submitting your first patch. All the latest BSD news and answers to your emails, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://changelog.complete.org/archives/9317-has-linux-lost-its-way-comments-prompt-a-debian-developer-to-revisit-freebsd-after-20-years" rel="nofollow noopener">Revisiting FreeBSD after 20 years</a></h3>

<ul>
<li>With comments like "has Linux lost its way?" floating around, a Debian developer was prompted to revisit FreeBSD after nearly two decades</li>
<li>This blog post goes through his experiences trying out a modern BSD variant, and includes the good, the bad and the ugly - not just praise this time</li>
<li>He loves ZFS and the beadm tool, and finds the FreeBSD implementation to be much more stable than ZoL</li>
<li>On the topic of jails, he summarizes: "Linux has tried so hard to get this right, and fallen on its face so many times, a person just wants to take pity sometimes. We’ve had linux-vserver, openvz, lxc, and still none of them match what FreeBSD jails have done for a long time."</li>
<li>The post also goes through the "just plain different" aspects of a complete OS vs. a distribution of various things pieced together</li>
<li>Finally, he includes some things he wasn't so happy about: subpar laptop support, virtualization being a bit behind, a <em>myriad</em> of complaints about pkgng and a few other things</li>
<li>There was some <a href="https://news.ycombinator.com/item?id=9063216" rel="nofollow noopener">decent discussion</a> on Hacker News about this article too, with counterpoints from both sides
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150218085759" rel="nofollow noopener">s2k15 hackathon report: network stack SMP</a></h3>

<ul>
<li>The first trip report from the recent OpenBSD hackathon in Australia has finally been submitted</li>
<li>One of the themes of this hackathon was SMP (symmetric multiprocessing) improvement, and Martin Pieuchot did some hacking on the network stack</li>
<li>If you're not familiar with him, he gave a <a href="http://www.openbsd.org/papers/tamingdragons.pdf" rel="nofollow noopener">presentation</a> at EuroBSDCon last year, titled <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener">Taming OpenBSD Network Stack Dragons</a></li>
<li>Teaming up with David Gwynne, they worked on getting some bits of the networking code out of the <a href="https://en.wikipedia.org/wiki/Giant_lock" rel="nofollow noopener">big lock</a></li>
<li>Hopefully more trip reports will be sent in during the coming weeks</li>
<li>Most of the big code changes should probably appear after the 5.7-release testing period
***</li>
</ul>

<h3><a href="https://www.tumfatig.net/20150215/bind-nsd-unbound-openbsd-5-6/" rel="nofollow noopener">From BIND to NSD and Unbound</a></h3>

<ul>
<li>If you've been running a DNS server on any of the BSDs, you've probably noticed a semi-recent trend: BIND being replaced with Unbound</li>
<li>BIND was ripped out in FreeBSD 10.0 and will be gone in OpenBSD 5.7, but both systems include Unbound now as an alternative</li>
<li>OpenBSD goes a step further, also including NSD in the base system, whereas you'll need to install that from ports on FreeBSD</li>
<li>Instead of one daemon doing everything like BIND tried to do, this new setup splits the authoritative nameserver and the caching resolver into two separate daemons </li>
<li>This post takes you through the transitional phase of going from a single BIND setup to a combination of NSD and Unbound</li>
<li>All in all, everyone wins here, as there will be a lot less security advisories in both BSDs because of it...
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/end_announcement.php" rel="nofollow noopener">m0n0wall calls it quits</a></h3>

<ul>
<li>The original, classic BSD firewall distribution <a href="https://en.wikipedia.org/wiki/M0n0wall" rel="nofollow noopener">m0n0wall</a> has finally decided to close up shop</li>
<li>For those unfamiliar, m0n0wall was a FreeBSD-based firewall project that put a lot of focus on embedded devices: running from a CF card, CD, USB drive or <strong>even a floppy disk</strong></li>
<li>It started over twelve years ago, which is pretty amazing when you consider that's around half of FreeBSD itself's lifespan</li>
<li>The project was probably a lot of people's first encounter with BSD in any form</li>
<li>If you were a m0n0wall user, fear not, you've got <em>plenty</em> of choices for a potential replacement: doing it yourself with something like <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a> or <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a>, or going the premade route with something like <a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a>, <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a> or the <a href="http://www.bsdnow.tv/episodes/2014_10_22-dont_buy_a_router" rel="nofollow noopener">BSD Router Project</a></li>
<li>The founder's announcement includes these closing words: "m0n0wall has served as the seed for several other well known open source projects, like pfSense, FreeNAS and AskoziaPBX. The newest offspring, OPNsense, aims to continue the open source spirit of m0n0wall while updating the technology to be ready for the future. In my view, it is the perfect way to bring the m0n0wall idea into 2015, and I encourage all current m0n0wall users to check out OPNsense and contribute if they can."</li>
<li>While m0n0wall didn't get a lot of on-air mention, surely a lot of our listeners will remember it fondly
***</li>
</ul>

<h2>Interview - Alex Reece &amp; Matt Ahrens - <a href="mailto:alex@delphix.com" rel="nofollow noopener">alex@delphix.com</a> &amp; <a href="mailto:matt@delphix.com" rel="nofollow noopener">matt@delphix.com</a> / <a href="https://twitter.com/openzfs" rel="nofollow noopener">@openzfs</a></h2>

<p>What's new in OpenZFS</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/patching-obsd" rel="nofollow noopener">Making your first patch (OpenBSD)</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.echothrust.com/blogs/using-openbsd-and-vxlan-overlay-remote-lans" rel="nofollow noopener">Overlaying remote LANs with OpenBSD's VXLAN</a></h3>

<ul>
<li>Have you ever wanted to "merge" multiple remote LANs? OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/vxlan.4" rel="nofollow noopener">vxlan(4)</a> is exactly what you need</li>
<li>This article talks about using it to connect two virtualized infrastructures on different ESXi servers</li>
<li>It gives a bit of networking background first, in case you're not quite up to speed on all this stuff</li>
<li>This tool opens up a lot of very cool possibilities, even possibly doing a "remote" LAN party</li>
<li>Be sure to check the <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">AsiaBSDCon talk</a> about VXLANs if you haven't already
***</li>
</ul>

<h3><a href="http://lukewolf.blogspot.com/2015/02/a-prediction-2020-year-of-pc-bsd-on.html" rel="nofollow noopener">2020, year of the PCBSD desktop</a></h3>

<ul>
<li>Here we have a blog post about BSD on the desktop, straight from a KDE developer</li>
<li>He predicts that PCBSD is going to take off before the year 2020, possibly even overtaking Linux's desktop market share (small as it may be)</li>
<li>With PCBSD making a preconfigured FreeBSD desktop a reality, and the new KMS work, the author is impressed with how far BSD has come as a viable desktop option</li>
<li>ZFS and easy-to-use boot environments top the list of things he says differentiate the BSD desktop experience from the Linux one</li>
<li>There was also some <a href="http://bsd.slashdot.org/story/15/02/16/2355236/pc-bsd-set-for-serious-growth" rel="nofollow noopener">discussion on Slashdot</a> that might be worth reading
***</li>
</ul>

<h3><a href="http://blog.djm.net.au/2015/02/hostkey-rotation-redux.html" rel="nofollow noopener">OpenSSH host key rotation, redux</a></h3>

<ul>
<li>We mentioned the new OpenSSH host key rotation and other goodies in <a href="http://www.bsdnow.tv/episodes/2015_02_04-from_the_foundation_1" rel="nofollow noopener">a previous episode</a>, but things have changed a little bit since then</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">djm</a> says "almost immediately after smugly declaring 'mission accomplished', the bug reports started rolling in."</li>
<li>There were some initial complaints from developers about the new options, and a serious bug shortly thereafter</li>
<li>After going back to the drawing board, he refactored some of the new code (and API) and added some more regression tests</li>
<li>Most importantly, the bigger big fix was described as: "a malicious server (say, "host-a") could advertise the public key of another server (say, "host-b"). Then, when the client subsequently connects back to host-a, instead of answering the connection as usual itself, host-a could proxy the connection to host-b. This would cause the user to connect to host-b when they think they are connecting to host-a, which is a violation of the authentication the host key is supposed to provide."</li>
<li>None of this code has been in a formal OpenSSH release just yet, but hopefully it will soon
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/pcbsd/commit/6ede13117dcee1272d7a7060b16818506874286e" rel="nofollow noopener">PCBSD tries out LibreSSL</a></h3>

<ul>
<li>PCBSD users may soon be seeing a lot less security problems because of two recent changes</li>
<li>After switching over to OpenNTPD <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">last week</a>, PCBSD decides to give the <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">portable LibreSSL</a> a try too</li>
<li>Note that this is only for the packages built from ports, not the base system unfortunately</li>
<li>They're not the first ones to do this - OPNsense has been experimenting with replacing OpenSSL in their ports tree for a little while now, and of course all of OpenBSD's ports are built against it</li>
<li>A good <a href="https://github.com/pcbsd/freebsd-ports/commit/2eee669f4d6ab9a641162ecda29b62ab921438eb" rel="nofollow noopener">number of patches</a> are still not committed in vanilla FreeBSD ports, so they had to borrow some from Bugzilla</li>
<li>Look forward to Kris wearing a "<a href="https://www.openbsdstore.com/cgi-bin/live/ecommerce.pl?site=shop_openbsdeurope_com&amp;state=item&amp;dept_id=01&amp;sub_dept_id=01&amp;product_id=TSHIRTOSSL" rel="nofollow noopener">keep calm and abandon OpenSSL</a>" shirt in the near future
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s28nyJ5omV" rel="nofollow noopener">Benjamin writes in</a></li>
<li><a href="http://slexy.org/view/s2wYUmUmh0" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s2BAKAQvMt" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/068405.html" rel="nofollow noopener">Debian</a> <a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054580.html" rel="nofollow noopener">Dejavu</a></li>
<li><a href="http://lists.dragonflybsd.org/pipermail/users/2015-February/207475.html" rel="nofollow noopener">Package gone missing</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>48: Liberating SSL</title>
  <link>https://www.bsdnow.tv/48</link>
  <guid isPermaLink="false">e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809</guid>
  <pubDate>Wed, 30 Jul 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e0c8ab6b-dd19-4778-8dc2-4b02bd2ae809.mp3" length="43106548" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>59:52</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD has gotten quite a lot done this quarter&lt;/li&gt;
&lt;li&gt;Changes in the way release branches are supported - major releases will get at least five years over their lifespan&lt;/li&gt;
&lt;li&gt;A new automounter is in the works, hoping to replace amd (which has some issues)&lt;/li&gt;
&lt;li&gt;The CAM target layer and RPC stack have gotten some major optimization and speed boosts&lt;/li&gt;
&lt;li&gt;Work on ZFSGuru continues, with a large status report specifically for that&lt;/li&gt;
&lt;li&gt;The report also mentioned some new committers, both source and ports&lt;/li&gt;
&lt;li&gt;It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show&lt;/li&gt;
&lt;li&gt;"Foundation-sponsored work resulted in &lt;strong&gt;226 commits&lt;/strong&gt; to FreeBSD over the April to June period"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724094043" rel="nofollow noopener"&gt;A new OpenBSD HTTPD is born&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Work has begun on a new HTTP daemon in the OpenBSD base system&lt;/li&gt;
&lt;li&gt;A lot of people are &lt;a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener"&gt;asking&lt;/a&gt; "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?&lt;/li&gt;
&lt;li&gt;Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)&lt;/li&gt;
&lt;li&gt;It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter&lt;/li&gt;
&lt;li&gt;This has the added benefit of the usual, easy-to-understand syntax and privilege separation &lt;/li&gt;
&lt;li&gt;There's a very brief &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener"&gt;man page&lt;/a&gt; online already&lt;/li&gt;
&lt;li&gt;It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs&lt;/li&gt;
&lt;li&gt;Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener"&gt;pkgng 1.3 announced&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest version of FreeBSD's second generation &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener"&gt;package management system&lt;/a&gt; has been released, with lots of new features&lt;/li&gt;
&lt;li&gt;It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)&lt;/li&gt;
&lt;li&gt;Lots of the code has been sandboxed for extra security&lt;/li&gt;
&lt;li&gt;You'll probably notice some new changes to the UI too, making things more user friendly&lt;/li&gt;
&lt;li&gt;A few days later &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;sortby=date&amp;amp;revision=362996" rel="nofollow noopener"&gt;1.3.1&lt;/a&gt; was released to fix a few small bugs, then &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363108" rel="nofollow noopener"&gt;1.3.2&lt;/a&gt; shortly thereafter and &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=363363" rel="nofollow noopener"&gt;1.3.3&lt;/a&gt; yesterday
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener"&gt;FreeBSD after-install security tasks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A number of people have written in to ask us "how do I secure my BSD box after I install it?"&lt;/li&gt;
&lt;li&gt;With this blog post, hopefully most of their questions will finally be answered in detail&lt;/li&gt;
&lt;li&gt;It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things&lt;/li&gt;
&lt;li&gt;Not only does it just list things to do, but the post also does a good job of explaining why you should do them&lt;/li&gt;
&lt;li&gt;Maybe we'll see some more posts in this series in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Brent Cook - &lt;a href="mailto:bcook@openbsd.org" rel="nofollow noopener"&gt;bcook@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/busterbcook" rel="nofollow noopener"&gt;@busterbcook&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;LibreSSL's portable version and development&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener"&gt;FreeBSD Mastery - Storage Essentials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;MWL&lt;/a&gt;'s new book about the FreeBSD storage subsystems now has an early draft available&lt;/li&gt;
&lt;li&gt;Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes&lt;/li&gt;
&lt;li&gt;Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance&lt;/li&gt;
&lt;li&gt;You'll get access to the completed (e)book when it's done if you buy the early draft&lt;/li&gt;
&lt;li&gt;The suggested price is $8
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener"&gt;Why BSD and not Linux?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another thread comes up asking why you should choose BSD over Linux or vice-versa&lt;/li&gt;
&lt;li&gt;Lots of good responses from users of the various BSDs&lt;/li&gt;
&lt;li&gt;Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."&lt;/li&gt;
&lt;li&gt;And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."&lt;/li&gt;
&lt;li&gt;Some other users share their switching experiences - worth a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" rel="nofollow noopener"&gt;More g2k14 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Following up from last week's &lt;a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener"&gt;huge list&lt;/a&gt; of hackathon reports, we have a few more&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140724161550" rel="nofollow noopener"&gt;Landry Breuil&lt;/a&gt; spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140728122850" rel="nofollow noopener"&gt;Andrew Fresh&lt;/a&gt; enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl&lt;/li&gt;
&lt;li&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140729070721" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth&lt;/li&gt;
&lt;li&gt;Luckily we didn't have to cover 20 new ones this time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener"&gt;BSDTalk episode 243&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The newest episode of &lt;a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener"&gt;BSDTalk&lt;/a&gt; is out, featuring an interview with Ingo Schwarze of the OpenBSD team&lt;/li&gt;
&lt;li&gt;The main topic of discussion is mandoc, which some users might not be familiar with&lt;/li&gt;
&lt;li&gt;mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)&lt;/li&gt;
&lt;li&gt;We'll catch up to you soon, Will!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener"&gt;Thomas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener"&gt;Stephen writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener"&gt;Bob Beck writes in&lt;/a&gt; - and note the "Caution" section that was added to &lt;a href="http://www.libressl.org/" rel="nofollow noopener"&gt;libressl.org&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, openssl, libressl, portable, openssh, security, linux, arc4random, intrinsic functions, rng, prng, status report, pkgng, openhttpd, relayd, httpd, web server, zfsguru, zfs, freebsd mastery, book, storage, ufs, geom, disks, presentation, talk, comparison, mandoc</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2014-04-2014-06.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>FreeBSD has gotten quite a lot done this quarter</li>
<li>Changes in the way release branches are supported - major releases will get at least five years over their lifespan</li>
<li>A new automounter is in the works, hoping to replace amd (which has some issues)</li>
<li>The CAM target layer and RPC stack have gotten some major optimization and speed boosts</li>
<li>Work on ZFSGuru continues, with a large status report specifically for that</li>
<li>The report also mentioned some new committers, both source and ports</li>
<li>It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show</li>
<li>"Foundation-sponsored work resulted in <strong>226 commits</strong> to FreeBSD over the April to June period"
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724094043" rel="nofollow noopener">A new OpenBSD HTTPD is born</a></h3>

<ul>
<li>Work has begun on a new HTTP daemon in the OpenBSD base system</li>
<li>A lot of people are <a href="http://www.reddit.com/r/BSD/comments/2b7azm/openbsd_gets_its_own_http_server/" rel="nofollow noopener">asking</a> "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?</li>
<li>Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)</li>
<li>It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter</li>
<li>This has the added benefit of the usual, easy-to-understand syntax and privilege separation </li>
<li>There's a very brief <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/httpd.8" rel="nofollow noopener">man page</a> online already</li>
<li>It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs</li>
<li>Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports-announce/2014-July/000084.html" rel="nofollow noopener">pkgng 1.3 announced</a></h3>

<ul>
<li>The newest version of FreeBSD's second generation <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package management system</a> has been released, with lots of new features</li>
<li>It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)</li>
<li>Lots of the code has been sandboxed for extra security</li>
<li>You'll probably notice some new changes to the UI too, making things more user friendly</li>
<li>A few days later <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=362996" rel="nofollow noopener">1.3.1</a> was released to fix a few small bugs, then <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363108" rel="nofollow noopener">1.3.2</a> shortly thereafter and <a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=363363" rel="nofollow noopener">1.3.3</a> yesterday
***</li>
</ul>

<h3><a href="http://twisteddaemon.com/post/92921205276/freebsd-installed-your-next-five-moves-should-be" rel="nofollow noopener">FreeBSD after-install security tasks</a></h3>

<ul>
<li>A number of people have written in to ask us "how do I secure my BSD box after I install it?"</li>
<li>With this blog post, hopefully most of their questions will finally be answered in detail</li>
<li>It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things</li>
<li>Not only does it just list things to do, but the post also does a good job of explaining why you should do them</li>
<li>Maybe we'll see some more posts in this series in the future
***</li>
</ul>

<h2>Interview - Brent Cook - <a href="mailto:bcook@openbsd.org" rel="nofollow noopener">bcook@openbsd.org</a> / <a href="https://twitter.com/busterbcook" rel="nofollow noopener">@busterbcook</a></h2>

<p>LibreSSL's portable version and development</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.tiltedwindmillpress.com/?product=freebsd-mastery-storage-essentials" rel="nofollow noopener">FreeBSD Mastery - Storage Essentials</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a>'s new book about the FreeBSD storage subsystems now has an early draft available</li>
<li>Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes</li>
<li>Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance</li>
<li>You'll get access to the completed (e)book when it's done if you buy the early draft</li>
<li>The suggested price is $8
***</li>
</ul>

<h3><a href="http://www.reddit.com/r/BSD/comments/2buea5/why_bsd_and_not_linux_or_why_linux_and_not_bsd/" rel="nofollow noopener">Why BSD and not Linux?</a></h3>

<ul>
<li>Yet another thread comes up asking why you should choose BSD over Linux or vice-versa</li>
<li>Lots of good responses from users of the various BSDs</li>
<li>Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."</li>
<li>And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."</li>
<li>Some other users share their switching experiences - worth a read
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">More g2k14 hackathon reports</a></h3>

<ul>
<li>Following up from last week's <a href="http://www.bsdnow.tv/episodes/2014_07_23-des_challenge_iv" rel="nofollow noopener">huge list</a> of hackathon reports, we have a few more</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140724161550" rel="nofollow noopener">Landry Breuil</a> spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140728122850" rel="nofollow noopener">Andrew Fresh</a> enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl</li>
<li><a href="http://undeadly.org/cgi?action=article&amp;sid=20140729070721" rel="nofollow noopener">Ted Unangst</a> did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth</li>
<li>Luckily we didn't have to cover 20 new ones this time!
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/07/mandoc-with-ingo-schwarze.html" rel="nofollow noopener">BSDTalk episode 243</a></h3>

<ul>
<li>The newest episode of <a href="http://www.bsdnow.tv/episodes/2014_03_05-bsd_now_vs_bsdtalk" rel="nofollow noopener">BSDTalk</a> is out, featuring an interview with Ingo Schwarze of the OpenBSD team</li>
<li>The main topic of discussion is mandoc, which some users might not be familiar with</li>
<li>mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)</li>
<li>We'll catch up to you soon, Will!
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xLRQytAZ" rel="nofollow noopener">Thomas writes in</a></li>
<li><a href="http://slexy.org/view/s21AYng20n" rel="nofollow noopener">Stephen writes in</a></li>
<li><a href="http://slexy.org/view/s2DwLRdQDS" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2E05L31BC" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s21Nmg3Jrk" rel="nofollow noopener">Bob Beck writes in</a> - and note the "Caution" section that was added to <a href="http://www.libressl.org/" rel="nofollow noopener">libressl.org</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
