<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 13 Jun 2026 23:58:20 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Smallwall”</title>
    <link>https://www.bsdnow.tv/tags/smallwall</link>
    <pubDate>Wed, 08 Jul 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>97: Big Network, SmallWall</title>
  <link>https://www.bsdnow.tv/97</link>
  <guid isPermaLink="false">8ae01f5e-8be5-4cbc-bb95-094f2d536681</guid>
  <pubDate>Wed, 08 Jul 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/8ae01f5e-8be5-4cbc-bb95-094f2d536681.mp3" length="56408980" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:18:20</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener"&gt;BSDCan and pkgsrcCon videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Even more BSDCan 2015 videos are slowly but surely making their way to the internet&lt;/li&gt;
&lt;li&gt;Nigel Williams, &lt;a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener"&gt;Multipath TCP for FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Stephen Bourne, &lt;a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener"&gt;Early days of Unix and design of sh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;John Criswell, &lt;a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener"&gt;Protecting FreeBSD with Secure Virtual Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Shany Michaely, &lt;a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener"&gt;Expanding RDMA capability over Ethernet in FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;John-Mark Gurney, &lt;a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener"&gt;Adding AES-ICM and AES-GCM to OpenCrypto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sevan Janiyan, &lt;a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener"&gt;Adventures in building&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener"&gt;open source software&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;And finally, &lt;a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener"&gt;the BSDCan 2015 closing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener"&gt;videos&lt;/a&gt; from this year's &lt;a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener"&gt;pkgsrcCon&lt;/a&gt; are also starting to appear online&lt;/li&gt;
&lt;li&gt;Sevan Janiyan, &lt;a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener"&gt;A year of pkgsrc 2014 - 2015&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pierre Pronchery, &lt;a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener"&gt;pkgsrc meets pkg-ng&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jonathan Perkin, &lt;a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener"&gt;pkgsrc at Joyent&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jörg Sonnenberger, &lt;a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener"&gt;pkg_install script framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Benny Siegert, &lt;a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener"&gt;New Features in BulkTracker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener"&gt;OPNsense 15.7 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OPNsense team has released version 15.7, almost exactly six months after &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;their initial debut&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server&lt;/li&gt;
&lt;li&gt;Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140419151959" rel="nofollow noopener"&gt;completely removed&lt;/a&gt; just over a year ago)&lt;/li&gt;
&lt;li&gt;The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed&lt;/li&gt;
&lt;li&gt;Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included&lt;/li&gt;
&lt;li&gt;Shortly afterwards, &lt;a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener"&gt;15.7.1&lt;/a&gt; was released with a few more small fixes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference 2015 Okinawa&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you liked &lt;a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener"&gt;last week's episode&lt;/a&gt; then you'll probably know what to expect with this one&lt;/li&gt;
&lt;li&gt;The NetBSD users group of Japan hit another open source conference, this time in Okinawa&lt;/li&gt;
&lt;li&gt;This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week&lt;/li&gt;
&lt;li&gt;We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://firstyear.id.au/entry/21" rel="nofollow noopener"&gt;OpenBSD BGP and VRFs&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"&lt;a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener"&gt;VRFs&lt;/a&gt;, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"&lt;/li&gt;
&lt;li&gt;This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness&lt;/li&gt;
&lt;li&gt;With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them&lt;/li&gt;
&lt;li&gt;The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues&lt;/li&gt;
&lt;li&gt;Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener"&gt;BSDCan talk on rdomains&lt;/a&gt; expands on the subject a bit more if you haven't seen it, as well as a few &lt;a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener"&gt;related&lt;/a&gt; &lt;a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener"&gt;posts&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Lee Sharp - &lt;a href="mailto:lee@smallwall.org" rel="nofollow noopener"&gt;lee@smallwall.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://smallwall.org" rel="nofollow noopener"&gt;SmallWall&lt;/a&gt;, a continuation of m0n0wall&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener"&gt;Solaris adopts more BSD goodies&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes&lt;/li&gt;
&lt;li&gt;They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls&lt;/li&gt;
&lt;li&gt;Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a &lt;a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener"&gt;second blog post&lt;/a&gt; up about their "SunSSH" fork&lt;/li&gt;
&lt;li&gt;Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that&lt;/li&gt;
&lt;li&gt;The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener"&gt;a third blog post&lt;/a&gt;, they talk about a new system call they're borrowing from OpenBSD, &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener"&gt;getentropy(2)&lt;/a&gt;, as well as the addition of &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener"&gt;arc4random&lt;/a&gt; to their libc&lt;/li&gt;
&lt;li&gt;With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming &lt;em&gt;better than us&lt;/em&gt;?&lt;/li&gt;
&lt;li&gt;Look forward to the upcoming "Solaris Now" podcast &lt;sub&gt;(not really)&lt;/sub&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener"&gt;EuroBSDCon 2015 talks and tutorials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published&lt;/li&gt;
&lt;li&gt;The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us&lt;/li&gt;
&lt;li&gt;It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course&lt;/li&gt;
&lt;li&gt;There are also &lt;a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener"&gt;a few tutorials&lt;/a&gt; planned for the event, some you've probably seen already and some you haven't&lt;/li&gt;
&lt;li&gt;Registration for the event will be opening very soon (likely this week or next)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener"&gt;Using ZFS replication to improve offsite backups&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data&lt;/li&gt;
&lt;li&gt;This article covers doing just that, but with a focus on making use of the replication capability&lt;/li&gt;
&lt;li&gt;It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it&lt;/li&gt;
&lt;li&gt;Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer&lt;/li&gt;
&lt;li&gt;Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them&lt;/li&gt;
&lt;li&gt;One thing the author didn't mention in his post: having an &lt;strong&gt;offline&lt;/strong&gt; copy of the data, ideally sealed in a safe place, is also important
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener"&gt;Block encryption in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;covered&lt;/a&gt; ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data&lt;/li&gt;
&lt;li&gt;This blog post takes you through the process of creating encrypted &lt;em&gt;containers&lt;/em&gt; in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem&lt;/li&gt;
&lt;li&gt;It goes through creating a file that looks like random data, pointing &lt;strong&gt;vnconfig&lt;/strong&gt; at it, setting up the crypto and finally using it as a fake storage device&lt;/li&gt;
&lt;li&gt;The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=391421" rel="nofollow noopener"&gt;Docker hits FreeBSD ports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The inevitable has happened, and an early FreeBSD port of docker is finally here &lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener"&gt;details and directions&lt;/a&gt; are available to read if you'd like to give it a try, as well as a list of which features work and which don't&lt;/li&gt;
&lt;li&gt;There was also some &lt;a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener"&gt;Hacker News discussion&lt;/a&gt; on the topic
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150708134520&amp;amp;mode=flat" rel="nofollow noopener"&gt;Microsoft donates to OpenSSH&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn&lt;/li&gt;
&lt;li&gt;With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor&lt;/li&gt;
&lt;li&gt;They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener"&gt;Joe writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener"&gt;Mike writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener"&gt;Randy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener"&gt;Tony writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener"&gt;Kevin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, smallwall, m0n0wall, opnsense, pfsense, router, mini-itx, apu, alix, soekris, pcengines, edgerouter, lite, encryption, containers, zfs, replication, docker</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener">BSDCan and pkgsrcCon videos</a></h3>

<ul>
<li>Even more BSDCan 2015 videos are slowly but surely making their way to the internet</li>
<li>Nigel Williams, <a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener">Multipath TCP for FreeBSD</a></li>
<li>Stephen Bourne, <a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener">Early days of Unix and design of sh</a></li>
<li>John Criswell, <a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener">Protecting FreeBSD with Secure Virtual Architecture</a></li>
<li>Shany Michaely, <a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener">Expanding RDMA capability over Ethernet in FreeBSD</a></li>
<li>John-Mark Gurney, <a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener">Adding AES-ICM and AES-GCM to OpenCrypto</a></li>
<li>Sevan Janiyan, <a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener">Adventures in building</a> <a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener">open source software</a></li>
<li>And finally, <a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener">the BSDCan 2015 closing</a></li>
<li>Some <a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener">videos</a> from this year's <a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon</a> are also starting to appear online</li>
<li>Sevan Janiyan, <a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener">A year of pkgsrc 2014 - 2015</a></li>
<li>Pierre Pronchery, <a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener">pkgsrc meets pkg-ng</a></li>
<li>Jonathan Perkin, <a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener">pkgsrc at Joyent</a></li>
<li>Jörg Sonnenberger, <a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener">pkg_install script framework</a></li>
<li>Benny Siegert, <a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener">New Features in BulkTracker</a></li>
<li>This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener">OPNsense 15.7 released</a></h3>

<ul>
<li>The OPNsense team has released version 15.7, almost exactly six months after <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">their initial debut</a></li>
<li>In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server</li>
<li>Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was <a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">completely removed</a> just over a year ago)</li>
<li>The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed</li>
<li>Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included</li>
<li>Shortly afterwards, <a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener">15.7.1</a> was released with a few more small fixes
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Okinawa</a></h3>

<ul>
<li>If you liked <a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener">last week's episode</a> then you'll probably know what to expect with this one</li>
<li>The NetBSD users group of Japan hit another open source conference, this time in Okinawa</li>
<li>This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week</li>
<li>We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***</li>
</ul>

<h3><a href="http://firstyear.id.au/entry/21" rel="nofollow noopener">OpenBSD BGP and VRFs</a></h3>

<ul>
<li>"<a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener">VRFs</a>, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"</li>
<li>This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness</li>
<li>With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them</li>
<li>The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues</li>
<li>Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here</li>
<li>The <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">BSDCan talk on rdomains</a> expands on the subject a bit more if you haven't seen it, as well as a few <a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener">related</a> <a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener">posts</a>
***</li>
</ul>

<h2>Interview - Lee Sharp - <a href="mailto:lee@smallwall.org" rel="nofollow noopener">lee@smallwall.org</a></h2>

<p><a href="http://smallwall.org" rel="nofollow noopener">SmallWall</a>, a continuation of m0n0wall</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener">Solaris adopts more BSD goodies</a></h3>

<ul>
<li>We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes</li>
<li>They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls</li>
<li>Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a <a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener">second blog post</a> up about their "SunSSH" fork</li>
<li>Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that</li>
<li>The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two</li>
<li>In <a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener">a third blog post</a>, they talk about a new system call they're borrowing from OpenBSD, <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener">getentropy(2)</a>, as well as the addition of <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener">arc4random</a> to their libc</li>
<li>With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming <em>better than us</em>?</li>
<li>Look forward to the upcoming "Solaris Now" podcast <sub>(not really)</sub>
***</li>
</ul>

<h3><a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener">EuroBSDCon 2015 talks and tutorials</a></h3>

<ul>
<li>This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published</li>
<li>The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us</li>
<li>It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course</li>
<li>There are also <a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener">a few tutorials</a> planned for the event, some you've probably seen already and some you haven't</li>
<li>Registration for the event will be opening very soon (likely this week or next)
***</li>
</ul>

<h3><a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener">Using ZFS replication to improve offsite backups</a></h3>

<ul>
<li>If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data</li>
<li>This article covers doing just that, but with a focus on making use of the replication capability</li>
<li>It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it</li>
<li>Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer</li>
<li>Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them</li>
<li>One thing the author didn't mention in his post: having an <strong>offline</strong> copy of the data, ideally sealed in a safe place, is also important
***</li>
</ul>

<h3><a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener">Block encryption in OpenBSD</a></h3>

<ul>
<li>We've <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">covered</a> ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data</li>
<li>This blog post takes you through the process of creating encrypted <em>containers</em> in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem</li>
<li>It goes through creating a file that looks like random data, pointing <strong>vnconfig</strong> at it, setting up the crypto and finally using it as a fake storage device</li>
<li>The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=391421" rel="nofollow noopener">Docker hits FreeBSD ports</a></h3>

<ul>
<li>The inevitable has happened, and an early FreeBSD port of docker is finally here </li>
<li>Some <a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener">details and directions</a> are available to read if you'd like to give it a try, as well as a list of which features work and which don't</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener">Hacker News discussion</a> on the topic
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520&amp;mode=flat" rel="nofollow noopener">Microsoft donates to OpenSSH</a></h3>

<ul>
<li>We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn</li>
<li>With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor</li>
<li>They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener">Joe writes in</a></li>
<li><a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener">Tony writes in</a></li>
<li><a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener">BSDCan and pkgsrcCon videos</a></h3>

<ul>
<li>Even more BSDCan 2015 videos are slowly but surely making their way to the internet</li>
<li>Nigel Williams, <a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener">Multipath TCP for FreeBSD</a></li>
<li>Stephen Bourne, <a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener">Early days of Unix and design of sh</a></li>
<li>John Criswell, <a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener">Protecting FreeBSD with Secure Virtual Architecture</a></li>
<li>Shany Michaely, <a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener">Expanding RDMA capability over Ethernet in FreeBSD</a></li>
<li>John-Mark Gurney, <a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener">Adding AES-ICM and AES-GCM to OpenCrypto</a></li>
<li>Sevan Janiyan, <a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener">Adventures in building</a> <a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener">open source software</a></li>
<li>And finally, <a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener">the BSDCan 2015 closing</a></li>
<li>Some <a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener">videos</a> from this year's <a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon</a> are also starting to appear online</li>
<li>Sevan Janiyan, <a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener">A year of pkgsrc 2014 - 2015</a></li>
<li>Pierre Pronchery, <a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener">pkgsrc meets pkg-ng</a></li>
<li>Jonathan Perkin, <a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener">pkgsrc at Joyent</a></li>
<li>Jörg Sonnenberger, <a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener">pkg_install script framework</a></li>
<li>Benny Siegert, <a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener">New Features in BulkTracker</a></li>
<li>This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener">OPNsense 15.7 released</a></h3>

<ul>
<li>The OPNsense team has released version 15.7, almost exactly six months after <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">their initial debut</a></li>
<li>In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server</li>
<li>Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was <a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">completely removed</a> just over a year ago)</li>
<li>The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed</li>
<li>Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included</li>
<li>Shortly afterwards, <a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener">15.7.1</a> was released with a few more small fixes
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Okinawa</a></h3>

<ul>
<li>If you liked <a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener">last week's episode</a> then you'll probably know what to expect with this one</li>
<li>The NetBSD users group of Japan hit another open source conference, this time in Okinawa</li>
<li>This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week</li>
<li>We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***</li>
</ul>

<h3><a href="http://firstyear.id.au/entry/21" rel="nofollow noopener">OpenBSD BGP and VRFs</a></h3>

<ul>
<li>"<a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener">VRFs</a>, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"</li>
<li>This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness</li>
<li>With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them</li>
<li>The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues</li>
<li>Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here</li>
<li>The <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">BSDCan talk on rdomains</a> expands on the subject a bit more if you haven't seen it, as well as a few <a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener">related</a> <a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener">posts</a>
***</li>
</ul>

<h2>Interview - Lee Sharp - <a href="mailto:lee@smallwall.org" rel="nofollow noopener">lee@smallwall.org</a></h2>

<p><a href="http://smallwall.org" rel="nofollow noopener">SmallWall</a>, a continuation of m0n0wall</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener">Solaris adopts more BSD goodies</a></h3>

<ul>
<li>We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes</li>
<li>They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls</li>
<li>Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a <a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener">second blog post</a> up about their "SunSSH" fork</li>
<li>Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that</li>
<li>The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two</li>
<li>In <a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener">a third blog post</a>, they talk about a new system call they're borrowing from OpenBSD, <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener">getentropy(2)</a>, as well as the addition of <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener">arc4random</a> to their libc</li>
<li>With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming <em>better than us</em>?</li>
<li>Look forward to the upcoming "Solaris Now" podcast <sub>(not really)</sub>
***</li>
</ul>

<h3><a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener">EuroBSDCon 2015 talks and tutorials</a></h3>

<ul>
<li>This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published</li>
<li>The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us</li>
<li>It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course</li>
<li>There are also <a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener">a few tutorials</a> planned for the event, some you've probably seen already and some you haven't</li>
<li>Registration for the event will be opening very soon (likely this week or next)
***</li>
</ul>

<h3><a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener">Using ZFS replication to improve offsite backups</a></h3>

<ul>
<li>If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data</li>
<li>This article covers doing just that, but with a focus on making use of the replication capability</li>
<li>It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it</li>
<li>Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer</li>
<li>Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them</li>
<li>One thing the author didn't mention in his post: having an <strong>offline</strong> copy of the data, ideally sealed in a safe place, is also important
***</li>
</ul>

<h3><a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener">Block encryption in OpenBSD</a></h3>

<ul>
<li>We've <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">covered</a> ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data</li>
<li>This blog post takes you through the process of creating encrypted <em>containers</em> in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem</li>
<li>It goes through creating a file that looks like random data, pointing <strong>vnconfig</strong> at it, setting up the crypto and finally using it as a fake storage device</li>
<li>The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=391421" rel="nofollow noopener">Docker hits FreeBSD ports</a></h3>

<ul>
<li>The inevitable has happened, and an early FreeBSD port of docker is finally here </li>
<li>Some <a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener">details and directions</a> are available to read if you'd like to give it a try, as well as a list of which features work and which don't</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener">Hacker News discussion</a> on the topic
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520&amp;mode=flat" rel="nofollow noopener">Microsoft donates to OpenSSH</a></h3>

<ul>
<li>We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn</li>
<li>With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor</li>
<li>They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener">Joe writes in</a></li>
<li><a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener">Tony writes in</a></li>
<li><a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>94: Builder's Insurance</title>
  <link>https://www.bsdnow.tv/94</link>
  <guid isPermaLink="false">62d29419-94fa-4252-89a9-581546c7e61d</guid>
  <pubDate>Wed, 17 Jun 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/62d29419-94fa-4252-89a9-581546c7e61d.mp3" length="61384180" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:25:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener"&gt;BSDCan 2015 videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSDCan just ended last week, but some of the BSD-related presentation videos are already online&lt;/li&gt;
&lt;li&gt;Allan Jude, &lt;a href="https://www.youtube.com/watch?v=8l6bhKIDecg" rel="nofollow noopener"&gt;UCL for FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andrew Cagney, &lt;a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" rel="nofollow noopener"&gt;What happens when a dwarf and a daemon start dancing by the light of the silvery moon?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Andy Tanenbaum, &lt;a href="https://www.youtube.com/watch?v=0pebP891V0c" rel="nofollow noopener"&gt;A reimplementation of NetBSD&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" rel="nofollow noopener"&gt;using a MicroKernel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Brooks Davis, &lt;a href="https://www.youtube.com/watch?v=DwCg-51vFAs" rel="nofollow noopener"&gt;CheriBSD: A research fork of FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Giuseppe Lettieri, &lt;a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" rel="nofollow noopener"&gt;Even faster VM networking with virtual passthrough&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Joseph Mingrone, &lt;a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" rel="nofollow noopener"&gt;Molecular Evolution, Genomic Analysis and FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Olivier Cochard-Labbe, &lt;a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" rel="nofollow noopener"&gt;Large-scale plug&amp;amp;play x86 network appliance deployment over Internet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Peter Hessler, &lt;a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener"&gt;Using routing domains / routing tables in a production network&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ryan Lortie, &lt;a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" rel="nofollow noopener"&gt;a stitch in time: jhbuild&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Ted Unangst, &lt;a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" rel="nofollow noopener"&gt;signify: Securing OpenBSD From Us To You&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Many more still to come...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://pid1.com/posts/post1.html" rel="nofollow noopener"&gt;Documenting my BSD experience&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try&lt;/li&gt;
&lt;li&gt;"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."&lt;/li&gt;
&lt;li&gt;In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks&lt;/li&gt;
&lt;li&gt;The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)&lt;/li&gt;
&lt;li&gt;You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into&lt;/li&gt;
&lt;li&gt;He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon&lt;/li&gt;
&lt;li&gt;His &lt;a href="http://pid1.com/posts/post2.html" rel="nofollow noopener"&gt;second post&lt;/a&gt; explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box&lt;/li&gt;
&lt;li&gt;After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing&lt;/li&gt;
&lt;li&gt;All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand&lt;/li&gt;
&lt;li&gt;Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://github.com/pcbsd/hardenedBSD-stable" rel="nofollow noopener"&gt;PC-BSD tries HardenedBSD builds&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated&lt;/li&gt;
&lt;li&gt;They're not the first major FreeBSD-based project to offer an alternate build - OPNsense &lt;a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener"&gt;did that&lt;/a&gt; a few weeks ago - but this might open the door for more projects to give it a try as well&lt;/li&gt;
&lt;li&gt;With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have&lt;/li&gt;
&lt;li&gt;Time will tell if more projects and products like FreeNAS might be interested too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=143423172522625&amp;amp;w=2" rel="nofollow noopener"&gt;C-states in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;People who run BSD on their notebooks, you'll want to pay attention to this one&lt;/li&gt;
&lt;li&gt;OpenBSD has recently committed some ACPI improvements for &lt;a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" rel="nofollow noopener"&gt;deep C-states&lt;/a&gt;, enabling the processor to enter a low-power mode&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/StevenUniq/status/610586711358316545" rel="nofollow noopener"&gt;According&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143430996602802&amp;amp;w=2" rel="nofollow noopener"&gt;to a&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143429914700826&amp;amp;w=2" rel="nofollow noopener"&gt;few users&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143425943026225&amp;amp;w=2" rel="nofollow noopener"&gt;so far&lt;/a&gt;, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life&lt;/li&gt;
&lt;li&gt;If you're running OpenBSD -current on a laptop, try out the latest snapshot and &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=143423391222952&amp;amp;w=2" rel="nofollow noopener"&gt;report back&lt;/a&gt; with your findings
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference 2015 Hokkaido&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference&lt;/li&gt;
&lt;li&gt;As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)&lt;/li&gt;
&lt;li&gt;We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Marc Espie - &lt;a href="mailto:espie@openbsd.org" rel="nofollow noopener"&gt;espie@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/espie_openbsd" rel="nofollow noopener"&gt;@espie_openbsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=143051151521627&amp;amp;w=2" rel="nofollow noopener"&gt;Recent&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=143151777209226&amp;amp;w=2" rel="nofollow noopener"&gt;improvements&lt;/a&gt; to OpenBSD's &lt;a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener"&gt;dpb&lt;/a&gt; tool&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/mist64/xhyve/blob/master/README.md" rel="nofollow noopener"&gt;Introducing xhyve, bhyve on OS X&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS&lt;/li&gt;
&lt;li&gt;As the name "xhyve" might imply, it's a port of bhyve to Mac OS X &lt;/li&gt;
&lt;li&gt;Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future&lt;/li&gt;
&lt;li&gt;It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer&lt;/li&gt;
&lt;li&gt;There are also &lt;a href="http://www.pagetable.com/?p=831" rel="nofollow noopener"&gt;a few examples&lt;/a&gt; on how to use it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" rel="nofollow noopener"&gt;4K displays on DragonFlyBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine&lt;/li&gt;
&lt;li&gt;Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas&lt;/li&gt;
&lt;li&gt;Some GUI applications might look weird on such a huge resolution, &lt;/li&gt;
&lt;li&gt;HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" rel="nofollow noopener"&gt;Sandboxing port daemons on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment&lt;/li&gt;
&lt;li&gt;This blog post uses a mumble server as an example, but you can apply it to &lt;em&gt;any&lt;/em&gt; service from ports that doesn't chroot by default&lt;/li&gt;
&lt;li&gt;It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it&lt;/li&gt;
&lt;li&gt;With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" rel="nofollow noopener"&gt;SmallWall 1.8.2 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SmallWall is a relatively new BSD-based project that we've never covered before&lt;/li&gt;
&lt;li&gt;It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits&lt;/li&gt;
&lt;li&gt;They've just released &lt;a href="http://www.smallwall.org/download.html" rel="nofollow noopener"&gt;the first official version&lt;/a&gt;, so you can give it a try now&lt;/li&gt;
&lt;li&gt;If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21gRTNnk7" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2DdiMvELg" rel="nofollow noopener"&gt;Brian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2h4ZS6SMd" rel="nofollow noopener"&gt;Dan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20kA1jeXY" rel="nofollow noopener"&gt;Joel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2wJ9HP1bs" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, dpb, poudriere, pbulk, packages, ports, distributed, bsdcan, pf, zfs, opnsense, pfsense, hardenedbsd, aslr, smallwall, m0n0wall, xhyve, bhyve</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener">BSDCan 2015 videos</a></h3>

<ul>
<li>BSDCan just ended last week, but some of the BSD-related presentation videos are already online</li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=8l6bhKIDecg" rel="nofollow noopener">UCL for FreeBSD</a></li>
<li>Andrew Cagney, <a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" rel="nofollow noopener">What happens when a dwarf and a daemon start dancing by the light of the silvery moon?</a></li>
<li>Andy Tanenbaum, <a href="https://www.youtube.com/watch?v=0pebP891V0c" rel="nofollow noopener">A reimplementation of NetBSD</a> <a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" rel="nofollow noopener">using a MicroKernel</a></li>
<li>Brooks Davis, <a href="https://www.youtube.com/watch?v=DwCg-51vFAs" rel="nofollow noopener">CheriBSD: A research fork of FreeBSD</a></li>
<li>Giuseppe Lettieri, <a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" rel="nofollow noopener">Even faster VM networking with virtual passthrough</a></li>
<li>Joseph Mingrone, <a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" rel="nofollow noopener">Molecular Evolution, Genomic Analysis and FreeBSD</a></li>
<li>Olivier Cochard-Labbe, <a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" rel="nofollow noopener">Large-scale plug&amp;play x86 network appliance deployment over Internet</a></li>
<li>Peter Hessler, <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">Using routing domains / routing tables in a production network</a></li>
<li>Ryan Lortie, <a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" rel="nofollow noopener">a stitch in time: jhbuild</a></li>
<li>Ted Unangst, <a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" rel="nofollow noopener">signify: Securing OpenBSD From Us To You</a></li>
<li>Many more still to come...
***</li>
</ul>

<h3><a href="http://pid1.com/posts/post1.html" rel="nofollow noopener">Documenting my BSD experience</a></h3>

<ul>
<li>Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try</li>
<li>"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."</li>
<li>In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks</li>
<li>The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)</li>
<li>You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into</li>
<li>He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon</li>
<li>His <a href="http://pid1.com/posts/post2.html" rel="nofollow noopener">second post</a> explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box</li>
<li>After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing</li>
<li>All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand</li>
<li>Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/hardenedBSD-stable" rel="nofollow noopener">PC-BSD tries HardenedBSD builds</a></h3>

<ul>
<li>The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated</li>
<li>They're not the first major FreeBSD-based project to offer an alternate build - OPNsense <a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener">did that</a> a few weeks ago - but this might open the door for more projects to give it a try as well</li>
<li>With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have</li>
<li>Time will tell if more projects and products like FreeNAS might be interested too
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143423172522625&amp;w=2" rel="nofollow noopener">C-states in OpenBSD</a></h3>

<ul>
<li>People who run BSD on their notebooks, you'll want to pay attention to this one</li>
<li>OpenBSD has recently committed some ACPI improvements for <a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" rel="nofollow noopener">deep C-states</a>, enabling the processor to enter a low-power mode</li>
<li><a href="https://twitter.com/StevenUniq/status/610586711358316545" rel="nofollow noopener">According</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143430996602802&amp;w=2" rel="nofollow noopener">to a</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143429914700826&amp;w=2" rel="nofollow noopener">few users</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143425943026225&amp;w=2" rel="nofollow noopener">so far</a>, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life</li>
<li>If you're running OpenBSD -current on a laptop, try out the latest snapshot and <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143423391222952&amp;w=2" rel="nofollow noopener">report back</a> with your findings
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Hokkaido</a></h3>

<ul>
<li>The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference</li>
<li>As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)</li>
<li>We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p><a href="https://www.marc.info/?l=openbsd-ports&amp;m=143051151521627&amp;w=2" rel="nofollow noopener">Recent</a> <a href="https://www.marc.info/?l=openbsd-ports&amp;m=143151777209226&amp;w=2" rel="nofollow noopener">improvements</a> to OpenBSD's <a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">dpb</a> tool</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/mist64/xhyve/blob/master/README.md" rel="nofollow noopener">Introducing xhyve, bhyve on OS X</a></h3>

<ul>
<li>We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS</li>
<li>As the name "xhyve" might imply, it's a port of bhyve to Mac OS X </li>
<li>Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future</li>
<li>It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer</li>
<li>There are also <a href="http://www.pagetable.com/?p=831" rel="nofollow noopener">a few examples</a> on how to use it
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" rel="nofollow noopener">4K displays on DragonFlyBSD</a></h3>

<ul>
<li>If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine</li>
<li>Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas</li>
<li>Some GUI applications might look weird on such a huge resolution, </li>
<li>HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***</li>
</ul>

<h3><a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" rel="nofollow noopener">Sandboxing port daemons on OpenBSD</a></h3>

<ul>
<li>We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment</li>
<li>This blog post uses a mumble server as an example, but you can apply it to <em>any</em> service from ports that doesn't chroot by default</li>
<li>It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it</li>
<li>With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***</li>
</ul>

<h3><a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" rel="nofollow noopener">SmallWall 1.8.2 released</a></h3>

<ul>
<li>SmallWall is a relatively new BSD-based project that we've never covered before</li>
<li>It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits</li>
<li>They've just released <a href="http://www.smallwall.org/download.html" rel="nofollow noopener">the first official version</a>, so you can give it a try now</li>
<li>If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21gRTNnk7" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DdiMvELg" rel="nofollow noopener">Brian writes in</a></li>
<li><a href="http://slexy.org/view/s2h4ZS6SMd" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s20kA1jeXY" rel="nofollow noopener">Joel writes in</a></li>
<li><a href="http://slexy.org/view/s2wJ9HP1bs" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be chatting with Marc Espie. He's recently added some additional security measures to dpb, OpenBSD's package building tool, and we'll find out why they're so important. We've also got all this week's news, answers to your emails and even a BSDCan wrap-up, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2015/schedule/" rel="nofollow noopener">BSDCan 2015 videos</a></h3>

<ul>
<li>BSDCan just ended last week, but some of the BSD-related presentation videos are already online</li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=8l6bhKIDecg" rel="nofollow noopener">UCL for FreeBSD</a></li>
<li>Andrew Cagney, <a href="https://www.youtube.com/watch?v=XDIcD4LR5HE" rel="nofollow noopener">What happens when a dwarf and a daemon start dancing by the light of the silvery moon?</a></li>
<li>Andy Tanenbaum, <a href="https://www.youtube.com/watch?v=0pebP891V0c" rel="nofollow noopener">A reimplementation of NetBSD</a> <a href="https://www.youtube.com/watch?v=Bu1JuwVfYTc" rel="nofollow noopener">using a MicroKernel</a></li>
<li>Brooks Davis, <a href="https://www.youtube.com/watch?v=DwCg-51vFAs" rel="nofollow noopener">CheriBSD: A research fork of FreeBSD</a></li>
<li>Giuseppe Lettieri, <a href="https://www.youtube.com/watch?v=Lo6wDCapo4k" rel="nofollow noopener">Even faster VM networking with virtual passthrough</a></li>
<li>Joseph Mingrone, <a href="https://www.youtube.com/watch?v=K2pnf1YcMTY" rel="nofollow noopener">Molecular Evolution, Genomic Analysis and FreeBSD</a></li>
<li>Olivier Cochard-Labbe, <a href="https://www.youtube.com/watch?v=6jhSvdnu4k0" rel="nofollow noopener">Large-scale plug&amp;play x86 network appliance deployment over Internet</a></li>
<li>Peter Hessler, <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">Using routing domains / routing tables in a production network</a></li>
<li>Ryan Lortie, <a href="https://www.youtube.com/watch?v=YSVFnM3_2Ik" rel="nofollow noopener">a stitch in time: jhbuild</a></li>
<li>Ted Unangst, <a href="https://www.youtube.com/watch?v=9R5s3l-0wh0" rel="nofollow noopener">signify: Securing OpenBSD From Us To You</a></li>
<li>Many more still to come...
***</li>
</ul>

<h3><a href="http://pid1.com/posts/post1.html" rel="nofollow noopener">Documenting my BSD experience</a></h3>

<ul>
<li>Increasingly common scenario: a long-time Linux user (since the mid-90s) decides it's finally time to give BSD a try</li>
<li>"That night I came home, I had been trying to find out everything I could about BSD and I watched many videos, read forums, etc. One of the shows I found was BSD Now. I saw that they helped people and answered questions, so I decided to write in."</li>
<li>In this ongoing series of blog posts, a user named Michael writes about his initial experiences with trying different BSDs for some different tasks</li>
<li>The first post covers ZFS on FreeBSD, used to build a file server for his house (and of course he lists the hardware, if you're into that)</li>
<li>You get a glimpse of a brand new user trying things out, learning how great ZFS-based RAID arrays are and even some of the initial hurdles someone could run into</li>
<li>He's also looking to venture into the realm of replacing some of his VMs with jails and bhyve soon</li>
<li>His <a href="http://pid1.com/posts/post2.html" rel="nofollow noopener">second post</a> explores replacing the firewall on his self-described "over complicated home network" with an OpenBSD box</li>
<li>After going from ipfwadmin to ipchains to iptables, not even making it to nftables, he found the simple PF syntax to be really refreshing</li>
<li>All the tools for his networking needs, the majority of which are in the base system, worked quickly and were easy to understand</li>
<li>Getting to hear experiences like this are very important - they show areas where all the BSD developers' hard work has paid off, but can also let us know where we need to improve
***</li>
</ul>

<h3><a href="https://github.com/pcbsd/hardenedBSD-stable" rel="nofollow noopener">PC-BSD tries HardenedBSD builds</a></h3>

<ul>
<li>The PC-BSD team has created a new branch of their git repo with the HardenedBSD ASLR patches integrated</li>
<li>They're not the first major FreeBSD-based project to offer an alternate build - OPNsense <a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener">did that</a> a few weeks ago - but this might open the door for more projects to give it a try as well</li>
<li>With Personacrypt, OpenNTPD, LibreSSL and recent Tor integration through the tools, these additional memory protections will offer PC-BSD users even more security that a default FreeBSD install won't have</li>
<li>Time will tell if more projects and products like FreeNAS might be interested too
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143423172522625&amp;w=2" rel="nofollow noopener">C-states in OpenBSD</a></h3>

<ul>
<li>People who run BSD on their notebooks, you'll want to pay attention to this one</li>
<li>OpenBSD has recently committed some ACPI improvements for <a href="http://www.hardwaresecrets.com/article/Everything-You-Need-to-Know-About-the-CPU-C-States-Power-Saving-Modes/611" rel="nofollow noopener">deep C-states</a>, enabling the processor to enter a low-power mode</li>
<li><a href="https://twitter.com/StevenUniq/status/610586711358316545" rel="nofollow noopener">According</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143430996602802&amp;w=2" rel="nofollow noopener">to a</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143429914700826&amp;w=2" rel="nofollow noopener">few users</a> <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143425943026225&amp;w=2" rel="nofollow noopener">so far</a>, the change has resulted in dramatically lower CPU temperatures on their laptops, as well as much better battery life</li>
<li>If you're running OpenBSD -current on a laptop, try out the latest snapshot and <a href="https://www.marc.info/?l=openbsd-misc&amp;m=143423391222952&amp;w=2" rel="nofollow noopener">report back</a> with your findings
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/06/13/msg000687.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Hokkaido</a></h3>

<ul>
<li>The Japanese NetBSD users group never sleeps, and they've hit yet another open source conference</li>
<li>As is usually the case, lots of strange machines on display were running none other than NetBSD (though it was mostly ARM this time)</li>
<li>We'll be having one of these guys on the show next week to discuss some of the lesser-known NetBSD platforms
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p><a href="https://www.marc.info/?l=openbsd-ports&amp;m=143051151521627&amp;w=2" rel="nofollow noopener">Recent</a> <a href="https://www.marc.info/?l=openbsd-ports&amp;m=143151777209226&amp;w=2" rel="nofollow noopener">improvements</a> to OpenBSD's <a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">dpb</a> tool</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/mist64/xhyve/blob/master/README.md" rel="nofollow noopener">Introducing xhyve, bhyve on OS X</a></h3>

<ul>
<li>We've talked about FreeBSD's "bhyve" hypervisor a lot on the show, and now it's been ported to another OS</li>
<li>As the name "xhyve" might imply, it's a port of bhyve to Mac OS X </li>
<li>Currently it only has support for virtualizing a few Linux distributions, but more guest systems can be added in the future</li>
<li>It runs entirely in userspace, and has no extra requirements beyond OS X 10.10 or newer</li>
<li>There are also <a href="http://www.pagetable.com/?p=831" rel="nofollow noopener">a few examples</a> on how to use it
***</li>
</ul>

<h3><a href="http://www.dragonflybsd.org/docs/newhandbook/docs/newhandbook/4KDisplays/" rel="nofollow noopener">4K displays on DragonFlyBSD</a></h3>

<ul>
<li>If you've been using DragonFly as a desktop, maybe with those nice Broadwell graphics, you'll be pleased to know that 4K displays work just fine</li>
<li>Matthew Dillon wrote up a wiki page about some of the specifics, including a couple gotchas</li>
<li>Some GUI applications might look weird on such a huge resolution, </li>
<li>HDMI ports are mostly limited to a 30Hz refresh rate, and there are slightly steeper hardware requirements for a smooth experience
***</li>
</ul>

<h3><a href="http://coderinaworldofcode.blogspot.com/2015/06/chrooting-mumble-server-on-openbsd.html" rel="nofollow noopener">Sandboxing port daemons on OpenBSD</a></h3>

<ul>
<li>We talked about different containment methods last week, and mentioned that a lot of the daemons in OpenBSD's base as chrooted by default - things from ports or packages don't always get the same treatment</li>
<li>This blog post uses a mumble server as an example, but you can apply it to <em>any</em> service from ports that doesn't chroot by default</li>
<li>It goes through the process of manually building a sandbox with all the libraries you'll need to run the daemon, and this setup will even wipe and refresh the chroot every time you restart it</li>
<li>With a few small changes, similar tricks could be done on the other BSDs as well - everybody has chroots
***</li>
</ul>

<h3><a href="http://smallwall.freeforums.net/thread/44/version-1-8-2-released" rel="nofollow noopener">SmallWall 1.8.2 released</a></h3>

<ul>
<li>SmallWall is a relatively new BSD-based project that we've never covered before</li>
<li>It's an attempt to keep the old m0n0wall codebase going, and appears to have started around the time m0n0wall called it quits</li>
<li>They've just released <a href="http://www.smallwall.org/download.html" rel="nofollow noopener">the first official version</a>, so you can give it a try now</li>
<li>If you're interested in learning more about SmallWall, the lead developer just might be on the show in a few weeks...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21gRTNnk7" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2DdiMvELg" rel="nofollow noopener">Brian writes in</a></li>
<li><a href="http://slexy.org/view/s2h4ZS6SMd" rel="nofollow noopener">Dan writes in</a></li>
<li><a href="http://slexy.org/view/s20kA1jeXY" rel="nofollow noopener">Joel writes in</a></li>
<li><a href="http://slexy.org/view/s2wJ9HP1bs" rel="nofollow noopener">Steve writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
