- pf_enable=YES in /etc/rc.conf.
- vi /etc/pf.conf. keep state is by default.
- reboot. then pf should be available now.
Friday, February 19, 2016
running pf on AWS
There's only FreeBSD AMI available on AWS cloud service currently. Therefore we can get it directly from Market Place if we want to run pf or other related services.
Tuesday, August 18, 2015
opensmtpd setup
mailq to view queue
smtpctl monitor to view realtime status
tail -f /var/log/maillog to view realtime logs
Tuesday, August 4, 2015
ports ∴ sysutils/coreutils
GNU coreutils supports utf8, which mostly not in the base system.
http://ports.su/sysutils/coreutils
quickly removes all packages
http://www.openbsd.org/faq/upgrade37.html
To quickly remove all packages from your system:
pkg_delete -q /var/db/pkg/*
Friday, May 8, 2015
compiling ffmpeg on OpenBSD
1) Install required packages like nasm, etc, following the CentOS guide below:
https://trac.ffmpeg.org/wiki/CompilationGuide/Centos
2) Install git, gmake, as well as x264, for H.264 encoding feature:
# pkg_add -v git gmake x264
3) check out the latest source:
$ git clone git://source.ffmpeg.org/ffmpeg.git ffmpeg
https://trac.ffmpeg.org/wiki/CompilationGuide/Centos
2) Install git, gmake, as well as x264, for H.264 encoding feature:
# pkg_add -v git gmake x264
3) check out the latest source:
$ git clone git://source.ffmpeg.org/ffmpeg.git ffmpeg
4) cd ffmpeg; ./configure --enable-gpl --enable-libx264 ; gmake .
Monday, November 3, 2014
fvwm local setup
REF: Doing ls -a shows the dot-files, too, and I see that there is a file called .fvwmrc in /usr/X11R6/lib/X11/fvwm/.
http://blogs.dailynews.com/click/2008/04/10/configuring-fvwm-in-openbsd-an/
xterm setup & alternatives
xterm alternatives: gnome-terminal, xfce4-terminal, konsole. xterm can be launched with -fg grey -bg black -font 10x20 to change colors.
REF:
https://mkaz.com/2010/04/04/xterm-colors/
http://docstore.mik.ua/orelly/unix3/upt/ch05_18.htm
Tuesday, October 28, 2014
tcpwrappers replacement
tcpwrappers moved out from OpenBSD 5.6, which can be implemented similarly by AllowUsers in sshd_config to restrict users and ip range.
Wednesday, October 22, 2014
Compile Wireshark on OpenBSD
Wireshark (older version, say 1.0.0) can be compiled on OpenBSD (--with-krb5=no) following this article: http://cromwell-intl.com/linux/compiling-wireshark-on-openbsd.html .
Sunday, October 12, 2014
OpenBSD upgrade with firmware
upgrading with bsd.rd can utilize firmware installed previously! then fw_update will download proper updates after system upgrade.
Sunday, December 15, 2013
HiR's Secure OpenBSD, Apache, MySQL and PHP Guide
Install php-mysql and mysql-server. This will install all necessary dependencies, including php, libiconv and several perl modules needed by the MySQL scripts.
$ sudo pkg_add php-mysql mysql-server
Ambiguous: choose package for php-mysql
a 0:
1: php-mysql-5.2.17p16
2: php-mysql-5.3.27
Your choice: 2
Ambiguous: choose dependency for php-mysql-5.3.27:
a 0: php-5.3.27
1: php-5.3.27-ap2
Your choice: 0
REF: http://www.h-i-r.net/p/hirs-secure-openbsd-apache-mysql-and.html
Monday, October 7, 2013
Match Address for root login
# vi /etc/ssh/sshd_config
Match Address 127.0.0.1
PermitRootLogin yes
REF: http://blog.dhampir.no/content/ssh-how-to-permit-root-login-only-from-local-network-ip
Match Address 127.0.0.1
PermitRootLogin yes
REF: http://blog.dhampir.no/content/ssh-how-to-permit-root-login-only-from-local-network-ip
Tuesday, September 10, 2013
install m:tier thin client
0) Download the thin client python code:
http://www.mtier.org/products/thin-client/
1) install from pkg_add: gtk+3 , python3.
2) install from src: pycairo, pygobject .
PYTHON=python3.2 ./configure
Makefile err may need to be corrected manually.
3) modify /etc/X11/xinit/xinitrc for startx automatically.
p.s. *.pc files for pkg-config need to be linked to /usr/lib/pkg-config .
Sunday, June 30, 2013
snmpd setup (renewed)
1) edit /etc/snmpd.conf and modify listen_addr
2) enable snmpd in /etc/rc.conf on startup
3) apply access control via /etc/pf.conf
2) enable snmpd in /etc/rc.conf on startup
3) apply access control via /etc/pf.conf
Tuesday, May 7, 2013
Reverse ftp-proxy setup
use ftp-proxy -R internal.server.ip -D7 -v can easily setup a reverse FTP proxy on OpenBSD.
Remember to allow packet forwarding in sysctl.conf, and also turn on the ftp-proxy anchor in pf.conf.
Remember to allow packet forwarding in sysctl.conf, and also turn on the ftp-proxy anchor in pf.conf.
Thursday, April 25, 2013
OpenBSD on USB drive with boot loader
if you install OpenBSD on a USB drive but cannot boot from it, you may try install GAG boot loader into the MBR. Remember to make your USB drive the first boot disk because GAG can only install to the first drive!
Monday, April 22, 2013
running scim input method with built-in fvwm
1) edit ~/.xsession
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
/usr/X11R6/bin/xterm &
exec dbus-launch /usr/X11R6/bin/fvwm
2) Exit and login again via xdm.
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
/usr/X11R6/bin/xterm &
exec dbus-launch /usr/X11R6/bin/fvwm
2) Exit and login again via xdm.
Saturday, April 20, 2013
install OpenBSD on USB drive
1) if you want to keep a FAT partition for using on Windows, make the FAT partition the first one, otherwise Windows cannot read it.
2) Install OpenBSD on the selected USB drive as the normal installation process. Remember to make the OpenBSD MBR active, or use tools such as Linux GParted to flag it as boot.
3) Soft update set in /etc/fstab could make I/O much faster: rw,softdep.
REFERENCE:
http://openbsd.org/faq/faq14.html#flashmemLive
http://openbsd.org/faq/faq14.html#flashmemBoot
http://openbsd.org/faq/faq14.html#SoftUpdates
2) Install OpenBSD on the selected USB drive as the normal installation process. Remember to make the OpenBSD MBR active, or use tools such as Linux GParted to flag it as boot.
3) Soft update set in /etc/fstab could make I/O much faster: rw,softdep.
REFERENCE:
http://openbsd.org/faq/faq14.html#flashmemLive
http://openbsd.org/faq/faq14.html#flashmemBoot
http://openbsd.org/faq/faq14.html#SoftUpdates
Friday, April 12, 2013
icewm workstation with chinese input
1) pkg_add icewm firefox scim-chewing gnome-terminal
2) edit ~/.xsession for normal user:
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
exec dbus-launch icewm-session
3) login from xdm with normal user, then all done!
4) if using startx, then edit ~/.xinitrc instead.
2) edit ~/.xsession for normal user:
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
exec dbus-launch icewm-session
3) login from xdm with normal user, then all done!
4) if using startx, then edit ~/.xinitrc instead.
Thursday, April 11, 2013
load icewm Desktop via xdm
1) install icewm via pkg_add.
# pkg_add icewm
2) edit /etc/rc.conf.local for xdm at startup
xdm_flags=""
3) edit /etc/X11/xdm/Xsession, and replace the fvwm line to icewm.
/usr/local/bin/icewm
REFERENCE:
http://openbsdsupport.org/desktopOBSD.html
# pkg_add icewm
2) edit /etc/rc.conf.local for xdm at startup
xdm_flags=""
3) edit /etc/X11/xdm/Xsession, and replace the fvwm line to icewm.
/usr/local/bin/icewm
REFERENCE:
http://openbsdsupport.org/desktopOBSD.html
Subscribe to:
Posts (Atom)