Friday, February 19, 2016

running pf on AWS

There's only FreeBSD AMI available on AWS cloud service currently. Therefore we can get it directly from Market Place if we want to run pf or other related services.

  • pf_enable=YES in /etc/rc.conf.
  • vi /etc/pf.conf. keep state is by default.
  • reboot. then pf should be available now.

Tuesday, August 18, 2015

opensmtpd setup

mailq to view queue
smtpctl monitor to view realtime status
tail -f /var/log/maillog to view realtime logs

Tuesday, August 4, 2015

Friday, May 8, 2015

compiling ffmpeg on OpenBSD

1) Install required packages like nasm, etc, following the CentOS guide below:
https://trac.ffmpeg.org/wiki/CompilationGuide/Centos

2) Install git, gmake, as well as x264, for H.264 encoding feature:
# pkg_add -v git gmake x264

3) check out the latest source:
$ git clone git://source.ffmpeg.org/ffmpeg.git ffmpeg

4) cd ffmpeg; ./configure --enable-gpl --enable-libx264 ; gmake .

Monday, November 3, 2014

fvwm local setup

REF: Doing ls -a shows the dot-files, too, and I see that there is a file called .fvwmrc in /usr/X11R6/lib/X11/fvwm/.

http://blogs.dailynews.com/click/2008/04/10/configuring-fvwm-in-openbsd-an/

xterm setup & alternatives

xterm alternatives: gnome-terminal, xfce4-terminal, konsole. xterm can be launched with -fg grey -bg black -font 10x20 to change colors.

REF:
https://mkaz.com/2010/04/04/xterm-colors/
http://docstore.mik.ua/orelly/unix3/upt/ch05_18.htm

Tuesday, October 28, 2014

tcpwrappers replacement

tcpwrappers moved out from OpenBSD 5.6, which can be implemented similarly by AllowUsers in sshd_config to restrict users and ip range.

Wednesday, October 22, 2014

Compile Wireshark on OpenBSD

Wireshark (older version, say 1.0.0) can be compiled on OpenBSD (--with-krb5=no) following this article: http://cromwell-intl.com/linux/compiling-wireshark-on-openbsd.html .

Sunday, October 12, 2014

OpenBSD upgrade with firmware

upgrading with bsd.rd can utilize firmware installed previously! then fw_update will download proper updates after system upgrade.

Sunday, December 15, 2013

HiR's Secure OpenBSD, Apache, MySQL and PHP Guide


Install php-mysql and mysql-server. This will install all necessary dependencies, including php, libiconv and several perl modules needed by the MySQL scripts.

$ sudo pkg_add php-mysql mysql-server
Ambiguous: choose package for php-mysql
 a       0: 
         1: php-mysql-5.2.17p16
         2: php-mysql-5.3.27
Your choice: 2
Ambiguous: choose dependency for php-mysql-5.3.27: 
 a       0: php-5.3.27
         1: php-5.3.27-ap2
Your choice: 0

REF: http://www.h-i-r.net/p/hirs-secure-openbsd-apache-mysql-and.html

Monday, October 7, 2013

Tuesday, September 10, 2013

install m:tier thin client


0) Download the thin client python code:
http://www.mtier.org/products/thin-client/

1) install from pkg_add: gtk+3 , python3.

2) install from src: pycairo, pygobject .
PYTHON=python3.2 ./configure
Makefile err may need to be corrected manually.

3) modify /etc/X11/xinit/xinitrc for startx automatically.

p.s. *.pc files for pkg-config  need to be linked to /usr/lib/pkg-config .


Sunday, June 30, 2013

snmpd setup (renewed)

1) edit /etc/snmpd.conf and modify listen_addr
2) enable snmpd in /etc/rc.conf on startup
3) apply access control via /etc/pf.conf

Tuesday, May 7, 2013

Reverse ftp-proxy setup

use ftp-proxy -R internal.server.ip -D7 -v can easily setup a reverse FTP proxy on OpenBSD.

Remember to allow packet forwarding in sysctl.conf, and also turn on the ftp-proxy anchor in pf.conf.

Thursday, April 25, 2013

OpenBSD on USB drive with boot loader

if you install OpenBSD on a USB drive but cannot boot from it, you may try install GAG boot loader into the MBR. Remember to make your USB drive the first boot disk because GAG can only install to the first drive!

Monday, April 22, 2013

running scim input method with built-in fvwm

1) edit ~/.xsession
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
/usr/X11R6/bin/xterm &
exec dbus-launch /usr/X11R6/bin/fvwm

2) Exit and login again via xdm.

Saturday, April 20, 2013

install OpenBSD on USB drive

1) if you want to keep a FAT partition for using on Windows, make the FAT partition the first one, otherwise Windows cannot read it.

2) Install OpenBSD on the selected USB drive as the normal installation process. Remember to make the OpenBSD MBR active, or use tools such as Linux GParted to flag it as boot.

3) Soft update set in /etc/fstab could make I/O much faster: rw,softdep.

REFERENCE:
http://openbsd.org/faq/faq14.html#flashmemLive
http://openbsd.org/faq/faq14.html#flashmemBoot
http://openbsd.org/faq/faq14.html#SoftUpdates

Friday, April 12, 2013

icewm workstation with chinese input

1) pkg_add icewm firefox scim-chewing gnome-terminal
2) edit ~/.xsession for normal user:
export LC_CTYPE=en_US.UTF-8
export XMODIFIERS=@im=scim
export GTK_IM_MODULE="scim"
scim -d&
exec dbus-launch icewm-session
3) login from xdm with normal user, then all done!
4) if using startx, then edit ~/.xinitrc instead.

Thursday, April 11, 2013

load icewm Desktop via xdm

1) install icewm via pkg_add.
# pkg_add icewm

2) edit /etc/rc.conf.local for xdm at startup
xdm_flags=""

3) edit /etc/X11/xdm/Xsession, and replace the fvwm line to icewm.
/usr/local/bin/icewm

REFERENCE:
http://openbsdsupport.org/desktopOBSD.html