summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2014-04-18Switch to the new makewhatis(8)/apropos(1)/whatis(1) combo.Ingo Schwarze
"commit the switch now" espie@ "go for it" deraadt@ See the apropos(1) manual for a description of what's new. On machines where you want the full functionality, run "sudo makewhatis" and put "MAKEWHATISARGS=' '" into weekly.local(8). Otherwise, when upgrading via source, run "sudo makewhatis -Q".
2014-04-11Move build machinery for libcrypto from libssl/crypto to libcrypto, as wellMiod Vallat
as configuration files; split manpages and .pc files between libcrypto and libssl. No functional change, only there to make engineering easier, and libcrypto sources are still found in libssl/src/crypto at the moment. ok reyk@, also discussed with deraadt@ beck@ and the usual crypto suspects.
2014-04-03regenMiod Vallat
2014-04-03Add wskbd nodes to the bsd.rd /dev posse; allows kbd -l to work as intendedMiod Vallat
in the install media. Reported by Donovan Watteau
2014-04-02Fix syntax error in commented out local-zone entry. OK sthen@Todd C. Miller
2014-03-30increase size of iso media (try 2)Theo de Raadt
2014-03-30increase size of iso mediaTheo de Raadt
2014-03-27do not keep hoststat and purgestat, they are pointing to the sendmailGilles Chehade
executable and will not serve any purpose with smtpd by default ok jmc@ tedu@
2014-03-26end experimental login.conf template support. one file per machine.Ted Unangst
ok deraadt millert
2014-03-24sum -> cksum, ok deraadtStuart Henderson
2014-03-24okan reminds me hosts.allow lived here tooTed Unangst
2014-03-24Stop monitoring apache files.Antoine Jacoutot
ok florian@ jung@ sthen@
2014-03-24Add /var/unbound/dev/log, it isn't needed for initial startup because UnboundStuart Henderson
opens the log before chrooting, but this handles the case where syslogd is restarted during Unbound's runtime.
2014-03-23Remove commented-out module-config line, it is already set to "validatorStuart Henderson
iterator" by default. Pointed out by Patrik Lundin.
2014-03-21Add nginx default log files to the rotation.Antoine Jacoutot
ok jung@ stephan@ tweaks and ok sthen@
2014-03-21Install a /var/unbound/db directory, writable by the _unbound daemon,Stuart Henderson
and use it as the default location for the DNSSEC root key. Update default config for this location. With this, the only step required to enable DNSSEC validation is to uncomment these default config entries and restart: #module-config: "validator iterator" #auto-trust-anchor-file: "/var/unbound/db/root.key" There is no longer a requirement to run unbound-anchor manually to update the root key. The rc.d script will take care of updates at boot, and Unbound will manage the file itself at runtime. Test with "dig test.dnssec-or-not.net txt @127.0.0.1" or similar.
2014-03-19Tell the manpage machinery to not output Xr to hd(4/vax) in MAKEDEV.8, sinceMiod Vallat
such a manpage does not currently exist. Requested by jmc@
2014-03-19no rest for the wicked. increase user blf logrounds default to 8(+2).Ted Unangst
increase root to 9(+1). ok deraadt (and a thank you to miod for helping to reduce the set of architectures harmed by this)
2014-03-18Retire hp300, mvme68k and mvme88k ports. These ports have no users, keepingMiod Vallat
this hardware alive is becoming increasingly difficult, and I should heed the message sent by the three disks which have died on me over the last few days. Noone sane will mourn these ports anyway. So long, and thanks for the fish.
2014-03-17No need to keep a manually maintained list of system daemons here, ftpd canStuart Henderson
disallow them itself. ok deraadt@ millert@, gsoares@ and aja@ like it too. ("nobody" still needs to be listed).
2014-03-17uucp cleansingTed Unangst
2014-03-17no more _ppp userStuart Henderson
2014-03-17ppp.log was just for ppp(8)Stuart Henderson
2014-03-17_ppp uid/gid will come up for recycling (but please not within a year)Theo de Raadt
2014-03-17the userland ppp(9) code goes awa. Having too much ppp choice in theTheo de Raadt
tree results in one-true-ppp not coming into existance. This code is essentially un-audited and quite dangerous. ok claudio sthen
2014-03-16add unbound.conf and (dnssec) root.key to changelistStuart Henderson
2014-03-15Add _unbound user here too. Reminded by aja@Stuart Henderson
2014-03-15Enable Unbound in base, ok deraadt@Stuart Henderson
2014-03-15Bump the cdXX image from 12MB to 13MB.Miod Vallat
2014-03-15httpd_flags was still used here; remove it.Stuart Henderson
Add a log socket in /var/www/dev/log if nginx is enabled, it is needed as the openlog() call is done after chrooting. ok brad@ florian@ deraadt@
2014-03-15Add a new sample config file and rc.d script for unbound, ok deraadt@Stuart Henderson
2014-03-14regenMark Kettenis
2014-03-14We no longer support the userland interface for agp(4).Mark Kettenis
2014-03-14Add "ub-dns-control" (for unbound's equivalent of rndc), so that it's addedStuart Henderson
to the port list in net.inet.tcp.baddynamic. Service name taken from IANA service-names-port-numbers.txt. If anyone's interested in adding AF_UNIX support for comms between unbound and unbound-control, that would very welcome. OK brad@ deraadt@
2014-03-14adding a user is hard. mistakes pointed out by ajacoutotTed Unangst
2014-03-13smtpd dudes forgot to add their _smtpq userTed Unangst
2014-03-13it's a tedu miracle! this file is just descriptions, so resurrect spraydTed Unangst
2014-03-13Unhook httpd(8) from build; etc bitsFlorian Obser
OK krw@, gilles@, lteo@, tedu@, todd@, benno@, sthen@ "The time is right." and much help getting the show on the road deraadt@
2014-03-12just run newaliases. should be about the same, but less sendmail.Ted Unangst
ok todd
2014-03-12switch over to smtpd by default.Ted Unangst
ok deraadt gilles todd
2014-03-12Are they going to help?Ted Unangst
No. Well, then tell them to stay out of the way. ok deraadt
2014-03-07too old, undermaintainedTed Unangst
2014-03-06the pre-5.5 test keys are no longer usefulTheo de Raadt
2014-03-05some files were not being hashes, because they were missing from MDEXTTheo de Raadt
noticed by jsg, and important enough to make release
2014-03-03cdemu is no moreTheo de Raadt
2014-03-02Add two disktab entries, for *.fs install filesystems (let's call themTheo de Raadt
'miniroot and maxiroot').. from chris
2014-02-28proper (non-test) keys for 5.5 and 5.6 baseTheo de Raadt
2014-02-27Build a small miniroot filesystem which can be dumped on a new disk or anMiod Vallat
existing swap partition for an easier initial installation.
2014-02-26proper (non-test) keys for 5.5 and 5.6 firmwareStuart Henderson
2014-02-26the test 5.4 keys can go awayTheo de Raadt