summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2015-04-03Add ddb.log example; OK halex@Todd C. Miller
2015-03-31For consistency with the diff subcommand, add rdiff -uChristian Weisgerber
(-N is always implied and -p isn't available.) ok guenther@, sthen@
2015-03-28_rc_err(): only display error message if there's an actual one.Antoine Jacoutot
Remove an exit() statement that could never be reached.
2015-03-27Actually use the new man.conf(5) "output" directive.Ingo Schwarze
Additional functionality, yet minus 45 lines of code.
2015-03-27Move man.conf from /etc to /etc/examples, deleting what's no longer supported.Ingo Schwarze
Discussed with many and OK ajacoutot@.
2015-03-11syncTheo de Raadt
2015-03-11openprom, just like eeprom; ok miodTheo de Raadt
2015-03-11syncTheo de Raadt
2015-03-11eeprom(8) is only run by root now, so no need for kmem groupTheo de Raadt
ok miod
2015-03-11'rc.firstime' -> 'rc.firsttime' in comment.Kenneth R Westerback
Diff from Navan Carson via tech@
2015-03-10Set verbosity to 1 (the default is 0) so we log incoming notifiesTodd C. Miller
and zone xfers. OK florian@ deraadt@
2015-03-10Disable db file. It is believed to be a saner default for the commonFlorian Obser
use case. sthen@ noticed a problem with missing records on shutdown. OK sthen@
2015-03-06fix pkgnames versionGiovanni Bechis
ok deraadt@
2015-03-05syncKenji Aoyama
ok deraadt@
2015-03-05Add com(4) and wd(4) to use them on PCMCIA.Kenji Aoyama
ok deraadt@
2015-02-18Remove old cruft, that make no sense at all on OpenBSD.Robert Peichaer
- comments relevant to other brands of UNIX - the no-op KSH_VERSION case-block, we only have pdksh - the case-block for setting aliases based on UNIX brand together with a comment that falsely encourages to modify this file instead of putting stuff in $HOME/.kshrc OK krw@ halex@
2015-02-17Add class section for unbound, using openfiles-cur=512 ratherStuart Henderson
than the daemon class' default of 128. Reminded by/ok ajacoutot@
2015-02-17Put the _unbound user in "unbound" login class; unbound uses setusercontextStuart Henderson
to initialize the unprivileged user, so the usual rc.d mechanism to set the class isn't used. Problem reported by otto, ok otto@ ajacoutout@
2015-02-10Add support for "constraints": when configured, ntpd(8) will query theReyk Floeter
time from HTTPS servers, by parsing the Date: header, and use the median constraint time as a boundary to verify NTP responses. This adds some level of authentication and protection against MITM attacks while preserving the accuracy of the NTP protocol; without relying on authentication options for NTP that are basically unavailable at present. This is an initial implementation and the semantics will be improved once it is in the tree. Discussed with deraadt@ and henning@ OK henning@
2015-02-04TypoFlorian Obser
From Michael (lesniewskister AT gmail), thanks!
2015-01-26Rename miniroot-sunxi to miniroot-cubie as the u-boot includedJonathan Gray
in the image is for Cubieboard1. Discussed with bmercer@ While here switch from using the separate spl and u-boot images to the combined spl and u-boot 'u-boot-sunxi-with-spl.bin'.
2015-01-22Use /etc/services names in all the default pf rules (most alreadyKenneth R Westerback
did). This allows any local changes to /etc/services to be effective if all you have is the default. Issue pointed out by Brian S. Vangsgaard on bugs@. Thanks! ok phessler@ deraadt@
2015-01-20Do not use /usr/ports/infrastructure/man/ by default because thisIngo Schwarze
directory is not contained in OpenBSD base, and because even people having the directory often don't understand that they need to run makewhatis(8) - and instead complain about the resulting warnings. This commit reverts revisions 1.17 and 1.21. Requested by deraadt@ millert@ kettenis@ who argue that people using /usr/ports/infrastructure/bin/ already need to set PATH, so editing man.conf (or, though more fragile, setting MANPATH) should not be a big deal for them.
2015-01-20increase limits for staff (user created at install time is in staff)Theo de Raadt
2015-01-20Change the machdep.lidsupsend example now that the default setting has beenTheo de Raadt
inverted.
2015-01-20Change the machdep.lidsupsend example now that the default setting has beenMiod Vallat
inverted.
2015-01-12Due to recent savings with instbin, we can take i386 to one installTheo de Raadt
floppy. A few drivers are missing, but the world has moved on (the drivers included are always a work in progress) Speeds up make release substantially, of course.
2015-01-075.8 packages keyChristian Weisgerber
2015-01-06add 5.8 base keyTheo de Raadt
2015-01-06firmware key for 5.8Stuart Henderson
2015-01-02Fix dow and apply the usual easter egg.Miod Vallat
2015-01-02Fix return code of _rc_quirks().Antoine Jacoutot
ok robert@
2015-01-02adjust dateTheo de Raadt
2015-01-02Add a comment about the default values being duplicated in rcctl(8).Antoine Jacoutot
discussed with schwarze@
2015-01-01move to 5.7-betaTheo de Raadt
2014-12-31add entries for xmpp, mdns and puppetJasper Lievisse Adriaanse
ok aja@
2014-12-30Add syslog-tls 6514/tcp to etc/services.Alexander Bluhm
OK jasper
2014-12-29regenKenji Aoyama
2014-12-29Add audio(4) related entries.Kenji Aoyama
ok miod@
2014-12-29Add line continuation to be consistent with rc_pre(); ok sthen@Antoine Jacoutot
2014-12-29pexp is not needed; ok sthen@Antoine Jacoutot
2014-12-28Change the default ext_addr from "egress" to "*". Listening on theReyk Floeter
egress group only works if you have a default route; this confused some people.
2014-12-26the kvm.db is now kmem owned. noticed by Steven RobertsTed Unangst
2014-12-22dickman noticed /var/rwho keeps coming back. remove it.Ted Unangst
2014-12-22Out out you evil network daemon.Florian Obser
OK deraadt@ some time ago
2014-12-19Add rdp/rfb/vnc.Antoine Jacoutot
no objection from deraadt@
2014-12-13Install netboot.mopMiod Vallat
2014-12-12Like previously done in relayd, change the keyword "ssl" to "tls" toReyk Floeter
reflect reality. OK benno@
2014-12-12Change the keyword "ssl" to "tls" to reflect reality since weReyk Floeter
effectively disabled support for the SSL protocols. SSL remains a common term describing SSL/TLS, there is some controvery about this change, and the name really doesn't matter, but I feel confident about it now. (btw., sthen@ pointed out some historical context: http://tim.dierks.org/2014/05/security-standards-and-name-changes-in.html) OK benno@, with input from tedu@
2014-12-11regenTed Unangst