summaryrefslogtreecommitdiff
path: root/etc
AgeCommit message (Collapse)Author
2019-12-04Attempt to smear out stampedes on the RPKI rsync serversjob
OK claudio@ benno@
2019-12-02sync namesTheo de Raadt
2019-12-01grow i386 cd ramdisk a little bitTheo de Raadt
2019-11-30Tweak rpki-client to create all 4 output file formats from a singleTheo de Raadt
compute, based upon flags. OpenBGPD compatible format by default if no options, to integrate with bgpd.conf and bgpctl reload. Adapt mtree and stuff. This will receive further refactoring... ok benno job
2019-11-29Uncomment a single line in root's crontab to run rpki-client and reloadTheo de Raadt
bpgd configuration, which enables Enterprise-Ready Industry-Leading-by-Example RPKI ROA filtering on your OpenBGP edge. Arguments remain about how often to run this operation, for now we propose 9AM when people who can fix their shit are in the office. ok claudio benno
2019-11-29Import /var/db/rpki-client/roa and filterTheo de Raadt
discussed at length with claudio and benno
2019-11-29add /var/cache/rpki-client, ok deraadt@Sebastian Benoit
2019-11-29create a var/db/rpki-client/roa file with correct ownership so thatTheo de Raadt
rpki-client(8) can deal with it (some upcoming changes...)
2019-11-29create var/db/rpki-client directory with correct modeTheo de Raadt
2019-11-27Nuke http captive portal detection; something better is coming.Florian Obser
OK otto
2019-11-26make implicit "listen on socket" explicit, the default config no longer hasGilles Chehade
any implicit behavior ok eric@, kn@
2019-11-25use explicit from notation in default configGilles Chehade
ok eric@
2019-11-22sndiod(8) reopens audio interfaces on SIGHUP, which makes a lot of senseClaudio Jeker
when -F is used. Because of this allow rc.d script to reload sndiod. OK kn ratchov aja
2019-11-15fix the spelling of rpki, as noted by jmc@Sebastian Benoit
2019-11-15grow an install mediaTheo de Raadt
2019-11-14uid/gid 70 is _rpki-client for privdrop; ok bennoTheo de Raadt
2019-11-11change the nmea sensor to "trusted"Theo de Raadt
2019-11-11move /usr and var remounting (nfs diskless case...) earlier, so thatTheo de Raadt
unwind can be started (silently) before pf is configured (for those few weirdos who use hostnames in pf.conf...). Other unidentified concerns may be improved by this startup re-ordering, so let's give it a try. discussed with florian.
2019-11-11update ntpd example configurationTheo de Raadt
2019-11-10use $(<file) instead of $(cat file) since this script uses ksh; ok ajacoutot@Christian Weisgerber
2019-11-07Reenable "val-log-level: 2", so that when sites have misconfiguredStuart Henderson
dnssec the sysadmin has some idea what's going on in logs, and "aggressive-nsec: yes", if we're using dnssec anyway we might as well get the benefits. These were both enabled last time dnssec was enabled in this sample unbound.conf. ok florian@
2019-11-07Enable DNSSEC validation in unbound by defaultjob
OK deraadt@ otto@
2019-11-06Perform contraint validation against 9.9.9.9 and 2620:fe::fe also (whichTheo de Raadt
avoids DNS lookups entirely, but yes this https is correctly validated) long discussions with otto, florian, and the quad9 crew.
2019-11-06we have emergency entropy injection code in rc, for if the bootblocks andTheo de Raadt
other methods failed to inject/churn the rng enough. Move it up far earlier. ok naddy sthen kettenis
2019-11-05Add a default priority of 5 for user _pbuild, this should help keeping systemsolene
responsive during packages compilation, especially on slower machines. feedback welcome from people building ports discussed with deraadt@
2019-10-25handle aggr(4) in the same way as trunk(4)David Gwynne
from brad@ ok bluhm@ claudio@ deraadt@
2019-10-22Import regenerated moduli file.Darren Tucker
2019-10-20regenMark Kettenis
2019-10-20Add /dev/pri.Mark Kettenis
2019-10-18Bump datasize-cur for pbuild on mips64, to make room for modernity.Visa Hankala
OK deraadt@
2019-10-12accidentally stated the MP kernel twice, leading the SHA256/SHA256.sigTheo de Raadt
file to contain two hashes for bsd.mp, and cause later upgrade problems spotted by afresh1
2019-10-07sync arm64 pbuild resource limits with amd64; arm64 now builds some largeStuart Henderson
things and can easily exceed the previous 1.5GB limit. (obviously, as with amd64, machines with less physical RAM won't cope with building the largest ports). ok deraadt phessler millert kettenis
2019-10-07update pkg nameTheo de Raadt
2019-10-07correct datesTheo de Raadt
2019-10-06for now, only mix in sysctl hw.{uuid,serialno,sensors} to /dev/random.Stuart Henderson
as found the hard way by d.rauschenb@gmail on an old fujitsu siemens machine, reading all of hw (notable hw.setperf) can have unexpected side-effects. ok deraadt
2019-10-02feed "sysctl hw" into /dev/random; a cheap way to feed in sensor dataStuart Henderson
as a one-shot at boot without more complex kernel work, and also includes some serial numbers/guids which may add a little more entropy e.g. for systems where /etc/random.seed may be known (e.g. cloned disk images). "why not" deraadt@
2019-09-21Increase datasize limit for ports building on arm64 in preparationKurt Miller
for enabling devel/jdk/11 there. okay phessler@
2019-09-18Correct sysctl section is 2solene
ok jmc millert
2019-09-18Add explanation about the default value of sysctl keysolene
machdep.pwraction ok jmc millert
2019-09-15Add ttyC4 to lost of devices to change when logging in on ttyC0 (and inMark Kettenis
some cases also the serial console) such that X can use it as its VT when running without root privileges. ok jsg@, matthieu@
2019-09-09Inform about system call memory write protection and stack mappingAlexander Bluhm
violations in system accounting. This will help to find missbehaving programs and possible attacks. The flags bit field is full, so recycle the PDP-11 compatibility on VAX. lastcomm(1) prints the AMAP flag as 'M'. daily(8) prints a list of affected processes. OK deraadt@
2019-09-08Bump datasize-cur to 4Gb for pbuild class on sparc64, rust is a pig.Landry Breuil
ok semarie@
2019-09-07Remove dependency on basename(1).Antoine Jacoutot
prodded by deraadt@ ok kn@ deraadt@ tb@
2019-08-25space -> tabsAntoine Jacoutot
ok deraadt@ kn@
2019-08-19The piggies have outgrown their pen again: Firefox 69 will no longerChristian Weisgerber
build in 5 GB of memory. Bump default datasize for pbuild to 6 GB. ok landry@ ajacoutot@
2019-08-19add 6.7 syspatch keyRobert Nagy
2019-08-12Add the rpki TAL files to the changelist including arin.tal (which is notClaudio Jeker
shipeed by default). OK job@ sthen@ deraadt@
2019-08-12There is no reason why the TAL files are installed only readable by rootClaudio Jeker
these are public files. Agreed by deraadt@ (and florian@)
2019-08-10move to 6.6-betaTheo de Raadt
2019-08-09add 6.7 firmware keyStuart Henderson