BSD Now

48: Liberating SSL


Listen Later

Coming up in this week's episode, we'll be talking with one of OpenBSD's newest developers - Brent Cook - about the portable version of LibreSSL and how it's developed. We've also got some information about the FreeBSD port of LibreSSL you might not know. The latest news and your emails, on BSD Now - the place to B.. SD.

This episode was brought to you by

Headlines
FreeBSD quarterly status report
  • FreeBSD has gotten quite a lot done this quarter
  • Changes in the way release branches are supported - major releases will get at least five years over their lifespan
  • A new automounter is in the works, hoping to replace amd (which has some issues)
  • The CAM target layer and RPC stack have gotten some major optimization and speed boosts
  • Work on ZFSGuru continues, with a large status report specifically for that
  • The report also mentioned some new committers, both source and ports
  • It also covers GNATS being replaced with Bugzilla, the new core team, 9.3-RELEASE, GSoC updates, UEFI booting and lots of other things that we've already mentioned on the show
  • "Foundation-sponsored work resulted in 226 commits to FreeBSD over the April to June period"
  • ***
    A new OpenBSD HTTPD is born
    • Work has begun on a new HTTP daemon in the OpenBSD base system
    • A lot of people are asking "why?" since OpenBSD includes a chrooted nginx already - will it be removed? Will they co-exist?
    • Initial responses seem to indicate that nginx is getting bloated, and is a bit overkill for just serving content (this isn't trying to be a full-featured replacement)
    • It's partially based on the relayd codebase and also comes from the author of relayd, Reyk Floeter
    • This has the added benefit of the usual, easy-to-understand syntax and privilege separation
    • There's a very brief man page online already
    • It supports vhosts and can serve static files, but is still in very active development - there will probably be even more new features by the time this airs
    • Will it be named OpenHTTPD? Or perhaps... LibreHTTPD? (I hope not)
    • ***
      pkgng 1.3 announced
      • The newest version of FreeBSD's second generation package management system has been released, with lots of new features
      • It has a new "real" solver to automatically handle conflicts, and dynamically discover new ones (this means the annoying -o option is deprecated now, hooray!)
      • Lots of the code has been sandboxed for extra security
      • You'll probably notice some new changes to the UI too, making things more user friendly
      • A few days later 1.3.1 was released to fix a few small bugs, then 1.3.2 shortly thereafter and 1.3.3 yesterday
      • ***
        FreeBSD after-install security tasks
        • A number of people have written in to ask us "how do I secure my BSD box after I install it?"
        • With this blog post, hopefully most of their questions will finally be answered in detail
        • It goes through locking down SSH with keys, patching the base system for security, installing packages and keeping them updated, monitoring and closing any listening services and a few other small things
        • Not only does it just list things to do, but the post also does a good job of explaining why you should do them
        • Maybe we'll see some more posts in this series in the future
        • ***
          Interview - Brent Cook - [email protected] / @busterbcook

          LibreSSL's portable version and development

          News Roundup
          FreeBSD Mastery - Storage Essentials
          • MWL's new book about the FreeBSD storage subsystems now has an early draft available
          • Early buyers can get access to an in-progress draft of the book before the official release, but keep in mind that it may go through a lot of changes
          • Topics of the book will include GEOM, UFS, ZFS, the disk utilities, partition schemes, disk encryption and maximizing I/O performance
          • You'll get access to the completed (e)book when it's done if you buy the early draft
          • The suggested price is $8
          • ***
            Why BSD and not Linux?
            • Yet another thread comes up asking why you should choose BSD over Linux or vice-versa
            • Lots of good responses from users of the various BSDs
            • Directly ripping a quote: "Features like Ports, Capsicum, CARP, ZFS and DTrace were stable on BSDs before their Linux versions, and some of those are far more usable on BSD. Features like pf are still BSD-only. FreeBSD has GELI and ipfw and is "GCC free". DragonflyBSD has HAMMER and kernel performance tuning. OpenBSD have upstream pf and their gamut of security features, as well as a general emphasis on simplicity."
            • And "Over the years, the BSDs have clearly shown their worth in the nix ecosystem by pioneering new features and driving adoption of others. The most recent on OpenBSD were 2038 support and LibreSSL. FreeBSD still arguably rules the FOSS storage space with ZFS."
            • Some other users share their switching experiences - worth a read
            • ***
              More g2k14 hackathon reports
              • Following up from last week's huge list of hackathon reports, we have a few more
              • Landry Breuil spent some time with Ansible testing his infrastructure, worked on the firefox port and tried to push some of their patches upstream
              • Andrew Fresh enjoyed his first hackathon, pushing OpenBSD's perl patches upstream and got tricked into rewriting the adduser utility in perl
              • Ted Unangst did his usual "teduing" (removing of) old code - say goodbye to asa, fpr, mkstr, xstr, oldrdist, fsplit, uyap and bluetooth
              • Luckily we didn't have to cover 20 new ones this time!
              • ***
                BSDTalk episode 243
                • The newest episode of BSDTalk is out, featuring an interview with Ingo Schwarze of the OpenBSD team
                • The main topic of discussion is mandoc, which some users might not be familiar with
                • mandoc is a utility for formatting manpages that OpenBSD and NetBSD use (DragonFlyBSD and FreeBSD include it in their source tree, but it's not built by default)
                • We'll catch up to you soon, Will!
                • ***
                  Feedback/Questions
                  • Thomas writes in
                  • Stephen writes in
                  • Sha'ul writes in
                  • Florian writes in
                  • Bob Beck writes in - and note the "Caution" section that was added to libressl.org
                  • ***
                    ...more
                    View all episodesView all episodes
                    Download on the App Store

                    BSD NowBy JT Pennington

                    • 4.9
                    • 4.9
                    • 4.9
                    • 4.9
                    • 4.9

                    4.9

                    89 ratings


                    More shows like BSD Now

                    View all
                    Security Now (Audio) by TWiT

                    Security Now (Audio)

                    1,970 Listeners

                    Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

                    Software Engineering Radio - the podcast for professional software developers

                    272 Listeners

                    The Changelog: Software Development, Open Source by Changelog Media

                    The Changelog: Software Development, Open Source

                    284 Listeners

                    LINUX Unplugged by Jupiter Broadcasting

                    LINUX Unplugged

                    265 Listeners

                    Python Bytes by Michael Kennedy and Brian Okken

                    Python Bytes

                    215 Listeners

                    Late Night Linux by The Late Night Linux Family

                    Late Night Linux

                    154 Listeners

                    Home Assistant Podcast by HK Media

                    Home Assistant Podcast

                    65 Listeners

                    CoRecursive: Coding Stories by Adam Gordon Bell - Software Developer

                    CoRecursive: Coding Stories

                    189 Listeners

                    Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

                    Kubernetes Podcast from Google

                    181 Listeners

                    Late Night Linux Family All Episodes by The Late Night Linux Family

                    Late Night Linux Family All Episodes

                    44 Listeners

                    Linux Dev Time by The Late Night Linux Family

                    Linux Dev Time

                    21 Listeners

                    Self-Hosted by Jupiter Broadcasting

                    Self-Hosted

                    135 Listeners

                    2.5 Admins by The Late Night Linux Family

                    2.5 Admins

                    92 Listeners

                    Linux After Dark by The Late Night Linux Family

                    Linux After Dark

                    29 Listeners

                    Oxide and Friends by Oxide Computer Company

                    Oxide and Friends

                    47 Listeners