This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.
This episode was brought to you by
Headlines
Updates to FreeBSD's random(4)
FreeBSD's random device, which presents itself as "/dev/random" to users, has gotten a fairly major overhaul in -CURRENTThe CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called FortunaYarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)Pluggable modules can now be written to add more sources of entropyThese changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9***
OpenBSD Tor relays and network diversity
We've talked about getting more BSD-based Tor nodes a few times in previous episodesThe "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodesWith the security features and attention to detail, it makes for an excellent dedicated Tor boxMore and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at largeA few users are even saying they'll convert their Linux nodes to OpenBSD to help outCheck the archive for the full conversation, and maybe run a node yourself on any of the BSDsThe Tor wiki page on OpenBSD is pretty out of date (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it***
SSP now default for FreeBSD ports
SSP, or Stack Smashing Protection, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it producesIt's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updatesIf you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back overNetBSD made this the default on i386 and amd64 two years ago and OpenBSD made this the default on all architectures twelve years agoNext time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed***
Building an OpenBSD firewall and router
While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware sideThe OP lists some of his potential choices, but was originally looking for something a bit cheaper than a SoekrisMost agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD communityThey also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.Through the comments, we also find out that QuakeCon runs OpenBSD on their networkHopefully most of our listeners are running some kind of BSD as their gateway - try it out if you haven't already***
Interview - Kristaps Džonsons -
[email protected]Mandoc, historical man pages, various topics
Tutorial
Throttling bandwidth with PF
News Roundup
NetBSD at Kansai Open Forum 2014
Japanese NetBSD users invade yet another conference, demonstrating that they can and will install NetBSD on everythingFrom a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it allAs always, you can find lots of pictures in the trip report***
Getting to know your portmgr lurkers
The lovable "getting to know your portmgr" series makes its triumphant returnThis time around, they interview Alex, one of the portmgr lurkers that joined just this month"How would you describe yourself?" "Too lazy."Another post includes a short interview with Emanuel, another new lurkerWe discussed the portmgr lurkers initiative with Steve Wills a while back***
NetBSD's ARM port gets SMP
The ARM port of NetBSD now has SMP support, allowing more than one CPU to be usedThis blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6XNetBSD's release team is working on getting these changes into the 7 branch before 7.0 is releasedThere are also a few nice pictures in the article***
A high performance mid-range NAS
This blog post is about FreeNAS and optimizing iSCSI performanceIt talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performanceThere are some nice graphs and lots of detail if you're interested in tweaking some of your own settingsThey conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"***
Feedback/Questions
Heto writes inBrad writes inTyler writes inTim writes inBrad writes in***
Mailing List Gold
Suspicious contributionsLa puissance du fromageNothing unusual here***