You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(55) |
Oct
(44) |
Nov
(156) |
Dec
(123) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(130) |
Feb
(156) |
Mar
(162) |
Apr
(171) |
May
(97) |
Jun
(127) |
Jul
(58) |
Aug
(81) |
Sep
(86) |
Oct
(45) |
Nov
(41) |
Dec
(84) |
| 2003 |
Jan
(71) |
Feb
(87) |
Mar
(133) |
Apr
(152) |
May
(151) |
Jun
(232) |
Jul
(320) |
Aug
(237) |
Sep
(271) |
Oct
(536) |
Nov
(301) |
Dec
(393) |
| 2004 |
Jan
(393) |
Feb
(184) |
Mar
(314) |
Apr
(225) |
May
(139) |
Jun
(77) |
Jul
(87) |
Aug
(75) |
Sep
(139) |
Oct
(50) |
Nov
(8) |
Dec
(28) |
| 2005 |
Jan
(66) |
Feb
(63) |
Mar
(14) |
Apr
(14) |
May
(8) |
Jun
(23) |
Jul
(21) |
Aug
(6) |
Sep
(29) |
Oct
(55) |
Nov
(38) |
Dec
(8) |
| 2006 |
Jan
(5) |
Feb
(10) |
Mar
(1) |
Apr
(15) |
May
(32) |
Jun
(44) |
Jul
(11) |
Aug
(8) |
Sep
(9) |
Oct
(14) |
Nov
(4) |
Dec
(3) |
| 2007 |
Jan
(3) |
Feb
(3) |
Mar
(2) |
Apr
|
May
|
Jun
|
Jul
(35) |
Aug
(49) |
Sep
(8) |
Oct
(42) |
Nov
(44) |
Dec
(7) |
| 2008 |
Jan
(2) |
Feb
(7) |
Mar
(8) |
Apr
(80) |
May
(74) |
Jun
(29) |
Jul
(5) |
Aug
(7) |
Sep
(6) |
Oct
(1) |
Nov
|
Dec
|
| 2009 |
Jan
(8) |
Feb
(19) |
Mar
(3) |
Apr
(24) |
May
(22) |
Jun
(23) |
Jul
(8) |
Aug
(23) |
Sep
(8) |
Oct
(27) |
Nov
(52) |
Dec
(27) |
| 2010 |
Jan
(36) |
Feb
(29) |
Mar
(17) |
Apr
(28) |
May
(21) |
Jun
(4) |
Jul
|
Aug
(28) |
Sep
(18) |
Oct
(6) |
Nov
(34) |
Dec
(16) |
| 2011 |
Jan
(18) |
Feb
(12) |
Mar
|
Apr
|
May
(9) |
Jun
(1) |
Jul
(5) |
Aug
(5) |
Sep
(7) |
Oct
(16) |
Nov
(26) |
Dec
(17) |
| 2012 |
Jan
(6) |
Feb
(34) |
Mar
(52) |
Apr
(10) |
May
(3) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(4) |
Nov
(1) |
Dec
(4) |
| 2013 |
Jan
(5) |
Feb
|
Mar
|
Apr
(5) |
May
(4) |
Jun
|
Jul
|
Aug
(14) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2014 |
Jan
|
Feb
(2) |
Mar
(5) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
(11) |
| 2015 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
| 2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2017 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2018 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Friedrich L. <fl...@fl...> - 2003-05-28 23:55:52
|
Bruce Smith wrote: > I added a simple iptables script that supports 2 NIC's w/masquerading. > Please take a look, and comment: OK, I added the script code to be able to comment on it. > #!/bin/bash > # > # $Source: /cvsroot/devil-linux/build/config/etc/init.d/firewall.rules.2nic,v $ > # $Revision: 1.1 $ > # $Date: 2003/05/28 14:53:18 $ > # > # http://www.devil-linux.org > # > # > # Basic Firewall rules for 2 NIC's and NAT > # > > # Path to IPTABLES executable > IPTABLES=/usr/sbin/iptables > > INT_DEV=eth1 # internal/protected network. > OUT_DEV=eth0 # Internet I'm thinking of way so we could mark the interenal and external interface in the network scripts ifcfg-ethX. But haven't made up for a desicion yet. This way if would allow the firewall script to walk all installed interfaces and reference them and their status being eg. external, dmz, internal, ... > > echo "0" > /proc/sys/net/ipv4/ip_forward # stop forwarding while setting up. > > # Uncomment ALL lines starting with #LOG# to log rejected packets > #LOG# modprobe ipt_LOG Would that be much easier for the user: # Uncomment the following line to enable logging # LOGGING="yes" and you'd put such lines everywhere in the script: [ -n "$LOGGING" ] && ...command that does the logging > > # Flush & Policy > ${IPTABLES} -F # flush all chains > # flush all tables: > for t in `cat /proc/net/ip_tables_names`; do ${IPTABLES} -F -t $t ; done > ${IPTABLES} -X # delete all user chains > ${IPTABLES} -Z # zero all counters > ${IPTABLES} -P INPUT DROP # Policy = DROP > ${IPTABLES} -P OUTPUT DROP # Drop all packets that are Hmmm...wouldn't do that with OUTPUT because then I guess you'd have to enable the some specific ICMP messages. Comments on that? > ${IPTABLES} -P FORWARD DROP # not specifically accepted. > > # Masquerading (aka NAT, PAT, ...) > ${IPTABLES} -t nat -A POSTROUTING -o ${OUT_DEV} -j MASQUERADE > > # uncomment/modify next 3 lines to forward a service to an internal IP. > # SERVER=192.168.1.1 # Internal IP of server. > # PORT=22 # 22 = SSH. Change to 80 for web server, etc. > # ${IPTABLES} -A PREROUTING -i ${OUT_DEV} -t nat -p TCP --dport $PORT -j DNAT --to ${SERVER}:$PORT I had to add an additional $IPTABLES -A FORWARD -m state --state NEW -p tcp -i ${OUT_DEV} -o ${IN_DEV} -d ${SERVER} --dport ${PORT} -j ACCEPT But I would first add the state rules below and than add any new rules. > > # Allow connections to the internet. > #LOG# ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j LOG > ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j DROP > ${IPTABLES} -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT > ${IPTABLES} -A FORWARD -m state --state NEW -i ${INT_DEV} -j ACCEPT > > # Prevent NetBIOS and Samba from leaking. > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 137:139 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 137:139 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 445 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 445 -j DROP Might want to consider Port 135 too. > > # Allow our firewall to connect. > ${IPTABLES} -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT > ${IPTABLES} -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT As above. I'd group those state related rules right after clearing the chains. > > # Allow Ping and friends. > ${IPTABLES} -A OUTPUT -p icmp -j ACCEPT > ${IPTABLES} -A INPUT -p icmp -j ACCEPT > > # We accept anything from the inside. > ${IPTABLES} -A INPUT -i ${INT_DEV} -j ACCEPT > ${IPTABLES} -A INPUT -i lo -j ACCEPT > ${IPTABLES} -A OUTPUT -o ${INT_DEV} -j ACCEPT > ${IPTABLES} -A OUTPUT -o lo -j ACCEPT As the lo is essential I'd move it right after the state related (EST/RELATED) rules. And tell the user to never ever remove them. > > # Fast reject for Ident to eliminate email delays. > ${IPTABLES} -A INPUT -p TCP --dport 113 -i ${OUT_DEV} -j REJECT --reject-with tcp-reset > > # make interactive sesions a bit more interactive under load > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ssh -j TOS --set-tos Minimize-Delay > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ftp -j TOS --set-tos Minimize-Delay > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ftp-data -j TOS --set-tos Maximize-Throughput > > # Log invalid packets: > #LOG# ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts > #LOG# ${IPTABLES} -A INPUT -j LOG > #LOG# ${IPTABLES} -A FORWARD -j LOG For all the logging you might want to add limit options to not get into troubles when flouded with invalid or block packages (denial of service!) Also "--log-prefix" would be nice. > > # enable dynamic IP address following > echo 7 > /proc/sys/net/ipv4/ip_dynaddr > > # stop some smurf attacks. > echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts > > # Don't accept source routed packets. > echo "0" > /proc/sys/net/ipv4/conf/all/accept_source_route > > # Syncookies > echo "1" > /proc/sys/net/ipv4/tcp_syncookies > > # Stop IP spoofing, > for interface in /proc/sys/net/ipv4/conf/*/rp_filter; do > echo "1" > $interface > done > > # Stop ICMP redirect > for interface in /proc/sys/net/ipv4/conf/*/accept_redirects; do > echo "0" > ${interface} > done > > # Enable bad error message protection. > /bin/echo "1" > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses > > # Enabling IP forwarding. > echo "1" > /proc/sys/net/ipv4/ip_forward You might want to take a look at the example script of the IP-Tables tutorial http://iptables-tutorial.frozentux.net/ You are missing the loading of modules, eg. $MODPROBE ip_conntrack > /dev/null 2>&1 $MODPROBE ip_conntrack_ftp > /dev/null 2>&1 $MODPROBE ip_nat_ftp > /dev/null 2>&1 -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Friedrich L. <fl...@fl...> - 2003-05-28 23:27:34
|
Bruce Smith wrote: > > Is there a better/easier way that I'm overlooking? None that I know of. Sorry ;-( -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Bruce S. <br...@ar...> - 2003-05-28 20:08:53
|
After updating my system with: cvs update -d -P ./update_src What's the best way to continue if the 2nd command downloads new source? I noticed the ./update_src script doesn't seem to unpack the new source in tmp/ and running "make unpack" does everything, if it's already unpacked or not. I guess I could "rm -fr tmp/oldsource" and manually untar the new source in tmp/ , "rm tmp/.done*packagename", and the "make build install iso" Or: make mrproper unpack build ... if I want to waste half a day. Is there a better/easier way that I'm overlooking? -------------------------------------------- Bruce Smith br...@ar... System Administrator / Network Administrator Armstrong International, Inc. Three Rivers, Michigan 49093 USA http://www.armstrong-intl.com/ -------------------------------------------- |
|
From: John v. V. <joh...@ya...> - 2003-05-28 18:26:49
|
Wow Bruce, you are hot !! --- Bruce Smith <bw...@ar...> wrote: > > >I added a simple iptables script that supports 2 NIC's w/masquerading. > > >Please take a look, and comment: > > > > > >http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/config/ > > >etc/init.d/firewall.rules.2nic?rev=HEAD > > > > I wouldn't fix the interface to interna=eth1 and external=eth0 . > > Let the user choose it. > > I'm trying to come up with script(s) that I can copy to firewall.rules > in my new setup script. I need to default them to something. I'm happy > to switch them around if you like that better. > > Also, in my experience, the numbering of ethernet interfaces is very > arbitrary. Even if the cards use two different drivers, I don't know > how to tell which is which without examining the MAC addresses or trying > them. The output of "ifconfig" doesn't say which driver it's using. > > Asking a newbie if they want eth0 or eth1 connected to the internet > isn't going to mean anything to them, unless I can tell them which card > is which. > > So, my instructions would be to plug one NIC into your cable/DSL modem, > and the other into your internal LAN. If it doesn't work, switch the > cables, reboot DL & modem, and try again. > > I'd appreciate advice, if there is a better way. > > > I didn't look over the rules. > > Please do, if you get the time. I'd like many people to look at it > seriously and test it. This script is very preliminary (untested by > myself), and I don't want it to have a security hole somewhere. > > It's true that the code was "borrowed" from a different firewall > package, but I made some changes. We need to check to make sure I > didn't break something while I was at it. I will test it myself, when I > get the time, but I'd feel much better if other people looked at it, and > tested it too. > > > >Much of the code was originally based on a script from my 2nd favorite > > >dedicated Linux firewall distribution. :-) > > > > Thief ;-) > > Open Source! :-) > > - BS > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: ObjectStore. > If flattening out C++ or Java code to make your application fit in a > relational database is painful, don't do it! Check out ObjectStore. > Now part of Progress Software. http://www.objectstore.net/sourceforge > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop ===== CXN, Inc. Contact: jo...@th... President, The Linux Society http://groups.yahoo.com/group/linux-society linux society distro -> http://www.thinman.com/eLSD/readme ThinMan is a registered trademark of CXN, Inc __________________________________ Do you Yahoo!? Yahoo! Calendar - Free online calendar with sync to Outlook(TM). http://calendar.yahoo.com |
|
From: Bruce S. <bw...@ar...> - 2003-05-28 17:59:19
|
> >I added a simple iptables script that supports 2 NIC's w/masquerading. > >Please take a look, and comment: > > > >http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/config/ > >etc/init.d/firewall.rules.2nic?rev=HEAD > > I wouldn't fix the interface to interna=eth1 and external=eth0 . > Let the user choose it. I'm trying to come up with script(s) that I can copy to firewall.rules in my new setup script. I need to default them to something. I'm happy to switch them around if you like that better. Also, in my experience, the numbering of ethernet interfaces is very arbitrary. Even if the cards use two different drivers, I don't know how to tell which is which without examining the MAC addresses or trying them. The output of "ifconfig" doesn't say which driver it's using. Asking a newbie if they want eth0 or eth1 connected to the internet isn't going to mean anything to them, unless I can tell them which card is which. So, my instructions would be to plug one NIC into your cable/DSL modem, and the other into your internal LAN. If it doesn't work, switch the cables, reboot DL & modem, and try again. I'd appreciate advice, if there is a better way. > I didn't look over the rules. Please do, if you get the time. I'd like many people to look at it seriously and test it. This script is very preliminary (untested by myself), and I don't want it to have a security hole somewhere. It's true that the code was "borrowed" from a different firewall package, but I made some changes. We need to check to make sure I didn't break something while I was at it. I will test it myself, when I get the time, but I'd feel much better if other people looked at it, and tested it too. > >Much of the code was originally based on a script from my 2nd favorite > >dedicated Linux firewall distribution. :-) > > Thief ;-) Open Source! :-) - BS |
|
From: Heiko Z. <hz...@pr...> - 2003-05-28 17:31:38
|
On 05/28/2003 11:01:12 AM Bruce Smith wrote: >I added a simple iptables script that supports 2 NIC's w/masquerading.= >Please take a look, and comment: > >http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/confi= g/ >etc/init.d/firewall.rules.2nic?rev=3DHEAD I wouldn't fix the interface to interna=3Deth1 and external=3Deth0 . Let the user choose it. I didn't look over the rules. >Much of the code was originally based on a script from my 2nd favorite= >dedicated Linux firewall distribution. :-) Thief ;-) = |
|
From: <no...@fr...> - 2003-05-28 15:14:35
|
This email is to inform you about the release of version '8.4.0-RC2' of 'bind' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/bind/ The changes in this release are as follows: IPv6 transport support was added for named, named-xfer, and ndc. Project description: The Berkeley Internet Name Domain (BIND) implements an Internet name server for Unix operating systems. The BIND consists of a server (or `daemon') called `named' and a resolver library. A name server is a network service that enables clients to name resources or objects and share this information with other objects in the network. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Concerned about getting enterprise-level support for Linux? No worries, weve got you covered! Oracle provides 24/7, one-stop-shop technical support for Oracle on Red Hat and UnitedLinux. Click to see how Oracle makes Linux unbreakable and stands behind it reducing the risk for you. http://ad.doubleclick.net/clk;5626879;8091585;e?http://www.oracle.com/go/?&Src=1675551&Act=49 ____________________________| Advertising |____________________________ |
|
From: Bruce S. <br...@ar...> - 2003-05-28 15:03:06
|
I added a simple iptables script that supports 2 NIC's w/masquerading. Please take a look, and comment: http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/config/etc/init.d/firewall.rules.2nic?rev=HEAD Much of the code was originally based on a script from my 2nd favorite dedicated Linux firewall distribution. :-) -------------------------------------------- Bruce Smith br...@ar... System Administrator / Network Administrator Armstrong International, Inc. Three Rivers, Michigan 49093 USA http://www.armstrong-intl.com/ -------------------------------------------- |
|
From: <no...@fr...> - 2003-05-28 13:44:04
|
This email is to inform you about the release of version '2.00.3' of 'cdrtools' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/cdrecord/ The changes in this release are as follows: This is mainly a security update to fix a possible root exploit that could be performed if the program is installed suid root. Use recent development versions should be used if you need a version of mkisofs with correct Rock Ridge support. Project description: cdrtools (formerly cdrecord) creates home-burned CDs with a CDR/CDRW recorder. It works as a burn engine for several applications. It supports CD recorders from many different vendors; all SCSI-3/mmc- and ATAPI/mmc-compliant drives should also work. Supported features include IDE/ATAPI, parallel port, and SCSI drives, audio CDs, data CDs, and mixed CDs, full multi-session support, CDRWs (rewritable), TAO, DAO, RAW, and human-readable error messages. cdrtools includes remote SCSI support and can access local or remote CD writers. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Concerned about getting enterprise-level support for Linux? No worries, weve got you covered! Oracle provides 24/7, one-stop-shop technical support for Oracle on Red Hat and UnitedLinux. Click to see how Oracle makes Linux unbreakable and stands behind it reducing the risk for you. http://ad.doubleclick.net/clk;5626879;8091585;e?http://www.oracle.com/go/?&Src=1675551&Act=49 ____________________________| Advertising |____________________________ |
|
From: SourceForge.net <no...@so...> - 2003-05-28 01:34:34
|
Bugs item #740185, was opened at 2003-05-19 19:22 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=740185&group_id=34096 Category: Base System Group: None >Status: Closed >Resolution: Fixed Priority: 5 Submitted By: Heiko Zuerker (smiley73) >Assigned to: Heiko Zuerker (smiley73) Summary: update busybox Initial Comment: get newest version for initrd ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=740185&group_id=34096 |
|
From: SourceForge.net <no...@so...> - 2003-05-28 01:34:14
|
Bugs item #710445, was opened at 2003-03-26 19:25 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=710445&group_id=34096 Category: Base System Group: None >Status: Deleted >Resolution: Postponed Priority: 8 Submitted By: Heiko Zuerker (smiley73) >Assigned to: Heiko Zuerker (smiley73) Summary: support for openssl patches Initial Comment: add support for openssl patches, so we can react fast to security issues. patches: http://www.openssl.org/ ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=710445&group_id=34096 |
|
From: <no...@fr...> - 2003-05-27 16:20:47
|
This email is to inform you about the release of version '2.0.0pre12' of 'Python-LDAP' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/pythonldap/ The changes in this release are as follows: LDAPv3 is now used by default. The new ldap.filter sub-module was added. The trace log was slightly modified. Some code was cleaned up and some bugs were fixed. Project description: python-ldap provides an object-oriented API to access LDAP directory servers from Python programs. It wraps the OpenLDAP 2.x libs for that purpose. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Microsoft Visual Studio .NET is today's comprehensive development tool for the task at hand, built to help you overcome programming challenges and increase productivity. Discover what it can do for you, today. Click here to try a free online hosted session. http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en ____________________________| Advertising |____________________________ |
|
From: <no...@fr...> - 2003-05-27 11:52:29
|
This email is to inform you about the release of version '2.5' of 'distcc' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/distcc/ The changes in this release are as follows: Servers can now limit the number of jobs they will accept, and the server overhead has been reduced. Project description: distcc is a parallel build system that distributes compilation of C/C++/ObjC code across machines on a network. It can be set up in just a few minutes and makes builds up to ten times faster. It does not require machines to share a filesystem or have the same libraries or header files, and installation does not need superuser privileges. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Microsoft Visual Studio .NET is today's comprehensive development tool for the task at hand, built to help you overcome programming challenges and increase productivity. Discover what it can do for you, today. Click here to try a free online hosted session. http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en ____________________________| Advertising |____________________________ |
|
From: <no...@fr...> - 2003-05-26 20:35:40
|
This email is to inform you about the release of version '0.9.7b' of 'OpenSSL' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/openssl/ The changes in this release are as follows: RSA blinding is turned on by default to avoid a timing attack. The RSA blinding code has been changed so that it works when the PRNG is not seeded. The target "mingw" now allows native Windows code to be generated in the Cygwin environment as well as with the MinGW compiler. Project description: The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, fully featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a full-strength general-purpose cryptography library. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Microsoft Visual Studio .NET is today's comprehensive development tool for the task at hand, built to help you overcome programming challenges and increase productivity. Discover what it can do for you, today. Click here to try a free online hosted session. http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en ____________________________| Advertising |____________________________ |
|
From: Heiko Z. <hz...@pr...> - 2003-05-23 22:08:52
|
On 05/23/2003 01:04:33 PM Bruce Smith wrote: >> Put the script in build/scripts/scripts/ , there's also the >save-config. > >Should I also modify build/scripts/copy_base to copy it somewhere so >it'll go into the ISO? (ala save-config) Yes, I would handle it the same way as save-config. Heiko = |
|
From: Bruce S. <bw...@ar...> - 2003-05-23 17:04:50
|
> Put the script in build/scripts/scripts/ , there's also the save-config. Should I also modify build/scripts/copy_base to copy it somewhere so it'll go into the ISO? (ala save-config) - BS |
|
From: Heiko Z. <hz...@pr...> - 2003-05-23 14:09:37
|
On 05/23/2003 08:45:27 AM Bruce Smith wrote: >Currently I have a script written that will edit the two files: >/etc/sysconfig/[software,config] It's not fancy, but it works. >A lot of Q&A, like the kernel "make config". > >Speaking of my scripts, is it permissible to post them to this mailing= >list for people to comment on, or should I upload them somewhere >(where?), and post a URL? They are small, but I know some lists strip= >attachments, and/or they are not permitted. (I'm still new here :) The maximum size of mail is 40kb on this ML. BUT do not attach the script in a mail. Since we're on the DL developer mailing list, I expect everybody in her= e being able to use CVS. So just check the stuff in and people can then try it out. Put the script in build/scripts/scripts/ , there's also the save-confi= g. Heiko = |
|
From: Bruce S. <bw...@ar...> - 2003-05-23 12:45:39
|
> Congratulations on becoming a core developer. Thanks! > The optional boot process can take a lot of turns all of which, except yours, > dilute security and make DL dependent on some external source. > > The method I created in my eLSD version of DL simply finds no floppy and boots > w/o it requiring manual configuration manual input. That is the next project I'm going to work on (manual configuration). My plan is to start out with something fairly simple, to get it working ASAP. Later on we can enhance it, add functionality, pretty it up, etc. My goal is to make DL usable by someone who does not know much about Linux (as a firewall, for home or SOHO). I'm not talking about the old guy down the street who has never touched a computer in his life (at least not to start with). My original target audience is is someone who is computer savvy, but hasn't used Linux. With that in mind, I'm trying to create a script that a Windows admin can use to configure Linux with a few simple instructions, without actually knowing Linux. (he won't need to know VI, config file formats, or command line usage - other than typing my script name) > The most important part of the boot process is configuring the network card. > To do this successfully, the PCI ether recognition process will have to be as > sophisticated as Knoppix. That's going to be the toughest part of my script. Currently I have a script written that will edit the two files: /etc/sysconfig/[software,config] It's not fancy, but it works. A lot of Q&A, like the kernel "make config". Speaking of my scripts, is it permissible to post them to this mailing list for people to comment on, or should I upload them somewhere (where?), and post a URL? They are small, but I know some lists strip attachments, and/or they are not permitted. (I'm still new here :) > Knoppix uses Anaconda where the detection subset is Libhardware. The question > is, "where should this happen in the boot process?" All the ethernet modules > will have to be in the distro in such a place that the boot kernel can find > them. Do you have something working now, that I can use? - BS |
|
From: Manu E. <ee...@ma...> - 2003-05-23 02:17:11
|
Hi Friedrich,
this is quite a Bad bash script (i'm not a developper !) but it works
... sure you can easily improve !
* I use rp-pppoe to connect to the internet 24/24.
* I write a script /etc/ppp/adsl-lost wich is called by
/usr/sbin/adsl-connect each time pppd dies; it simply call update_dyndns
script, but could be used for other stuff to do when Adsl link comes
down (ex change route to use an isdn link as backup ... etc)
* also create a script (from the skeleton) /etc/init.d/adsl to
start/stop/restart adsl link : it simply call /usr/sbin/adsl-start and
then update_dyndns
(started with 0.5b6 ... there was none ... )
* add $WAN_HOST in the /etc/sysconfig/config file to store the dyndns
name for that host
* get_inet_addr and get_ddns_addr are standalone scripts as i use them
for other things. (i know these are bad ;-) )
Comments are welcome ! but don't be too malicious, i'm sensitive ;-)
MaNU
----------------
#!/bin/sh
# script execute quand on remonte le lien adsl
#
# /root/sbin/update_dyndns
#
source /etc/sysconfig/config
logger -p info "Lien ADSL en cours de (re)connexion ... "
if ! [ -f /var/run/adsl-lost.pid ]; then #si le process
n'est pas déja en train de tourner ...
echo "1" > /var/run/adsl-lost.pid
logger -p info "On boucle jusqu'a ppp0 .... "
until [ -d /proc/sys/net/ipv4/conf/ppp0 ] #on boucle
jusqu'a ce que ppp0 soit up ...
do
logger -p info "On attend 1 Minute de plus ... "
sleep 60
done
logger -p info "L'ADSL est de Retour .... "
# on teste si l'ip a change
until test "$MY_DDNS" != ""; do
sleep 1
MY_DDNS=`/root/sbin/get_ddns_addr`
done
until test "$MY_INET" != ""; do
sleep 1
MY_INET=`/root/sbin/get_inet_addr`
done
if test $MY_INET != $MY_DDNS ; then
# l'IP a CHANGE, on a un certain nombre de choses a
mettre a jour
logger -p info "L'adresse a changée : $MY_DDNS =>
$MY_INET .... "
# en commencant par le dynamic DNS
/usr/sbin/ddup --host $WAN_HOST | logger -p info
sleep 5 # un petit delai pour la propagation de la
nouvelle adresse
# puis on recharge les regles du firewall pour prendre
en compte le changement
/usr/bin/setsid /etc/init.d/firewall reload
else
logger -p info "L'adresse est inchangée : $MY_DDNS ==
$MY_INET .... "
fi
rm /var/run/adsl-lost.pid
fi
----------------
----------------
#!/bin/sh
#
# /root/sbin/get_inet_addr
#
ifconfig ppp0 | awk '/inet addr:/ {print $2}' | awk '// {print $2}' FS=":"
----------------
----------------
#!/bin/sh
#
# /root/sbin/get_ddns_addr
#
source /etc/sysconfig/config
nslookup -sil $WAN_HOST | grep -A 1 $WAN_HOST | awk '{print $4}' RS="/"
----------------
|
|
From: John v. V. <joh...@ya...> - 2003-05-22 22:06:08
|
Hi there have been requests for the eLSD images and source so here it is.
The new version, SOY, will be completely newly built using the v0.3 framework,
inside the BOCHS emulator from LinuxBIOS/uClibc components and intends to be
distro that can go into any boot sequence from any boot media (except floppy).
So the new version will be SOY, because eLSD is not controversial enough ;)
##################################
# eLSD CD Boot and HD Images #
# and BOCHS emulator kits #
##################################
http://www.thinman.com/eLSD/
EVERYTHING has tested ok, but the 0.3a release is very raw.
NOTE: Each version directory has a README.txt that supports that release.
eLSD v0.2 First true eLSD, major changes to the linuxrc and init.d/boot files
* Does not require a boot floppy
- Builds a boot floppy w/ save-config
>>-> http://www.thinman.com/eLSD/eLSD-0.2/
* BOCHS emulator kit
- boots inside and emulator built, complete kit
>>-> http://www.thinman.com/bochs/eLSD-v0.2-bochs-img.tar.gz
eLSD v0.3a EXPERIMENTAL hard drive version designed to burn eLSD/Devil-Linux
CDs.
* Initrd w/ new busybox/tinylogin tools which works independantly
- Your /boot partition is in control of the system
* Initrd that boots to the DL derived hard drive eLSD OS
- this allows and FSCK of the root file system w/o mounting
it
* Gnu/grub boot floppy that has a kernel but no OS
- Make the boot disk bootable, no tutorial
* Gnu/parted floppies which has a full OS but no grub :(
- First step in dist'n linux, includes text tutorial
* New kernel which supports CDRECORD w/o append lines in boot
process so that DL/eLSD can burn DL/eLSD from the CD boot
>>-> http://www.thinman.com/eLSD/eLSD-0.3/
## Future
Soy v0.1 Complex Struture Model
* System configuration through complex structures
* Structures scale to distributed portal
* Refined application server model
-----
bzip2 binary is provided in case you dont have it
-----
#########################
# #
# Directory Information #
# #
#########################
** eLSD ver. 2 and 3 Directories
==========
eLSD-0.2/
==========
Includes DL boot w/ or w/o /etc on a floppy disk
** Images
eLSD-0.2/
eLSD-0.2.tar.bz2
eLSD-0.2.tar.bz2.md5sum
** Source Directories in Tarball
src/eLSD-0.2.tar.gz
===========
eLSD-0.3/
===========
Copies DL type Image to Harddrive and boot as DL does
** /boot Directory
boot/bzImage
boot/initrd.gz
boot/initrd_bb.gz
boot/initrd_busybox.gz@
boot_dir.tar.bz2
boot_dir.tar.bz2.md5sum
** Hard Drive Images
eLSDhd.iso
eLSDhd.tar.bz2
eLSDhd.tar.bz2.md5sum
** Boot and Disk Tools
grubboot_ext2fs.img
grubboot_ext2fs.img.md5sum
partboot.img.bz2
partboot.img.bz2.md5sum
partroot.img.bz2
partroot.img.bz2.md5sum
** Source Directories in Tarball
src/eLSDhd.tar.gz
=====
CXN, Inc. Contact: jo...@th...
President, The Linux Society
http://groups.yahoo.com/group/linux-society
linux society distro -> http://www.thinman.com/eLSD/readme
ThinMan is a registered trademark of CXN, Inc
__________________________________
Do you Yahoo!?
The New Yahoo! Search - Faster. Easier. Bingo.
http://search.yahoo.com
|
|
From: <no...@fr...> - 2003-05-22 18:50:36
|
This email is to inform you about the release of version '2.0.10' of 'Postfix' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/postfix/ The changes in this release are as follows: This release fixes lots of documentation and a few minor code problems, none security related. Project description: Postfix is an attempt to provide an alternative to the widely-used Sendmail program. Postfix attempts to be fast, easy to administer, and hopefully secure, while at the same time being sendmail compatible enough to not upset your users. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net ____________________________| Advertising |____________________________ Microsoft Visual Studio .NET is today's comprehensive development tool for the task at hand, built to help you overcome programming challenges and increase productivity. Discover what it can do for you, today. Click here to try a free online hosted session. http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en http://fmads.osdn.com/cgi-bin/redirect.pl?micr5043en ____________________________| Advertising |____________________________ |
|
From: SourceForge.net <no...@so...> - 2003-05-22 15:34:27
|
Bugs item #725157, was opened at 2003-04-21 13:40 Message generated for change (Settings changed) made by smiley73 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=725157&group_id=34096 Category: Build System >Group: v1.0 >Status: Closed >Resolution: Fixed Priority: 5 Submitted By: Heiko Zuerker (smiley73) >Assigned to: Bruce Smith (blubdog) Summary: menuconfig help Initial Comment: add help for the various menuconfig entries ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=725157&group_id=34096 |
|
From: Friedrich L. <fl...@fl...> - 2003-05-22 15:33:54
|
SourceForge.net wrote: > Bugs item #741777, was opened at 2003-05-22 09:55 > Message generated for change (Tracker Item Submitted) made by Item Submitter > You can respond by visiting: > https://sourceforge.net/tracker/?func=detail&atid=410643&aid=741777&group_id=34096 > > Category: Base System > Group: None > Status: Open > Resolution: None > Priority: 5 > Submitted By: Heiko Zuerker (smiley73) > Assigned to: Nobody/Anonymous (nobody) > Summary: depmod: unresolved symbols in pcwd.o > > Initial Comment: > message comes up on final system > even after a clean build Maybe we just copy the pcwd stuff over to the kernel tree so it replaces the original pcwd module completely. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: Friedrich L. <fl...@fl...> - 2003-05-22 15:29:03
|
John van V. wrote: > The optional boot process can take a lot of turns all of which, except yours, > dilute security and make DL dependent on some external source. > > The method I created in my eLSD version of DL simply finds no floppy and boots > w/o it requiring manual configuration manual input. > > At the end of the day, there are a huge number of boot options. The most > interesting is a net config, most simply where it gets /etc from an https > server. > > The most important part of the boot process is configuring the network card. > To do this successfully, the PCI ether recognition process will have to be as > sophisticated as Knoppix. > > Knoppix uses Anaconda where the detection subset is Libhardware. The question > is, "where should this happen in the boot process?" All the ethernet modules > will have to be in the distro in such a place that the boot kernel can find > them. Is this just planned or do you have anything working right now? Because we are restructuring things quite heavly now might be time to post your stuff to get it integrated before changes are too big which might complicate adapting your stuff. > Initrd should be kept as small as possible since it requires size configuration > in the kernel. That's true but we only need a minimal system ramdisk that creates a ramdisk, loads the needed drivers to access the cdrom, loads stuff from there and finaly the whole system boots. > This is why I am tending towards a whole new build, where the majority of the > process occurs in a boot kernel built under uClibc. I guess this will have to wait for 2.6 and its initramfs. > One problem I have found, say with busybox, is that the init process guides you > to the tradioinal boot sometimes locking you into a process that the BB group > has determined is desireable, mostly for utility/setup linuxes. Sorry I don't understand what you are talking about. > the LinuxBIOS folks are using uClibc linux and offer a reboot process called > kexec. The word "monte" also appears on their lists as well. Yes I know of two-kernel-monte but that does not actually work for 2.4 anymore. uClinux is actually kernel 2.0. But that's embedded stuff. And kexec I think is for kernel 2.5/2.6. > I am trying to do recall on the whole thing, but my conclusion has been to > restart with a whole new Linux and to build it in BOCHS rather than VMWare to > keep it a fully open source project. > > BOCHS seems to do compression very poorly, but then decompressing images also > slows down the DL boot process. > > LinuxBIOS, by comparison boots in 3 seconds. But.. you have to have a kernel > hacked for the specfic hardware. None the less, I think the rest of the > LinuxBIOS suite is desirable for a future DL. > > GRUB, PartEd and LVM would benefit from uClibc compiling as well to help make a > HD version of DL. My vision of this is to have Linux boot in Initrd or VFS and > do a complete check on the disks before using any of them. Traditional Linux > boots from the root disk, of course, in read only and then goes through the > familiar fsck process and dropout to a single user shell. For me the uClibc and initramfs stuff will have to wait for kernel 2.6. For kernel 2.4 we'll have to live with the current schema but we'll for sure will try to optimize that. > I am presently insanely busy trying to: find a job, get college started, and > flesh out my dream of bring DL type linuxes a focus for the UNESCO WSIS > conferences coming up soon. I wish you the best. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |
|
From: John v. V. <joh...@ya...> - 2003-05-22 15:06:44
|
Hi, Congratulations on becoming a core developer. The optional boot process can take a lot of turns all of which, except yours, dilute security and make DL dependent on some external source. The method I created in my eLSD version of DL simply finds no floppy and boots w/o it requiring manual configuration manual input. At the end of the day, there are a huge number of boot options. The most interesting is a net config, most simply where it gets /etc from an https server. The most important part of the boot process is configuring the network card. To do this successfully, the PCI ether recognition process will have to be as sophisticated as Knoppix. Knoppix uses Anaconda where the detection subset is Libhardware. The question is, "where should this happen in the boot process?" All the ethernet modules will have to be in the distro in such a place that the boot kernel can find them. Initrd should be kept as small as possible since it requires size configuration in the kernel. This is why I am tending towards a whole new build, where the majority of the process occurs in a boot kernel built under uClibc. One problem I have found, say with busybox, is that the init process guides you to the tradioinal boot sometimes locking you into a process that the BB group has determined is desireable, mostly for utility/setup linuxes. the LinuxBIOS folks are using uClibc linux and offer a reboot process called kexec. The word "monte" also appears on their lists as well. I am trying to do recall on the whole thing, but my conclusion has been to restart with a whole new Linux and to build it in BOCHS rather than VMWare to keep it a fully open source project. BOCHS seems to do compression very poorly, but then decompressing images also slows down the DL boot process. LinuxBIOS, by comparison boots in 3 seconds. But.. you have to have a kernel hacked for the specfic hardware. None the less, I think the rest of the LinuxBIOS suite is desirable for a future DL. GRUB, PartEd and LVM would benefit from uClibc compiling as well to help make a HD version of DL. My vision of this is to have Linux boot in Initrd or VFS and do a complete check on the disks before using any of them. Traditional Linux boots from the root disk, of course, in read only and then goes through the familiar fsck process and dropout to a single user shell. I am presently insanely busy trying to: find a job, get college started, and flesh out my dream of bring DL type linuxes a focus for the UNESCO WSIS conferences coming up soon. John --- Bruce Smith <bw...@re...> wrote: > I just uploaded changes to CVS that allows DL to create a default > configuration for you. If during the boot, DL finds an empty floppy in > the drive, it now asks permission to copy the default etc tar file to > the floppy. It also gives you the option to probe for SCSI controllers > in case your CD drive is on a SCSI chain. > > This simplifies a new DL install. Instead of having to create the > floppy manually, now just boot the first time with a blank/formatted > floppy in the drive, and answer the questions. > > Existing installations (that already have a good config on floppy) will > not notice any difference. > > Before building a new ISO, you must create a new etc directory. If you > don't want to start over with a "make mrproper", do this: > > rm tmp/.done_install_015_create_etc tmp/.done_iso_100_build-iso > make install > make iso > > and test out my new changes! :-) > > - BS > > > > > ------------------------------------------------------- > This SF.net email is sponsored by: ObjectStore. > If flattening out C++ or Java code to make your application fit in a > relational database is painful, don't do it! Check out ObjectStore. > Now part of Progress Software. http://www.objectstore.net/sourceforge > _______________________________________________ > Devil-linux-develop mailing list > Dev...@li... > https://lists.sourceforge.net/lists/listinfo/devil-linux-develop ===== CXN, Inc. Contact: jo...@th... President, The Linux Society http://groups.yahoo.com/group/linux-society linux society distro -> http://www.thinman.com/eLSD/readme ThinMan is a registered trademark of CXN, Inc __________________________________ Do you Yahoo!? The New Yahoo! Search - Faster. Easier. Bingo. http://search.yahoo.com |