home tags events about rss login

Stand back... I'm going to write some code.

(aka @timkuijsten@mastodon.social)

kuijsten honked

Just released filter-dmarc v0.3.0. It now supports non-UTF-8 mail bodies and does stricter filter protocol parsing. If you are interested in #DMARC with #OpenSMTPD you should definitely give it a try.

https://netsend.nl/opensmtpd-filter-dmarc/

TODO:
Currently on OpenBSD "stdio rpath inet" is pledged and everything, that is DMARC, DKIM and SPF verification including DNS resolving, is done by Stalwart's mail-auth (written in Rust). I want to only pledge "stdio" to this huge amount of Rust code and do DNS resolving using OpenBSD native asr(3) in a separate process.

kuijsten honked

I'm happy to share my #DMARC filter for #OpenSMTPD with a wider audience. I've been running it for several weeks myself and so far DMARC is being enforced successfully while no legitimate mail has been blocked. This is just a thin wrapper around @stalwartlabs's DMARC, DKIM and SPF implementations.

It supports an --spf-only-domains argument so that you can easily bypass DMARC for mailing lists like openbsd.org or lists.openwall.com.

See https://netsend.nl/opensmtpd-filter-dmarc/

kuijsten honked

Just released an update to my spf and spamtrap filters for #OpenSMTPD. If you are using them on a listener with auth enabled (i.e. listen on ... auth filter spf) you should update immediately because otherwise an attacker can bypass the filter.

Fixed in filter-spf v1.0.2 and filter-spamtrap v1.0.0, both released today.

kuijsten honked

Just released a fix for #OpenSMTPD filter-spf on OpenBSD 7.9. Apparently pledge dns needs to be accompanied with rpath /etc/resolv.conf.

kuijsten honked

In case you like to do DNS lookups using #Go on #OpenBSD with pledge you have to set GODEBUG=netdns=cgo or compile using go build -tags netcgo ...

I.e. to make my honk resolve hostnames again without recompiling I have set the following:

$ cat /etc/login.conf.d/honk
honk:\
	:setenv=GODEBUG=netdns=cgo:\
	:tc=daemon:

kuijsten honked

Happy to see symon v2.91 is released and available in #openbsd current! 🎉

  • modernized mbuf and smart probes
  • new wg(4) probe
  • new time probe to measure cpu usage of symon itself
  • tight pledge and unveil for symux(8)
  • unveil for symon(8)
  • removed old 2001-2004 era ifdefs

mbuf:
- model after systat(1) mbufs
- add missing cluster mcl2k2
- big performance improvements
- stricter sysctl error handling
- remove ifdef KERN_MBSTAT (defined since OpenBSD 3.2)

smart:
- support running unpriviledged
- support disklabel UIDs using opendev(3)
- use xreallocarray instead of xrealloc
- stricter ioctl error check

pkg_add symon symux

kuijsten honked

@damienmiller is there a place I can read or watch about the rationale of openssh replacing sntrup761x25519-sha51 with mlkem768x25519-sha256 as the default kem?

kuijsten bonked
original: libreleah@mas.to

update regarding my librewolf port for OpenBSD: it works perfectly. i screwed up the branding, so the menu icons (e.g. lxqt menu) say firefox. easy fix (just have to enable librewolf branding in the build process; accidentally removed it earlier)

https://codeberg.org/vimuser/librewolf-openbsd-port

will update for openbsd 7.9 soon (current package is 7.8) and then also for CURRENT. debating whether or not to maintain a temporary package repo, until openbsd merges it. i plan on sending to the openbsd ports team for review.

openbsd librewolf

kuijsten bonked
original: eanakashima@hachyderm.io

My greatest professional accomplishment of the year: I got my exec & manager teammates saying "point positive," a term from whitewater rafting and kayaking.

Meaning: when facing hazards, point people toward where to go/what to do, rather than drawing attention to everything to avoid.

A drawing showing a river rafter who has fallen out of a raft in rapids. The people still in the raft are pointing to a safe way to swim rather than at rocks to avoid. Caption: "Point positive: pointing the way to go, rather than at the problem." Drawing created by sketchplanations.