From hopet at ics.muni.cz Tue Jul 2 15:30:47 2002 From: hopet at ics.muni.cz (Petr Holub) Date: Tue, 2 Jul 2002 15:30:47 +0200 Subject: IPsec mezi FreeBSD a Win2k In-Reply-To: <9E85DC6CA1D5D311BB460006293960FEDCA5D4@dcrfs.decros.cz> Message-ID: <002a01c221cc$aca0f5b0$2603fb93@kloboucek> Dobry den, zkuste se podivat na http://www.cesnet.cz/doc/techzpravy/2002/ipsec/ a zde zminene dokumenty. Pokud to nezabere, tak se na to muzem podivat podrobne. Pomerne dulezite je How to Configure IPSec Tunneling in Windows 2000, http://support.microsoft.com/support/kb/articles/q252/7/35.asp - jak si zpravne zkonfigurovat ty Windowse. Petr ================================================================ Petr Holub CESNET z.s.p.o. Supercomputing Center Brno Zikova 4 Institute of Compt. Science 160 00 Praha 6, CZ Masaryk University Czech Republic Botanicka 68a, 60200 Brno, CZ e-mail: Petr.Holub at cesnet.cz phone: +420-5-41512213 e-mail: hopet at ics.muni.cz > -----Original Message----- > From: owner-users-l at freebsd.cz [mailto:owner-users-l at freebsd.cz]On > Behalf Of Prib Pavel > Sent: Friday, June 28, 2002 8:32 AM > To: users-l at freebsd.cz > Subject: IPsec mezi FreeBSD a Win2k > > > Preji pekny den. > > Mam problem pri vytvareni spojeni mezi FreeBSD a Win2k. > Jako zaklad pro experimentovani jsem pouzil > > http://www.wiretapped.net/~fyre/ipsec/ > http://www.sigsegv.cx/FreeBSD-WIN2K-IPSEC-HOWTO.html > > Import klicu z FreeBSD do Win2k probehl OK. > > A po pingu mi na FreeBSD vybehne od racoonu nasledujici chyba: > > Foreground mode. > 2002-06-28 08:23:27: INFO: main.c:168:main(): > 2002-06-28 08:23:27: INFO: main.c:170:main(): @r ouzz uzzhZ > 2002-06-28 08:23:27: INFO: main.c:171:main(): @(#)This product linked > (http://www.openssl.org/) > 2002-06-28 08:23:27: INFO: isakmp.c:1357:isakmp_open(): used as > isakmp port (fd=-1077937456) > 2002-06-28 08:23:27: INFO: isakmp.c:1357:isakmp_open(): used as > isakmp port (fd=9) > 2002-06-28 08:23:27: INFO: isakmp.c:1357:isakmp_open(): used as > isakmp port (fd=9) > 2002-06-28 08:23:43: INFO: isakmp.c:1681:isakmp_post_acquire(): > IPsec-SA request for @ER > z queued due to no phase1 found. > 2002-06-28 08:23:43: INFO: isakmp.c:795:isakmp_ph1begin_i(): initiate > new phase 1 negotiation: `n <=>192.168.51.49[500] > 2002-06-28 08:23:43: INFO: isakmp.c:800:isakmp_ph1begin_i(): begin > mode. > 2002-06-28 08:23:43: INFO: vendorid.c:128:check_vendorid(): received > Vendor IDEl > 2002-06-28 08:23:44: ERROR: oakley.c:1532:oakley_getsign(): failed to > get private key. > 2002-06-28 08:23:44: ERROR: isakmp.c:623:ph1_main(): failed to process > packet. > 2002-06-28 08:23:44: ERROR: isakmp.c:437:isakmp_main(): phase1 > negotiation failed. > > Kde muze byt chyba ? > > > Diky. > > Pavel > From dan at obluda.cz Tue Jul 2 16:55:55 2002 From: dan at obluda.cz (Dan Lukes) Date: Tue, 02 Jul 2002 16:55:55 +0200 Subject: IPsec mezi FreeBSD a Win2k References: <002a01c221cc$aca0f5b0$2603fb93@kloboucek> Message-ID: <3D21BEFB.30803@obluda.cz> Petr Holub wrote: >>Mam problem pri vytvareni spojeni mezi FreeBSD a Win2k. >>Import klicu z FreeBSD do Win2k probehl OK. >>2002-06-28 08:23:43: INFO: vendorid.c:128:check_vendorid(): received >>Vendor IDEl >>2002-06-28 08:23:44: ERROR: oakley.c:1532:oakley_getsign(): failed to >>get private key. >>Kde muze byt chyba ? Mate klice na Windows ulozene v "Computer store" nikoli v "Personal store" ? Klic CA, ktera certifikovala klice, ktere nyni mate na Voknech mate n FreeBSD pojmenovan "hash".0 jmenem ? Do debug logu na WIndowsech jste se dival, jestli tam nebude neco zajimaveho ? -------- Logovani IPsec na strane Windows se zapne v registry: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent\Oakley] "EnableLogging"=dword:00000001 "Debug"=dword:000000ff log se vytvari v %SystemRoot%\debug\oakley.log - ale format neni nikde popsany, takze je nutna intuice a znalost ISAKMP protokolu. ----------- Ono toho, bohuzel, muze byt strasna spousta co je pripadne spatne, navic v tomto ohledu je mozna snazsi popsat vam cely postup konfigurace nez hledat kde je chyba ve vasem nastaveni ... Ja to zkousel uz pred ctvrt rokem a tak uz si detaily nepamatuju - a transportni mod za situace, kdy obe strany mely statickou adresu mi pripadal trivialni, takze jsem si ho ani nezapsal. V pripade nouze tu jeste mam (almost) step-by-step postup jak rozjet transport-mode IPSec mezi FreeBSD se statickou adresou a W2K s adresou dynamickou - neni to presne to co potrebujete, ale treba by vam to pomohlo. Dan -- Dan Lukes tel: +420 2 21914205, fax: +420 2 21914206 root of FIONet, KolejNET, webmaster of www.freebsd.cz AKA: dan at obluda.cz, dan at freebsd.cz, dan at kolej.mff.cuni.cz From vasek at openbsd.cz Tue Jul 2 17:18:23 2002 From: vasek at openbsd.cz (Vaclav Rehak) Date: Tue, 2 Jul 2002 17:18:23 +0200 Subject: IPsec mezi FreeBSD a Win2k In-Reply-To: <3D21BEFB.30803@obluda.cz>; from dan@obluda.cz on Tue, Jul 02, 2002 at 04:55:55PM +0200 References: <002a01c221cc$aca0f5b0$2603fb93@kloboucek> <3D21BEFB.30803@obluda.cz> Message-ID: <20020702171823.B10308@openbsd.cz> on Tue, Jul 02, 2002 at 04:55:55PM +0200, Dan Lukes wrote: > Petr Holub wrote: > >>Mam problem pri vytvareni spojeni mezi FreeBSD a Win2k. > > >>Import klicu z FreeBSD do Win2k probehl OK. > >>2002-06-28 08:23:43: INFO: vendorid.c:128:check_vendorid(): received > >>Vendor IDEl > >>2002-06-28 08:23:44: ERROR: oakley.c:1532:oakley_getsign(): failed to > >>get private key. > > > >>Kde muze byt chyba ? > Ono toho, bohuzel, muze byt strasna spousta co je pripadne spatne, navic > v tomto ohledu je mozna snazsi popsat vam cely postup konfigurace nez > hledat kde je chyba ve vasem nastaveni ... > > Ja to zkousel uz pred ctvrt rokem a tak uz si detaily nepamatuju - a > transportni mod za situace, kdy obe strany mely statickou adresu mi > pripadal trivialni, takze jsem si ho ani nezapsal. V pripade nouze tu Pokud je chyba na strane Windows, mohlo by se Vam hodit tohle: http://www.cs.umd.edu/~mvanopst/xp2obsd.pdf Je to pomerne pekny popis tunel modu mezi OpenBSD isakmpd a Win 2k (resp. XP). Pri trose fantazie by to melo byt pouzitelne i pro FreeBSD. > jeste mam (almost) step-by-step postup jak rozjet transport-mode IPSec > mezi FreeBSD se statickou adresou a W2K s adresou dynamickou - neni to > presne to co potrebujete, ale treba by vam to pomohlo. Na tohle bych se rad podival. Podle vyse uvedeneho navodu mi uz funguje vsechno a jedine, co zatim brani praktickemu nasazeni, jsou dynamicka IPcka. Vaclav Rehak From dan at obluda.cz Tue Jul 2 18:02:53 2002 From: dan at obluda.cz (Dan Lukes) Date: Tue, 02 Jul 2002 18:02:53 +0200 Subject: IPsec mezi FreeBSD a Win2k References: <002a01c221cc$aca0f5b0$2603fb93@kloboucek> <3D21BEFB.30803@obluda.cz> <20020702171823.B10308@openbsd.cz> Message-ID: <3D21CEAD.30407@obluda.cz> Vaclav Rehak wrote: > Je to pomerne pekny popis tunel modu mezi OpenBSD isakmpd a Win 2k > (resp. XP). Pri trose fantazie by to melo byt pouzitelne i pro FreeBSD. isakmpd ale neni racoon, takze ten dokument muze byt pouzitelny jen podminene - a to i v pripade, ze je problem skutecne pouze na strane WIndows > >>jeste mam (almost) step-by-step postup jak rozjet transport-mode IPSec >>mezi FreeBSD se statickou adresou a W2K s adresou dynamickou - neni to >>presne to co potrebujete, ale treba by vam to pomohlo. > Na tohle bych se rad podival. Podle vyse uvedeneho navodu > mi uz funguje vsechno a jedine, co zatim brani praktickemu nasazeni, > jsou dynamicka IPcka. Podotykam, ze jsem uvedeny navod nepsal pro ucely teto konference a ani jsem ho ted kvuli ni neprepisoval (pouze jsem vynechal casti zabyvajici se konfiguracemi jinych typu spojeni) - tomu odpovida pouzity jazyk. Pro vas ale asi bude zajimavejsi varovani, ze klic k tomu, aby Vokna mohly mit dynamickou adresu spociva ve specificke konfiguraci racoona - a tak pokud pouzivate isakmpd, zrejme to stejne nebudete moci pouzit. A pokud pouzijete racona, tak co se praktickeho nasazeni tyce, jsou dynamicke adresy jen podruznym problemem - hlavnim problemem pro prakticke nasazeni je to, ze OpenSSL (respektive racoon) zatim jeste nema v tuto chvili implementovanou podporu pro CRL - a bez toho je v praxi prakticky nenasaditelny (jak je na tom v tomto ohledu isakmpd nevim). Dan ======================================================================= Pro ucely techto konfiguraci predpokladam, ze laskavy ctenar je alespon zakladne seznamem s principy IPSec a jeho implementaci na FreeBSD (protoze jinak je to na obrovsky dlouhe povidani), vi jaka je uloha racoon daemona v cele te veci, neni mu uplne neznamy pojem Oakley/ISAKMP (protokol pouzivany (nejen) Racoonem pro vymenu informaci), ma alespon zakladni prehled o problematice PKIX, X509 a tak podobne. Jeste technicka poznamka - sice jsem svemu software zakazal zalamovat radky, ale stat se to, preci jen, muze - proto kazdy radek jest predchazen znakem '!'. Pokud radek timto znakem nezacina, je to nejspis zalomenina z radku predchoziho. ... [3]=== Transport FreeBSD vs Windows 2000, dynamic, X509 ============ Na strane Windows predpokladam nikoli Basic W2k, ale W2k se vsemi dostupnymi patchy. Je mozne, ze nejsou potrebne vsechny, ale neoveroval jsem minimalni seznam nutnych. Jiste je, ze urcite musi byt instalovany High Encryption Patch a pravdepodobne i SP2. Instalovany musi byt take Client Microsoft Network, nemusi vsak byt bindnuty k zadne sitove karte a prislusny service muze byt disabled. ---- ipsec.conf (pro setkey, strana FreeBSD) -------- !flush; !spdflush; ---- ipsec.conf (pro setkey) - END ------------------ ---- racoon.conf (pro racoon, strana FreeBSD) ------- !path include "/usr/local/etc/racoon" ; !path certificate "/usr/local/etc/racoon" ; !padding !{ ! maximum_length 20; # maximum padding length. ! randomize off; # enable randomize length. ! strict_check off; # enable strict check. ! exclusive_tail off; # extract last one octet. !} !timer !{ ! counter 5; # maximum trying count to send. ! interval 20 sec; # maximum interval to resend. ! persend 1; # the number of packets per a send. ! phase1 30 sec; ! phase2 15 sec; !} !remote anonymous !{ ! exchange_mode main,aggressive; ! doi ipsec_doi; ! my_identifier address; ! certificate_type x509 "dz.pem" "dzk.pem"; ! generate_policy on; ! nonce_size 16; ! lifetime time 1 min; # sec,min,hour ! initial_contact on; ! support_mip6 on; ! proposal_check obey; # obey, strict or claim ! ! proposal { ! encryption_algorithm 3des; ! hash_algorithm md5; ! authentication_method rsasig ; ! dh_group 2 ; ! } !} ! !sainfo anonymous !{ ! pfs_group 1; ! lifetime time 30 sec; ! encryption_algorithm 3des,des,cast128,blowfish ; ! authentication_algorithm hmac_sha1, hmac_md5; ! compression_algorithm deflate ; !} ---- racoon.conf (pro racoon) - END ------------------ Konfigurace Windows neni zdaleka tak pekne vysvetlitelna. Spustite mmc.exe. Console->[Add/Remove Snap In]->Add Vyberete [IP Security Policy Manager] a [Certificates] (V obou pripadech Local Computer, u Certifikatu je jeste jedna volba, spravna je "Computer Account"). [OK] az do zakladniho menu MMC. Do "Console Root\Certificates (Local Computer)\Trusted Root Certification Authorities\Certificates" date certifikaty certifikacnich autorit klicu obou stran (pridava se pres prave tlacitko, "All tasks->Import"), samozrejme, pokud vydala oba klice jedna autorita, staci jen jednou. Do "Console Root\Certificates (Local Computer)\Personal\Certificates" date certifikat a klic generovany pro tuto stanici. Pro jistotu overite, ze status pridaneho certifikatu je "OK" Tim by mely byt certifikaty hotovy. Jste je ale nutne vyrobit Polici - takze [IP Security Policy Manager], New (pravym tlacitkem), nejak ji pojmenovat NEMIT zasktnuti "Activate the default response rule", zato zaskrtnout "Edit properties". Zalozku [General] nechat zcela byt, vytvorit novou IP Security Rule (tlacitko Add). THIS RULE DOES NOT SPECIFY A TUNNEL, [All Network Connections], Use a Certificate from this Certificate Authority a Browse (najit Certifikat te CA, ktera podepsala klic PROTEJSIHO stroje). Jsme v IP FILTER LISTS. Zde [Add], znovu [Add], SOurce Address je "My address", Destination je "specific DNS address" nebo "specific IP address", protocol je Any, a mame [Finish] a po nem [Close]. Jsme zpet v "IP filter lists", kde zaskrtneme prave vyvoreny a [Next], "Require security" (NOT Optional!) a [Next] a [Finish] a [Close]. Jsme zpet v MMC. Pravym tlacitkem na prave vytvorene Polici a aktivovat "Assign". Od teto chvile by to melo, teoreticky, fungovat. Muzete zkusit spustit IPsecmon, zda je navazana konexe. Podotykam, ze ta se navazuje "on demand", takze nejprve je nutne vyvolat nejakou komunikaci s druhym koncem (pozor, primo s druhym koncem - to co mame NENI tunnel). ------------------------------------------ ... Logovani IPsec na strane Windows se zapne v registry: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PolicyAgent\Oakley] "EnableLogging"=dword:00000001 "Debug"=dword:000000ff log se vytvari v %SystemRoot%\debug\oakley.log - ale format neni nikde popsany, takze je nutna intuice a znalost ISAKMP protokolu. ... ==================================================================== -- Dan Lukes tel: +420 2 21914205, fax: +420 2 21914206 root of FIONet, KolejNET, webmaster of www.freebsd.cz AKA: dan at obluda.cz, dan at freebsd.cz, dan at kolej.mff.cuni.cz From ZEJDLT1 at cs.felk.cvut.cz Tue Jul 2 22:43:14 2002 From: ZEJDLT1 at cs.felk.cvut.cz (Tomas Zejdlik) Date: Tue, 2 Jul 2002 22:43:14 +0200 Subject: problem s detekci pcib Message-ID: Zdravim, prosim, netusite nekdo, kde by mohl byt problem? Mam MB (cca 98 rocnik)s chipsetem VXPro II, (HT82C371USBII, HT82C437VXII) Cyrix 200mhz, 2xisa+4xpci (vsechny pci obsazeny) V linuxu pci bez problemu, najde vsechny zarizeni - cat /proc/pci PCI devices found: Bus 0, device 5, function 0: Host bridge: Unknoendor Unknown device (rev 0). Vendor id=3388. Device id=8011. Sevsel. Fast back-to-back capable. Master Capable. Latency=64. Bus 0, e 5, function 1: ISA bridge: Unknown vendor Unknown device (rev 0). Vendor id=3388. Device id=8012. Slow devsel. Fast back-to-back capa Master Capable. Latency=64. Bus 0, device 5, function 2: IDE ince: Unknown vendor Unknown device (rev 0). Vendor id=3388. Device id= Medium devsel. Fast back-to-back capable. Bus 0, device 8, fun 0: Communication controller: Lucent (ex-AT&T) Microelectronics L56xMF 1). Medium devsel. Fast back-to-back capable. IRQ 5. Master CapabNo bursts. Min Gnt=252.Max Lat=14. Non-prefetchable 32 bit memory atfe7f00 [0xebfe7f00]. I/O at 0xefe0 [0xefe1]. I/O at 0xec00 [0xe Bus 0, device 9, function 0: Ethernet controller: Realtek 8029 (). Medium devsel. IRQ 10. I/O at 0xef40 [0xef41]. Bus 0, device 10, function 0: Multimedia audio controller: Unknown ve Unknown device (rev 1). Vendor id=125d. Device id=1969. Mediumel. Fast back-to-back capable. IRQ 11. Master Capable. Latency=64. Min2.Max Lat=24. I/O at 0xef00 [0xef01]. I/O at 0xefa0 [0xefa1]. I/O at 0xef90 [0xef91]. I/O at 0xeff4 [0xeff5]. I/O at 0xeff0 [1]. Bus 0, device 11, function 0: VGA compatible controller: S3 InRGE/DX or /GX (rev 1). Medium devsel. Master Capable. Latency=64. nt=4.Max Lat=255. Non-prefetchable 32 bit memory at 0xec000000 [0xec0]. vse fungujici, avsak pri nabootovani fbsd - FreeBSD 4.4-RELEASE #0: Sun Jun 30 18:35:33 CEST 2002 root at chcipacek.chm:/usr/obj/usr/src/sys/CHCIPACEK Timecounter "i8254" frequency 1193182 Hz Tunter "TSC" frequency 199740825 Hz CPU: Cyrix 6x86MX (199.74-MHz 686-class Origin = "CyrixInstead" Id = 0x600 Stepping = 0 DIR=0x0853 Featuresa135 real memory = 100663296 (98304K bytetsmb_dev: loaded md0: Malloc disk npx0: on motherboard npxT 16 interface isa0: on motherboard orm0:
ukaz takze nakoniec dostanete nieco take ze test.php?a=nieco.... ide o to ze absolutne ignoruje hodnotu a a tvari sa ze tam nie je nic, takze mu to nedovoli zapisat ten query string toz kde moze byt chyba ? Dik Michal Kapalka From kapalka at mfn.sk Thu Sep 12 10:49:03 2002 From: kapalka at mfn.sk (Michal Kapalka) Date: Thu, 12 Sep 2002 10:49:03 +0200 Subject: instalacia mod_php4 z portou In-Reply-To: <002601c25988$6ba1def0$1501a8c0@mkapalka> Message-ID: <003601c25a39$3f968520$1501a8c0@mkapalka> Cavte Vyriesenie : bolo to v php.ini boli tam nastavene nieake blokady a tak to nehralo Ahojte Michal Kapalka -----Original Message----- From: owner-users-l at freebsd.cz [mailto:owner-users-l at freebsd.cz] On Behalf Of Michal Kapalka Sent: Wednesday, September 11, 2002 1:43 PM To: users-l at freebsd.cz Subject: RE: instalacia mod_php4 z portou Php pod FreeBSD nedovoli puistit ziadnu hodnonotu cez query string ??? Napr.

ukaz takze nakoniec dostanete nieco take ze test.php?a=nieco.... ide o to ze absolutne ignoruje hodnotu a a tvari sa ze tam nie je nic, takze mu to nedovoli zapisat ten query string toz kde moze byt chyba ? Dik Michal Kapalka From dobes at tesnet.cz Mon Sep 16 08:52:55 2002 From: dobes at tesnet.cz (Michal Dobes) Date: Mon, 16 Sep 2002 08:52:55 +0200 Subject: Unix -- Linux sit. References: <9E85DC6CA1D5D311BB460006293960FEC33F0E@dcrfs.decros.cz> Message-ID: <3D857FC7.A7D58461@trb.tesnet.cz> kirtep at post.cz wrote: > chtel bych se zeptat na vas nazory na tuto problematiku: > Server bezim pod FreeBSD a pracovni stanice na Linuxu (Slackware). > Chtel bych aby se automaticky kazdemu Linuxovskemu uzivateli po > nalogovani na stanici pripojil jeho domovsky adresar, ktery je > exportovan serverem (NFS). A po jeho odhlaseni se zase automaticky > odpojil. Ano, jde to bez problemu. Pouzjete treba autofs na linuxu pro toto, ten si umi brat konfiguraci i pres NIS, takze neni treba nic obihat. v /etc/auto.master bude: /home /etc/auto.home --timeout 600 v /etc/auto.home pak: * -rw,soft,intr freebsd:/home/& Predpokladam, ze z toho freebsd exportujete primo ten /home. > Centralni sprava uzivatelu -- pomoci NIS. Jestli jsem to > dobre pochopil tak na kazde stanici staci minimalni /etc/passwd > (root + systemove ucty) a zbytek se prenasi ze serveru. Je to > zivotaschopne reseni? Ano, funguje to. > Ma s tim nekdo zkusenosti? Uspesne provozovano (teda server i stanice jsou linux, ale problem v tom na freebsd nebude). > Je to OK i pro stinova hesla? Ano, stejne je normalni nastaveni takove, ze hesla ze shadow se slouci s passwd a dal se to uz jen distribuuje jako normalni passwd. Pri pouziti normalniho NIS vam vyznam shadow pro znepristupneni hesel uzivatelum zanika. Kdo umi poslouchat na siti nebo pouzit prikaz ypcat se je dozvi. > Neni to prilis nebezpecne? Je to nebezpece. Vse se prenasi volne pres sit a kdo posloucha vsechno vi. Reseni je nekolik, treba pouzit NIS+, ale to by ten server musel byt Solaris a klienti klidne linux. Majkl From hopet at ics.muni.cz Sun Sep 15 13:37:50 2002 From: hopet at ics.muni.cz (Petr Holub) Date: Sun, 15 Sep 2002 13:37:50 +0200 Subject: pro Martina Liznera In-Reply-To: <20020910131625.GJ83171@freepuppy.bellavista.cz> Message-ID: <002401c25cac$525270a0$a1b5a8c0@kloboucek> > Vas MTA (anect.com) mi neustale posila emaily s nejakymi divnymi > prilohami: application/ms-tnef. To bude asi virus, ne? At na to v muttu > klikam, jak klikam, porad se to nechce otevrit. To neni virus, ale jen nejaky dobrak pouziva MS Outlook 97 (98 a vyssi uz tohle nepouziva - aspon ne by default). Je to zpusob, jak delat prilohy, akorat, ze si s tim prakticky nic jineho, nez zas jen ty Outlooky, neporadi (prestoze uz toty vyssi nepouzivaji, jsou to schopny otevrit...) Petr From MLizner at anect.com Mon Sep 16 15:49:46 2002 From: MLizner at anect.com (Lizner Martin) Date: Mon, 16 Sep 2002 15:49:46 +0200 Subject: pro Martina Liznera Message-ID: a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela mrtveho brouka - je m$oidni :) m. -----Original Message----- From: Petr Holub [mailto:hopet at ics.muni.cz] Sent: Sunday, September 15, 2002 1:38 PM To: users-l at freebsd.cz Subject: RE: pro Martina Liznera > Vas MTA (anect.com) mi neustale posila emaily s nejakymi divnymi > prilohami: application/ms-tnef. To bude asi virus, ne? At na to v muttu > klikam, jak klikam, porad se to nechce otevrit. To neni virus, ale jen nejaky dobrak pouziva MS Outlook 97 (98 a vyssi uz tohle nepouziva - aspon ne by default). Je to zpusob, jak delat prilohy, akorat, ze si s tim prakticky nic jineho, nez zas jen ty Outlooky, neporadi (prestoze uz toty vyssi nepouzivaji, jsou to schopny otevrit...) Petr From josef.mruzek at i.cz Mon Sep 16 16:25:31 2002 From: josef.mruzek at i.cz (Josef Mruzek) Date: Mon, 16 Sep 2002 16:25:31 +0200 Subject: pro Martina Liznera References: Message-ID: <3D85E9DB.7000902@i.cz> Lizner Martin wrote: > a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela mrtveho brouka - je m$oidni :) > > m. Zdravim, http://support.microsoft.com/default.aspx?scid=kb;en-us;Q138053 Ale mozna by stacilo vypnout odesilani posty jako RTF (teda jestli to jde v outlooku?). Pepa Mruzek From hopet at ics.muni.cz Mon Sep 16 16:58:37 2002 From: hopet at ics.muni.cz (Petr Holub) Date: Mon, 16 Sep 2002 16:58:37 +0200 Subject: pro Martina Liznera In-Reply-To: <3D85E9DB.7000902@i.cz> Message-ID: <00cd01c25d91$897da870$2c64a8c0@kloboucek> > Zdravim, > > http://support.microsoft.com/default.aspx?scid=kb;en-us;Q138053 > > Ale mozna by stacilo vypnout odesilani posty jako RTF (teda jestli to > jde v outlooku?). A nebo udelat upgrade na Outlook98, coz je mimochodem zdarma, protoze u verze 97 i MS seznal, ze je to takovy kram, ze se to musi upgradovat. Akorat tim asi nebudeme uz otravovat FreeBSD koferu. Howgh, Petr ================================================================ Petr Holub CESNET z.s.p.o. Supercomputing Center Brno Zikova 4 Institute of Compt. Science 160 00 Praha 6, CZ Masaryk University Czech Republic Botanicka 68a, 60200 Brno, CZ e-mail: Petr.Holub at cesnet.cz phone: +420-5-41512213 e-mail: hopet at ics.muni.cz From neuhauser at bellavista.cz Mon Sep 16 16:57:14 2002 From: neuhauser at bellavista.cz (Roman Neuhauser) Date: Mon, 16 Sep 2002 16:57:14 +0200 Subject: pro Martina Liznera In-Reply-To: References: Message-ID: <20020916145714.GD370@freepuppy.bellavista.cz> # MLizner at anect.com / 2002-09-16 15:49:46 +0200 top-posted: quoting opraven > > -----Original Message----- > > From: Petr Holub [mailto:hopet at ics.muni.cz] > > Sent: Sunday, September 15, 2002 1:38 PM > > To: users-l at freebsd.cz > > Subject: RE: pro Martina Liznera > > > > > > > Vas MTA (anect.com) mi neustale posila emaily s nejakymi divnymi > > > prilohami: application/ms-tnef. To bude asi virus, ne? At na to v muttu > > > klikam, jak klikam, porad se to nechce otevrit. > > > > To neni virus, ale jen nejaky dobrak pouziva MS Outlook 97 (98 a vyssi > > uz tohle nepouziva - aspon ne by default). Je to zpusob, jak delat > > prilohy, akorat, ze si s tim prakticky nic jineho, nez zas jen ty Outlooky, > > neporadi (prestoze uz toty vyssi nepouzivaji, jsou to schopny otevrit...) ja vim, ze to nebyl virus, to byl vtip. > a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela > mrtveho brouka - je m$oidni :) zmenit spravce mailu? -- begin 666 nonexistent.vbs FreeBSD 4.6-STABLE 4:55PM up 5:58, 4 users, load averages: 0.00, 0.00, 0.00 end From neuhauser at bellavista.cz Mon Sep 16 17:01:07 2002 From: neuhauser at bellavista.cz (Roman Neuhauser) Date: Mon, 16 Sep 2002 17:01:07 +0200 Subject: pro Martina Liznera In-Reply-To: <3D85E9DB.7000902@i.cz> References: <3D85E9DB.7000902@i.cz> Message-ID: <20020916150107.GE370@freepuppy.bellavista.cz> # josef.mruzek at i.cz / 2002-09-16 16:25:31 +0200: > Lizner Martin wrote: > >a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela mrtveho > >brouka - je m$oidni :) > > > >m. > > Zdravim, > > http://support.microsoft.com/default.aspx?scid=kb;en-us;Q138053 > > Ale mozna by stacilo vypnout odesilani posty jako RTF (teda jestli to > jde v outlooku?). spatne reseni. ja vubec nepotrebuju zadne bouncy ze serveru p. Liznera. jeho MTA tvrdi, ze rozesilam vbs soubor, coz je evidentne nesmysl: je to jenom inline signatura. cili, at ve forme x-ms-tnef nebo rfc822, furt je to spatne. ale co, tuhle signaturu nemam omylem, a tech par bouncu jde snadno odfiltrovat. -- begin 666 nonexistent.vbs FreeBSD 4.6-STABLE 4:58PM up 6:02, 4 users, load averages: 0.10, 0.04, 0.01 end From Vladimir.Tyman at i.cz Mon Sep 16 17:12:40 2002 From: Vladimir.Tyman at i.cz (Tyman Vladimir) Date: Mon, 16 Sep 2002 17:12:40 +0200 Subject: pro Martina Liznera References: Message-ID: <3D85F4E8.CB772782@i.cz> Lizner Martin wrote: > > a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela mrtveho brouka - je m$oidni :) Zkuste TNEF http://sourceforge.net/projects/tnef/ nebo tnef2txt http://www.fiction.net/blong/programs/#tnef2txt Zkusenosti s nimi nemam, budto takovehle posty ignoruji nebo to prectu na jinem pocitaci s OE ve Windows. VT > > m. > > -----Original Message----- > From: Petr Holub [mailto:hopet at ics.muni.cz] > Sent: Sunday, September 15, 2002 1:38 PM > To: users-l at freebsd.cz > Subject: RE: pro Martina Liznera > > > Vas MTA (anect.com) mi neustale posila emaily s nejakymi divnymi > > prilohami: application/ms-tnef. To bude asi virus, ne? At na to v muttu > > klikam, jak klikam, porad se to nechce otevrit. > > To neni virus, ale jen nejaky dobrak pouziva MS Outlook 97 (98 a vyssi > uz tohle nepouziva - aspon ne by default). Je to zpusob, jak delat > prilohy, akorat, ze si s tim prakticky nic jineho, nez zas jen ty Outlooky, > neporadi (prestoze uz toty vyssi nepouzivaji, jsou to schopny otevrit...) > > Petr -- Vladimir Tyman ICZ a.s. - Oddeleni vnitrniho IT V Olsinach 2300/75, 100 97 Praha 10, CZ Tel: +420 (2) 81002158, 81002222 Fax: +420 (2) 81002244 http://www.i.cz From neuhauser at bellavista.cz Mon Sep 16 18:10:37 2002 From: neuhauser at bellavista.cz (Roman Neuhauser) Date: Mon, 16 Sep 2002 18:10:37 +0200 Subject: pro Martina Liznera In-Reply-To: <3D85F4E8.CB772782@i.cz> References: <3D85F4E8.CB772782@i.cz> Message-ID: <20020916161036.GF370@freepuppy.bellavista.cz> # Vladimir.Tyman at i.cz / 2002-09-16 17:12:40 +0200: snad je ten kontext jeste spravne, ale jak vidim, outlookar je outlookar i kdyz pouziva mozillu na linuxu :] > > -----Original Message----- > > From: Petr Holub [mailto:hopet at ics.muni.cz] > > Sent: Sunday, September 15, 2002 1:38 PM > > To: users-l at freebsd.cz > > Subject: RE: pro Martina Liznera > > > > > Vas MTA (anect.com) mi neustale posila emaily s nejakymi divnymi > > > prilohami: application/ms-tnef. To bude asi virus, ne? At na to v muttu > > > klikam, jak klikam, porad se to nechce otevrit. > > > > To neni virus, ale jen nejaky dobrak pouziva MS Outlook 97 (98 a vyssi > > uz tohle nepouziva - aspon ne by default). Je to zpusob, jak delat > > prilohy, akorat, ze si s tim prakticky nic jineho, nez zas jen ty Outlooky, > > neporadi (prestoze uz toty vyssi nepouzivaji, jsou to schopny otevrit...) > Lizner Martin wrote: > > > > a co s tim ? :) preposilal jsem to nasemu spravci mailu ale dela > > mrtveho brouka - je m$oidni :) > > Zkuste TNEF > http://sourceforge.net/projects/tnef/ > nebo tnef2txt > http://www.fiction.net/blong/programs/#tnef2txt > > Zkusenosti s nimi nemam, budto takovehle posty ignoruji nebo to prectu > na jinem pocitaci s OE ve Windows. mozna by stalo za to precist si cely thread driv nez poslete followup. p. Lizner (resp. jeho MTA) je odesilatelem tech emailu. rozhodne neshani software, ve kterem by si je precetl. -- begin 666 nonexistent.vbs FreeBSD 4.6-STABLE 6:08PM up 7:12, 7 users, load averages: 0.00, 0.00, 0.00 end From galambos at com-os2.ms.mff.cuni.cz Sat Sep 21 16:42:29 2002 From: galambos at com-os2.ms.mff.cuni.cz (Leo Galambos) Date: Sat, 21 Sep 2002 16:42:29 +0200 (CEST) Subject: PPP Message-ID: Lze nejakym zpusobem nastavit pppd tak, aby zkousel nekolik telefonnich cisel (pripojovacich uzlu) a zaroven pri tom mel pokazde jine username a password? Myslim to tak, ze se nejdriv pokusi o spojeni na prvni cislo, kdyz se to nepovede, tak druhe, atd. cyklicky dokola. Dalsi problem mam s tim, ze od jiste doby modem nedetekuje obsazeno na volanem cisle. Je to Sporster 56K. Nemate neko inicializacni retezec, se kterym to normalne funguje? Diky -g- From pavel.prib at i.cz Mon Sep 23 09:44:51 2002 From: pavel.prib at i.cz (Pavel Prib) Date: Mon, 23 Sep 2002 09:44:51 +0200 Subject: PPP Message-ID: <9E85DC6CA1D5D311BB460006293960FEDCA6B8@dcrfs.decros.cz> > -----Original Message----- > From: Leo Galambos [mailto:galambos at com-os2.ms.mff.cuni.cz] > Sent: Saturday, September 21, 2002 4:42 PM > To: users-l at freebsd.cz > Subject: PPP > Dalsi problem mam s tim, ze od jiste doby modem nedetekuje obsazeno na > volanem cisle. Je to Sporster 56K. Nemate neko inicializacni > retezec, se > kterym to normalne funguje? Zkuste AT&F1L3X3. Pavel Prib From juro at software602.sk Tue Sep 24 15:57:04 2002 From: juro at software602.sk (Juraj Petrik) Date: Tue, 24 Sep 2002 15:57:04 +0200 Subject: pomoc s IPNAT + IPFILTER + DUMMYNET + FreeBSD 4.7prerelease Message-ID: <000801c263d2$5054ec60$7a01a8c0@pcjuro> odpoved moze byt kludne v SK/CZ vopred vdaka!!!! ---------------------------------- hello, can you help me, please, I'm trying to run firewall with using IPFilter, IPNAT and Dummynet, on FreeBSD I'm readed so much HOWTOs but, I can't do redirection to another server in internal network: rl0 - WAN (194.x.x.0/24) 194.x.x.22 if FreeBSD box rl1 - LAN (192.168.1.0/24) 192.168.1.22 if FreeBSD box rl2 - DMZ (10.0.0.0/24) 10.0.0.22 if FreeBSD box my server is now on LAN, not on DMZ. I'm using FreeBSD 4.7 prerelease from CVS. In kernel config have added: options IPFIREWALL options IPFIREWALL_VERBOSE options IPFIREWALL_VERBOSE_LIMIT=30 options IPFIREWALL_FORWARD options IPFIREWALL_DEFAULT_TO_ACCEPT options IPDIVERT options DUMMYNET options IPFILTER options IPFILTER_LOG options IPFILTER_DEFAULT_BLOCK options RANDOM_IP_ID in /etc/rc.conf have: tcp_extensions="YES" gateway_enable="YES" portmap_enable="NO" #firewall_enable="YES" #firewall_type="/etc/dummynet.conf" #firewall_logging="NO" ipfilter_enable="YES" ipfilter_flags="" ipfilter_rules="/etc/ipf.conf" ipnat_enable="YES" ipnat_flags="" ipnat_rules="/etc/ipnat.conf" ipmon_enable="YES" ipmon_flags="-Dns -l block" in /etc/ipf.conf: pass in log all pass out log all in /etc/ipnat.conf: map rl0 192.168.1.0/24 -> 194.x.x.22/32 map rl0 0/0 -> 194.x.x.22/32 proxy port ftp ftp/tcp map rl0 192.168.1.0/24 -> 194.x.x.22/32 portmap tcp/udp 12500:60000 map rl0 192.168.1.0/24 -> 194.x.x.22/32 rdr rl0 194.x.x.22/32 port 80 -> 192.168.1.35 port 80 rdr rl0 194.x.x.22/32 port 22 -> 192.168.1.35 port 22 NAT from LAN to internet works OK, but from Internet I can't redirct. Please help me ANYBODY!!!! -jp- From jjursa at ibp.cz Fri Sep 27 14:13:07 2002 From: jjursa at ibp.cz (Josef Jursa) Date: Fri, 27 Sep 2002 14:13:07 +0200 (CEST) Subject: NFS client In-Reply-To: <9E85DC6CA1D5D311BB460006293960FEDCA601@dcrfs.decros.cz> Message-ID: Dobry den, nedarise mne rozchodit NFS clienta v 4.6.2 mount -t nfs pocitac.domena.cz:/exports/test /mnt pocitac.domena.cz:/exports/test: nfsd: RPCPROG_NFS: RPC: Program not registered V cem muze byt problem? Zdravi Josef Jursa From dobes at tesnet.cz Fri Sep 27 17:32:24 2002 From: dobes at tesnet.cz (Michal Dobes) Date: Fri, 27 Sep 2002 17:32:24 +0200 Subject: NFS client References: Message-ID: <3D947A08.24AC4AE2@trb.tesnet.cz> Josef Jursa wrote: > mount -t nfs pocitac.domena.cz:/exports/test /mnt > pocitac.domena.cz:/exports/test: nfsd: RPCPROG_NFS: RPC: Program not > registered A bezi na tom serveru pocitac.domena.cz vse co bezet ma? Prikaz 'rpcinfo -p pocitac.domena.cz' by mel vratit vypis registrovanych sluzeb na serveru pro Sun RPC. Melo by tam byt registrovan program c. 100000 (portmapper), 100003 (nfs) a 100005 (mount), vetsinou v nekolika verzich, pripadne kombinace TCP/UDP portu. Na klientovi musi bezet take portmapper. Majkl From zero at estimese.net Fri Sep 27 19:32:59 2002 From: zero at estimese.net (Robert Bopko) Date: Fri, 27 Sep 2002 19:32:59 +0200 Subject: NFS client In-Reply-To: <3D947A08.24AC4AE2@trb.tesnet.cz> References: <3D947A08.24AC4AE2@trb.tesnet.cz> Message-ID: <20020927173259.GB9484@finom.estimese.net> > A bezi na tom serveru pocitac.domena.cz vse co bezet ma? > Prikaz 'rpcinfo -p pocitac.domena.cz' by mel vratit > vypis registrovanych sluzeb na serveru pro Sun RPC. > Melo by tam byt registrovan program c. 100000 (portmapper), > 100003 (nfs) a 100005 (mount), vetsinou v nekolika verzich, > pripadne kombinace TCP/UDP portu. > Na klientovi musi bezet take portmapper. predpokladam, ze sa jedna o freebsd tam portmapper na klientovy bezat nemusi. From neuhauser at bellavista.cz Fri Sep 27 17:34:23 2002 From: neuhauser at bellavista.cz (Roman Neuhauser) Date: Fri, 27 Sep 2002 17:34:23 +0200 Subject: NFS client In-Reply-To: References: Message-ID: <20020927153423.GF30361@freepuppy.bellavista.cz> # jjursa at ibp.cz / 2002-09-27 14:13:07 +0200: > Dobry den, > nedarise mne rozchodit NFS clienta v 4.6.2 > > mount -t nfs pocitac.domena.cz:/exports/test /mnt > pocitac.domena.cz:/exports/test: nfsd: RPCPROG_NFS: RPC: Program not > registered > > V cem muze byt problem? nepostupoval jste podle navodu: /usr/share/doc/handbook/nfs.html ty demony je potreba nastartovat ve spravnem poradi. v pripade pochybnosti doporucuju vsechny pozabijet a nastartovat znovu v poradi napsanem v tom clanku. anebo proste restartovat (se vsim potrebnym v /etc/rc.conf, /etc/exports, a /etc/fstab). -- begin 666 nonexistent.vbs FreeBSD 4.7-RC 5:30PM up 10 days, 45 mins, 12 users, load averages: 0.10, 0.05, 0.04 end From hlubik at dashofer.cz Fri Sep 27 22:03:03 2002 From: hlubik at dashofer.cz (=?iso-8859-2?Q?Pavel_Hlub=EDk?=) Date: Fri, 27 Sep 2002 22:03:03 +0200 Subject: rndc-confgen In-Reply-To: Message-ID: <000001c26660$e3a04420$0f01a8c0@dashofer.cz> Ahoj, nevite, prosim, nekdo proc mi prikaz /usr/local/sbin/rndc-confgen -a -t /etc/namedb/ -u bind FreeBSD 4.6.2 nic nedela. Pro pokracovani prace musim stiknout Ctrl+C. Take varianta prikazu /usr/local/sbin/rndc-confgen -a se chova stejne. V manu je napsano, aby se zkontrolovala pritomnost souboru /dev/random. Ten mam. Na OpenBSD mi to krasne vykouzlilo rndc.conf soubor a bylo vymalovano. Diky za radu. Pavel Hlubik From brano at zmail.sk Sat Sep 28 05:56:34 2002 From: brano at zmail.sk (Brano Vislocky) Date: Sat, 28 Sep 2002 05:56:34 +0200 Subject: FreeBSD & Informix OnLine v 5.x pre SCO Message-ID: <3D952872.8060609@zmail.sk> Ahojte, podarilo sa niekomu z rozbehat $SUBJ, prip. neviete o nejakej vhodnej dokumentacii ? dakujem Brano From hlubik at dashofer.cz Mon Sep 30 16:49:05 2002 From: hlubik at dashofer.cz (=?iso-8859-2?Q?Pavel_Hlub=EDk?=) Date: Mon, 30 Sep 2002 16:49:05 +0200 Subject: Sendmail In-Reply-To: <000001c26660$e3a04420$0f01a8c0@dashofer.cz> Message-ID: <000001c26890$8664fda0$0f01a8c0@dashofer.cz> Ahoj, nevite, prosim, nekdo jak upravit sendmail.cf tak, aby kdyz nen? v dobe odesilani mailu k dispozici MX zaznam cilove domeny , neposlal klientovi chybovou hlasku, ale nechal zpravu ve fronte a ridil se nastavenimi O Timeout.queuereturn O Timeout.queuewarn Diky za pomoc. Pavel Hlubik From jjursa at ibp.cz Mon Sep 30 09:45:02 2002 From: jjursa at ibp.cz (Josef Jursa) Date: Mon, 30 Sep 2002 09:45:02 +0200 (CEST) Subject: NFS client In-Reply-To: <3D947A08.24AC4AE2@trb.tesnet.cz> Message-ID: Diky za nakopnuti, skleroza je strasna vec, nedavno jsem nfs vypnul kvuli bezpecnostnim diram v IRIXu, a samozrejme zapomnel vratit zpet. :-( Zdravi Josef Jursa On Fri, 27 Sep 2002, Michal Dobes wrote: > Josef Jursa wrote: > > mount -t nfs pocitac.domena.cz:/exports/test /mnt > > pocitac.domena.cz:/exports/test: nfsd: RPCPROG_NFS: RPC: Program not > > registered > > A bezi na tom serveru pocitac.domena.cz vse co bezet ma? > Prikaz 'rpcinfo -p pocitac.domena.cz' by mel vratit > vypis registrovanych sluzeb na serveru pro Sun RPC. > Melo by tam byt registrovan program c. 100000 (portmapper), > 100003 (nfs) a 100005 (mount), vetsinou v nekolika verzich, > pripadne kombinace TCP/UDP portu. > Na klientovi musi bezet take portmapper. > > Majkl >