OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 15.7 Legacy Series »
  • HardenedBSD experimental builds
« previous next »
  • Print
Pages: [1] 2

Author Topic: HardenedBSD experimental builds  (Read 14560 times)

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13693
  • Karma: 1176
    • View Profile
HardenedBSD experimental builds
« on: August 28, 2015, 12:20:07 pm »
Hi everyone,

courtesy of Shawn Webb, here are the latest images for OPNsense on HardenedBSD. Note that upgrading does not work on these, they show the integration progress, which is: it works. :)

https://pkg.opnsense.org/snapshots/hbsd-exp-05/

Making HardenedBSD additions available by default in OPNsense is what we are aiming at for 16.1. More on this soon. Please also note Shawn's announcement over at HardenedBSD:

https://hardenedbsd.org/article/shawn-webb/2015-06-10/first-official-opnsense-images-hardenedbsd

Build number 6 is going to come out soon.


Cheers,
Franco
Logged

Supermule

  • Full Member
  • ***
  • Posts: 223
  • Karma: 15
    • View Profile
Re: HardenedBSD experimental builds
« Reply #1 on: August 28, 2015, 01:26:29 pm »
Are you moving away from FreeBSD?
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13693
  • Karma: 1176
    • View Profile
Re: HardenedBSD experimental builds
« Reply #2 on: August 28, 2015, 01:35:32 pm »
Long answer: HardenedBSD is security goodness on top of FreeBSD, in some regards more than what OpenBSD offers without being OpenBSD underneath, some parts even better than that. HardenedBSD patches are going upstream to FreeBSD eventually. We try to adapt these patches earlier and can keep it fully compatible with FreeBSD at the same time. Bottom line is the patches make sense and work great already, so why not use them for the benefit of our users.

Short answer: No. :)
Logged

Supermule

  • Full Member
  • ***
  • Posts: 223
  • Karma: 15
    • View Profile
Re: HardenedBSD experimental builds
« Reply #3 on: August 28, 2015, 02:34:58 pm »
Thanks man! Very appreciated!  ;)

Logged

Solaris17

  • Full Member
  • ***
  • Posts: 108
  • Karma: 14
    • View Profile
Re: HardenedBSD experimental builds
« Reply #4 on: August 30, 2015, 11:32:31 pm »
I cant wait! security is good!
Logged

guest7876

  • Guest
Re: HardenedBSD experimental builds
« Reply #5 on: September 02, 2015, 06:49:22 am »
security is always a good thing.

having opnsense on top of hardenedBSD is even better considering we dont
have to deal with OpenBSD... they annoy me with there attitudes. (dont ask me
how i know).

im considering rebuilding a Huge server farm (>100 servers) with HardenedBSD (currently on stock FreeBSD now)
Logged

Solaris17

  • Full Member
  • ***
  • Posts: 108
  • Karma: 14
    • View Profile
Re: HardenedBSD experimental builds
« Reply #6 on: September 02, 2015, 04:04:52 pm »
Will these builds still support the same hardware they 10.2 currently does?
Logged

lattera

  • Full Member
  • ***
  • Posts: 200
  • Karma: 80
    • View Profile
Re: HardenedBSD experimental builds
« Reply #7 on: September 02, 2015, 04:17:58 pm »
Shawn Webb here. Yeah, the HardenedBSD experimental builds support the same hardware as OPNSense. Build number six was going to happen yesterday, but will be delayed until next week at the earliest and October at the latest.

Please note that build five doesn't support binary updates, but build six will. So going from three to five (four is intentionally missing) or five to six you'll have to backup your config, reinstall, then restore your config. Versions six and onward will have the same binary upgrade capabilities you currently enjoy with OPNSense.
Logged

Solaris17

  • Full Member
  • ***
  • Posts: 108
  • Karma: 14
    • View Profile
Re: HardenedBSD experimental builds
« Reply #8 on: September 02, 2015, 04:36:52 pm »
Quote from: lattera on September 02, 2015, 04:17:58 pm
Shawn Webb here. Yeah, the HardenedBSD experimental builds support the same hardware as OPNSense. Build number six was going to happen yesterday, but will be delayed until next week at the earliest and October at the latest.

Please note that build five doesn't support binary updates, but build six will. So going from three to five (four is intentionally missing) or five to six you'll have to backup your config, reinstall, then restore your config. Versions six and onward will have the same binary upgrade capabilities you currently enjoy with OPNSense.

Thank you very much for this information and your continued hard work!
Logged

Solaris17

  • Full Member
  • ***
  • Posts: 108
  • Karma: 14
    • View Profile
Re: HardenedBSD experimental builds
« Reply #9 on: September 30, 2015, 04:20:45 pm »
Just a quick question sorry for the double post. Are there plans to move exclusively to hardened BSD as our core or have side by side releases on the same version number and opnsense build? I am very interested in getting on board with this.
Logged

lattera

  • Full Member
  • ***
  • Posts: 200
  • Karma: 80
    • View Profile
Re: HardenedBSD experimental builds
« Reply #10 on: September 30, 2015, 04:56:52 pm »
I can't speak for the OPNSense crew, but I'll be continuously providing builds based on HardenedBSD. I'm doing a new build now based on 15.7.15. :-) And I have all the bits in place to support binary updates along with managed secadm rule updates. Build seven will likely also include Integriforce rules for all of userland. :-)
Logged

lattera

  • Full Member
  • ***
  • Posts: 200
  • Karma: 80
    • View Profile
Re: HardenedBSD experimental builds
« Reply #11 on: September 30, 2015, 07:29:09 pm »
New experimental builds posted! You can find them here: https://hardenedbsd.org/~shawn/opnsense/hbsd-exp-06-15.7/

I still need to populate the package repo on our web server, but this build itself now supports binary updates.
Logged

Solaris17

  • Full Member
  • ***
  • Posts: 108
  • Karma: 14
    • View Profile
Re: HardenedBSD experimental builds
« Reply #12 on: September 30, 2015, 09:07:09 pm »
great news thank you!
Logged

franco

  • Administrator
  • Hero Member
  • *****
  • Posts: 13693
  • Karma: 1176
    • View Profile
Re: HardenedBSD experimental builds
« Reply #13 on: October 02, 2015, 07:35:15 am »
Shawn, put them on the mirror as well: https://pkg.opnsense.org/snapshots/hbsd-exp-06/
Logged

LuckyURE

  • Newbie
  • *
  • Posts: 1
  • Karma: 0
    • View Profile
Re: HardenedBSD experimental builds
« Reply #14 on: October 02, 2015, 05:40:07 pm »
I'm using the new build and love it!  Quick question though, the update feature isn't working in the latest build, do you plan to add an update server/option to the list so we can simply upgrade just as the primary releases do?
Logged

  • Print
Pages: [1] 2
« previous next »
  • OPNsense Forum »
  • Archive »
  • 15.7 Legacy Series »
  • HardenedBSD experimental builds
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2