OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of yonas »
  • Show Posts »
  • Topics
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Topics - yonas

Pages: [1]
1
General Discussion / Reasons why I'm choosing OPNsense over pfSense
« on: June 02, 2016, 04:30:09 am »
Don't start a flame war  ;D


After reading the interesting pfSense roadmap by Jim Thompson, I was surprised by two things.


First and foremost, LibreSSL will probably never be accepted into pfSense:


"Finally, since I mentioned OpenSSL, let me say this:  Other projects may explore alternative implementations of OpenSSL (e.g. LibreSSL), but pfSense is unlikely to do this for three reasons:


1) OpenSSL had its issues, but a good, long-time (> 30 year) friend named Rich Salz is now leading the development there.  I’ve known Rich since 1985, and I trust his leadership of the OpenSSL project.


2) Intel is focused on OpenSSL, as is the Linux Foundation, and their funding.  There will be more test path coverage and more performance work in OpenSSL than any other implementation.


3) I don’t like the attitude of the people behind the LibreSSL project.  Talking smack about the project you forked from is bad form. I’ll say no more than to quote Frank Zappa on the subject."


The arguments are very weak. Points 1 and 3 are extremely subjective and openly biased, and all points ignore the fact that LibreSSL has already proven to be more secure than OpenSSL, having fewer vulnerabilities since it's release.


Secondly, the first, and likely most important, reason for switching from PHP to Python for pfSense 3.0 was simply "Personally, I have no time for PHP..."


....This is not a very in-depth analysis of why Python is the most appropriate language for pfSense. I can imagine many people would argue to use Go, or Node, or something else.


Considering that PHP is much more widely used than Python, using less popular language becomes a barrier to entry for developers. Hence, making such decisions shouldn't be done so carelessly.


OPNsense has already incorporated LibreSSL and security hardening features from HardenedBSD. That's very proactive.

2
General Discussion / [SOLVED] Can't fetch updates: "Repository problem"
« on: May 09, 2016, 09:00:47 am »
When I try to fetch updates under System > Firmware > Updates, I get "Repository problem".

I get the same error when checking for updates under Lobby > Dashboard > Updates.

I've made sure the server has access to the Internet by running `ping google.com` from the command line.

I'm using OPNsense 16.7.b_113-amd64, FreeBSD 11.0-CURRENT-HBSD.

The logs show:

Quote
configd.py: [2463ae76-bb96-46ce-9205-555cf47c921f] Script action stderr returned "pkg: http://pkgs.hardenedbsd.org/OPNSense/pkg/FreeBSD:11:amd64/16.1/libressl/meta.txz: Not Found pkg: http://pkgs.hardenedbsd.org/OPNSense/pkg/FreeBSD:11:amd64/16.1/libressl/packagesite.txz: Not Found pkg: http://pkgs.hardenedbsd.org/OPNSense/pkg/FreeBSD:"

which makes sense, because http://pkgs.hardenedbsd.org doesn't exist, but this address does:

http://pkg.hardenedbsd.org/HardenedBSD/pkg/FreeBSD:11:amd64/meta.txz
http://pkg.hardenedbsd.org/HardenedBSD/pkg/FreeBSD:11:amd64/packagesite.txz

Editing /usr/local/etc/pkg/repos/origin.conf and setting the url to:

pkg+http://pkg.hardenedbsd.org/HardenedBSD/pkg${ABI}

seems to have worked, but after running an upgrade, which upgraded `pkg` itself, no installed or available packages show up. Running `pkg` on the command line produces no output. I suspect this copy of pkg isn't compatible with HardenedBSD.

3
General Discussion / Not mobile friendly
« on: May 09, 2016, 08:52:29 am »
Great work on OPNsense!

I noticed some issues when viewing OPNsense on a mobile device.

In OPNsense, you need to scroll horizontally to see everything on the page. In pfSense 2.3, you don't need to. See attached screenshots.

I'm using OPNsense 16.7.b_113-amd64, FreeBSD 11.0-CURRENT-HBSD.

Pages: [1]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2