<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[OpenBSD]]></title><description><![CDATA[Strong, secure, no compromises. 
For all things OpenBSD, pf, and pledge.]]></description><link>https://billboard.bsd.cafe/category/8</link><generator>RSS for Node</generator><lastBuildDate>Thu, 13 Aug 2026 12:40:48 GMT</lastBuildDate><atom:link href="https://billboard.bsd.cafe/category/8.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 14 Jul 2026 17:20:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[OpenBSD in the wild... spotted at the gym]]></title><description><![CDATA[Thanks to everyone who pointed out Linux. Now that I'm paying attention this is clearly the systemd startup logging. 
]]></description><link>https://billboard.bsd.cafe/topic/297/openbsd-in-the-wild...-spotted-at-the-gym</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/297/openbsd-in-the-wild...-spotted-at-the-gym</guid><dc:creator><![CDATA[naltun]]></dc:creator><pubDate>Tue, 14 Jul 2026 17:20:40 GMT</pubDate></item><item><title><![CDATA[wg(4), pf(4), and relayd(8): a love story]]></title><description><![CDATA[tl;dr I used wg(4), pf(4), and relayd(8), all OpenBSD native tools, to encrypt all inbound connections from a gateway VPS to my local home server. This also hides my local IP information and I managed it all without much hassle and pain.
I recently stood up a VPS running OpenBSD 7.9 on Vultr. The VPS is hosted in Chicago, Illinois, USA. I then took OpenBSD's native WireGuard driver, wg(4), to establish an encrypted tunnel to my local home lab server. Using relayd(8), OpenBSD's native reverse proxy, I can now forward virtual host connections to my home lab server, which has httpd(8) as a web server frontend. I used pf.conf(5) to configure OpenBSD's native fireweall, pf(4), which was incredibly easy.
The result is a secure gateway that routes all traffic via WireGuard to my local server, obfuscating its location and other IP information. This was done by simply configuring handful of system daemons. I've done some OpenBSD network configuration before, but this was the most work I've done. The best part, it wasn't that difficult, and all manual pages provided sufficient details to work with them.
Once I get my site set up I'll write up the experience and step-by-step instructions and share the page here.
New OpenBSD milestone unlocked; no intent to stop anytime soon
Happy hacking, hackers!
]]></description><link>https://billboard.bsd.cafe/topic/296/wg-4-pf-4-and-relayd-8-a-love-story</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/296/wg-4-pf-4-and-relayd-8-a-love-story</guid><dc:creator><![CDATA[naltun]]></dc:creator><pubDate>Tue, 14 Jul 2026 17:12:24 GMT</pubDate></item><item><title><![CDATA[[Arxiv.org]]]></title><description><![CDATA[@phessler FYI ]]></description><link>https://billboard.bsd.cafe/topic/289/arxiv.org</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/289/arxiv.org</guid><dc:creator><![CDATA[grahamperrin@mastodon.bsd.cafe]]></dc:creator><pubDate>Tue, 07 Jul 2026 11:31:25 GMT</pubDate></item><item><title><![CDATA[[dataswamp.org&#x2F;~solene] Full-featured email server running OpenBSD]]></title><description><![CDATA[
@naltun said:
tyvm

??? Hummm, maybe: "Thank you very much", isn'it?!
]]></description><link>https://billboard.bsd.cafe/topic/283/dataswamp.org-solene-full-featured-email-server-running-openbsd</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/283/dataswamp.org-solene-full-featured-email-server-running-openbsd</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Tue, 30 Jun 2026 12:50:01 GMT</pubDate></item><item><title><![CDATA[I submitted the desktop-installer script popular on other BSDs and its depend to ports@, please test on your machine to improve chances of import.]]></title><description><![CDATA[What title says
More info here: https://github.com/outpaddling/desktop-installer/issues/30#issuecomment-4835472901
]]></description><link>https://billboard.bsd.cafe/topic/280/i-submitted-the-desktop-installer-script-popular-on-other-bsds-and-its-depend-to-ports@-please-test-on-your-machine-to-improve-chances-of-import.</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/280/i-submitted-the-desktop-installer-script-popular-on-other-bsds-and-its-depend-to-ports@-please-test-on-your-machine-to-improve-chances-of-import.</guid><dc:creator><![CDATA[izder456]]></dc:creator><pubDate>Mon, 29 Jun 2026 18:01:11 GMT</pubDate></item><item><title><![CDATA[Partitioning without &#x2F;usr&#x2F;src and &#x2F;usr&#x2F;obj]]></title><description><![CDATA[Hi! So I have a small VPS with OpenBSD on it and I anticipate that disk space will not be enough, so my question is, if I know that I will never compile the whole system from source, can I just repurpose the space allocated to /usr/obj and /usr/src and mount those partitions where they're needed? Or is this a really really bad idea? It would free up about 10GB (out of 40GB total).
]]></description><link>https://billboard.bsd.cafe/topic/277/partitioning-without-usr-src-and-usr-obj</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/277/partitioning-without-usr-src-and-usr-obj</guid><dc:creator><![CDATA[vagnretur]]></dc:creator><pubDate>Sun, 28 Jun 2026 13:45:11 GMT</pubDate></item><item><title><![CDATA[Working around dragons with the Lemote Yeeloong laptop and OpenBSD]]></title><description><![CDATA[@CiotBSD OT = off topic
]]></description><link>https://billboard.bsd.cafe/topic/276/working-around-dragons-with-the-lemote-yeeloong-laptop-and-openbsd</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/276/working-around-dragons-with-the-lemote-yeeloong-laptop-and-openbsd</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Sun, 28 Jun 2026 08:42:58 GMT</pubDate></item><item><title><![CDATA[SSH port knocking with OpenBSD 7.9]]></title><description><![CDATA[
Port knocking is mostly a bad idea. But people keep wanting to do it, for some false sense of security. If you don't consider it a security control but a way to keep garbage out of your logs, it might be valid. In my case I'm using an old USG Pro 4 running OpenBSD as my firewall and I'd prefer to avoid writing stuff to the logs, as I'd prefer the flash not to wear out sooner than needed, definitely not thanks to background radiation on the internet.


https://dgl.cx/2026/06/ssh-port-knocking-with-openbsd

]]></description><link>https://billboard.bsd.cafe/topic/257/ssh-port-knocking-with-openbsd-7.9</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/257/ssh-port-knocking-with-openbsd-7.9</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 19 Jun 2026 11:42:03 GMT</pubDate></item><item><title><![CDATA[[astharoshe.net] Hello assembler!]]></title><description><![CDATA[Sharing this [1] link as I dive into amd64 assembly programming on OpenBSD (it really came in handy!).
This [2] Reddit thread also helped me understand the elf(5) requirements for programming assembly on OpenBSD.
Happy hacking!
[1] https://astharoshe.net/2020-06-28-Hello_assembler.html
[2] https://www.reddit.com/r/openbsd/s/JN0hTLNKQF
e: typo
]]></description><link>https://billboard.bsd.cafe/topic/255/astharoshe.net-hello-assembler</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/255/astharoshe.net-hello-assembler</guid><dc:creator><![CDATA[naltun]]></dc:creator><pubDate>Thu, 18 Jun 2026 20:11:46 GMT</pubDate></item><item><title><![CDATA[A 27-Year-Old Authentication Bypass in OpenBSD&#x27;s PPP Stack]]></title><description><![CDATA[
@grahamperrin said:

… The code originated from FreeBSD, which itself derived it from Cronyx Engineering Ltd.'s implementation written by Serge Vakulenko in 1994-1996. …

I assume that FreeBSD is not affected.

Surely (!?)
But I dont known! 
]]></description><link>https://billboard.bsd.cafe/topic/254/a-27-year-old-authentication-bypass-in-openbsd-s-ppp-stack</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/254/a-27-year-old-authentication-bypass-in-openbsd-s-ppp-stack</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 17 Jun 2026 06:57:27 GMT</pubDate></item><item><title><![CDATA[[Kirill&#x27;s journal]]]></title><description><![CDATA[⇒ OpenBSD under QEMU

Architecture specific notes for OpenBSD guests under QEMU, with working command lines where installation succeeds and failure points where it does not.


https://kirill.korins.ky/articles/openbsd-under-qemu/

]]></description><link>https://billboard.bsd.cafe/topic/238/kirill-s-journal</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/238/kirill-s-journal</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 10 Jun 2026 15:14:50 GMT</pubDate></item><item><title><![CDATA[[Dr Brian R. Callahan]]]></title><description><![CDATA[26/08/11
⇒ Cleaning costs, or, examining the OpenBSD -fret-clean flag

I start with apologies to williewillus, calvin, and reezer on Lobste.rs. Prior to July 9, I would have agreed with you all. But it appears I was wrong. There is no need to further engage; it is clear that critique-from-within is undesirable. Which is perfectly OK, because I stepped away from being on the inside. So let's just keep evaluating OpenBSD's mitigations and we'll continue to learn interesting things along the way.


https://briancallahan.net/blog/20260811.html

]]></description><link>https://billboard.bsd.cafe/topic/236/dr-brian-r.-callahan</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/236/dr-brian-r.-callahan</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 10 Jun 2026 14:43:10 GMT</pubDate></item><item><title><![CDATA[Personal VPN Setup Using Wireguard, OpenBSD, and Vultr VPS]]></title><description><![CDATA[Thanks for sharing, I will need this soon!
]]></description><link>https://billboard.bsd.cafe/topic/208/personal-vpn-setup-using-wireguard-openbsd-and-vultr-vps</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/208/personal-vpn-setup-using-wireguard-openbsd-and-vultr-vps</guid><dc:creator><![CDATA[gambler]]></dc:creator><pubDate>Thu, 28 May 2026 14:46:05 GMT</pubDate></item><item><title><![CDATA[Scroll WM on OpenBSD?]]></title><description><![CDATA[The problem is this, and this will always be the answer a member gives you: if the port doesn't exist, create it; otherwise, do without it until someone else does it someday—if ever.
That sets the tone; if that's okay with you, great…
As you can see on: https://www.openbsd.org/mail.html

ports@openbsd.org (Archive)
Discussions about using and contributing to the ports tree.
(Archive: https://marc.info/?l=openbsd-ports)

Browse the archive and you'll see…
]]></description><link>https://billboard.bsd.cafe/topic/207/scroll-wm-on-openbsd</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/207/scroll-wm-on-openbsd</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 27 May 2026 02:36:03 GMT</pubDate></item><item><title><![CDATA[ksh tab completions and other nice-to-haves]]></title><description><![CDATA[I came across this [1] nice post detailing how to customize the ksh(1) experience. I came for the tab completions but it has some general ksh wisdom.
Sharing it as ksh(1) is the default shell on OpenBSD and it's a great shell in general.
[1] https://www.vincentdelft.be/post/post_20210102
]]></description><link>https://billboard.bsd.cafe/topic/206/ksh-tab-completions-and-other-nice-to-haves</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/206/ksh-tab-completions-and-other-nice-to-haves</guid><dc:creator><![CDATA[naltun]]></dc:creator><pubDate>Tue, 26 May 2026 22:02:46 GMT</pubDate></item><item><title><![CDATA[OpenBSD 7.9 is released!!]]></title><description><![CDATA[https://www.openbsd.org/
]]></description><link>https://billboard.bsd.cafe/topic/189/openbsd-7.9-is-released</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/189/openbsd-7.9-is-released</guid><dc:creator><![CDATA[betounix]]></dc:creator><pubDate>Tue, 19 May 2026 18:04:16 GMT</pubDate></item><item><title><![CDATA[Has anyone installed OpenBSD on a Framework 13 AMD 7840?]]></title><description><![CDATA[@Jan ohhh, interesting!
The only question left is whether it's possible to install it from Fuguita.
At the very least, this should let you know which devices are being detected correctly.
]]></description><link>https://billboard.bsd.cafe/topic/186/has-anyone-installed-openbsd-on-a-framework-13-amd-7840</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/186/has-anyone-installed-openbsd-on-a-framework-13-amd-7840</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Tue, 19 May 2026 02:58:03 GMT</pubDate></item><item><title><![CDATA[NGINX (Rift) on OpenBSD: vulnerable?]]></title><description><![CDATA[Hi.
About Nginx: Rift vulnerability:
On my OpenBSD (actually on 7.8) server, I use Nginx (v1.28.x)  ­— I known, normally tomorrow, in few hours, v7.9 will be release, and Nginx will release with 1.30.1 — and I've some rewrite rules.
As we can see on this page, I rewroted my rules.
Is-it needed on OpenBSD? Your opinion about, plz.
In any case, I think — maybe I'm wrong?! — that it's a good idea to get into the habit of “filtering” rewrite rules this way, don't you think? is-not-it?
]]></description><link>https://billboard.bsd.cafe/topic/184/nginx-rift-on-openbsd-vulnerable</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/184/nginx-rift-on-openbsd-vulnerable</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Mon, 18 May 2026 13:26:52 GMT</pubDate></item><item><title><![CDATA[OpenSMTPD Is The Mail Server For The Future]]></title><description><![CDATA[Today on undeadly log: Migrating mail servers from exim to OpenSMTPD (smtpd) is fun and useful

Like (we suspect) quite a few of our readers, undeadly.org co-editor Peter Hansteen runs a mail service and settled on exim as the reasonable alternative to the classic sendmail way back when.
However, that software has had its share of security issues over the years, and during the preparations for the OpenBSD 7.9 release, the ports maintainers decided that…


https://undeadly.org/cgi?action=article;sid=20260516064650

]]></description><link>https://billboard.bsd.cafe/topic/176/opensmtpd-is-the-mail-server-for-the-future</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/176/opensmtpd-is-the-mail-server-for-the-future</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 15 May 2026 13:34:00 GMT</pubDate></item><item><title><![CDATA[minwm: An extremely minimal window manager]]></title><description><![CDATA[See:

https://minwm.btxx.org/


ping: https://mastodon.bsd.cafe/@bt/116573608067727480
]]></description><link>https://billboard.bsd.cafe/topic/175/minwm-an-extremely-minimal-window-manager</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/175/minwm-an-extremely-minimal-window-manager</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Thu, 14 May 2026 17:55:09 GMT</pubDate></item><item><title><![CDATA[[Undeadly.org] OpenBSD logs]]></title><description><![CDATA[26/08/06
⇒ OpenBGPD 9.2 released

A sure sign that a new OpenBSD will soon be ready is that a new OpenBGPD release appears. On August 6th, 2026, the project released OpenBGPD version 9.2.


https://undeadly.org/cgi?action=article;sid=20260807061435
https://www.openbgpd.org/

]]></description><link>https://billboard.bsd.cafe/topic/168/undeadly.org-openbsd-logs</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/168/undeadly.org-openbsd-logs</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 13 May 2026 08:06:52 GMT</pubDate></item><item><title><![CDATA[OpenBSD and slopcode: raindrop to a torrent?]]></title><description><![CDATA[
Every single software product is dealing with the question about what to do with “AI”-generated code, but the question is particularly difficult to answer for open source operating systems like Linux distributions and the various BSDs, which often consist of a wide variety of software packages from hundreds to thousands of different developers. On top of that, they also have to ask the “AI” question for every layer of their offering, from the base install, to the official repositories, to community-run ones…


https://www.osnews.com/story/144935/openbsd-and-slopcode-raindrop-to-a-torrent/


ping: https://framapiaf.org/@osnews@mstdn.social/116558432820118949
]]></description><link>https://billboard.bsd.cafe/topic/165/openbsd-and-slopcode-raindrop-to-a-torrent</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/165/openbsd-and-slopcode-raindrop-to-a-torrent</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Tue, 12 May 2026 12:35:12 GMT</pubDate></item><item><title><![CDATA[Let&#x27;s find out how to get predictable IPv6 addresses assigned to OpenBSD VMs]]></title><description><![CDATA[
Florian Obser (florian@) recently gave a BSD-NL talk entitled "Let's find out how to get predictable IPv6 addresses assigned to OpenBSD VMs".
Florian takes us on a guided tour of how inet6 autoconf actually works, with enlightening and entertaining peeks into selected piece of OpenBSD source.
At the end, we are asked to "now, draw the rest of the owl".


https://undeadly.org/cgi?action=article;sid=20260512115225
slides: https://www.openbsd.org/events.html#bsdnl2026
video: https://exquisite.tube/w/38gDYhMNTNZimk3GcFnHNa

]]></description><link>https://billboard.bsd.cafe/topic/163/let-s-find-out-how-to-get-predictable-ipv6-addresses-assigned-to-openbsd-vms</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/163/let-s-find-out-how-to-get-predictable-ipv6-addresses-assigned-to-openbsd-vms</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Tue, 12 May 2026 12:06:56 GMT</pubDate></item><item><title><![CDATA[OpenBSD Spotted in the Wild]]></title><description><![CDATA["A balloon ! Mum, I want this balloonnnn…"
]]></description><link>https://billboard.bsd.cafe/topic/161/openbsd-spotted-in-the-wild</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/161/openbsd-spotted-in-the-wild</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Mon, 11 May 2026 20:56:07 GMT</pubDate></item><item><title><![CDATA[Setting Up snac2 on OpenBSD]]></title><description><![CDATA[
A guide on deploying a lightweight, C-based ActivityPub instance using snac2 on an OpenBSD stack.


https://geekyschmidt.com/post/2026-05-05-snac2openbsd/

]]></description><link>https://billboard.bsd.cafe/topic/156/setting-up-snac2-on-openbsd</link><guid isPermaLink="true">https://billboard.bsd.cafe/topic/156/setting-up-snac2-on-openbsd</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Sat, 09 May 2026 13:10:13 GMT</pubDate></item></channel></rss>