<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Thilo Bangert</title>
	<atom:link href="http://blogs.gentoo.org/bangert/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gentoo.org/bangert</link>
	<description>Just another Gentoo Blogs site</description>
	<lastBuildDate>Tue, 02 Nov 2010 10:49:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Introducing Entangle: Tethered Camera Control &amp; Capture</title>
		<link>http://blogs.gentoo.org/bangert/2010/06/07/introducing-entangle-tethered-camera-control-and-capture/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2010/06/07/introducing-entangle-tethered-camera-control-and-capture/#comments</comments>
		<pubDate>Mon, 07 Jun 2010 19:11:00 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[development]]></category>
		<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Inspired by Kushal Das from Planet Fedora, I packaged entangle &#8211; a nifty tool enabling tethered control of your Canon or Nikon DSLR from your Linux desktop. It has some dependencies not yet in portage, so you need the gnome and the bangert overlay &#8211; for &#8220;easy&#8221; installation on Gentoo. $ layman -a gnome $ [...]]]></description>
				<content:encoded><![CDATA[<p>Inspired by <a href="http://kushaldas.in/2010/06/05/timelapse-using-fedora-and-d80/">Kushal Das</a> from <a href="http://planet.fedoraproject.org/">Planet Fedora</a>, I packaged <a href="http://capa-project.org/">entangle</a> &#8211; a nifty tool enabling tethered control of your Canon or Nikon <a href="http://en.wikipedia.org/wiki/DSLR">DSLR</a> from your Linux desktop.</p>
<p>It has some dependencies not yet in portage, so you need the <a href="http://git.overlays.gentoo.org/gitweb/?p=proj/gnome.git">gnome</a> and the <a href="http://overlays.gentoo.org/dev/bangert">bangert</a> overlay &#8211; for &#8220;easy&#8221; installation on Gentoo.</p>
<p>$ layman -a gnome<br />
$ layman -a bangert<br />
$ emerge -av entangle</p>
<p>Mind you, entangle-0.1.0 is its first release, but it works pretty well already.  Daniel Berrangé &#8211; the principal developer behind entangle &#8211; has been very responsive in fixing a nasty segfault. Thanks.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2010/06/07/introducing-entangle-tethered-camera-control-and-capture/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Replacing Konqueror with rekonq</title>
		<link>http://blogs.gentoo.org/bangert/2010/05/31/replacing-konqueror-with-rekonq/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2010/05/31/replacing-konqueror-with-rekonq/#comments</comments>
		<pubDate>Mon, 31 May 2010 10:56:15 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[development]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[In a typical day I use multiple browsers. Konqueror, Firefox and Arora have been good companions the past few years. My main browser has usually been Konqueror, with Firefox being the one used for webdevelopment and sites which failed in Konqueror. The recent slew of webkit browsers then added Arora to the mix, which was [...]]]></description>
				<content:encoded><![CDATA[<p>In a typical day I use multiple browsers. <a href="http://www.konqueror.org/">Konqueror</a>, <a href="http://www.mozilla.com/en-US/firefox/firefox.html">Firefox</a> and <a href="http://code.google.com/p/arora/">Arora</a> have been good companions the past few years. My main browser has usually been Konqueror, with Firefox being the one used for webdevelopment and sites which failed in Konqueror.</p>
<p>The recent slew of <a href="http://webkit.org/">webkit</a> browsers then added Arora to the mix, which was a really nice experience. I use it a lot on Windows too. However, the reason I like Konqueror so much, is due to the really good Desktop integration &#8211; especially the <a href="http://en.wikipedia.org/wiki/KWallet">wallet</a> has me hooked. Granted, Firefox provides a similar experience, but its slow startup times and less slick KDE integration have always put me off.</p>
<p>Now, <a href="http://rekonq.sourceforge.net/">rekonq</a> is an attempt to provide a Konqueror-like, but webkit based alternative. The ambition, so it seems, is to produce a browser that is compatible with Konqueror: Among other things it will use the passwords stored in the wallet by Konqueror. That makes for a nice transition between the two browsers.</p>
<p>Over the past few weeks, rekonq has first replaced Arora and now even Konqueror, which I have demoted as second in line for the text/html mime-type.</p>
<p>If you like Konqueror I urge you to try rekonq. Its available in portage as www-client/rekonq<br />
<code><br />
$ sudo emerge -pv rekonq<br />
</code></p>
<p>Rekonq&#8217;s fast paced development can be followed over at http://gitorious.org/rekonq</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2010/05/31/replacing-konqueror-with-rekonq/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Teredo IPv6 in Gentoo</title>
		<link>http://blogs.gentoo.org/bangert/2010/05/03/teredo-ipv6/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2010/05/03/teredo-ipv6/#comments</comments>
		<pubDate>Mon, 03 May 2010 10:31:02 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[development]]></category>
		<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The world is running out of IP addresses. IPv6 to the rescue! Unfortunately most ISPs dont yet provide IPv6 connectivity. But be sure to ask your provider in order to increase awareness. In the meantime a number of tunnelling mechanisms have been developed, among them Teredo. Miredo is a GPL implementation of Teredo and it [...]]]></description>
				<content:encoded><![CDATA[<p>The world is <a href="http://www.potaroo.net/tools/ipv4/index.html">running out of IP addresses.</a> <a href="http://en.wikipedia.org/wiki/IPv6">IPv6</a> to the rescue! Unfortunately most ISPs dont yet provide IPv6 connectivity. But be sure to ask your provider in order to increase awareness.</p>
<p>In the meantime a number of <a href="http://en.wikipedia.org/wiki/IPv6#Tunneling">tunnelling mechanisms</a> have been developed, among them <a href="http://en.wikipedia.org/wiki/Teredo_tunneling">Teredo</a>. <a href="http://www.remlab.net/miredo/">Miredo</a> is a GPL implementation of Teredo and it is now available in Portage.</p>
<p>The advantage of Toredo is, that it also works through NAT. Windows Vista and later have Teredo support built-in.</p>
<p>To enable Teredo on Gentoo, simply sync portage and emerge and start miredo:<br />
<code><br />
$ sudo eix-sync<br />
$ sudo emerge -av net-misc/miredo<br />
$ sudo /etc/init.d/miredo start<br />
</code></p>
<p>To start miredo at boot, do<br />
<code><br />
$ sudo rc-update add miredo default<br />
</code></p>
<p>Now go to http://www.kame.net/ and watch the turtle dance <img src='http://blogs.gentoo.org/bangert/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2010/05/03/teredo-ipv6/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>MTKII as /dev/ttyACM0 in bt747</title>
		<link>http://blogs.gentoo.org/bangert/2010/01/31/earth-to-rxtx/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2010/01/31/earth-to-rxtx/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 13:17:14 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[development]]></category>
		<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[During summer I got interested in GPS and mapping and bought myself a mtkII based device. For these there is a java app called bt747 in the tree. However I couldn&#8217;t get it to work &#8211; bt747 would not accept the device name I tried to convince it of using. Turns out that older devices [...]]]></description>
				<content:encoded><![CDATA[<p>During summer I got interested in <a href="http://en.wikipedia.org/wiki/GPS">GPS</a> and <a href="http://www.openstreetmap.org/">mapping</a> and bought myself a mtkII based device. For these there is a java app called <a href="http://www.bt747.org/">bt747</a> in the <a href="http://znurt.org/sci-geosciences/bt747">tree</a>. However I couldn&#8217;t get it to work &#8211; bt747 would not accept the device name I tried to convince it of using.</p>
<p>Turns out that older devices where using a USB to serial converter to provide the USB interface: these show up as /dev/ttyUSBx &#8211; with x being an integer. The device I bought is a newer generation who appear to have an on-chip USB port, which will show up as /dev/ttyACMx (x again being an integer). So, support for ttyACMx type devices is needed in BT747. See <a href="http://bugs.gentoo.org/show_bug.cgi?id=281888">bug #281888</a>.</p>
<p>It turns out BT747, being a java app, uses rxtx to provide support for serial device communication. So lets fix rxtx &#8211; see <a href="http://bugs.gentoo.org/show_bug.cgi?id=301126">bug #301126</a>.</p>
<p>Meanwhile there is also <a href="http://sourceforge.net/projects/mtkbabel/">mtkbabel</a> in <a href="http://znurt.org/sci-geosciences/mtkbabel">portage</a>, which is not so picky about the device names.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2010/01/31/earth-to-rxtx/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Voting in Bugzilla</title>
		<link>http://blogs.gentoo.org/bangert/2009/05/29/voting-in-bugzilla/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2009/05/29/voting-in-bugzilla/#comments</comments>
		<pubDate>Fri, 29 May 2009 21:03:08 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Voting for a bug gives users the possibility to express more finegrained the urgency with which they prefer to have a certain bug fixed. The KDE bug system has had it for years and it seems to work rather well. Recently voting was enabled on the Gentoo bugzilla. So go vote &#8211; yeah, also for [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://bugs.gentoo.org/page.cgi?id=voting.html">Voting for a bug</a> gives users the possibility to express more finegrained the urgency with which they prefer to have a certain bug fixed. The <a href="http://bugs.kde.org">KDE bug system</a> has had it for years and it seems to work rather well.</p>
<p>Recently voting was enabled on the <a href="https://bugs.gentoo.org/">Gentoo bugzilla</a>. </p>
<p>So <a href="http://bugs.gentoo.org/votes.cgi?action=show_user">go</a> <a href="http://bugs.gentoo.org/page.cgi?id=voting.html">vote</a> &#8211; yeah, also for the <a href="http://www.europarl.europa.eu/">EP</a> and the <a href="http://en.wikipedia.org/wiki/Danish_Act_of_Succession_referendum,_2009">next</a> <a href="http://valg.vfm.dk/vaelgere/folkeafstemning-tronfoelgeloven/Sider/Start.aspx">queen</a>, if you have the privilege.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2009/05/29/voting-in-bugzilla/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>How to help Gentoo: Seeding ISO images</title>
		<link>http://blogs.gentoo.org/bangert/2008/11/23/how_to_help_gentoo_seeding_iso_images/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2008/11/23/how_to_help_gentoo_seeding_iso_images/#comments</comments>
		<pubDate>Fri, 21 Nov 2008 14:41:15 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Long time no blog. So &#8211; you&#8217;ve always wanted to help out Gentoo? A common way to help is by providing a mirror &#8211; either distfiles or rsync. We have a good list of mirrors, both rsync and distfiles. Setting up a mirror is a huge commitment and my thanks go out to all those [...]]]></description>
				<content:encoded><![CDATA[<p>Long time no blog.</p>
<p>So &#8211; you&#8217;ve always wanted to help out Gentoo? A common way to help is by providing a mirror &#8211; either distfiles or rsync. <a href="http://www.gentoo.org/main/en/mirrors2.xml">We have a good list of mirrors</a>, both rsync and distfiles. Setting up a mirror is a huge commitment and my thanks go out to all those who do.</p>
<p>Due to the large requirements for diskspace, bandwith and cpu power, this is usually not an option for individuals.</p>
<p>However, <a href="http://www.gentoo.org/proj/en/releng/">Gentoo releases</a> are also <a href="http://torrents.gentoo.org/">distributed</a> using <a href="http://en.wikipedia.org/wiki/BitTorrent">BitTorrent</a>.</p>
<p>A good way to help gentoo is to</p>
<ul>
<li><strong>use bittorrent</strong> to download releases.</li>
<li><strong>keep seeding</strong> after the download has finished.</li>
<li><strong>seed the other isos and stages</strong> as well.</li>
</ul>
<p>There is a large number of <a href="http://en.wikipedia.org/wiki/BitTorrent_client">bittorrent clients</a> available for linux and many of them are available in portage. On my desktop I use <a href="http://ktorrent.org/">ktorrent</a> which works really well.</p>
<p>However, since my uplink to the internet is quite limited, it occurred to me, to run a bittorrent client on my Virtual Private Server (VPS).</p>
<p>Looking for an CLI bittorrent client I found rtorrent. Here is how to get started:</p>
<ul>
<li><strong>Install rtorrent</strong>
<p>Most distributions have rtorrent packages &#8211; so does Gentoo <img src='http://blogs.gentoo.org/bangert/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />
</p>
<blockquote><p>$ emerge -av rtorrent</p></blockquote>
</li>
<li><strong>Start screen</strong>
<p> You will want to have rtorrent running also when you disconnect from your VPS. <a href="http://www.gnu.org/software/screen/">screen</a> allows you to do that.
</p>
<blockquote><p>$ screen</p></blockquote>
</li>
<li><strong>Configure rtorrent</strong>
<p>Here we disable up- and download throttling &#8211; YMMV.</p>
<blockquote><p>
$ cat > ~/.rtorrent.rc<br />
download_rate = 0<br />
upload_rate = 0<br />
^D
</p></blockquote>
</li>
<li><strong>Start rtorrent</strong>
<p>
<code><br />
$ rtorrent<br />
</code></p>
</li>
<li><strong>Download torrents</strong>
<p>
Press <del><em>backslash</em></del><em>backspace</em> and paste a URL to a torrent from <a href="http://torrents.gentoo.org/">torrents.gentoo.org</a>. Hit <em>enter</em>. Continue adding all the torrents you want to help with &#8211; the more the merrier.
</p>
</li>
<li><strong>Wait</strong>
<p>rtorrent will now download the isos. At the same time it will start seeding. You can now detach from screen &#8211; press CTRL-a + d</p>
</li>
<li><strong>Watch</strong>
<p>Reconnect to your running rtorrent using screen:
</p>
<blockquote><p>$ screen -r
</p></blockquote>
<p>
You will be able to see how much traffic you already have seeded. Press <em>right</em> to see details of the individual torrents.
</p>
</li>
<li><strong>That&#8217;s it.</strong></li>
</ul>
<p><a href="http://dev.gentoo.org/~bangert/images/rtorrent-1week.png"><br />
<img src="http://dev.gentoo.org/~bangert/images/rtorrent-1week.png" alt="1 week rtorrent" title="1 Week rtorrent" width="100%"/>Click to enlarge.</a></p>
<p>In the past week the rtorrent on my VPS seeded roughly 13 GB. The VPS has a big pipe, so most likely this has speed up some peoples download of gentoo release isos and stages. </p>
<p><strong>Warning:</strong> If your VPS plan does not have a lot of traffic included, you may want to keep an eye on the traffic counter. There is also the possibility of configuring upload throttling, which limits the amount of bandwith rtorrent will use.</p>
<p>Check out the <a href="http://linux.die.net/man/1/rtorrent">rtorrent man page</a> for a more detailed look on how to use and configure rtorrent.</p>
<p>Happy Seeding.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2008/11/23/how_to_help_gentoo_seeding_iso_images/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Cookies for HTTPOnly</title>
		<link>http://blogs.gentoo.org/bangert/2007/07/05/cookies_for_httponly/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2007/07/05/cookies_for_httponly/#comments</comments>
		<pubDate>Thu, 05 Jul 2007 18:53:40 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[development]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Recently I researched cookies a bit and while playing with the cookie related functions in PHP I stumbled upon the HTTPOnly flag. The purpose of the HTTPOnly flag is to prevent cross-site scripting (XSS) attacks. The idea is, that the browser will use the HTTPOnly-flagged cookie only when doing HTTP requests. It will not, as [...]]]></description>
				<content:encoded><![CDATA[<p>Recently I researched <a href="http://wp.netscape.com/newsref/std/cookie_spec.html">cookies</a> a bit and while playing with the <a href="http://php.net/manual/en/function.setcookie.php">cookie related functions in PHP</a> I stumbled upon the HTTPOnly flag.</p>
<p>The purpose of the HTTPOnly flag is to prevent cross-site scripting (XSS) attacks. The idea is, that the browser will use the HTTPOnly-flagged cookie only when doing HTTP requests. It will not, as it normally would, make this cookie available to client side scripting languages (like JavaScript).</p>
<p>The HTTPOnly flag has been introduced by <a href="http://msdn2.microsoft.com/en-us/library/ms533046.aspx">Microsoft as part of Service Pack 1 for Internet Explorer 6</a>, released in <a href="http://en.wikipedia.org/wiki/Browser_timeline">September of 2002</a>.</p>
<p>A neat idea, as limiting the possibilities for XSS vulnerabilities can only be good. However, being an extension to the standard, this requires support in both the server and the client. Microsoft did the first step, so how do the other involved parties hold up?</p>
<p><a href="http://ilia.ws/archives/121-httpOnly-cookie-flag-support-in-PHP-5.2.html">PHP added support for the HTTPOnly cookie in version 5.2</a>, released in <a href="http://en.wikipedia.org/wiki/PHP#Important_Release_history"><em>November of 2006</em></a>.</p>
<p>Current releases of Firefox do not support HTTPOnly cookies. Version 3, however, will <a href="http://blogs.securiteam.com/index.php/archives/849">support HTTPOnly cookies</a>. And Stefan Esser, of Hardened-PHP and suhosin fame, wrote an extension for <a href="https://addons.mozilla.org/en-US/firefox/addon/3629">Firefox 2.0 which supports HTTPOnly cookies</a>.</p>
<p><a href="http://www.avencius.nl/?q=node/566">Opera will support HTTPOnly cookies in version 9.5</a>.</p>
<p>I am not sure whether KHTML or WebKit support HTTPOnly cookies.</p>
<p>Apparently <a href="http://www.webappsec.org/lists/websecurity/archive/2006-08/msg00014.html"> ancient browsers break</a> when asked to process a HTTPOnly cookie. In this day and age this should not be too big a problem however.</p>
<p>It appears, that Microsoft, as unlikely as it may seem, had a pretty decent idea, but the open source community did not respond as one could have hoped.<br />
Is this NIH?</p>
<p>Now, after the <a href="http://community.livejournal.com/lj_dev/708069.html">LiveJournal incident</a>, which could have been prevented if HTTPOnly cookies were widely supported, an increased effort seems underway to finally get this implemented.</p>
<p>Of course, HTTPOnly cookies do not protect against all types of XSS attacks. Nevertheless, it is another layer of protection for which I am grateful. I was surprised to learn that this was introduced by Microsoft AND that the open source community hasn&#8217;t adopted this feature more widely. Microsofts positive impacts on this industry do exist afterall&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2007/07/05/cookies_for_httponly/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>srlog2: secure remote logging</title>
		<link>http://blogs.gentoo.org/bangert/2007/06/11/title_17/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2007/06/11/title_17/#comments</comments>
		<pubDate>Sun, 10 Jun 2007 16:43:02 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[A year ago, Bruce Guenter released srlog2, which is a secure remote log transmission system. At work we will be wanting centralized logging, which is why I finally hacked on an ebuild for it. Getting there was a bit tricky, as nistp224 (ebuild) &#8212; an elliptic curve crypto library &#8212; did not compile using gcc-4. [...]]]></description>
				<content:encoded><![CDATA[<p>A year ago, <a href="http://untroubled.org">Bruce Guenter</a> released <a href="http://untroubled.org/srlog2/">srlog2</a>, which is <em> a secure remote log transmission system</em>. At work we will be wanting centralized logging, which is why I finally hacked on an <a href="http://overlays.gentoo.org/dev/bangert/browser/ebuilds/app-admin/srlog2">ebuild</a> for it.</p>
<p>
Getting there was a bit tricky, as <a href="http://cr.yp.to/nistp224.html">nistp224</a> (<a href="http://overlays.gentoo.org/dev/bangert/browser/ebuilds/app-crypt/nistp224">ebuild</a>) &#8212; an elliptic curve crypto library &#8212; did not compile using gcc-4. Luckily Griffon26 is more asm-savy than I am and within minutes he produced a working patch. (Thanks!)</p>
<p>Anyway &#8211; getting srlog2 to work is a breeze:</p>
<ol>
<li>On the receiver aka. central loghost, create srlog2d keys
<p><code><br />
receiver.example.com $ srlog2-keygen -t nistp224 /var/log/srlog2<br />
</code><br />
The public key will need to be distributed to all sending hosts (see step 5).
</li>
<li>Set the private key as server key
<p><code><br />
receiver.example.com $ mv /var/log/srlog2/nistp224 /var/log/srlog2/secrets<br />
</code>
</li>
<li>Use the following run file to start srlog2d
<p><code><br />
#!/bin/bash<br />
cd /var/log/srlog2<br />
exec srlog2d srlog2-logger --mkdirs<br />
</code>
</li>
<li>On the sender, create host keys
<p><code><br />
sender-hostname.example.com $ srlog2-keygen -t nistp224 /etc/srlog2<br />
</code><br />
The public key needs to be put on the receiving host (see step 7).
</li>
<li>Put the receivers public key into <code>/etc/srlog2/servers/receiver.example.com.nistp224</code></li>
<li>Start a log service. srlog2 takes a log line from standard input and sends it to the central loghost. It is designed to be similar to <a href="http://cr.yp.to/daemontools/multilog.html">multilog</a> and thus also supports the patterns.
<p><code><br />
sender-hostname.example.com $ srlog2 bla receiver.example.com<br />
--type stuff--<br />
</code></li>
<li>Before the above will work you need to put the senders public key into /var/log/srlog2/senders. Prepend it with its hostname (not fqdn)  followed by a semicolon:
<p><code><br />
sender-hostname:nistp224:0kfFexdXjzVPPRQOUbLq3f2K9fDqC2BDsE3o/Q==<br />
</code>
</li>
</ol>
<p><strong>Done!</strong></p>
<p>You will now start to see logfiles in /var/log/srlog2/sender-hostname/bla/. If everything worked well, you should be seeing what you typed in step 6.</p>
<p>If you want to use <a href="http://cr.yp.to/ecdh.html">curve25519</a> instead of nistp224, replace all occurrences of nistp224 above accordingly. However, currently curve25519 is only supported on 32-bit <code>x86</code>.</p>
<p><strong>Note:</strong> The example above is only meant to get you up and running. On a production system the server keys would not be stored in /var/log/srlog2. Also be aware of funny line wrapping in the shell commands above.</p>
<p><strong>Update:</strong> it was pointed out to me, that dragonheart already had prepared ebuilds for nistp224 and srlog2. And they are much more refined too. Way cool!</p>
<p>Happy hacking!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2007/06/11/title_17/feed/</wfw:commentRss>
		<slash:comments>34</slash:comments>
		</item>
		<item>
		<title>red5, mod_flex and enhost and more</title>
		<link>http://blogs.gentoo.org/bangert/2007/05/27/red5_mod_flex_and_enhost_and_more/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2007/05/27/red5_mod_flex_and_enhost_and_more/#comments</comments>
		<pubDate>Sun, 27 May 2007 15:53:52 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The other day I updated the red5 ebuild to the most recent version (0.6.1). The red5 release team keeps me informed of releases just before they happen so that we can stay fairly up-to-date&#8230; neat! The company I work for develops learning tools using flash and flex2. For this reason I tried to create an [...]]]></description>
				<content:encoded><![CDATA[<p>The other day I <a href="http://overlays.gentoo.org/dev/bangert/browser/ebuilds/dev-java/red5">updated</a> the <a href="http://osflash.org/red5">red5</a> ebuild to the most recent version (0.6.1). The red5 release team keeps me informed of releases just before they happen so that we can stay fairly up-to-date&#8230; neat!</p>
<p>The company I work for develops learning tools using flash and flex2. For this reason I tried to create an ebuild for <a href="http://labs.adobe.com/wiki/index.php/Flex_Module_for_Apache_and_IIS">mod_flex</a> &#8211; an apache module which compiles adobe flex code (.mxml) on the fly&#8230; which is great, as you get a .swf back and thus it is much easier to test things during development. Adobe originally provided an installer for the apache module &#8211; a horrible idea, as the installer required java and a X terminal and was generally broken (for me). Upon (not only) my complaint, Adobe now distributes a plain old zip file and thus a mod_flex ebuild is a reality. Installer programs are so 1990ies..</p>
<p><a href="http://reductivelabs.com/projects/enhost/">enhost</a> &#8211; a program which adds system facts (collected using <a href="http://reductivelabs.com/projects/facter/">facter</a> from the same author) into a ldap database &#8211; is not in the tree (yet) but I&#8217;ve added it to my overlay. Great concept &#8211; although enhost could need some love. I am currently investigating server inventory systems for which enhost (or a similar program) could be pretty helpful. This morning I found <a href="http://opensource.vidavee.com/nVentory">nVentory</a> which looks promising.</p>
<p>Both facter, enhost and nVentory are written in Ruby. nVentory is web-based and thus uses Rails. In an effort to try to grasp this language I have created some scripts which check the metadata of the portage tree. In turn this resulted in a spree of herd fixing&#8230; Thus far I enjoy Ruby and I would not mind doing more with it.</p>
<p>With exams out of the door &#8211; I plan on being more present in the community (IRC &#8211; uhu)&#8230; lets see how that works out.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2007/05/27/red5_mod_flex_and_enhost_and_more/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>RMS in CPH</title>
		<link>http://blogs.gentoo.org/bangert/2007/03/28/rms_in_cph/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://blogs.gentoo.org/bangert/2007/03/28/rms_in_cph/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 07:37:53 +0000</pubDate>
		<dc:creator>bangert</dc:creator>
				<category><![CDATA[Gentoo]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[It appears Richard Stallman is going to be at DTU near Copenhagen this weekend. He is going to talk about The Danger of Software Patents, a topic covered by him on numerous occasions already. Nevertheless I am planning on being there &#8211; give me a shout and we can meet up. &#8230; I really need [...]]]></description>
				<content:encoded><![CDATA[<p>It <a href="http://dtulug.dtu.dk/bof.html">appears</a> Richard Stallman is going to be at DTU near <a href="http://dtulug.dtu.dk/maps/dtu308.html.en">Copenhagen</a> this weekend.</p>
<p>He is going to talk about <em>The Danger of Software Patents</em>, a topic covered by him on numerous occasions already. Nevertheless I am planning on being there &#8211; give me a shout and we can meet up.</p>
<p>&#8230; I really need a Gentoo (t-)shirt&#8230; </p>
<p><code>Fighting patents one by one will never eliminate the danger of software patents, any more than swatting mosquitoes will eliminate malaria.</p>
<p>Richard Stallman</code></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gentoo.org/bangert/2007/03/28/rms_in_cph/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
