From sara.fink at gmail.com Tue Mar 1 12:43:07 2016 From: sara.fink at gmail.com (sara fink) Date: Tue, 1 Mar 2016 12:43:07 +0200 Subject: vdsl2 router Message-ID: Hi Everyone I would like to buy a vdsl2 router that supports openwrt or ddwrt. Anyone has experience with a good router? Xphone gives dlink 225 which doesn't support openwrt. -------------- next part -------------- An HTML attachment was scrubbed... URL: From rabin at rabin.io Tue Mar 1 13:40:01 2016 From: rabin at rabin.io (Rabin Yasharzadehe) Date: Tue, 1 Mar 2016 13:40:01 +0200 Subject: vdsl2 router In-Reply-To: References: Message-ID: In my opinion , a good place to start is this list - http://www.netcheif.com/Articles/VDSL_Router/VDSL_Router.htm find one/two that meet your demand, and then check if they have support for openwrt/dd-wrt -- Rabin On 1 March 2016 at 12:43, sara fink wrote: > Hi Everyone > > I would like to buy a vdsl2 router that supports openwrt or ddwrt. Anyone > has experience with a good router? Xphone gives dlink 225 which doesn't > support openwrt. > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > > -------------- next part -------------- An HTML attachment was scrubbed... URL: From esr+linux-il at g.jct.ac.il Tue Mar 8 01:07:10 2016 From: esr+linux-il at g.jct.ac.il (E.S. Rosenberg) Date: Tue, 8 Mar 2016 01:07:10 +0200 Subject: vdsl2 router In-Reply-To: References: Message-ID: Personally I don't bother with the modem/router supporting OpenWRT, I bought a nice TP-Link router which functions as the router of my networks and runs OpenWRT then the provider router/bridge/whatever box is just used as a bridge device and nothing more. There are far less xDSL devices that support *WRT and also you never know if the device you'll get from your provider is under your full control (these days with 2/3-play packages the router tends to not be under your control since it also does your VoIP/TV) so as far as I am concerned the provider-device is 'outside' my network and should be treated as such.... Also the provider devices tend to have terrible firmware/updates which of course you want to salvage with *WRT. Regards, Eliyahu - ????? 2016-03-01 13:40 GMT+02:00 Rabin Yasharzadehe : > In my opinion , a good place to start is this list - > http://www.netcheif.com/Articles/VDSL_Router/VDSL_Router.htm > find one/two that meet your demand, and then check if they have support for > openwrt/dd-wrt > > -- > Rabin > > On 1 March 2016 at 12:43, sara fink wrote: >> >> Hi Everyone >> >> I would like to buy a vdsl2 router that supports openwrt or ddwrt. Anyone >> has experience with a good router? Xphone gives dlink 225 which doesn't >> support openwrt. >> >> _______________________________________________ >> Linux-il mailing list >> Linux-il at cs.huji.ac.il >> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il >> > > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > From esr+linux-il at g.jct.ac.il Tue Mar 8 02:37:46 2016 From: esr+linux-il at g.jct.ac.il (E.S. Rosenberg) Date: Tue, 8 Mar 2016 02:37:46 +0200 Subject: vdsl2 router In-Reply-To: References: <56DE1287.2000500@gmail.com> Message-ID: re:all 2016-03-08 2:36 GMT+02:00 E.S. Rosenberg : > 2016-03-08 1:45 GMT+02:00 geoffrey mendelson : >> On 3/8/2016 1:07 AM, E.S. Rosenberg wrote: >>> >>> Personally I don't bother with the modem/router supporting OpenWRT, I >>> bought a nice TP-Link router which functions as the router of my >>> networks and runs OpenWRT then the provider router/bridge/whatever box >>> is just used as a bridge device and nothing more. >> >> >> Would you please post a direct link to where you bought it, and the exact >> model. I asked about six months ago for a recommendation and in the end >> could not figure out which was the exact model I needed, and did not want to >> spend a couple of hundred NIS (I need two) to buy paperweights. :-) > I have at different locations the WR740N (v4.23 iirc), WR841ND (v5.x > iirc?) and WR1043ND (v1.x) and am extremely satisfied with all of > them, note none of these devices support the 5GHz band but since I > don't suffer from lot's of interference from neighbors and the 'big' > consumers (laptops) anyhow don't support the 5GHz band either I > haven't bothered getting a newer router as of yet. > > All these devices are available through both KSP and Ivory (and I'm > pretty sure Bug also carries TP-Link). > > If your main use is wireless and you don't need very high speeds the > WR740N is extremely high value for money since it also has pretty > advanced features if you open it up (voiding warranty), I actually use > 2 740s in a very large house to provide the whole house with coverage > instead of bothering with one much stronger but much more expensive > device. > > If you also want gigabit Ethernet the 1043 is the only option from the > devices I mentioned, however there are plenty of other well supported > TP-Link devices that also have Gigabit ethernet available here. > In the past (4-5 years ago) I have managed to brick a 841 which I > still have sitting on a shelve waiting for me to hook it up to a > console and reflash it (at the time I was mucking around with flashing > from CLI and modifying individual byte ranges manually and I used the > bricking as the perfect excuse to get a 1043), but the other 841 I > have is running perfectly fine. > > When I want to buy a new router I basically go through what is > available and what is known about the hardware & support on > OpernWRT.org and try to get the best value/NIS ratio, things to look > for (other then connectivity details) are decent size RAM (at least > 32MiB) and preferably also a larger ROM size so you can install the > more expansive versions of OpenWRT.... > > Of the newer dual-band routers (the Archers C*) some devices seem to > have good support but you'll have to check when you are deciding what > to get.... > >> >>> There are far less xDSL devices that support *WRT and also you never >>> know if the device you'll get from your provider is under your full >>> control (these days with 2/3-play packages the router tends to not be >>> under your control since it also does your VoIP/TV) so as far as I am >>> concerned the provider-device is 'outside' my network and should be >>> treated as such.... >>> >>> Also the provider devices tend to have terrible firmware/updates which >>> of course you want to salvage with *WRT. >>> >> I have a Cell-Com TV router. It is not the version with a VoIP interface, it >> is for their "double play" service. It came with a decent user interface. I >> got the admin name and password via their on-line support chat via their >> website (in Hebrew). I had to do the usual ID number and credit card digits >> verification. >> >> This was to open a port so that I could open a port on the router I have >> bridging them to my network. It has a DMZ option, but I don't use it. The >> port has stayed open since I changed it. > Since the provider often has a was to access the device even if you > have Admin access (very nice of them they allowed you, I know other > devices where they make port forwarding available through the user > interface and Admin is strictly them) and you also have nonsense like > Bezeq_free lurking around afaik the provider device is not 'inside' my > network. > >> >> Note to prospective Cell-Com TV users, their router and connection work >> fine, however before we had it, we had a gamer's package with Netvision. >> This did some QOS tweaks to our connection at their end which improved >> on-line gaming. The Cell-Com TV is QOS tweaked at their end for their >> service, so we lost the gamer's package. It only really affects us during >> the evening hours and all day Friday and Saturday. >> >> The Cell-Com TV boxes are on the wifi network on their router, and nothing >> else is. > What do you mean by this, you have no WiFi enabled devices except for > the TV decoders? is the WiFi network isolated from your wired network? > >> >> I also have a line with CCC on our network, I use the CCC line, my wife and >> sons use the Cell-Com. We share DNS, mail, etc servers which split across >> them. > My experience with CCC is very positive, only reason I'm not using > them is I live with people who demand Rimon. > > As a closing note: I have replaced provider devices very often due to > device failure while the TP-Links continue to function without issue > (definitely during the period that Bezeq still provided modems but was > not buying new ones so you got refurbished devices that failed often). > > HTH, > Eliyahu - ????? >> >> Geoff. >> >> -- >> Geoffrey S. Mendelson 4X1GM/N3OWJ >> Jerusalem Israel. >> From gabor at szabgab.com Tue Mar 8 07:05:03 2016 From: gabor at szabgab.com (Gabor Szabo) Date: Tue, 8 Mar 2016 07:05:03 +0200 Subject: OT: SSL certificates Message-ID: Hi there, I think it's time to move some of my sites to use https, but as I only had self-signed ssl so far I wonder if you ppl have any recommendation where to get the certificate from and how much should I expect to pay? I have one domain with about 20 subdomains (the translated versions of my articles) and a few other domains with 1-2, sometimes even more subdomains. Most of them are probably considered commercial as they have ads on it and on some of them I even have a few subscribers, but they are, unfortunately, not a big business. Nevertheless I think this might exclude some "open source" providers. I looked at http://www.cacert.org/ but as I can see the certificate they use on their own site is not recognized by either Chrome or Firefox. That does not seem to be a good thing. (See https://www.cacert.org/ ) A found plenty of companies offering SSL certificates. One of them https://www.ssl.com/ that was recommended by the domain registrar I am using had $177 / year for the first 3 hostname and then $49 / year for each additional hostname and $129/year for each wildcard domain. Is that a reasonable price? Any suggestions? regards Gabor -------------- next part -------------- An HTML attachment was scrubbed... URL: From baruch at tkos.co.il Tue Mar 8 07:24:34 2016 From: baruch at tkos.co.il (Baruch Siach) Date: Tue, 8 Mar 2016 07:24:34 +0200 Subject: OT: SSL certificates In-Reply-To: References: Message-ID: <20160308052434.GW2877@tarshish> Hi Gabor, On Tue, Mar 08, 2016 at 07:05:03AM +0200, Gabor Szabo wrote: > A found plenty of companies offering SSL certificates. One of them > https://www.ssl.com/ > that was recommended by the domain registrar I am using had > $177 / year for the first 3 hostname and then $49 / year for each > additional hostname and $129/year for each wildcard domain. > > Is that a reasonable price? Any suggestions? How about https://letsencrypt.org/ free certs? baruch -- http://baruch.siach.name/blog/ ~. .~ Tk Open Systems =}------------------------------------------------ooO--U--Ooo------------{= - baruch at tkos.co.il - tel: +972.2.679.5364, http://www.tkos.co.il - From amos.shapira at gmail.com Tue Mar 8 08:23:14 2016 From: amos.shapira at gmail.com (Amos Shapira) Date: Tue, 8 Mar 2016 17:23:14 +1100 Subject: OT: SSL certificates In-Reply-To: <20160308052434.GW2877@tarshish> References: <20160308052434.GW2877@tarshish> Message-ID: I too would recommend letsenctlrypt. The only down side is possibly that you have to keep renewing (automatically with a cron job) every three months. Alternatively, www.ssls.com lists very very cheap certs. On 8 Mar 2016 4:49 p.m., "Baruch Siach" wrote: > Hi Gabor, > > On Tue, Mar 08, 2016 at 07:05:03AM +0200, Gabor Szabo wrote: > > A found plenty of companies offering SSL certificates. One of them > > https://www.ssl.com/ > > that was recommended by the domain registrar I am using had > > $177 / year for the first 3 hostname and then $49 / year for each > > additional hostname and $129/year for each wildcard domain. > > > > Is that a reasonable price? Any suggestions? > > How about https://letsencrypt.org/ free certs? > > baruch > > -- > http://baruch.siach.name/blog/ ~. .~ Tk Open > Systems > =}------------------------------------------------ooO--U--Ooo------------{= > - baruch at tkos.co.il - tel: +972.2.679.5364, http://www.tkos.co.il - > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > -------------- next part -------------- An HTML attachment was scrubbed... URL: From tewner at gmail.com Tue Mar 8 08:27:47 2016 From: tewner at gmail.com (Michael Tewner) Date: Tue, 8 Mar 2016 08:27:47 +0200 Subject: OT: SSL certificates In-Reply-To: <20160308052434.GW2877@tarshish> References: <20160308052434.GW2877@tarshish> Message-ID: As far as I know, letsencrypt.org certs are only good for 90 days, and you'll want to have a script automatically renew and replace the cert in the background all the time. I like https://www.namecheap.com , as it helps you find the cheapest between different CA's. CACert is worthy of this community's support, but as you mentioned, their certs aren't included in any browsers or OS's. On Tue, Mar 8, 2016 at 7:24 AM, Baruch Siach wrote: > Hi Gabor, > > On Tue, Mar 08, 2016 at 07:05:03AM +0200, Gabor Szabo wrote: > > A found plenty of companies offering SSL certificates. One of them > > https://www.ssl.com/ > > that was recommended by the domain registrar I am using had > > $177 / year for the first 3 hostname and then $49 / year for each > > additional hostname and $129/year for each wildcard domain. > > > > Is that a reasonable price? Any suggestions? > > How about https://letsencrypt.org/ free certs? > > baruch > > -- > http://baruch.siach.name/blog/ ~. .~ Tk Open > Systems > =}------------------------------------------------ooO--U--Ooo------------{= > - baruch at tkos.co.il - tel: +972.2.679.5364, http://www.tkos.co.il - > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > -------------- next part -------------- An HTML attachment was scrubbed... URL: From amos.shapira at gmail.com Tue Mar 8 09:10:07 2016 From: amos.shapira at gmail.com (Amos Shapira) Date: Tue, 8 Mar 2016 18:10:07 +1100 Subject: vdsl2 router In-Reply-To: References: Message-ID: What exact model of TP-Link have you got? I have a TP-Link AC1750 ADSL2+ modem router which is great except that OpenWRT doesn't support this specific model's WiFi well (see multiple "Notes" in https://wiki.openwrt.org/toh/tp-link/archer-c5-c7-wdr7500) So I'm half-heartedly on the lookout for something to run OpenWRT or VyOS on, with 1Gb ethernet and 802.11ac WiFi and which can be used to do smart and efficient routing especially over OpenVPN tunnels. On 8 March 2016 at 10:07, E.S. Rosenberg wrote: > Personally I don't bother with the modem/router supporting OpenWRT, I > bought a nice TP-Link router which functions as the router of my > networks and runs OpenWRT then the provider router/bridge/whatever box > is just used as a bridge device and nothing more. > > There are far less xDSL devices that support *WRT and also you never > know if the device you'll get from your provider is under your full > control (these days with 2/3-play packages the router tends to not be > under your control since it also does your VoIP/TV) so as far as I am > concerned the provider-device is 'outside' my network and should be > treated as such.... > > Also the provider devices tend to have terrible firmware/updates which > of course you want to salvage with *WRT. > > Regards, > Eliyahu - ????? > > 2016-03-01 13:40 GMT+02:00 Rabin Yasharzadehe : > > In my opinion , a good place to start is this list - > > http://www.netcheif.com/Articles/VDSL_Router/VDSL_Router.htm > > find one/two that meet your demand, and then check if they have support > for > > openwrt/dd-wrt > > > > -- > > Rabin > > > > On 1 March 2016 at 12:43, sara fink wrote: > >> > >> Hi Everyone > >> > >> I would like to buy a vdsl2 router that supports openwrt or ddwrt. > Anyone > >> has experience with a good router? Xphone gives dlink 225 which doesn't > >> support openwrt. > >> > >> _______________________________________________ > >> Linux-il mailing list > >> Linux-il at cs.huji.ac.il > >> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > >> > > > > > > _______________________________________________ > > Linux-il mailing list > > Linux-il at cs.huji.ac.il > > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > > > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > -- -------------- next part -------------- An HTML attachment was scrubbed... URL: From efraim at flashner.co.il Tue Mar 8 09:29:38 2016 From: efraim at flashner.co.il (Efraim Flashner) Date: Tue, 8 Mar 2016 09:29:38 +0200 Subject: OT: SSL certificates In-Reply-To: References: Message-ID: <20160308092938.6d8a6089@debian-netbook> I use wosign for my free certs. They're good for up to 3 years, free is good, and afaik they're in all the browsers. The website is in chinese though, so that can make it a bit challenging. On Tue, 8 Mar 2016 07:05:03 +0200 Gabor Szabo wrote: > Hi there, > > I think it's time to move some of my sites to use https, but as I only had > self-signed ssl so far I wonder if you ppl have any recommendation where to > get the certificate from and how much > should I expect to pay? > > I have one domain with about 20 subdomains (the translated versions of my > articles) > and a few other domains with 1-2, sometimes even more subdomains. > > Most of them are probably considered commercial as they have ads on it and > on some of them I even have a few subscribers, but they are, unfortunately, > not a big business. Nevertheless I think this might exclude some "open > source" providers. > > I looked at http://www.cacert.org/ but as I can see the certificate they > use on their own site is not recognized by either Chrome or Firefox. That > does not seem to be a good thing. (See https://www.cacert.org/ ) > > A found plenty of companies offering SSL certificates. One of them > https://www.ssl.com/ > that was recommended by the domain registrar I am using had > $177 / year for the first 3 hostname and then $49 / year for each > additional hostname and $129/year for each wildcard domain. > > Is that a reasonable price? Any suggestions? > > regards > Gabor -- Efraim Flashner ????? ????? GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 819 bytes Desc: OpenPGP digital signature URL: From esr+linux-il at g.jct.ac.il Tue Mar 8 12:01:00 2016 From: esr+linux-il at g.jct.ac.il (E.S. Rosenberg) Date: Tue, 8 Mar 2016 12:01:00 +0200 Subject: vdsl2 router In-Reply-To: References: Message-ID: 2016-03-08 9:10 GMT+02:00 Amos Shapira : > What exact model of TP-Link have you got? > WR740N (v4.x), WR841ND (v5.x), WR1043ND (v1.x) > I have a TP-Link AC1750 ADSL2+ modem router which is great except that > OpenWRT doesn't support this specific model's WiFi well (see multiple > "Notes" in https://wiki.openwrt.org/toh/tp-link/archer-c5-c7-wdr7500) > Did you check recently? The way I understand the notes v2 is fully supported while v1.x only the 2.4GHz Band is supported (though they do write that they don't do hardware NAT which will affect you if you have a WAN line > 300MBit/s). So I'm half-heartedly on the lookout for something to run OpenWRT or VyOS > on, with 1Gb ethernet and 802.11ac WiFi and which can be used to do smart > and efficient routing especially over OpenVPN tunnels. > Let us know if you find something.... in a few month OpenWRT should be releasing 16.x (Designated Driver, if they manage to stick to the roughly yearly releases) which may bring improved support for your existing device considering how they already have half decent support there is someone (and probably more then one someone) working on it.... If you want something really powerful with a very powerful OS have a look at this: http://routerboard.com/RB962UiGS-5HacT2HnT Regards, Eliyahu - ????? > > > On 8 March 2016 at 10:07, E.S. Rosenberg wrote: > >> Personally I don't bother with the modem/router supporting OpenWRT, I >> bought a nice TP-Link router which functions as the router of my >> networks and runs OpenWRT then the provider router/bridge/whatever box >> is just used as a bridge device and nothing more. >> >> There are far less xDSL devices that support *WRT and also you never >> know if the device you'll get from your provider is under your full >> control (these days with 2/3-play packages the router tends to not be >> under your control since it also does your VoIP/TV) so as far as I am >> concerned the provider-device is 'outside' my network and should be >> treated as such.... >> >> Also the provider devices tend to have terrible firmware/updates which >> of course you want to salvage with *WRT. >> >> Regards, >> Eliyahu - ????? >> >> 2016-03-01 13:40 GMT+02:00 Rabin Yasharzadehe : >> > In my opinion , a good place to start is this list - >> > http://www.netcheif.com/Articles/VDSL_Router/VDSL_Router.htm >> > find one/two that meet your demand, and then check if they have support >> for >> > openwrt/dd-wrt >> > >> > -- >> > Rabin >> > >> > On 1 March 2016 at 12:43, sara fink wrote: >> >> >> >> Hi Everyone >> >> >> >> I would like to buy a vdsl2 router that supports openwrt or ddwrt. >> Anyone >> >> has experience with a good router? Xphone gives dlink 225 which doesn't >> >> support openwrt. >> >> >> >> _______________________________________________ >> >> Linux-il mailing list >> >> Linux-il at cs.huji.ac.il >> >> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il >> >> >> > >> > >> > _______________________________________________ >> > Linux-il mailing list >> > Linux-il at cs.huji.ac.il >> > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il >> > >> >> _______________________________________________ >> Linux-il mailing list >> Linux-il at cs.huji.ac.il >> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il >> > > > > -- > > -------------- next part -------------- An HTML attachment was scrubbed... URL: From esr+linux-il at g.jct.ac.il Tue Mar 8 12:56:30 2016 From: esr+linux-il at g.jct.ac.il (E.S. Rosenberg) Date: Tue, 8 Mar 2016 12:56:30 +0200 Subject: vdsl2 router In-Reply-To: <56DEA925.3090805@gmail.com> References: <56DEA925.3090805@gmail.com> Message-ID: 2016-03-08 12:27 GMT+02:00 geoffrey mendelson : > On 3/8/2016 12:01 PM, E.S. Rosenberg wrote: >> >> >> >> >> Let us know if you find something.... in a few month OpenWRT should be >> releasing 16.x (Designated Driver, if they manage to stick to the roughly >> yearly releases) which may bring improved support for your existing device >> considering how they already have half decent support there is someone (and >> probably more then one someone) working on it.... >> >> If you want something really powerful with a very powerful OS have a look >> at this: >> http://routerboard.com/RB962UiGS-5HacT2HnT > > That looks like what I want, but I am sure it is too much money. I am > looking for two ethernet ports (one in, one out) and enough smarts to > support GRE tunnels (such as an old cisco router, that friends in the US > recycled by the 100's), or some form of open WRT. Anything else is extra, > but not needed. It is priced similarly to the high end TP-Links and has high end specs.... RouterOS (Mikrotik) is a very powerful router OS based on Linux used in system critical applications but also available for home use. > > I think, besides finding old cisco routers in someone's junkpile (so far > unsuccessful), a home grade wifi router would be perfect. > > Anyone have a WRT-54gl they want to get rid of cheaply? If those are all your demands an ~80NIS WR740N meets you requirements fully..... (though you need to be careful the latest revision seems to only have experimental support)... If anything the WR740N is more powerful then the wrt54gl and unlike the wrt54gl can run the latest version of OpenWRT. HTH, Eliyahu - ????? > > > Geoff. > > -- > Geoffrey S. Mendelson 4X1GM/N3OWJ > Jerusalem Israel. > From shlomif at gmail.com Tue Mar 8 13:30:51 2016 From: shlomif at gmail.com (Shlomi Fish) Date: Tue, 8 Mar 2016 13:30:51 +0200 Subject: RFC: Creating an Israeli directory of Linux savvy Computer Professionals? In-Reply-To: References: Message-ID: Hi all, On Sun, Feb 14, 2016 at 12:53 PM, Shlomi Fish wrote: > Hi Amichai and everyone, > > On Sat, Feb 13, 2016 at 11:27 PM, Amichai Rotman > wrote: > >> I mentioned this list as an example for how the list *shouldn't* look... >> >> It is also well hidden. The average Joe will not be able to use it and >> will never find it... >> >> We (as a community) need to revamp the http://www.linux.org.il web site. >> In it's current state, it looks like an outdated early 90s site... >> >> Amichai Rotman >> >> > The sources for http://www.linux.org.il/ are maintained in a GitHub > repository at https://github.com/Hamakor/linux.org.il . Filing pull > requests or specific issues is welcome. If you can suggest modifications or > solicit people to do that, then they will be considered. > > Talk is cheap and complaints are easy. Actually doing something about it > is where it's at. See http://shlomif.livejournal.com/39215.html . > > I have yet to hear back from Amichai regarding my suggestions, and it's been over three weeks. Regards, -- Shlomi Fish -- ------------------------------------------ Shlomi Fish http://www.shlomifish.org/ Chuck Norris helps the gods that help themselves. Please reply to list if it's a mailing list post - http://shlom.in/reply . -------------- next part -------------- An HTML attachment was scrubbed... URL: From gabor at szabgab.com Tue Mar 8 21:33:17 2016 From: gabor at szabgab.com (Gabor Szabo) Date: Tue, 8 Mar 2016 21:33:17 +0200 Subject: OT: SSL certificates In-Reply-To: References: <20160308052434.GW2877@tarshish> Message-ID: I am trying letsencrypt.org . I just cloned their repo and started to follow their instructions, but then they say "nginx support is experimental, buggy, and not installed by default" and I am using nginx for most of my servers. I guess their nginx support will come soon and I can wait a bit though I wonder, have any of you used it on nginx? regards Gabor On Tue, Mar 8, 2016 at 8:27 AM, Michael Tewner wrote: > As far as I know, letsencrypt.org certs are only good for 90 days, and > you'll want to have a script automatically renew and replace the cert in > the background all the time. > I like https://www.namecheap.com , as it helps you find the cheapest > between different CA's. > CACert is worthy of this community's support, but as you mentioned, their > certs aren't included in any browsers or OS's. > > > > On Tue, Mar 8, 2016 at 7:24 AM, Baruch Siach wrote: > >> Hi Gabor, >> >> On Tue, Mar 08, 2016 at 07:05:03AM +0200, Gabor Szabo wrote: >> > A found plenty of companies offering SSL certificates. One of them >> > https://www.ssl.com/ >> > that was recommended by the domain registrar I am using had >> > $177 / year for the first 3 hostname and then $49 / year for each >> > additional hostname and $129/year for each wildcard domain. >> > >> > Is that a reasonable price? Any suggestions? >> >> How about https://letsencrypt.org/ free certs? >> >> baruch >> >> -- >> http://baruch.siach.name/blog/ ~. .~ Tk Open >> Systems >> >> =}------------------------------------------------ooO--U--Ooo------------{= >> - baruch at tkos.co.il - tel: +972.2.679.5364, http://www.tkos.co.il - >> >> _______________________________________________ >> Linux-il mailing list >> Linux-il at cs.huji.ac.il >> http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il >> > > -------------- next part -------------- An HTML attachment was scrubbed... URL: From linux-il at shimi.net Tue Mar 8 21:47:16 2016 From: linux-il at shimi.net (shimi) Date: Tue, 8 Mar 2016 21:47:16 +0200 Subject: OT: SSL certificates In-Reply-To: References: <20160308052434.GW2877@tarshish> Message-ID: On Tue, Mar 8, 2016 at 9:33 PM, Gabor Szabo wrote: > I am trying letsencrypt.org . > I just cloned their repo and started to follow their instructions, but > then they say "nginx support is experimental, buggy, and not installed by > default" and I am using nginx for most of my servers. I guess their nginx > support will come soon and I can wait a bit though I wonder, have any of > you used it on nginx? > > When they say 'nginx support' they mean 'automatically configuring nginx for you'. There are plenty other ways (including manual, with other clients that doesn't force you to provide them with root access to your machine) to just issue the cert from a CSR, and install the cert normally on any web server you want. See for example https://tty1.net/blog/2015/using-letsencrypt-in-manual-mode_en.html and https://github.com/diafygi/letsencrypt-nosudo HTH, -- Shimi -------------- next part -------------- An HTML attachment was scrubbed... URL: From gabor at szabgab.com Tue Mar 8 23:04:35 2016 From: gabor at szabgab.com (Gabor Szabo) Date: Tue, 8 Mar 2016 23:04:35 +0200 Subject: OT: SSL certificates In-Reply-To: References: <20160308052434.GW2877@tarshish> Message-ID: On Tue, Mar 8, 2016 at 9:47 PM, shimi wrote: > On Tue, Mar 8, 2016 at 9:33 PM, Gabor Szabo wrote: > >> I am trying letsencrypt.org . >> I just cloned their repo and started to follow their instructions, but >> then they say "nginx support is experimental, buggy, and not installed by >> default" and I am using nginx for most of my servers. I guess their nginx >> support will come soon and I can wait a bit though I wonder, have any of >> you used it on nginx? >> >> > When they say 'nginx support' they mean 'automatically configuring nginx > for you'. There are plenty other ways (including manual, with other clients > that doesn't force you to provide them with root access to your machine) to > just issue the cert from a CSR, and install the cert normally on any web > server you want. See for example > https://tty1.net/blog/2015/using-letsencrypt-in-manual-mode_en.html and > https://github.com/diafygi/letsencrypt-nosudo > Very useful links. Thanks Gabor -------------- next part -------------- An HTML attachment was scrubbed... URL: From tewner at gmail.com Thu Mar 10 08:54:33 2016 From: tewner at gmail.com (Michael Tewner) Date: Thu, 10 Mar 2016 08:54:33 +0200 Subject: [JOB] Scene53 is Looking for a Junior DevOps Engineer Message-ID: Hi Guys! Our company, Scene53, is looking for a Junior DevOps engineer. Specifically, we're looking to hire a bright, challenge-driven, Linux user to join our small team; We'll be happy to bring you up-to-speed on the world of DevOps (for various definitions of "DevOps")! Besides the standard DevOps fare, our team is responsible for all infrastructure (Production and Dev), networking, and designing and implementing new technical solutions as required. We are often involved with working with the developers to tailor solutions which are scalable, resilient, and self-healing. Scene53 is an established startup in Tel Aviv (near Nachalat Binyamin); I like to call it "A Silicon Valley Startup in Tel Aviv". We won TechCrunch Disrupt a few years back for our Virtual Bar "Shaker" and have since pivot'ed into other markets. We have a friendly and enjoyable work environment. There are dogs, and lots of 'em, so keep that in mind if you're interested in joining us! Full disclosure: Being a small start-up, our team is also responsible for all of the company's Windows-based infrastructure, including Active Directory and desktop PC's. There will be a minimal amount of helping out the other teams with PC issues, troubleshooting, and maintenance. If you have a sincere, passionate desire to learn about the world of CI/CD, NoSQL, Amazon cloud, and infrastructure, this is for you! For anyone interested, please send over a CV and a short introduction! Thank you, all! -Mike -------------- next part -------------- An HTML attachment was scrubbed... URL: From amos.shapira at gmail.com Thu Mar 10 22:01:43 2016 From: amos.shapira at gmail.com (Amos Shapira) Date: Fri, 11 Mar 2016 07:01:43 +1100 Subject: vdsl2 router In-Reply-To: References: Message-ID: On 8 March 2016 at 21:01, E.S. Rosenberg wrote: > > > 2016-03-08 9:10 GMT+02:00 Amos Shapira : > >> What exact model of TP-Link have you got? >> > WR740N (v4.x), WR841ND (v5.x), WR1043ND (v1.x) > >> I have a TP-Link AC1750 ADSL2+ modem router which is great except that >> OpenWRT doesn't support this specific model's WiFi well (see multiple >> "Notes" in https://wiki.openwrt.org/toh/tp-link/archer-c5-c7-wdr7500) >> > Did you check recently? The way I understand the notes v2 is fully > supported while v1.x only the 2.4GHz Band is supported (though they do > write that they don't do hardware NAT which will affect you if you have a > WAN line > 300MBit/s). > I've just double checked this morning - the serial label on the router says "v1.0", which means I can't take advantage of 802.11ac with OpenWRT on it :(. > > So I'm half-heartedly on the lookout for something to run OpenWRT or VyOS >> on, with 1Gb ethernet and 802.11ac WiFi and which can be used to do smart >> and efficient routing especially over OpenVPN tunnels. >> > Let us know if you find something.... in a few month OpenWRT should be > releasing 16.x (Designated Driver, if they manage to stick to the roughly > yearly releases) which may bring improved support for your existing device > considering how they already have half decent support there is someone (and > probably more then one someone) working on it.... > > If you want something really powerful with a very powerful OS have a look > at this: > http://routerboard.com/RB962UiGS-5HacT2HnT > Perhaps my top priority, after having something that's flexible enough, is hardware which won't take more than 3W to run. Thanks, --Amos -------------- next part -------------- An HTML attachment was scrubbed... URL: From erez0001 at gmail.com Wed Mar 23 09:22:06 2016 From: erez0001 at gmail.com (Erez D) Date: Wed, 23 Mar 2016 09:22:06 +0200 Subject: revisioning mysql server Message-ID: hi i have a running mysql server, and want to be able to restore it to any day, with as little backup space as needed i do mysqldump to the same file every day then commit the file with "svn ci" the idea is that if there are no changes, it takes no space it works well if i just append entries to a database, as svn will just save the changes however, if i insert a record, and for instance the dump file has 5 record at every line then the change is big and actually svn will save most of the file though there is a very small change actually. another issue - if the records hold changing info like timestamps etc. any idea ? -------------- next part -------------- An HTML attachment was scrubbed... URL: From nad.oby at gmail.com Wed Mar 23 09:39:19 2016 From: nad.oby at gmail.com (Evgeniy Ginzburg) Date: Wed, 23 Mar 2016 09:39:19 +0200 Subject: revisioning mysql server In-Reply-To: References: Message-ID: You can try to switch to BUP https://bup.github.io/ This is GIT based backup system, works fine in small scale scenarios. It works OK with big files cause of chunk deduplication. On Wed, Mar 23, 2016 at 9:22 AM, Erez D wrote: > hi > > i have a running mysql server, and want to be able to restore it to any > day, with as little backup space as needed > > i do mysqldump to the same file every day then commit the file with "svn > ci" > the idea is that if there are no changes, it takes no space > > it works well if i just append entries to a database, as svn will just > save the changes > > however, if i insert a record, and for instance the dump file has 5 record > at every line > then the change is big and actually svn will save most of the file though > there is a very small change actually. > > another issue - if the records hold changing info like timestamps etc. > > any idea ? > > > > > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > > -- So long, and thanks for all the fish. -------------- next part -------------- An HTML attachment was scrubbed... URL: From efraim at flashner.co.il Wed Mar 23 09:56:07 2016 From: efraim at flashner.co.il (Efraim Flashner) Date: Wed, 23 Mar 2016 09:56:07 +0200 Subject: revisioning mysql server In-Reply-To: References: Message-ID: <20160323095607.7bb0d0b5@debian-netbook> On Wed, 23 Mar 2016 09:22:06 +0200 Erez D wrote: > hi > > i have a running mysql server, and want to be able to restore it to any > day, with as little backup space as needed > > i do mysqldump to the same file every day then commit the file with "svn ci" > the idea is that if there are no changes, it takes no space > > it works well if i just append entries to a database, as svn will just save > the changes > > however, if i insert a record, and for instance the dump file has 5 record > at every line > then the change is big and actually svn will save most of the file though > there is a very small change actually. > > another issue - if the records hold changing info like timestamps etc. > > any idea ? Is there a program like mysql-diff that will compare two dumps and spit out a diff file? Or is it possible to copy the incoming commands to the database and write them to a separate file and back that up with a weekly snapshot of the database? -- Efraim Flashner ????? ????? GPG key = A28B F40C 3E55 1372 662D 14F7 41AA E7DC CA3D 8351 Confidentiality cannot be guaranteed on emails sent or received unencrypted -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 819 bytes Desc: OpenPGP digital signature URL: From dotan at shavitos.com Wed Mar 23 12:22:50 2016 From: dotan at shavitos.com (=?UTF-8?Q?=D7=93=D7=95=D7=AA=D7=9F_=D7=A9=D7=91=D7=99=D7=98?=) Date: Wed, 23 Mar 2016 12:22:50 +0200 Subject: revisioning mysql server In-Reply-To: References: Message-ID: check mysqlbinlog # :??? Erez D, 2016-03-23 09:22 ?????? > hi > > i have a running mysql server, and want to be able to restore it to any day, with as little backup space as needed > > i do mysqldump to the same file every day then commit the file with "svn ci" the idea is that if there are no changes, it takes no space > > it works well if i just append entries to a database, as svn will just save the changes > however, if i insert a record, and for instance the dump file has 5 record at every line then the change is big and actually svn will save most of the file though there is a very small change actually. > > another issue - if the records hold changing info like timestamps etc. > > any idea ? > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il -------------- next part -------------- An HTML attachment was scrubbed... URL: From linux-il at shimi.net Wed Mar 23 12:53:16 2016 From: linux-il at shimi.net (shimi) Date: Wed, 23 Mar 2016 12:53:16 +0200 Subject: revisioning mysql server In-Reply-To: References: Message-ID: On Wed, Mar 23, 2016 at 9:22 AM, Erez D wrote: > hi > > i have a running mysql server, and want to be able to restore it to any > day, with as little backup space as needed > > i do mysqldump to the same file every day then commit the file with "svn > ci" > the idea is that if there are no changes, it takes no space > > it works well if i just append entries to a database, as svn will just > save the changes > > however, if i insert a record, and for instance the dump file has 5 record > at every line > then the change is big and actually svn will save most of the file though > there is a very small change actually. > > another issue - if the records hold changing info like timestamps etc. > > any idea ? > > What about xdelta[1] and saving the .xdelta files ? (from last copy or original copy - your choice, but the cost of choosing the former to save space would be that you'll have to roll the opposite operation in sequence for any recovery) -- Shimi [1] http://xdelta.org/ -------------- next part -------------- An HTML attachment was scrubbed... URL: From shlomif at gmail.com Wed Mar 23 13:25:37 2016 From: shlomif at gmail.com (Shlomi Fish) Date: Wed, 23 Mar 2016 13:25:37 +0200 Subject: revisioning mysql server In-Reply-To: References: Message-ID: Hi Shimi and Erez, On Wed, Mar 23, 2016 at 12:53 PM, shimi wrote: > > > On Wed, Mar 23, 2016 at 9:22 AM, Erez D wrote: > >> hi >> >> i have a running mysql server, and want to be able to restore it to any >> day, with as little backup space as needed >> >> i do mysqldump to the same file every day then commit the file with "svn >> ci" >> the idea is that if there are no changes, it takes no space >> >> it works well if i just append entries to a database, as svn will just >> save the changes >> >> however, if i insert a record, and for instance the dump file has 5 >> record at every line >> then the change is big and actually svn will save most of the file though >> there is a very small change actually. >> >> another issue - if the records hold changing info like timestamps etc. >> >> any idea ? >> >> > What about xdelta[1] and saving the .xdelta files ? (from last copy or > original copy - your choice, but the cost of choosing the former to save > space would be that you'll have to roll the opposite operation in sequence > for any recovery) > > Subversion already uses xdelta (or its alternative vdelta) internally for keeping track of binary diffs, so this will likely not buy you much (and add a lot of complexity to the process). I believe git and mercurial/hg can handle binary diffs well in a similar manner. As a result, one cannot rely on the textual "diff -u" output to accurately indicate the change size (e.g: changing one byte in a line of thousands of bytes will yield a thousands-bytes diff -u , but be a very small binary change). Regards, ? Shlomi Fish > -- Shimi > > [1] http://xdelta.org/ > > _______________________________________________ > Linux-il mailing list > Linux-il at cs.huji.ac.il > http://mailman.cs.huji.ac.il/mailman/listinfo/linux-il > > -- ------------------------------------------ Shlomi Fish http://www.shlomifish.org/ Chuck Norris helps the gods that help themselves. Please reply to list if it's a mailing list post - http://shlom.in/reply . -------------- next part -------------- An HTML attachment was scrubbed... URL: From shlomif at gmail.com Wed Mar 30 14:49:48 2016 From: shlomif at gmail.com (Shlomi Fish) Date: Wed, 30 Mar 2016 14:49:48 +0300 Subject: Can someone chat with me in mixed Hebrew/Latin using Pidgin over XMPP/Jabber? Message-ID: Hi all! I'm trying to comply with this comment on this bug report in the pidgin facebook plugin that I opened: https://github.com/jgeboski/purple-facebook/issues/233 I was told to check whether Mixed HEbrew/Latin is displayed correctly over XMPP/Jabber. I need someone who: 1. Can type in Hebrew and Latin/English. 2. Uses Pidgin versioon 2.10.x 3. Can talk with me at my ShlomiFish at jabber.org account (and that excludes GMail/GTalk/GChat/GoogleHangouts which only support a client-side XMPP bridge). Best regards, -- Shlomi Fish -- ------------------------------------------ Shlomi Fish http://www.shlomifish.org/ Chuck Norris helps the gods that help themselves. Please reply to list if it's a mailing list post - http://shlom.in/reply . -------------- next part -------------- An HTML attachment was scrubbed... URL: From shlomif at gmail.com Wed Mar 30 20:10:09 2016 From: shlomif at gmail.com (Shlomi Fish) Date: Wed, 30 Mar 2016 20:10:09 +0300 Subject: Can someone chat with me in mixed Hebrew/Latin using Pidgin over XMPP/Jabber? In-Reply-To: References: Message-ID: Hi all, two people have already complied with my request and we verified that the problem does not happen with the XMPP protocl, so no further assistance is required. Thanks! Regards, -- Shlomi Fish On Wed, Mar 30, 2016 at 2:49 PM, Shlomi Fish wrote: > Hi all! > > I'm trying to comply with this comment on this bug report in the pidgin > facebook plugin that I opened: > > https://github.com/jgeboski/purple-facebook/issues/233 > > I was told to check whether Mixed HEbrew/Latin is displayed correctly over > XMPP/Jabber. > > I need someone who: > > 1. Can type in Hebrew and Latin/English. > > 2. Uses Pidgin versioon 2.10.x > > 3. Can talk with me at my ShlomiFish at jabber.org account (and that > excludes GMail/GTalk/GChat/GoogleHangouts which only support a client-side > XMPP bridge). > > Best regards, > > -- Shlomi Fish > > -- > ------------------------------------------ > Shlomi Fish http://www.shlomifish.org/ > > Chuck Norris helps the gods that help themselves. > > Please reply to list if it's a mailing list post - http://shlom.in/reply . > -- ------------------------------------------ Shlomi Fish http://www.shlomifish.org/ Chuck Norris helps the gods that help themselves. Please reply to list if it's a mailing list post - http://shlom.in/reply . -------------- next part -------------- An HTML attachment was scrubbed... URL: From shlomif at gmail.com Thu Mar 31 22:56:28 2016 From: shlomif at gmail.com (Shlomi Fish) Date: Thu, 31 Mar 2016 22:56:28 +0300 Subject: [ANN] Understanding Vim's excalamation mark command quoting/escaping rules Message-ID: Hi all! I prepared a document where I investigated which characters need to be escaped in vim's ":!" commands of filtering the text through a shell command. It can be found here: https://github.com/shlomif/vim-begin/tree/master/understanding-exclamation-mark-shell-exec--escaping-rules (short URL: http://is.gd/wA8Yie ) Executive summary: - ?%?, ?#?, and ?!? should be escaped with a backslash (?\?). - All other punctuation/special characters (including a backslash) need not and should not be escaped. Enjoy! Regards, -- Shlomi Fish -- ------------------------------------------ Shlomi Fish http://www.shlomifish.org/ Chuck Norris helps the gods that help themselves. Please reply to list if it's a mailing list post - http://shlom.in/reply . -------------- next part -------------- An HTML attachment was scrubbed... URL: