Planet Binder

September 02, 2010

FriendFeed

Josh Neff, Man of Mystery: Darth Vader's interrogation of Princess Leia in the Star Wars radio drama is really damn scary! #starwars

Josh Neff, Man of Mystery
Darth Vader's interrogation of Princess Leia in the Star Wars radio drama is really damn scary! #starwars
Aden, Dan: From Space and CW™ liked this
I know! Especially that part when he whipped out his... wait, no. I'm thinking about a fan fic. - Dan: From Space

September 02, 2010 03:33 PM

Josh Neff, Man of Mystery: Dear Thursday, Tuesday sucked & yesterday was no picnic either. Let's pick things up some, OK? Love, me.

Josh Neff, Man of Mystery
Dear Thursday, Tuesday sucked & yesterday was no picnic either. Let's pick things up some, OK? Love, me.
yes, show us some love, thursday!!!! - αnnα vαȵ scoyoç

September 02, 2010 11:41 AM

September 01, 2010

FriendFeed

Halil: I'm curious, how many languages can you speak? Can be either fluently or badly, but if badly, I don't mean unintelligible!

Halil
I'm curious, how many languages can you speak? Can be either fluently or badly, but if badly, I don't mean unintelligible!
Solveigh Calderin, Katie: The Hippie of FF, Roberto Bonini and 11 other people liked this
I can speak 2, English and Turkish! My French is awful, so not including that. :) - Halil
Does Klingon, Tamarian, and Jawa count? - Fleagle
erm...only if you can find someone to have a chat with! :-P - Halil

September 01, 2010 03:41 PM

August 31, 2010

Manjusri Blog

Shrew Soft Client Under Ubuntu 10.04

This may not help you. But this is what I did to get it working against our OpenBSD isakmpd VPN server. If you’re not using precisely the same configuration we are, this is going to be dead wrong. If you are using ‘Mutual RSA’ authentication, this might be suitable.

We have a nice CGI at work which takes your client hostname and spits out a zip file containing the SSL certs needed, the VPN.VPN site configuration file for a ShrewSoft client and some helper batch scripts. So that all works for Windows. Assuming that you’ve got all those pieces or the local equivalent, and you got Shrew Soft working from Windows, these are the frobs to turn for doing this on Ubuntu 10.04.

Here’s the catch for doing this on Ubuntu 10.04. You can’t do it with the packaged Shrew Soft client (packages named ike*) because that version doesn’t support the PolicyGeneration option you need to set. So uninstall any that you have installed.

Then go grab version 2.1.6-release or newer (depending upon degree of daring) from

http://www.shrew.net/download/ike

Compile it. This will require you to install the cmake, build-essential, flex, bison and libssl-dev packages. Maybe some others, but those are the big ones. The README.TXT in the ike source is helpful.

Import your VPN.VPN configuration.

Copy the contents of certs into ~/.ike/certs so the agent can find them.

Start  ‘iked’ by running it with sudo. Add the -F switch if you want to keep it foregrounded. (Until you’ve got it working, you want to keep it foregrounded.)

Start ‘ikea’. Edit your imported connection. Make these configuration changes:

  • Name Resolution tab: uncheck Obtain Automatically, add a DNS server/suffix. There’s possibly something wrong with the  handling of DHCP, this should just work. I set a single DNS server and search domain explicitly and that worked well enough.
  • Authentication tab, Remote Identity subtab: change Identification type to Fully Qualified Domain Name, FQDN String is whatever your VPN endpoint thinks its name is. This was ipv4-address in my configuration, the iked log output helped me fix this one. If you see messages from iked about it getting fqdn when it wanted ipv4 or vice-versa, this tab is where you fix expectations.
  • Policy Tab, Policy Generation: shared. This is the connection option which was key and before 2.1.6, unavailable. The docs say this allows it to emulate some kind of wacky Cisco mode. I guess that’s what we need.

You may need to pound on various rp_filter sysctls but I’m not convinced that did anything in my case. If you packet capture and see reply traffic coming to you but never seeming to be received by your running clients, it may well be you need to set some rp_filter sysctl or other to 0.

by binder at August 31, 2010 04:05 PM

August 30, 2010

FriendFeed

Picture 1.png 1

sofarsoShawn
relapsed...my cancer (AML Leukemia) came back (why I was MIA) ugh... well could be worse...just finished going through the most INTENSIVE chemotherapy yet ~ awwfuulll ~ but I MADE IT :D now I'm set to do a Bone Marrow Transplant: Admission Sept 7 the operation the 15th. My family's distraught & I'm terrified, but i'm all right ~ being positive :)
SOFARSOSHAWNBALD.jpg Picture 1.png
Jessie, Yasin, cemreakkartal and 139 other people liked this
so Pic 1 thatès me BALD!!! # 2 thatès me with my favourite toque (beanie) my mom gave me :D - sofarsoShawn
Uh Ohz, hate to break it to you Louis but the hats are coming!!! Momo's doing :) - sofarsoShawn
Be strong, and good luck Shawn! - ciw

August 30, 2010 08:16 PM

Marissa: Tell me about your day so far:

Marissa
Marissa (Josh Neff, Man of Mystery commented on this)
Tell me about your day so far:
I'm rocking a sinus headache I can't shake & I'm kind of bored at work, but overall I'm happy & having a good day. - Josh Neff, Man of Mystery
If you thought Monday was something, you should have seen Tuesday! - RAPatton
Well got a book idea with a co-author to go along with that about how the IT Industry eats its young - set up a trip to baltimore for the end of october - figured out a way I could go 1/2 time at work and not lose much money so I can still pay bills - worked on a couple of courses - hooked up my new employee with the same trip to baltimore (hey he wanted to travel) - went to lunch and had sushi - about the usual day. - Dan likes this so does

August 30, 2010 06:50 PM

August 27, 2010

Manjusri Blog Comments

Comment on What Have You Done Lately? by jess

I think you can cross “Not blogged” off the list now.

by jess at August 27, 2010 02:59 PM

Manjusri Blog

What Have You Done Lately?

Not blogged, not read novels, not taken pictures, not slept, not baked.

But I did convert two teams from subversion to mercurial.

Oh, and we’re buying a house.

by binder at August 27, 2010 05:13 AM