Sun flubs another SSH patch
I haven't been involved with Solaris 9 for a while now, so I have no ideaif they've fixed the Solaris 9 SSH patch problem bynow (although I certainly hope they have). But I was recently heartenedto discover that Sun is perfectly capable of fumbling Solaris 10 SSHpatches as well.
Sun recently released patch 126134-03, 'sshd patch',for Solaris 10 x86, in order to fix CVE-2008
A simple request for vendor websites
Dear vendor websites, I have a simple request for you, or morespecifically for your search people: there should be a search box whereI can plug in either a product name or a part number, and the firstthing that comes up should be that product's or part's webpage. Thisshould work even for parts that you don't normally sell separately, andit definitely should work for the product codes that you put on yourboxes. In specific, I should be able to take a
Why people persist in sending files by email
One of the things that annoys (some) sysadmins is users exchanging filesover the email system, often for good technical reasons, and over theyears a lot of people have devoted a lot of effort to trying to persuadeusers to switch to various other mechanisms.
It's not going to happen. (Well, you knew that already if you've been paying attention .)
People keep exchanging files over email because email remains the mostvisibly secure and convenient way of doing so, especially to naiveusers.
Why DNS blocklists return information as IP addresses
Especially in light of the difficulties that they present in returningmultiple bits of information , you might sensibly askwhy DNS blocklists opt to return information as IP addresses, instead ofsomething more flexible. A related question is why DNSBLs are queriedin such an odd way, by reversing the octets of the host address you'reinterested in.
The IP address thing is simple: everyone has has gethostbyname() orits equivalent in their standard library. Especially if you just wanta yes or no answer (and that'
The cost of virtualization
Virtualization is in the air around here, partly as a way of beingenvironmentally friendly; fewer physical machines means less power andheating and so on. Now, I'd like to be environmentally friendly, but oneof the issues with virtualization is that getting into it for anythingimportant has significant startup costs.
One of the reasons we run different services on different machines tostart with is for fault isolation, so we don't have all of our eggsin one basket. Virtualization reverses that; if you lose
The problem with ZFS, SANs, and failover
The fundamental problem with Solaris 10's current version of ZFS in aSAN failover environment is that it has no concept of locking or hostownership of ZFS pools; instead, ZFS pools are either active (imported)or inactive (exported). So, if a host crashes and you want to failover its ZFS pools, the pools are still marked as active, which meansyou must force pool import, which has catastrophic consequences if something ever goes wrong.
But it gets worse. Because hosts don'
Tabs versus windows, or why I usually want windows
Tabs versus windows is one of those eternal debates (well, now thatwe can have the debate at all). For a long time I was strongly on thewindow side, to the point where I didn't use tabs in Firefox at all, butI've recently relented a bit on my dislike.
For me, the core difference between the two is that windows can overlap,can be moved independently, and can be organized freely (in twodimensions). Tabs are inherently non-overlapping,
Designing a usable DNS Blocklist result format
It's relatively common for DNS blocklists to want to encode a certainamount of information in their results, ranging from the source of theinformation to how reliable they consider the results. For sensiblereasons, DNS blocklists have to encode this information in the IPaddress or addresses that they return.
As it turns out, there is a useful way and a not so useful way to encodethis information, because of the limitations of mailer support for DNSBLlookups. Most mailers can ask only two questions: 'is this
Mirrored system disks should be trivial to set up
I have a simple request for people putting together installers formodern systems, especially systems generally aimed at servers: it shouldbe dirt simple to do an install with mirrored system disks .
With most modern servers having two drive bays (often hotswap ones) anddisk space being so cheap, going to mirrored system disks make a lotof sense. But most people won't move to this configuration until it issomewhere between easy and trivial to set up, much like many people didnot move to LVM-based system
Recovering my Eee PC from a post-update problem
I recently applied a bunch of pending Eee updatesfrom Asus, and suddenly the full desktop mode that I prefer stoppedworking. The Eee always booted into the basic interface, and when Iswitched back to advanced mode everything in my Desktop directory haddisappeared (which is bad, because I have some customized launchersthere)
(Fortunately I had an off-machine backup of my Desktop directory so I couldrestore my customizations.)
I enabled advanced desktop mode the easy way , namely by installing the advanced-desktop-eeepc