Page MenuHomeVyOS Platform

lucasec (Lucas Christian)
User

Projects

User does not belong to any projects.

User Details

User Since
Apr 2 2019, 2:39 AM (128 w, 6 d)

Recent Activity

Sun, Sep 19

lucasec added a comment to T3840: dns forwarding: Cache size should allow values > 10k.

Pull request: https://github.com/vyos/vyos-1x/pull/1010

Sun, Sep 19, 4:50 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec changed Difficulty level from unknown to easy on T3840: dns forwarding: Cache size should allow values > 10k.
Sun, Sep 19, 4:29 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec claimed T3840: dns forwarding: Cache size should allow values > 10k.
Sun, Sep 19, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta
lucasec created T3840: dns forwarding: Cache size should allow values > 10k.
Sun, Sep 19, 4:21 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Fri, Sep 17

lucasec added a comment to T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.

Tested on latest build VyOS 1.4-rolling-202109160217 and confirmed it is adding the remote id attribute by default as expected. Connections establish without issue.

Fri, Sep 17, 4:02 AM · VyOS 1.4 Sagitta

Wed, Sep 15

lucasec assigned T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified to c-po.
Wed, Sep 15, 5:57 AM · VyOS 1.4 Sagitta
lucasec created T3830: ipsec: remote-id no longer included in IKE AUTH if not explicitly specified.
Wed, Sep 15, 5:57 AM · VyOS 1.4 Sagitta

Tue, Sep 14

lucasec added a comment to T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.

Booted my host with 1.4-rolling-202109140217 and confirmed pfs enabled is now generating the expected swanctl.conf file to match the old behavior. If I don't report back in exactly an hour from now that my tunnels died, we can assume the fix works.

Tue, Sep 14, 5:03 AM · VyOS 1.4 Sagitta

Mon, Sep 13

lucasec assigned T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta to c-po.
Mon, Sep 13, 7:20 AM · VyOS 1.4 Sagitta
lucasec created T3828: ipsec: Subtle change in "pfs enable" behavior from equuleus -> sagitta.
Mon, Sep 13, 7:20 AM · VyOS 1.4 Sagitta
lucasec added a comment to T3827: interfaces migration script fails on AWS hosts.

Note: config versions were added to the default configs here https://github.com/vyos/vyos-build/commit/23639568a945f19471af88547dab45b87bbd642d, but the current vyos-build-ami replaces the default file with its own that hasn't been modified to add the versioning comment yet. That can probably be fixed whenever that repo is updated for equuleus (I have my own patched local branch that I could publish if desired).

Mon, Sep 13, 12:44 AM · VyOS 1.3 Equuleus
lucasec updated subscribers of T3827: interfaces migration script fails on AWS hosts.

cc: @c-po maybe this was a side effect of unifying the two parsers

Mon, Sep 13, 12:20 AM · VyOS 1.3 Equuleus
lucasec created T3827: interfaces migration script fails on AWS hosts.
Mon, Sep 13, 12:16 AM · VyOS 1.3 Equuleus

Sat, Sep 11

lucasec added a comment to T3805: OpenVPN insufficient privileges for rtnetlink when closing TUN/TAP interface.

FYI, if your OpenVPN config relies on cert files or anything you uploaded into the config directory, you may need to change the owner to the openvpn user or widen file permissions. Oddly this only seems to affect equuleus, not sagitta (OpenVPN seems fine reading files owned by "root" out of "/config/auth").

Sat, Sep 11, 8:58 AM · VyOS 1.3 Equuleus (1.3.0-epa1), VyOS 1.4 Sagitta

Nov 14 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

Your revert appears to do the trick. Image booted fine with QAT enabled, and "show system acceleration qat status" shows the QAT device came up fine and is running happily.

Nov 14 2020, 6:21 AM · VyOS 1.3 Equuleus

Nov 12 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

Sure—if you want to drop me an image I can try it out. I do have a working vyos-build as well, I can also try and produce my own with that change backed out when I get some time towards the end of the week.

Nov 12 2020, 4:23 AM · VyOS 1.3 Equuleus

Nov 10 2020

lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

I will perform a few additional tests tomorrow with the oldest available rolling releases (looks like October 13th as of writing). Will see if I can binary search my way to when things broke.

Nov 10 2020, 7:27 AM · VyOS 1.3 Equuleus
lucasec updated the task description for T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.
Nov 10 2020, 7:22 AM · VyOS 1.3 Equuleus
lucasec added a comment to T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.

A few updates... the failure still occurs on latest rolling. Similar outcome—the kernel panics and dumps a stacktrace during the initial boot-up configure process. However, this issue goes back further than I expected (and initially expressed in the ticket). I goofed up in my testing of 1.3-rolling-202010260327 by booting with a default config file without the QAT option.

Nov 10 2020, 7:21 AM · VyOS 1.3 Equuleus

Nov 3 2020

lucasec created T3041: Intel QAT: vyos-1.3-rolling-202011020217-amd64 kernel panic during configure.
Nov 3 2020, 5:11 AM · VyOS 1.3 Equuleus

Oct 27 2020

lucasec closed T2961: Support "stateless" DHCP-v6 (information-request) clients as Resolved.
Oct 27 2020, 7:01 PM
lucasec closed T2964: pdns_recursor should support explicitly configuring query source address as Resolved.
Oct 27 2020, 7:01 PM

Oct 6 2020

lucasec added a comment to T2964: pdns_recursor should support explicitly configuring query source address.

Pull request https://github.com/vyos/vyos-1x/pull/563

Oct 6 2020, 2:14 AM
lucasec created T2964: pdns_recursor should support explicitly configuring query source address.
Oct 6 2020, 1:54 AM

Oct 4 2020

lucasec added a comment to T2961: Support "stateless" DHCP-v6 (information-request) clients.

Pull request: https://github.com/vyos/vyos-1x/pull/562

Oct 4 2020, 10:59 PM
lucasec created T2961: Support "stateless" DHCP-v6 (information-request) clients.
Oct 4 2020, 10:48 PM