{"version":"https://jsonfeed.org/version/1","title":"Stéphane HUC :: IT Log","home_page_url":"https://doc.huc.fr.eu.org","feed_url":"https://doc.huc.fr.eu.org/en/feed.json","description":"Documentations for SysAdmin, Network by Stéphane HUC","author":{"avatar":"/svg/Logo_final.svg","name":"Stéphane HUC","url":"https://doc.huc.fr.eu.org"},"icon":"/svg/Logo_final.svg","favicon":"/img/favicon.ico","items":[{"id":"tag:doc.huc.fr.eu.org,2026-06-22:/en/post/linux-elite-dangerous/#60fe04b72f5df9a9bd62a6fb46a117a57be972494eedf50ce02ac7ba84f67911","url":"https://it-log.fr.eu.org/en/post/linux-elite-dangerous/","title":"(Linux) Elite Dangerous: complementary tools","author":{"name":"Stéphane HUC"},"content_text":"Description Environment : Steam / Debian Sid / Xfce Game : Elite Dangerous ; DLC : Odyssey Compatibility : no specific Steam Play compatibility tool o7, CMDR: The game is functional without particular worries…\nConfiguration Installation folder of the game : steam/steamapps/common/Elite Dangerous/; this one is easily found in Steam, click D on the game, then “Properties”; menu “Installed files”; then click on the [ Browse… ] button that will open the directory in question.\nPath to the Binary EliteDangerous64.exe: steam/steamapps/common/Elite Dangerous/Products/elite-dangerous-odyssey-64/\nPath of the “windows” data of the game: steam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Frontier Developments/Elite Dangerous/\nGame backup folder: steam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/Saved Games/Frontier Developments/Elite Dangerous/\nKeybinding Setting up keyboard key management is not a part of the fun.\nYou must create a directory called “Bindings” in the subdirectory “Options” of the “windows” data folder of the game, such as: steam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Frontier Developments/Elite Dangerous/Options/Bindings/.\n⇒ Profiles are available mainly on EDRefCard.\nHere is my version : Custom.4.2.binds ; remove the extension .txt ;)\nRelaunch the game and change the profile in the Game Options \u0026gt; Controls; then choose to change the presets. Steam desktop shortcut It’s possible that Steam created a game desktop launcher; but in fact, it won’t work.\nRight-click on the launcher to “Edit Launcher” and then in the “Order” field, fill in the absolute path to the Steam executable, such as (under Debian): /usr/games/steam steam://…\nTo find out where the absolute path to the Steam binary is, in a console, run the following command: :$ command -v steam\nThis modification being made, the desktop launcher will indeed launch the game.\nDesktop Authorizations You must allow the file to be executed as a .desktop file.\nIf at the first launch, you refused, it does not matter; right click on the launcher:\nchoose “Properties…”,\nclick on the “Launcher” tab and in the “Security” section, click on the checkboxes in front:\nAllow this file to be run as a .desktop file Set this file as approved Tools All of the tools below run on Linux, with some configurations.\nIt is not, however, that it is necessary to install them all; in any case, ensure that only a single tool that collects them datas, (Inara, EDSM, etc.), such as EDMarketConnector or EDDiscovery for example.\nFor some, the use of the tool protontricks will be necessary; fortunately in many distributions, including Debian, it is provided as a package; install it!\nEDHM-UI EDHM-UI v3 is a tool to modify the graphical interface.\nOfficial website: https://bluemystical.github.io/edhm-api/ Git: https://github.com/BlueMystical/EDHM_UI Used version: 3.0.67, 3.0.70 Once installed :\nConfiguration files : $HOME/.local/share/EDHM-UI-V3/ In the repository, you have to go to the Release page and download:\nthe archive edhm-ui-v3-linux-x64.zip the shell script linux_installer.sh Once the archive is downloaded, unzip it and copy into the install script. Give the script execution rights and run it.\nThe tool is accessible from the system menu; with Xfce, in the “Accessories” menu.\nBy default, the tool seeks to communicate with the game for the correct setting; it is necessary to restore the absolute path of the directory “elite-dangerous-odyssey-64”; if you missed something in the step, choose the menu “Main menu” \u0026gt; “Settings”.\nEDMarketConnector EDMarketConnector is a python tool to “improve” trade in Elite Dangerous, mainly, although it is able to use secondary features through plugins.\nTwo versions exist: one via flatpak, and the other through the sources into the Git repository.\nGit: https://github.com/EDCD/EDMarketConnector\nUsed version: 6.1.2\nConfiguration files:\nvia flatpak: $HOME/.var/app/io.edcd.EDMarketConnector/ via git: $HOME/.local/share/EDMarketConnector/ The main configuration file: config.toml.\n⇒ Installation from the sources is done quite easily:\n:$ git clone https://github.com/EDCD/EDMarketConnector.git :$ cd EDMarketConnector EDMarketConnector :$ python3 -m venv venv EDMarketConnector :$ source venv/bin/activate EDMarketConnector :$ pip3 install -r requirements.txt EDMarketConnector :$ python3 EDMarketConnector.py Since the tool must be launched in a python environment, I created a shell launcher:\n#!/bin/bash dir=\u0026#34;~/Games/EDMarketConnector/\u0026#34; cd \u0026#34;${dir}\u0026#34; source venv/bin/activate python3 EDMarketConnector.py Then a desktop launcher that points to the shell script, while setting the icon with the icon of the tool at the root. (Choose “Files images”). If the icon is not in the archive, you will find it in the repository.\nThe functional plugins—which I use… : ⇒ cargo-manifest: it seems necessary to change the name of the main directory; from cargo-manifest to cargo_manifest. With this slight modification, the plugin is functional!\n⇒ docking-denied-raison\n⇒ EDMC-Bioscan requires ExploData which requires sqlalchemy.\nIf you are using the flatpak version of EDMC, download the named version ExploData-***-db-***-flatpak.zip; Because it embarks sqlalchemy. If you are using the sources, you will need to install python3-slqalchemy in the dedicated python3 environment! ⇒ EDMCHotKeys\n⇒ EDMCModerOverlay\n⇒ EDMC-NavRoute\n⇒ EDMC-NeutronDancer\n⇒ EDMC-Pioneer\n⇒ EDMC-Screenshot-Linux\n⇒ UpdateTD\nOther plugins exist; they should work…\nEDDiscovery EDDiscovery is a complete dashboard to manage all the aspects that the game offers.\nGit: https://github.com/EDDiscovery/EDDiscovery/\nUsed version: 19.1.9.0\nSteam:\nforced compatibility option: Proton 9.0-4 launch option: none From the ‘Release’ page of the repository, download the Portable zip archive; unzip it wherever you want.\nIn Steam:\nclick on the “Games” menu \u0026gt; “Add a game name Steam to my library…”, choose the binary EDDiscovery.exe which is in the decompressed archive. right-click for the “game” properties, and force compatibility – currently, I’m using the “Proton 9.0-4” version. right click again for the “Manage” menu \u0026gt; “Create a shortcut on desktop”. All the remarks made in the Steam desktop shortcut chapter are to be made!\nOnce EDD is opened, go to the “Settings” tab:\nIn the “Settings” section, click the [ Add ] button, a new window will open called “CommanderForm”. In the “Journal Related Information” section: Write the name of your Commander, in the “Commander Name” field click on the [ Browse ] button to select the game backup directory. make any other desired configuration click on the [ OK ] button to validate the configuration. delete the profile named “Jameson (Default)”. Return to the “History” tab, you will find the feedback related to the commander used in the game.\nTo be able to set the icons, and the desktop launcher, and in the Steam app, you need to unzip the archive eddwebsite.zip, located at the root of the Portable archive. The image to be used mainly is in the subdirectory “Images” and is called “EdLogo600.png”.\nNote: Some plugins, such as those to display Inara, EDSM sites do not work because it lacks a tool called WebView2.\nElite Dangerous Monitor Daemon Elite Dangerous Monitor Daemon alias EDMD is another complete dashboard to monitor in real time the game session, made for Linux natively (GTK4 interface).\nGit: https://github.com/Maldor/EDMD Once installed :\nConfiguration file: $HOME/.config/EDMD/config.toml ED Odyssey Materials Helper Elite Dangerous Odyssey Materials Helper is the tool that revolutionizes the acquisition of the necessary materials in the relations with engineers. It shows you what you have, what you miss, the relationship with such an engineer, and much more…\nwebsite: https://edomh.nl/ Git: https://github.com/jixxed/ed-odyssey-materials-helper/ Discord: https://discord.gg/M8Rgz4AmmA Used version: 3.13.8, 3.13.12 From the ‘Release’ page, download at least the zip archive, but prefers the autoupdater .deb, .rpm package.\nFrom the binary, everything is installed in the system where it is necessary and becomes accessible from the system menu; under Xfce, menu “Other” \u0026gt; “Elite Dangerous Odyssey Materials Helper”.\nOnce the application is open:\nClick on the “Settings” menu on “Folder Journal” line, click on the [ Select Directory ] button and choose the absolute path related to the game’s backup directory. Then, do all the other configurations, such as the language, and then use the tool.\nMin ED Launcher Min ED Launcher is not a tool. It replaces the official launcher, while being very light, which is convenient under Linux, and has other practical aspects, including third-party tool execution, such as SRVSurvey.\nGit: https://github.com/Rfvgyhn/min-ed-launcher/\nUsed version: 0.13.0\nSteam:\nforced compatibility option : none launch option : yes; read the explanations below. Once installed:\nConfiguration file: $HOME/.config/min-ed-launcher/settings.json log: $HOME/.local/state/min-ed-launcher/min-ed-launcher.log From the ‘Release’ page, download the zip archive for Linux, and then unzip it.\nCopy the binary MinEdLauncher into the ED\u0026rsquo;s installation folder. ⇒ In Steam:\nRight-click to open the game properties in the launch options, write at least: for Gnome—run too into Xfce4!: gnome-terminal -- ./MinEdLauncher %command% /autorun /autoquit what works for me: gnome-terminal --hide-menubar -t \u0026quot;Min ED Launcher\u0026quot; -- ./MinEdLauncher %command% /autorun /autoquit waitForExit for Xfce4: xfce4-terminal --disable-server -x ./MinEdLauncher %command% /autorun /autoquit waitForExit what I\u0026rsquo;m using: xfce4-terminal --disable-server --hide-menubar --hide-scrollbar --hide-toolbar -T \u0026quot;Min ED Launcher\u0026quot; -x ./MinEdLauncher %command% /autorun /autoquit waitForExit (It is possible to use other terminals in the launch options; please read the information on the repository!).\n⇒ The archive provided a desktop launcher and icon. It is possible to copy the desktop launcher to your desktop. Then right-click to change the command, such as: /usr/games/steam steam://rungameid/359320 /edo This will run the launch of the Odyssey version of the game directly.\n⇒ All the remarks made in the Steam desktop shortcut chapter are to be made!\n⇒ It is imperative that the launch options are written in the general properties of the game; cf above!\nNote:\nIt is important that the two layers IPv4 AND IPv6 networks are functional, otherwise it will not work. OD Explorer OD Explorer is truly THE companion to Elite Dangerous, to help us in exploration and exobiology research.\nNote: This tool is designed to work well with the English language of the game Elite Dangerous, in the other languages of the game, it will not be able to bring everything up properly. But if you understand the English language well enough: “go!”\nGit: https://github.com/WarmedxMints/OD-Explorer\nUsed version: 2.0.14, 2.0.15\nSteam:\nforced compatibility option: Proton 9.0-4 launch options: none The Logo is available from the repository in the subdirectory Resources/ and is named Astronaut.png.\nFrom the ‘Release’ page of the repository, download the ODExplorer-Portable.zip version.\nUnwind it, for example, in such a way that you have it: ~/Games/ODExplorer-Portable\nThen you have to use the protontricks tool.\nThat being done, in Steam:\nClick on the “Games” menu \u0026gt; “Add a game name Steam to my library…”. right-click for the “game” properties, and force compatibility – currently, I’m using the “Proton 9.0-4” version. Click the [ Play ] button…\nAt the first launch, a window will open asking for the installation of the “runtime v8.0” of Microsoft Windows. Close the windows by pressing the [ No ] button.\nNext, open Protontricks and target “Non-Steam shortcut: ODExplorer.exe: …”. Choose to install a component, select dotnetdesktop8.\nOnce the installation is complete, before running the binary from Steam again, right-click again and choose the “Manage” \u0026gt; “Create a shortcut on desktop” menu.\nThe remarks made for the game’s Steam desktop shortcut are exactly the same for this shortcut; so make the same changes.\nPS: Although we have mono installable under Linux, the use of mono ODExplorer.exe does not work.\nSRV Survey SRV Survey is a useful support companion by displaying data on the game screen, during a game session; it is useful for organic scans during exploration, to track the player’s position, and useful on the sites of the “Guardians”.\nGit: https://github.com/njthomson/SrvSurvey Used version: 2.0.95.23 Here is the procedure to operate this tool:\nMin ED Launcher is required then the installation of SRV Survey, and a complementary script Then the use of protontricks. ⇒ 1. Download the zip archive from the “Releases” page, currently version 2.0.95.23.\nUncompress the archive Go to the “Application Files” directory Copy the directory named SrvSurvey_number-version to the ED game installation directory Rename the directory in SrvSurvey. Download the shell script SRV_Survey.sh, provided by Maldor, the author of EDMD. Edit the SRV_Survey.sh shell script and copy to the “SrvSurvey” directory, previously copied, renamed to the installation directory of the game. ⇒ Concern Min ED Launcher: whatever your configuration, you must add a process declaration; change the key processes to a similar statement:\n\u0026#34;processes\u0026#34;: [ { \u0026#34;fileName\u0026#34;: \u0026#34;/home/userid/.local/share/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh\u0026#34; } ], Change litteraly \u0026ldquo;/home/userid\u0026rdquo; by your!\n⇒ SRV Survey requires the to be installed to work. This is where the use of the protontricks tool comes in:\nonce protontricks is executed:\nselect the line corresponding to the game “Elite Dangerous : 359320”, then click on the [ Validate ] button. different windows of error messages related to winetricks appear, click [ Validate ].\nthe “Winetricks - choose a wineprefix” window ends up appearing: select, if not the case, the choice “( ) Select the default wineprefix” and then click on the [ Validate ] button. the “Winetricks - current prefix” window opens, choose “( ) Install a Windows DLL or component”, and then click the [ Validate ] button. a new window “Winetricks - current prefix” opens and asks which package is to be installed; scroll until you find the choice “[ ] dotnetdesktop9 MS . NET Desktop Runtime 9.0 LTS”, then click the [ Validate ] button. Once installed, click the [ Cancel ] buttons until the protontricks tool closes.\n⇒ If SRV_Survey does not really launch, even Min Ed Launcher indicates that it\u0026rsquo;s, please read this section: Proton version!\nWith all these changes, SRV Survey should finally work!\nKeep in mind that some features could crash the software. If so, close the game, and restart it so that Min ED Launcher will open both apps again.\nAcknowledgements:\nhttps://github.com/njthomson/SrvSurvey/discussions/524 Squadron Manager Squadron Manager is a tool to manage or participate one squadron. Yes, it\u0026rsquo;s possible to run this Windows app under Linux, by using protontricks and Steam.\nYou need to register first on website!\nRepository: https://github.com/SquadronManager/App/\nLogo: https://squadronmanager.comtac-fr.space/logos/logo2.png\nWebsite: https://squadronmanager.comtac-fr.space/\nUsed version: 3.5.6\nSteam:\nforced compatibility option: Proton 9.0-4 launch option: none After download the exceutable Setup, clic-right to launch with protontricks.\nSelect the wineprefix for Elite Dangerous line, and finish normally the installation. The install folder is: steamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Programs/Squadron Manager/\n⇒ Once the installation is complete, before running the binary from Steam again, right-click again and choose the “Manage” \u0026gt; “Create a shortcut on desktop” menu.\nThe remarks made for the game’s Steam desktop shortcut are exactly the same for this shortcut; so make the same changes. Use the website logo for the launcher icon, available on URL belowe.\nA EDMC plugin, named Michelle, is needed to communicate correctly between EDMC and Squadron Manager.\nRepository: https://github.com/taloche1/Michelle/ Used version: 3.86 to install into the EDMC\u0026rsquo;s plugins folder.\nElite Intel Elite Intel is an AI voice assistant for Elite Dangerous, using NVIDIA Parakeet, and working either local LLM or cloud.\nversion: 1.0\nGPU specs min.: 12 Go VRAM\nwebsite: https://www.elite-intel.org/index.html\nRepository: https://github.com/SudoKrondor/EliteIntel\nTroubleshooting Proton version ⇒ A note regarding SRV_Survey and the version of Proton:\nSRV_Survey must run on the same version of Proton as ED!\nSRV_Survey.sh modified: #!/usr/bin/env bash PROTON_Version=\u0026#34;Proton 9.0 (Beta)\u0026#34; sleep 10s export STEAM_COMPAT_DATA_PATH=\u0026#34;$HOME/.steam/steam/steamapps/compatdata/359320\u0026#34; export STEAM_COMPAT_CLIENT_INSTALL_PATH=\u0026#34;$HOME/.steam/steam\u0026#34; \u0026#34;$HOME/.steam/steam/steamapps/common/${PROTON_Version}/proton\u0026#34; run $HOME/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_survey/SrvSurvey.exe The Min ED Launcher log informs from the beginning which arguments it calls, such as:\n---------- 2026-06-21 11:38:57.294 +02:00 [INF] Elite Dangerous: Minimal Launcher - v0.13.0+6e50d0e0 2026-06-21 11:38:57.385 +02:00 [DBG] Args: [|\u0026#34;/home/myusername/.steam/debian-installation/ubuntu12_32/steam-launch-wrapper\u0026#34;; \u0026#34;--\u0026#34;; \u0026#34;/home/myusername/.steam/debian-installation/ubuntu12_32/reaper\u0026#34;; \u0026#34;SteamLaunch\u0026#34;; \u0026#34;AppId=359320\u0026#34;; \u0026#34;--\u0026#34;; \u0026#34;/home/myusername/.steam/debian-installation/steamapps/common/SteamLinuxRuntime_sniper/_v2-entry-point\u0026#34;; \u0026#34;--verb=waitforexitandrun\u0026#34;; \u0026#34;--\u0026#34;; \u0026#34;/home/myusername/Games/Steam/steamapps/common/Proton 9.0 (Beta)/proton\u0026#34;; \u0026#34;waitforexitandrun\u0026#34;; \u0026#34;/run/media/myusername/games/SteamLibrary/steamapps/common/Elite Dangerous/EDLaunch.exe\u0026#34;; \u0026#34;/Steam\u0026#34;; \u0026#34;/novr\u0026#34;; \u0026#34;/autorun\u0026#34;; \u0026#34;/autoquit\u0026#34;; \u0026#34;waitForExit\u0026#34;|] OS: Linux64 Env: STEAM_COMPAT_DATA_PATH=/run/media/myusername/games/SteamLibrary/steamapps/compatdata/359320 (…) cf the sixth line… \u0026quot;/home/myusername/Games/Steam/steamapps/common/Proton 9.0 (Beta)/proton\u0026quot;; ;-)\nBecause ED is launch with this Proton version!\nNo such file or directory ⇒ A mention about using SRV_Survey with Min Ed Launcher:\nIf you see on Min Ed Launcher logfile, similar statements: 2026-08-01 21:07:05.623 -05:00 [INF] Starting process $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh 2026-08-01 21:07:05.629 -05:00 [FTL] Unable to start process $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh HRESULT: 0x80004005 Win32 Error Code: 2\nSystem.ComponentModel.Win32Exception (2): ErrorStartingProcess, $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh, $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey, No such file or directory\nModify into the Min Ed Launcher\u0026rsquo;s JSON file yours writing; you use $HOME instead of writing litteraly your home user, like: /home/michael!\n$HOME is only a shell variable; JSON can’t use it because he doesn’t know what to do with it!\nEOF Here you go!\n“Fly safe, or fly trouble… it’s up to you! or not…” o7\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnvironment : Steam / Debian Sid / Xfce\u003c/li\u003e\n\u003cli\u003eGame : Elite Dangerous ; DLC : Odyssey\u003c/li\u003e\n\u003cli\u003eCompatibility : no specific Steam Play compatibility tool\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eo7, CMDR: The game is functional without particular worries…\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eInstallation folder of the game : \u003ccode\u003esteam/steamapps/common/Elite Dangerous/\u003c/code\u003e; \u003cem\u003ethis one is easily found in Steam, click D on the game, then “Properties”; menu “Installed files”; then click on the [ Browse… ] button that will open the directory in question\u003c/em\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ePath to the Binary \u003ccode\u003eEliteDangerous64.exe\u003c/code\u003e: \u003ccode\u003esteam/steamapps/common/Elite Dangerous/Products/elite-dangerous-odyssey-64/\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ePath of the “windows” data of the game: \u003ccode\u003esteam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Frontier Developments/Elite Dangerous/\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eGame backup folder: \u003ccode\u003esteam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/Saved Games/Frontier Developments/Elite Dangerous/\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"keybinding\"\u003eKeybinding\u003c/h3\u003e\n\u003cp\u003eSetting up keyboard key management is not a part of the fun.\u003c/p\u003e\n\u003cp\u003eYou must create a directory called “Bindings” in the subdirectory “Options” of the “windows” data folder of the game, such as: \u003cbr\u003e\n\u003ccode\u003esteam/steamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Frontier Developments/Elite Dangerous/Options/Bindings/\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Profiles are available mainly on EDRefCard.\u003c/p\u003e\n\u003cp\u003eHere is my version : \u003ca href=\"/share/Custom.4.2.binds.txt\"\u003eCustom.4.2.binds\u003c/a\u003e ; remove the extension \u003ccode\u003e.txt\u003c/code\u003e ;)\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRelaunch the game and change the profile in the Game Options \u0026gt; Controls; then choose to change the presets.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"steam-desktop-shortcut\"\u003eSteam desktop shortcut\u003c/h3\u003e\n\u003cp\u003eIt’s possible that Steam created a game desktop launcher; but in fact, it won’t work.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRight-click on the launcher to “Edit Launcher” and then in the “Order” field, fill in the absolute path to the Steam executable, such as (under Debian): \u003cbr\u003e\n\u003ccode\u003e/usr/games/steam steam://…\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eTo find out where the absolute path to the Steam binary is, in a console, run the following command: \u003cbr\u003e\n\u003ccode\u003e:$ command -v steam\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis modification being made, the desktop launcher will indeed launch the game.\u003c/p\u003e\n\u003ch3 id=\"desktop-authorizations\"\u003eDesktop Authorizations\u003c/h3\u003e\n\u003cp\u003eYou must allow the file to be executed as a .desktop file.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eIf at the first launch, you refused, it does not matter\u003c/em\u003e; right click on the launcher:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003echoose “Properties…”,\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eclick on the “Launcher” tab and in the “Security” section, click on the checkboxes in front:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cinput disabled=\"\" type=\"checkbox\"\u003e Allow this file to be run as a .desktop file\u003c/li\u003e\n\u003cli\u003e\u003cinput disabled=\"\" type=\"checkbox\"\u003e Set this file as approved\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"tools\"\u003eTools\u003c/h2\u003e\n\u003cp\u003eAll of the tools below run on Linux, with some configurations.\u003c/p\u003e\n\u003cp\u003eIt is not, however, that it is necessary to install them all; in any case, ensure that only a single tool that collects them datas, (\u003cem\u003eInara, EDSM, etc.\u003c/em\u003e), such as \u003ca href=\"/en/post/linux-elite-dangerous/#edmarketconnector\"\u003eEDMarketConnector\u003c/a\u003e or \u003ca href=\"/en/post/linux-elite-dangerous/#eddiscovery\"\u003eEDDiscovery\u003c/a\u003e for example.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eFor some, the use of the tool \u003ccode\u003eprotontricks\u003c/code\u003e will be necessary; fortunately in many distributions, including Debian, it is provided as a package; install it!\u003c/p\u003e\n\u003ch3 id=\"edhm-ui\"\u003eEDHM-UI\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eEDHM-UI\u003c/strong\u003e v3 is a tool to modify the graphical interface.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOfficial website: \u003ca href=\"https://bluemystical.github.io/edhm-api/\" rel=\"external\"\u003ehttps://bluemystical.github.io/edhm-api/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGit: \u003ca href=\"https://github.com/BlueMystical/EDHM_UI\" rel=\"external\"\u003ehttps://github.com/BlueMystical/EDHM_UI\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUsed version: \u003cdel\u003e3.0.67\u003c/del\u003e, 3.0.70\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOnce installed :\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration files : \u003ccode\u003e$HOME/.local/share/EDHM-UI-V3/\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eIn the repository, you have to go to the \u003ca href=\"https://github.com/BlueMystical/EDHM_UI/releases\" rel=\"external\"\u003eRelease\u003c/a\u003e page and download:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe archive \u003cstrong\u003eedhm-ui-v3-linux-x64.zip\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003cstrong\u003eshell script linux_installer.sh\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOnce the archive is downloaded, unzip it and copy into the install script. Give the script execution rights and run it.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThe tool is accessible from the system menu; \u003cem\u003ewith Xfce, in the “Accessories” menu\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eBy default, the tool seeks to communicate with the game for the correct setting; it is necessary to restore the absolute path of the directory “elite-dangerous-odyssey-64”; if you missed something in the step, choose the menu “Main menu” \u0026gt; “Settings”.\u003c/p\u003e\n\u003ch3 id=\"edmarketconnector\"\u003eEDMarketConnector\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eEDMarketConnector\u003c/strong\u003e is a python tool to “improve” trade in Elite Dangerous, mainly, although it is able to use secondary features through plugins.\u003c/p\u003e\n\u003cp\u003eTwo versions exist: one via \u003ca href=\"https://flathub.org/fr/apps/io.edcd.EDMarketConnector\" rel=\"external\"\u003eflatpak\u003c/a\u003e, and the other through the sources into the Git repository.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eGit: \u003ca href=\"https://github.com/EDCD/EDMarketConnector\" rel=\"external\"\u003ehttps://github.com/EDCD/EDMarketConnector\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUsed version: 6.1.2\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConfiguration files:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003evia flatpak: \u003ccode\u003e$HOME/.var/app/io.edcd.EDMarketConnector/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003evia git: \u003ccode\u003e$HOME/.local/share/EDMarketConnector/\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe main configuration file: \u003ccode\u003econfig.toml\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Installation from the sources is done quite easily:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e:$ git clone https://github.com/EDCD/EDMarketConnector.git\n\n:$ cd EDMarketConnector\nEDMarketConnector :$ python3 -m venv venv\nEDMarketConnector :$ source venv/bin/activate\nEDMarketConnector :$ pip3 install -r requirements.txt\nEDMarketConnector :$ python3 EDMarketConnector.py\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eSince the tool must be launched in a python environment, I created a shell launcher:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/bash\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;~/Games/EDMarketConnector/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecd \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esource venv/bin/activate\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epython3 EDMarketConnector.py\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThen a desktop launcher that points to the shell script, while setting the icon with the icon of the tool at the root. (Choose “Files images”). \u003cbr\u003e\n\u003cem\u003eIf the icon is not in the archive, you will find it in the repository\u003c/em\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cul\u003e\n\u003cli\u003eThe functional plugins—which I use… :\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ \u003cstrong\u003ecargo-manifest\u003c/strong\u003e: it seems necessary to change the name of the main directory; from \u003ccode\u003ecargo-manifest\u003c/code\u003e to \u003ccode\u003ecargo_manifest\u003c/code\u003e. \u003cbr\u003e\nWith this slight modification, the plugin is functional!\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003edocking-denied-raison\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMC-Bioscan\u003c/strong\u003e requires ExploData which requires \u003ccode\u003esqlalchemy\u003c/code\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIf you are using the flatpak version of EDMC, download the named version \u003ccode\u003eExploData-***-db-***-flatpak.zip\u003c/code\u003e; Because it embarks sqlalchemy.\u003c/li\u003e\n\u003cli\u003eIf you are using the sources, you will need to install \u003ccode\u003epython3-slqalchemy\u003c/code\u003e in the dedicated python3 environment!\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMCHotKeys\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMCModerOverlay\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMC-NavRoute\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMC-NeutronDancer\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMC-Pioneer\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eEDMC-Screenshot-Linux\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eUpdateTD\u003c/strong\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cem\u003eOther plugins exist; they should work\u003c/em\u003e…\u003c/p\u003e\n\u003ch3 id=\"eddiscovery\"\u003eEDDiscovery\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eEDDiscovery\u003c/strong\u003e is a complete dashboard to manage all the aspects that the game offers.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eGit: \u003ca href=\"https://github.com/EDDiscovery/EDDiscovery/\" rel=\"external\"\u003ehttps://github.com/EDDiscovery/EDDiscovery/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUsed version: 19.1.9.0\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSteam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eforced compatibility option: Proton 9.0-4\u003c/li\u003e\n\u003cli\u003elaunch option: none\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eFrom the ‘\u003ca href=\"https://github.com/EDDiscovery/EDDiscovery/releases\" rel=\"external\"\u003eRelease\u003c/a\u003e’ page of the repository, download the Portable zip archive; unzip it wherever you want.\u003c/p\u003e\n\u003cp\u003eIn Steam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eclick on the “Games” menu \u0026gt; “Add a game name Steam to my library…”, choose the binary \u003ccode\u003eEDDiscovery.exe\u003c/code\u003e which is in the decompressed archive.\u003c/li\u003e\n\u003cli\u003eright-click for the “game” properties, and force compatibility – \u003cem\u003ecurrently, I’m using the “Proton 9.0-4” version\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003eright click again for the “Manage” menu \u0026gt; “Create a shortcut on desktop”.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll the remarks made in the \u003ca href=\"/en/post/linux-elite-dangerous/#steam-desktop-shortcut\"\u003eSteam desktop shortcut\u003c/a\u003e chapter are to be made!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eOnce EDD is opened, go to the “Settings” tab:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIn the “Settings” section, click the [ Add ] button, a new window will open called “CommanderForm”.\n\u003cul\u003e\n\u003cli\u003eIn the “Journal Related Information” section:\n\u003cul\u003e\n\u003cli\u003eWrite the name of your Commander, in the “Commander Name” field\u003c/li\u003e\n\u003cli\u003eclick on the [ Browse ] button to select the game backup directory.\u003c/li\u003e\n\u003cli\u003emake any other desired configuration\u003c/li\u003e\n\u003cli\u003eclick on the [ OK ] button to validate the configuration.\u003c/li\u003e\n\u003cli\u003edelete the profile named “Jameson (Default)”.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eReturn to the “History” tab, you will find the feedback related to the commander used in the game.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eTo be able to set the icons, and the desktop launcher, and in the Steam app, you need to unzip the archive \u003ccode\u003eeddwebsite.zip\u003c/code\u003e, located at the root of the Portable archive. The image to be used mainly is in the subdirectory “Images” and is called “EdLogo600.png”.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cem\u003eNote: Some plugins, such as those to display Inara, EDSM sites do not work because it lacks a tool called WebView2\u003c/em\u003e.\u003c/p\u003e\n\u003ch3 id=\"elite-dangerous-monitor-daemon\"\u003eElite Dangerous Monitor Daemon\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eElite Dangerous Monitor Daemon\u003c/strong\u003e alias \u003cem\u003eEDMD\u003c/em\u003e is another complete dashboard to monitor in real time the game session, made for Linux natively (GTK4 interface).\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eGit: \u003ca href=\"https://github.com/Maldor/EDMD\" rel=\"external\"\u003ehttps://github.com/Maldor/EDMD\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOnce installed :\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e$HOME/.config/EDMD/config.toml\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"ed-odyssey-materials-helper\"\u003eED Odyssey Materials Helper\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eElite Dangerous Odyssey Materials Helper\u003c/strong\u003e is the tool that revolutionizes the acquisition of the necessary materials in the relations with engineers. It shows you what you have, what you miss, the relationship with such an engineer, and much more…\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewebsite: \u003ca href=\"https://edomh.nl/\" rel=\"external\"\u003ehttps://edomh.nl/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGit: \u003ca href=\"https://github.com/jixxed/ed-odyssey-materials-helper/\" rel=\"external\"\u003ehttps://github.com/jixxed/ed-odyssey-materials-helper/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDiscord: \u003ca href=\"https://discord.gg/M8Rgz4AmmA\" rel=\"external\"\u003ehttps://discord.gg/M8Rgz4AmmA\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUsed version: \u003cdel\u003e3.13.8\u003c/del\u003e, 3.13.12\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFrom the ‘\u003ca href=\"https://github.com/jixxed/ed-odyssey-materials-helper/releases\" rel=\"external\"\u003eRelease\u003c/a\u003e’ page, download at least the zip archive, but prefers the autoupdater .deb, .rpm package.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eFrom the binary, everything is installed in the system where it is necessary and becomes accessible from the system menu; \u003cem\u003eunder Xfce, menu “Other” \u0026gt; “Elite Dangerous Odyssey Materials Helper”\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eOnce the application is open:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClick on the “Settings” menu\u003c/li\u003e\n\u003cli\u003eon “Folder Journal” line, click on the [ Select Directory ] button and choose the absolute path related to the game’s backup directory.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThen, do all the other configurations, such as the language, and then use the tool.\u003c/p\u003e\n\u003ch3 id=\"min-ed-launcher\"\u003eMin ED Launcher\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eMin ED Launcher\u003c/strong\u003e is not a tool. It replaces the official launcher, while being very light, which is convenient under Linux, and has other practical aspects, \u003cem\u003eincluding third-party tool execution, such as \u003ca href=\"/en/post/linux-elite-dangerous/#srv-survey\"\u003eSRVSurvey\u003c/a\u003e\u003c/em\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eGit: \u003ca href=\"https://github.com/Rfvgyhn/min-ed-launcher/\" rel=\"external\"\u003ehttps://github.com/Rfvgyhn/min-ed-launcher/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUsed version: 0.13.0\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSteam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eforced compatibility option : none\u003c/li\u003e\n\u003cli\u003elaunch option : yes; \u003cem\u003e\u003cstrong\u003eread the explanations below\u003c/strong\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOnce installed:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e$HOME/.config/min-ed-launcher/settings.json\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003elog: \u003ccode\u003e$HOME/.local/state/min-ed-launcher/min-ed-launcher.log\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eFrom the ‘\u003ca href=\"https://github.com/rfvgyhn/min-ed-launcher/releases\" rel=\"external\"\u003eRelease\u003c/a\u003e’ page, download the zip archive for Linux, and then unzip it.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCopy the binary \u003ccode\u003eMinEdLauncher\u003c/code\u003e into the ED\u0026rsquo;s installation folder.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ In Steam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRight-click to open the game properties\u003c/li\u003e\n\u003cli\u003ein the launch options, write at least:\n\u003cul\u003e\n\u003cli\u003efor Gnome—\u003cem\u003erun too into Xfce4!\u003c/em\u003e:  \u003cbr\u003e\n\u003ccode\u003egnome-terminal -- ./MinEdLauncher %command% /autorun /autoquit\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003ewhat works for me: \u003cbr\u003e\n\u003ccode\u003egnome-terminal --hide-menubar -t \u0026quot;Min ED Launcher\u0026quot; -- ./MinEdLauncher %command% /autorun /autoquit waitForExit\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efor Xfce4: \u003cbr\u003e\n\u003ccode\u003exfce4-terminal --disable-server -x ./MinEdLauncher %command% /autorun /autoquit waitForExit\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003ewhat I\u0026rsquo;m using: \u003cbr\u003e\n\u003ccode\u003exfce4-terminal --disable-server --hide-menubar --hide-scrollbar --hide-toolbar -T \u0026quot;Min ED Launcher\u0026quot; -x ./MinEdLauncher %command% /autorun /autoquit waitForExit\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003cem\u003eIt is possible to use other terminals in the launch options; please read the information on the repository!\u003c/em\u003e).\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ The archive provided a desktop launcher and icon. It is possible to copy the desktop launcher to your desktop. Then right-click to change the command, such as: \u003cbr\u003e\n\u003ccode\u003e/usr/games/steam steam://rungameid/359320 /edo\u003c/code\u003e \u003cbr\u003e\nThis will run the launch of the Odyssey version of the game directly.\u003c/p\u003e\n\u003cp\u003e⇒ All the remarks made in the \u003ca href=\"/en/post/linux-elite-dangerous/#steam-desktop-shortcut\"\u003eSteam desktop shortcut\u003c/a\u003e chapter are to be made!\u003c/p\u003e\n\u003cp\u003e⇒ It is imperative that the launch options are written in the general properties of the game; cf above!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNote:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIt is important that the two layers IPv4 AND IPv6 networks are functional, otherwise it will not work.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"od-explorer\"\u003eOD Explorer\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eOD Explorer\u003c/strong\u003e is truly THE companion to Elite Dangerous, to help us in exploration and exobiology research.\u003c/p\u003e\n\u003cp\u003eNote: This tool is designed to work well with the English language of the game Elite Dangerous, in the other languages of the game, it will not be able to bring everything up properly. But if you understand the English language well enough: “go!”\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eGit: \u003ca href=\"https://github.com/WarmedxMints/OD-Explorer\" rel=\"external\"\u003ehttps://github.com/WarmedxMints/OD-Explorer\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUsed version: \u003cdel\u003e2.0.14\u003c/del\u003e, 2.0.15\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSteam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eforced compatibility option: Proton 9.0-4\u003c/li\u003e\n\u003cli\u003elaunch options: none\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe Logo is available from the repository in the subdirectory \u003ccode\u003eResources/\u003c/code\u003e and is named \u003ccode\u003eAstronaut.png\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eFrom the ‘\u003ca href=\"https://github.com/WarmedxMints/OD-Explorer/releases\" rel=\"external\"\u003eRelease\u003c/a\u003e’ page of the repository, download the \u003ccode\u003eODExplorer-Portable.zip\u003c/code\u003e version.\u003c/p\u003e\n\u003cp\u003eUnwind it, for example, in such a way that you have it: \u003ccode\u003e~/Games/ODExplorer-Portable\u003c/code\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThen you have to use the \u003ccode\u003eprotontricks\u003c/code\u003e tool.\u003c/p\u003e\n\u003cp\u003eThat being done, in Steam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClick on the “Games” menu \u0026gt; “Add a game name Steam to my library…”.\u003c/li\u003e\n\u003cli\u003eright-click for the “game” properties, and force compatibility – \u003cem\u003ecurrently, I’m using the “Proton 9.0-4” version\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eClick the [ Play ] button…\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eAt the first launch, a window will open asking for the installation of the “runtime v8.0” of Microsoft Windows. Close the windows by pressing the [ No ] button.\u003c/p\u003e\n\u003cp\u003eNext, open Protontricks and target “Non-Steam shortcut: ODExplorer.exe: …”. Choose to install a component, select \u003ccode\u003edotnetdesktop8\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/protontricks-odexplorer-line.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/protontricks-odexplorer-line_hu_b779dc657a4504d9.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/protontricks-odexplorer-line_hu_570c924189cf8aed.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Protontricks - select Steam app; line ‘ODExplorer.exe: …’\"\n                    height=\"200\"\n                    id=\"img_images_post_elite-dangerous_protontricks-odexplorer-line.png_0\"\n                    src=\"/images/post/elite-dangerous/protontricks-odexplorer-line.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003cp\u003e\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/winetricks-wineprefix-install-component.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-wineprefix-install-component_hu_50b7b595ff9e578b.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-wineprefix-install-component_hu_dafe7b8ead8209b6.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Winetricks - wineprefix; install component\"\n                    height=\"147\"\n                    id=\"img_images_post_elite-dangerous_winetricks-wineprefix-install-component.png_1\"\n                    src=\"/images/post/elite-dangerous/winetricks-wineprefix-install-component.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003cp\u003e\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/winetricks-package-dotnetdesktop8.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-package-dotnetdesktop8_hu_7efb317f3429eaeb.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-package-dotnetdesktop8_hu_ecb7e6a984cc476c.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Winetricks - wineprefix; choose dotnetdesktop8\"\n                    height=\"147\"\n                    id=\"img_images_post_elite-dangerous_winetricks-package-dotnetdesktop8.png_2\"\n                    src=\"/images/post/elite-dangerous/winetricks-package-dotnetdesktop8.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003cp\u003eOnce the installation is complete, before running the binary from Steam again, right-click again and choose the “Manage” \u0026gt; “Create a shortcut on desktop” menu.\u003c/p\u003e\n\u003cp\u003eThe remarks made for the game’s \u003ca href=\"/en/post/linux-elite-dangerous/#steam-desktop-shortcut\"\u003eSteam desktop shortcut\u003c/a\u003e are exactly the same for this shortcut; so make the same changes.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cem\u003ePS: Although we have mono installable under Linux, the use of mono \u003ccode\u003eODExplorer.exe\u003c/code\u003e does not work\u003c/em\u003e.\u003c/p\u003e\n\u003ch3 id=\"srv-survey\"\u003eSRV Survey\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eSRV Survey\u003c/strong\u003e is a useful support companion by displaying data on the game screen, during a game session; it is useful for organic scans during exploration, to track the player’s position, and useful on the sites of the “Guardians”.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eGit: \u003ca href=\"https://github.com/njthomson/SrvSurvey\" rel=\"external\"\u003ehttps://github.com/njthomson/SrvSurvey\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUsed version: 2.0.95.23\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eHere is the procedure to operate this tool:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/en/post/linux-elite-dangerous/#min-ed-launcher\"\u003e\u003cstrong\u003eMin ED Launcher\u003c/strong\u003e\u003c/a\u003e is required\u003c/li\u003e\n\u003cli\u003ethen the installation of SRV Survey, and a complementary script\u003c/li\u003e\n\u003cli\u003eThen the use of \u003ccode\u003eprotontricks\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ 1. Download the zip archive from the “\u003ca href=\"https://github.com/njthomson/SrvSurvey/releases\" rel=\"external\"\u003eReleases\u003c/a\u003e” page, \u003cem\u003ecurrently version 2.0.95.23\u003c/em\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUncompress the archive\u003c/li\u003e\n\u003cli\u003eGo to the “Application Files” directory\u003c/li\u003e\n\u003cli\u003eCopy the directory named \u003cstrong\u003eSrvSurvey_number-version\u003c/strong\u003e to the ED game installation directory\u003c/li\u003e\n\u003cli\u003eRename the directory in \u003ccode\u003eSrvSurvey\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDownload the shell script \u003ca href=\"https://github.com/user-attachments/files/23442962/SRV_Survey.sh\" rel=\"external\"\u003eSRV_Survey.sh\u003c/a\u003e, provided by Maldor, the author of \u003ca href=\"/en/post/linux-elite-dangerous/#edmd\"\u003eEDMD\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEdit the \u003ccode\u003eSRV_Survey.sh\u003c/code\u003e shell script and copy to the “SrvSurvey” directory, \u003cem\u003epreviously copied, renamed to the installation directory of the game\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ Concern \u003cstrong\u003eMin ED Launcher\u003c/strong\u003e: whatever your configuration, you must add a process declaration; change the key \u003ccode\u003eprocesses\u003c/code\u003e to a similar statement:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e    \u0026#34;processes\u0026#34;: [\n        { \u0026#34;fileName\u0026#34;: \u0026#34;/home/userid/.local/share/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh\u0026#34; }\n    ],\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003e\u003cem\u003e\u003cstrong\u003eChange litteraly \u0026ldquo;\u003ccode\u003e/home/userid\u003c/code\u003e\u0026rdquo; by your!\u003c/strong\u003e\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e⇒ \u003cstrong\u003eSRV Survey\u003c/strong\u003e requires the to be installed to work. This is where the use of the \u003ccode\u003eprotontricks\u003c/code\u003e tool comes in:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eonce protontricks is executed:\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eselect the line corresponding to the game “Elite Dangerous : 359320”, then click on the [ Validate ] button.\n\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/protontricks-elite-dangerous-line.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/protontricks-elite-dangerous-line_hu_fe8028f5e87282b5.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/protontricks-elite-dangerous-line_hu_bcddff3cea275678.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Protontricks - select Steam app; ‘Elite Dangerous: 359320’ line\"\n                    height=\"200\"\n                    id=\"img_images_post_elite-dangerous_protontricks-elite-dangerous-line.png_3\"\n                    src=\"/images/post/elite-dangerous/protontricks-elite-dangerous-line.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003edifferent windows of error messages related to winetricks appear, click [ Validate ].\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ethe “Winetricks - choose a wineprefix” window ends up appearing: select, \u003cem\u003eif not the case\u003c/em\u003e, the choice “( ) Select the default wineprefix” and then click on the [ Validate ] button.\n\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/winetricks-choose-a-wineprefix.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-choose-a-wineprefix_hu_18e4a6fe9ada839c.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-choose-a-wineprefix_hu_e9155a2c43739cf0.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Winetricks - choose a prefix; select default\"\n                    height=\"148\"\n                    id=\"img_images_post_elite-dangerous_winetricks-choose-a-wineprefix.png_4\"\n                    src=\"/images/post/elite-dangerous/winetricks-choose-a-wineprefix.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ethe “Winetricks - current prefix” window opens, choose “( ) Install a Windows DLL or component”, and then click the [ Validate ] button.\n\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/winetricks-current-prefix-install-component.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-current-prefix-install-component_hu_aea1df8afbdd035c.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-current-prefix-install-component_hu_cbba97991fa98119.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Winetricks - current prefix; install DLL or component\"\n                    height=\"147\"\n                    id=\"img_images_post_elite-dangerous_winetricks-current-prefix-install-component.png_5\"\n                    src=\"/images/post/elite-dangerous/winetricks-current-prefix-install-component.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ea new window “Winetricks - current prefix” opens and asks which package is to be installed; scroll until you find the choice “[ ] dotnetdesktop9 MS . NET Desktop Runtime 9.0 LTS”, then click the [ Validate ] button.\n\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/elite-dangerous/winetricks-current-prefix-which-package.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-current-prefix-which-package_hu_d2a939ab6cbdf6.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/elite-dangerous/winetricks-current-prefix-which-package_hu_3de2ee4286015ba1.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Winetricks - current prefix; choose dotnetdesktop9\"\n                    height=\"145\"\n                    id=\"img_images_post_elite-dangerous_winetricks-current-prefix-which-package.png_6\"\n                    src=\"/images/post/elite-dangerous/winetricks-current-prefix-which-package.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOnce installed, click the [ Cancel ] buttons until the protontricks tool closes.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ \u003cem\u003eIf SRV_Survey does not really launch, even Min Ed Launcher indicates that it\u0026rsquo;s, please read this section\u003c/em\u003e: \u003ca href=\"/en/post/linux-elite-dangerous/#proton-version\"\u003eProton version\u003c/a\u003e!\u003c/p\u003e\n\u003cp\u003eWith all these changes, \u003cstrong\u003eSRV Survey\u003c/strong\u003e should finally work!\u003c/p\u003e\n\u003cp\u003eKeep in mind that some features could crash the software. If so, close the game, and restart it so that \u003cstrong\u003eMin ED Launcher\u003c/strong\u003e will open both apps again.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eAcknowledgements:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/njthomson/SrvSurvey/discussions/524\" rel=\"external\"\u003ehttps://github.com/njthomson/SrvSurvey/discussions/524\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"squadron-manager\"\u003eSquadron Manager\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eSquadron Manager\u003c/strong\u003e is a tool to manage or participate one squadron. Yes, it\u0026rsquo;s possible to run this Windows app under Linux, by using protontricks and Steam.\u003c/p\u003e\n\u003cp\u003eYou need to register first on website!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRepository: \u003ca href=\"https://github.com/SquadronManager/App/\" rel=\"external\"\u003ehttps://github.com/SquadronManager/App/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eLogo: \u003ca href=\"https://squadronmanager.comtac-fr.space/logos/logo2.png\" rel=\"external\"\u003ehttps://squadronmanager.comtac-fr.space/logos/logo2.png\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eWebsite: \u003ca href=\"https://squadronmanager.comtac-fr.space/\" rel=\"external\"\u003ehttps://squadronmanager.comtac-fr.space/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUsed version: 3.5.6\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSteam:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eforced compatibility option: Proton 9.0-4\u003c/li\u003e\n\u003cli\u003elaunch option: none\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eAfter download the exceutable Setup, clic-right to launch with  \u003cstrong\u003eprotontricks\u003c/strong\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSelect the wineprefix for Elite Dangerous line, and finish normally the installation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe install folder is: \u003cbr\u003e\n\u003ccode\u003esteamapps/compatdata/359320/pfx/drive_c/users/steamuser/AppData/Local/Programs/Squadron Manager/\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ Once the installation is complete, before running the binary from Steam again, right-click again and choose the “Manage” \u0026gt; “Create a shortcut on desktop” menu.\u003c/p\u003e\n\u003cp\u003eThe remarks made for the game’s \u003ca href=\"/en/post/linux-elite-dangerous/#steam-desktop-shortcut\"\u003eSteam desktop shortcut\u003c/a\u003e are exactly the same for this shortcut; so make the same changes. Use the website logo for the launcher icon, available on URL belowe.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eA \u003ca href=\"/en/post/linux-elite-dangerous/#edmarketconnector\"\u003eEDMC\u003c/a\u003e plugin, named \u003cstrong\u003eMichelle\u003c/strong\u003e, is needed to communicate correctly between EDMC and Squadron Manager.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRepository: \u003ca href=\"https://github.com/taloche1/Michelle/\" rel=\"external\"\u003ehttps://github.com/taloche1/Michelle/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUsed version: 3.86\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eto install into the EDMC\u0026rsquo;s \u003ccode\u003eplugins\u003c/code\u003e folder.\u003c/p\u003e\n\u003ch3 id=\"elite-intel\"\u003eElite Intel\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eElite Intel\u003c/strong\u003e is an AI voice assistant for Elite Dangerous, using NVIDIA Parakeet, and working either local LLM or cloud.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eversion: 1.0\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eGPU specs min.: 12 Go VRAM\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ewebsite: \u003ca href=\"https://www.elite-intel.org/index.html\" rel=\"external\"\u003ehttps://www.elite-intel.org/index.html\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRepository: \u003ca href=\"https://github.com/SudoKrondor/EliteIntel\" rel=\"external\"\u003ehttps://github.com/SudoKrondor/EliteIntel\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"proton-version\"\u003eProton version\u003c/h3\u003e\n\u003cp\u003e⇒ A note regarding SRV_Survey and the version of Proton:\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eSRV_Survey must run on the same version of Proton as ED!\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSRV_Survey.sh \u003cem\u003emodified\u003c/em\u003e:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e#!/usr/bin/env bash\nPROTON_Version=\u0026#34;Proton 9.0 (Beta)\u0026#34;\nsleep 10s\nexport STEAM_COMPAT_DATA_PATH=\u0026#34;$HOME/.steam/steam/steamapps/compatdata/359320\u0026#34;\nexport STEAM_COMPAT_CLIENT_INSTALL_PATH=\u0026#34;$HOME/.steam/steam\u0026#34;\n \u0026#34;$HOME/.steam/steam/steamapps/common/${PROTON_Version}/proton\u0026#34; run $HOME/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_survey/SrvSurvey.exe\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003cp\u003eThe \u003cstrong\u003eMin ED Launcher log\u003c/strong\u003e informs from the beginning which arguments it calls, such as:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e----------\n2026-06-21 11:38:57.294 +02:00 [INF] Elite Dangerous: Minimal Launcher - v0.13.0+6e50d0e0\n2026-06-21 11:38:57.385 +02:00 [DBG]\n    Args: [|\u0026#34;/home/myusername/.steam/debian-installation/ubuntu12_32/steam-launch-wrapper\u0026#34;; \u0026#34;--\u0026#34;;\n  \u0026#34;/home/myusername/.steam/debian-installation/ubuntu12_32/reaper\u0026#34;; \u0026#34;SteamLaunch\u0026#34;;\n  \u0026#34;AppId=359320\u0026#34;; \u0026#34;--\u0026#34;;\n  \u0026#34;/home/myusername/.steam/debian-installation/steamapps/common/SteamLinuxRuntime_sniper/_v2-entry-point\u0026#34;;\n  \u0026#34;--verb=waitforexitandrun\u0026#34;; \u0026#34;--\u0026#34;;\n  \u0026#34;/home/myusername/Games/Steam/steamapps/common/Proton 9.0 (Beta)/proton\u0026#34;;\n  \u0026#34;waitforexitandrun\u0026#34;;\n  \u0026#34;/run/media/myusername/games/SteamLibrary/steamapps/common/Elite Dangerous/EDLaunch.exe\u0026#34;;\n  \u0026#34;/Steam\u0026#34;; \u0026#34;/novr\u0026#34;; \u0026#34;/autorun\u0026#34;; \u0026#34;/autoquit\u0026#34;; \u0026#34;waitForExit\u0026#34;|]\n    OS: Linux64\n    Env: STEAM_COMPAT_DATA_PATH=/run/media/myusername/games/SteamLibrary/steamapps/compatdata/359320\n\n(…)\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003ecf the sixth line… \u003ccode\u003e\u0026quot;/home/myusername/Games/Steam/steamapps/common/Proton 9.0 (Beta)/proton\u0026quot;;\u003c/code\u003e ;-)\u003c/p\u003e\n\u003cp\u003eBecause ED is launch with this Proton version!\u003c/p\u003e\n\u003ch3 id=\"no-such-file-or-directory\"\u003eNo such file or directory\u003c/h3\u003e\n\u003cp\u003e⇒ A mention about using SRV_Survey with Min Ed Launcher:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIf you see on Min Ed Launcher logfile, similar statements:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e2026-08-01 21:07:05.623 -05:00 [INF] Starting process $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh\n2026-08-01 21:07:05.629 -05:00 [FTL] Unable to start process $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh\nHRESULT: 0x80004005\nWin32 Error Code: 2\u003c/p\u003e\n\u003cp\u003eSystem.ComponentModel.Win32Exception (2): ErrorStartingProcess, $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey/SRV_Survey.sh, $HOME/.steam/steam/steamapps/common/Elite Dangerous/SrvSurvey, No such file or directory\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e\u003cstrong\u003eModify into the Min Ed Launcher\u0026rsquo;s JSON file yours writing\u003c/strong\u003e; you use \u003ccode\u003e$HOME\u003c/code\u003e instead of writing litteraly your home user, like: \u003ccode\u003e/home/michael\u003c/code\u003e!\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e$HOME\u003c/code\u003e is only a shell variable; JSON can’t use it because he doesn’t know what to do with it!\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"eof\"\u003eEOF\u003c/h2\u003e\n\u003cp\u003eHere you go!\u003c/p\u003e\n\u003cp\u003e“\u003cem\u003eFly safe, or fly trouble… it’s up to you! or not…”\u003c/em\u003e o7\u003c/p\u003e\n","summary":"Installation and configuration of additional tools to play Elite Dangerous (Steam) on Linux ","tags":["Games","Steam","Linux"],"date_published":"2026-06-13T02:16:42+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2026-06-22:/en/post/linux-forza-horizon/#816b6fcc62fd175fe64083e81757575fb952b696b37c93a8e7310cda46392ba8","url":"https://it-log.fr.eu.org/en/post/linux-forza-horizon/","title":"(Linux) Forza Horizon: troubleshooting","author":{"name":"Stéphane HUC"},"content_text":"Description Environment : Steam Linux / Debian Sid Game : Forza Horizon 5 NO! this little article is not to promote or learn to play any of the Forza Horizon.\nTroubleshooting Connection When opening the game, a window prevents you from playing by stating that a mandatory connection is required.\nMandatory Connexion You cannot continue without being logged in to a profile. [ OK ] Stop the game\nGo to the game installation folder, accessible from the ‘Properties…’ menu, then go to the ‘Installed Files’ menu and click the [ Browse… ] button to open the file browser to the game installation folder.\nHead to SteamLibrary/steamapps/compatdata/1551360/pfx/. You have to go back two files to get to the file steamapps from the installation directory of the game. Open the file user.reg.\nSearch the key Xbl|DeviceKey; which should be around line 2040.\nDelete the entire block corresponding to the equivalent of the following:\n[Software\\\\Wine\\\\Credential Manager\\\\Generic: Xbl|DeviceKey] 1781126654 #time=1dcf91f7c643250 @=\u0026#34;Xbl|DeviceKey\u0026#34; \u0026#34;Comment\u0026#34;=\u0026#34;{3F754FAD-C788-48B1-A0F4-0F6279924F2A}|00000000|1\u0026#34; \u0026#34;Flags\u0026#34;=dword:00000000 \u0026#34;LastWritten\u0026#34;=hex:eb,2e,64,7c,1f,f9,dc,01 \u0026#34;Password\u0026#34;=hex:(…) \u0026#34;Persist\u0026#34;=dword:00000002 \u0026#34;Type\u0026#34;=dword:00000001 Save\nRelaunching the game; normally the Microsoft login window must open and allow the connection (often by already having the user name filled). Once validated, the game will open.\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnvironment : Steam Linux / Debian Sid\u003c/li\u003e\n\u003cli\u003eGame : Forza Horizon 5\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eNO! this little article is not to promote or learn to play any of the Forza Horizon.\u003c/p\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"connection\"\u003eConnection\u003c/h3\u003e\n\u003cp\u003eWhen opening the game, a window prevents you from playing by stating that a mandatory connection is required.\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003eMandatory Connexion\n\nYou cannot continue without being logged in to a profile.\n\n[ OK ]\n\u003c/code\u003e\u003c/pre\u003e\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eStop the game\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eGo to the game installation folder, accessible from the ‘Properties…’ menu, then go to the ‘Installed Files’ menu and click the [ Browse… ] button to open the file browser to the game installation folder.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eHead to \u003ccode\u003eSteamLibrary/steamapps/compatdata/1551360/pfx/\u003c/code\u003e. \u003cem\u003eYou have to go back two files to get to the file \u003ccode\u003esteamapps\u003c/code\u003e from the installation directory of the game\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOpen the file \u003ccode\u003euser.reg\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSearch the key \u003ccode\u003eXbl|DeviceKey\u003c/code\u003e; which should be around line 2040.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDelete the entire block corresponding to the equivalent of the following:\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e[Software\\\\Wine\\\\Credential Manager\\\\Generic: Xbl|DeviceKey] 1781126654\n#time=1dcf91f7c643250\n@=\u0026#34;Xbl|DeviceKey\u0026#34;\n\u0026#34;Comment\u0026#34;=\u0026#34;{3F754FAD-C788-48B1-A0F4-0F6279924F2A}|00000000|1\u0026#34;\n\u0026#34;Flags\u0026#34;=dword:00000000\n\u0026#34;LastWritten\u0026#34;=hex:eb,2e,64,7c,1f,f9,dc,01\n\u0026#34;Password\u0026#34;=hex:(…)\n\u0026#34;Persist\u0026#34;=dword:00000002\n\u0026#34;Type\u0026#34;=dword:00000001\n\u003c/code\u003e\u003c/pre\u003e\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eSave\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eRelaunching the game; normally the Microsoft login window must open and allow the connection (\u003cem\u003eoften by already having the user name filled\u003c/em\u003e). \u003cbr\u003e\nOnce validated, the game will open.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"tips for how the game Forza Horizon works (5) on Linux ","tags":["Games","Steam","Linux"],"date_published":"2026-06-10T23:34:26+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2026-06-08:/en/post/gmail-detect-error/#466b7cf62c85ee2e89d2b8149d41ff519a2d480ac6790febfc7ef96ee20ffa62","url":"https://it-log.fr.eu.org/en/post/gmail-detect-error/","title":"Gmail Detect Error 550-5.7.1 (gsmtp)","author":{"name":"Stéphane HUC"},"content_text":"Merciless “Communication” with Gmail services seems anything but a model of good communication!\nIn the serie \u0026ldquo;Gmail, your ruthless world…\u0026rdquo;:\nDescription Personally, I own two domain names—one free and one yearly paid. I manage my DNS zones (on OpenBSD, using nsd); and the MX servers are managed by a friend (on OpenBSD, too, using OpenSMTPD).\nDNS zones for both domains contains DKIM, DMARC, and SPF records, such as:\n$ grep -E \u0026#39;dkim|dmarc|spf\u0026#39; /etc/ns/huc.fr.eu.org dkimpubkey._domainkey IN TXT ( \u0026#34;v=DKIM1; k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8zDa4/c/HZYbd2NwouHXwgWoUVtRnmc89gjH4xYfVICd8n74Ojr7UVHSz80xiqsQEzEq+UM0FLPqt6IMgCb3\u0026#34; \u0026#34;1zZIF2CJqIa1U2esJi50+Kl50aho3e9bOL76uXMiY0VinrjeWbRU1gQ/ZEhYJdMeQZj60CULXXphVeBqOItNXoXGlJ/lBZZZHZ1Fv/PB8aLwU3fG1CsL9xiY9/PGclhOubwXUUbSgrKJQFAawvgpYp6DZIoZnbDun/uJCwR/1Q+jXGJ56ps45XGeRfZbx17B\u0026#34; \u0026#34;X9ldnQ3iliKpWl9jLSWJ/mR/GdqGIuYeLuzZW7CxrNjd+TGEg9j0Poqf+MGzRpwLOwIDAQAB\u0026#34;) _dmarc IN TXT \u0026#34;v=DMARC1; p=reject; sp=reject;\u0026#34; @ IN TXT \u0026#34;v=spf1 a mx ~all\u0026#34; $ grep -E \u0026#39;dkim|dmarc|spf\u0026#39; /etc/ns/stephane-huc.net dkimpubkey._domainkey IN TXT ( \u0026#34;v=DKIM1; k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8zDa4/c/HZYbd2NwouHXwgWoUVtRnmc89gjH4xYfVICd8n74Ojr7UVHSz80xiqsQEzEq+UM0FLPqt6IMgCb3\u0026#34; \u0026#34;1zZIF2CJqIa1U2esJi50+Kl50aho3e9bOL76uXMiY0VinrjeWbRU1gQ/ZEhYJdMeQZj60CULXXphVeBqOItNXoXGlJ/lBZZZHZ1Fv/PB8aLwU3fG1CsL9xiY9/PGclhOubwXUUbSgrKJQFAawvgpYp6DZIoZnbDun/uJCwR/1Q+jXGJ56ps45XGeRfZbx17B\u0026#34; \u0026#34;X9ldnQ3iliKpWl9jLSWJ/mR/GdqGIuYeLuzZW7CxrNjd+TGEg9j0Poqf+MGzRpwLOwIDAQAB\u0026#34;) _dmarc IN TXT \u0026#34;v=DMARC1; p=reject; sp=reject;\u0026#34; @ IN TXT \u0026#34;v=spf1 a mx ~all\u0026#34; Actually, the mail-tester.com website shows a \u0026ldquo;Perfect\u0026rdquo; rating. Regarding:\nan email sent from my huc.fr.eu.org domain: https://mail-tester.com/test-loynfonhr an email sent from my stephane-huc.net domain: https://mail-tester.com/test-7b231r0vz Honestly, it\u0026rsquo;s hard to do better—not impossible, but…\nRunning DNS queries to check if the PTR record is valid returns the correct results:\n:$ dig mx.huc.fr.eu.org +short 89.234.141.148 :$ dig mx.huc.fr.eu.org AAAA +short 2a00:5881:8110:1e00::2 :$ dig -x 89.234.141.148 +short mx.vinishor.xyz. :$ dig -x 2a00:5881:8110:1e00::2 +short mx.vinishor.xyz. Same result for the other domain.\nI mainly use these email accounts for receiving messages; on average, I send one or two emails, and in rare cases, about ten; and I have NEVER engaged in mass emailing or any similar automated process.\nHowever: as soon as I send an email to a Gmail address from an email address associated with the huc… domain, it’s guaranteed to be rejected and the email blocked!\nHi! This is the MAILER-DAEMON, please DO NOT REPLY to this email. An error has occurred while attempting to deliver a message for the following list of recipients: stephane.huc@gmail.com: 550-5.7.1 [89.234.141.148 12] Gmail has detected that this message is likely unsolicited mail. To reduce the amount of spam sent to Gmail, this message has been blocked. For more information, go to https://support.google.com/mail/?p=UnsolicitedMessage Error ffacd0b85a97d-4601f38a6f1si30466498f8f.340 - gsmtp Below is a copy of the original message: Reporting-MTA: dns; mx.vinishor.xyz Final-Recipient: rfc822; stephane.huc@gmail.com Action: failed Status: 5.0.0 There was a time when messages ended up in the spam folder, but now they don\u0026rsquo;t even do that anymore. It\u0026rsquo;s a \u0026ldquo;flat-out\u0026rdquo; rejection, simply because they\u0026rsquo;re “unsolicited.” But what gives them the right?!\nAs you can see, I also have a Gmail account.\nIn short, it seems to me that there’s no way to communicate with users who have Gmail addresses.\nEhlo ⇒ It\u0026rsquo;s impossible to speak with an actual professional on the team, even if you\u0026rsquo;re willing to pay for the service. Why not try contacting them through the support site?\nThey just pass the buck to the community.\n⇒ When you try to describe the issue on the Google Support website, the submission is automatically rejected, with the following message displayed in red: \u0026lsquo;Failed to post. The content violates the Community Guidelines.\u0026rsquo;\nThe content I tried to post via the support website is exactly what is written here, in the description section, word for word, but in French. What in that content could possibly violate the rules?!\nGmail, Helo? In short, it\u0026rsquo;s a hopeless technical situation…\n","content_html":"\u003ch2 id=\"merciless\"\u003eMerciless\u003c/h2\u003e\n\u003cp\u003e“Communication” with Gmail services seems anything but a model of good communication!\u003c/p\u003e\n\u003cp\u003eIn the serie \u0026ldquo;Gmail, your ruthless world…\u0026rdquo;:\u003c/p\u003e\n\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003ePersonally, I own two domain names—one free and one yearly paid.\nI manage my DNS zones (on OpenBSD, using \u003ccode\u003ensd\u003c/code\u003e); and the MX servers are managed by a friend (on OpenBSD, too, using OpenSMTPD).\u003c/p\u003e\n\u003cp\u003eDNS zones for both domains contains DKIM, DMARC, and SPF records, such as:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e$ grep -E \u0026#39;dkim|dmarc|spf\u0026#39; /etc/ns/huc.fr.eu.org\ndkimpubkey._domainkey    IN TXT    ( \u0026#34;v=DKIM1; k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8zDa4/c/HZYbd2NwouHXwgWoUVtRnmc89gjH4xYfVICd8n74Ojr7UVHSz80xiqsQEzEq+UM0FLPqt6IMgCb3\u0026#34; \u0026#34;1zZIF2CJqIa1U2esJi50+Kl50aho3e9bOL76uXMiY0VinrjeWbRU1gQ/ZEhYJdMeQZj60CULXXphVeBqOItNXoXGlJ/lBZZZHZ1Fv/PB8aLwU3fG1CsL9xiY9/PGclhOubwXUUbSgrKJQFAawvgpYp6DZIoZnbDun/uJCwR/1Q+jXGJ56ps45XGeRfZbx17B\u0026#34; \u0026#34;X9ldnQ3iliKpWl9jLSWJ/mR/GdqGIuYeLuzZW7CxrNjd+TGEg9j0Poqf+MGzRpwLOwIDAQAB\u0026#34;)\n_dmarc IN TXT \u0026#34;v=DMARC1; p=reject; sp=reject;\u0026#34;\n@       IN TXT  \u0026#34;v=spf1 a mx ~all\u0026#34;\n\n$ grep -E \u0026#39;dkim|dmarc|spf\u0026#39; /etc/ns/stephane-huc.net\ndkimpubkey._domainkey    IN TXT    ( \u0026#34;v=DKIM1; k=rsa; t=s; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA8zDa4/c/HZYbd2NwouHXwgWoUVtRnmc89gjH4xYfVICd8n74Ojr7UVHSz80xiqsQEzEq+UM0FLPqt6IMgCb3\u0026#34; \u0026#34;1zZIF2CJqIa1U2esJi50+Kl50aho3e9bOL76uXMiY0VinrjeWbRU1gQ/ZEhYJdMeQZj60CULXXphVeBqOItNXoXGlJ/lBZZZHZ1Fv/PB8aLwU3fG1CsL9xiY9/PGclhOubwXUUbSgrKJQFAawvgpYp6DZIoZnbDun/uJCwR/1Q+jXGJ56ps45XGeRfZbx17B\u0026#34; \u0026#34;X9ldnQ3iliKpWl9jLSWJ/mR/GdqGIuYeLuzZW7CxrNjd+TGEg9j0Poqf+MGzRpwLOwIDAQAB\u0026#34;)\n_dmarc IN TXT \u0026#34;v=DMARC1; p=reject; sp=reject;\u0026#34;\n@       IN TXT  \u0026#34;v=spf1 a mx ~all\u0026#34;\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eActually, the mail-tester.com website shows a \u0026ldquo;Perfect\u0026rdquo; rating. Regarding:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ean email sent from my \u003ccode\u003ehuc.fr.eu.org\u003c/code\u003e domain: \u003ca href=\"https://mail-tester.com/test-loynfonhr\" rel=\"external\"\u003ehttps://mail-tester.com/test-loynfonhr\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ean email sent from my \u003ccode\u003estephane-huc.net\u003c/code\u003e domain: \u003ca href=\"https://mail-tester.com/test-7b231r0vz\" rel=\"external\"\u003ehttps://mail-tester.com/test-7b231r0vz\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eHonestly, it\u0026rsquo;s hard to do better—not impossible, but…\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eRunning DNS queries to check if the PTR record is valid returns the correct results:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e:$ dig mx.huc.fr.eu.org +short\n89.234.141.148\n:$ dig mx.huc.fr.eu.org AAAA +short\n2a00:5881:8110:1e00::2\n\n:$ dig -x 89.234.141.148 +short\nmx.vinishor.xyz.\n:$ dig -x 2a00:5881:8110:1e00::2 +short\nmx.vinishor.xyz.\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eSame result for the other domain.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eI mainly use these email accounts for receiving messages; on average, I send one or two emails, and in rare cases, about ten; and I have NEVER engaged in mass emailing or any similar automated process.\u003c/p\u003e\n\u003cp\u003eHowever: as soon as I send an email to a Gmail address from an email address associated with the \u003ccode\u003ehuc…\u003c/code\u003e domain, it’s guaranteed to be rejected and the email blocked!\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003eHi! This is the MAILER-DAEMON, please DO NOT REPLY to this email. An error has occurred while attempting to deliver a message for the following list of recipients: stephane.huc@gmail.com: 550-5.7.1 [89.234.141.148 12] Gmail has detected that this message is likely unsolicited mail. To reduce the amount of spam sent to Gmail, this message has been blocked. For more information, go to https://support.google.com/mail/?p=UnsolicitedMessage\nError ffacd0b85a97d-4601f38a6f1si30466498f8f.340 - gsmtp Below is a copy of the original message:\n\nReporting-MTA: dns; mx.vinishor.xyz\n Final-Recipient: rfc822; stephane.huc@gmail.com\nAction: failed\nStatus: 5.0.0\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThere was a time when messages ended up in the spam folder, but now they don\u0026rsquo;t even do that anymore. It\u0026rsquo;s a \u0026ldquo;flat-out\u0026rdquo; rejection, simply because they\u0026rsquo;re “unsolicited.” But what gives them the right?!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eAs you can see, I also have a Gmail account.\u003c/p\u003e\n\u003cp\u003eIn short, it seems to me that there’s no way to communicate with users who have Gmail addresses.\u003c/p\u003e\n\u003ch2 id=\"ehlo\"\u003eEhlo\u003c/h2\u003e\n\u003cp\u003e⇒ It\u0026rsquo;s impossible to speak with an actual professional on the team, even if you\u0026rsquo;re willing to pay for the service. Why not try contacting them through the support site?\u003c/p\u003e\n\u003cp\u003eThey just pass the buck to the community.\u003c/p\u003e\n\u003cp\u003e⇒ When you try to describe the issue on the Google Support website, the submission is automatically rejected, with the following message displayed in red: \u0026lsquo;Failed to post. The content violates the \u003ca href=\"https://support.google.com/communities/answer/7425194\" rel=\"external\"\u003eCommunity Guidelines\u003c/a\u003e.\u0026rsquo;\u003c/p\u003e\n\u003cp\u003eThe content I tried to post via the support website is exactly what is written here, in the \u003ca href=\"/en/post/gmail-detect-error/#description\"\u003edescription\u003c/a\u003e section, word for word, but in French. What in that content could possibly violate the rules?!\u003c/p\u003e\n\u003cp\u003eGmail, Helo? \u003cbr\u003e\nIn short, it\u0026rsquo;s a hopeless technical situation…\u003c/p\u003e\n\u003chr\u003e\n","summary":"Help, about Gmail (gsmtp) service! Your email support and response are unbearable… You're not playing the rules, even though DKIM, DMARC, SPF, and PTR records are all correct!","tags":["gmail","error"],"date_published":"2026-06-08T13:38:29+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2026-05-04:/en/web/hugo/week-number/#ba4e036770af61d17af4a01853f81171f420b17982ef710ff05cf282525ab174","url":"https://it-log.fr.eu.org/en/web/hugo/week_number/","title":"Hugo: Get the week number of the year (tips)","author":{"name":"Stéphane HUC"},"content_text":"Description Actually, Hugo (the SSG) is not capable to get a week number! It\u0026rsquo;s ‘under consideration’!\nHowever, Go language provides the IsoWeek() method.\nFind the week number serves a purpose, whilst uncommon, is certainly useful. As instance, a weekly newsletter :)\nI\u0026rsquo;m going to show you two differents functions:\nby getIsoWeek or with getWeekNumber getisoweek First, create a partial template: /func/getIsoWeek:\n{{- $date := time.AsTime . -}} {{- $weekday := $date.Weekday }} {{/* 1. Normalize Weekday (Mon=1 ... Sun=7) */}} {{- $isoDay := cond (eq $weekday 0) 7 (int $weekday) -}} {{/* 2. Find Thursday (ISO Week belongs to the year of its Thursday) */}} {{- $offset := sub 4 $isoDay -}} {{- $thursday := $date.AddDate 0 0 $offset -}} {{/* 3. Calculate Week Number */}} {{- $isoYear := $thursday.Year -}} {{- $isoWeek := add (div (sub $thursday.YearDay 1) 7) 1 -}} {{/* 4. Return the data */}} {{- $str := dict \u0026#34;week\u0026#34; (printf \u0026#34;%02d\u0026#34; $isoWeek) \u0026#34;year\u0026#34; (printf \u0026#34;%04d\u0026#34; $isoYear) -}} {{- $data := dict \u0026#34;week\u0026#34; $isoWeek \u0026#34;year\u0026#34; $isoYear \u0026#34;str\u0026#34; $str -}} {{- return $data -}} The call:\n{{- partial \u0026#34;func/getisoweek\u0026#34; .Date -}} Or any other varible using Time, such as now.\n⇒ Remark about getIsoWeek :\nif I want values as int, I call $data.week and $data.year if I want values as str, I call $data.str.week and $data.str.year Personnaly, I\u0026rsquo;ve too created another partial template, called utils/formatIsoDate.\nThe code as follows:\n{{- $data := partial \u0026#34;func/getIsoWeek\u0026#34; . -}} {{- $s := printf \u0026#34;w%s-y%s\u0026#34; $data.str.week $data.str.year -}} {{- return $s -}} I can call it either from the default archetypes, or anywhere into the templates or shortcodes, as I wish, such as: {{ partial \u0026quot;utils/formatIsoDate\u0026quot; .Date }} ou {{ partial \u0026quot;utils/formatIsoDate\u0026quot; now }}.\ngetweeknumber This second method for finding the week number is a little trickier!\nThis time, I have two main files.\n⇒ The first function, func/splitNameYMO, is designed to “break down” a standardized date (YYYY-MM-DD) into the corresponding day, month, and year, and return a dictionary.\n{{- $str := split . \u0026#34;-\u0026#34; -}} {{- $d = (int (index $str 2)) -}} {{- $m = (int (index $str 1)) -}} {{- $y = (int (index $str 0)) -}} {{- return (dict \u0026#34;day\u0026#34; $d \u0026#34;month\u0026#34; $m \u0026#34;year\u0026#34; $y) -}} I created this file because I use it frequently throughout my code…\n⇒ The second file is the main function, named func/getWeekNumber\n{{- $date := \u0026#34;\u0026#34; -}} {{- $tz := site.Params.timeZone -}} {{- $week := 0 -}} {{ $type := printf \u0026#34;%T\u0026#34; . }} {{ if eq $type \u0026#34;string\u0026#34; }} {{- $data := partial \u0026#34;func/splitNameYMO\u0026#34; . }} {{- $date = time (printf \u0026#34;%04d-%02d-%02d\u0026#34; $data.year $data.month $data.day) $tz -}} {{ else }} {{- $date = time . $tz -}} {{- end -}} {{/* Calcul \u0026#39;doy: day of the year\u0026#39;, \u0026#39;dow: day of the week\u0026#39; */}} {{- $doy := $date.YearDay -}} {{- $dow := int $date.Weekday -}} {{- $year := $date.Year -}} {{/* calcul week number */}} {{- $week = div (add (sub $doy $dow) 10) 7 -}} {{- if eq $dow 0 -}} {{- $week = sub $week 1 -}} {{- end -}} {{- $str := dict \u0026#34;week\u0026#34; (printf \u0026#34;%02d\u0026#34; $week) \u0026#34;year\u0026#34; (printf \u0026#34;%04d\u0026#34; $year) -}} {{- $data := dict \u0026#34;week\u0026#34; $week \u0026#34;year\u0026#34; $year \u0026#34;str\u0026#34; $str -}} {{- return $data -}} Explanations:\nFirst, I need to determine the type of the value I\u0026rsquo;m injecting into the file call — whether it’s a string or something else, in this case a timestamp — keep in mind that Hugo doesn’t know how to declare a value type for a timestamp, but in the repository, it is defined as Time.time.\nNext, I determine which day of the year the date ($doy) corresponds to, which day of the week it falls on ($dow), and finally the year, of course.\nCalcul of the week number is known:\nsubtract the day of the week from the day of the year add 10 and divide the result by 7 and finally, if the day of the week is a Sunday, I subtract 1 from the week number found — this applies to Hugo, where weeks start on Sunday Voila!\nDocumentation https://gohugo.io/quick-reference/methods/#time Acknowledgements https://discourse.gohugo.io/t/group-content-by-week-number-of-year/11894/6 ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eActually, Hugo (the SSG) is not capable to get a week number! \u003cbr\u003e\nIt\u0026rsquo;s ‘under consideration’!\u003c/p\u003e\n\u003cp\u003eHowever, Go language provides the \u003ca href=\"https://pkg.go.dev/time#Time.ISOWeek\" rel=\"external\"\u003eIsoWeek()\u003c/a\u003e\nmethod.\u003c/p\u003e\n\u003cp\u003eFind the week number serves a purpose, whilst uncommon, is certainly useful. \u003cbr\u003e\nAs instance, a weekly newsletter :)\u003c/p\u003e\n\u003cp\u003eI\u0026rsquo;m going to show you two differents functions:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eby \u003ca href=\"/en/web/hugo/week_number/#getisoweek\"\u003e\u003ccode\u003egetIsoWeek\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eor with \u003ca href=\"/en/web/hugo/week_number/#getweeknumber\"\u003e\u003ccode\u003egetWeekNumber\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"getisoweek\"\u003egetisoweek\u003c/h2\u003e\n\u003cp\u003eFirst, create a partial template: \u003ccode\u003e/func/getIsoWeek\u003c/code\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- $date := time.AsTime . -}}\n{{- $weekday := $date.Weekday }}\n{{/* 1. Normalize Weekday (Mon=1 ... Sun=7) */}}\n{{- $isoDay := cond (eq $weekday 0) 7 (int $weekday) -}}\n{{/* 2. Find Thursday (ISO Week belongs to the year of its Thursday) */}}\n{{- $offset := sub 4 $isoDay -}}\n{{- $thursday := $date.AddDate 0 0 $offset -}}\n{{/* 3. Calculate Week Number */}}\n{{- $isoYear := $thursday.Year -}}\n{{- $isoWeek := add (div (sub $thursday.YearDay 1) 7) 1 -}}\n{{/* 4. Return the data */}}\n{{- $str := dict \u0026#34;week\u0026#34; (printf \u0026#34;%02d\u0026#34; $isoWeek) \u0026#34;year\u0026#34; (printf \u0026#34;%04d\u0026#34; $isoYear) -}}\n{{- $data := dict \u0026#34;week\u0026#34; $isoWeek \u0026#34;year\u0026#34; $isoYear \u0026#34;str\u0026#34; $str -}}\n{{- return $data -}}\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThe call:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- partial \u0026#34;func/getisoweek\u0026#34; .Date -}}\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eOr any other varible using Time, such as \u003ccode\u003enow\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e⇒ Remark about \u003ccode\u003egetIsoWeek\u003c/code\u003e :\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eif I want values as \u003ccode\u003eint\u003c/code\u003e, I call \u003ccode\u003e$data.week\u003c/code\u003e and \u003ccode\u003e$data.year\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eif I want values as \u003ccode\u003estr\u003c/code\u003e, I call \u003ccode\u003e$data.str.week\u003c/code\u003e and \u003ccode\u003e$data.str.year\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003ePersonnaly, I\u0026rsquo;ve too created another partial template, called \u003ccode\u003eutils/formatIsoDate\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe code as follows:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- $data := partial \u0026#34;func/getIsoWeek\u0026#34; . -}}\n{{- $s := printf \u0026#34;w%s-y%s\u0026#34; $data.str.week $data.str.year -}}\n{{- return $s -}}\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003cp\u003eI can call it either from the \u003ccode\u003edefault\u003c/code\u003e archetypes, or anywhere into the templates or shortcodes, as I wish, such as: \u003cbr\u003e\n\u003ccode\u003e{{ partial \u0026quot;utils/formatIsoDate\u0026quot; .Date }}\u003c/code\u003e ou \u003ccode\u003e{{ partial \u0026quot;utils/formatIsoDate\u0026quot; now }}\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"getweeknumber\"\u003egetweeknumber\u003c/h2\u003e\n\u003cp\u003eThis second method for finding the week number is a little trickier!\u003c/p\u003e\n\u003cp\u003eThis time, I have two main files.\u003c/p\u003e\n\u003cp\u003e⇒ The first function, \u003ccode\u003efunc/splitNameYMO\u003c/code\u003e, is designed to “break down” a standardized date (\u003ccode\u003eYYYY-MM-DD\u003c/code\u003e) into the corresponding day, month, and year, and return a dictionary.\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- $str := split . \u0026#34;-\u0026#34; -}}\n{{- $d = (int (index $str 2)) -}}\n{{- $m = (int (index $str 1)) -}}\n{{- $y = (int (index $str 0)) -}}\n{{- return (dict \u0026#34;day\u0026#34; $d \u0026#34;month\u0026#34; $m \u0026#34;year\u0026#34; $y) -}}\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003e\u003cem\u003eI created this file because I use it frequently throughout my code…\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e⇒ The second file is the main function, named \u003ccode\u003efunc/getWeekNumber\u003c/code\u003e\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- $date := \u0026#34;\u0026#34; -}}\n{{- $tz := site.Params.timeZone -}}\n{{- $week := 0 -}}\n\n{{ $type := printf \u0026#34;%T\u0026#34; . }}\n\n{{ if eq $type \u0026#34;string\u0026#34; }}\n\n    {{- $data := partial \u0026#34;func/splitNameYMO\u0026#34; . }}\n    {{- $date = time (printf \u0026#34;%04d-%02d-%02d\u0026#34; $data.year $data.month $data.day) $tz -}}\n\n{{ else }}\n\n    {{- $date = time . $tz -}}\n\n{{- end -}}\n\n{{/* Calcul \u0026#39;doy: day of the year\u0026#39;, \u0026#39;dow: day of the week\u0026#39; */}}\n{{- $doy := $date.YearDay -}}\n{{- $dow := int $date.Weekday -}}\n{{- $year := $date.Year -}}\n\n{{/* calcul week number */}}\n{{- $week = div (add (sub $doy $dow) 10) 7 -}}\n{{- if eq $dow 0 -}}\n    {{- $week = sub $week 1 -}}\n{{- end -}}\n\n{{- $str := dict \u0026#34;week\u0026#34; (printf \u0026#34;%02d\u0026#34; $week) \u0026#34;year\u0026#34; (printf \u0026#34;%04d\u0026#34; $year) -}}\n{{- $data := dict \u0026#34;week\u0026#34; $week \u0026#34;year\u0026#34; $year \u0026#34;str\u0026#34; $str -}}\n{{- return $data -}}\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eExplanations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFirst, I need to determine the type of the value I\u0026rsquo;m injecting into the file call — whether it’s a \u003ccode\u003estring\u003c/code\u003e or something else, in this case a timestamp — \u003cem\u003ekeep in mind that Hugo doesn’t know how to declare a value type for a timestamp, but in the repository, it is defined as \u003ccode\u003eTime.time\u003c/code\u003e\u003c/em\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eNext, I determine which day of the year the date (\u003ccode\u003e$doy\u003c/code\u003e) corresponds to, which day of the week it falls on (\u003ccode\u003e$dow\u003c/code\u003e), and finally the year, of course.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCalcul of the week number is \u003ca href=\"https://en.wikipedia.org/wiki/ISO_week_date#Calculating_the_week_number_from_an_ordinal_date\" rel=\"external\"\u003eknown\u003c/a\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003esubtract the day of the week from the day of the year\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003e10\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eand divide the result by \u003ccode\u003e7\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eand finally, if the day of the week is a Sunday, I subtract \u003ccode\u003e1\u003c/code\u003e from the week number found — \u003cem\u003ethis applies to Hugo, where weeks start on Sunday\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/quick-reference/methods/#time\" rel=\"external\"\u003ehttps://gohugo.io/quick-reference/methods/#time\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"acknowledgements\"\u003eAcknowledgements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://discourse.gohugo.io/t/group-content-by-week-number-of-year/11894/6\" rel=\"external\"\u003ehttps://discourse.gohugo.io/t/group-content-by-week-number-of-year/11894/6\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","summary":"Hugo: Get a week number since Date!","tags":["Hugo","Time","tips"],"date_published":"2026-05-04T13:06:25+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2026-03-18:/en/post/bat-cat","url":"https://it-log.fr.eu.org/en/post/bat-cat/","title":"BAT: a 'cat killer'… with wings, for color and syntax highligthing!","author":{"name":"Stéphane HUC"},"content_text":"Description Introducing to bat tool, an \u0026ldquo;enhanced\u0026rdquo; clone of cat, which offers syntax highlighting and colouring, supports multiple languages and integrates with Git!\nIt\u0026rsquo;s a tool available under an open-source licence, either MIT or Apache 2.0 licence, wrote since several years (4y, at the time of writing this article).\nNote: Prefers to use a terminal capable of handling a 24-bit colour palette properly.\nOfficiel repository: https://github.com/sharkdp/bat Installation Regardless you\u0026rsquo;re using either Linux or *BSD, the package to be installed is bat.\non Debian: the binary is batcat on OpenBSD : bat! Configuration You can generate a file config, as instance:\n:$ bat --generate-config-file To use truecolor or 24bit on the terminal, add the environment variable: COLORTERM :\nif [ -x $(command -v bat) ]; then export COLORTERM=\u0026#34;truecolor\u0026#34; # or \u0026#34;24bit\u0026#34; fi (For Debian/*Buntu, change the binary name!)\nUtilisation One using case is to combine with others tools, like git, find, man, etc.\nfind To use bat with find:\nfind … -exec bat {} + where \u0026lsquo;…\u0026rsquo; represents the search term.\ngit bat can show you the git diff, by highlighting term, whilst maintaining the indentation.\nMake a batdiff function:\nbatdiff() { git diff --name-only --relative --diff-filter=d -z | xargs -0 bat --diff } man Add the MANPAGER environment variable:\nexport MANPAGER=\u0026#34;bat -pl man\u0026#34; Of course, it\u0026rsquo;s possible to implement any feature supported by bat tool.\nAnd finally, call simply (the best) man:\nDebian : man batcat OpenBSD : man pf.conf Tip You will notice that the output also contains ANSI escape characters or symbols, which are incomprehensible to us, humans.\nPipe col to bat:\nman() { sh -c \u0026#34;man \u0026#39;$@\u0026#39; | col -bx | bat -l man\u0026#34; } And use simply man. (always the best).\nDocumentation A cat(1) clone with syntax highlighting and Git integration: https://github.com/sharkdp/bat Bash scripts that integrate bat with various command line tools: https://github.com/eth-p/bat-extras Pipe man into col -b to get rid of ^H Anatomy of a Terminal Emulator Acknowledgements Wesley: @obj@bsd.cafe Justine Smithies: @justine@snac.smithies.me.uk ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eIntroducing to \u003ccode\u003ebat\u003c/code\u003e tool, an \u0026ldquo;enhanced\u0026rdquo; clone of \u003ccode\u003ecat\u003c/code\u003e, which offers syntax\nhighlighting and colouring, supports multiple languages and integrates with Git!\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s a tool available under an open-source licence, either MIT or Apache 2.0\nlicence, wrote since several years (\u003cem\u003e4y, at the time of writing this article\u003c/em\u003e).\u003c/p\u003e\n\u003cp\u003eNote: Prefers to use a terminal capable of handling a 24-bit colour palette\nproperly.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOfficiel repository: \u003ca href=\"https://github.com/sharkdp/bat\" rel=\"external\"\u003ehttps://github.com/sharkdp/bat\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eRegardless you\u0026rsquo;re using either Linux or *BSD, the package to be installed is\n\u003ccode\u003ebat\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cul\u003e\n\u003cli\u003eon Debian: the binary is \u003ccode\u003ebatcat\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eon OpenBSD : \u003ccode\u003ebat\u003c/code\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eYou can generate a file config, as instance:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ bat --generate-config-file\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eTo use \u003ccode\u003etruecolor\u003c/code\u003e or \u003ccode\u003e24bit\u003c/code\u003e on the terminal, add the environment variable:\n\u003ccode\u003eCOLORTERM\u003c/code\u003e :\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eif [ -x $(command -v bat) ]; then\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eexport COLORTERM\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;truecolor\u0026#34; # or \u0026#34;24bit\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e(\u003cem\u003eFor Debian/*Buntu, change the binary name!\u003c/em\u003e)\u003c/p\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\u003cp\u003eOne using case is to combine with others tools, like \u003ccode\u003egit\u003c/code\u003e, \u003ccode\u003efind\u003c/code\u003e, \u003ccode\u003eman\u003c/code\u003e, etc.\u003c/p\u003e\n\u003ch3 id=\"find\"\u003efind\u003c/h3\u003e\n\u003cp\u003eTo use \u003ccode\u003ebat\u003c/code\u003e with \u003ccode\u003efind\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efind … -exec bat \u003cspan style=\"color:#5bc4bf\"\u003e{}\u003c/span\u003e +\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003ewhere \u0026lsquo;…\u0026rsquo; represents the search term.\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"git\"\u003egit\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebat\u003c/code\u003e can show you the git diff, by highlighting term, whilst maintaining the\nindentation.\u003c/p\u003e\n\u003cp\u003eMake a \u003ccode\u003ebatdiff\u003c/code\u003e function:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003ebatdiff() {\n    git diff --name-only --relative --diff-filter=d -z | xargs -0 bat --diff\n}\n\u003c/code\u003e\u003c/pre\u003e\u003ch3 id=\"man\"\u003eman\u003c/h3\u003e\n\u003cp\u003eAdd the \u003ccode\u003eMANPAGER\u003c/code\u003e environment variable:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003eexport MANPAGER=\u0026#34;bat -pl man\u0026#34;\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003e\u003cem\u003eOf course, it\u0026rsquo;s possible to implement any feature supported by \u003ccode\u003ebat\u003c/code\u003e tool\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eAnd finally, call simply (\u003cem\u003ethe best\u003c/em\u003e) \u003ccode\u003eman\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDebian : \u003ccode\u003eman batcat\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/debian-batcat-man.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/debian-batcat-man_hu_3cc503cacf8b31ca.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/debian-batcat-man_hu_591483d71d811558.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"Debian : man batcat\"\n                    height=\"134\"\n                    id=\"img_images_post_debian-batcat-man.png_0\"\n                    src=\"/images/post/debian-batcat-man.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD : \u003ccode\u003eman pf.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\n    \n\n            \n                    \n                    \u003cfigure role=\"figure\"\u003e\n    \u003ca href=\"/images/post/openbsd-bat-man.png\"\u003e\n        \u003cpicture\u003e\n                \n                    \n                    \u003csource srcset=\"/images/post/openbsd-bat-man_hu_d6fcc6312cf7b7b6.avif\" type=\"image/avif\"\u003e\n                    \n                    \u003csource srcset=\"/images/post/openbsd-bat-man_hu_5e95e196aa2bb610.webp\" type=\"image/webp\"\u003e\n            \u003cimg loading=\"lazy\"\n                    alt=\"OpenBSD : man pf.conf\"\n                    height=\"114\"\n                    id=\"img_images_post_openbsd-bat-man.png_1\"\n                    src=\"/images/post/openbsd-bat-man.png\"\n                    width=\"300\"\u003e\n        \u003c/picture\u003e\n    \u003c/a\u003e\n\u003c/figure\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"tip\"\u003eTip\u003c/h3\u003e\n\u003cp\u003eYou will notice that the output also contains ANSI escape characters or symbols,\nwhich are incomprehensible to us, humans.\u003c/p\u003e\n\u003cp\u003ePipe \u003ccode\u003ecol\u003c/code\u003e to \u003ccode\u003ebat\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eman\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    sh -c \u003cspan style=\"color:#48b685\"\u003e\u0026#34;man \u0026#39;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$@\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#39; | col -bx | bat -l man\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAnd use simply \u003ccode\u003eman\u003c/code\u003e. (\u003cem\u003ealways the best\u003c/em\u003e).\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp/bat\" rel=\"external\"\u003eA cat(1) clone with syntax highlighting and Git integration\u003c/a\u003e: \u003ca href=\"https://github.com/sharkdp/bat\" rel=\"external\"\u003ehttps://github.com/sharkdp/bat\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eth-p/bat-extras\" rel=\"external\"\u003eBash scripts that integrate bat with various command line tools\u003c/a\u003e: \u003ca href=\"https://github.com/eth-p/bat-extras\" rel=\"external\"\u003ehttps://github.com/eth-p/bat-extras\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://sebastiano.tronto.net/blog/2022-09-05-man-col/\" rel=\"external\"\u003ePipe man into col -b to get rid of ^H\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://poor.dev/terminal-anatomy/\" rel=\"external\"\u003eAnatomy of a Terminal Emulator\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"acknowledgements\"\u003eAcknowledgements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eWesley: \u003ca href=\"https://framapiaf.org/@obj@bsd.cafe/116240454529047739\" rel=\"external\"\u003e@obj@bsd.cafe\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJustine Smithies: \u003ca href=\"https://snac.smithies.me.uk/justine/p/1773688945.119139\" rel=\"external\"\u003e@justine@snac.smithies.me.uk\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Bat: THE tool that replaces cat; AND highlights syntax with colours, supports multiple languages.","tags":["Sys","outil"],"date_published":"2026-03-18T10:03:45+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2023-02-19:/en/sys/openwrt/unbound-dot","url":"https://it-log.fr.eu.org/en/sys/openwrt/unbound-dot/","title":"OpenWRT + Unbound: Using DoT","author":{"name":"Stéphane HUC"},"content_text":"opkg → apk Since OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition. Description The purpose is to add unbound to enable the DoT (DNS-over-TCP) protocol, slightly modifying dnsmasq, installed by default:\nReasons are:\nencrypt DNS traffic to improve its confidentiality. prevent DNS leaks and hijacking bypass regional restrictions, or those imposed by your ISP (Internet Service Provider) . Installation Install packages needed: unbound unbound-control luci-app-unbound\n:# opkg update :# opkg install unbound unbound-control luci-app-unbound May usefull to install too:\nunbound-checkconf: to ensure the compliance of the configuration unbound-control-setup: allows you to install/create the required certificates for the tool control unbound-host: test… Configuration dnsmasq First, edit the file /etc/config/dhcp, to use two options:\noption noresolv \u0026#39;1\u0026#39; list server \u0026#39;127.0.0.1#531\u0026#39; the first requires that the file /etc/resolv.conf not be use the second requires redirecting DNS requests locally to the selected port, here: 531. Of course, these options can be modified directly using LUCI:\n\u0026lsquo;Resolv and Hosts Files\u0026rsquo; \u0026gt; Ignore resolv file option \u0026lsquo;General Settings\u0026rsquo; \u0026gt; DNS forwardings option About using uci, in your terminal:\nuci set dhcp.@dnsmasq[0].noresolv=\u0026#39;1\u0026#39; uci set dhcp.@dnsmasq[0].server=\u0026#39;127.0.0.1#531\u0026#39; uci commit Restart your dnsmasq service!\nunbound The simplest thing to do is to enable Unbound and check Manual Conf option to edit manually the configuration file through LUCI.\nAdd your networks in the Trigger Networks option, at least lan.\nFile configuration : /var/lib/unbound/unbound.conf The minimum changes to be made correspond to the following variables:\nserver: (…) port: 531 do-ip4: yes do-ip6: yes do-tcp: yes hide-identity: yes hide-version: yes qname-minimisation: yes prefetch: yes rrset-roundrobin: yes minimal-responses: yes tls-cert-bundle: \u0026#34;/etc/ssl/certs/ca-certificates.crt\u0026#34; (…) Regarding the port number chosen, here 531: we dont choose 5353, which is normally reserved for the mdns service. Of course, you can change it, in the dnsmasq configuration; but, be sure to choose it from amont the preferred port numbers. (ie. below 1024…)\n⇒ Be sure to add/modify the access-control variables to allow only:\naccess-control: 0.0.0.0/0 refuse access-control: ::0/0 refuse access-control: 127.0.0.0/8 allow access-control: ::1 allow Then declare the LAN\u0026rsquo;s IPv(4|6), or even your Wi-Fi…\nIt\u0026rsquo;s necessary to modify the forward-zone section:\nforward-zone: name: \u0026#34;.\u0026#34; forward-tls-upstream: yes Then add all IP addresses of the DoT servers; of course, both IPv4 and IPv6 are functional.\nforward-addr: 9.9.9.9@853 # Quad9 forward-addr: 1.1.1.1@853 # Cloudflare forward-addr: 149.112.112.112@853 # Quad9 secondaire forward-addr: 1.0.0.1@853 # Cloudflare secondaire forward-addr: 2620:fe::fe@853 # Quad9 / IPv6 forward-addr: 2606:4700:4700::1111@853 # Cloudflare / IPv6 forward-addr: 2606:4700:4700::1001@853 # Cloudflare secondaire / IPv6 The above example shows how the \u0026ldquo;greats of this world\u0026rdquo; are used.\nHere some interesting alternatives:\n# FDN DoT forward-addr: 80.67.169.12@853 forward-addr: 80.67.169.40@853 forward-addr: 2001:910:800::12@853 forward-addr: 2001:910:800::40@853 # dns.sb forward-addr: 185.222.222.222@853 forward-addr: 45.11.45.11@853 forward-addr: 2a09::@853 forward-addr: 2a11::@853 # dns4eu forward-addr: 86.54.11.11@853 forward-addr: 86.54.11.211@853 forward-addr: 2a13:1001::86:54:11:11@853 forward-addr: 2a13:1001::86:54:11:211@853 # dot.bortzmeyer.fr forward-addr: 193.70.85.11@853 forward-addr: 2001:41d0:302:2200::180@853 # applied-privacy.net forward-addr: 146.255.56.98@853 forward-addr: 2a02:1b8:10:234::2@853 # cleanbrowsing.org: family filter https://cleanbrowsing.org/filters/ forward-addr: 185.228.168.168@853 forward-addr: 185.228.169.168@853 forward-addr: 2a0d:2a00:1::@853 forward-addr: 2a0d:2a00:2::@853 # cz.nic #forward-addr: 193.17.47.1@853 #forward-addr: 185.43.135.1@853 #forward-addr: 2001:148f:ffff::1@853 #forward-addr: 2001:148f:fffe::1@853 # dnsforfamily.com forward-addr: 78.47.64.161@853 forward-addr: 94.130.180.225@853 forward-addr: 2a01:4f8:1c0c:40db::1@853 forward-addr: 2a01:4f8:1c17:4df8::1@853 # he.net #forward-addr: 74.82.42.42@853 #forward-addr: 2001:470:20::2@853 # libredns.gr forward-addr: 116.202.176.26@853 forward-addr: 2a01:4f8:1c0c:8274::1@853 # dns4all forward-addr: 194.0.5.3@853 forward-addr: 194.0.5.64@853 forward-addr: 2001:678:8::3@853 forward-addr: 2001:678:8::64@853 That\u0026rsquo;s for the basic configuration, which should allow you to use unbound with dnsmasq.\nBe sure to restart the unbound service!\nCheck ⇒ If you decide to install the unbound-checkconf tool, now it\u0026rsquo;s time to use it to verify all are correct. If it\u0026rsquo;s well, the tool returns this informational message:\n# unbound-checkconf unbound-checkconf: no errors in /var/lib/unbound/unbound.conf If there are any errors, the tool will tell you where!\n⇒ If you decide to install the unbound-host tool, you can test the connection, for example:\n# unbound-host -vf /var/lib/unbound/root.key com. com. has no address (secure) com. has no IPv6 address (secure) com. has no mail handler record (secure) Do the same for the www.ripe.net, www.afnic.fr, dnssec.cz addresses. The (secure) label guarantess a secure connection.\nControl A brief note about checking that unbound works properly. It\u0026rsquo;s necessary to initialize the settings:\n# unbound-control-setup setup in directory /var/lib/unbound/ generating unbound_server.key Generating RSA private key, 3072 bit long modulus ...............................................................................................................++ ............................................................++ e is 65537 (0x10001) generating unbound_control.key Generating RSA private key, 3072 bit long modulus ........................................................................++ ..................++ e is 65537 (0x10001) create unbound_server.pem (self signed certificate) create unbound_control.pem (signed client certificate) Signature ok subject=/CN=unbound-control Getting CA Private Key Setup success. Certificates created. Enable in unbound.conf file to use Then modify the unbound configuration file to add/uncomment the remote-control section, as follows:\nremote-control: control-enable: yes control-interface: 127.0.0.1 control-interface: ::1 control-port: 8953 control-use-cert: no server-key-file: \u0026#34;/var/lib/unbound/unbound_server.key\u0026#34; server-cert-file: \u0026#34;/var/lib/unbound/unbound_server.pem\u0026#34; control-key-file: \u0026#34;/var/lib/unbound/unbound_control.key\u0026#34; control-cert-file: \u0026#34;/var/lib/unbound/unbound_control.pem\u0026#34; After restarting the service, all that remains is to test it with the unbound-control tool, as in this example:\n# unbound-control -s ::1 status version: 1.17.0 verbosity: 1 threads: 4 modules: 2 [ validator iterator ] uptime: 3482 seconds options: reuseport control unbound (pid 32307) is running... It\u0026rsquo;s possible to find the value of any option by using get_option option followed by the name of the option. Similarly, it\u0026rsquo;s still possible to dump the cache for flow analysis, using the dump_cache option redirected to a file name.\nVoila!\n","content_html":"\u003cdiv class=\"tab-info i-deprecated\"\u003e\u003cstrong\u003eopkg → apk\u003c/strong\u003e\u003c/div\u003e\n\u003cdiv class=\"alert alert-deprecated\" role=\"alert\"\u003e\u003cstrong\u003eSince OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition.\u003c/strong\u003e\u003c/div\u003e\n\n\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eThe purpose is to add unbound to enable the \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eDoT \u003cem\u003e(DNS-over-TCP)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n protocol, slightly modifying dnsmasq, installed by default:\u003c/p\u003e\n\u003cp\u003eReasons are:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eencrypt DNS traffic to improve its confidentiality.\u003c/li\u003e\n\u003cli\u003eprevent DNS leaks and hijacking\u003c/li\u003e\n\u003cli\u003ebypass regional restrictions, or those imposed by your \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eISP \u003cem\u003e(Internet Service Provider)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eInstall packages needed: \u003cstrong\u003eunbound unbound-control luci-app-unbound\u003c/strong\u003e\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# opkg update\n:# opkg install unbound unbound-control luci-app-unbound\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eMay usefull to install too:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eunbound-checkconf\u003c/strong\u003e: to ensure the compliance of the configuration\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eunbound-control-setup\u003c/strong\u003e: allows you to install/create the required certificates for the tool control\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eunbound-host\u003c/strong\u003e: test…\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"dnsmasq\"\u003ednsmasq\u003c/h3\u003e\n\u003cp\u003eFirst, edit the file \u003ccode\u003e/etc/config/dhcp\u003c/code\u003e, to use two options:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eoption noresolv \u0026#39;1\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elist server \u0026#39;127.0.0.1#531\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003ethe first requires that the file \u003ccode\u003e/etc/resolv.conf\u003c/code\u003e not be use\u003c/li\u003e\n\u003cli\u003ethe second requires redirecting DNS requests locally to the selected port, here: \u003ccode\u003e531\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eOf course, these options can be modified directly using LUCI:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u0026lsquo;Resolv and Hosts Files\u0026rsquo; \u0026gt; \u003cstrong\u003eIgnore resolv file\u003c/strong\u003e option\u003c/li\u003e\n\u003cli\u003e\u0026lsquo;General Settings\u0026rsquo; \u0026gt; \u003cstrong\u003eDNS forwardings\u003c/strong\u003e option\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eAbout using \u003ccode\u003euci\u003c/code\u003e, in your terminal:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003euci set dhcp.@dnsmasq[0].noresolv=\u0026#39;1\u0026#39;\nuci set dhcp.@dnsmasq[0].server=\u0026#39;127.0.0.1#531\u0026#39;\nuci commit\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003eRestart your dnsmasq service\u003c/strong\u003e!\u003c/p\u003e\n\u003ch3 id=\"unbound\"\u003eunbound\u003c/h3\u003e\n\u003cp\u003eThe simplest thing to do is to enable Unbound and check \u003cstrong\u003eManual Conf\u003c/strong\u003e option to edit manually the configuration file through LUCI.\u003c/p\u003e\n\u003cp\u003eAdd your networks in the \u003cstrong\u003eTrigger Networks\u003c/strong\u003e option, at least \u003cstrong\u003elan\u003c/strong\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFile configuration : \u003ccode\u003e/var/lib/unbound/unbound.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eThe minimum changes to be made correspond to the following variables:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eserver:\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eport: 531\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003edo-ip4: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003edo-ip6: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003edo-tcp: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ehide-identity: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ehide-version: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eqname-minimisation: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eprefetch: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003errset-roundrobin: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eminimal-responses: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003etls-cert-bundle: \u0026#34;/etc/ssl/certs/ca-certificates.crt\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eRegarding the port number chosen, here \u003ccode\u003e531\u003c/code\u003e: we dont choose \u003ccode\u003e5353\u003c/code\u003e, which is normally reserved for the mdns service. Of course, you can change it, in the dnsmasq configuration; but, be sure to choose it from amont the preferred port numbers. (ie. below \u003ccode\u003e1024\u003c/code\u003e…)\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Be sure to add/modify the \u003ccode\u003eaccess-control\u003c/code\u003e variables to allow only:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eaccess-control: 0.0.0.0/0 refuse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eaccess-control: ::0/0 refuse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eaccess-control: 127.0.0.0/8 allow\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eaccess-control: ::1 allow\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThen declare the LAN\u0026rsquo;s IPv(4|6), or even your Wi-Fi…\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eIt\u0026rsquo;s necessary to modify the \u003ccode\u003eforward-zone\u003c/code\u003e section:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eforward-zone:\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ename: \u0026#34;.\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-tls-upstream: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThen add all IP addresses of the DoT servers; of course, both IPv4 and IPv6 are functional.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 9.9.9.9@853       # Quad9\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 1.1.1.1@853       # Cloudflare\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 149.112.112.112@853       # Quad9 secondaire\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 1.0.0.1@853       # Cloudflare secondaire\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2620:fe::fe@853       # Quad9 / IPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2606:4700:4700::1111@853  # Cloudflare / IPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2606:4700:4700::1001@853  # Cloudflare secondaire / IPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe above example shows how the \u0026ldquo;greats of this world\u0026rdquo; are used.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eHere some interesting alternatives:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# FDN DoT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 80.67.169.12@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 80.67.169.40@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2001:910:800::12@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2001:910:800::40@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# dns.sb\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 185.222.222.222@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 45.11.45.11@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a09::@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a11::@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# dns4eu\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 86.54.11.11@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 86.54.11.211@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a13:1001::86:54:11:11@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a13:1001::86:54:11:211@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# dot.bortzmeyer.fr\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 193.70.85.11@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2001:41d0:302:2200::180@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# applied-privacy.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 146.255.56.98@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a02:1b8:10:234::2@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# cleanbrowsing.org: family filter https://cleanbrowsing.org/filters/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 185.228.168.168@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 185.228.169.168@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a0d:2a00:1::@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a0d:2a00:2::@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# cz.nic\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 193.17.47.1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 185.43.135.1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 2001:148f:ffff::1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 2001:148f:fffe::1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# dnsforfamily.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 78.47.64.161@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 94.130.180.225@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a01:4f8:1c0c:40db::1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a01:4f8:1c17:4df8::1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# he.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 74.82.42.42@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#forward-addr: 2001:470:20::2@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# libredns.gr\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 116.202.176.26@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2a01:4f8:1c0c:8274::1@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# dns4all\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 194.0.5.3@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 194.0.5.64@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2001:678:8::3@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward-addr: 2001:678:8::64@853\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eThat\u0026rsquo;s for the basic configuration, which should allow you to use unbound with dnsmasq.\u003c/p\u003e\n\u003cp\u003eBe sure to restart the unbound service!\u003c/p\u003e\n\u003ch2 id=\"check\"\u003eCheck\u003c/h2\u003e\n\u003cp\u003e⇒ If you decide to install the \u003cstrong\u003eunbound-checkconf\u003c/strong\u003e tool, now it\u0026rsquo;s time to use it to verify all are correct. \u003cbr\u003e\nIf it\u0026rsquo;s well, the tool returns this informational message:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e# unbound-checkconf\nunbound-checkconf: no errors in /var/lib/unbound/unbound.conf\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eIf there are any errors, the tool will tell you where!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ If you decide to install the \u003cstrong\u003eunbound-host\u003c/strong\u003e tool, you can test the connection, for example:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e# unbound-host -vf /var/lib/unbound/root.key com.\ncom. has no address (secure)\ncom. has no IPv6 address (secure)\ncom. has no mail handler record (secure)\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eDo the same for the \u003cstrong\u003e\u003ca href=\"https://www.ripe.net\" rel=\"external\"\u003ewww.ripe.net\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003e\u003ca href=\"https://www.afnic.fr\" rel=\"external\"\u003ewww.afnic.fr\u003c/a\u003e\u003c/strong\u003e, \u003cstrong\u003ednssec.cz\u003c/strong\u003e addresses. \u003cbr\u003e\nThe \u003cstrong\u003e(secure)\u003c/strong\u003e label guarantess a secure connection.\u003c/p\u003e\n\u003ch2 id=\"control\"\u003eControl\u003c/h2\u003e\n\u003cp\u003eA brief note about checking that unbound works properly. \u003cbr\u003e\nIt\u0026rsquo;s necessary to initialize the settings:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e# unbound-control-setup\nsetup in directory /var/lib/unbound/\ngenerating unbound_server.key\nGenerating RSA private key, 3072 bit long modulus\n...............................................................................................................++\n............................................................++\ne is 65537 (0x10001)\ngenerating unbound_control.key\nGenerating RSA private key, 3072 bit long modulus\n........................................................................++\n..................++\ne is 65537 (0x10001)\ncreate unbound_server.pem (self signed certificate)\ncreate unbound_control.pem (signed client certificate)\nSignature ok\nsubject=/CN=unbound-control\nGetting CA Private Key\nSetup success. Certificates created. Enable in unbound.conf file to use\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThen modify the unbound configuration file to add/uncomment the \u003ccode\u003eremote-control\u003c/code\u003e section, as follows:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eremote-control:\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-enable: yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-interface: 127.0.0.1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-interface: ::1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-port: 8953\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-use-cert: no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eserver-key-file: \u0026#34;/var/lib/unbound/unbound_server.key\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eserver-cert-file: \u0026#34;/var/lib/unbound/unbound_server.pem\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-key-file: \u0026#34;/var/lib/unbound/unbound_control.key\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003econtrol-cert-file: \u0026#34;/var/lib/unbound/unbound_control.pem\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eAfter restarting the service\u003c/strong\u003e, all that remains is to test it with the \u003ccode\u003eunbound-control\u003c/code\u003e tool, as in this example:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e# unbound-control -s ::1 status\nversion: 1.17.0\nverbosity: 1\nthreads: 4\nmodules: 2 [ validator iterator ]\nuptime: 3482 seconds\noptions: reuseport control\nunbound (pid 32307) is running...\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eIt\u0026rsquo;s possible to find the value of any option by using \u003ccode\u003eget_option\u003c/code\u003e option followed by the name of the option. \u003cbr\u003e\nSimilarly, it\u0026rsquo;s still possible to dump the cache for flow analysis, using the \u003ccode\u003edump_cache\u003c/code\u003e option redirected to a file name.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003chr\u003e\n","summary":"Add Unbound to OpenWRT using DoT protocol.","tags":["OpenWRT","unbound","DNS","DNSSEC","DoT"],"date_published":"2023-02-19T15:37:43+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2022-10-04:/en/post/openbsd-nsd-dnssec-tlsa","url":"https://it-log.fr.eu.org/en/post/openbsd-nsd-dnssec-tlsa/","title":"OpenBSD: Manage DNS, DNSSEC (to automate TLSA records)","author":{"name":"Stéphane HUC"},"content_text":"Description Since 2018, I asked me about how to manage TLSA records, according to the DANE and DNSSEC protocols, for my DNS. (I wroted one article in french, on March 2018, about creating TLSA records in shell or PHP languages; if you read french, see: DNS: Générer un enregistrement TLSA…)\nSomeone prefers using knot, as package on OpenBSD, because they thing that\u0026rsquo;s complex to manage. Here, we\u0026rsquo;ll see some tips to manage this, an automated way, in shell, on OpenBSD.\nMy DNS service run since 4 years, under OpenBSD native tool named nsd. I manage DNSSEC with ldns tools, a package into ports. In the facts, I use ldnscript tool to create all needed keys and manage DNSSEC.\n⇒ Starting Juin 2022, I decided to switch from RSA to use ECDSA.\nBefore going any further in this direction, let\u0026rsquo;s move on to the installation of the necessary prerequisites necessary:\nInstallation ldnscript To remind myself how to do this, I made myself the following little memo:\nInstall ldns-utils:\n$ doas pkg_add ldns-utils git\nDownload and install ldnscripts\n$ cd /usr/local/src/ $ doas mkdir ldnscripts $ doas chown $USER ldnscripts $ git clone https://framagit.org/22decembre/ldnscripts.git $ cd ldnscripts $ doas make install Configure /etc/ns/ldnscript.conf ; SHA256 est largement suffisant et sécuritaire ALG=ECDSAP256SHA256 NSEC3_ALG=SHA-256 Init the domain name:\n$ doas ldnscript init domain.tld\nYou need to create symbolic link from /usr/bin/dig to /usr/sbin/dig:\n$ doas ln -sf /usr/bin/dig /usr/sbin/dig (without this, the ldnscript tool will not be able to find the binary and therefore will refuse to run, displaying error message).\nConfiguration /etc/monthly.local Into the /etc/monthly.local script, I include this shellcode to create the needed rollover keys:\n### ldnscript printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ ldnscript rollover\u0026#34; /usr/local/sbin/ldnscript rollover all Let\u0026rsquo;s Encrypt Next, the shell script queries the Let\u0026rsquo;s Encrypt services to know if it\u0026rsquo;s necessary to renew the certificates for the domain names I use.\nNormally, one would use the native acme client on OpenBSD, but I had some problems, I decided to switch to certbot.\nTo renew, on shell, that\u0026rsquo;s enough:\n/usr/local/bin/certbot renew --pre-hook \u0026quot;rcctl stop nginx\u0026quot; --post-hook \u0026quot;rcctl start nginx\u0026quot;\n(Yesss, I known; I use nginx, because I prefer… but, I you like httpd, the native webserver, replace by his name service).\nIn fact, this part is not directly related to the DNS(SEC) management. This is important to take carefull because during certificate renewall, it\u0026rsquo;s necessary to regenerate TLSA records. We\u0026rsquo;ll see that later…\nDNS Zone Example Here, for instance, a minimilastic DNS Zone, managed by ns server:\n$TTL 1H $ORIGIN domain.tld. @ IN SOA domain.tld. dns.domain.tld. ( 2022090101 ; 3H ; refresh 1H ; retry 2W ; expire 1H ; negative ) @ IN NS ns1.domain.tld. @ IN NS ns2.domain.tld. @ IN A 46.23.90.29 IN AAAA 2a03:6000:6e65:619::29 ; enregistrement CAA @ IN CAA 0 iodef \u0026#34;mailto:mail@domain.tld\u0026#34; @ IN CAA 0 issue \u0026#34;letsencrypt.org\u0026#34; @ IN CAA 0 issuewild \u0026#34;letsencrypt.org\u0026#34; www IN A 46.23.90.29 IN AAAA 2a03:6000:6e65:619::29 ; TLSA _443._tcp.domain.tld. IN TLSA 3 1 2 5c8fdd68178ce4cd8d88bd90b82a96df41674d555340b88283c24a0b3416aa375144cd6c16a58160ba3b168e59f5003bff656ce67cb24931b462fe4910bd62f5 shell Generate TLSA Record On shellcode, managing a TLSA record is simple — need to use openssl:\nopenssl x509 -noout -pubkey -in \u0026quot;${cert}\u0026quot; | openssl \u0026quot;${command}\u0026quot; -pubin -outform der 2\u0026gt;/dev/null | \u0026quot;${algo}\u0026quot; | tr \u0026quot;a-z\u0026quot; \u0026quot;A-Z\u0026quot;\nExplains :\n⇒ The above command generate a tlsa_cert_associated variable, where:\n$cert: the absolute pathname for the server TLS cert, on the filesystem, about one domain name. $command: the command name used by openssl, either rsa or ec (reciprocally for RSA or ECDSA encryption records). $algo: sha256, or sha512 tool to use. ⇒ Writing the TLSA record is also simple:\ntlsa_record=\u0026quot;_${tls_port}._${tls_proto}.${domain}. IN TLSA ${tlsa_usage} ${tlsa_selector} ${tlsa_method} ${tlsa_cert_associated}\u0026quot;\n${tls_port}: port number of the webservice; by default 443 ${tls_proto}: protocol name used; by default tls ${domain}: the domain name ${tlsa_usage}: the number according the DANE-EE constraint; 3 is recommended by Let\u0026rsquo;s Encrypt, ${tlsa_selector}: the number according to the SPKI selector; 1 is recommended by Let\u0026rsquo;s Encrypt, ${tlsa_method}: the method segun the choosed algorythm; by default: SHA256, which offers currently a secure level of encryption, egually recommended by Let\u0026rsquo;s Encrypt. finishing with the previous tlsa_cert_associated variable. Check TLSA Record Check a TLSA record is more complex; you need to:\n1/ query the DNS server to known the actual TLSA record, with dig tool, for example. 2/ compare with the openssl output; OpenSSL requesting the cert to the webserver, linked to the domain name. queries the DNS server, like: tlsa=\u0026#34;$(dig TLSA _443._tcp.\u0026#34;${domain}\u0026#34; +short)\u0026#34; d_tlsa=\u0026#34;$(echo \u0026#34;${tlsa}\u0026#34; | awk \u0026#39;{ for(i=4;i\u0026lt;=NF;++i) printf \u0026#34;%s\u0026#34;, tolower($i); print \u0026#34;\u0026#34; }\u0026#39;)\u0026#34; use openssl to request TLS certificate used on the webserver: tlsa=\u0026#34;$(echo | openssl s_client -servername \u0026#34;${domain}\u0026#34; -showcerts -connect \u0026#34;${domain}\u0026#34;:443 2\u0026gt;/dev/null | openssl x509 -noout -pubkey | openssl pkey -outform der -pubin 2\u0026gt;/dev/null | openssl dgst -\u0026#34;${algo}\u0026#34; 2\u0026gt;/dev/null )\u0026#34; o_tlsa=\u0026#34;$(echo \u0026#34;${tlsa}\u0026#34; | awk -F\u0026#39;=\u0026#39; \u0026#39;{ print $2 }\u0026#39; | tr -d \u0026#39; \u0026#39;)\u0026#34; Finally, it enoughs to compare both shell variables, d_tlsa and o_tlsa. In normal time, that should be case. Except in case of renewal certificate, which will require the renewal of the TLSA record in the domain name zone, on the DNS server.\nNOTE: if this is not done, a DNS server query on the DNSSEC protocol will generate an error since the TLSA record will not match a freshly used, or renewed TLS cert, which will result in that consequence:\naccess to the server, linked to the target domain name, will be impossible.\nIt will be necessary to generate a new TLSA record corresponding to the renewal of the TLS certificate, then egual to regenerate the signature of the DNSSEC records, for the DNS zone of the target domain.\nShell Scripts Note: Put the tlsa.sh, dns.conf, dns.ksh shell scripts on your home. If you change their location on the filesystem, think to modify your monthly local.\nmonthly.local Here, a monthly.local:\n#!/bin/sh ### ldnscript printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ ldnscript rollover\u0026#34; /usr/local/sbin/ldnscript rollover all ### renew ssl by certbot printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ renew letsencrypt certs\u0026#34; /usr/local/bin/certbot renew --pre-hook \u0026#34;rcctl stop nginx\u0026#34; --post-hook \u0026#34;rcctl start nginx\u0026#34; ### check tlsa records for domain; only for tcp:443 for domain in \u0026#34;sub.domain.tld\u0026#34; \u0026#34;domain.tld\u0026#34; \u0026#34;www.domain.tld\u0026#34; \u0026#34;sub.domain2.tld\u0026#34; \u0026#34;domain2.tld\u0026#34; \u0026#34;www.domain2.tld\u0026#34;; do printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ Test TLSA for ${domain}\u0026#34; /home/-your-user-/dns-tools/tlsa.sh \u0026#34;${domain}\u0026#34; done (…) tlsa.sh Here, the tlsa.sh script:\n#!/bin/sh set -e #set -x ######################################################################## # # Author: Stéphane HUC # mail: devs@stephane-huc.net # gpg:fingerprint: CE2C CF7C AB68 0329 0D20 5F49 6135 D440 4D44 BD58 # # License: BSD Simplified # # Github: # # Date: 2022/07/01 06:45 # ######################################################################## # # Purpose: tool to test TLSA record # - for the geek: DANE-TLSA... # # Needed tools: dig, openssl # # OS: Tested on OpenBSD, Devuan # ######################################################################## ### ## # see: https://www.bortzmeyer.org/monitor-dane.html ## ### ######################################################################## ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; . \u0026#34;${ROOT}/dns.conf\u0026#34; dir_admin=\u0026#34;/home/-your-user-/dns-tools\u0026#34; domain=\u0026#34;$1\u0026#34; ### DO NOT TOUCH! d_tlsa=\u0026#39;\u0026#39;\t# TLSA record by dig o_tlsa=\u0026#39;\u0026#39;\t# TLSA record by openssl tlsa_record=\u0026#39;\u0026#39;\t# TLSA record tlsa_method=2 ######################################################################## #### ## # All needed functions! DO NOT TOUCH-IT! ## ### ######################################################################## byebye() { mssg \u0026#34;KO\u0026#34; \u0026#34;Script stop here!\u0026#34; mssg \u0026#34;KO\u0026#34; \u0026#34;Please, search to understand reasons.\u0026#34; exit 1 } check_uid() { if [ \u0026#34;$(id -u)\u0026#34; -ne 0 ]; then mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: Script not launch with rights admin!\u0026#34; byebye fi } _dig() { tlsa=\u0026#34;$(dig TLSA _443._tcp.\u0026#34;${domain}\u0026#34; +short)\u0026#34; d_tlsa=\u0026#34;$(echo $tlsa | awk \u0026#39;{ for(i=4;i\u0026lt;=NF;++i) printf \u0026#34;%s\u0026#34;, tolower($i); print \u0026#34;\u0026#34; }\u0026#39;)\u0026#34; } _openssl() { tlsa=\u0026#34;$(echo | openssl s_client -servername \u0026#34;${domain}\u0026#34; -showcerts -connect \u0026#34;${domain}\u0026#34;:443 2\u0026gt;/dev/null | openssl x509 -noout -pubkey | openssl pkey -outform der -pubin 2\u0026gt;/dev/null | openssl dgst -\u0026#34;${algo}\u0026#34; 2\u0026gt;/dev/null )\u0026#34; o_tlsa=\u0026#34;$(echo $tlsa | awk -F\u0026#39;=\u0026#39; \u0026#39;{ print $2 }\u0026#39; | tr -d \u0026#39; \u0026#39;)\u0026#34; } mssg() { typeset statut info text statut=\u0026#34;$1\u0026#34; info=\u0026#34;$2\u0026#34; case \u0026#34;${statut}\u0026#34; in \u0026#34;KO\u0026#34;) text=\u0026#34;[ ${red}${statut}${neutral} ] ${info}\u0026#34; ;; \u0026#34;OK\u0026#34;) text=\u0026#34;[ ${green}${statut}${neutral} ] ${info}\u0026#34; ;; #*) mssg=\u0026#34;${text}\u0026#34; ;; esac printf \u0026#34;%s \\n\u0026#34; \u0026#34;${text}\u0026#34; unset info statut text } new_tlsa() { cert=\u0026#34;/etc/letsencrypt/live/${domain}/cert.pem\u0026#34; case \u0026#34;${le_key_type}\u0026#34; in \u0026#34;ecdsa\u0026#34;) tlsa_cert_associated=\u0026#34;$(openssl x509 -noout -pubkey -in \u0026#34;${cert}\u0026#34; | openssl ec -pubin -outform der 2\u0026gt;/dev/null | \u0026#34;${algo}\u0026#34;)\u0026#34; ;; \u0026#34;rsa\u0026#34;) tlsa_cert_associated=\u0026#34;$(openssl x509 -noout -pubkey -in \u0026#34;${cert}\u0026#34; | openssl rsa -pubin -outform der 2\u0026gt;/dev/null | \u0026#34;${algo}\u0026#34;)\u0026#34; ;; esac tlsa_record=\u0026#34;_${tls_port}._${tls_proto}.${domain}. IN TLSA ${tlsa_usage} ${tlsa_selector} ${tlsa_method} ${tlsa_cert_associated}\u0026#34; unset tlsa_cert_associated } ######################################################################## #### ## # Execution ## ### ######################################################################## if [ -z \u0026#34;${domain}\u0026#34; ]; then printf \u0026#39;%s\\n\u0026#39; \u0026#34;[ KO ] Script stops here; no domain!\u0026#34;; exit; fi _dig _openssl if [ \u0026#34;${d_tlsa}\u0026#34; = \u0026#34;${o_tlsa}\u0026#34; ]; then mssg \u0026#34;OK\u0026#34; \u0026#34;Similar TLSA records! :D\u0026#34; else mssg \u0026#34;KO\u0026#34; \u0026#34;There seems to be a problem with the TLSA records of the domain: ${domain}!\u0026#34; printf \u0026#39;%s\\n\u0026#39; \u0026#34;Have you renew recently the TLS certs for the domain? If yes, change the TLSA record into the DNS zone relevent!\u0026#34; printf \u0026#39;%s\\n%s\\n\u0026#39; \u0026#34;⇒ Perhaps, the dns.sh script shell can help you. ;-)\u0026#34; check_uid printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ Display new TLSA record:\u0026#34; new_tlsa printf \u0026#39;%s\\n%s\\n\u0026#39; \u0026#34;Add/modify tlsa into your DNS zone for ${domain}: \u0026#34; \u0026#34;${tlsa_record}\u0026#34; printf \u0026#39;%s\\n\u0026#39; \u0026#34;⇒ Modify TLSA record into the domain zone for ${domain}\u0026#34; \u0026#34;${dir_admin}\u0026#34;/dns.ksh tlsa \u0026#34;${domain}\u0026#34; fi ATTENTION: You need to modify the dir_admin variable, at the top of script!\nExplains:\nit call the dns.conf file config; see below, and, if the TLSA records does not match, it call the pdksh dns.ksh script, with tlsa and targeted domain name as arguments. dns.conf Here, the file config — needed for both dns.ksh and tlsa.sh shell scripts:\n######################################################################## # # Author: Stéphane HUC # mail: devs@stephane-huc.net # gpg:fingerprint: CE2C CF7C AB68 0329 0D20 5F49 6135 D440 4D44 BD58 # # License: BSD Simplified # # Github: https://framagit.org/hucste/AH.git # # Date: 2022/06/01 07:20 # ######################################################################## ### ## # Config file to dns.ksh script ## ### ######################################################################## ### Algorithm ## values: sha256, sha512; choose-it segun TLSA Method algo=\u0026#34;sha256\u0026#34; ### SOA Serial type ## values: date, timestamp ## DNS recommandation: prefer date SOA_serial_type=\u0026#34;date\u0026#34; ### Port number tls_port=443 ### Protocols ## values: stcp, tcp, udp tls_proto=\u0026#34;tcp\u0026#34; ### TLSA ## Lets Encrypt Recommandation; ## see: https://community.letsencrypt.org/t/please-avoid-3-0-1-and-3-0-2-dane-tlsa-records-with-le-certificates/7022 ## usage: Lets Encrypt recommands 3, at least 2 ## values: 0 =\u0026gt; 3; or (PKIX-TA, PKIX-EE, DANE-TA, DANE-EE; respectivly: 0 -\u0026gt; 3) tlsa_usage=3 ## selector: Lets Encrypt recommands 1 ## values: 0 or 1; or (CERT, SPKI; respectively: O or 1) tlsa_selector=1 ## method: Lets Encrypt recommands 1 ## values: 0 =\u0026gt; 2; or (FULL, SHA256, SHA512; respectively: 0 -\u0026gt; 2) # this change segun algo tlsa_method=1 ### Key Type Letsencrypt ## rsa or ecdsa ## if ecdsa, specify elliptic curve: secp256r1, secp384r1, secp512r1 (256 is enough) le_key_type=ecdsa le_curve=secp256r1 I personally choose to use:\nthe sha512 algorythm the ecdsa to use the ec command with openssl. Of course, it\u0026rsquo;s possible to use rsa; in this case, those shell scripts will not use the $le_curve variable. dns.ksh This complex and large script is available to:\ngenerate DNSSEC signs for the DNS zone. modify TLSA records and regenerate DNSSEC signs; in this case: find the SOA record create a new file for the DNS zone and backup the actual if the new file is available, the script will write: a new SOA record replace the oldier TLSA record with the new try to sign the DNS zone with the DNSSEC protocol: if succeeded, it destroy the oldier DNS zone file, if it fails, it warns, stops the execution and this case you need to rename manually the backuped file.\nYou can modify the debug variable to 1, and relaunch the script; it logs the differents steps. This helps to review and analyse why… Maybe, ./dns.ksh help will show you more information.\n#!/bin/ksh set -e #set -x ################################################################################ # # Author: Stéphane HUC # mail: devs@stephane-huc.net # gpg:fingerprint: CE2C CF7C AB68 0329 0D20 5F49 6135 D440 4D44 BD58 # # License: BSD Simplified # # Github: # # Date: 2022/06/01 07:25 # ################################################################################ # # Purpose: to add a TLSA Record into DNS zone, segun your cert TLS (LE) # - for the geek: DANE-TLSA... #### IMPORTANT: recreate your TLSA Record after (re?)new cert... # # Needed tools: nsd* and ldnscript ## ldnscript is a tool to sign dns zone. (DNSSEC) ## https://framagit.org/22decembre/ldnscripts.git # # OS: Tested on OpenBSD # ################################################################################ ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; . \u0026#34;${ROOT}/dns.conf\u0026#34; ################################################################################ ### ## # DONT TOUCH THOSES VARIABLES! ## ### ################################################################################ debug=0 dir_le=\u0026#34;/etc/letsencrypt/live\u0026#34; dir_ns_cfg=\u0026#34;/etc/ns\u0026#34; # folder config ns dir_sbin=\u0026#34;/usr/local/sbin\u0026#34; log=\u0026#34;${ROOT}/dns-script.log\u0026#34; nsd_cfg=\u0026#34;/var/nsd/etc/nsd.conf\u0026#34; timestamp=\u0026#34;$(date +%s)\u0026#34; today=\u0026#34;$(date +\u0026#34;%Y%m%d\u0026#34;)\u0026#34; server=\u0026#34;nsd\u0026#34; SOA_ns=\u0026#34;\u0026#34; tlsa_record=\u0026#34;\u0026#34; set -A tlsa_records\t# if X509 DNS Alternative Names \u0026gt; 1 set -A tlsa_method_names -- \u0026#34;FULL\u0026#34; \u0026#34;SHA256\u0026#34; \u0026#34;SHA512\u0026#34; set -A tlsa_selector_names -- \u0026#34;CERT\u0026#34; \u0026#34;SPKI\u0026#34; set -A tlsa_usage_names -- \u0026#34;PKIX-TA\u0026#34; \u0026#34;PKIX-EE\u0026#34; \u0026#34;DANE-TA\u0026#34; \u0026#34;DANE-EE\u0026#34; NB_PARAMS=\u0026#34;$#\u0026#34; set -A PARAMS -- \u0026#34;$@\u0026#34; ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; if [ -z \u0026#34;${PARAMS[0]}\u0026#34; ]; then MENU_CHOICE=\u0026#34;help\u0026#34; else PARAMS[0]=\u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${PARAMS[0]}\u0026#34; | tr -s \u0026#34;[:upper:]\u0026#34; \u0026#34;[:lower:]\u0026#34;)\u0026#34; MENU_CHOICE=${PARAMS[0]} fi [ -n \u0026#34;${PARAMS[1]}\u0026#34; ] \u0026amp;\u0026amp; domain=\u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${PARAMS[1]}\u0026#34; | tr -s \u0026#34;[:upper:]\u0026#34; \u0026#34;[:lower:]\u0026#34;)\u0026#34; ################################################################################ #### ## # All needed functions! DO NOT TOUCH-IT! ## ### ################################################################################ _add_tlsa() { check_var_algo check_var_soa_serial_type check_var_tls_port check_var_tls_proto check_tlsa_methods check_tlsa_selectors check_tlsa_usages get_soa_ns danefile=\u0026#34;${zonefile}.dane\u0026#34; newzonefile=\u0026#34;${zonefile}.${today}\u0026#34; oldzonefile=\u0026#34;${zonefile}.${OLD_SOA_sn}\u0026#34; create_new_filezone if [ -f \u0026#34;${newzonefile}\u0026#34; ]; then write_soa_serial_number build_tlsa_record write_tlsa_record mv_new_file_zone if _resign; then del_old_zonefile; fi fi unset danefile newzonefile oldzonefile } build_needed_variables() { check_var_domain printf \u0026#39;%s\\n\u0026#39; \u0026#34;*** Build needed variables:\u0026#34; # build cert variable if menu \u0026#39;tlsa\u0026#39; if [ \u0026#34;${MENU_CHOICE}\u0026#34; = \u0026#34;tlsa\u0026#34; ]; then cert=\u0026#34;${dir_le}/${domain}/cert.pem\u0026#34; if [ ! -f \u0026#34;${cert}\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;*** It seems cert file not exists!\u0026#34; byebye else printf \u0026#39;%s\\n\u0026#39; \u0026#34;cert: ${cert}\u0026#34; fi fi # build zonedir and zonefile variables zonedir=\u0026#34;$(awk -F \u0026#39;\u0026#34;\u0026#39; \u0026#39;/zonesdir/ { print substr($2,-1) }\u0026#39; \u0026#34;${nsd_cfg}\u0026#34;)\u0026#34; if [ -z \u0026#34;${zonedir}\u0026#34; ]; then zonedir=\u0026#34;/var/nsd/zones/\u0026#34;; fi printf \u0026#39;%s\\n\u0026#39; \u0026#34;zonedir: ${zonedir}\u0026#34; #zonefile=\u0026#34;$(awk -F \u0026#39;\u0026#34;\u0026#39; \u0026#39;/zonefile: \u0026#34;[a-z]*\\/\u0026#39;\u0026#34;${domain}\u0026#34;\u0026#39;\u0026#34;/ { print substr($2, -1) }\u0026#39; \u0026#34;${nsd_cfg}\u0026#34;)\u0026#34; #if [ \u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${zonefile}\u0026#34; | awk -F\u0026#39;/\u0026#39; \u0026#39;{ print $1}\u0026#39;)\u0026#34; == \u0026#34;signed\u0026#34; ]; then ##zonefilesigned=$zonefile #zonefile=\u0026#34;$(find \u0026#34;${dir_ns_cfg}\u0026#34; -name \u0026#34;${domain}\u0026#34;)\u0026#34; #if [ -z \u0026#34;${zonefile}\u0026#34; ]; then zonefile=\u0026#34;$(find \u0026#34;${zonedir}\u0026#34; -name \u0026#34;${domain}\u0026#34;)\u0026#34;; fi #if [ -z \u0026#34;${zonefile}\u0026#34; ]; then #display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: It seems zonefile for domain: \u0026#39;${domain}\u0026#39; not exists!\u0026#34; #byebye #fi #else #zonefile=\u0026#34;${zonedir}${zonefile}\u0026#34; #fi zonefile=\u0026#34;${dir_ns_cfg}/${domain}\u0026#34; printf \u0026#39;%s\\n\u0026#39; \u0026#34;zonefile: ${zonefile}\u0026#34; } build_tlsa_record() { # get TLSA by reading cert pem case \u0026#34;${le_key_type}\u0026#34; in \u0026#34;ecdsa\u0026#34;) command=\u0026#34;ec\u0026#34; ;; \u0026#34;rsa\u0026#34;) command=\u0026#34;rsa\u0026#34; ;; esac tlsa_cert_associated=\u0026#34;$(openssl x509 -noout -pubkey -in \u0026#34;${cert}\u0026#34; | openssl \u0026#34;${command}\u0026#34; -pubin -outform der 2\u0026gt;/dev/null | \u0026#34;${algo}\u0026#34;)\u0026#34; _log \u0026#34;TLSA Cert Associated: ${tlsa_cert_associated}\u0026#34; unset command if [ -z \u0026#34;${tlsa_cert_associated}\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: TLSA Cert Associated could not generated!\u0026#34; byebye else # rebuild tlsa method segun algo choosed; possible: 0 (no match), 1 (sha256), 2 (sha512) case \u0026#34;${algo}\u0026#34; in \u0026#34;sha256\u0026#34;) tlsa_method=1 ;; \u0026#34;sha512\u0026#34;) tlsa_method=2 ;; *) tlsa_method=0 ;; esac if [ \u0026#34;${tls_port}\u0026#34; = \u0026#34;443\u0026#34; ] \u0026amp;\u0026amp; [ \u0026#34;${tls_proto}\u0026#34; = \u0026#34;tcp\u0026#34; ]; then get_dns_alternative_names count=\u0026#34;${#domains[@]}\u0026#34; if [ \u0026#34;${count}\u0026#34; -eq 1 ]; then set_tlsa_record\telse set_tlsa_records fi fi fi unset tlsa_cert_associated } byebye() { display_mssg \u0026#34;KO\u0026#34; \u0026#34;Script stop here!\u0026#34; display_mssg \u0026#34;KO\u0026#34; \u0026#34;Please, search to understand reasons.\u0026#34; exit 1 } check_domain_name() { pattern=\u0026#34;^(([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\\-]*[a-zA-Z0-9])\\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\\-]*[A-Za-z0-9])$\u0026#34; # like RFC 1123 if [ ${#domain} -gt 67 ]; then # Larg domain name \u0026lt;= 67 display_mssg \u0026#34;KO\u0026#34; \u0026#34;Error: Domain Length: ${domain}; \u0026gt;= 67 carachters!\u0026#34; byebye fi if printf \u0026#39;%s\\n\u0026#39; \u0026#34;${domain}\u0026#34; | grep -Eio \u0026#34;${pattern}\u0026#34;; then display_mssg \u0026#34;OK\u0026#34; \u0026#34;Domain Name: ${domain} is valid!\u0026#34; sleep 1 else display_mssg \u0026#34;KO\u0026#34; \u0026#34;Error: Bad Domain Name: ${domain}\u0026#34; byebye fi unset pattern } check_tlsa_methods() { case \u0026#34;${tlsa_method}\u0026#34; in 0|\u0026#34;FULL\u0026#34;) tlsa_method=0 ;; 1|\u0026#34;SHA256\u0026#34;) tlsa_method=1 ;; 2|\u0026#34;SHA512\u0026#34;)\ttlsa_method=2 ;; *) display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ The TLSA Method: not correctly configurated!\u0026#34; byebye :: esac _log \u0026#34;TLSA Method: ${tlsa_method}\u0026#34; } check_tlsa_selectors() { case \u0026#34;${tlsa_selector}\u0026#34; in 0|\u0026#34;CERT\u0026#34;) tlsa_selector=0 ;; 1|\u0026#34;SPKI\u0026#34;) tlsa_selector=1 ;; *) display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ The TLSA Selector: not correctly configurated!\u0026#34; byebye ;; esac _log \u0026#34;TLSA Selector: ${tlsa_selector}\u0026#34; } check_tlsa_usages() { case \u0026#34;${tlsa_usage}\u0026#34; in 0|\u0026#34;PKIX-TA\u0026#34;) tlsa_usage=0 ;; 1|\u0026#34;PKIX-EE\u0026#34;) tlsa_usage=1 ;; 2|\u0026#34;DANE-TA\u0026#34;)\ttlsa_usage=2 ;; 3|\u0026#34;DANE-EE\u0026#34;)\ttlsa_usage=3 ;; *) display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ The TLSA Usage: not correctly configurated!\u0026#34; byebye ;; esac _log \u0026#34;TLSA Usage: ${tlsa_usage}\u0026#34; } check_uid() { if [ \u0026#34;$(id -u)\u0026#34; -ne 0 ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: Script not launch with rights admin!\u0026#34; byebye fi } check_var_algo () { if [ \u0026#34;${algo}\u0026#34; != \u0026#34;sha256\u0026#34; ] \u0026amp;\u0026amp; [ \u0026#34;${algo}\u0026#34; != \u0026#34;sha512\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ Algorythm: not correctly configurated!\u0026#34; byebye fi _log \u0026#34;Algo: ${algo}\u0026#34; } check_var_domain() { if [ -z \u0026#34;${domain}\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;*** It seems fault informations!\u0026#34; help byebye fi _log \u0026#34;Domain: ${domain}\u0026#34; } check_var_soa_serial_type() { if [ \u0026#34;${SOA_serial_type}\u0026#34; != \u0026#34;date\u0026#34; ] \u0026amp;\u0026amp; [ \u0026#34;${SOA_serial_type}\u0026#34; != \u0026#34;timestamp\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ SOA Serial Type: not correctly configurated!\u0026#34; byebye fi _log \u0026#34;SOA Serial Type: ${SOA_serial_type}\u0026#34; } check_var_tls_port(){ if [ \u0026#34;${tls_port}\u0026#34; -lt 0 ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ TLS port: not correctly configurated!\u0026#34; byebye fi _log \u0026#34;TLS port: ${tls_port}\u0026#34; } check_var_tls_proto() { if [ \u0026#34;${tls_proto}\u0026#34; != \u0026#34;sctp\u0026#34; ] \u0026amp;\u0026amp; [ \u0026#34;${tls_proto}\u0026#34; != \u0026#34;tcp\u0026#34; ] \u0026amp;\u0026amp; [ \u0026#34;${tls_proto}\u0026#34; != \u0026#34;tcp\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ TLS proto: not correctly configurated!\u0026#34; byebye fi _log \u0026#34;TLS proto: ${tls_proto}\u0026#34; } checkconf() { nsd-checkconf \u0026#34;${nsd_cfg}\u0026#34; } checkzone() { nsd-checkzone \u0026#34;${domain}\u0026#34; \u0026#34;${zonefile}\u0026#34; } confirm () { read -r response?\u0026#34;${1} [y|n] \u0026#34; case \u0026#34;${response}\u0026#34; in # \u0026#39;o\u0026#39;, \u0026#39;O\u0026#39;: Oui and not 0! y|Y|o|O|1) true ;; *) false ;; esac unset response } create_new_filezone() { cp \u0026#34;${zonefile}\u0026#34; \u0026#34;${newzonefile}\u0026#34; } del_old_zonefile() { if [ -f \u0026#34;${oldzonefile}\u0026#34; ]; then rm -fP \u0026#34;${oldzonefile}\u0026#34; fi } display_mssg() { typeset statut info text statut=\u0026#34;$1\u0026#34; info=\u0026#34;$2\u0026#34; case \u0026#34;${statut}\u0026#34; in \u0026#34;KO\u0026#34;) text=\u0026#34;[ ${red}${statut}${neutral} ] ${info}\u0026#34; ;; \u0026#34;OK\u0026#34;) text=\u0026#34;[ ${green}${statut}${neutral} ] ${info}\u0026#34; ;; #*) mssg=\u0026#34;${text}\u0026#34; ;; esac printf \u0026#34;%s \\n\u0026#34; \u0026#34;${text}\u0026#34; unset info statut text } get_dns_alternative_names() { # get \u0026#34;X509 DNS Alternative Names\u0026#34; characters domains=\u0026#34;$(echo | openssl x509 -text -noout -in \u0026#34;${cert}\u0026#34; | awk -F \u0026#39;,\u0026#39; \u0026#39;/DNS:/ { for(i=1;i\u0026lt;NF;i++) { p=match($i,\u0026#34;:\u0026#34;); print substr($i,p+1) }}\u0026#39;)\u0026#34; # convert into array; no double-quotes, else not run! set -A domains -- ${domains[@]} printf \u0026#39;%s\\n\u0026#39; \u0026#34;domains: ${domains[*]}\u0026#34; _log \u0026#34;domains: ${domains[*]}\u0026#34; } get_soa_ns() { OLD_SOA_sn=\u0026#34;$(grep -A1 \u0026#34;SOA\u0026#34; \u0026#34;${zonefile}\u0026#34; | tail -n1 | awk -F \u0026#39; \u0026#39; \u0026#39;{ print $1 }\u0026#39;)\u0026#34; _log \u0026#34;Old SOA Serial Number: ${OLD_SOA_sn}!\u0026#34; } get_soa_serial_number() { OLD_SOA_sn=\u0026#34;$(printf \u0026#39;%s\\n\u0026#39; \u0026#34;${line}\u0026#34; | awk -F \u0026#39; \u0026#39; \u0026#39;{ print $1 }\u0026#39;)\u0026#34; _log \u0026#34;OLD SOA Serial Number: ${OLD_SOA_sn}\u0026#34; } help() { printf \u0026#39;%s\\n\u0026#39; \u0026#34; $0 sign domain # to sign a domain $0 tlsa domain # to add a tlsa record into domain zone ---- when use tlsa, this script will resign the domain zone... \u0026#34; } init_zone() { \u0026#34;${dir_sbin}\u0026#34;/ldnscript init \u0026#34;${domain}\u0026#34; } in_array() { local i=0 need=\u0026#34;$1\u0026#34; IFS=\u0026#34; \u0026#34;; shift; set -A array -- $* count=\u0026#34;${#array[@]}\u0026#34; while [ $i -le $count ]; do if [ \u0026#34;${array[$i]}\u0026#34; = \u0026#34;${need}\u0026#34; ]; then return 0; fi # true #let \u0026#34;i=$i+1\u0026#34; (( i=i+1 )) done return 1 unset i need IFS array } _log() { if [ \u0026#34;${debug}\u0026#34; -eq 1 ]; then printf \u0026#39;%s\\n\u0026#39; \u0026#34;$1\u0026#34; \u0026gt;\u0026gt; \u0026#34;${log}\u0026#34;; fi } main() { check_uid verify_need_softs build_needed_variables check_domain_name case \u0026#34;${MENU_CHOICE}\u0026#34; in \u0026#34;help\u0026#34;) help ;; \u0026#34;sign\u0026#34;) _resign ;; \u0026#34;tlsa\u0026#34;) _add_tlsa ;; *) display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: this option ${MENU_CHOICE} is not exists!\u0026#34; help byebye ;; esac } mv_new_file_zone() { if [ -f \u0026#34;${newzonefile}\u0026#34; ]; then mv \u0026#34;${zonefile}\u0026#34; \u0026#34;${oldzonefile}\u0026#34; mv \u0026#34;${newzonefile}\u0026#34; \u0026#34;${zonefile}\u0026#34; fi } _resign() { if checkzone \u0026amp;\u0026amp; checkconf; then display_mssg \u0026#34;OK\u0026#34; \u0026#34;file config nsd and zone ${domain} are good! :D\u0026#34; sign_zone else display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: it exists a problem with file config nsd or zone ${domain}\u0026#34; byebye fi } restart_server() { printf \u0026#39;%s\\n\u0026#39; \u0026#34;=\u0026gt; Restart Server: \u0026#34; stop_server start_server status_server } set_soa_serial_number() { case \u0026#34;${SOA_serial_type}\u0026#34; in \u0026#34;date\u0026#34;) SOA_date=\u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${OLD_SOA_sn}\u0026#34; | awk \u0026#39;{print substr($0, 0, 8)}\u0026#39;)\u0026#34;; SOA_number=\u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${OLD_SOA_sn}\u0026#34; | awk \u0026#39;{print substr($0, 9)}\u0026#39;)\u0026#34;; if [ \u0026#34;${SOA_date}\u0026#34; == \u0026#34;${today}\u0026#34; ]; then #let SOA_number=$SOA_number+1 (( SOA_number=${SOA_number}+1 )) || true if [ \u0026#34;${SOA_number}\u0026#34; -lt 10 ]; then SOA_number=\u0026#34;0${SOA_number}\u0026#34;; fi SOA_sn=\u0026#34;${SOA_date}${SOA_number}\u0026#34; else SOA_sn=\u0026#34;${today}01\u0026#34; fi ;; \u0026#34;timestamp\u0026#34;) SOA_sn=\u0026#34;${timestamp}\u0026#34; ;; *) display_mssg \u0026#34;KO\u0026#34; \u0026#34;Invalid SOA Serial Type!\u0026#34; byebye ;; esac _log \u0026#34;New SOA Serial Number: ${SOA_sn}!\u0026#34; } set_tlsa_record() { # build tlsa record tlsa_records[0]=\u0026#34;_${tls_port}._${tls_proto}.${domains[0]}. IN TLSA ${tlsa_usage} ${tlsa_selector} ${tlsa_method} ${tlsa_cert_associated}\u0026#34; _log \u0026#34;TLSA Record: ${tlsa_records[0]}\u0026#34; } set_tlsa_records() { # do not use domain variable here i=0 for dom in \u0026#34;${domains[@]}\u0026#34;; do tlsa_records[$i]=\u0026#34;_${tls_port}._${tls_proto}.${dom}. IN TLSA ${tlsa_usage} ${tlsa_selector} ${tlsa_method} ${tlsa_cert_associated}\u0026#34; (( i=i+1 )) done unset i dom _log \u0026#34;TLSA Records: ${tlsa_records[*]}\u0026#34; } sign_zone() { \u0026#34;${dir_sbin}\u0026#34;/ldnscript signing \u0026#34;${domain}\u0026#34; } start_server() { printf \u0026#39;%s\\n\u0026#39; \u0026#34;Start serveur: ${server}\u0026#34; rcctl start \u0026#34;${server}\u0026#34; sleep 1s } status_server() { printf \u0026#39;%s\\n\u0026#39; \u0026#34;Check serveur: ${server}\u0026#34; rcctl check \u0026#34;${server}\u0026#34; } stop_server() { printf \u0026#39;%s\\n\u0026#39; \u0026#34;Stop serveur: ${server}\u0026#34; rcctl stop \u0026#34;${server}\u0026#34; sleep 1s } verify_need_softs() { if [ ! -f \u0026#34;${dir_sbin}/ldnscript\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: ldnscript seems not install!\u0026#34; byebye elif [ ! -x \u0026#34;${dir_sbin}/ldnscript\u0026#34; ]; then display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: ldnscript is not executable!\u0026#34; byebye fi } write_soa_serial_number() { set_soa_serial_number if sed -i -e \u0026#34;s#\\(.*\\)${OLD_SOA_sn} \\;#\\1${SOA_sn} \\;#\u0026#34; \u0026#34;${newzonefile}\u0026#34;; then _log \u0026#34;SOA serial number changed!\u0026#34; else display_mssg \u0026#34;KO\u0026#34; \u0026#34;/!\\ Script cant change SOA serial number!\u0026#34; fi } write_tlsa_record() { if [ ! -f \u0026#34;${danefile}\u0026#34; ]; then touch \u0026#34;${danefile}\u0026#34;; fi i=0 # add tlsa records into dns zone for tlsa_record in \u0026#34;${tlsa_records[@]}\u0026#34;; do dom=\u0026#34;${domains[$i]}\u0026#34; _log \u0026#34;domain: $dom\u0026#34; ### /!\\ ERROR with $domain /!\\ if sed -i -e \u0026#34;s#_${tls_port}._${tls_proto}.${dom}. IN TLSA\\(.*\\)#${tlsa_record}#\u0026#34; \u0026#34;${newzonefile}\u0026#34;; then _log \u0026#34;TLSA Record rewrited!\u0026#34; else printf \u0026#39;%s\\n\u0026#39; \u0026#34;${tlsa_record}\u0026#34; \u0026gt;\u0026gt; \u0026#34;${newzonefile}\u0026#34; _log \u0026#34;TLSA Record added!\u0026#34; fi (( i=i+1 )) # add record in first line into dane file printf \u0026#39;%s\\n\u0026#39; \u0026#34;${timestamp}:${tlsa_record}\u0026#34; \u0026gt;\u0026gt; \u0026#34;${danefile}\u0026#34; _log \u0026#34;${timestamp}:${tlsa_record}\u0026#34; unset dom done unset i tlsa_record } ################################################################################ main EOD End Of Documentation\nVoila; this is my process to manage my DNS zones, with DNSSEC for the TLSA records.\nFrom a large and complex process, I can manage simply with the two useful commands:\nsign my DNS zones by DNSSEC: ./dns.ksh sign domain check the TLSA records, at any time, and if necessary, regenerate them: ./tlsa.sh domain But if you have understood, the monthly cron takes care of it all and makes the appropriate report, so I know how it was executed.\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eSince 2018, I asked me about how to manage TLSA records, according to the\nDANE and DNSSEC protocols, for my DNS.\n\u003cem\u003e(I wroted one article in french, on March 2018, about creating TLSA records\nin shell or PHP languages; if you read french, see:\n\u003ca href=\"/fr/post/generer-enregistrement-tlsa/\"\u003eDNS: Générer un enregistrement TLSA\u003c/a\u003e…)\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eSomeone prefers using \u003cstrong\u003eknot\u003c/strong\u003e, as package on OpenBSD, because they thing\nthat\u0026rsquo;s complex to manage. Here, we\u0026rsquo;ll see some tips to manage this,\nan automated way, in shell, on OpenBSD.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eMy DNS service run since 4 years, under OpenBSD native tool named \u003cstrong\u003ensd\u003c/strong\u003e.\nI manage DNSSEC with \u003cstrong\u003e\u003ca href=\"https://openports.pl/path/net/ldns,-utils\" rel=\"external\"\u003eldns\u003c/a\u003e\u003c/strong\u003e\ntools, a package into ports. \u003cbr\u003e\nIn the facts, I use \u003cstrong\u003e\u003ca href=\"https://www.22decembre.eu/en/2017/11/01/ldnscripts/\" rel=\"external\"\u003eldnscript\u003c/a\u003e\u003c/strong\u003e\ntool to create all needed keys and manage DNSSEC.\u003c/p\u003e\n\u003cp\u003e⇒ Starting Juin 2022, I decided to switch from RSA to use ECDSA.\u003c/p\u003e\n\u003cp\u003eBefore going any further in this direction, let\u0026rsquo;s move on to the installation\nof the necessary prerequisites necessary:\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003ch3 id=\"ldnscript\"\u003eldnscript\u003c/h3\u003e\n\u003cp\u003eTo remind myself how to do this, I made myself the following little memo:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\n\u003cp\u003eInstall ldns-utils:\u003cbr\u003e\n\u003ccode\u003e$ doas pkg_add ldns-utils git\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDownload and install ldnscripts\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd /usr/local/src/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ doas mkdir ldnscripts\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ doas chown \u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e ldnscripts\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ git clone https://framagit.org/22decembre/ldnscripts.git\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd ldnscripts\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ doas make install\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003col start=\"3\"\u003e\n\u003cli\u003eConfigure /etc/ns/ldnscript.conf\u003c/li\u003e\n\u003c/ol\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e; SHA256 est largement suffisant et sécuritaire\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eALG\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003eECDSAP256SHA256 \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eNSEC3_ALG\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003eSHA-256\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003col start=\"4\"\u003e\n\u003cli\u003e\n\u003cp\u003eInit the domain name:\u003cbr\u003e\n\u003ccode\u003e$ doas ldnscript init domain.tld\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eYou need to create symbolic link from \u003ccode\u003e/usr/bin/dig\u003c/code\u003e to \u003ccode\u003e/usr/sbin/dig\u003c/code\u003e:\u003cbr\u003e\n\u003ccode\u003e$ doas ln -sf /usr/bin/dig /usr/sbin/dig\u003c/code\u003e \u003cbr\u003e\n\u003cem\u003e(without this, the \u003ccode\u003eldnscript\u003c/code\u003e tool will not be able to find the binary\nand therefore will refuse to run, displaying error message)\u003c/em\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"etcmonthlylocal\"\u003e/etc/monthly.local\u003c/h3\u003e\n\u003cp\u003eInto the \u003ccode\u003e/etc/monthly.local\u003c/code\u003e script, I include this shellcode to create\nthe needed rollover keys:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### ldnscript\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ ldnscript rollover\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/usr/local/sbin/ldnscript rollover all\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"lets-encrypt\"\u003eLet\u0026rsquo;s Encrypt\u003c/h4\u003e\n\u003cp\u003eNext, the shell script queries the Let\u0026rsquo;s Encrypt services to know if it\u0026rsquo;s\nnecessary to renew the certificates for the domain names I use.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eNormally, one would use the native \u003ccode\u003eacme\u003c/code\u003e client on OpenBSD, but I\nhad some problems, I decided to switch to \u003ccode\u003ecertbot\u003c/code\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eTo renew, on shell, that\u0026rsquo;s enough:\u003cbr\u003e\n\u003ccode\u003e/usr/local/bin/certbot renew --pre-hook \u0026quot;rcctl stop nginx\u0026quot; --post-hook \u0026quot;rcctl start nginx\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e(Yesss, I known; I use nginx, because I prefer… but, I you like \u003cstrong\u003ehttpd\u003c/strong\u003e,\nthe native webserver, replace by his name service).\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eIn fact, this part is not directly related to the DNS(SEC) management.\nThis is important to take carefull because during certificate renewall,\nit\u0026rsquo;s necessary to regenerate TLSA records. \u003cem\u003eWe\u0026rsquo;ll see that later…\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"dns-zone-example\"\u003eDNS Zone Example\u003c/h3\u003e\n\u003cp\u003eHere, for instance, a minimilastic DNS Zone, managed by \u003cstrong\u003ens\u003c/strong\u003e server:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e$TTL 1H\n$ORIGIN domain.tld.\n@   IN  SOA domain.tld. dns.domain.tld. (\n    2022090101 ;\n    3H ; refresh\n    1H ; retry\n    2W ; expire\n    1H ; negative\n)\n                    \n@   IN NS   ns1.domain.tld.\n@   IN NS   ns2.domain.tld.\n\n@   IN A    46.23.90.29\n    IN AAAA 2a03:6000:6e65:619::29\n\n; enregistrement CAA\n@    IN CAA  0 iodef \u0026#34;mailto:mail@domain.tld\u0026#34;\n@    IN CAA  0 issue \u0026#34;letsencrypt.org\u0026#34;\n@    IN CAA  0 issuewild \u0026#34;letsencrypt.org\u0026#34;\n\nwww IN A    46.23.90.29\n    IN AAAA 2a03:6000:6e65:619::29\n\n; TLSA\n_443._tcp.domain.tld. IN TLSA 3 1 2 5c8fdd68178ce4cd8d88bd90b82a96df41674d555340b88283c24a0b3416aa375144cd6c16a58160ba3b168e59f5003bff656ce67cb24931b462fe4910bd62f5\n\u003c/code\u003e\u003c/pre\u003e\u003ch2 id=\"shell\"\u003eshell\u003c/h2\u003e\n\u003ch3 id=\"generate-tlsa-record\"\u003eGenerate TLSA Record\u003c/h3\u003e\n\u003cp\u003eOn shellcode, managing a TLSA record is simple — \u003cem\u003eneed to use openssl\u003c/em\u003e:\u003cbr\u003e\n\u003ccode\u003eopenssl x509 -noout -pubkey -in \u0026quot;${cert}\u0026quot; | openssl \u0026quot;${command}\u0026quot; -pubin -outform der 2\u0026gt;/dev/null | \u0026quot;${algo}\u0026quot; | tr \u0026quot;a-z\u0026quot; \u0026quot;A-Z\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eExplains\u003c/strong\u003e :\u003c/p\u003e\n\u003cp\u003e⇒ The above command generate a \u003ccode\u003etlsa_cert_associated\u003c/code\u003e variable, where:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e$cert\u003c/code\u003e: the absolute pathname for the server TLS cert, on the\nfilesystem, about one domain name.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e$command\u003c/code\u003e: the command name used by openssl, either \u003ccode\u003ersa\u003c/code\u003e or\n\u003ccode\u003eec\u003c/code\u003e \u003cem\u003e(reciprocally for RSA or ECDSA encryption records)\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e$algo\u003c/code\u003e: \u003ccode\u003esha256\u003c/code\u003e, or \u003ccode\u003esha512\u003c/code\u003e tool to use.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ Writing the TLSA record is also simple:\u003cbr\u003e\n\u003ccode\u003etlsa_record=\u0026quot;_${tls_port}._${tls_proto}.${domain}. IN TLSA ${tlsa_usage} ${tlsa_selector} ${tlsa_method} ${tlsa_cert_associated}\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e${tls_port}\u003c/code\u003e: port number of the webservice; by default \u003cstrong\u003e443\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e${tls_proto}\u003c/code\u003e: protocol name used; by default \u003cstrong\u003etls\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e${domain}\u003c/code\u003e: the domain name\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e${tlsa_usage}\u003c/code\u003e: the number according the \u003cstrong\u003eDANE-EE\u003c/strong\u003e constraint;\n\u003cstrong\u003e3\u003c/strong\u003e is recommended by Let\u0026rsquo;s Encrypt,\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e${tlsa_selector}\u003c/code\u003e: the number according to the \u003cstrong\u003eSPKI\u003c/strong\u003e selector;\n\u003cstrong\u003e1\u003c/strong\u003e is recommended by Let\u0026rsquo;s Encrypt,\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e${tlsa_method}\u003c/code\u003e: the method segun the choosed algorythm; by default:\n\u003cstrong\u003eSHA256\u003c/strong\u003e, \u003cem\u003ewhich offers currently a secure level of encryption,\negually recommended by Let\u0026rsquo;s Encrypt\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003efinishing with the previous \u003ccode\u003etlsa_cert_associated\u003c/code\u003e variable.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"check-tlsa-record\"\u003eCheck TLSA Record\u003c/h3\u003e\n\u003cp\u003eCheck a TLSA record is more complex; you need to:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e1/ query the DNS server to known the actual TLSA record, with \u003ccode\u003edig\u003c/code\u003e\ntool, for example.\u003c/li\u003e\n\u003cli\u003e2/ compare with the \u003ccode\u003eopenssl\u003c/code\u003e output; OpenSSL requesting the cert to\nthe webserver, linked to the domain name.\u003c/li\u003e\n\u003c/ol\u003e\n\u003chr\u003e\n\u003cul\u003e\n\u003cli\u003equeries the DNS server, like:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edig TLSA _443._tcp.\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e +short\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ed_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ for(i=4;i\u0026lt;=NF;++i) printf \u0026#34;%s\u0026#34;, tolower($i); print \u0026#34;\u0026#34; }\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003euse openssl to request TLS certificate used on the webserver:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho | openssl s_client -servername \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -showcerts -connect \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:443 2\u0026gt;/dev/null | openssl x509 -noout -pubkey | openssl pkey -outform der -pubin 2\u0026gt;/dev/null | openssl dgst -\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e 2\u0026gt;/dev/null \u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eo_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk -F\u003cspan style=\"color:#48b685\"\u003e\u0026#39;=\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ print $2 }\u0026#39;\u003c/span\u003e | tr -d \u003cspan style=\"color:#48b685\"\u003e\u0026#39; \u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eFinally, it enoughs to compare both shell variables, \u003ccode\u003ed_tlsa\u003c/code\u003e and \u003ccode\u003eo_tlsa\u003c/code\u003e.\nIn normal time, that should be case.\n\u003cstrong\u003eExcept in case of renewal certificate, which will require the renewal\nof the TLSA record in the domain name zone, on the DNS server.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eNOTE: if this is not done, a DNS server query on the DNSSEC protocol will\ngenerate an error since the TLSA record will not match a freshly used, or\nrenewed TLS cert, which will result in that consequence:\u003cbr\u003e\naccess to the server, linked to the target domain name, will be impossible.\u003cbr\u003e\n\u003cstrong\u003eIt will be necessary to generate a new TLSA record corresponding to the\nrenewal of the TLS certificate, then egual to regenerate the signature of\nthe DNSSEC records, for the DNS zone of the target domain.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2 id=\"shell-scripts\"\u003eShell Scripts\u003c/h2\u003e\n\u003cp\u003eNote: Put the \u003cstrong\u003etlsa.sh\u003c/strong\u003e, \u003cstrong\u003edns.conf\u003c/strong\u003e, \u003cstrong\u003edns.ksh\u003c/strong\u003e shell scripts on your\nhome. \u003cem\u003eIf you change their location on the filesystem, think to modify your\nmonthly local.\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"monthlylocal\"\u003emonthly.local\u003c/h3\u003e\n\u003cp\u003eHere, a \u003cstrong\u003emonthly.local\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### ldnscript\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ ldnscript rollover\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/usr/local/sbin/ldnscript rollover all\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### renew ssl by certbot\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ renew letsencrypt certs\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/usr/local/bin/certbot renew --pre-hook \u003cspan style=\"color:#48b685\"\u003e\u0026#34;rcctl stop nginx\u0026#34;\u003c/span\u003e --post-hook \u003cspan style=\"color:#48b685\"\u003e\u0026#34;rcctl start nginx\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### check tlsa records for domain; only for tcp:443\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e domain in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sub.domain.tld\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;domain.tld\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;www.domain.tld\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sub.domain2.tld\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;domain2.tld\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;www.domain2.tld\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ Test TLSA for \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t/home/-your-user-/dns-tools/tlsa.sh \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"tlsash\"\u003etlsa.sh\u003c/h3\u003e\n\u003cp\u003eHere, the \u003cstrong\u003etlsa.sh\u003c/strong\u003e script:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#set -x\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Author: Stéphane HUC\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# mail: devs@stephane-huc.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# gpg:fingerprint: CE2C CF7C AB68 0329 0D20  5F49 6135 D440 4D44 BD58\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# License: BSD Simplified\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Github: \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Date: 2022/07/01 06:45\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Purpose: tool  to test TLSA record\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  - for the geek: DANE-TLSA...\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Needed tools: dig, openssl\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# OS: Tested on OpenBSD, Devuan\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# see: https://www.bortzmeyer.org/monitor-dane.html\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e. \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/dns.conf\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_admin\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/home/-your-user-/dns-tools\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### DO NOT TOUCH!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ed_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#39;\u003c/span\u003e\t\u003cspan style=\"color:#776e71\"\u003e# TLSA record by dig\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eo_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#39;\u003c/span\u003e\t\u003cspan style=\"color:#776e71\"\u003e# TLSA record by openssl\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#39;\u003c/span\u003e\t\u003cspan style=\"color:#776e71\"\u003e# TLSA record \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e####\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   All needed functions! DO NOT TOUCH-IT!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebyebye\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Script stop here!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Please, search to understand reasons.\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    exit \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_uid\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -u\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -ne \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: Script not launch with rights admin!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_dig\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edig TLSA _443._tcp.\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e +short\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003ed_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho \u003cspan style=\"color:#ef6155\"\u003e$tlsa\u003c/span\u003e | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ for(i=4;i\u0026lt;=NF;++i) printf \u0026#34;%s\u0026#34;, tolower($i); print \u0026#34;\u0026#34; }\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_openssl\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho | openssl s_client -servername \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -showcerts -connect \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:443 2\u0026gt;/dev/null | openssl x509 -noout -pubkey | openssl pkey -outform der -pubin 2\u0026gt;/dev/null | openssl dgst -\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e 2\u0026gt;/dev/null \u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003eo_tlsa\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho \u003cspan style=\"color:#ef6155\"\u003e$tlsa\u003c/span\u003e | awk -F\u003cspan style=\"color:#48b685\"\u003e\u0026#39;=\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ print $2 }\u0026#39;\u003c/span\u003e | tr -d \u003cspan style=\"color:#48b685\"\u003e\u0026#39; \u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emssg\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    typeset statut info text\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;[ \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ered\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneutral\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e ]    \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OK\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;[ \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003egreen\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneutral\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e ]   \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#*) mssg=\u0026#34;${text}\u0026#34; ;;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#34;%s \\n\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset info statut text\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003enew_tlsa\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/etc/letsencrypt/live/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/cert.pem\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ele_key_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#48b685\"\u003e\u0026#34;ecdsa\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eopenssl x509 -noout -pubkey -in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | openssl ec -pubin -outform der 2\u0026gt;/dev/null | \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#48b685\"\u003e\u0026#34;rsa\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eopenssl x509 -noout -pubkey -in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | openssl rsa -pubin -outform der 2\u0026gt;/dev/null | \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;_\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e._\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e. IN TLSA \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tunset tlsa_cert_associated\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e####\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   Execution\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e########################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;[ KO ] Script stops here; no domain!\u0026#34;\u003c/span\u003e; exit; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_dig\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_openssl\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ed_tlsa\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eo_tlsa\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tmssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OK\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Similar TLSA records! :D\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tmssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;There seems to be a problem with the TLSA records of the domain: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Have you renew recently the TLS certs for the domain? If yes, change the TLSA record into the DNS zone relevent!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ Perhaps, the dns.sh script shell can help you. ;-)\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_uid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ Display new TLSA record:\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tnew_tlsa\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Add/modify tlsa into your DNS zone for \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e: \u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;⇒ Modify TLSA record into the domain zone for \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_admin\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e/dns.ksh tlsa \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eATTENTION: You need to modify the \u003ccode\u003edir_admin\u003c/code\u003e variable, at the top of\nscript!\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eExplains\u003c/strong\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eit call the \u003cstrong\u003edns.conf\u003c/strong\u003e file config; see below,\u003c/li\u003e\n\u003cli\u003eand, if the TLSA records does not match, it call the pdksh \u003cstrong\u003edns.ksh\u003c/strong\u003e\nscript, with \u003ccode\u003etlsa\u003c/code\u003e and targeted domain name as arguments.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"dnsconf\"\u003edns.conf\u003c/h3\u003e\n\u003cp\u003eHere, the file config — \u003cem\u003eneeded for both \u003cstrong\u003edns.ksh\u003c/strong\u003e and \u003cstrong\u003etlsa.sh\u003c/strong\u003e shell\nscripts\u003c/em\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e########################################################################\n#\n# Author: Stéphane HUC\n# mail: devs@stephane-huc.net\n# gpg:fingerprint: CE2C CF7C AB68 0329 0D20  5F49 6135 D440 4D44 BD58\n#\n# License: BSD Simplified\n#\n# Github: https://framagit.org/hucste/AH.git\n#\n# Date: 2022/06/01 07:20\n#\n########################################################################\n###\n##\n# Config file to dns.ksh script\n##\n###\n########################################################################\n\n### Algorithm\n## values: sha256, sha512; choose-it segun TLSA Method\nalgo=\u0026#34;sha256\u0026#34;\n### SOA Serial type\n## values: date, timestamp\n## DNS recommandation: prefer date\nSOA_serial_type=\u0026#34;date\u0026#34;\n### Port number\ntls_port=443\n### Protocols\n## values: stcp, tcp, udp\ntls_proto=\u0026#34;tcp\u0026#34;\n\n### TLSA \n## Lets Encrypt Recommandation; \n## \tsee: https://community.letsencrypt.org/t/please-avoid-3-0-1-and-3-0-2-dane-tlsa-records-with-le-certificates/7022\n## usage: Lets Encrypt recommands 3, at least 2\n## values: 0 =\u0026gt; 3; or (PKIX-TA, PKIX-EE, DANE-TA, DANE-EE; respectivly: 0 -\u0026gt; 3)\ntlsa_usage=3\n## selector: Lets Encrypt recommands 1\n## values: 0 or 1; or (CERT, SPKI; respectively: O or 1)\ntlsa_selector=1\n## method: Lets Encrypt recommands 1\n## values: 0 =\u0026gt; 2; or (FULL, SHA256, SHA512; respectively: 0 -\u0026gt; 2)\n# this change segun algo\ntlsa_method=1\n\n### Key Type Letsencrypt\n## rsa or ecdsa\n## if ecdsa, specify elliptic curve: secp256r1, secp384r1, secp512r1 (256 is enough)\nle_key_type=ecdsa\nle_curve=secp256r1\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eI personally choose to use:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003cstrong\u003esha512\u003c/strong\u003e algorythm\u003c/li\u003e\n\u003cli\u003ethe \u003cstrong\u003eecdsa\u003c/strong\u003e to use the \u003cstrong\u003eec\u003c/strong\u003e command with openssl. \u003cem\u003eOf course, it\u0026rsquo;s\npossible to use \u003cstrong\u003ersa\u003c/strong\u003e; in this case, those shell scripts will not\nuse the \u003ccode\u003e$le_curve\u003c/code\u003e variable\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"dnsksh\"\u003edns.ksh\u003c/h3\u003e\n\u003cp\u003eThis complex and large script is available to:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003egenerate DNSSEC signs for the DNS zone.\u003c/li\u003e\n\u003cli\u003emodify TLSA records and regenerate DNSSEC signs; in this case:\n\u003cul\u003e\n\u003cli\u003efind the SOA record\u003c/li\u003e\n\u003cli\u003ecreate a new file for the DNS zone and backup the actual\u003c/li\u003e\n\u003cli\u003eif the new file is available, the script will write:\n\u003cul\u003e\n\u003cli\u003ea new SOA record\u003c/li\u003e\n\u003cli\u003ereplace the oldier TLSA record with the new\u003c/li\u003e\n\u003cli\u003etry to sign the DNS zone with the DNSSEC protocol:\n\u003cul\u003e\n\u003cli\u003eif succeeded, it destroy the oldier DNS zone file,\u003c/li\u003e\n\u003cli\u003eif it fails, it warns, stops the execution \u003cstrong\u003eand\u003c/strong\u003e this case\nyou need to rename manually the backuped file.\u003cbr\u003e\n\u003cem\u003eYou can modify the \u003ccode\u003edebug\u003c/code\u003e variable to 1, and relaunch\nthe script; it logs the differents steps.\nThis helps to review and analyse why…\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eMaybe, \u003ccode\u003e./dns.ksh help\u003c/code\u003e will show you more information.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/ksh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#set -x\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Author: Stéphane HUC\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# mail: devs@stephane-huc.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# gpg:fingerprint: CE2C CF7C AB68 0329 0D20  5F49 6135 D440 4D44 BD58\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# License: BSD Simplified\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Github: \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Date: 2022/06/01 07:25\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Purpose: to add a TLSA Record into DNS zone, segun your cert TLS (LE)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  - for the geek: DANE-TLSA...\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#### IMPORTANT: recreate your TLSA Record after (re?)new cert...\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Needed tools: nsd* and ldnscript\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## ldnscript is a tool to sign dns zone. (DNSSEC)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## https://framagit.org/22decembre/ldnscripts.git\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# OS: Tested on OpenBSD\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e. \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/dns.conf\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   DONT TOUCH THOSES VARIABLES!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edebug\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_le\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/etc/letsencrypt/live\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_ns_cfg\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/etc/ns\u0026#34;\u003c/span\u003e    \u003cspan style=\"color:#776e71\"\u003e# folder config ns\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_sbin\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/usr/local/sbin\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003elog\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/dns-script.log\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ensd_cfg\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/nsd/etc/nsd.conf\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etimestamp\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edate +%s\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etoday\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edate +\u003cspan style=\"color:#48b685\"\u003e\u0026#34;%Y%m%d\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;nsd\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_ns\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -A tlsa_records\t\u003cspan style=\"color:#776e71\"\u003e# if X509 DNS Alternative Names \u0026gt; 1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -A tlsa_method_names -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;FULL\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SHA256\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SHA512\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -A tlsa_selector_names -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;CERT\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SPKI\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -A tlsa_usage_names -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;PKIX-TA\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;PKIX-EE\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;DANE-TA\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;DANE-EE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eNB_PARAMS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$#\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset -A PARAMS -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$@\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ePARAMS\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eMENU_CHOICE\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;help\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    PARAMS\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e0\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ePARAMS\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | tr -s \u003cspan style=\"color:#48b685\"\u003e\u0026#34;[:upper:]\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;[:lower:]\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eMENU_CHOICE\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ePARAMS\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -n \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ePARAMS\u003c/span\u003e[1]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ePARAMS\u003c/span\u003e[1]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | tr -s \u003cspan style=\"color:#48b685\"\u003e\u0026#34;[:upper:]\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;[:lower:]\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e####\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   All needed functions! DO NOT TOUCH-IT!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_add_tlsa\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_var_algo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_var_soa_serial_type\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_var_tls_port\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_var_tls_proto\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_tlsa_methods\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_tlsa_selectors\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_tlsa_usages\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tget_soa_ns\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003edanefile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.dane\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etoday\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003eoldzonefile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    create_new_filezone\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\twrite_soa_serial_number\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tbuild_tlsa_record\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\twrite_tlsa_record\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tmv_new_file_zone\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e _resign; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e del_old_zonefile; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tunset danefile newzonefile oldzonefile\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebuild_needed_variables\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    check_var_domain\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** Build needed variables:\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# build cert variable if menu \u0026#39;tlsa\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMENU_CHOICE\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;tlsa\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_le\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/cert.pem\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e ! -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** It seems cert file not exists!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;cert: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# build zonedir and zonefile variables\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ezonedir\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eawk -F \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/zonesdir/ { print substr($2,-1) }\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ensd_cfg\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonedir\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ezonedir\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/nsd/zones/\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;zonedir: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonedir\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#zonefile=\u0026#34;$(awk -F \u0026#39;\u0026#34;\u0026#39; \u0026#39;/zonefile: \u0026#34;[a-z]*\\/\u0026#39;\u0026#34;${domain}\u0026#34;\u0026#39;\u0026#34;/ { print substr($2, -1) }\u0026#39; \u0026#34;${nsd_cfg}\u0026#34;)\u0026#34;    \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#if [ \u0026#34;$(printf \u0026#39;%s\u0026#39; \u0026#34;${zonefile}\u0026#34; | awk -F\u0026#39;/\u0026#39; \u0026#39;{ print $1}\u0026#39;)\u0026#34; == \u0026#34;signed\u0026#34; ]; then\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e##zonefilesigned=$zonefile        \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#zonefile=\u0026#34;$(find \u0026#34;${dir_ns_cfg}\u0026#34; -name \u0026#34;${domain}\u0026#34;)\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#if [ -z \u0026#34;${zonefile}\u0026#34; ]; then zonefile=\u0026#34;$(find \u0026#34;${zonedir}\u0026#34; -name \u0026#34;${domain}\u0026#34;)\u0026#34;; fi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#if [ -z \u0026#34;${zonefile}\u0026#34; ]; then\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#776e71\"\u003e#display_mssg \u0026#34;KO\u0026#34; \u0026#34;ERROR: It seems zonefile for domain: \u0026#39;${domain}\u0026#39; not exists!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#776e71\"\u003e#byebye\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#fi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#else\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#zonefile=\u0026#34;${zonedir}${zonefile}\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#fi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_ns_cfg\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;zonefile: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebuild_tlsa_record\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#776e71\"\u003e# get TLSA by reading cert pem\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ele_key_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#48b685\"\u003e\u0026#34;ecdsa\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#ef6155\"\u003ecommand\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;ec\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#48b685\"\u003e\u0026#34;rsa\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#ef6155\"\u003ecommand\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;rsa\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eopenssl x509 -noout -pubkey -in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | openssl \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecommand\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -pubin -outform der 2\u0026gt;/dev/null | \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    _log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Cert Associated: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset command\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: TLSA Cert Associated could not generated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e# rebuild tlsa method segun algo choosed; possible: 0 (no match), 1 (sha256), 2 (sha512)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sha256\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sha512\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;443\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;tcp\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tget_dns_alternative_names\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#ef6155\"\u003ecount\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${#\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -eq \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\tset_tlsa_record\t\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\tset_tlsa_records\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset tlsa_cert_associated\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebyebye\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Script stop here!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Please, search to understand reasons.\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    exit \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_domain_name\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003epattern\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;^(([a-zA-Z0-9]|[a-zA-Z0-9][a-zA-Z0-9\\-]*[a-zA-Z0-9])\\.)*([A-Za-z0-9]|[A-Za-z0-9][A-Za-z0-9\\-]*[A-Za-z0-9])\u003c/span\u003e$\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# like RFC 1123\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e${#\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e -gt \u003cspan style=\"color:#f99b15\"\u003e67\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e    \u003cspan style=\"color:#776e71\"\u003e# Larg domain name \u0026lt;= 67\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Error: Domain Length: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e; \u0026gt;= 67 carachters!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | grep -Eio \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003epattern\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OK\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Domain Name: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e is valid!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        sleep \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Error: Bad Domain Name: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset pattern\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_tlsa_methods\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t0|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;FULL\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \t\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e ;; \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t1|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;SHA256\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t2|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;SHA512\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t*\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\  The TLSA Method: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t::\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Method: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_tlsa_selectors\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t0|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;CERT\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \t\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e ;; \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t1|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;SPKI\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \t\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t*\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\  The TLSA Selector: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Selector: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_tlsa_usages\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t0|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;PKIX-TA\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \t\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e ;; \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t1|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;PKIX-EE\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \t\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t2|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;DANE-TA\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t3|\u003cspan style=\"color:#48b685\"\u003e\u0026#34;DANE-EE\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\t\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t*\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\  The TLSA Usage: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Usage: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_uid\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -u\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -ne \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: Script not launch with rights admin!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_var_algo \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sha256\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sha512\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\ Algorythm: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Algo: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ealgo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_var_domain\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** It seems fault informations!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        help\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    _log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Domain: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_var_soa_serial_type\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_serial_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;date\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_serial_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;timestamp\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\ SOA Serial Type: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SOA Serial Type: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_serial_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_var_tls_port\u003cspan style=\"color:#5bc4bf\"\u003e(){\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -lt \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\ TLS port: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLS port: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeck_var_tls_proto\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sctp\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;tcp\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;tcp\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\ TLS proto: not correctly configurated!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLS proto: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeckconf\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    nsd-checkconf \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ensd_cfg\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echeckzone\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    nsd-checkzone \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003econfirm \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    read -r response?\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e1\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e [y|n] \u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eresponse\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e# \u0026#39;o\u0026#39;, \u0026#39;O\u0026#39;: Oui and not 0!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        y|Y|o|O|1\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e  true ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e          false ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset response\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecreate_new_filezone\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcp \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edel_old_zonefile\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        rm -fP \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edisplay_mssg\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    typeset statut info text\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;[ \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ered\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneutral\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e ]    \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OK\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;[ \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003egreen\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatut\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneutral\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e ]   \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003einfo\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#*) mssg=\u0026#34;${text}\u0026#34; ;;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#34;%s \\n\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etext\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset info statut text\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eget_dns_alternative_names\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#776e71\"\u003e# get \u0026#34;X509 DNS Alternative Names\u0026#34; characters\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eecho | openssl x509 -text -noout -in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecert\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk -F \u003cspan style=\"color:#48b685\"\u003e\u0026#39;,\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/DNS:/ { for(i=1;i\u0026lt;NF;i++) { p=match($i,\u0026#34;:\u0026#34;); print substr($i,p+1) }}\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#776e71\"\u003e# convert into array; no double-quotes, else not run!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tset -A domains -- \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;domains: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[*]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;domains: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[*]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eget_soa_ns\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003egrep -A1 \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SOA\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | tail -n1 | awk -F \u003cspan style=\"color:#48b685\"\u003e\u0026#39; \u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ print $1 }\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Old SOA Serial Number: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eget_soa_serial_number\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eline\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk -F \u003cspan style=\"color:#48b685\"\u003e\u0026#39; \u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{ print $1 }\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OLD SOA Serial Number: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehelp\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e sign domain      # to sign a domain\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e tlsa domain      # to add a tlsa record into domain zone\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    ----\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    when use tlsa, this script will resign the domain zone...\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    \u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003einit_zone\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_sbin\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e/ldnscript init \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ein_array\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    local \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eneed\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eIFS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; \u0026#34;\u003c/span\u003e; shift; set -A array -- \u003cspan style=\"color:#ef6155\"\u003e$*\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ecount\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${#\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003earray\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ewhile\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e -le \u003cspan style=\"color:#ef6155\"\u003e$count\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003earray\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneed\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e 0; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# true\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e#let \u0026#34;i=$i+1\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ei+1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset i need IFS array\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_log\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edebug\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -eq \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u0026gt;\u0026gt; \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003elog\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emain\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tcheck_uid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tverify_need_softs\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tbuild_needed_variables\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    check_domain_name\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMENU_CHOICE\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;help\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e help ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;sign\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e _resign ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;tlsa\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e _add_tlsa ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: this option \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMENU_CHOICE\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e is not exists!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            help\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emv_new_file_zone\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        mv \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        mv \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ezonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_resign\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e checkzone \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e checkconf; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OK\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;file config nsd and zone \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e are good! :D\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        sign_zone\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: it exists a problem with file config nsd or zone \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003erestart_server\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; Restart Server: \u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    stop_server\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    start_server\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    status_server\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset_soa_serial_number\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_serial_type\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;date\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#ef6155\"\u003eSOA_date\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{print substr($0, 0, 8)}\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{print substr($0, 9)}\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_date\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etoday\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                \u003cspan style=\"color:#776e71\"\u003e#let SOA_number=$SOA_number+1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e+1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e||\u003c/span\u003e true\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -lt \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;0\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                \u003cspan style=\"color:#ef6155\"\u003eSOA_sn\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_date\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_number\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                \u003cspan style=\"color:#ef6155\"\u003eSOA_sn\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etoday\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e01\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;timestamp\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#ef6155\"\u003eSOA_sn\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etimestamp\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Invalid SOA Serial Type!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tbyebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    _log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;New SOA Serial Number: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset_tlsa_record\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#776e71\"\u003e# build tlsa record\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\ttlsa_records\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e0\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;_\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e._\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e. IN TLSA \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Record: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_records\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset_tlsa_records\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#776e71\"\u003e# do not use domain variable here\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e dom in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\ttlsa_records\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;_\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e._\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edom\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e. IN TLSA \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_usage\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_selector\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_method\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_cert_associated\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ei+1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tunset i dom\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Records: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_records\u003c/span\u003e[*]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esign_zone\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_sbin\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e/ldnscript signing \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estart_server\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Start serveur: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    rcctl start \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    sleep 1s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estatus_server\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Check serveur: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    rcctl check \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estop_server\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    printf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Stop serveur: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    rcctl stop \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eserver\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    sleep 1s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003everify_need_softs\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e ! -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_sbin\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/ldnscript\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: ldnscript seems not install!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eelif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e ! -x \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_sbin\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/ldnscript\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        display_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ERROR: ldnscript is not executable!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        byebye\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewrite_soa_serial_number\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\tset_soa_serial_number\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e sed -i -e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;s#\\(.*\\)\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eOLD_SOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \\;#\\1\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eSOA_sn\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \\;#\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;SOA serial number changed!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tdisplay_mssg \u003cspan style=\"color:#48b685\"\u003e\u0026#34;KO\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/!\\  Script cant change SOA serial number!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewrite_tlsa_record\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e ! -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edanefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e touch \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edanefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# add tlsa records into dns zone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e tlsa_record in \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_records\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#ef6155\"\u003edom\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomains\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;domain: \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$dom\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#776e71\"\u003e### /!\\ ERROR with $domain /!\\ \u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e sed -i -e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;s#_\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_port\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e._\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etls_proto\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edom\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e. IN TLSA\\(.*\\)#\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e#\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Record rewrited!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\t\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u0026gt;\u0026gt; \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003enewzonefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;TLSA Record added!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ei+1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#776e71\"\u003e# add record in first line into dane file\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tprintf \u003cspan style=\"color:#48b685\"\u003e\u0026#39;%s\\n\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etimestamp\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u0026gt;\u0026gt; \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edanefile\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t_log \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etimestamp\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003etlsa_record\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\tunset dom\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset i tlsa_record\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emain\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003ch2 id=\"eod\"\u003eEOD\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eEnd Of Documentation\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eVoila; this is my process to manage my DNS zones, with DNSSEC for the\nTLSA records.\u003c/p\u003e\n\u003cp\u003eFrom a large and complex process, I can manage simply with the two useful commands:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003esign my DNS zones by DNSSEC:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e./dns.ksh sign domain\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003echeck the TLSA records, at any time, and if necessary, regenerate them:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e./tlsa.sh domain\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eBut if you have understood, the monthly cron takes care of it all and\nmakes the appropriate report, so I know how it was executed.\u003c/p\u003e\n\u003chr\u003e\n","summary":"How to manage DNSSEC, TLSA records, to validate TLS certificates on OpenBSD with nsd, ldns and others…","tags":["DNS","DANE","DNSSEC","OpenBSD","TLSA"],"date_published":"2022-10-04T00:32:16+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2022-04-19:/en/monitor/iblock-openbsd","url":"https://it-log.fr.eu.org/en/monitor/iblock-openbsd/","title":"iblock: block scanner TCP connections under OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description iblock is a software whose purpose is to detect TCP connections, on specific ports, in order to block the corresponding IP adresses, through Packet Filter.\nThe inetd service is responsible for active listening.\nAuthor: Solène Rapenne URL: https://tildegit.org/solene/iblock.git list of banned URLs: http://perso.pw/blocklist.txt Installation Let\u0026rsquo;s start with the copy of Git depository:\n:$ git clone https://tildegit.org/solene/iblock.git :$ cd iblock Compile the binary — OpenBSD contains natively the appropriate tools:\n:$ doas make cc -o iblock main.c ; vérifions la présence du binaire :$ ls -al iblock -rwxr-xr-x 1 root moi 8496 Apr 10 12:23 iblock* If the compilation phase does not run correctly, contact Solène!\nSolène did not create the \u0026ldquo;install\u0026rdquo; target, so let\u0026rsquo;s copy it into the target directory:\n:$ doas cp iblock /usr/local/bin/ :$ ls -al /usr/local/bin/iblock -rwxr-xr-x 1 root wheel 8496 Apr 10 12:26 /usr/local/bin/iblock* Let\u0026rsquo;s move to the configuration:\nConfiguration _iblock In first, create a dedicated user, named _iblock:\n:$ doas useradd -s /sbin/nologin _iblock\ndoas Configuration file: /etc/doas.conf Now, add the below rule into the doas configuration file to allow the dedicated user to use pfctl:\npermit nopass _iblock cmd /sbin/pfctl\ninetd Configuration file: /etc/inetd.conf Configure the inetd service:\n666 stream tcp nowait _iblock /usr/local/bin/iblock iblock blocked_tcp 666 stream tcp6 nowait _iblock /usr/local/bin/iblock iblock blocked_tcp 666: used port — of course, you can change… the _iblock user manage the binary iblock the last argument: the name of the added parameter to the IP addresses stored in the PF table. And, now, let\u0026rsquo;s active and start the service:\n:$ doas rcctl enable inetd \u0026amp;\u0026amp; doas rcctl start inetd shutdown Create a \u0026ldquo;backup\u0026rdquo; file to make the future table persistent in PF, on server shutdown and restart:\n:# touch /etc/pf-blocked_tcp.txt And, create|modify the /etc/rc.shutdown file:\npfctl -t blocked_tcp -T show \u0026gt; /etc/pf-blocked_tcp.txt PF Here is an instance of rules to add to Packet Filter:\none variable, named block_tcp_ports: a set of ports to monitor one persistent table, named blocked_tcp. the blocking rule, labeled iblock. the two ultime rules analyze the TCP flow, on IPv(4|6) protocols, by active listening on the stored ports into the block_tcp_ports variable, and then redirect on the local interface, to the port 666. block_tcp_ports = \u0026#34;{ 21 23 111 135 137:139 445 1433 3306 3389 5432 6000:6010 7890 9999 25565 27019 }\u0026#34; table \u0026lt;blocked_tcp\u0026gt; persist file \u0026#34;/etc/pf-blocked_tcp.txt\u0026#34; ### iblock: block all in table block in quick from \u0026lt;blocked_tcp\u0026gt; label iblock ### iblock: redirect to inetd service on localhost pass in quick on egress inet proto tcp to port $block_tcp_ports rdr-to 127.0.0.1 port 666 pass in quick on egress inet6 proto tcp to port $block_tcp_ports rdr-to ::1 port 666 InfoBy default, the set of the ports are FTP, telnet, DNS, RPC, SMB, MSSQL, MySQL, PostgreSQL, Minecraft, Steam. I add: X11, Goaccess, pfstat; it\u0026rsquo;s up to you… WarningIf you are hosting a service, such as DNS, you will block all connections, because by default the appropriate port 53 is scanned. (this applies to any service you host!) Remember: reload the rule set: :$ doas pfctl -f /etc/pf.conf\nMonitoring But, who is the monitor?\n⇒ The activity is recorded in the two logs \u0026lsquo;daemon\u0026rsquo; and \u0026lsquo;messages\u0026rsquo;.\n:$ grep iblock /var/log/messages Apr 10 12:26:38 sh1 iblock: blocking 46.23.148.71 Apr 10 12:30:28 sh1 iblock: blocking 180.225.98.236 Apr 10 12:31:48 sh1 iblock: blocking 46.23.157.246 Apr 10 12:32:43 sh1 iblock: blocking 95.57.218.103 Apr 10 12:36:00 sh1 iblock: blocking 103.89.91.158 Apr 10 12:38:41 sh1 iblock: blocking 23.128.248.41 ⇒ Also, pfctl can show us the different IP addresses registered into the PF table:\n:$ doas pfctl -t blocked_tcp -T show 23.128.248.41 46.23.148.71 46.23.157.246 95.57.218.103 103.89.91.158 180.225.98.236 or event to use it to find the related statistics to — see documentation for column meaning:\n:$ doas pfctl -sl | grep iblock iblock 44666 1188 58504 1188 58504 0 0 0 ⇒ It\u0026rsquo;s possible to monitoring the user _iblock — but, in this case, not very useful:\ntop -U _iblock fstat -u _iblock -n ps aux -U _iblock munin If you want to get statistics with munin , Solène provided me a script, to be executed with the rights of the user _munin:\n#!/bin/sh if [ \u0026#34;$1\u0026#34; = \u0026#34;config\u0026#34; ]; then echo \u0026#34;graph_title Banned IP absolute number\u0026#34; echo \u0026#34;graph_vlabel gauge\u0026#34; echo \u0026#34;a1.label value\u0026#34; exit 0 fi printf \u0026#34;a1.value \u0026#34; doas /sbin/pfctl -t blocked_tcp -T show | sort -n -u | awk \u0026#39;END { print NR }\u0026#39; This need to modify the configuration of doas to allow the user _munin to use pfctl:\n# iblock: auth _munin-plugin to use pfctl permit nopass _munin-plugin cmd /sbin/pfctl args -t blocked_tcp -T show Below, here a view of statistics of blocked IP addresses, gived by Solène,\nCi-dessous, voici une image de statistiques d\u0026rsquo;adresses IP bloquées, restituée par Solène, on 2022/10/04:\nStatistics of IP addresses blocked with iblock Troubleshooting Into the both logs \u0026lsquo;daemon\u0026rsquo; and \u0026lsquo;messages\u0026rsquo;, see the message:\ninetd[69849]: execv /usr/local/bin/iblock: No such file or directory\nMake sure you have compiled and copied the iblock binary to the target directory!\nVoila!\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eiblock\u003c/strong\u003e is a software whose purpose is to detect TCP connections, on\nspecific ports, in order to block the corresponding IP adresses, through\nPacket Filter.\u003c/p\u003e\n\u003cp\u003eThe inetd service is responsible for active listening.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAuthor: Solène Rapenne\u003c/li\u003e\n\u003cli\u003eURL: \u003ca href=\"https://tildegit.org/solene/iblock.git\" rel=\"external\"\u003ehttps://tildegit.org/solene/iblock.git\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003elist of banned URLs: \u003ca href=\"http://perso.pw/blocklist.txt\" rel=\"external\"\u003ehttp://perso.pw/blocklist.txt\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eLet\u0026rsquo;s start with the copy of Git depository:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ git clone https://tildegit.org/solene/iblock.git\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ cd iblock\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eCompile the binary — \u003cem\u003eOpenBSD contains natively the appropriate tools\u003c/em\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas make\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecc -o iblock main.c\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e; vérifions la présence du binaire\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ls -al iblock\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e-rwxr-xr-x  \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e root  moi  \u003cspan style=\"color:#f99b15\"\u003e8496\u003c/span\u003e Apr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:23 iblock*\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003eIf the compilation phase does not run correctly, contact Solène!\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eSolène did not create the \u0026ldquo;install\u0026rdquo; target, so let\u0026rsquo;s copy it into the\ntarget directory:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas cp iblock /usr/local/bin/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ls -al /usr/local/bin/iblock\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e-rwxr-xr-x  \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e root  wheel  \u003cspan style=\"color:#f99b15\"\u003e8496\u003c/span\u003e Apr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:26 /usr/local/bin/iblock*\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eLet\u0026rsquo;s move to the configuration:\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"_iblock\"\u003e_iblock\u003c/h3\u003e\n\u003cp\u003eIn first, create a dedicated user, named \u003cstrong\u003e_iblock\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:$ doas useradd -s /sbin/nologin _iblock\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"doas\"\u003edoas\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/doas.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNow, add the below rule into the doas configuration file to allow the\ndedicated user to use \u003ccode\u003epfctl\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003epermit nopass _iblock cmd /sbin/pfctl\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"inetd\"\u003einetd\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/inetd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eConfigure the \u003cstrong\u003einetd\u003c/strong\u003e service:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e666 stream tcp nowait _iblock /usr/local/bin/iblock iblock blocked_tcp\n666 stream tcp6 nowait _iblock /usr/local/bin/iblock iblock blocked_tcp\n\u003c/code\u003e\u003c/pre\u003e\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e666\u003c/strong\u003e: used port — \u003cem\u003eof course, you can change…\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003cstrong\u003e_iblock\u003c/strong\u003e user manage the binary \u003ccode\u003eiblock\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ethe last argument: the name of the added parameter to the IP addresses\nstored in the PF table.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd, now, let\u0026rsquo;s active and start the service:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas rcctl enable inetd \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e doas rcctl start inetd\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"shutdown\"\u003eshutdown\u003c/h3\u003e\n\u003cp\u003eCreate a \u0026ldquo;backup\u0026rdquo; file to make the future table persistent in PF, on\nserver shutdown and restart:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# touch /etc/pf-blocked_tcp.txt\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAnd, create|modify the \u003ccode\u003e/etc/rc.shutdown\u003c/code\u003e file:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003epfctl -t blocked_tcp -T show \u0026gt; /etc/pf-blocked_tcp.txt\n\u003c/code\u003e\u003c/pre\u003e\u003ch3 id=\"pf\"\u003ePF\u003c/h3\u003e\n\u003cp\u003eHere is an instance of rules to add to Packet Filter:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eone variable, named \u003cstrong\u003eblock_tcp_ports\u003c/strong\u003e: a set of ports to monitor\u003c/li\u003e\n\u003cli\u003eone persistent table, named \u003cstrong\u003eblocked_tcp\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003ethe blocking rule, labeled \u003cstrong\u003eiblock\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003ethe two ultime rules analyze the TCP flow, on IPv(4|6) protocols, by\nactive listening on the stored ports into the \u003cstrong\u003eblock_tcp_ports\u003c/strong\u003e\nvariable, and then redirect on the local interface, to the port \u003cstrong\u003e666\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003eblock_tcp_ports = \u0026#34;{ 21 23 111 135 137:139 445 1433 3306 3389 5432 6000:6010 7890 9999 25565 27019 }\u0026#34;\n\ntable \u0026lt;blocked_tcp\u0026gt; persist file \u0026#34;/etc/pf-blocked_tcp.txt\u0026#34;\n\n### iblock: block all in table\nblock in quick from \u0026lt;blocked_tcp\u0026gt; label iblock\n\n### iblock: redirect to inetd service on localhost\npass in quick on egress inet  proto tcp to port $block_tcp_ports rdr-to 127.0.0.1 port 666\npass in quick on egress inet6 proto tcp to port $block_tcp_ports rdr-to ::1       port 666\n\u003c/code\u003e\u003c/pre\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eBy default, the set of the ports are FTP, telnet, DNS, RPC, SMB, MSSQL,\nMySQL, PostgreSQL, Minecraft, Steam. \u003cbr\u003e\nI add: X11, Goaccess, pfstat; \u003cem\u003eit\u0026rsquo;s up to you…\u003c/em\u003e\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eIf you are hosting a service, such as DNS, you will block all connections,\nbecause by default the appropriate port 53 is scanned. \u003cbr\u003e\n\u003cem\u003e(this applies to any service you host!)\u003c/em\u003e\u003c/div\u003e\n\n\u003cp\u003eRemember: reload the rule set: \u003cbr\u003e\n\u003ccode\u003e:$ doas pfctl -f /etc/pf.conf\u003c/code\u003e\u003c/p\u003e\n\u003ch2 id=\"monitoring\"\u003eMonitoring\u003c/h2\u003e\n\u003cblockquote\u003e\n\u003cp\u003eBut, who is the monitor?\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e⇒ The activity is recorded in the two logs \u0026lsquo;daemon\u0026rsquo; and \u0026lsquo;messages\u0026rsquo;.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ grep iblock /var/log/messages\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:26:38 sh1 iblock: blocking 46.23.148.71\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:30:28 sh1 iblock: blocking 180.225.98.236\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:31:48 sh1 iblock: blocking 46.23.157.246\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:32:43 sh1 iblock: blocking 95.57.218.103\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:36:00 sh1 iblock: blocking 103.89.91.158\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eApr \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e 12:38:41 sh1 iblock: blocking 23.128.248.41\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Also, \u003ccode\u003epfctl\u003c/code\u003e can show us the different IP addresses registered into\nthe PF table:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas pfctl -t blocked_tcp -T show\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   23.128.248.41\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   46.23.148.71\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   46.23.157.246\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   95.57.218.103\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   103.89.91.158\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   180.225.98.236\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eor event to use it to find the related statistics to —\n\u003cem\u003e\u003ca href=\"https://man.openbsd.org/pfctl#s~8\" rel=\"external\"\u003esee documentation for column meaning\u003c/a\u003e\u003c/em\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas pfctl -sl | grep iblock\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eiblock \u003cspan style=\"color:#f99b15\"\u003e44666\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1188\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e58504\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1188\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e58504\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ It\u0026rsquo;s possible to monitoring the user \u003cstrong\u003e_iblock\u003c/strong\u003e —\n\u003cem\u003ebut, in this case, not very useful\u003c/em\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003etop -U _iblock\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efstat -u _iblock -n\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eps aux -U _iblock\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"munin\"\u003emunin\u003c/h3\u003e\n\u003cp\u003eIf you want to get statistics with \u003ca class=\"tag\" href=\"/en/tags/munin\"\u003emunin\u003c/a\u003e\n, Solène provided me\na script, to be executed with the rights of the user \u003cstrong\u003e_munin\u003c/strong\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e#!/bin/sh\n\nif [ \u0026#34;$1\u0026#34; = \u0026#34;config\u0026#34; ]; then\n        echo \u0026#34;graph_title Banned IP absolute number\u0026#34;\n        echo \u0026#34;graph_vlabel gauge\u0026#34;\n        echo \u0026#34;a1.label value\u0026#34;\n        exit 0\nfi\n\nprintf \u0026#34;a1.value \u0026#34;\ndoas /sbin/pfctl -t blocked_tcp -T show | sort -n -u | awk \u0026#39;END { print NR }\u0026#39;\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThis need to modify the configuration of \u003ca href=\"/en/monitor/iblock-openbsd/#doas\"\u003edoas\u003c/a\u003e to allow the user\n\u003cstrong\u003e_munin\u003c/strong\u003e to use \u003ccode\u003epfctl\u003c/code\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e# iblock: auth _munin-plugin to use pfctl\npermit nopass _munin-plugin cmd /sbin/pfctl args -t blocked_tcp -T show\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003cp\u003eBelow, here a view of statistics of blocked IP addresses, gived by Solène,\u003c/p\u003e\n\u003cp\u003eCi-dessous, voici une image de statistiques d\u0026rsquo;adresses IP bloquées, restituée\npar Solène, on 2022/10/04:\u003c/p\u003e\n\u003cfigure\u003e\n    \u003ca href=\"/images/monitor/iblock-stats.png\" title=\"Statistics of IP addresses blocked with iblock\"\u003e\n    \u003cpicture\u003e\n        \n        \u003csource srcset=\"/images/monitor/iblock-stats_hu_3dbffc249bb7edfe.webp\" type=\"image/webp\"\u003e\n        \n        \u003cimg alt=\"Statistics of IP addresses blocked with iblock\" height=\"142\" loading=\"lazy\" src=\"/images/monitor/iblock-stats_hu_ab68ffa9accd8a1b.png\" type=\"image/png\" width=\"250\"\u003e\n    \u003c/picture\u003e\n    \u003c/a\u003e\n    \u003cfigcaption\u003eStatistics of IP addresses blocked with iblock\u003c/figcaption\u003e\n\u003c/figure\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003cp\u003eInto the both logs \u0026lsquo;daemon\u0026rsquo; and \u0026lsquo;messages\u0026rsquo;, see the message:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003einetd[69849]: execv /usr/local/bin/iblock: No such file or directory\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eMake sure you have compiled and copied the iblock binary to the target\ndirectory!\u003c/strong\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003chr\u003e\n","summary":"iblock: a tool to block scanner on unused ports, TCP connections, adding the IP to a Packet Filter table, on OpenBSD, using inetd service.","tags":["Monitoring","TCP","OpenBSD","PF","inetd"],"date_published":"2022-04-19T14:00:06+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-07-30:/en/monitor/goaccess-openbsd","url":"https://it-log.fr.eu.org/en/monitor/goaccess-openbsd/","title":"Goaccess / OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description Goaccess is a FLoSS, known to be light, fast, in order to to analyze in real time or not the activity on a web server, either directly within a Unix terminal, or on the HTTPS protocol.\nIt\u0026rsquo;s able to produce statistics on HTML, JSON even CSV format.\n⇒ Environnement:\nOpenBSD: 6.9 → 7.1 Installation Usual: :# pkg_add goaccess\nConfiguration The main file config is on: /etc/goaccess/goaccess.conf.\n⇒ You can use goaccess without any modifications on its file config. This need to pass all options on the CLI, but few options are clearly commons and can be \u0026ldquo;frozen\u0026rdquo; on the file config.\n⇒ Too, it\u0026rsquo;s also possible to create numerous files config, each specific to a web domain, to set particularly segun this domain. In this case, you need to specify it…\nIn this article, I use one configuration file, and put some options on the CLI.\nNow, let\u0026rsquo;s see the main configuration options:\nTime and Date formats Formatting the time!\n⇒ If you use httpd, you need to be careful to set correctly the style of the log, and into in the goaccess configuration file in the Time Format Options section.\nsee: httpd.conf(5)#style ⇒ For nginx, it will be enough to uncomment the following options:\ntime-format %H:%M:%S date-format %d/%b/%Y - this being into Date Format Options section. Log format log-format: prefer the COMBINED format — for httpd, you can choose the common format, too. If you use nginx, it is imperative to register all statuses, not to filter the 2xx and 3xx — if you had created the map directive you will have at least to comment it and restart the web service.\nFile Options If you have only one web domaine on the server to analyze, it\u0026rsquo;s usefull to set the log-file option with the absolute directory of the access.log relient.\nParse Options exclude-ip: use this option to exclude adresses IP or network segments, like you personal network at home\n444-as-404: the 444 error is nginx\u0026rsquo;s specific. If you want to analyze as an 404 error, change to true. It\u0026rsquo;s up to you!\nignore-crawlers: to ignore all crawlers robots; change to true\nignore-panel is one panel that can be disabled. On Europe, with the RGPD, it is better to disable, at least, the REMOTE_USER panel.\nanonymize-ip : change to true - egual, because RGPD, disable!\nPersistence Options db-path: the absolute directory of the goaccess database ­— configure only one domain. persist: to backup the analyzed datas. restore: load the data to be visualized from the saved data. ⇒ Enable both last options to true, if you want to save the data into the goaccess database.\nOf course, there are numerous options.\nAfter, just use goaccess.\nNow, let\u0026rsquo;s push the configuration a further:\nUser system I prefer to create and use a dedicated user system. Among the advantages are the search in log messages and even cron.\n:# useradd -s /sbin/nologin -d /var/db/goaccess _goaccess ⇒ to search in log messages:\n:$ grep goaccess /var/log/messages or :$ doas grep _goaccess /var/cron/log\ndoas ⇒ I preferred to add the permission to use the goaccess binary into /etc/doas.conf:\npermit nopass _goaccess cmd /usr/local/bin/goaccess (I\u0026rsquo;m not absolutly sure about the necessity).\ndatabase directory ⇒ Go to create the main directory for the goaccess database:\n:# mkdir -p /var/db/goaccess :# chown _goaccess:daemon /var/db/goaccess (personally, I preferred another absolute folder).\nThink to add at yours backups!\nThen if like me, you have several web domains on your server, create many subdirectories with the name of the web domain, such as:\n:$ domain= :$ doas -u _goaccess mkdir \u0026#34;/var/db/goaccess/${domain}\u0026#34; Thus, future statistics will be really dedicated to a domain.\ncrontab ⇒ You need to set cron rules:\n:$ doas -u _goaccess crontab -e (Egual, it\u0026rsquo;s possible to do by: doas crontab -u _goaccess -e).\nAdd:\n*/15 * * * * -ns goaccess -a --db-path \u0026#34;/var/db/goaccess/domain/\u0026#34; -f /var/www/logs/domain/access.log -o /var/www/goaccess/domain/stats.html Littles explainations:\none crontab to execute every 15 minutes. Keep on mind, it\u0026rsquo;s an example. replace the domain string by the domain name. Authenticate It\u0026rsquo;s up to you if you want web authentication before viewing; some people think you should, others don\u0026rsquo;t; personally I prefer it.\nAfter using htpasswd, you need to configure on the server directive on the virtual host:\nfor http, use authenticate. on nginx, both auth_basic and auth_basic_user_file directives. httpd configuration Basically:\nserver \u0026#34;domain.tld\u0026#34; { (…) root \u0026#34;/htdocs/domain.tld/www\u0026#34; location \u0026#34;/stats\u0026#34; { authenticate with \u0026#34;/file_htpwd\u0026#34; directory auto index } (…) } Do not forget: the path of the htpasswd file is relative to the web chroot!\nnginx configuration (…) location /stats/ { auth_basic \u0026#34;Auth Area\u0026#34;; auth_basic_user_file /file_htpwd; autoindex on; } (…) Voila for the \u0026ldquo;configuration\u0026rdquo; part!\nUse Basic use Execute the binary, as:\n:$ goaccess -o /var/www/htdocs/domain.tld/stats/index.html use _goaccess ⇒ Use goaccess with the _goaccess user:\nFor instance, the first time, to precise datation with month and year:\n:$ domain= :$ date=\u0026#34;$(date +\u0026#39;%Y-%m\u0026#39;)\u0026#34; :$ doas -u _goaccess goaccess -a --db-path \u0026#34;/var/db/goaccess/${domain}/\u0026#34; -f \u0026#34;/var/www/logs/${domain}/access.log\u0026#34; -o \u0026#34;/var/db/goaccess/${domain}/stats-${domain}-${date}.html\u0026#34; I created a shell script, named goaccess.sh:\n#!/bin/sh ### # # manage statistics by domain # ## date=\u0026#34;$(date +\u0026#39;%m-%Y\u0026#39;)\u0026#34; dir_db=\u0026#34;/var/db/goaccess\u0026#34; domain=\u0026#34;$1\u0026#34; if [ -z \u0026#34;${domain}\u0026#34; ]; then printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;No domain. Script stops!\u0026#34; logger \u0026#34;$0: no domain found as option; script stops!\u0026#34; exit 1 fi if [ ! -d \u0026#34;${dir_db}/${domain}/\u0026#34; ]; then printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;The destination directory \u0026#39;${dir_db}/${domain}/\u0026#39; seems not exist!\u0026#34; logger \u0026#34;$0: The destination directory for goaccess not exists; script stops!\u0026#34; exit 2 fi goaccess -a --db-path \u0026#34;${dir_db}/${domain}/\u0026#34; -f \u0026#34;/var/www/logs/${domain}/access.log\u0026#34; -o \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34; And, after setting up the _goaccess crontab:\n*/15 * * * * -ns /directory/goaccess.sh domain-x.tld 0 * * * * -ns /directory/goaccess.sh domain-y.tld 0 0 * * * -ns /directory/goaccess.sh domain-z.tld (at differents times).\nNo! It\u0026rsquo;s not finish…\nIn fact, the generated HTML file to dataviz is wrote on the database directory. The _goaccess user cant write on the web directory, and does not have access.\nOn the other hand, it is possible to ask the web user www to copy the HTML statistics file on the corresponding web directory.\nHere, I use this following shell script, named cp_stats.sh:\n#!/bin/sh set -e #set -x ### # # copy statistics files into the domain web directory # ## date=\u0026#34;$(date +\u0026#39;%m-%Y\u0026#39;)\u0026#34; domain=\u0026#34;$1\u0026#34; dir_db=\u0026#34;/var/db/goaccess\u0026#34; dir_stats=\u0026#34;/var/www/htdocs/${domain}/www/stats/\u0026#34; if [ -z \u0026#34;${domain}\u0026#34; ]; then printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;No domain. Script stops!\u0026#34; logger \u0026#34;$0: no domain found as option; script stops!\u0026#34; exit 1 fi if [ ! -f \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34; ]; then printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;The needed file \u0026#39;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#39; not exists. Script stops!\u0026#34; logger \u0026#34;$0: The needed file \u0026#39;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#39; not exists; script stops!\u0026#34; exit 2 fi if [ ! -d \u0026#34;${dir_stats}\u0026#34; ]; then mkdir -p \u0026#34;${dir_stats}\u0026#34;; fi cp \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34; \u0026#34;${dir_stats}\u0026#34; chown -R www \u0026#34;${dir_stats}\u0026#34; You need to modify the crontab of the web user:\n:$ doas -u www crontab -e Like, for instance:\n*/15 * * * * -ns /directory/cp_stats.sh domain-x.tld 5 * * * * -ns /directory/cp_stats.sh domain-y.tld 5 0 * * * -ns /directory/cp_stats.sh domain-z.tld Time-real The real time use is done in two possible ways.\nInto those contexts, we will not need the _goaccess user.\nTerminal ⇒ at least, tape:\n:$ goaccess -f /var/www/logs/${domain}/access.log Enjoy the aesthetic view based on monokai colors, by default.\nWeb proxy Here, it\u0026rsquo;s really interesting, but a \u0026ldquo;bit complicated\u0026rdquo;:\nrelay httpd I have not found solution for the httpd service. Maybe, with relayd ;-)\nproxy nginx Lets to set the server configuration to add the location directive:\nlocation /ws { proxy_pass http://localhost:7890; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection \u0026#34;Upgrade\u0026#34;; } websocket Now, you need to execute goaccess with the www web user rights:\n:$ doas -u www goaccess -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html --ws-url=wss://huc.fr.eu.org:443/ws --port 7890 [PARSING /var/www/logs/doc.huc.fr.eu.org/access.log] {0} @ {0/s} WebSocket server ready to accept new client connections Note: for this test, I have to:\ncreate a new configuration file named goaccess.realtime.conf to create a new HTML file and to listen the server on the secure websocket. Also, we can monitoring, in real time, the user, into a SSH console, with binaries like fstat, ps; see:\n:$ fstat -u www -n USER CMD PID FD DEV INUM MODE R/W SZ|DV www goaccess 76729 wd 4,15 725760 40755 r 512 www goaccess 76729 0 4,0 78329 20620 rw 5,0 www goaccess 76729 1 4,0 78329 20620 rw 5,0 www goaccess 76729 2 4,0 78329 20620 rw 5,0 www goaccess 76729 3 4,3 175 10644 rw 0 www goaccess 76729 4 4,3 176 10644 rw 0 www goaccess 76729 5 4,3 175 10644 w 0 www goaccess 76729 6 4,3 176 10644 w 0 www goaccess 76729 7 pipe 0x0 state: www goaccess 76729 8 pipe 0x0 state: www goaccess 76729 9* internet stream tcp 0x0 *:7890 www goaccess 76729 10 pipe 0x0 state: www goaccess 76729 11 pipe 0x0 state: www goaccess 76729 12* internet stream tcp 0x0 127.0.0.1:7890 \u0026lt;-- 127.0.0.1:6459 :$ ps aux -U www USER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMAND www 4071 0.0 0.1 1572 3488 ?? S 10:12AM 0:00.88 sshd: www@notty (sshd) www 76729 0.0 0.3 10096 12752 p0 S+ 7:56PM 0:01.49 goaccess -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html /var/www/logs/do Now, go to view the realtime.html file on your web browser.\ndashboard goaccess real time Note the little dash below the parameter icone, at the top left on the screen.\nIt seems necessary to reload the page; after some time, it lose the connector. Press F5…\nFinally, we cant execute goaccess as service, either by the \u0026ndash;daemonize option, or by configuring the dedicated configuration file.\n:$ doas -u www goaccess --daemonize -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html --ws-url=wss://huc.fr.eu.org:443/ws --port 7890 Daemonized GoAccess: 48646 This option only works with real time option enabled.\nEgual, it\u0026rsquo;s imperative that the web user is given access to the path that will write the PID process file — otherwise, you will fail!\nYou need to set the pid-file option into the configuration file.\nAs reminder, on OpenBSD, by default, it\u0026rsquo;s on the web chroot: /var/www/run. Prefer to create a sub-directory dedicated to the user www.\nOf course, all of this, it\u0026rsquo;s for the FUN, and the example! :D\nVoila!\n(It\u0026rsquo;s my XP… and yours‽)\nTroubleshooting Here are some errors encountered:\nPermission denied Couldn't open file /var/db/goaccess/xxx/I32_DATES.db: Permission denied Unable to open the specified pid file. Permission denied Unable to open the specified pid file. Permission denied goaccess can not write into the directory! check that directory exists. check rights user; they must match the one of the user who runs goaccess, like : _goaccess:daemon This is the same problem during the generation of HTML files.\nExample:\nGoAccess - version 1.5.1 - Sep 26 2021 14:08:19 Config file: /etc/goaccess/goaccess.conf Fatal error has occurred Error occurred at: src/output.c - output_html - 1183 Unable to open HTML file: Permission denied. Error opening the specified MaxMind DB file GoAccess - version 1.5.5 - Apr 8 2022 09:03:43 Config file: /etc/goaccess/goaccess.conf Fatal error has occurred Error occurred at: src/geoip2.c - init_geoip - 89 Unable to open GeoIP2 database /var/db/GeoIP/GeoLite2-Country.mmdb: Error opening the specified MaxMind DB file You have certainly activate the geoip-database option.\nBut did you download the necessary files and install them in the directory /var/db/GeoIP/?\nNo home directory Make sure that the home directory for the dedicated user really exists ! Then check the existence of the path in your filesystem, without forgetting the user rights on!\nmake sure that the home directory of the dedicated user AND the dir_db variable on the goaccess.sh script matches. Documentations https://www.geeek.org/goaccess-analyser-access-log/ Wikipédia List_of_HTTP_status_codes : 4xx_client_errors WP ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eGoaccess\u003c/strong\u003e is a FLoSS, known to be light, fast, in order to to analyze\nin real time or not the activity on a web server, either directly within\na Unix terminal, or on the HTTPS protocol.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s able to produce statistics on HTML, JSON even CSV format.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Environnement:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD: \u003cdel\u003e6.9\u003c/del\u003e → 7.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eUsual: \u003ccode\u003e:# pkg_add goaccess\u003c/code\u003e\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eThe main file config is on: \u003ccode\u003e/etc/goaccess/goaccess.conf\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ You can use goaccess without any modifications on its file config. \u003cbr\u003e\nThis need to pass all options on the CLI, but few options are clearly\ncommons and can be \u0026ldquo;frozen\u0026rdquo; on the file config.\u003c/p\u003e\n\u003cp\u003e⇒ Too, it\u0026rsquo;s also possible to create numerous files config, each specific\nto a web domain, to set particularly segun this domain. In this case, you\nneed to specify it…\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eIn this article, I use one configuration file, and put some options on\nthe CLI.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eNow, let\u0026rsquo;s see the main configuration options:\u003c/p\u003e\n\u003ch3 id=\"time-and-date-formats\"\u003eTime and Date formats\u003c/h3\u003e\n\u003cp\u003eFormatting the time!\u003c/p\u003e\n\u003cp\u003e⇒ If you use \u003cstrong\u003ehttpd\u003c/strong\u003e, you need to be careful to set correctly the style\nof the log, and into in the goaccess configuration file in the\n\u003cstrong\u003eTime Format Options\u003c/strong\u003e section.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003esee: \u003ca href=\"https://man.openbsd.org/httpd.conf.5#style\" rel=\"external\"\u003ehttpd.conf\u003c/a\u003e(5)#style\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ For \u003cstrong\u003enginx\u003c/strong\u003e, it will be enough to uncomment the following options:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003etime-format %H:%M:%S\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003edate-format %d/%b/%Y\u003c/strong\u003e - this being into \u003cstrong\u003eDate Format Options\u003c/strong\u003e\nsection.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"log-format\"\u003eLog format\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003elog-format\u003c/strong\u003e: prefer the \u003cstrong\u003eCOMBINED\u003c/strong\u003e format — \u003cem\u003efor httpd, you can\nchoose the \u003cstrong\u003ecommon\u003c/strong\u003e format, too\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cem\u003eIf you use \u003cstrong\u003enginx\u003c/strong\u003e, it is imperative to register all statuses,\nnot to filter the 2xx and 3xx — if you had created the \u003cstrong\u003emap\u003c/strong\u003e directive\nyou will have at least to comment it and restart the web service\u003c/em\u003e.\u003c/p\u003e\n\u003ch3 id=\"file-options\"\u003eFile Options\u003c/h3\u003e\n\u003cp\u003eIf you have only one web domaine on the server to analyze, it\u0026rsquo;s usefull\nto set the \u003cstrong\u003elog-file\u003c/strong\u003e option with the absolute directory of the \u003cstrong\u003eaccess.log\u003c/strong\u003e\nrelient.\u003c/p\u003e\n\u003ch3 id=\"parse-options\"\u003eParse Options\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eexclude-ip\u003c/strong\u003e: use this option to exclude adresses IP or network segments,\n\u003cem\u003elike you personal network at home\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e444-as-404\u003c/strong\u003e: the \u003cstrong\u003e444\u003c/strong\u003e error is nginx\u0026rsquo;s specific.\nIf you want to analyze as an \u003cstrong\u003e404\u003c/strong\u003e error, change to \u003cstrong\u003etrue\u003c/strong\u003e.\nIt\u0026rsquo;s up to you!\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eignore-crawlers\u003c/strong\u003e: to ignore all crawlers robots; change to \u003cstrong\u003etrue\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eignore-panel\u003c/strong\u003e is one panel that can be disabled. On Europe, with the\nRGPD, it is better to disable, at least, the \u003cstrong\u003eREMOTE_USER\u003c/strong\u003e panel.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eanonymize-ip\u003c/strong\u003e : change to \u003cstrong\u003etrue\u003c/strong\u003e - \u003cem\u003eegual, because RGPD, disable!\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"persistence-options\"\u003ePersistence Options\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003edb-path\u003c/strong\u003e: the absolute directory of the goaccess database ­— \u003cem\u003econfigure\nonly one domain.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003epersist\u003c/strong\u003e: to backup the analyzed datas.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003erestore\u003c/strong\u003e: load the data to be visualized from the saved data.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ Enable both last options to \u003cstrong\u003etrue\u003c/strong\u003e, if you want to save the data into\nthe goaccess database.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eOf course, there are numerous options.\u003c/p\u003e\n\u003cp\u003eAfter, \u003ca href=\"/en/monitor/goaccess-openbsd/#basic-use\"\u003ejust use\u003c/a\u003e goaccess.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNow, let\u0026rsquo;s push the configuration a further:\u003c/p\u003e\n\u003ch3 id=\"user-system\"\u003eUser system\u003c/h3\u003e\n\u003cp\u003eI prefer to create and use a dedicated user system. Among the advantages\nare the search in log messages and even cron.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# useradd -s /sbin/nologin -d /var/db/goaccess _goaccess\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003e⇒ to search in log messages:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:$ grep goaccess /var/log/messages\u003c/code\u003e or \u003cbr\u003e\n\u003ccode\u003e:$ doas grep _goaccess /var/cron/log\u003c/code\u003e\u003c/p\u003e\n\u003ch4 id=\"doas\"\u003edoas\u003c/h4\u003e\n\u003cp\u003e⇒ I preferred to add the permission to use the \u003cstrong\u003egoaccess\u003c/strong\u003e binary into\n\u003ccode\u003e/etc/doas.conf\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epermit nopass _goaccess cmd /usr/local/bin/goaccess\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003e(I\u0026rsquo;m not absolutly sure about the necessity)\u003c/em\u003e.\u003c/p\u003e\n\u003ch4 id=\"database-directory\"\u003edatabase directory\u003c/h4\u003e\n\u003cp\u003e⇒ Go to create the main directory for the goaccess database:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# mkdir -p /var/db/goaccess\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# chown _goaccess:daemon /var/db/goaccess\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003e(personally, I preferred another absolute folder)\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eThink to add at yours backups!\u003c/strong\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThen if like me, you have several web domains on your server, create\nmany subdirectories with the name of the web domain, such as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ \u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u _goaccess mkdir \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/db/goaccess/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThus, future statistics will be really dedicated to a domain.\u003c/p\u003e\n\u003ch4 id=\"crontab\"\u003ecrontab\u003c/h4\u003e\n\u003cp\u003e⇒ You need to set cron rules:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u _goaccess crontab -e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003e(Egual, it\u0026rsquo;s possible to do by: \u003ccode\u003edoas crontab -u _goaccess -e\u003c/code\u003e)\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eAdd:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e*/15 * * * * -ns goaccess -a --db-path \u0026#34;/var/db/goaccess/domain/\u0026#34; -f /var/www/logs/domain/access.log -o /var/www/goaccess/domain/stats.html\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eLittles explainations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eone crontab to execute every 15 minutes. \u003cem\u003eKeep on mind, it\u0026rsquo;s an example.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003ereplace the \u003cem\u003edomain\u003c/em\u003e string by the domain name.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"authenticate\"\u003eAuthenticate\u003c/h3\u003e\n\u003cp\u003eIt\u0026rsquo;s up to you if you want web authentication before viewing; some people\nthink you should, others don\u0026rsquo;t; personally I prefer it.\u003c/p\u003e\n\u003cp\u003eAfter using \u003cstrong\u003ehtpasswd\u003c/strong\u003e, you need to configure on the server directive\non the virtual host:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efor http, use \u003cstrong\u003eauthenticate\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eon nginx, both \u003cstrong\u003eauth_basic\u003c/strong\u003e and \u003cstrong\u003eauth_basic_user_file\u003c/strong\u003e directives.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"httpd-configuration\"\u003ehttpd configuration\u003c/h4\u003e\n\u003cp\u003eBasically:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-httpd\" data-lang=\"httpd\"\u003eserver \u0026#34;domain.tld\u0026#34; {\n\n(…)\n\n    root \u0026#34;/htdocs/domain.tld/www\u0026#34;\n\n    location \u0026#34;/stats\u0026#34; {\n        authenticate with \u0026#34;/file_htpwd\u0026#34;\n        directory auto index\n    }\n\n(…)\n\n}\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003e\u003cstrong\u003eDo not forget: the path of the htpasswd file is relative to the web chroot!\u003c/strong\u003e\u003c/p\u003e\n\u003ch4 id=\"nginx-configuration\"\u003enginx configuration\u003c/h4\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-nginx\" data-lang=\"nginx\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003elocation\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e/stats/\u003c/span\u003e {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003eauth_basic\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Auth\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003eArea\u0026#34;\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003eauth_basic_user_file\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e/file_htpwd\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003eautoindex\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eon\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eVoila for the \u0026ldquo;configuration\u0026rdquo; part!\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"use\"\u003eUse\u003c/h2\u003e\n\u003ch3 id=\"basic-use\"\u003eBasic use\u003c/h3\u003e\n\u003cp\u003eExecute the binary, as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ goaccess -o /var/www/htdocs/domain.tld/stats/index.html\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"use-_goaccess\"\u003euse _goaccess\u003c/h3\u003e\n\u003cp\u003e⇒ Use goaccess with the \u003cstrong\u003e_goaccess\u003c/strong\u003e user:\u003c/p\u003e\n\u003cp\u003eFor instance, the first time, to precise datation with month and year:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ \u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ \u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edate +\u003cspan style=\"color:#48b685\"\u003e\u0026#39;%Y-%m\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u _goaccess goaccess -a --db-path \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/db/goaccess/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/\u0026#34;\u003c/span\u003e -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/www/logs/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/access.log\u0026#34;\u003c/span\u003e -o \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/var/db/goaccess/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/stats-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.html\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eI created a shell script, named \u003cstrong\u003egoaccess.sh\u003c/strong\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-file\" data-lang=\"file\"\u003e#!/bin/sh\n\n###\n#\n# manage statistics by domain\n#\n##\n\ndate=\u0026#34;$(date +\u0026#39;%m-%Y\u0026#39;)\u0026#34;\ndir_db=\u0026#34;/var/db/goaccess\u0026#34;\ndomain=\u0026#34;$1\u0026#34;\n\nif [ -z \u0026#34;${domain}\u0026#34; ]; then\n    printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;No domain. Script stops!\u0026#34;\n    logger \u0026#34;$0: no domain found as option; script stops!\u0026#34;\n    exit 1\nfi\n\nif [ ! -d \u0026#34;${dir_db}/${domain}/\u0026#34; ]; then\n    printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;The destination directory \u0026#39;${dir_db}/${domain}/\u0026#39; seems not exist!\u0026#34;\n    logger \u0026#34;$0: The destination directory for goaccess not exists; script stops!\u0026#34;\n    exit 2\nfi\n\ngoaccess -a --db-path \u0026#34;${dir_db}/${domain}/\u0026#34; -f \u0026#34;/var/www/logs/${domain}/access.log\u0026#34; -o \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34;\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eAnd, after setting up the \u003cstrong\u003e_goaccess\u003c/strong\u003e crontab:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e*/15 * * * * -ns /directory/goaccess.sh domain-x.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e0    * * * * -ns /directory/goaccess.sh domain-y.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e0    0 * * * -ns /directory/goaccess.sh domain-z.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003e(at differents times)\u003c/em\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNo! It\u0026rsquo;s not finish…\u003c/p\u003e\n\u003cp\u003eIn fact, the generated HTML file to dataviz is wrote on the database directory.\nThe \u003cstrong\u003e_goaccess\u003c/strong\u003e user cant write on the web directory, and does not have\naccess.\u003c/p\u003e\n\u003cp\u003eOn the other hand, it is possible to ask the web user \u003cstrong\u003ewww\u003c/strong\u003e to copy\nthe HTML statistics file on the corresponding web directory.\u003c/p\u003e\n\u003cp\u003eHere, I use this following shell script, named \u003cstrong\u003ecp_stats.sh\u003c/strong\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-file\" data-lang=\"file\"\u003e#!/bin/sh\n\nset -e\n#set -x\n\n###\n#\n# copy statistics files into the domain web directory\n#\n##\n\ndate=\u0026#34;$(date +\u0026#39;%m-%Y\u0026#39;)\u0026#34;\ndomain=\u0026#34;$1\u0026#34;\ndir_db=\u0026#34;/var/db/goaccess\u0026#34;\ndir_stats=\u0026#34;/var/www/htdocs/${domain}/www/stats/\u0026#34;\n\nif [ -z \u0026#34;${domain}\u0026#34; ]; then\n    printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;No domain. Script stops!\u0026#34;\n    logger \u0026#34;$0: no domain found as option; script stops!\u0026#34;\n    exit 1\nfi\n\nif [ ! -f \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34; ]; then\n    printf \u0026#39;%s %s\\n\u0026#39; \u0026#34;KO\u0026#34; \u0026#34;The needed file \u0026#39;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#39; not exists. Script stops!\u0026#34;\n    logger \u0026#34;$0: The needed file \u0026#39;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#39; not exists; script stops!\u0026#34;\n    exit 2\nfi\n\nif [ ! -d \u0026#34;${dir_stats}\u0026#34; ]; then mkdir -p \u0026#34;${dir_stats}\u0026#34;; fi\n\ncp \u0026#34;${dir_db}/${domain}/stats-${domain}-${date}.html\u0026#34; \u0026#34;${dir_stats}\u0026#34;\nchown -R www \u0026#34;${dir_stats}\u0026#34;\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eYou need to modify the crontab of the web user:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u www crontab -e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eLike, for instance:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e*/15 * * * * -ns /directory/cp_stats.sh domain-x.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e5    * * * * -ns /directory/cp_stats.sh domain-y.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e5    0 * * * -ns /directory/cp_stats.sh domain-z.tld\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"time-real\"\u003eTime-real\u003c/h3\u003e\n\u003cp\u003eThe real time use is done in two possible ways.\u003c/p\u003e\n\u003cp\u003eInto those contexts, we will not need the \u003cstrong\u003e_goaccess\u003c/strong\u003e user.\u003c/p\u003e\n\u003ch4 id=\"terminal\"\u003eTerminal\u003c/h4\u003e\n\u003cp\u003e⇒ at least, tape:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ goaccess -f /var/www/logs/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edomain\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/access.log\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eEnjoy the aesthetic view based on monokai colors, by default.\u003c/p\u003e\n\u003ch4 id=\"web-proxy\"\u003eWeb proxy\u003c/h4\u003e\n\u003cp\u003eHere, it\u0026rsquo;s really interesting, but a \u0026ldquo;bit complicated\u0026rdquo;:\u003c/p\u003e\n\u003ch5 id=\"relay-httpd\"\u003erelay httpd\u003c/h5\u003e\n\u003cp\u003eI have not found solution for the httpd service. Maybe, with relayd ;-)\u003c/p\u003e\n\u003ch5 id=\"proxy-nginx\"\u003eproxy nginx\u003c/h5\u003e\n\u003cp\u003eLets to set the server configuration to add the \u003cstrong\u003elocation\u003c/strong\u003e directive:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-nginx\" data-lang=\"nginx\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003elocation\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e/ws\u003c/span\u003e {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#5bc4bf\"\u003eproxy_pass\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003ehttp://localhost:7890\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#5bc4bf\"\u003eproxy_http_version\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.1\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#5bc4bf\"\u003eproxy_set_header\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003eUpgrade\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$http_upgrade\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#5bc4bf\"\u003eproxy_set_header\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003eConnection\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Upgrade\u0026#34;\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch5 id=\"websocket\"\u003ewebsocket\u003c/h5\u003e\n\u003cp\u003eNow, you need to execute goaccess with the \u003cstrong\u003ewww\u003c/strong\u003e web user rights:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u www goaccess -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html --ws-url\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ewss://huc.fr.eu.org:443/ws --port \u003cspan style=\"color:#f99b15\"\u003e7890\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003ePARSING /var/www/logs/doc.huc.fr.eu.org/access.log\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e0\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e @ \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e0/s\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eWebSocket server ready to accept new client connections\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNote: for this test, I have to:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ecreate a new configuration file named \u003cstrong\u003egoaccess.realtime.conf\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eto create a new HTML file\u003c/li\u003e\n\u003cli\u003eand to listen the server on the secure websocket.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAlso, we can monitoring, in real time, the user, into a SSH console, with\nbinaries like \u003cstrong\u003efstat\u003c/strong\u003e, \u003cstrong\u003eps\u003c/strong\u003e; see:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ fstat -u www -n\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER     CMD          PID   FD  DEV      INUM        MODE   R/W    SZ|DV\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e   wd  4,15   \u003cspan style=\"color:#f99b15\"\u003e725760\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e40755\u003c/span\u003e    r      \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e78329\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20620\u003c/span\u003e   rw    5,0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e78329\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20620\u003c/span\u003e   rw    5,0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e78329\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20620\u003c/span\u003e   rw    5,0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e  4,3       \u003cspan style=\"color:#f99b15\"\u003e175\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e10644\u003c/span\u003e   rw        \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e  4,3       \u003cspan style=\"color:#f99b15\"\u003e176\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e10644\u003c/span\u003e   rw        \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e5\u003c/span\u003e  4,3       \u003cspan style=\"color:#f99b15\"\u003e175\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e10644\u003c/span\u003e    w        \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e6\u003c/span\u003e  4,3       \u003cspan style=\"color:#f99b15\"\u003e176\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e10644\u003c/span\u003e    w        \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e8\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e    9* internet stream tcp 0x0 *:7890\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e   \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e   \u003cspan style=\"color:#f99b15\"\u003e11\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  goaccess   \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e   12* internet stream tcp 0x0 127.0.0.1:7890 \u0026lt;-- 127.0.0.1:6459\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ps aux -U www\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER       PID %CPU %MEM   VSZ   RSS TT  STAT   STARTED       TIME COMMAND\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww   \u003cspan style=\"color:#f99b15\"\u003e4071\u003c/span\u003e  0.0  0.1  \u003cspan style=\"color:#f99b15\"\u003e1572\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e3488\u003c/span\u003e ??  S      10:12AM    0:00.88 sshd: www@notty \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003esshd\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww  \u003cspan style=\"color:#f99b15\"\u003e76729\u003c/span\u003e  0.0  0.3 \u003cspan style=\"color:#f99b15\"\u003e10096\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e12752\u003c/span\u003e p0  S+      7:56PM    0:01.49 goaccess -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html /var/www/logs/do\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNow, go to view the \u003cstrong\u003erealtime.html\u003c/strong\u003e file on your web browser.\u003c/p\u003e\n\u003cfigure\u003e\n    \u003ca href=\"/images/monitor/goaccess-realtime.png\" title=\"dashboard goaccess real time\"\u003e\n    \u003cpicture\u003e\n        \n        \u003csource srcset=\"/images/monitor/goaccess-realtime_hu_32de140a245efaa6.webp\" type=\"image/webp\"\u003e\n        \n        \u003cimg alt=\"dashboard goaccess real time\" height=\"36\" loading=\"lazy\" src=\"/images/monitor/goaccess-realtime_hu_1e00616802b3e058.png\" type=\"image/png\" width=\"250\"\u003e\n    \u003c/picture\u003e\n    \u003c/a\u003e\n    \u003cfigcaption\u003edashboard goaccess real time\u003c/figcaption\u003e\n\u003c/figure\u003e\n\u003cp\u003eNote the little dash below the parameter icone, at the top left on the\nscreen.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eIt seems necessary to reload the page; after some time, it lose the connector.\nPress \u003ckbd\u003eF5\u003c/kbd\u003e…\u003c/em\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eFinally, we cant execute goaccess as service, either by the \u003cstrong\u003e\u0026ndash;daemonize\u003c/strong\u003e\noption, or by configuring the dedicated configuration file.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas -u www goaccess --daemonize -p /etc/goaccess/goaccess.realtime.conf -o /var/www/htdocs/huc.fr.eu.org/www/stats/realtime.html --ws-url\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ewss://huc.fr.eu.org:443/ws --port \u003cspan style=\"color:#f99b15\"\u003e7890\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eDaemonized GoAccess: \u003cspan style=\"color:#f99b15\"\u003e48646\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThis option \u003cstrong\u003eonly works with real time option\u003c/strong\u003e enabled.\u003c/p\u003e\n\u003cp\u003eEgual, it\u0026rsquo;s \u003cstrong\u003eimperative that the web user is given access to the path that\nwill write the PID process file\u003c/strong\u003e — \u003cem\u003eotherwise, you will fail!\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eYou need to set the \u003cstrong\u003epid-file\u003c/strong\u003e option into the configuration file.\u003c/p\u003e\n\u003cp\u003eAs reminder, on OpenBSD, by default, it\u0026rsquo;s on the web chroot: \u003ccode\u003e/var/www/run\u003c/code\u003e.\nPrefer to create a sub-directory dedicated to the user \u003cstrong\u003ewww\u003c/strong\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eOf course, all of this, it\u0026rsquo;s for the FUN, and the example! :D\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e(It\u0026rsquo;s my XP… and yours‽)\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003cp\u003eHere are some errors encountered:\u003c/p\u003e\n\u003ch3 id=\"permission-denied\"\u003ePermission denied\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eCouldn't open file /var/db/goaccess/xxx/I32_DATES.db: Permission denied\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eUnable to open the specified pid file. Permission denied\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eUnable to open the specified pid file. Permission denied\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003col\u003e\n\u003cli\u003egoaccess can not write into the directory!\u003c/li\u003e\n\u003cli\u003echeck that directory exists.\u003c/li\u003e\n\u003cli\u003echeck rights user; they must match the one of the user who runs\ngoaccess, like : \u003ccode\u003e_goaccess:daemon\u003c/code\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eThis is the same problem during the generation of HTML files.\u003c/p\u003e\n\u003cp\u003eExample:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eGoAccess - version 1.5.1 - Sep \u003cspan style=\"color:#f99b15\"\u003e26\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e2021\u003c/span\u003e 14:08:19\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eConfig file: /etc/goaccess/goaccess.conf\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eFatal error has occurred\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eError occurred at: src/output.c - output_html - \u003cspan style=\"color:#f99b15\"\u003e1183\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUnable to open HTML file: Permission denied.\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"error-opening-the-specified-maxmind-db-file\"\u003eError opening the specified MaxMind DB file\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eGoAccess - version 1.5.5 - Apr  \u003cspan style=\"color:#f99b15\"\u003e8\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e2022\u003c/span\u003e 09:03:43\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eConfig file: /etc/goaccess/goaccess.conf\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eFatal error has occurred\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eError occurred at: src/geoip2.c - init_geoip - \u003cspan style=\"color:#f99b15\"\u003e89\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUnable to open GeoIP2 database /var/db/GeoIP/GeoLite2-Country.mmdb: Error opening the specified MaxMind DB file\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eYou have certainly activate the \u003ccode\u003egeoip-database\u003c/code\u003e option.\u003c/p\u003e\n\u003cp\u003eBut did you download the necessary files and install them in the directory\n\u003ccode\u003e/var/db/GeoIP/\u003c/code\u003e?\u003c/p\u003e\n\u003ch3 id=\"no-home-directory\"\u003eNo home directory\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMake sure that the home directory for the dedicated user really exists !\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThen check the existence of the path in your filesystem, without forgetting\nthe user rights on!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003emake sure that the home directory of the dedicated user AND the \u003ccode\u003edir_db\u003c/code\u003e\nvariable on the \u003ccode\u003egoaccess.sh\u003c/code\u003e script matches.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.geeek.org/goaccess-analyser-access-log/\" rel=\"external\"\u003ehttps://www.geeek.org/goaccess-analyser-access-log/\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"wikipédia\"\u003eWikipédia\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/List_of_HTTP_status_codes#4xx_client_errors\" title=\"Wikipedia Article: List_of_HTTP_status_codes\"\u003e\n    List_of_HTTP_status_codes : 4xx_client_errors\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Install to use Goaccess on OpenBSD (with configuration snippets for both webserver, httpd and nginx)","tags":["Monitoring","dataviz","log","goaccess","OpenBSD","httpd","nginx"],"date_published":"2021-07-30T15:35:45+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-07-28:/en/monitor/pfstat-openbsd","url":"https://it-log.fr.eu.org/en/monitor/pfstat-openbsd/","title":"pfstat on OpenBSD: analyze stream on IPv4 and IPv6 through PF","author":{"name":"Stéphane HUC"},"content_text":"Description pfstat is a project made by Daniel Hartmeir to generate graphic statistiques about the network stream through the firewall PF.\nOfficial website: https://www.benzedrine.ch/pfstat.html ⇒ Environnement:\nOpenBSD : 6.9 ⇒ 7.1 Installation Usual: # pkg_add pfstat pfstatd\npfstatd is not essential for a simpliest configuration. It becomes interesting to run with dedicated user.\nConfiguration PF Assuming that the network interface is em0, we need to modify /etc/pf.conf to add:\nset loginterface em0 InfoIf you have several network interfaces, it is possible to analyze all; add them line by line. pfstat Configure pfstat is not complicated. By installing the package, the file config is created, as instance on /etc/pfstat.conf.\nYou need to change the web directory where the future images will be create.\n# sed -i -e \u0026#39;s/sis0/em0/g;s/benzedrine.cx/pfstat/g\u0026#39; /etc/pfstat.conf This change all lines where:\nsis0 interface by em0 the folder benzedrine.cx by our future directory pfstat. Next, you need to configure the crontab of root to run pftstat.\n* * * * * -ns /usr/local/bin/pfstat -q -d /var/db/pfstat/pfstat.db */15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db 30 0 * * * -ns /usr/local/bin/pfstat -t 30 -d /var/db/pfstat/pfstat.db first line executed every minute to analyze the network stream and save on database second line generate the images every 15 minutes third will delete every data, at 0:30, datas older than thirty days. ⇒ Create the future folder of the database:\n# mkdir -p /var/db/pfstat/ InfoFYI, you can create a folder when you wish. It\u0026rsquo;s up to you! Voila: a minimum functional configuration.\nNow, we will create a user system, without right, no password to manage both daemon and package.\n_pfstat Create the user _pfstat is usefull to start daemon pfstatd and after to use the binary pfstat:\n# useradd -s /sbin/nologin -d /var/db/pfstat _pfstat # chown _pfstat /var/db/pfstat pfstatd Just enable, set, and active the daemon:\n# rcctl enable pfstatd # rcctl set pfstatd flags -u _pfstat -a 127.0.0.1 # rcctl start pfstatd We have not set port number; by default is 9999.\nTools, like nc, help to assume service is run correctly, like: nc localhost 9999 — normally, stats are displayed, line by line; if not the case, you have one problem…\npfstatd and PF I strongly encourage you to block into OpenBSD firewall, all connections on the pfstatd service!\nA rule like the following should be sufficient:\nblock drop in on ! lo0 proto tcp to port 9999 pfstat and _pfstat Now, we need to reconfigure how using pfstat with the user _pfstat.\nFirst time, we need to comment or delete all writings into the crontab of the root. and set that of the user _pfstat : create a filenamed crontab4pfstat, with those rules: * * * * * -ns /usr/local/bin/pfstat -q -d /var/db/pfstat/pfstat.db -r 127.0.0.1 */15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db 30 0 * * * -ns /usr/local/bin/pfstat -t 30 -d /var/db/pfstat/pfstat.db Little explaination:\noption -r followed by the loopback address: to remote the statistics and save them on the database. Now, add the file content crontab4pfstat into the _pfstat user crontab:\n# crontab -u _pfstat crontab4pfstat Monitoring _pfstat It exists differents ways to monitoring the _pfstat user activity:\ntop -U _pfstat : load averages: 0.05, 0.38, 0.38 56 processes: 54 idle, 2 on processor CPU0 states: 0.0% user, 0.0% nice, 0.0% sys, 0.0% spin, 0.0% intr, 100% idle Memory: Real: 84M/5985M act/tot Free: 9778M Cache: 2757M Swap: 0K/32G PID USERNAME PRI NICE SIZE RES STATE WAIT TIME CPU COMMAND 16833 _pfstat 2 0 700K 984K sleep/6 netcon 0:00 0.00% pfstatd $ fstat -u _pfstat -n USER CMD PID FD DEV INUM MODE R/W SZ|DV _pfstat pfstatd 16833 wd 4,0 2 40755 r 512 _pfstat pfstatd 16833 0 4,0 27162 20666 rw 2,2 _pfstat pfstatd 16833 1 4,0 27162 20666 rw 2,2 _pfstat pfstatd 16833 2 4,0 27162 20666 rw 2,2 _pfstat pfstatd 16833 3 4,0 27028 20600 r 73,0 _pfstat pfstatd 16833 4* internet stream tcp 0x0 127.0.0.1:9999 $ ps aux -U _pfstat USER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMAND _pfstat 16833 0.0 0.0 700 984 ?? I 1:19AM 0:00.02 /usr/local/bin/pfstatd -u _pfstat -a 127.0.0.1 Those commands confirm that:\npfstatd is started and managed by the user _pfstat. the daemon listen on local interface, on number port 9999, is waiting a connection — on these examples. Now, configure httpd:\nhttpd Start to create the needed folder:\n# mkdir -p /var/www/htdocs/pfstat/ Next, add the following directives to the file configuration /etc/httpd.conf, as:\ntypes { include \u0026#34;/usr/share/misc/mime.types\u0026#34; } server \u0026#34;pfstat\u0026#34; { listen on 127.0.0.1 port 80 location \u0026#34;/pfstat/\u0026#34; { directory auto index root \u0026#34;/htdocs/\u0026#34; } } Check the configuration, and enable and start the service:\n# rcctl enable httpd # httpd -n \u0026amp;\u0026amp; rcctl start httpd Now, we can consult locally, at: http://localhost/pfstat\nVoila!\n(another time… but it\u0026rsquo;s not the final time of)\nhttpd and _pfstat Add the _pfstat user to the web group and change the user rights on the web directory:\n# usermod -G www _pfstat # chown -R _pfstat:www /var/www/htdocs/pfstat PFstats PFstats is my little projet: create a responsive webpage to consult easier the created images by pfstat.\nIt is designed to analyze hourly, daily, weekly, monthly and even yearly statistics.\nGit depot: https://tildegit.org/hucste/pfstats See README.md Modified BSD License Here one screenshot:\nScreenshot of 'pfstat.hml' webpage Explainations:\npfstat.conf ⇒ pfstat.conf is configured:\nto analyze IPv4 and IPv6, with the interface em0 to view the hourly, daily, weekly, monthly graphics to publish on web directory: /var/www/htdocs/pfstat. You need to copy into /etc.\nInfoI comment all queues directives; by default, it\u0026rsquo;s not supported. pfstat.html Copy all .css, .js and .html files on the web directory.\nconvert-img.sh ⇒ The shell script transform/convert images JPEG to the Avif and Webp format.\nYou need to install libavif, and libwebp packages.\nFinally:\nadd _pfstat user to your user group, and chmod needed rights to the script # usermod -G userid _pfstat # chmod 0750 /home/userid/folder/pfstats/convert-img.sh InfoGenerate AVIF images can be slow; this is not the case for Webp. Too, depend on your machine. pfstats and crontab You need to modify the second line on the _pfstat crontab:\n15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db; /dir/convert-img.sh pfstats and httpd To manage correctly both images format (avif and webp), it may be necessary to slightly modify the configuration of httpd, to add:\nimage/avif\tavif Like:\ntypes { include \u0026#34;/usr/share/misc/mime.types\u0026#34; image/avif\tavif } ⇒ To check the support of the webp format:\n$ grep webp /usr/share/misc/mime.types image/webp\twebp If the command not display result, we nee to add image/webp\twebp into the directive types. Since OpenBSD 6.9, it\u0026rsquo;s normally not needed!\nTroubleshots ALTQ-style queues not supported anymore The complete message is: /etc/pfstat.conf:61: ALTQ-style queues not supported anymore\nIt seems, by default, that the queues analyze is not possible. Delete or comment all relevent lines.\ndbopen: /var/db/pfstat/pfstat.db: No such file or directory Check if the folder is created!\nVoila!\n(the final count… is down!\nthe final countdown!)\nDocumentations ⇒ Those formats are supported by:\nhttps://caniuse.com/avif https://caniuse.com/webp ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003epfstat\u003c/strong\u003e is a project made by Daniel Hartmeir to generate graphic\nstatistiques about the network stream through the firewall \u003cabbr title=\"Packet Filter\"\u003ePF\u003c/abbr\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOfficial website: \u003ca href=\"https://www.benzedrine.ch/pfstat.html\" rel=\"external\"\u003ehttps://www.benzedrine.ch/pfstat.html\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Environnement:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD : \u003cdel\u003e6.9\u003c/del\u003e ⇒ 7.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eUsual: \u003ccode\u003e# pkg_add pfstat pfstatd\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003epfstatd\u003c/strong\u003e is not essential for a simpliest configuration. It becomes\ninteresting to run with dedicated user.\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"pf\"\u003ePF\u003c/h3\u003e\n\u003cp\u003eAssuming that the network interface is \u003cstrong\u003eem0\u003c/strong\u003e, we need to modify\n\u003ccode\u003e/etc/pf.conf\u003c/code\u003e to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eset loginterface em0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eIf you have several network interfaces, it is possible to analyze all;\nadd them line by line.\u003c/div\u003e\n\n\u003ch3 id=\"pfstat\"\u003epfstat\u003c/h3\u003e\n\u003cp\u003eConfigure \u003cstrong\u003epfstat\u003c/strong\u003e is not complicated. By installing the package, the\nfile config is created, as instance on \u003ccode\u003e/etc/pfstat.conf\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eYou need to change the web directory where the future images\nwill be create.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sed -i -e \u0026#39;s/sis0/em0/g;s/benzedrine.cx/pfstat/g\u0026#39; /etc/pfstat.conf\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThis change all lines where:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esis0\u003c/strong\u003e interface by \u003cstrong\u003eem0\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003ethe folder \u003cem\u003ebenzedrine.cx\u003c/em\u003e by our future directory \u003cem\u003epfstat\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eNext, you need to configure the crontab of root to run \u003cstrong\u003epftstat\u003c/strong\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e*  * * * * -ns /usr/local/bin/pfstat -q -d /var/db/pfstat/pfstat.db\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e*/15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e30 0 * * * -ns /usr/local/bin/pfstat -t 30 -d /var/db/pfstat/pfstat.db\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003efirst line executed every minute to analyze the network stream and\nsave on database\u003c/li\u003e\n\u003cli\u003esecond line generate the images every 15 minutes\u003c/li\u003e\n\u003cli\u003ethird will delete every data, at 0:30, datas older than thirty days.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ Create the future folder of the database:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# mkdir -p /var/db/pfstat/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eFYI, you can create a folder when you wish. It\u0026rsquo;s up to you!\u003c/div\u003e\n\n\u003chr\u003e\n\u003cp\u003eVoila: a minimum functional configuration.\u003c/p\u003e\n\u003cp\u003eNow, we will create a user system, without right, no password to manage\nboth daemon and package.\u003c/p\u003e\n\u003ch3 id=\"_pfstat\"\u003e_pfstat\u003c/h3\u003e\n\u003cp\u003eCreate the user \u003cstrong\u003e_pfstat\u003c/strong\u003e is usefull to start daemon \u003cstrong\u003epfstatd\u003c/strong\u003e and\nafter to use the binary \u003cstrong\u003epfstat\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# useradd -s /sbin/nologin -d /var/db/pfstat  _pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# chown _pfstat /var/db/pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"pfstatd\"\u003epfstatd\u003c/h4\u003e\n\u003cp\u003eJust enable, set, and active the daemon:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable pfstatd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl set pfstatd flags -u _pfstat -a 127.0.0.1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start pfstatd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eWe have not set port number; by default is 9999.\u003c/p\u003e\n\u003cp\u003eTools, like nc, help to assume service is run correctly, like: \u003cbr\u003e\n\u003ccode\u003enc localhost 9999\u003c/code\u003e — normally, stats are displayed, line by line;\n\u003cem\u003eif not the case, you have one problem…\u003c/em\u003e\u003c/p\u003e\n\u003ch5 id=\"pfstatd-and-pf\"\u003epfstatd and PF\u003c/h5\u003e\n\u003cp\u003eI strongly encourage you to block into OpenBSD firewall, all connections\non the pfstatd service!\u003c/p\u003e\n\u003cp\u003eA rule like the following should be sufficient:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eblock drop in on ! lo0 proto tcp to port 9999\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"pfstat-and-_pfstat\"\u003epfstat and _pfstat\u003c/h4\u003e\n\u003cp\u003eNow, we need to reconfigure how using \u003cstrong\u003epfstat\u003c/strong\u003e with the user \u003cstrong\u003e_pfstat\u003c/strong\u003e.\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eFirst time, we need to comment or delete all writings into the crontab\nof the root.\u003c/li\u003e\n\u003cli\u003eand set that of the user \u003cstrong\u003e_pfstat\u003c/strong\u003e :\n\u003cul\u003e\n\u003cli\u003ecreate a filenamed \u003cstrong\u003ecrontab4pfstat\u003c/strong\u003e, with those rules:\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e*  * * * * -ns /usr/local/bin/pfstat -q -d /var/db/pfstat/pfstat.db -r 127.0.0.1\n*/15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db\n30 0 * * * -ns /usr/local/bin/pfstat -t 30 -d /var/db/pfstat/pfstat.db\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eLittle explaination:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eoption \u003ccode\u003e-r\u003c/code\u003e followed by the loopback address: to remote the statistics\nand save them on the database.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNow, add the file content \u003cstrong\u003ecrontab4pfstat\u003c/strong\u003e into the  \u003cstrong\u003e_pfstat\u003c/strong\u003e user crontab:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# crontab -u _pfstat crontab4pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"monitoring-_pfstat\"\u003eMonitoring _pfstat\u003c/h4\u003e\n\u003cp\u003eIt exists differents ways to monitoring the \u003cstrong\u003e_pfstat\u003c/strong\u003e user activity:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003etop -U _pfstat\u003c/code\u003e :\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eload averages:  0.05,  0.38,  0.38                                      \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f99b15\"\u003e56\u003c/span\u003e processes: \u003cspan style=\"color:#f99b15\"\u003e54\u003c/span\u003e idle, \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e on processor                                   \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCPU0 states:  0.0% user,  0.0% nice,  0.0% sys,  0.0% spin,  0.0% intr,  100% idle\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMemory: Real: 84M/5985M act/tot Free: 9778M Cache: 2757M Swap: 0K/32G\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  PID USERNAME PRI NICE  SIZE   RES STATE     WAIT      TIME    CPU COMMAND\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e _pfstat    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  700K  984K sleep/6   netcon    0:00  0.00% pfstatd\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ fstat -u _pfstat -n\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER     CMD          PID   FD  DEV      INUM        MODE   R/W    SZ|DV\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e   wd  4,0         \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e40755\u003c/span\u003e    r      \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2  \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2  \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2  \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27028\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20600\u003c/span\u003e    r   73,0  \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  pfstatd    \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e    4* internet stream tcp 0x0 127.0.0.1:9999\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ ps aux -U _pfstat\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER       PID %CPU %MEM   VSZ   RSS TT  STAT   STARTED       TIME COMMAND\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_pfstat  \u003cspan style=\"color:#f99b15\"\u003e16833\u003c/span\u003e  0.0  0.0   \u003cspan style=\"color:#f99b15\"\u003e700\u003c/span\u003e   \u003cspan style=\"color:#f99b15\"\u003e984\u003c/span\u003e ??  I       1:19AM    0:00.02 /usr/local/bin/pfstatd -u _pfstat -a 127.0.0.1\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThose commands confirm that:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003epfstatd\u003c/strong\u003e is started and managed by the user \u003cstrong\u003e_pfstat\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003ethe daemon listen on local interface, on number port 9999, is waiting\na connection — \u003cem\u003eon these examples\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eNow, configure httpd:\u003c/p\u003e\n\u003ch3 id=\"httpd\"\u003ehttpd\u003c/h3\u003e\n\u003cp\u003eStart to create the needed folder:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# mkdir -p /var/www/htdocs/pfstat/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNext, add the following directives to the file configuration \u003ccode\u003e/etc/httpd.conf\u003c/code\u003e,\nas:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etypes {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003einclude \u0026#34;/usr/share/misc/mime.types\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eserver \u0026#34;pfstat\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#06b6ef\"\u003elisten on 127.0.0.1 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#06b6ef\"\u003elocation \u0026#34;/pfstat/\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#06b6ef\"\u003edirectory auto index\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#06b6ef\"\u003eroot \u0026#34;/htdocs/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eCheck the configuration, and enable and start the service:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable httpd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# httpd -n \u0026amp;\u0026amp; rcctl start httpd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNow, we can consult locally, at: http://localhost/pfstat\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e(another time… but it\u0026rsquo;s not the final time of)\u003c/em\u003e\u003c/p\u003e\n\u003ch4 id=\"httpd-and-_pfstat\"\u003ehttpd and _pfstat\u003c/h4\u003e\n\u003cp\u003eAdd the \u003cstrong\u003e_pfstat\u003c/strong\u003e user to the web group and change the user rights on\nthe web directory:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# usermod -G www _pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# chown -R _pfstat:www /var/www/htdocs/pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003ch2 id=\"pfstats\"\u003ePFstats\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ePFstats\u003c/strong\u003e is my little projet: create a responsive webpage to consult\neasier the created images by pfstat.\u003c/p\u003e\n\u003cp\u003eIt is designed to analyze hourly, daily, weekly, monthly and even yearly\nstatistics.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eGit depot: \u003ca href=\"https://tildegit.org/hucste/pfstats\" rel=\"external\"\u003ehttps://tildegit.org/hucste/pfstats\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSee \u003ca href=\"https://tildegit.org/hucste/pfstats/src/branch/main/README.md\" rel=\"external\"\u003eREADME.md\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tildegit.org/hucste/pfstats/src/branch/main/LICENSE\" rel=\"external\"\u003eModified BSD License\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eHere one screenshot:\u003c/p\u003e\n\u003cfigure\u003e\n    \u003ca href=\"/images/openbsd/pfstats.html.png\" title=\"Screenshot of \u0026#39;pfstat.hml\u0026#39; webpage\"\u003e\n    \u003cpicture\u003e\n        \n        \u003csource srcset=\"/images/openbsd/pfstats.html_hu_44f5065c3fc752c1.webp\" type=\"image/webp\"\u003e\n        \n        \u003cimg alt=\"Screenshot of \u0026#39;pfstat.hml\u0026#39; webpage\" height=\"204\" loading=\"lazy\" src=\"/images/openbsd/pfstats.html_hu_888bbe36212847bd.png\" type=\"image/png\" width=\"250\"\u003e\n    \u003c/picture\u003e\n    \u003c/a\u003e\n    \u003cfigcaption\u003eScreenshot of 'pfstat.hml' webpage\u003c/figcaption\u003e\n\u003c/figure\u003e\n\u003chr\u003e\n\u003cp\u003eExplainations:\u003c/p\u003e\n\u003ch3 id=\"pfstatconf\"\u003epfstat.conf\u003c/h3\u003e\n\u003cp\u003e⇒ \u003cstrong\u003epfstat.conf\u003c/strong\u003e is configured:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eto analyze IPv4 and IPv6, with the interface \u003cstrong\u003eem0\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eto view the hourly, daily, weekly, monthly graphics\u003c/li\u003e\n\u003cli\u003eto publish on web directory: \u003ccode\u003e/var/www/htdocs/pfstat\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou need to copy into \u003ccode\u003e/etc\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eI comment all queues directives; by default, it\u0026rsquo;s not supported.\u003c/div\u003e\n\n\u003ch3 id=\"pfstathtml\"\u003epfstat.html\u003c/h3\u003e\n\u003cp\u003eCopy all .css, .js and .html files on the web directory.\u003c/p\u003e\n\u003ch3 id=\"convert-imgsh\"\u003econvert-img.sh\u003c/h3\u003e\n\u003cp\u003e⇒ The shell script transform/convert images JPEG to the Avif and Webp\nformat.\u003c/p\u003e\n\u003cp\u003eYou need to install \u003cstrong\u003elibavif\u003c/strong\u003e, and \u003cstrong\u003elibwebp\u003c/strong\u003e packages.\u003c/p\u003e\n\u003cp\u003eFinally:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003cstrong\u003e_pfstat\u003c/strong\u003e user to your user group, and\u003c/li\u003e\n\u003cli\u003echmod needed rights to the script\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# usermod -G userid _pfstat\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# chmod 0750 /home/userid/folder/pfstats/convert-img.sh\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eGenerate AVIF images can be slow; this is not the case for Webp. Too,\ndepend on your machine.\u003c/div\u003e\n\n\u003ch3 id=\"pfstats-and-crontab\"\u003epfstats and crontab\u003c/h3\u003e\n\u003cp\u003eYou need to modify the second line on the \u003cstrong\u003e_pfstat\u003c/strong\u003e crontab:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e15 * * * * -ns /usr/local/bin/pfstat -p -d /var/db/pfstat/pfstat.db; /dir/convert-img.sh\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"pfstats-and-httpd\"\u003epfstats and httpd\u003c/h3\u003e\n\u003cp\u003eTo manage correctly both images format (avif and webp), it may be necessary\nto slightly modify the configuration of httpd, to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eimage/avif\tavif\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eLike:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etypes {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003einclude \u0026#34;/usr/share/misc/mime.types\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eimage/avif\tavif\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ To check the support of the webp format:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ grep webp /usr/share/misc/mime.types\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eimage/webp\t\t\t\t\t\twebp\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIf the command not display result, we nee to add \u003ccode\u003eimage/webp\twebp\u003c/code\u003e into\nthe directive \u003cstrong\u003etypes\u003c/strong\u003e. \u003cem\u003eSince OpenBSD 6.9, it\u0026rsquo;s normally not needed!\u003c/em\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"troubleshots\"\u003eTroubleshots\u003c/h2\u003e\n\u003ch3 id=\"altq-style-queues-not-supported-anymore\"\u003eALTQ-style queues not supported anymore\u003c/h3\u003e\n\u003cp\u003eThe complete message is:\n\u003ccode\u003e/etc/pfstat.conf:61: ALTQ-style queues not supported anymore\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIt seems, by default, that the queues analyze is not possible. Delete or\ncomment all relevent lines.\u003c/p\u003e\n\u003ch3 id=\"dbopen-vardbpfstatpfstatdb-no-such-file-or-directory\"\u003edbopen: /var/db/pfstat/pfstat.db: No such file or directory\u003c/h3\u003e\n\u003cp\u003eCheck if the folder is created!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e(the final count… is down!\u003cbr\u003ethe final countdown!)\u003c/em\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cp\u003e⇒ Those formats are supported by:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://caniuse.com/avif\" rel=\"external\"\u003ehttps://caniuse.com/avif\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://caniuse.com/webp\" rel=\"external\"\u003ehttps://caniuse.com/webp\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n","summary":"Install pfstat to analyze stream on IPv4, IPv6 through the firewall PF (Packet Filter), on OpenBSD!","tags":["Monitoring","dataviz","pfstat","OpenBSD","httpd"],"date_published":"2021-07-28T00:13:24+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-07-24:/en/sys/openbsd/gnome","url":"https://it-log.fr.eu.org/en/sys/openbsd/gnome/","title":"OpenBSD: Gnome","author":{"name":"Stéphane HUC"},"content_text":"Description Gnome is one Desktop Environment, available on OpenBSD.\n⇒ Environnement:\nOpenBSD: 6.9 → 7.1 In this tutorial, I assume that OpenBSD has just been freshly installed, and that everything has to be done.\nInstallation Usual: # pkg_add gnome gnome-extras\nSome dependancies are installed, like avahi, consolekit2, dbus, samba, sane-backend, and many more.\nConfiguration The Gnome3 environment works differently from other desktop environments.\nDon\u0026rsquo;t try to set up personal files profile, .kshrc, or even .xsession; they will not be taken into your account when starting and using Gnome.\nDaemons If during the OpenBSD installation you have activated xenodm — the default X Display Manager ­— disable it!\n:# rcctl disable xenodm :# rcctl stop xenodm After, active gdm, the session manager, and all needed daemons.\n:# rcctl enable multicast messagebus avahi_daemon gdm :# rcctl start multicast messagebus avahi_daemon gdm Language To manage your language — mine is FR — you need to modify the /etc/gdm/locale.conf file, as:\n# $OpenBSD: locale.conf,v 1.4 2014/01/08 14:07:48 ajacoutot Exp $ # # Mimics Linux\u0026#39;s /etc/locale.conf. # See locale(1) for a list of supported locales (`locale -a`). # OpenBSD setlocale(3) does not handle LANG #LANG=\u0026#34;en_US.UTF-8\u0026#34; LC_CTYPE=\u0026#34;fr_FR.UTF-8\u0026#34; LC_MESSAGES=\u0026#34;fr_FR.UTF-8\u0026#34; If you do not make this change, and if you have a password with accented characters in your language, according to the keyboard settings during the OpenBSD installation, you will not be able to log in, because gdm uses English by default.\nThink to restart gdm.\nPower Management To use the suspend and hibernate features, you need to active the apmd daemon:\n# rcctl enable apmd # rcctl set apmd flags -A # rcctl start apmd Printing To print, install Cups:\n# pkg_add cups cups-filters cups-libs foomatic-db gutenprint Start both services cupsd, and cups_browsed — this second is useful to detect printers on network using Bonjour broadcast messages, as Avahi.\n# rcctl enable cupsd cups_browsed # rcctl start cups cups_browsed You can administrate by the Printing Parameters, the webui of Cups, *available on http://localhost:631*, or by tools as cupsctl, lpadmin`.\nLibreOffice The gnome-documents manager does not support Office types documents. Install the unoconv package!\nTips Keyboard Display Desktop ⇒ Don\u0026rsquo;t try to hide all windows to show just the desktop, the option is not activated by default!\nOpen \u0026ldquo;Parameters\u0026rdquo; \u0026gt; \u0026ldquo;Keyboard\u0026rdquo;. Into the Navigate windows section, search \u0026ldquo;Minimize all windows\u0026rdquo;. Click on and set the desired key combination, like the Super + D keys.\nRandom Wallpaper This feature does not exist by default!\nI provide two scripts to implement this feature, on my Gitlab: WallpaperManager\nRead the instructions to install and use it.\nTroubleshooting GDM refuse to start!\nDirectly, read the daemon log file, or even that of the messages log:\n# grep gdm /var/log/daemon Gdm: Couldn\u0026rsquo;t connect to system bus: Into both files, daemons, messages, you have the equivalent of this message:\nJul 23 09:38:14 og3 gdm[56941]: Gdm: Couldn\u0026#39;t connect to system bus: Could not connect: No such file or directory Probably, this is because the messagebus service is not activated and started.\nHave you activated all the services as written at the beginning of this article‽\nDocumentations the differents pkg-readme files: /usr/local/share/doc/pkg-readmes/gnome /usr/local/share/doc/pkg-readmes/gnupg /usr/local/share/doc/pkg-readmes/samba /usr/local/share/doc/pkg-readmes/sane-backends and others… Voila!\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eGnome\u003c/strong\u003e is one Desktop Environment, available on OpenBSD.\u003c/p\u003e\n\u003cp\u003e⇒ Environnement:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD: \u003cdel\u003e6.9\u003c/del\u003e → 7.1\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eIn this tutorial, I assume that OpenBSD has just been freshly installed,\nand that everything has to be done.\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eUsual: \u003ccode\u003e# pkg_add gnome gnome-extras\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSome dependancies are installed, like \u003cstrong\u003eavahi\u003c/strong\u003e, \u003cstrong\u003econsolekit2\u003c/strong\u003e, \u003cstrong\u003edbus\u003c/strong\u003e,\n\u003cstrong\u003esamba\u003c/strong\u003e, \u003cstrong\u003esane-backend\u003c/strong\u003e, and many more.\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eThe Gnome3 environment works differently from other desktop environments.\u003c/p\u003e\n\u003cp\u003eDon\u0026rsquo;t try to set up personal files \u003ccode\u003eprofile\u003c/code\u003e, \u003ccode\u003e.kshrc\u003c/code\u003e, or even \u003ccode\u003e.xsession\u003c/code\u003e; they will not be taken into your account when starting and using Gnome.\u003c/p\u003e\n\u003ch3 id=\"daemons\"\u003eDaemons\u003c/h3\u003e\n\u003cp\u003eIf during the OpenBSD installation you have activated \u003ccode\u003exenodm\u003c/code\u003e — \u003cem\u003ethe default X Display Manager\u003c/em\u003e ­— disable it!\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# rcctl disable xenodm\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# rcctl stop xenodm\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAfter, active \u003ccode\u003egdm\u003c/code\u003e, the session manager, and all needed daemons.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# rcctl enable multicast messagebus avahi_daemon gdm\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# rcctl start multicast messagebus avahi_daemon gdm\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"language\"\u003eLanguage\u003c/h3\u003e\n\u003cp\u003eTo manage your language — \u003cem\u003emine is FR\u003c/em\u003e — you need to modify the \u003ccode\u003e/etc/gdm/locale.conf\u003c/code\u003e\nfile, as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# $OpenBSD: locale.conf,v 1.4 2014/01/08 14:07:48 ajacoutot Exp $\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Mimics Linux\u0026#39;s /etc/locale.conf.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# See locale(1) for a list of supported locales (`locale -a`).\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# OpenBSD setlocale(3) does not handle LANG\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#LANG=\u0026#34;en_US.UTF-8\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eLC_CTYPE\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;fr_FR.UTF-8\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eLC_MESSAGES\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;fr_FR.UTF-8\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003eIf you do not make this change, and if you have a password with accented characters in your language, according to the keyboard settings during the OpenBSD installation, you will not be able to log in, because gdm uses English by default\u003c/em\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThink to restart gdm.\u003c/p\u003e\n\u003ch3 id=\"power-management\"\u003ePower Management\u003c/h3\u003e\n\u003cp\u003eTo use the suspend and hibernate features, you need to active the \u003cstrong\u003eapmd\u003c/strong\u003e\ndaemon:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable apmd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl set apmd flags -A\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start apmd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"printing\"\u003ePrinting\u003c/h3\u003e\n\u003cp\u003eTo print, install Cups:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# pkg_add cups cups-filters cups-libs foomatic-db gutenprint\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eStart both services \u003ccode\u003ecupsd\u003c/code\u003e, and \u003ccode\u003ecups_browsed\u003c/code\u003e — \u003cem\u003ethis second is useful to detect printers on network using Bonjour broadcast messages, as Avahi\u003c/em\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable cupsd cups_browsed\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start cups cups_browsed\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eYou can administrate by the Printing Parameters, the webui of Cups, *available on \u003ccode\u003ehttp://localhost:631*, or by tools as \u003c/code\u003ecupsctl\u003ccode\u003e, \u003c/code\u003elpadmin`.\u003c/p\u003e\n\u003ch3 id=\"libreoffice\"\u003eLibreOffice\u003c/h3\u003e\n\u003cp\u003eThe \u003cstrong\u003egnome-documents\u003c/strong\u003e manager does not support Office types documents.\nInstall the \u003ccode\u003eunoconv\u003c/code\u003e package!\u003c/p\u003e\n\u003ch2 id=\"tips\"\u003eTips\u003c/h2\u003e\n\u003ch3 id=\"keyboard\"\u003eKeyboard\u003c/h3\u003e\n\u003ch4 id=\"display-desktop\"\u003eDisplay Desktop\u003c/h4\u003e\n\u003cp\u003e⇒ Don\u0026rsquo;t try to hide all windows to show just the desktop, the option is not activated by default!\u003c/p\u003e\n\u003cp\u003eOpen \u0026ldquo;Parameters\u0026rdquo; \u0026gt; \u0026ldquo;Keyboard\u0026rdquo;. Into the \u003cstrong\u003eNavigate windows\u003c/strong\u003e section, search \u0026ldquo;Minimize all windows\u0026rdquo;. Click on and set the desired key combination, like the \u003ckbd\u003eSuper + D\u003c/kbd\u003e keys.\u003c/p\u003e\n\u003ch3 id=\"random-wallpaper\"\u003eRandom Wallpaper\u003c/h3\u003e\n\u003cp\u003eThis feature does not exist by default!\u003c/p\u003e\n\u003cp\u003eI provide two scripts to implement this feature, on my Gitlab:\n\u003ca href=\"https://framagit.org/hucste/tools/tree/master/OpenBSD/Gnome3/WallpaperManager\" rel=\"external\"\u003eWallpaperManager\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eRead the instructions to install and use it.\u003c/p\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eGDM\u003c/strong\u003e refuse to start!\u003c/p\u003e\n\u003cp\u003eDirectly, read the daemon log file, or even that of the messages log:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# grep gdm /var/log/daemon\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"gdm-couldnt-connect-to-system-bus\"\u003eGdm: Couldn\u0026rsquo;t connect to system bus:\u003c/h3\u003e\n\u003cp\u003eInto both files, \u003cstrong\u003edaemons\u003c/strong\u003e, \u003cstrong\u003emessages\u003c/strong\u003e, you have the equivalent of this message:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-log\" data-lang=\"log\"\u003eJul 23 09:38:14 og3 gdm[56941]: Gdm: Couldn\u0026#39;t connect to system bus: Could not connect: No such file or directory\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eProbably, this is because the \u003cstrong\u003emessagebus\u003c/strong\u003e service is not activated and started.\u003c/p\u003e\n\u003cp\u003eHave you activated all the services as written at the beginning of this article‽\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ethe differents pkg-readme files:\n\u003cul\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/gnome\u003c/li\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/gnupg\u003c/li\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/samba\u003c/li\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/sane-backends\u003c/li\u003e\n\u003cli\u003eand others…\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003chr\u003e\n","summary":"How to install, set and use Gnome on OpenBSD!","tags":["OpenBSD","Gnome"],"date_published":"2021-07-24T20:00:00+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-07-20:/en/sys/openbsd/xfce4","url":"https://it-log.fr.eu.org/en/sys/openbsd/xfce4/","title":"OpenBSD: Xfce4","author":{"name":"Stéphane HUC"},"content_text":"Description Xfce4 is a Desktop Environnement, available on OpenBSD.\n⇒ Environnement:\nOpenBSD: 6.6 → 7.8 Xfce4: 4.14 → 4.20 In this tutorial, I assume that OpenBSD has just been freshly installed, and that everything has to be done.\nInstallation Usual: :# pkg_add xfce xfce-extras\nSome dependancies are installed, like dbus, consolekit2.\nAdditionnal packages By default, some packages are not installed.\nxfce4-icon-theme: additional icons pack xfce4-power-manager: power management for laptop xfce4-pulseaudio: plugin for the pulseaudio sound system - but, it\u0026rsquo;s not necessary… OSS works great! xfce4-xkb : switch between layers keyboard languages - but, is-it really useful, when using the command setxkbmap, or even just kbd, followed with the language code… is enough‽ Configuration Since Xfce4 4.14, available on OpenBSD 6.6, it\u0026rsquo;s a bit easier to configure simply your personal environment system.\nIn a first step, I talk about a basic functional configuration; and, I\u0026rsquo;ll add information to improve your comfort.\n.xsession The first file to create is: ~/.xsession.\nAdd:\n/usr/local/bin/ck-launch-session xfce4-session Voila!\nIt\u0026rsquo;s enough to run correctly Xfce4. Think to restart your session or the machine.\nNow, let\u0026rsquo;s go a little further in the configuration, like setting the French language, or yours, and others useful tips.\n.profile Start setting your personal file: ~/.profile\nto add the following mentions:\nEDITOR=vi # or nano, emacs, vim ENV=$HOME/.kshrc LC_MESSAGES=fr # or fr_FR.UTF8; it\u0026#39;s egual! export EDITOR ENV LC_MESSAGES ⇒ Explains:\nI love nano as editor; into the base, vi is installed. The others need to be installed. We declare a personal ENVironment; here, the pdksh. Finally, define the language, as french. And we export the three variables.\nOf course, it\u0026rsquo;s possible to configure any environment variable, like PS1:\nexport PS1=\u0026quot;[\\t] \\e[0;35m:\\u@\\h: \\e[0;32m\\w \\e[0;36m\\$ \\e[m\u0026quot;\nHere an complete instance:\n# $OpenBSD: dot.profile,v 1.7 2020/01/24 02:09:51 okan Exp $ # # sh/ksh initialization PATH=$HOME/bin:/bin:/sbin:/usr/bin:/usr/sbin:/usr/X11R6/bin:/usr/local/bin:/usr/local/sbin:/usr/games export PATH HOME TERM EDITOR=nano ENV=$HOME/.kshrc LC_MESSAGES=fr export EDITOR ENV LC_MESSAGES You need to change your personal file ~/.xsession to add your environment profile:\n. $HOME/.profile /usr/local/bin/ck-launch-session xfce4-session Thus your graphic session will take account differents settings of your profile, such as language.\n.kshrc The content of this personal file is not complicated. Here is what to add to be functional:\n. /etc/ksh.kshrc . $HOME/.profile HISTCONTROL=ignoredumps HISTFILE=$HOME/.mksh_hist HISTSIZE=10000 PAGER=less export PAGER /usr/local/bin/ck-launch-session xfce4-session ⇒ Useful explains:\nWe source the global initialization for ksh to obtain a correct environment shell.\nWe source your personal profil file.\nHIST variables are usefull to historize the orders commands:\nHISTFILE: to define the backup file history HISTSIZE: the number of commands to remember; do not confuse with the number of lines into file, defined with HISTFILESIZE - not here. it\u0026rsquo;s not necessary to export them. dbus dbus is installed as dependancy.\nThe changes below are not essential, although useful. They\u0026rsquo;re reported on the relative pkg-readme file.\nAdd into your personal file ~/.xsession:\nif [ -x /usr/local/bin/dbus-launch -a -z \u0026#34;${DBUS_SESSION_BUS_ADDRESS}\u0026#34; ]; then eval `dbus-launch --sh-syntax --exit-with-x11` fi The file will look like this:\n. $HOME/.profile if [ -x /usr/local/bin/dbus-launch -a -z \u0026#34;${DBUS_SESSION_BUS_ADDRESS}\u0026#34; ]; then eval `dbus-launch --sh-syntax --exit-with-x11` fi exec xfce4-session Egual, pkg-readme upower informs us that it\u0026rsquo;s useful to run the apmd and messagebus services, so the power management system works; let\u0026rsquo;s go to enable the latter:\n# rcctl enable messagebus # rcctl start messagebus ⇒ if your machine is a laptop, think to install xfce4-powermanager package, which is not provided by default.\nPrinting To print, install Cups:\n# pkg_add cups cups-filters cups-libs foomatic-db gutenprint Start both services cupsd, and cups_browsed — this second is useful to detect printers on network using Bonjour broadcast messages.\n# rcctl enable cupsd cups_browsed # rcctl start cups cups_browsed You can administrate by the webui of Cups, available on http://localhost:631, or by tools as cupsctl, lpadmin.\nSince OpenBSD 6.2, binaries lpq, lpr, and lprm need to be symbolics links to run smoothly.\nEdit again your personal file ~/.kshrc to add:\nfor i in lpq lpr lprm; do alias $i=/usr/local/bin/$i; done Avahi Avahi is, on OpenBSD, the DNS multicast discovery service.\nJust install the avahi package, and after active and start the services:\n# rcctl enable multicast avahi_daemon # rcctl order messagebus avahi_daemon # rcctl start avahi_daemon Normally, messagebus is already started!\nPerformances apmd To use the sleep and hibernate functions, apmd need to be set. We set on automatic performance adjustement mode.\n# rcctl enable apmd # rcctl set apmd flags -A # rcctl start apmd obsdfreqd If you have a laptop or would like the system to manage performance fine-tune performance, you may prefer to use the use of obsdfreqd.\nobsdfreqd is a CPU frequency manager, created by Solène Rapenne, packaged since OpenBSD 7.1.\nIt replace the native apmd daemon.\n# rcctl enable obsdfreqd # rcctl stop apmd # rcctl set apmd flags -L # rcctl start apmd obsdfreqd Explanations:\nit\u0026rsquo;s necessary to start apmd in the manual mode, for obsdfreqd can handle it. obsdfreqd\u0026rsquo;s defaults settings are enough. Tips PF I\u0026rsquo;ve not discuted about firewall rules, but here is an example:\n⇒ Cups :\npass in on egress proto tcp from egress:network to egress port 631 flags S/SA modulate state ⇒ Avahi :\npass proto udp from any to 224.0.0.251 port mdns allow-opts pass inet6 proto udp from any to ff02::fb port mdns allow-opts pass proto udp from any to 239.255.255.250 port ssdp allow-opts pass inet6 proto udp from any to { ff02::c, ff05::c, ff08::c } port ssdp allow-opts Of course, it\u0026rsquo;s up to you!\nVoila Think to restart your session, after modifying yours personals files.\nAfter, you can install others packages…\nVoila!\nDocumentations the differents pkg-readme files: /usr/local/share/doc/pkg-readmes/xfce /usr/local/share/doc/pkg-readmes/dbus /usr/local/share/doc/pkg-readmes/upower Official FAQ: https://wiki.xfce.org/faq Official tips: https://wiki.xfce.org/tips ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eXfce4\u003c/strong\u003e is a Desktop Environnement, available on OpenBSD.\u003c/p\u003e\n\u003cp\u003e⇒ Environnement:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD: \u003cdel\u003e6.6\u003c/del\u003e → 7.8\u003c/li\u003e\n\u003cli\u003eXfce4: \u003cdel\u003e4.14\u003c/del\u003e → 4.20\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eIn this tutorial, I assume that OpenBSD has just been freshly installed, and that everything has to be done.\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eUsual: \u003ccode\u003e:# pkg_add xfce xfce-extras\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSome dependancies are installed, like \u003ccode\u003edbus\u003c/code\u003e, \u003ccode\u003econsolekit2\u003c/code\u003e.\u003c/p\u003e\n\u003ch3 id=\"additionnal-packages\"\u003eAdditionnal packages\u003c/h3\u003e\n\u003cp\u003eBy default, some packages are not installed.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003exfce4-icon-theme\u003c/strong\u003e: additional icons pack\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003exfce4-power-manager\u003c/strong\u003e: power management for laptop\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003exfce4-pulseaudio\u003c/strong\u003e: plugin for the pulseaudio sound system - \u003cem\u003ebut, it\u0026rsquo;s not necessary… OSS works great!\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003exfce4-xkb\u003c/strong\u003e : switch between layers keyboard languages - \u003cem\u003ebut, is-it really useful, when using the command \u003ccode\u003esetxkbmap\u003c/code\u003e, or even just \u003ccode\u003ekbd\u003c/code\u003e, followed with the language code… is enough‽\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eSince Xfce4 4.14, available on OpenBSD 6.6, it\u0026rsquo;s a bit easier to configure simply your personal environment system.\u003c/p\u003e\n\u003cp\u003eIn a first step, I talk about a basic functional configuration; and, I\u0026rsquo;ll add information to improve your comfort.\u003c/p\u003e\n\u003ch3 id=\"xsession\"\u003e.xsession\u003c/h3\u003e\n\u003cp\u003eThe first file to create is: \u003ccode\u003e~/.xsession\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAdd:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e/usr/local/bin/ck-launch-session  xfce4-session\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s enough to run correctly Xfce4.\nThink to restart your session or the machine.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNow, let\u0026rsquo;s go a little further in the configuration, like setting the\nFrench language, \u003cem\u003eor yours\u003c/em\u003e, and others useful tips.\u003c/p\u003e\n\u003ch3 id=\"profile\"\u003e.profile\u003c/h3\u003e\n\u003cp\u003eStart setting your personal file: \u003ccode\u003e~/.profile\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eto add the following mentions:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eEDITOR\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003evi   # or nano, emacs, vim\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eENV\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e$HOME/.kshrc\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eLC_MESSAGES\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003efr  # or fr_FR.UTF8; it\u0026#39;s egual!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eexport EDITOR ENV LC_MESSAGES\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Explains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eI love \u003cstrong\u003enano\u003c/strong\u003e as editor; into the base, \u003cstrong\u003evi\u003c/strong\u003e is installed. The others need to be installed.\u003c/li\u003e\n\u003cli\u003eWe declare a personal ENVironment; here, the \u003cstrong\u003epdksh\u003c/strong\u003e.\u003c/li\u003e\n\u003cli\u003eFinally, define the language, as french.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd we export the three variables.\u003c/p\u003e\n\u003cp\u003eOf course, it\u0026rsquo;s possible to configure any environment variable, like \u003ccode\u003ePS1\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eexport PS1=\u0026quot;[\\t] \\e[0;35m:\\u@\\h: \\e[0;32m\\w \\e[0;36m\\$ \\e[m\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eHere an complete instance:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# $OpenBSD: dot.profile,v 1.7 2020/01/24 02:09:51 okan Exp $\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sh/ksh initialization\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePATH\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e$HOME/bin:/bin:/sbin:/usr/bin:/usr/sbin:/usr/X11R6/bin:/usr/local/bin:/usr/local/sbin:/usr/games\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eexport PATH HOME TERM\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eEDITOR\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003enano\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eENV\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e$HOME/.kshrc\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eLC_MESSAGES\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003efr\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eexport EDITOR ENV LC_MESSAGES\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eYou need to change your personal file \u003ccode\u003e~/.xsession\u003c/code\u003e to add your\nenvironment profile:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e. $HOME/.profile\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e/usr/local/bin/ck-launch-session xfce4-session\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThus your graphic session will take account differents settings of your\nprofile, such as language.\u003c/p\u003e\n\u003ch3 id=\"kshrc\"\u003e.kshrc\u003c/h3\u003e\n\u003cp\u003eThe content of this personal file is not complicated. Here is what to\nadd to be functional:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e. /etc/ksh.kshrc\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e. $HOME/.profile\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHISTCONTROL\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003eignoredumps\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHISTFILE\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e$HOME/.mksh_hist\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHISTSIZE\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e10000\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePAGER\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003eless\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eexport PAGER\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e/usr/local/bin/ck-launch-session xfce4-session\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Useful explains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eWe source the global initialization for ksh to obtain a correct\nenvironment shell.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eWe source your personal profil file.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eHIST\u003c/strong\u003e variables are usefull to historize the orders commands:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eHISTFILE\u003c/code\u003e: to define the backup file history\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eHISTSIZE\u003c/code\u003e: the number of commands to remember; do not confuse with\nthe number of lines into file, defined with \u003ccode\u003eHISTFILESIZE\u003c/code\u003e - \u003cem\u003enot here\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003eit\u0026rsquo;s not necessary to export them.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"dbus\"\u003edbus\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003edbus\u003c/strong\u003e is installed as dependancy.\u003c/p\u003e\n\u003cp\u003eThe changes below are not essential, although useful. They\u0026rsquo;re reported on the relative pkg-readme file.\u003c/p\u003e\n\u003cp\u003eAdd into your personal file \u003ccode\u003e~/.xsession\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eif [ -x /usr/local/bin/dbus-launch -a -z \u0026#34;${DBUS_SESSION_BUS_ADDRESS}\u0026#34; ]; then\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eeval `dbus-launch --sh-syntax --exit-with-x11`\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe file will look like this:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e. $HOME/.profile\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eif [ -x /usr/local/bin/dbus-launch -a -z \u0026#34;${DBUS_SESSION_BUS_ADDRESS}\u0026#34; ]; then\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eeval `dbus-launch --sh-syntax --exit-with-x11`\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eexec xfce4-session\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eEgual, pkg-readme \u003cstrong\u003eupower\u003c/strong\u003e informs us that it\u0026rsquo;s useful to run the \u003cstrong\u003eapmd\u003c/strong\u003e\nand \u003cstrong\u003emessagebus\u003c/strong\u003e services, so the power management system works; let\u0026rsquo;s\ngo to enable the latter:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable messagebus\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start messagebus\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ if your machine is a laptop, think to install \u003cstrong\u003exfce4-powermanager\u003c/strong\u003e\npackage, which is not provided by default.\u003c/p\u003e\n\u003ch3 id=\"printing\"\u003ePrinting\u003c/h3\u003e\n\u003cp\u003eTo print, install Cups:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# pkg_add  cups cups-filters cups-libs foomatic-db gutenprint\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eStart both services \u003cstrong\u003ecupsd\u003c/strong\u003e, and \u003cstrong\u003ecups_browsed\u003c/strong\u003e — \u003cem\u003ethis second is useful\nto detect printers on network using Bonjour broadcast messages\u003c/em\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable cupsd cups_browsed\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start cups cups_browsed\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eYou can administrate by the webui of Cups, available on http://localhost:631,\nor by tools as \u003cstrong\u003ecupsctl\u003c/strong\u003e, \u003cstrong\u003elpadmin\u003c/strong\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eSince OpenBSD 6.2, binaries \u003cstrong\u003elpq\u003c/strong\u003e, \u003cstrong\u003elpr\u003c/strong\u003e, and \u003cstrong\u003elprm\u003c/strong\u003e need to be symbolics\nlinks to run smoothly.\u003c/p\u003e\n\u003cp\u003eEdit again your personal file \u003ccode\u003e~/.kshrc\u003c/code\u003e to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efor i in lpq lpr lprm; do alias $i\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/usr/local/bin/$i; done\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"avahi\"\u003eAvahi\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eAvahi\u003c/strong\u003e is, on OpenBSD, the DNS multicast discovery service.\u003c/p\u003e\n\u003cp\u003eJust install the \u003cstrong\u003eavahi\u003c/strong\u003e package, and after active and start the\nservices:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable multicast avahi_daemon\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl order messagebus avahi_daemon\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start avahi_daemon\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNormally, messagebus is already started!\u003c/p\u003e\n\u003ch3 id=\"performances\"\u003ePerformances\u003c/h3\u003e\n\u003ch4 id=\"apmd\"\u003eapmd\u003c/h4\u003e\n\u003cp\u003eTo use the sleep and hibernate functions, \u003cstrong\u003eapmd\u003c/strong\u003e need to be set.\nWe set on automatic performance adjustement mode.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable apmd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl set apmd flags -A\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start apmd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"obsdfreqd\"\u003eobsdfreqd\u003c/h4\u003e\n\u003cp\u003eIf you have a laptop or would like the system to manage performance\nfine-tune performance, you may prefer to use the use of \u003cstrong\u003eobsdfreqd\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eobsdfreqd\u003c/strong\u003e is a CPU frequency manager, created by Solène\nRapenne, packaged since OpenBSD 7.1.\u003c/p\u003e\n\u003cp\u003eIt replace the native \u003cstrong\u003eapmd\u003c/strong\u003e daemon.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl enable obsdfreqd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl stop apmd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl set apmd flags -L\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl start apmd obsdfreqd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eExplanations\u003c/strong\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eit\u0026rsquo;s necessary to start \u003cstrong\u003eapmd\u003c/strong\u003e in the manual mode, for obsdfreqd can handle it.\u003c/li\u003e\n\u003cli\u003eobsdfreqd\u0026rsquo;s defaults settings are enough.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"tips\"\u003eTips\u003c/h2\u003e\n\u003ch3 id=\"pf\"\u003ePF\u003c/h3\u003e\n\u003cp\u003eI\u0026rsquo;ve not discuted about firewall rules, but here is an example:\u003c/p\u003e\n\u003cp\u003e⇒ Cups :\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in on egress proto tcp from egress:network to egress port 631 flags S/SA modulate state\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Avahi :\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass proto udp from any to 224.0.0.251 port mdns allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass inet6 proto udp from any to ff02::fb port mdns allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass proto udp from any to 239.255.255.250 port ssdp allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass inet6 proto udp from any to { ff02::c, ff05::c, ff08::c } port ssdp allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eOf course, it\u0026rsquo;s up to you!\u003c/p\u003e\n\u003ch3 id=\"voila\"\u003eVoila\u003c/h3\u003e\n\u003cp\u003eThink to restart your session, after modifying yours personals files.\u003c/p\u003e\n\u003cp\u003eAfter, you can install others packages…\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ethe differents pkg-readme files:\n\u003cul\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/xfce\u003c/li\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/dbus\u003c/li\u003e\n\u003cli\u003e/usr/local/share/doc/pkg-readmes/upower\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cul\u003e\n\u003cli\u003eOfficial FAQ: \u003ca href=\"https://wiki.xfce.org/faq\" rel=\"external\"\u003ehttps://wiki.xfce.org/faq\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOfficial tips: \u003ca href=\"https://wiki.xfce.org/tips\" rel=\"external\"\u003ehttps://wiki.xfce.org/tips\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"How-to install, set and use Xfce4 on OpenBSD!","tags":["OpenBSD","Xfce","Xfce4"],"date_published":"2021-07-20T21:05:54+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-07-18:/en/sys/openbsd/nut","url":"https://it-log.fr.eu.org/en/sys/openbsd/nut/","title":"OpenBSD: Managing an inverter/converter with NUT","author":{"name":"Stéphane HUC"},"content_text":"Description Having an Eaton Ellipse ECO UPS, I use the NUT project to manage it under OpenBSD.\n⇒ OS:\nOpenBSD: 6.9 ⇒ 7.6 ⇒ UPS Hardware: Eaton Ellipse ECO 650 VA USB FR, MGE ELLIPSE 1000\nInstallation Like as : # pkg_add nut\nConfiguration The nut-scanner tool allow to detect any UPS hardware connected, either by USB, or network.\nWith administrator rights:\nExample for Eaton Ellipse ECO 650 VA USB FR : :$ doas nut-scanner SNMP library not found. SNMP search disabled. Neon library not found. XML search disabled. AVAHI client library not found. AVAHI search disabled. Scanning USB bus. No start IP, skipping NUT bus (old connect method) [nutdev1] driver = \u0026#34;usbhid-ups\u0026#34; port = \u0026#34;auto\u0026#34; vendorid = \u0026#34;0463\u0026#34; productid = \u0026#34;FFFF\u0026#34; product = \u0026#34;Ellipse ECO\u0026#34; serial = \u0026#34;000000000\u0026#34; vendor = \u0026#34;EATON\u0026#34; bus = \u0026#34;005\u0026#34; Example for MGE ELLIPSE 1000 : Cannot load SNMP library (libnetsnmp.so) : file not found. SNMP search disabled. Cannot load XML library (libneon.so) : file not found. XML search disabled. Scanning USB bus. No start IP, skipping NUT bus (old connect method) Scanning NUT bus (avahi method). [nutdev1] driver = \u0026#34;usbhid-ups\u0026#34; port = \u0026#34;auto\u0026#34; vendorid = \u0026#34;0463\u0026#34; productid = \u0026#34;FFFF\u0026#34; product = \u0026#34;ELLIPSE\u0026#34; serial = \u0026#34;1H6G4401F\u0026#34; vendor = \u0026#34;MGE UPS SYSTEMS\u0026#34; bus = \u0026#34;001\u0026#34; device = \u0026#34;002\u0026#34; busport = \u0026#34;002\u0026#34; ###NOTMATCHED-YET###bcdDevice = \u0026#34;4241\u0026#34; Now, few configuration files are to be modified. Any change on one of them needs to restart the ad hoc services.\nups.conf Configuration file: /etc/nut/ups.conf You have to fill this file with the returned informations by the software:\nExample for Eaton Ellipse ECO 650 VA USB FR : (…) [eaton] desc = \u0026#34;Eaton Ellipse ECO 650 VA USB FR\u0026#34; driver = \u0026#34;usbhid-ups\u0026#34; port = \u0026#34;auto\u0026#34; vendorid = \u0026#34;0463\u0026#34; productid = \u0026#34;FFFF\u0026#34; product = \u0026#34;Ellipse ECO\u0026#34; serial = \u0026#34;000000000\u0026#34; vendor = \u0026#34;EATON\u0026#34; bus = \u0026#34;005\u0026#34; upsd.conf Configuration file: /etc/nut/upsd.conf This file allow to set the access control to the managed datas by upds. By default, the server is only accessible on localhost, in IPv4, IPv6, on port 3493.\nAs instance, you need to set this file to use TLS.\nInfoSince v2.4.0, the ACL and allowfrom directives have been replaced by the LISTEN directive and tcp-wrappers! (cf la note de changements…)\nDo not use thoses oldiers ACL directives; many old tutorials refer to it :( Take it into account!\nWarningIf the LISTEN directive is configured to allow access on IPv4, IPv6 adress, you have to manage PF to allow the connexion on the adequat port… upsd.users Configuration file: /etc/nut/upsd.users This configuration file allow to set users who will have rights to interact with the upsd server.\nWarningIt is IMPERATIVE that this file has the most minimalist system rights! By default, on OpenBSD, only the dedicate user had read and write access.\n:$ doas chmod 0400 /etc/nut/upsd.users Now, set an user who will have the rights to comminucate between upsd and upmon servers:\n[upsmon] password = *** upsmon master More explains, here we are:\nan upsmon username into the brackets with master rights on upsmon service. (this defines the role which, according to its dominance, will stop the system first or last, in the case of management of several connected OS; in the context of a single managed OS, the value master is imposed by itself). and, set the password value, by your choice. Now, we modify the upsmon.conf file.\nupsmon.conf Configuration file: /etc/nut/upsmon.conf This configuration file allow the monitor service.\nWarningWarning: this file contains sensitive information, it is therefore imperative to check the permissions and user rights. Following the modification of the upsd.users file to configure a upsmon user, we need to add a MONITOR directive, such as:\nMONITOR eaton@localhost 1 upsmon *** master (Change \u0026lsquo;***\u0026rsquo; by your upsmon password)\n⇒ Now, at least, we need to modify NOTIFYMSG, NOTIFYFLAG directives; please, see the official documentation…\n⇒ About the NOTIFYFLAG directives, it is important to add the EXEC flag for the execution of commands. Without it, they will not be executed.\n⇒ About the NOTIFYCMD directive: this is not set up correctly:\nfirst, uncomment it, and change the path to the upssched binary, like: NOTIFYCMD /usr/local/sbin/upssched Now, the upsmon service will relay to upsched binary; this tool will read the upssched.conf configuration file. See the Suppressing notify storms official documentation about why it\u0026rsquo;s needed!\nupssched.conf Configuration file: /etc/nut/upssched.conf This configuration file allow actions to plan.\nIt\u0026rsquo;s necessary to uncomment PIPEFN, LOCKFN, and AT directives.\n⇒ About LOCKFN and PIPEFN: the absolute pathname by default not exists; you need to create and give access for the _ups user:\n:# install -d -o _ups -g wheel -m 750 /var/db/nut/upssched ⇒ Now, we create the needed AT directives; as instance:\n(…) AT ONBATT * START-TIMER onbatt 15 AT ONBATT * START-TIMER onbattwarn 30 (…) AT ONLINE * CANCEL-TIMER onbatt AT ONLINE * CANCEL-TIMER onbattwarn (…) AT ONLINE * EXECUTE ups-back-on-line FYI: it\u0026rsquo;s possible to modify the /usr/local/bin/upssched-cmd script to interact with the system according to the called event. See the official documentation…\nupsset.conf Configuration file: /etc/nut/upsset.conf This file allow to use CGI scripts, builded on the nut-cgi package. One only role: to certify that the configuration to use the CGI scripts is indeed (supposedly?) secure.\nIt is only useful in this context.\nPermissions InfoAt each OpenBSD release migration, it will be necessary to change the permissions again, as they are permissions again, as they are reset. During the installation, here are configured:\nan _ups user and an _ups group It is necessary to configure user permissions in order to have access to the appropriate device node.\n⇒ For the USB devices, you need to identify the USB controller to which the UPS device is connected, or even the ugen device node(s).\nWe use the usbdevs command, like as:\n:$ doas usbdevs (…) Controller /dev/usb5: addr 01: 1002:0000 ATI, OHCI root hub addr 02: 0463:ffff EATON, Ellipse ECO (…) In this cas, the UPS device is connected on the usb5 controller, without specified device nodes.\nNow, we change the rights user on the device; on this case:\n:$ doas chown :_ups /dev/usb5 # ou, chgrp _ups /dev/usb5 :$ doas chmod g+w /dev/usb5 Now, the _ups group gained access to the controller!\nFinally, let\u0026rsquo;s make sure we have user rights on the files into \u0026lsquo;/etc/nut\u0026rsquo;:\n:$ doas chown _ups:_ups /etc/nut/ups* Normally, this enough to start the services.\nWarningFew USB APC-like inverters have problems; see the pkg-readme file! ⇒ if the inverter is connected by RS232, either you need to:\nadd the _ups user to the dialer group, or modify the user rights on the /dev/tty adequat, that the _ups user can manage it. Services About services, you have to enable and start those follow daemons:\nupsd: to manage network server upsmon: to manage the monitor upsd need to start in first, before upsmon.\n:$ doas rcctl enable upsd upsmon :$ doas rcctl set upsd flags -u _ups :$ doas rcctl start upsd upsmon Normally, the daemon log notify thoses services:\n(…) Jul 17 13:25:34 sh1 usbhid-ups[47317]: Startup successful Jul 17 13:25:34 sh1 upsd[83153]: listening on ::1 port 3493 Jul 17 13:25:34 sh1 upsd[83153]: listening on 127.0.0.1 port 3493 Jul 17 13:25:34 sh1 upsd[83153]: Connected to UPS [eaton]: usbhid-ups-eaton Jul 17 13:25:34 sh1 upsd[90348]: Startup successful Jul 17 13:25:34 sh1 upsmon[19005]: Startup successful (…) Check Status upsc is a tool to check the inverter status, like: :$ upsc eaton est la même chose que faire $ upsc eaton@localhost\n⇒ To known the battery status:\n:$ upsc eaton ups.status OL Few explains:\nOL signify On Line; all is good! OB: On Battery: the inverter now only works on the battery LB: Low Battery: the battery is at its lowest charge level! OB and LB must trigger actions; they are configured on upsmon.conf file, or even upssched.conf.\nProcess and files You can check what are the process managed by the _ups user, and the opened files; as instance, with ps and fstat:\n:$ ps aux -U _ups USER PID %CPU %MEM VSZ RSS TT STAT STARTED TIME COMMAND _ups 31655 0.0 0.0 836 1668 ?? S 5:07PM 0:00.70 /usr/local/bin/usbhid-ups -a eaton _ups 4840 0.0 0.0 764 1308 ?? S 5:07PM 0:00.12 /usr/local/sbin/upsd -u _ups _ups 65469 0.0 0.0 780 3084 ?? S 5:07PM 0:00.09 /usr/local/sbin/upsmon :$ fstat -u _ups -n USER CMD PID FD DEV INUM MODE R/W SZ|DV _ups upsmon 65469 wd 4,0 103712 40700 r 512 _ups upsmon 65469 0 4,0 27162 20666 rw 2,2 _ups upsmon 65469 1 4,0 27162 20666 rw 2,2 _ups upsmon 65469 2 4,0 27162 20666 rw 2,2 _ups upsmon 65469 3* internet stream tcp 0x0 127.0.0.1:26706 --\u0026gt; 127.0.0.1:3493 _ups upsmon 65469 4 pipe 0x0 state: _ups upsd 4840 wd 4,4 26111 40700 r 512 _ups upsd 4840 0 4,0 27162 20666 rw 2,2 _ups upsd 4840 1 4,0 27162 20666 rw 2,2 _ups upsd 4840 2 4,0 27162 20666 rw 2,2 _ups upsd 4840 3* internet6 stream tcp 0x0 [::1]:3493 _ups upsd 4840 4* internet stream tcp 0x0 127.0.0.1:3493 _ups upsd 4840 5* unix stream 0x0 _ups upsd 4840 6* internet stream tcp 0x0 127.0.0.1:3493 \u0026lt;-- 127.0.0.1:26706 _ups usbhid-ups 31655 wd 4,4 26111 40700 r 512 _ups usbhid-ups 31655 0 4,0 27162 20666 rw 2,2 _ups usbhid-ups 31655 1 4,0 27162 20666 rw 2,2 _ups usbhid-ups 31655 2 4,0 27162 20666 rw 2,2 _ups usbhid-ups 31655 3 pipe 0x0 state: _ups usbhid-ups 31655 4 pipe 0x0 state: _ups usbhid-ups 31655 5* unix stream 0x0 /var/db/nut/usbhid-ups-eaton _ups usbhid-ups 31655 6* unix stream 0x0 /var/db/nut/usbhid-ups-eaton We notice:\nupsd and upsmon run correctly, well managed by _ups user\nstreams TCP are correctly created, and used on localhost the eaton profil is correctly managed by usbhid-ups!\nTroubleshooting Connection refused Here, an example about errors messages:\n(…) upsd[55984]: Can\u0026#39;t connect to UPS [eaton] (usbhid-ups-eaton): Connection refused upsmon[20574]: Poll UPS [eaton@localhost] failed - Driver not connected upsmon[20574]: Communications with UPS eaton@localhost lost (…) upsmon[44238]: UPS eaton@localhost is unavailable upsmon[44238]: UPS [eaton@localhost]: connect failed: Connection failure: Connection refused (…) At least, two possibles reasons:\ncheck the physical USB connection. May be, it\u0026rsquo;s usefull to change the USB cable, or disconnect to reconnect it. Even, the USB ports on the motherboard or your USB hub can be defective/faulty.\nafter a OpenBSD upgrade: it\u0026rsquo;s necessary to redo the needed permissions !\nLogin failed upsmon[39287]: Login on UPS [eaton@localhost] failed - got [ERR ACCESS-DENIED] Check your managed user between upsd.users and upsmon.conf files.\nPermission denied upsd[87303]: Can\u0026#39;t open /etc/nut/upsd.conf: Permission denied Check the user rights on this file; it must belong to the _ups user.\nnut-cgi nut-cgi provides CGI scripts to monitor the inverter through the web service.\nActually, this officially works only with the Apache server, and requires writing a configuration file hosts.conf, not created by default.\nDocumentations Projet NUT : https://networkupstools.org/ pkg-readme : /usr/local/share/doc/pkg-readmes/nut ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eHaving an Eaton Ellipse ECO UPS, I use the \u003cabbr title=\"Network UPS Tools\"\u003eNUT\u003c/abbr\u003e\nproject to manage it under OpenBSD.\u003c/p\u003e\n\u003cp\u003e⇒ OS:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD: \u003cdel\u003e6.9\u003c/del\u003e ⇒ 7.6\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ UPS Hardware: \u003cdel\u003eEaton Ellipse ECO 650 VA USB FR\u003c/del\u003e, \u003cstrong\u003eMGE ELLIPSE 1000\u003c/strong\u003e\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eLike as : \u003ccode\u003e# pkg_add nut\u003c/code\u003e\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eThe \u003cstrong\u003enut-scanner\u003c/strong\u003e tool allow to detect any UPS hardware connected, either\nby USB, or network.\u003c/p\u003e\n\u003cp\u003eWith administrator rights:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExample for Eaton Ellipse ECO 650 VA USB FR :\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas nut-scanner\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSNMP library not found. SNMP search disabled.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNeon library not found. XML search disabled.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAVAHI client library not found. AVAHI search disabled.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eScanning USB bus.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNo start IP, skipping NUT bus \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eold connect method\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003enutdev1\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003edriver\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;usbhid-ups\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;auto\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003evendorid\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;0463\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eproductid\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;FFFF\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eproduct\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Ellipse ECO\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eserial\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;000000000\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003evendor\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;EATON\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ebus\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;005\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003eExample for MGE ELLIPSE 1000 :\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCannot load SNMP library \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003elibnetsnmp.so\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e : file not found. SNMP search disabled.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCannot load XML library \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003elibneon.so\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e : file not found. XML search disabled.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eScanning USB bus.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNo start IP, skipping NUT bus \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eold connect method\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eScanning NUT bus \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eavahi method\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003enutdev1\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003edriver\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;usbhid-ups\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;auto\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003evendorid\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;0463\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eproductid\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;FFFF\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eproduct\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ELLIPSE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eserial\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;1H6G4401F\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003evendor\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;MGE UPS SYSTEMS\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ebus\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;001\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003edevice\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;002\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003ebusport\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;002\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e###NOTMATCHED-YET###bcdDevice = \u0026#34;4241\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNow, few configuration files are to be modified. Any change on one of them\nneeds to restart the ad hoc services.\u003c/p\u003e\n\u003ch3 id=\"upsconf\"\u003eups.conf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/ups.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eYou have to fill this file with the returned informations by the software:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExample for Eaton Ellipse ECO 650 VA USB FR :\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003e[eaton]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003edesc\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Eaton Ellipse ECO 650 VA USB FR\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    driver = \u0026#34;usbhid-ups\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    port = \u0026#34;auto\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    vendorid = \u0026#34;0463\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    productid = \u0026#34;FFFF\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    product = \u0026#34;Ellipse ECO\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    serial = \u0026#34;000000000\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    vendor = \u0026#34;EATON\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    bus = \u0026#34;005\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"upsdconf\"\u003eupsd.conf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/upsd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis file allow to set the access control to the managed datas by upds.\nBy default, the server is only accessible on localhost, in IPv4, IPv6,\non port 3493.\u003c/p\u003e\n\u003cp\u003eAs instance, you need to set this file to use TLS.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eSince v2.4.0, the \u003cstrong\u003eACL\u003c/strong\u003e and \u003cstrong\u003eallowfrom\u003c/strong\u003e directives have been replaced\nby the \u003cstrong\u003eLISTEN\u003c/strong\u003e directive and tcp-wrappers! \u003cbr\u003e\n\u003cem\u003e(cf la \u003ca href=\"https://networkupstools.org/docs/user-manual.chunked/apis12.html\" rel=\"external\"\u003enote de changements\u003c/a\u003e…)\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eDo not use thoses oldiers ACL directives; many old tutorials refer to it :( \u003cbr\u003e\nTake it into account!\u003c/p\u003e\n\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eIf the LISTEN directive is configured to allow access on IPv4, IPv6 adress,\nyou have to manage PF to allow the connexion on the adequat port…\u003c/div\u003e\n\n\u003ch3 id=\"upsdusers\"\u003eupsd.users\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/upsd.users\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis configuration file allow to set users who will have rights to interact\nwith the upsd server.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eIt is IMPERATIVE that this file has the most minimalist system rights! \u003cbr\u003e\n\u003cem\u003eBy default, on OpenBSD, only the dedicate user had read and write access.\u003c/em\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas chmod \u003cspan style=\"color:#f99b15\"\u003e0400\u003c/span\u003e /etc/nut/upsd.users\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003c/div\u003e\n\n\u003cp\u003eNow, set an user who will have the rights to comminucate between upsd and\nupmon servers:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003e[upsmon]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003epassword\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e***\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    upsmon master\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eMore explains, here we are:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ean \u003cstrong\u003eupsmon\u003c/strong\u003e username \u003cem\u003einto the brackets\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003ewith master rights on upsmon service.\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(this defines the role which, according to its dominance, will\nstop the system first or last, in the case of management of several\nconnected OS; in the context of a single managed OS, the value\n\u003cstrong\u003emaster\u003c/strong\u003e is imposed by itself)\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eand, set the \u003cstrong\u003epassword\u003c/strong\u003e value, by your choice.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eNow, we modify the \u003cstrong\u003eupsmon.conf\u003c/strong\u003e file.\u003c/p\u003e\n\u003ch3 id=\"upsmonconf\"\u003eupsmon.conf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/upsmon.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis configuration file allow the monitor service.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eWarning: this file contains sensitive information, it is therefore\nimperative to check the permissions and user rights.\u003c/div\u003e\n\n\u003cp\u003eFollowing the modification of the \u003cstrong\u003eupsd.users\u003c/strong\u003e file to configure a\n\u003cstrong\u003eupsmon\u003c/strong\u003e user, we need to add a \u003cstrong\u003eMONITOR\u003c/strong\u003e directive, such as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eMONITOR eaton@localhost 1 upsmon *** master\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003e(Change \u0026lsquo;***\u0026rsquo; by your upsmon password)\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e⇒ Now, at least, we need to modify \u003cstrong\u003eNOTIFYMSG\u003c/strong\u003e, \u003cstrong\u003eNOTIFYFLAG\u003c/strong\u003e directives;\n\u003cem\u003eplease, see the official documentation\u003c/em\u003e…\u003c/p\u003e\n\u003cp\u003e⇒ About the \u003cstrong\u003eNOTIFYFLAG\u003c/strong\u003e directives, it is important to add the \u003cstrong\u003eEXEC\u003c/strong\u003e\nflag for the execution of commands. Without it, they will not be executed.\u003c/p\u003e\n\u003cp\u003e⇒ About the \u003cstrong\u003eNOTIFYCMD\u003c/strong\u003e directive: this is not set up correctly:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efirst, uncomment it, and\u003c/li\u003e\n\u003cli\u003echange the path to the \u003cstrong\u003eupssched\u003c/strong\u003e binary, like: \u003cbr\u003e\n\u003ccode\u003eNOTIFYCMD /usr/local/sbin/upssched\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNow, the \u003cstrong\u003eupsmon\u003c/strong\u003e service will relay to \u003cstrong\u003eupsched\u003c/strong\u003e binary; this tool\nwill read the \u003cstrong\u003eupssched.conf\u003c/strong\u003e configuration file. \u003cbr\u003e\n\u003cem\u003eSee the \u003cstrong\u003e\u003ca href=\"https://networkupstools.org/docs/user-manual.chunked/ar01s07.html\" rel=\"external\"\u003eSuppressing notify storms\u003c/a\u003e\u003c/strong\u003e\nofficial documentation about why it\u0026rsquo;s needed!\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"upsschedconf\"\u003eupssched.conf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/upssched.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis configuration file allow actions to plan.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s necessary to uncomment \u003cstrong\u003ePIPEFN\u003c/strong\u003e, \u003cstrong\u003eLOCKFN\u003c/strong\u003e, and \u003cstrong\u003eAT\u003c/strong\u003e directives.\u003c/p\u003e\n\u003cp\u003e⇒ About \u003cstrong\u003eLOCKFN\u003c/strong\u003e and \u003cstrong\u003ePIPEFN\u003c/strong\u003e: the absolute pathname by default not\nexists; you need to create and give access for the \u003cstrong\u003e_ups\u003c/strong\u003e user:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# install -d -o _ups -g wheel -m \u003cspan style=\"color:#f99b15\"\u003e750\u003c/span\u003e /var/db/nut/upssched\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Now, we create the needed \u003cstrong\u003eAT\u003c/strong\u003e directives; as instance:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAT ONBATT * START-TIMER onbatt 15\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAT ONBATT * START-TIMER onbattwarn 30\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAT ONLINE * CANCEL-TIMER onbatt\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAT ONLINE * CANCEL-TIMER onbattwarn\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAT ONLINE * EXECUTE ups-back-on-line\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eFYI: it\u0026rsquo;s possible to modify the \u003ccode\u003e/usr/local/bin/upssched-cmd\u003c/code\u003e script\nto interact with the system according to the called event.\n\u003cem\u003eSee the official documentation\u003c/em\u003e…\u003c/p\u003e\n\u003ch3 id=\"upssetconf\"\u003eupsset.conf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/nut/upsset.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis file allow to use CGI scripts, builded on the \u003cstrong\u003enut-cgi\u003c/strong\u003e package.\nOne only role: to certify that the configuration to use the CGI scripts\nis indeed (supposedly?) secure.\u003c/p\u003e\n\u003cp\u003eIt is \u003cstrong\u003eonly\u003c/strong\u003e useful in this context.\u003c/p\u003e\n\u003ch3 id=\"permissions\"\u003ePermissions\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eAt each OpenBSD release migration, it will be necessary to change the\npermissions again, as they are permissions again, as they are reset.\u003c/div\u003e\n\n\u003cp\u003eDuring the installation, here are configured:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ean \u003cstrong\u003e_ups\u003c/strong\u003e user\u003c/li\u003e\n\u003cli\u003eand an \u003cstrong\u003e_ups\u003c/strong\u003e group\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIt is necessary to configure user permissions in order to have access\nto the appropriate device node.\u003c/p\u003e\n\u003cp\u003e⇒ For the USB devices, you need to identify the USB controller to which\nthe UPS device is connected, or even the \u003cstrong\u003eugen\u003c/strong\u003e device node(s).\u003c/p\u003e\n\u003cp\u003eWe use the \u003cstrong\u003eusbdevs\u003c/strong\u003e command, like as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas usbdevs\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eController /dev/usb5:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eaddr 01: 1002:0000 ATI, OHCI root hub\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eaddr 02: 0463:ffff EATON, Ellipse ECO\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cem\u003eIn this cas, the UPS device is connected on the \u003cstrong\u003eusb5\u003c/strong\u003e controller,\nwithout specified device nodes\u003c/em\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNow, we change the rights user on the device; on this case:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas chown :_ups /dev/usb5 \u003cspan style=\"color:#776e71\"\u003e# ou, chgrp _ups /dev/usb5\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas chmod g+w /dev/usb5\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNow, the \u003cstrong\u003e_ups\u003c/strong\u003e group gained access to the controller!\u003c/p\u003e\n\u003cp\u003eFinally, let\u0026rsquo;s make sure we have user rights on the files into \u0026lsquo;/etc/nut\u0026rsquo;:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas chown _ups:_ups /etc/nut/ups*\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNormally, this enough to start the services.\u003c/p\u003e\n\u003chr\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eFew USB APC-like inverters have problems; see the pkg-readme file!\u003c/div\u003e\n\n\u003chr\u003e\n\u003cp\u003e⇒ if the inverter is connected by RS232, either you need to:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eadd the \u003cstrong\u003e_ups\u003c/strong\u003e user to the \u003cstrong\u003edialer\u003c/strong\u003e group, or\u003c/li\u003e\n\u003cli\u003emodify the user rights on the \u003ccode\u003e/dev/tty\u003c/code\u003e adequat, that the \u003cstrong\u003e_ups\u003c/strong\u003e user\ncan manage it.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"services\"\u003eServices\u003c/h3\u003e\n\u003cp\u003eAbout services, you have to enable and start those follow daemons:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eupsd\u003c/strong\u003e: to manage network server\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eupsmon\u003c/strong\u003e: to manage the monitor\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eupsd\u003c/strong\u003e need to start in first, before \u003cstrong\u003eupsmon\u003c/strong\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas rcctl enable upsd upsmon\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas rcctl set upsd flags -u _ups\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ doas rcctl start upsd upsmon\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNormally, the \u003cstrong\u003edaemon\u003c/strong\u003e log notify thoses services:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 usbhid-ups\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e47317\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Startup successful\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 upsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e83153\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: listening on ::1 port \u003cspan style=\"color:#f99b15\"\u003e3493\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 upsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e83153\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: listening on 127.0.0.1 port \u003cspan style=\"color:#f99b15\"\u003e3493\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 upsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e83153\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Connected to UPS \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eeaton\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: usbhid-ups-eaton\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 upsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e90348\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Startup successful\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eJul \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 13:25:34 sh1 upsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e19005\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Startup successful\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"check\"\u003eCheck\u003c/h2\u003e\n\u003ch3 id=\"status\"\u003eStatus\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eupsc\u003c/strong\u003e is a tool to check the inverter status, like: \u003cbr\u003e\n\u003ccode\u003e:$ upsc eaton\u003c/code\u003e est la même chose que faire \u003ccode\u003e$ upsc eaton@localhost\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ To known the battery status:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ upsc eaton ups.status\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eOL\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eFew explains:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eOL\u003c/strong\u003e signify \u003cstrong\u003eOn Line\u003c/strong\u003e; all is good!\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eOB\u003c/strong\u003e: \u003cstrong\u003eOn Battery\u003c/strong\u003e: the inverter now only works on the battery\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLB\u003c/strong\u003e: \u003cstrong\u003eLow Battery\u003c/strong\u003e: the battery is at its lowest charge level!\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eOB\u003c/strong\u003e and \u003cstrong\u003eLB\u003c/strong\u003e must trigger actions; they are configured on \u003cstrong\u003eupsmon.conf\u003c/strong\u003e\nfile, or even \u003cstrong\u003eupssched.conf\u003c/strong\u003e.\u003c/p\u003e\n\u003ch3 id=\"process-and-files\"\u003eProcess and files\u003c/h3\u003e\n\u003cp\u003eYou can check what are the process managed by the \u003cstrong\u003e_ups\u003c/strong\u003e user, and the\nopened files; as instance, with \u003ccode\u003eps\u003c/code\u003e and \u003ccode\u003efstat\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ps aux -U _ups\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER       PID %CPU %MEM   VSZ   RSS TT  STAT   STARTED       TIME COMMAND\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e  0.0  0.0   \u003cspan style=\"color:#f99b15\"\u003e836\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e1668\u003c/span\u003e ??  S       5:07PM    0:00.70 /usr/local/bin/usbhid-ups -a eaton\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups      \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e  0.0  0.0   \u003cspan style=\"color:#f99b15\"\u003e764\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e1308\u003c/span\u003e ??  S       5:07PM    0:00.12 /usr/local/sbin/upsd -u _ups\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e  0.0  0.0   \u003cspan style=\"color:#f99b15\"\u003e780\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e3084\u003c/span\u003e ??  S       5:07PM    0:00.09 /usr/local/sbin/upsmon\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ fstat -u _ups -n\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUSER     CMD          PID   FD  DEV      INUM        MODE   R/W    SZ|DV\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e   wd  4,0    \u003cspan style=\"color:#f99b15\"\u003e103712\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e40700\u003c/span\u003e    r      \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e    3* internet stream tcp 0x0 127.0.0.1:26706 --\u0026gt; 127.0.0.1:3493\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsmon     \u003cspan style=\"color:#f99b15\"\u003e65469\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e   wd  4,4     \u003cspan style=\"color:#f99b15\"\u003e26111\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e40700\u003c/span\u003e    r      \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    3* internet6 stream tcp 0x0 \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e::1\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:3493\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    4* internet stream tcp 0x0 127.0.0.1:3493\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    5* unix stream 0x0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     upsd        \u003cspan style=\"color:#f99b15\"\u003e4840\u003c/span\u003e    6* internet stream tcp 0x0 127.0.0.1:3493 \u0026lt;-- 127.0.0.1:26706\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e   wd  4,4     \u003cspan style=\"color:#f99b15\"\u003e26111\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e40700\u003c/span\u003e    r      \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e  4,0     \u003cspan style=\"color:#f99b15\"\u003e27162\u003c/span\u003e        \u003cspan style=\"color:#f99b15\"\u003e20666\u003c/span\u003e   rw    2,2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e pipe 0x0 state:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    5* unix stream 0x0 /var/db/nut/usbhid-ups-eaton\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_ups     usbhid-ups \u003cspan style=\"color:#f99b15\"\u003e31655\u003c/span\u003e    6* unix stream 0x0 /var/db/nut/usbhid-ups-eaton\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eWe notice:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eupsd and upsmon run correctly, well managed by \u003cstrong\u003e_ups\u003c/strong\u003e user\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003estreams TCP are correctly created, and used on localhost\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ethe \u003cstrong\u003eeaton\u003c/strong\u003e profil is correctly managed by \u003cstrong\u003eusbhid-ups\u003c/strong\u003e!\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"connection-refused\"\u003eConnection refused\u003c/h3\u003e\n\u003cp\u003eHere, an example about errors messages:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e55984\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Can\u003cspan style=\"color:#ef6155\"\u003e\u0026#39;\u003c/span\u003et connect to UPS \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eeaton\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eusbhid-ups-eaton\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: Connection refused\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e20574\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Poll UPS \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eeaton@localhost\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e failed - Driver not connected\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e20574\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Communications with UPS eaton@localhost lost\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e44238\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: UPS eaton@localhost is unavailable\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e44238\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: UPS \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eeaton@localhost\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: connect failed: Connection failure: Connection refused\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAt least, two possibles reasons:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003echeck the physical USB connection\u003c/strong\u003e. May be, it\u0026rsquo;s usefull to change\nthe USB cable, or disconnect to reconnect it. Even, the USB ports on the\nmotherboard or your USB hub can be defective/faulty.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eafter a OpenBSD upgrade\u003c/strong\u003e: it\u0026rsquo;s necessary to redo the needed\n\u003ca href=\"/en/sys/openbsd/nut/#permissions\"\u003epermissions\u003c/a\u003e !\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"login-failed\"\u003eLogin failed\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsmon\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e39287\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Login on UPS \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eeaton@localhost\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e failed - got \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eERR ACCESS-DENIED\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eCheck your managed user between \u003cstrong\u003eupsd.users\u003c/strong\u003e and \u003cstrong\u003eupsmon.conf\u003c/strong\u003e files.\u003c/p\u003e\n\u003ch3 id=\"permission-denied\"\u003ePermission denied\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eupsd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e87303\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: Can\u003cspan style=\"color:#ef6155\"\u003e\u0026#39;\u003c/span\u003et open /etc/nut/upsd.conf: Permission denied\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eCheck the user rights on this file; it must belong to the \u003cstrong\u003e_ups\u003c/strong\u003e user.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"nut-cgi\"\u003enut-cgi\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003enut-cgi\u003c/strong\u003e provides CGI scripts to monitor the inverter through the web\nservice.\u003c/p\u003e\n\u003cp\u003eActually, this officially works only with the Apache server, and requires\nwriting a configuration file \u003cstrong\u003ehosts.conf\u003c/strong\u003e, not created by default.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eProjet NUT : \u003ca href=\"https://networkupstools.org/\" rel=\"external\"\u003ehttps://networkupstools.org/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003epkg-readme : \u003ccode\u003e/usr/local/share/doc/pkg-readmes/nut\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Managing an inverter with the NUT project on OpenBSD","tags":["OpenBSD","NUT","UPS"],"date_published":"2021-07-18T15:34:24+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-02-21:/en/sys/openbsd/vmd-serial-console","url":"https://it-log.fr.eu.org/en/sys/openbsd/vmd-serial-console/","title":"[OpenBSD :: Virtualization] No login screen ; no login!","author":{"name":"Stéphane HUC"},"content_text":"Description As a reminder, the vmm(4) hypervisor on OpenBSD not have graphic support on the VM guests. Only serial console access is available.\nWhen you do virtualization on OpenBSD am64, i386, OpenBSD handles all correctly. So, the serial console access is configured on /etc/boot.conf; tty00 to use correctly the serial console.\nThe following problem results when you have the idea to create VM under another OS, Linux for example, unless you answer specifically yes when the installer asks to configure com0:\nNo login screen ; no login!\nTo illustrate: once OpenBSD VM is copied on the OpenBSD host, here is the boot:\n$ vmctl start -c vm-test Using drive 0, partition 3. Loading...... probing: pc0 com0 mem[638K 1022M a20=on] disk: hd0+ \u0026gt;\u0026gt; OpenBSD/amd64 BOOT 3.52 boot\u0026gt; booting hd0a:/bsd: 14329128+3191816+337072+0+872448 [999468+128+1135344+859361]=0x14ba488 entry point at 0xffffffff81001000 [ using 2995336 bytes of bsd ELF symbol table ] Copyright (c) 1982, 1986, 1989, 1991, 1993 The Regents of the University of California. All rights reserved. Copyright (c) 1995-2020 OpenBSD. All rights reserved. https://www.OpenBSD.org OpenBSD 6.8 (GENERIC) #4: Mon Jan 11 10:34:36 MST 2021 root@syspatch-68-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC real mem = 1056956416 (1007MB) avail mem = 1010040832 (963MB) random: good seed from bootblocks mpath0 at root scsibus0 at mpath0: 256 targets mainbus0 at root bios0 at mainbus0: SMBIOS rev. 2.4 @ 0xf3f40 (10 entries) bios0: vendor SeaBIOS version \u0026#34;1.11.0p3-OpenBSD-vmm\u0026#34; date 01/01/2011 bios0: OpenBSD VMM acpi at bios0 not configured cpu0 at mainbus0: (uniprocessor) cpu0: AMD FX-8320E Eight-Core Processor, 3211.59 MHz, 15-02-00 cpu0: FPU,VME,DE,PSE,TSC,MSR,PAE,CX8,SEP,PGE,CMOV,PAT,PSE36,CFLUSH,MMX,FXSR,SSE,SSE2,SSE3,PCLMUL,SSSE3,FMA3,CX16,SSE4.1,SSE4.2,POPCNT,AES,XSAVE,AVX,F16C,HV,NXE,MMXX,FFXSR,PAGE1GB,LONG,LAHF,CMPLEG,EAPICSP,AMCR8,ABM,SSE4A,MASSE,3DNOWP,OSVW,IBS,XOP,SKINIT,WDT,FMA4,TCE,NODEID,TBM,TOPEXT,CPCTR,ITSC,BMI1 cpu0: 64KB 64b/line 2-way I-cache, 16KB 64b/line 4-way D-cache, 2MB 64b/line 16-way L2 cache, 8MB 64b/line 64-way L3 cache cpu0: ITLB 48 4KB entries fully associative, 24 4MB entries fully associative cpu0: DTLB 64 4KB entries fully associative, 64 4MB entries fully associative cpu0: smt 0, core 0, package 0 pvbus0 at mainbus0: OpenBSD pvclock0 at pvbus0 pci0 at mainbus0 bus 0 pchb0 at pci0 dev 0 function 0 \u0026#34;OpenBSD VMM Host\u0026#34; rev 0x00 virtio0 at pci0 dev 1 function 0 \u0026#34;Qumranet Virtio RNG\u0026#34; rev 0x00 viornd0 at virtio0 virtio0: irq 3 virtio1 at pci0 dev 2 function 0 \u0026#34;Qumranet Virtio Network\u0026#34; rev 0x00 vio0 at virtio1: address fe:e1:bb:d1:a9:7b virtio1: irq 5 virtio2 at pci0 dev 3 function 0 \u0026#34;Qumranet Virtio Storage\u0026#34; rev 0x00 vioblk0 at virtio2 scsibus1 at vioblk0: 1 targets sd0 at scsibus1 targ 0 lun 0: \u0026lt;VirtIO, Block Device, \u0026gt; sd0: 51200MB, 512 bytes/sector, 104857600 sectors virtio2: irq 6 virtio3 at pci0 dev 4 function 0 \u0026#34;OpenBSD VMM Control\u0026#34; rev 0x00 vmmci0 at virtio3 virtio3: irq 7 isa0 at mainbus0 isadma0 at isa0 com0 at isa0 port 0x3f8/8 irq 4: ns8250, no fifo com0: console vscsi0 at root scsibus2 at vscsi0: 256 targets softraid0 at root scsibus3 at softraid0: 256 targets root on sd0a (6dc570f70e2c7991.a) swap on sd0b dump on sd0b Automatic boot in progress: starting file system checks. /dev/sd0a (6dc570f70e2c7991.a): file system is clean; not checking /dev/sd0m (6dc570f70e2c7991.m): file system is clean; not checking /dev/sd0d (6dc570f70e2c7991.d): file system is clean; not checking /dev/sd0f (6dc570f70e2c7991.f): file system is clean; not checking /dev/sd0g (6dc570f70e2c7991.g): file system is clean; not checking /dev/sd0h (6dc570f70e2c7991.h): file system is clean; not checking /dev/sd0j (6dc570f70e2c7991.j): file system is clean; not checking /dev/sd0i (6dc570f70e2c7991.i): file system is clean; not checking /dev/sd0e (6dc570f70e2c7991.e): file system is clean; not checking /dev/sd0k (6dc570f70e2c7991.k): file system is clean; not checking /dev/sd0l (6dc570f70e2c7991.l): file system is clean; not checking pf enabled kern.seminfo.semmni: 10 -\u0026gt; 60 kern.seminfo.semmns: 60 -\u0026gt; 1024 starting network reordering libraries: done. starting early daemons: syslogd pflogd nsd ntpd. starting RPC daemons:. savecore: no core dump checking quotas: done. clearing /tmp kern.securelevel: 0 -\u0026gt; 1 creating runtime link editor directory cache. preserving editor files. starting network daemons: sshd smtpd. starting local daemons: cron. Thu Feb 18 12:25:45 CET 2021 It stops at the time display… and the session login screen will never come up!\nNo, it\u0026rsquo;s not due to a corruption during the copy/synchronisation. Tests based on sha256 checksum were done before and after the copy, such as:\n⇒ on Linux:\n$ cat vm-test.qcow2.sha256 73054a89bb2e0b13d78e8cb446424baa01f7761099d8681a59137655b28c979c vm-test.qcow2 ⇒ then, on OpenBSD:\n$ sha256 vm-test.qcow2 SHA256 (vm-test.qcow2) = 73054a89bb2e0b13d78e8cb446424baa01f7761099d8681a59137655b28c979c $ sha256 -C vm-test.qcow2.sha256 vm-test.qcow2 (SHA256) vm-test.qcow2: OK What to do?!\nOn your OS source, where the VM has been created, connect you on the VM, and make the two following necessary modifications:\nConfiguration boot.conf The /etc/boot.conf/ file config was not created. It must contain at least:\nset tty com0 By default, the connection rate is 9200 baups.\nSince the future host is OpenBSD, write:\nstty com0 115200 set tty com0 So, we configure to use secure tty at 115200 baups.\nttys The second modification is to set the terminal session tty00.\nYou need to change the line matching tty00 into the /etc/ttys file:\ntty00 \u0026#34;/usr/libexec/getty std.115200\u0026#34; vt220 on secure Voila!\nWhen the VM is copied on OpenBSD, you will have the login screen.\nDocumentations the OpenBSD FAQ \u0026ldquo;Configuring a Serial Console\u0026rdquo; (cf : la traduction FR faite par la communauté \u0026ldquo;OpenBSD Pour Tous\u0026rdquo;) Acknowledgements @jggimi…\n","content_html":"\u003ch1 id=\"description\"\u003eDescription\u003c/h1\u003e\n\u003cp\u003eAs a reminder, the \u003ca href=\"https://man.openbsd.org/vmm\" rel=\"external\"\u003evmm(4)\u003c/a\u003e hypervisor on OpenBSD\nnot have graphic support on the VM guests. \u003cstrong\u003eOnly serial console access is\navailable.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eWhen you do virtualization on OpenBSD am64, i386, OpenBSD handles all correctly.\nSo, the serial console access is configured on \u003ccode\u003e/etc/boot.conf\u003c/code\u003e; \u003ccode\u003etty00\u003c/code\u003e\nto use correctly the serial console.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThe following problem results when you have the idea to create VM under\nanother OS, Linux for example, unless you answer specifically \u003cstrong\u003eyes\u003c/strong\u003e when\nthe installer asks to configure \u003cstrong\u003ecom0\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eNo login screen ; no login!\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eTo illustrate: once OpenBSD VM is copied on the OpenBSD host, here is the\nboot:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ vmctl start -c vm-test\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing drive 0, partition 3.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eLoading......\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprobing: pc0 com0 mem\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e638K 1022M \u003cspan style=\"color:#ef6155\"\u003ea20\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eon\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edisk: hd0+\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026gt;\u0026gt; OpenBSD/amd64 BOOT 3.52\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eboot\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebooting hd0a:/bsd: 14329128+3191816+337072+0+872448 \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e999468+128+1135344+859361\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e0x14ba488\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eentry point at 0xffffffff81001000\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e using \u003cspan style=\"color:#f99b15\"\u003e2995336\u003c/span\u003e bytes of bsd ELF symbol table \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCopyright \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003ec\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e 1982, 1986, 1989, 1991, \u003cspan style=\"color:#f99b15\"\u003e1993\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    The Regents of the University of California.  All rights reserved.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCopyright \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003ec\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e 1995-2020 OpenBSD. All rights reserved.  https://www.OpenBSD.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eOpenBSD 6.8 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eGENERIC\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e#4: Mon Jan 11 10:34:36 MST 2021\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    root@syspatch-68-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/GENERIC\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereal \u003cspan style=\"color:#ef6155\"\u003emem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1056956416\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e1007MB\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eavail \u003cspan style=\"color:#ef6155\"\u003emem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1010040832\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e963MB\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003erandom: good seed from bootblocks\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003empath0 at root\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003escsibus0 at mpath0: \u003cspan style=\"color:#f99b15\"\u003e256\u003c/span\u003e targets\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emainbus0 at root\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebios0 at mainbus0: SMBIOS rev. 2.4 @ 0xf3f40 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e entries\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebios0: vendor SeaBIOS version \u003cspan style=\"color:#48b685\"\u003e\u0026#34;1.11.0p3-OpenBSD-vmm\u0026#34;\u003c/span\u003e date 01/01/2011\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ebios0: OpenBSD VMM\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eacpi at bios0 not configured\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0 at mainbus0: \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003euniprocessor\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: AMD FX-8320E Eight-Core Processor, 3211.59 MHz, 15-02-00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: FPU,VME,DE,PSE,TSC,MSR,PAE,CX8,SEP,PGE,CMOV,PAT,PSE36,CFLUSH,MMX,FXSR,SSE,SSE2,SSE3,PCLMUL,SSSE3,FMA3,CX16,SSE4.1,SSE4.2,POPCNT,AES,XSAVE,AVX,F16C,HV,NXE,MMXX,FFXSR,PAGE1GB,LONG,LAHF,CMPLEG,EAPICSP,AMCR8,ABM,SSE4A,MASSE,3DNOWP,OSVW,IBS,XOP,SKINIT,WDT,FMA4,TCE,NODEID,TBM,TOPEXT,CPCTR,ITSC,BMI1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: 64KB 64b/line 2-way I-cache, 16KB 64b/line 4-way D-cache, 2MB 64b/line 16-way L2 cache, 8MB 64b/line 64-way L3 cache\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: ITLB \u003cspan style=\"color:#f99b15\"\u003e48\u003c/span\u003e 4KB entries fully associative, \u003cspan style=\"color:#f99b15\"\u003e24\u003c/span\u003e 4MB entries fully associative\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: DTLB \u003cspan style=\"color:#f99b15\"\u003e64\u003c/span\u003e 4KB entries fully associative, \u003cspan style=\"color:#f99b15\"\u003e64\u003c/span\u003e 4MB entries fully associative\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecpu0: smt 0, core 0, package \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epvbus0 at mainbus0: OpenBSD\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epvclock0 at pvbus0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epci0 at mainbus0 bus \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epchb0 at pci0 dev \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OpenBSD VMM Host\u0026#34;\u003c/span\u003e rev 0x00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio0 at pci0 dev \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Qumranet Virtio RNG\u0026#34;\u003c/span\u003e rev 0x00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eviornd0 at virtio0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio0: irq \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio1 at pci0 dev \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Qumranet Virtio Network\u0026#34;\u003c/span\u003e rev 0x00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evio0 at virtio1: address fe:e1:bb:d1:a9:7b\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio1: irq \u003cspan style=\"color:#f99b15\"\u003e5\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio2 at pci0 dev \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;Qumranet Virtio Storage\u0026#34;\u003c/span\u003e rev 0x00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evioblk0 at virtio2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003escsibus1 at vioblk0: \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e targets\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esd0 at scsibus1 targ \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e lun 0: \u0026lt;VirtIO, Block Device, \u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esd0: 51200MB, \u003cspan style=\"color:#f99b15\"\u003e512\u003c/span\u003e bytes/sector, \u003cspan style=\"color:#f99b15\"\u003e104857600\u003c/span\u003e sectors\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio2: irq \u003cspan style=\"color:#f99b15\"\u003e6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio3 at pci0 dev \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OpenBSD VMM Control\u0026#34;\u003c/span\u003e rev 0x00\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evmmci0 at virtio3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evirtio3: irq \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eisa0 at mainbus0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eisadma0 at isa0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecom0 at isa0 port 0x3f8/8 irq 4: ns8250, no fifo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecom0: console\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evscsi0 at root\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003escsibus2 at vscsi0: \u003cspan style=\"color:#f99b15\"\u003e256\u003c/span\u003e targets\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esoftraid0 at root\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003escsibus3 at softraid0: \u003cspan style=\"color:#f99b15\"\u003e256\u003c/span\u003e targets\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eroot on sd0a \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.a\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e swap on sd0b dump on sd0b\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAutomatic boot in progress: starting file system checks.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0a \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.a\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0m \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.m\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0d \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.d\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0f \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.f\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0g \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.g\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0h \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.h\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0j \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.j\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0i \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.i\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0k \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.k\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/dev/sd0l \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e6dc570f70e2c7991.l\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: file system is clean; not checking\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epf enabled\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ekern.seminfo.semmni: \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e -\u0026gt; \u003cspan style=\"color:#f99b15\"\u003e60\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ekern.seminfo.semmns: \u003cspan style=\"color:#f99b15\"\u003e60\u003c/span\u003e -\u0026gt; \u003cspan style=\"color:#f99b15\"\u003e1024\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estarting network\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereordering libraries: \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estarting early daemons: syslogd pflogd nsd ntpd.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estarting RPC daemons:.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esavecore: no core dump\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003echecking quotas: \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eclearing /tmp\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ekern.securelevel: \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e -\u0026gt; \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ecreating runtime link editor directory cache.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epreserving editor files.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estarting network daemons: sshd smtpd.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003estarting local daemons: cron.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eThu Feb \u003cspan style=\"color:#f99b15\"\u003e18\u003c/span\u003e 12:25:45 CET \u003cspan style=\"color:#f99b15\"\u003e2021\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIt stops at the time display… and the session login screen will never come\nup!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eNo, it\u0026rsquo;s not due to a corruption during the copy/synchronisation. Tests\nbased on sha256 checksum were done before and after the copy, such as:\u003c/p\u003e\n\u003cp\u003e⇒ on Linux:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cat vm-test.qcow2.sha256\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e73054a89bb2e0b13d78e8cb446424baa01f7761099d8681a59137655b28c979c  vm-test.qcow2\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ then, on OpenBSD:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sha256 vm-test.qcow2                                                                                                                                                                    \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSHA256 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003evm-test.qcow2\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e 73054a89bb2e0b13d78e8cb446424baa01f7761099d8681a59137655b28c979c\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sha256 -C vm-test.qcow2.sha256 vm-test.qcow2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eSHA256\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e vm-test.qcow2: OK\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eWhat to do?!\u003c/p\u003e\n\u003cp\u003eOn your OS source, where the VM has been created, connect you on the VM,\nand make the \u003cstrong\u003etwo\u003c/strong\u003e following necessary modifications:\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"bootconf\"\u003eboot.conf\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003e/etc/boot.conf/\u003c/code\u003e file config was not created. It must contain at least:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eset tty com0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eBy default, the connection rate is 9200 baups.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eSince the future host is OpenBSD, write:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003estty com0 115200\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eset tty com0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eSo, we configure to use secure tty at 115200 baups.\u003c/p\u003e\n\u003ch3 id=\"ttys\"\u003ettys\u003c/h3\u003e\n\u003cp\u003eThe second modification is to set the terminal session \u003cstrong\u003etty00\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003eYou need to change the line matching \u003cstrong\u003etty00\u003c/strong\u003e into the \u003ccode\u003e/etc/ttys\u003c/code\u003e file:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etty00   \u0026#34;/usr/libexec/getty std.115200\u0026#34; vt220    on secure\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003cp\u003eWhen the VM is copied on OpenBSD, you will have the login screen.\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ethe OpenBSD FAQ \u0026ldquo;\u003ca href=\"https://www.openbsd.org/faq/faq7.html#SerCon\" rel=\"external\"\u003eConfiguring a Serial Console\u003c/a\u003e\u0026rdquo;\n\u003cem\u003e(cf : la traduction \u003ca href=\"https://wiki.openbsd.fr.eu.org/doku.php/openbsd.org/faq/faq7#configurer-une-console-serie\" rel=\"external\"\u003eFR\u003c/a\u003e faite par la communauté \u0026ldquo;OpenBSD Pour Tous\u0026rdquo;)\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"acknowledgements\"\u003eAcknowledgements\u003c/h2\u003e\n\u003cp\u003e@\u003ca href=\"http://daemonforums.org/showthread.php?t=11643\" rel=\"external\"\u003ejggimi\u003c/a\u003e…\u003c/p\u003e\n\u003chr\u003e\n","summary":"Solve serial console problem for a VM, copied from another OS to OpenBSD!","tags":["OpenBSD","vmd","astuce"],"date_published":"2021-02-21T23:14:42+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2021-02-21:/en/sys/openbsd/vmd-host-guest-on-same-network","url":"https://it-log.fr.eu.org/en/sys/openbsd/vmd-host-guest-on-same-network/","title":"[OpenBSD :: Virtualization] Host and guests on the same network","author":{"name":"Stéphane HUC"},"content_text":"Description To virtualize on OpenBSD, since 5.9, is easy; you need to pay attention to certains details.\nThis article is about to virtualize host and guests on same network.\nVersion : native OS : OpenBSD 6.4 → 6.9 Prerequisites First, check if the machine is CPU compliant:\n$ dmesg | egrep \u0026#39;(VMX/EPT|SVM/RVI)\u0026#39; The result should be:\n⇒ for Intel CPU:\nvmm0 at mainbus0: VMX/EPT ⇒ for AMD CPU:\nvmm0 at mainbus0: SVM/RVI If the system returns no result, then the virtualization is not possible, never. Just in case, check on your BIOS|UEFI, and see if the option is disabled.\nInfoIn relation with Meltdow and Spectre attacks, few Intel CPU are patched to mitigate L1TF.\nOn OpenBSD, these CPUs receive an appropriate patch. Sadly, this impact the virtualization, make it impossible.\nCreation After downloading the ultime instalXX.iso, and checking it…\nWhy using, preferably, the iso image? To install OpenBSD by option cd, because the install sets are on.\nFor instance, with the 6.9 release:\n$ ftp https://cdn.openbsd.org/pub/OpenBSD/6.9/amd64/{install69.iso,SHA256,SHA256.sig} $ sha256 -C SHA256 install69.iso (SHA256) install69.iso: OK $ signify -Cp /etc/signify/openbsd-69-base.pub -x SHA256.sig install69.iso Signature Verified install69.iso: OK ⇒ Create the VM:\n$ vmctl create -s 50G disk.qcow2 ⇒ Start the install:\n# vmctl start -c -m 1G -i 1 -r installXX.iso -d disk.qcow2 test WarningYou need to declare a network interface, with the option -i. This allows automatically one tap(4) interface to the VM.\nEgual, do not use the option -L to manage host and guests on same network; this option declare a local interface, preventing communication with the bridge. In this cas, we need to configure forwarding, sysctl, etc.\nDo the install, and after a few minutes, at the end, choose [halt] to shutdown correctly the OS into the VM. To leave the serial console, use the escape sequence : ~.; or if you are on SSH session: ~~..\nInfoAnother reason why you need to stop the VM: if you do not, the VM reboot normally, without any problem… but, without network connections. Do not try to modify yours networks parameters, perhaps just to verify adresses IP gateway and DNS resolver.\nThe tip: configure the file /etc/vm.conf on the host, restart the vmd daemon et after start the VM. Now, the network should work correctly!\nConfiguration Assuming that:\nthe network segment is on Class C, as 192.168.1.0 address IP of gateway: 192.168.1.1 DNS resolvers: perhaps those about FDN… These informations are the network parameters to configure the VM.\nThe following parameters are made on:\nNetworking Only the Ethernet devices, not Wireless, can be used.\nPrefer to use static adress IP, because dhcp can complicate matters.\nhostname.iface In this article, we assume that your network interface is managed by the em(4) Intel firmware.\nChange segun your case, if necessary.\nConfigue the /etc/hostname.em0 file:\ninet 192.168.1.2 vm.conf /etc/vm.conf is the file configuration:\nswitch \u0026#34;sw\u0026#34; { interface bridge0 } vm \u0026#34;test\u0026#34; { disk /home/your_user/disk.qcow2 format qcow2 enable memory 1G interface { switch \u0026#34;sw\u0026#34; } owner your_user } Bridge Configure the bridge to manage em0:\n# echo \u0026#39;add em0\u0026#39; \u0026gt; /etc/hostname.bridge0 # sh /etc/netstart bridge0 Voilà!\nWhich is not mentioned in the FAQ, has a lot to do with PF, mainly.\nAnother important information: when the VM is running, on tap interface is created and mounted by the bridge.\nPF WarningDO NOT use the uRPF feature with vm; otherwize yours VMs can not communicate! According to the notes of the bridge manpage, set the rules on PF to manage the bridge is possible, but you need to be very fine-tuned and have an excellent understanding about the network flow within PF.\nDo simple:\n⇒ pass all on the interface group tap:\npass on tap InfoIf you prefer to manage individually all interfaces tap, you can declare, by exemple, only tap0:\npass on tap0\nNow, you need to manage the physical network interface; here: em0\n⇒ create a table to manage all the VMs:\ntable \u0026lt;vm_tap\u0026gt; const { 192.168.1.3 192.168.1.4 } and, for the exemple, authozise SSH to VMs:\npass in log on em0 inet proto tcp from any to \u0026lt;vm_tab\u0026gt; port 22 Of course, these PF rules are minimalist. It\u0026rsquo;s up to you!\nFinally, remember to manage PF rules within the VM.\ntap - Ethernet tunnel pseudo-device OpenBSD create 4 tap interfaces, by default. If you need more VM, you need to create more tap interfaces.\nSee the note…\nAnd use MAKEDEV(8), as:\n# sh MAKEDEV tap5 Egual, it\u0026rsquo;s possible to assign such pseudo virtual device tap to such VM. Use the keyword interface:\nvm \u0026#34;test\u0026#34; { (…) interface tap5 { … } (…) } Another information to understand: as long as the VM is not active, the matching tap interface will not be created and mounted on the bridge. Compare with ifconfig command, before and after. ;-)\nsysctl NO, it\u0026rsquo;s not necessary to configure systcl to forward the trafic. We do not make NAT!\nSee the manpage vmctl:\nIf NAT is desired, the net.inet.ip.forwarding sysctl(8) must also be set to 1.\nSo, in the bridge context where host and guests are on same network, no need to forward the flow.\nDocumentations See the official FAQ Virtualisation in order to understand the different informations needed.\nIt\u0026rsquo;s highly interesting to read the manpages:\nvmctl(8) vmd(8) vm.conf(5) vmm(4) sans oublier bridge(4) Here an example of a patched L1TF Intel CPU where the boot media was not found, with error message in dmesg: vmx_fault_page: uvm_fault returns 14, GPA=0xffffca78, rip=0xfbd49 ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eTo virtualize on OpenBSD, since 5.9, is easy; you need to pay attention\nto certains details.\u003c/p\u003e\n\u003cp\u003eThis article is about to virtualize host and guests on same network.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVersion : \u003cstrong\u003enative\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eOS : OpenBSD \u003cstrong\u003e6.4\u003c/strong\u003e → \u003cstrong\u003e6.9\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"prerequisites\"\u003ePrerequisites\u003c/h2\u003e\n\u003cp\u003eFirst, check if the machine is CPU compliant:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ dmesg | egrep \u003cspan style=\"color:#48b685\"\u003e\u0026#39;(VMX/EPT|SVM/RVI)\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe result should be:\u003c/p\u003e\n\u003cp\u003e⇒ for Intel CPU:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evmm0 at mainbus0: VMX/EPT\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ for AMD CPU:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003evmm0 at mainbus0: SVM/RVI\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIf the system returns no result, then the virtualization is not possible,\nnever. Just in case, check on your BIOS|UEFI, and see if the option is disabled.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eIn relation with Meltdow and Spectre attacks, few Intel CPU are patched\nto mitigate \u003ca href=\"https://www.intel.fr/content/www/fr/fr/architecture-and-technology/l1tf.html\" rel=\"external\"\u003eL1TF\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eOn OpenBSD, these CPUs receive an appropriate patch. Sadly, this impact\nthe virtualization, make it impossible.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"creation\"\u003eCreation\u003c/h2\u003e\n\u003cp\u003eAfter downloading the ultime \u003ccode\u003einstalXX.iso\u003c/code\u003e, and checking it…\u003c/p\u003e\n\u003cp\u003eWhy using, preferably, the iso image? To install OpenBSD by option \u003ccode\u003ecd\u003c/code\u003e,\nbecause the install sets are on.\u003c/p\u003e\n\u003cp\u003eFor instance, with the 6.9 release:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ ftp https://cdn.openbsd.org/pub/OpenBSD/6.9/amd64/\u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003einstall69.iso,SHA256,SHA256.sig\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sha256 -C SHA256 install69.iso\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eSHA256\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e install69.iso: OK\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ signify -Cp /etc/signify/openbsd-69-base.pub -x SHA256.sig install69.iso\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSignature Verified\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003einstall69.iso: OK\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Create the VM:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ vmctl create -s 50G disk.qcow2\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ Start the install:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# vmctl start -c -m 1G -i 1 -r installXX.iso -d disk.qcow2 test\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eYou need to declare a network interface, with the option \u003ccode\u003e-i\u003c/code\u003e. This allows\nautomatically one \u003cstrong\u003e\u003ca href=\"https://man.openbsd.org/tap.4\" rel=\"external\"\u003etap(4)\u003c/a\u003e\u003c/strong\u003e interface\nto the VM.\u003c/p\u003e\n\u003cp\u003eEgual, \u003cstrong\u003edo not use the option \u003ccode\u003e-L\u003c/code\u003e\u003c/strong\u003e to manage host and guests on same\nnetwork; this option declare a local interface, preventing communication\nwith the bridge. \u003cem\u003eIn this cas, we need to configure forwarding, sysctl, etc.\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eDo the install, and after a few minutes, at the end, choose \u003ccode\u003e[halt]\u003c/code\u003e to\nshutdown correctly the OS into the VM. To leave the serial console, use\nthe escape sequence : \u003ccode\u003e~.\u003c/code\u003e; or if you are on SSH session: \u003ccode\u003e~~.\u003c/code\u003e.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eAnother reason why you need to stop the VM: if you do not, the VM reboot\nnormally, without any problem… but, without network connections.\nDo not try to modify yours networks parameters, perhaps just to verify\nadresses IP gateway and DNS resolver.\u003c/p\u003e\n\u003cp\u003eThe tip: configure  the file \u003ccode\u003e/etc/vm.conf\u003c/code\u003e on the host, restart the vmd\ndaemon et after start the VM. Now, the network should work correctly!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eAssuming that:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe network segment is on Class C, as 192.168.1.0\u003c/li\u003e\n\u003cli\u003eaddress IP of gateway: 192.168.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.fdn.fr/actions/dns/\" rel=\"external\"\u003eDNS resolvers\u003c/a\u003e: perhaps those about FDN…\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThese informations are the network parameters to configure the VM.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThe following parameters are made on:\u003c/p\u003e\n\u003ch3 id=\"networking\"\u003eNetworking\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eOnly the Ethernet devices, not Wireless, can be used\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003ePrefer to use static adress IP, because dhcp can complicate matters.\u003c/p\u003e\n\u003ch3 id=\"hostnameiface\"\u003ehostname.iface\u003c/h3\u003e\n\u003cp\u003eIn this article, we assume that your network interface is managed by the\n\u003cstrong\u003e\u003ca href=\"https://man.openbsd.org/man4/em.4\" rel=\"external\"\u003eem(4)\u003c/a\u003e\u003c/strong\u003e Intel firmware.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eChange segun your case, if necessary.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eConfigue the \u003ccode\u003e/etc/hostname.em0\u003c/code\u003e file:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003einet 192.168.1.2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"vmconf\"\u003evm.conf\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003e/etc/vm.conf\u003c/code\u003e is the file configuration:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eswitch \u0026#34;sw\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003einterface bridge0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003evm \u0026#34;test\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003edisk /home/your_user/disk.qcow2 format qcow2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eenable\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ememory 1G\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003einterface { switch \u0026#34;sw\u0026#34; }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eowner your_user\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"bridge\"\u003eBridge\u003c/h3\u003e\n\u003cp\u003eConfigure the bridge to manage em0:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# echo \u0026#39;add em0\u0026#39; \u0026gt; /etc/hostname.bridge0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sh /etc/netstart bridge0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eVoilà!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eWhich is not mentioned in the FAQ, has a lot to do with PF, mainly.\u003c/p\u003e\n\u003cp\u003eAnother important information: when the VM is running, on tap interface\nis created and mounted by the bridge.\u003c/p\u003e\n\u003ch3 id=\"pf\"\u003ePF\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eDO NOT use the \u003ca href=\"https://www.openbsd.org/faq/pf/filter.html#urpf\" rel=\"external\"\u003euRPF\u003c/a\u003e\nfeature with vm; otherwize yours VMs can not communicate!\u003c/div\u003e\n\n\u003cp\u003eAccording to the \u003ca href=\"https://man.openbsd.org/bridge.4#NOTES\" rel=\"external\"\u003enotes of the bridge manpage\u003c/a\u003e,\nset the rules on PF to manage the bridge is possible, but you need to be\nvery fine-tuned and have an excellent understanding about the network\nflow within PF.\u003c/p\u003e\n\u003cp\u003eDo simple:\u003c/p\u003e\n\u003cp\u003e⇒ pass all on the interface group \u003cstrong\u003etap\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass on tap\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eIf you prefer to manage individually all interfaces \u003cstrong\u003etap\u003c/strong\u003e, you can declare,\nby exemple, only \u003cstrong\u003etap0\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003epass on tap0\u003c/code\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eNow, you need to manage the physical network interface; here: \u003cstrong\u003eem0\u003c/strong\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ create a table to manage all the VMs:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etable \u0026lt;vm_tap\u0026gt; const { 192.168.1.3 192.168.1.4 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eand, for the exemple, authozise SSH to VMs:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in log on em0 inet proto tcp from any to \u0026lt;vm_tab\u0026gt; port 22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eOf course, these PF rules are minimalist. It\u0026rsquo;s up to you!\u003c/p\u003e\n\u003cp\u003eFinally, remember to manage PF rules within the VM.\u003c/p\u003e\n\u003ch3 id=\"tap---ethernet-tunnel-pseudo-device\"\u003etap - Ethernet tunnel pseudo-device\u003c/h3\u003e\n\u003cp\u003eOpenBSD create 4 tap interfaces, by default. If you need more VM, you need\nto create more tap interfaces.\u003c/p\u003e\n\u003cp\u003eSee the \u003ca href=\"https://man.openbsd.org/vm.conf.5#SWITCH_CONFIGURATION\" rel=\"external\"\u003enote\u003c/a\u003e…\u003c/p\u003e\n\u003cp\u003eAnd use \u003ca href=\"https://man.openbsd.org/MAKEDEV.8\" rel=\"external\"\u003eMAKEDEV(8)\u003c/a\u003e, as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-ksh\" data-lang=\"ksh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sh MAKEDEV tap5\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eEgual, it\u0026rsquo;s possible to assign such pseudo virtual device tap to such VM.\nUse the keyword \u003cstrong\u003e\u003ca href=\"https://man.openbsd.org/vm.conf.5#interface\" rel=\"external\"\u003einterface\u003c/a\u003e\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003evm \u0026#34;test\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003einterface tap5 { … }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAnother information to understand: as long as the VM is not active, the\nmatching tap interface will not be created and mounted on the bridge.\nCompare with \u003ccode\u003eifconfig\u003c/code\u003e command, before and after. ;-)\u003c/p\u003e\n\u003ch3 id=\"sysctl\"\u003esysctl\u003c/h3\u003e\n\u003cp\u003eNO, it\u0026rsquo;s not necessary to configure systcl to forward the trafic. We do\nnot make NAT!\u003c/p\u003e\n\u003cp\u003eSee the manpage \u003cstrong\u003e\u003ca href=\"https://man.openbsd.org/vmctl.8#LOCAL_INTERFACES\" rel=\"external\"\u003evmctl\u003c/a\u003e\u003c/strong\u003e:\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eIf NAT is desired, the net.inet.ip.forwarding sysctl(8) must also be set to 1.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eSo, in the bridge context where host and guests are on same network, no\nneed to forward the flow.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eSee the official \u003cstrong\u003e\u003ca href=\"https://www.openbsd.org/faq/faq16.html\" rel=\"external\"\u003eFAQ Virtualisation\u003c/a\u003e\u003c/strong\u003e in order to understand the\ndifferent informations needed.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIt\u0026rsquo;s highly interesting to read the manpages:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/vmctl.8\" title=\"OpenBSD Manual Page Server for: vmctl\"\u003evmctl(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/vmd.8\" title=\"OpenBSD Manual Page Server for: vmd\"\u003evmd(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/vm.conf.5\" title=\"OpenBSD Manual Page Server for: vm.conf\"\u003evm.conf(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/vmm.4\" title=\"OpenBSD Manual Page Server for: vmm\"\u003evmm(4)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003esans oublier \n\u003ca class=\"man\" href=\"https://man.openbsd.org/bridge.4\" title=\"OpenBSD Manual Page Server for: bridge\"\u003ebridge(4)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cul\u003e\n\u003cli\u003eHere an \u003ca href=\"http://daemonforums.org/showthread.php?t=11628\" rel=\"external\"\u003eexample\u003c/a\u003e of a\npatched L1TF Intel CPU where the boot media was not found, with error\nmessage in \u003ccode\u003edmesg\u003c/code\u003e: \u003cbr\u003e\n\u003ccode\u003evmx_fault_page: uvm_fault returns 14, GPA=0xffffca78, rip=0xfbd49\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Tips to virtualize serenely under OpenBSD with vmd, where host and guest(s) are part of the same network!","tags":["OpenBSD","vmd"],"date_published":"2021-02-21T19:54:31+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-09-20:/en/sys/openwrt/openssh","url":"https://it-log.fr.eu.org/en/sys/openwrt/openssh/","title":"OpenWRT: OpenSSH instead of Dropbear","author":{"name":"Stéphane HUC"},"content_text":"Description In fact, Dropbear is the SSH server on OpenWRT. Even if this lightweight server use only SSH Protocol v2, it has some gaps:\nA partial support of SFTP protocol; you need to add the package openssh-sftp-server No user privilege separation No official support for cryptographic modules, approved by approved by the FIPS 140-2. (although in our particular context, it is not a necessity) Since version 2020.79, Dropbear seems to manage the Elliptic curve algorithms — which is not the case for the previous versions, included before OpenWRT 19.07.4 ­—: hostkey ed25519 chiffer chacha20-poly1305 or even the key signatures rsa-sha2 Installation :# /etc/init.d/sshd enable :# /etc/init.d/sshd start InfoThe openssh-moduli package is not stritcly necessary. As a reminder, the /etc/ssh/moduli file is a file containing the prime numbers and generators to be used by the SSH server in the\nDH (Diffie-Hellman)\ngroup key exchange method. Prefer to install it…\nConfiguration Dropbear configuration Let\u0026rsquo;s the default port on Dropbear\nHowever, you can configure it, either through the LUCI interface, or in CLI, like as:\n:# uci set dropbear.@dropbear[0].Port=xxx :# uci commit dropbear :# /etc/init.d/dropbear restart xxx: the port number segun your choice. and connect you on this port…\nOpenSSH Configuration Configuration file: /etc/ssh/sshd_config Apply ABSOLUTELY this following recommandations:\nUse only the v2 protocol, Do not connect with root account disable the PasswordAuthentication option use only the PubkeyAuthentication option Now, we harden the configuration:\nrecreate the host keys, and allow only the Ed25519 algorithm. InfoWhen OpenSSH starts, it will recreate the ECDSA keys. auth only: strong encryption the following algorithms: key exchange host keys message authentication codes WarningThe sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com host keys algorithms not seem to be recognized; do not use! moduli If you installed the openssh-moduli package, prefer accept only DH key exchange greater than or equal to 3072 bits.\nLet\u0026rsquo;s save the file, before, in case of…\n:# cp /etc/ssh/moduli /etc/ssh/moduli.bckp :# chmod 0400 /etc/ssh/moduli.bckp Then, you need to recreate\nTipIf you have correctly configured a user with sudo rights:\n:# sudo awk \u0026#39;$5 \u0026gt;= 3071\u0026#39; /etc/ssh/moduli | sudo tee /etc/ssh/moduli.safe :# mv /etc/ssh/moduli.safe /etc/ssh/moduli TL;DR Here a minimalist example of the configuration file:\nHostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_ed25519_key Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org, HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com PermitRootLogin no MaxAuthTries 3 PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys PasswordAuthentication no PermitEmptyPasswords no Subsystem sftp /usr/lib/sftp-server WarningHave you set the ListenAddress option? Forget or you win a race condition! Service management OpenSSH Service Voila, now, connect you… but, after testing the configuration and start the service:\n:# sshd -t\nIf the configuration is valid:\n:# /etc/init.d/sshd enable :# /etc/init.d/sshd start Dropbear Service Now, it\u0026rsquo;s possible to stop and disable the dropbear service:\n:# /etc/init.d/dropbear stop :# /etc/init.d/dropbear disable Backup system Normally, the /etc/ssh directory and its contents are included in the backup system maded by the sysupgrade tool.\nTo check: :# sysupgrade -l | grep ssh\nIf it\u0026rsquo;s not case, edit the /etc/sysupgrade.conf file to add this folder.\nTroubleshooting Race condition ⇒ Not possible to connect after reboot:\nHave you set the ListenAdress option on the configuration file?\nIf yes, comment the corresponding line . OpenSSH can not start due to race condition.\nWhen you specify this option, OpenSSH will run when you start on the CLI. But, during the (re)boot, OpenSSH will fail because the network interface(s) is|are not ready!\nThen, do not specify this option and configure you firewall to auth only your LAN network interface.\nsource\nDocumentation Wikipedia Comparison_of_SSH_servers WP , FIPS_140-2 WP Race_condition WP ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eIn fact, Dropbear is the SSH server on OpenWRT. Even if this lightweight server use only SSH Protocol v2, it has some gaps:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eA partial support of SFTP protocol; you need to add the package \u003cstrong\u003eopenssh-sftp-server\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eNo user privilege separation\u003c/li\u003e\n\u003cli\u003eNo official support for cryptographic modules, approved by approved by the \u003cstrong\u003eFIPS 140-2\u003c/strong\u003e.\n\u003cem\u003e(although in our particular context, it is not a necessity)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eSince version \u003cstrong\u003e2020.79\u003c/strong\u003e, Dropbear seems to manage the Elliptic curve algorithms — \u003cem\u003ewhich is not the case for the previous versions, included before OpenWRT 19.07.4\u003c/em\u003e ­—:\n\u003cul\u003e\n\u003cli\u003ehostkey \u003cstrong\u003eed25519\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003echiffer \u003cstrong\u003echacha20-poly1305\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eor even the key signatures  \u003cstrong\u003ersa-sha2\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# /etc/init.d/sshd enable\n:# /etc/init.d/sshd start\n\u003c/code\u003e\u003c/pre\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eThe \u003cstrong\u003eopenssh-moduli\u003c/strong\u003e package is not stritcly necessary. As a reminder, the \u003ccode\u003e/etc/ssh/moduli\u003c/code\u003e file is a file containing the prime numbers and generators to be used by the SSH server in the\u003c/p\u003e\n\u003cp\u003e\u003cspan lang=\"en\"\u003eDH \u003cem\u003e(Diffie-Hellman)\u003c/em\u003e\u003c/span\u003e\u003c/p\u003e\n\u003cp\u003egroup key exchange method. Prefer to install it…\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"dropbear-configuration\"\u003eDropbear configuration\u003c/h3\u003e\n\u003cp\u003eLet\u0026rsquo;s the default port on Dropbear\u003c/p\u003e\n\u003cp\u003eHowever, you can configure it, either through the LUCI interface, or in CLI, like as:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# uci set dropbear.@dropbear[0].Port=xxx\n:# uci commit dropbear\n:# /etc/init.d/dropbear restart\n\u003c/code\u003e\u003c/pre\u003e\u003cul\u003e\n\u003cli\u003e\u003cem\u003exxx\u003c/em\u003e: the port number segun your choice.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eand connect you on this port…\u003c/p\u003e\n\u003ch3 id=\"openssh-configuration\"\u003eOpenSSH Configuration\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/ssh/sshd_config\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eApply ABSOLUTELY this following recommandations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse \u003cstrong\u003eonly\u003c/strong\u003e the v2 protocol,\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDo not connect with root account\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003edisable the \u003cstrong\u003ePasswordAuthentication\u003c/strong\u003e option\u003c/li\u003e\n\u003cli\u003euse \u003cstrong\u003eonly\u003c/strong\u003e the \u003cstrong\u003ePubkeyAuthentication\u003c/strong\u003e option\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eNow, we harden the configuration:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/en/sec/ssh/sshd-harden#recreate-host-keys\"\u003erecreate the host keys\u003c/a\u003e, and allow \u003cstrong\u003eonly\u003c/strong\u003e the \u003cstrong\u003eEd25519\u003c/strong\u003e algorithm.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eWhen OpenSSH starts, it will recreate the \u003cstrong\u003eECDSA\u003c/strong\u003e keys.\u003c/div\u003e\n\n\u003cul\u003e\n\u003cli\u003eauth \u003cstrong\u003eonly\u003c/strong\u003e:\n\u003cul\u003e\n\u003cli\u003estrong \u003ca href=\"/en/sec/ssh/sshd-harden#ciphers/\"\u003eencryption\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe following algorithms:\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/en/sec/ssh/sshd-harden#KeyExchange\"\u003ekey exchange\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/en/sec/ssh/sshd-harden#HostKeyAlgorithms\"\u003ehost keys\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/en/sec/ssh/sshd-harden#MACs\"\u003emessage authentication codes\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eThe \u003ccode\u003esk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com\u003c/code\u003e host keys algorithms not seem to be recognized; \u003cstrong\u003edo not use!\u003c/strong\u003e\u003c/div\u003e\n\n\u003ch4 id=\"moduli\"\u003emoduli\u003c/h4\u003e\n\u003cp\u003eIf you installed the \u003cstrong\u003eopenssh-moduli\u003c/strong\u003e package, prefer accept only \n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"Diffie-Hellman\"\u003eDH\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n key exchange greater than or equal to 3072 bits.\u003c/p\u003e\n\u003cp\u003eLet\u0026rsquo;s save the file, before, in case of…\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# cp /etc/ssh/moduli /etc/ssh/moduli.bckp\n:# chmod 0400 /etc/ssh/moduli.bckp\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThen, you need to \u003ca href=\"/en/sec/ssh/sshd-harden#moduli--linux\"\u003erecreate\u003c/a\u003e\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003e\u003cp\u003eIf you have correctly configured a user with \u003ca href=\"/en/sys/openwrt/sudo/\"\u003esudo\u003c/a\u003e rights:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# sudo awk \u0026#39;$5 \u0026gt;= 3071\u0026#39; /etc/ssh/moduli | sudo tee /etc/ssh/moduli.safe\n:# mv /etc/ssh/moduli.safe /etc/ssh/moduli\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\n\u003ch4 id=\"tldr\"\u003eTL;DR\u003c/h4\u003e\n\u003cp\u003eHere a minimalist example of the configuration file:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_rsa_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_ed25519_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eCiphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eKexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org,\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eMACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePermitRootLogin no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eMaxAuthTries 3\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePubkeyAuthentication yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAuthorizedKeysFile  .ssh/authorized_keys\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePasswordAuthentication no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePermitEmptyPasswords no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eSubsystem   sftp    /usr/lib/sftp-server\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eHave you set the \u003cstrong\u003eListenAddress\u003c/strong\u003e option? \u003cbr\u003e\nForget or you win a \u003ca href=\"/en/sys/openwrt/openssh/#race-condition\"\u003erace condition\u003c/a\u003e!\u003c/div\u003e\n\n\u003chr\u003e\n\u003ch2 id=\"service-management\"\u003eService management\u003c/h2\u003e\n\u003ch3 id=\"openssh-service\"\u003eOpenSSH Service\u003c/h3\u003e\n\u003cp\u003eVoila, now, connect you… but, after testing the configuration and start the service:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# sshd -t\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIf the configuration is valid:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# /etc/init.d/sshd enable\n:# /etc/init.d/sshd start\n\u003c/code\u003e\u003c/pre\u003e\u003ch3 id=\"dropbear-service\"\u003eDropbear Service\u003c/h3\u003e\n\u003cp\u003eNow, it\u0026rsquo;s possible to stop and disable the dropbear service:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# /etc/init.d/dropbear stop\n:# /etc/init.d/dropbear disable\n\u003c/code\u003e\u003c/pre\u003e\u003chr\u003e\n\u003ch2 id=\"backup-system\"\u003eBackup system\u003c/h2\u003e\n\u003cp\u003eNormally, the \u003ccode\u003e/etc/ssh\u003c/code\u003e directory and its contents are included in the backup system maded by the \u003ccode\u003esysupgrade\u003c/code\u003e tool.\u003c/p\u003e\n\u003cp\u003eTo check: \u003ccode\u003e:# sysupgrade -l | grep ssh\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIf it\u0026rsquo;s not case, edit the \u003ccode\u003e/etc/sysupgrade.conf\u003c/code\u003e file to add this folder.\u003c/p\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"race-condition\"\u003eRace condition\u003c/h3\u003e\n\u003cp\u003e⇒ Not possible to connect after reboot:\u003c/p\u003e\n\u003cp\u003eHave you set the \u003ccode\u003eListenAdress\u003c/code\u003e option on the configuration file?\u003c/p\u003e\n\u003cp\u003eIf yes, \u003cspan class=\"red\"\u003ecomment the corresponding line\u003c/span\u003e\n.\nOpenSSH can not start due to race condition.\u003c/p\u003e\n\u003cp\u003eWhen you specify this option, OpenSSH will run when you start on the CLI.\nBut, during the (re)boot, OpenSSH will fail because the network interface(s) is|are not ready!\u003c/p\u003e\n\u003cp\u003eThen, do not specify this option and configure you firewall to auth only your LAN network interface.\u003c/p\u003e\n\u003cp\u003e\u003cem\u003e\u003ca href=\"https://forum.openwrt.org/t/luci-https-not-working-after-upgrade-to-19-7-4/74352/16\" rel=\"external\"\u003esource\u003c/a\u003e\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003ch3 id=\"wikipedia\"\u003eWikipedia\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Comparison_of_SSH_servers\" title=\"Wikipedia Article: Comparison_of_SSH_servers\"\u003e\n    Comparison_of_SSH_servers\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n, \u003ca href=\"https://en.wikipedia.org/wiki/FIPS_140-2\" title=\"Wikipedia Article: FIPS_140-2\"\u003e\n    FIPS_140-2\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Race_condition\" title=\"Wikipedia Article: Race_condition\"\u003e\n    Race_condition\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Install OpenSSH to replace Dropbear, on OpenWRT","tags":["OpenWRT","OpenSSH","SSH"],"date_published":"2020-09-20T12:02:05+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-09-18:/en/sec/ssh/sshd-harden","url":"https://it-log.fr.eu.org/en/sec/ssh/sshd-harden/","title":"OpenSSH : Harden the service","author":{"name":"Stéphane HUC"},"content_text":"Description By default, even on OpenBSD, the SSH configuration is not the most secure.\nNISTP Algorithms — likely to be an NSA backdoor; but beware, this is seem to be a rumor, even SHA1 are always used.\nWarningUse absolutly an OpenSSH version greater than the v6.5! Configuration Configuration file: /etc/ssh/sshd_config Apply ABSOLUTELY this following recommandations:\nUse only the v2 protocol, Do not connect with root account disable the PasswordAuthentication option use only the PubkeyAuthentication option Recreate host keys :$ cd /etc/ssh :# rm ssh_host_* :# ssh-keygen -t ed25519 -f ssh_host_ed25519_key -N \u0026#34;\u0026#34; :# ssh-keygen -t rsa -b 4096 -f ssh_host_rsa_key -N \u0026#34;\u0026#34; -o -a 64 InfoDo not use passphrase during the generation, otherwise the server will not be able to read them…\nAnyway, the /var/log/auth file will help you!\nNext, you need to pay attention to the following:\nHostKey WarningDO NOT USE the DSA, ECDSA protocols! Comment the HostKey options to keep only related RSA and ED25519 encryptions.\nHostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_ed25519_key TipYou can use only elliptic curves keys, such ed25519. In this case, make sure that all your SSH clients can use this encryption mode too. Ciphers Allow those ciphers:\nCiphers chacha20-poly1305@openssh.com\nHostKeyAlgorithms The HostKeyAlgorithms:\nHostKeyAlgorithms ssh-ed25519-cert-v01@openssh.com,ssh-ed25519\nInfoSegun you OpenSSH version, it\u0026rsquo;s possible to obtain a error message. See the section \u0026ldquo;Troubleshooting\u0026rdquo;! KeyExchange Focus on those KeyExchange algoritms:\nKexAlgorithms mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com\nMACs Choose those Message Authentication Codes:\nMACs umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com\nModuli The moduli file containt prime numbers and generators to be used by the SSH server in the DH (Diffie-Hellman) group key exchange method.\nWarningSince 2017, this bug #2793 explains that in some contexts the proper functioning fails, following recommendations below.\nIf you can no longer login, consider reversing this change!\nModuli / Linux It is recommended to recreate it, in such a way:\nawk \u0026#39;$5 \u0026gt;= 3071\u0026#39; /etc/ssh/moduli \u0026gt; /etc/ssh/moduli.safe mv /etc/ssh/moduli.safe /etc/ssh/moduli Moduli / OpenBSD Yes, it is possible to create, as: ssh-keygen -G /etc/ssh/moduli -b 3072\nAttention, the generation will be long and depends very strongly on the power of your server.\nHowever, you should know that for a few years/versions, the file is already generated and happens to be in /etc/moduli\nSee moduli(5) Sandbox WarningSince v7.5, this is an deprecated and obsolete option!\nDo not use it anymore!\nTL;DR Here is a minimalist example of the secure configuration file on the server side:\nPort 22 ListenAddress 192.168.xxx.yyy ListenAddress fd00:abcd:efg0::1 HostKey /etc/ssh/ssh_host_rsa_key HostKey /etc/ssh/ssh_host_ed25519_key Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org HostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com PermitRootLogin no PubkeyAuthentication yes AuthorizedKeysFile .ssh/authorized_keys PasswordAuthentication no Troubleshooting Bad key types If you had this following error:\n/etc/ssh/sshd_config line 26: Bad key types 'ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com'\nDelete those sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com algorithms, and test again. If, OK, reload the service.\nLoginGraceTime Think to grow the value of the LoginGraceTime option. Using RSA + PKBDF, or ed25519 keys, require more time for connections. Egual, you will not see any error messages into the auth log.\nTest To check the configuration: :# sshd -t ssh-audit It exists a tool, named ssh-audit to check if your configuration is secure.\nInstall and execute against your server as:\n:$ ssh-audit adresse-ip-serveur-ssh\nYou need to fix URGENTLY all red colored messages. A green colored message mean OK sshaudit on internet It is possible to test too your server with the sshaudit website: https://www.sshaudit.com\nDocumentation Manpages sshd(8) , sshd_config(5) , sftp-server(8) moduli(5) Others https://infosec.mozilla.org/guidelines/openssh https://www.sshaudit.com/hardening_guides.html ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eBy default, even on OpenBSD, the SSH configuration is not the most secure.\u003c/p\u003e\n\u003cp\u003eNISTP Algorithms — \u003cem\u003elikely to be an NSA backdoor; but beware, this is\nseem to be a rumor\u003c/em\u003e, even SHA1 are always used.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eUse absolutly an OpenSSH version greater than the v6.5!\u003c/div\u003e\n\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eConfiguration file: \u003ccode\u003e/etc/ssh/sshd_config\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eApply ABSOLUTELY this following recommandations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse \u003cstrong\u003eonly\u003c/strong\u003e the v2 protocol,\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDo not connect with root account\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003edisable the \u003cstrong\u003ePasswordAuthentication\u003c/strong\u003e option\u003c/li\u003e\n\u003cli\u003euse \u003cstrong\u003eonly\u003c/strong\u003e the \u003cstrong\u003ePubkeyAuthentication\u003c/strong\u003e option\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"recreate-host-keys\"\u003eRecreate host keys\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ cd /etc/ssh\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# rm ssh_host_*\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# ssh-keygen -t ed25519 -f ssh_host_ed25519_key -N \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# ssh-keygen -t rsa -b \u003cspan style=\"color:#f99b15\"\u003e4096\u003c/span\u003e -f ssh_host_rsa_key -N \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u0026#34;\u003c/span\u003e -o -a \u003cspan style=\"color:#f99b15\"\u003e64\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eDo not use passphrase during the generation, otherwise the server will not\nbe able to read them…\u003c/p\u003e\n\u003cp\u003eAnyway, the \u003ccode\u003e/var/log/auth\u003c/code\u003e file will help you!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003chr\u003e\n\u003cp\u003eNext, you need to pay attention to the following:\u003c/p\u003e\n\u003ch3 id=\"hostkey\"\u003eHostKey\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cspan class=\"red\"\u003eDO NOT USE the DSA, ECDSA protocols!\u003c/span\u003e\u003c/div\u003e\n\n\u003cp\u003e\u003cstrong\u003eComment\u003c/strong\u003e the \u003ccode\u003eHostKey\u003c/code\u003e options to \u003cspan em\u003ekeep only related RSA and\nED25519 encryptions\u003c/span\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_rsa_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_ed25519_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eYou can use only elliptic curves keys, such ed25519. In this case, make\nsure that all your SSH clients can use this encryption mode too.\u003c/div\u003e\n\n\u003ch3 id=\"ciphers\"\u003eCiphers\u003c/h3\u003e\n\u003cp\u003eAllow those \u003cstrong\u003eciphers\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eCiphers chacha20-poly1305@openssh.com\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"hostkeyalgorithms\"\u003eHostKeyAlgorithms\u003c/h3\u003e\n\u003cp\u003eThe \u003cstrong\u003eHostKeyAlgorithms\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eHostKeyAlgorithms ssh-ed25519-cert-v01@openssh.com,ssh-ed25519\u003c/code\u003e\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eSegun you OpenSSH version, it\u0026rsquo;s possible to obtain a error message. \u003cbr\u003e\nSee the section \u0026ldquo;\u003ca href=\"/en/sec/ssh/sshd-harden/#bad-key-types\"\u003eTroubleshooting\u003c/a\u003e\u0026rdquo;!\u003c/div\u003e\n\n\u003ch3 id=\"keyexchange\"\u003eKeyExchange\u003c/h3\u003e\n\u003cp\u003eFocus on those \u003cstrong\u003eKeyExchange algoritms\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eKexAlgorithms mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"macs\"\u003eMACs\u003c/h3\u003e\n\u003cp\u003eChoose those \u003cstrong\u003eMessage Authentication Codes\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eMACs umac-64-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"moduli\"\u003eModuli\u003c/h3\u003e\n\u003cp\u003eThe moduli file containt prime numbers and generators to be used by the\nSSH server in the  \n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eDH \u003cem\u003e(Diffie-Hellman)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n group key exchange method.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eSince 2017, this \u003ca href=\"https://bugzilla.mindrot.org/show_bug.cgi?id=2793\" rel=\"external\"\u003ebug #2793\u003c/a\u003e\nexplains that in some contexts the proper functioning fails, following\nrecommendations below.\u003c/p\u003e\n\u003cp\u003eIf you can no longer login, consider reversing this change!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch4 id=\"moduli--linux\"\u003eModuli / Linux\u003c/h4\u003e\n\u003cp\u003eIt is recommended to recreate it, in such a way:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eawk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;$5 \u0026gt;= 3071\u0026#39;\u003c/span\u003e /etc/ssh/moduli \u0026gt; /etc/ssh/moduli.safe\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003emv /etc/ssh/moduli.safe /etc/ssh/moduli\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"moduli--openbsd\"\u003eModuli / OpenBSD\u003c/h4\u003e\n\u003cp\u003eYes, it is possible to create, as: \u003cbr\u003e\n\u003ccode\u003essh-keygen -G /etc/ssh/moduli -b 3072\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eAttention, the generation will be long and depends very strongly on the\npower of your server.\u003c/p\u003e\n\u003cp\u003eHowever, you should know that for a few years/versions, the file is\nalready generated and happens to be in \u003ccode\u003e/etc/moduli\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSee \n\u003ca class=\"man\" href=\"https://man.openbsd.org/moduli.5\" title=\"OpenBSD Manual Page Server for: moduli\"\u003emoduli(5)\u003c/a\u003e\n\u003c/p\u003e\n\u003ch3 id=\"sandbox\"\u003eSandbox\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eSince v7.5, this is an \u003cspan em\u003edeprecated and obsolete\u003c/span\u003e option!\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eDo not use it anymore!\u003c/strong\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"tldr\"\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003eHere is a minimalist example of the secure configuration file on the server\nside:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePort 22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eListenAddress 192.168.xxx.yyy\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eListenAddress fd00:abcd:efg0::1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_rsa_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKey /etc/ssh/ssh_host_ed25519_key\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eCiphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eKexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHostKeyAlgorithms ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eMACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128-etm@openssh.com\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePermitRootLogin no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePubkeyAuthentication yes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eAuthorizedKeysFile  .ssh/authorized_keys\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ePasswordAuthentication no\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"bad-key-types\"\u003eBad key types\u003c/h3\u003e\n\u003cp\u003eIf you had this following error:\u003cbr\u003e\n\u003ccode\u003e/etc/ssh/sshd_config line 26: Bad key types 'ssh-ed25519,ssh-ed25519-cert-v01@openssh.com,sk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com,rsa-sha2-256,rsa-sha2-512,rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com'\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eDelete those \u003ccode\u003esk-ssh-ed25519@openssh.com,sk-ssh-ed25519-cert-v01@openssh.com\u003c/code\u003e\nalgorithms, and \u003ca href=\"/en/sec/ssh/sshd-harden/#test\"\u003etest\u003c/a\u003e again. If, \u003cstrong\u003eOK\u003c/strong\u003e, reload the service.\u003c/p\u003e\n\u003ch3 id=\"logingracetime\"\u003eLoginGraceTime\u003c/h3\u003e\n\u003cp\u003eThink to grow the value of the \u003ccode\u003eLoginGraceTime\u003c/code\u003e option. Using RSA + PKBDF,\nor ed25519 keys, require more time for connections.\nEgual, you will not see any error messages into the auth log.\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"test\"\u003eTest\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTo check the configuration: \u003ccode\u003e:# sshd -t\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch4 id=\"ssh-audit\"\u003essh-audit\u003c/h4\u003e\n\u003cp\u003eIt exists a tool, named \u003ccode\u003essh-audit\u003c/code\u003e to check if your configuration is secure.\u003c/p\u003e\n\u003cp\u003eInstall and execute against your server as:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:$ ssh-audit adresse-ip-serveur-ssh\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eYou need to fix URGENTLY all red colored messages.\u003c/li\u003e\n\u003cli\u003eA green colored message mean OK\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"sshaudit-on-internet\"\u003esshaudit on internet\u003c/h4\u003e\n\u003cp\u003eIt is possible to test too your server with the \u003cstrong\u003esshaudit\u003c/strong\u003e website:\n\u003ca href=\"https://www.sshaudit.com\" rel=\"external\"\u003ehttps://www.sshaudit.com\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/sshd.8\" title=\"OpenBSD Manual Page Server for: sshd\"\u003esshd(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/sshd_config.5\" title=\"OpenBSD Manual Page Server for: sshd_config\"\u003esshd_config(5)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/sftp-server.8\" title=\"OpenBSD Manual Page Server for: sftp-server\"\u003esftp-server(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/moduli.5\" title=\"OpenBSD Manual Page Server for: moduli\"\u003emoduli(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"others\"\u003eOthers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://infosec.mozilla.org/guidelines/openssh\" rel=\"external\"\u003ehttps://infosec.mozilla.org/guidelines/openssh\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.sshaudit.com/hardening_guides.html\" rel=\"external\"\u003ehttps://www.sshaudit.com/hardening_guides.html\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Harden SSH server!","tags":["SSH","harden"],"date_published":"2020-09-18T15:58:58+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-09-14:/en/sys/openwrt/sysupgrade","url":"https://it-log.fr.eu.org/en/sys/openwrt/sysupgrade/","title":"OpenWRT: Manage correctly the process to upgrade to the new version!","author":{"name":"Stéphane HUC"},"content_text":"opkg → apk Since OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition. Description DangerBefore updating your system, it is ESSENTIAL that you read the following the OpenWRT release announcement, especially the chapters “Upgrading to…” and “ Known issues”.\nThese chapters may contain information relating to your router; skipping them could damage your damage your equipment and render it unusable!\nOpenWRT has a tool to upgrade the system, named sysupgrade. You can invoque on the Luci\u0026rsquo;s web admin.\nIf you are more interesting by sysupgrade on LuCI, go to this note: Flash on LuCI\nThe following procedure explains step by step the sysupgrade in CLI mode, while preserving the user configuration…\nProcess The first action is install the tool curl, because the native wget does not support TLS.\n:# opkg install curl\nopkgscript.sh The opkgscript.sh script is used to save the list of packages installed in addition to the base.\n⇒ Now, fetch opkgscript.sh: :$ curl -O https://raw.githubusercontent.com/richb-hanover/OpenWrtScripts/master/opkgscript.sh\n⇒ Put the +x needed rights: :# chmod 0700 opkgscript.sh\n⇒ backup the list of installed packages; to re-install easy them after the sysupgrade process: \\\n:# ./opkgscript.sh -v write\nThis script write the list into file /etc/config/opkg.installed.\nDownload firmware Let\u0026rsquo;s retrieve the new firmware version:\ne.g. the current version: :# v=\u0026quot;24.10.5\u0026quot;\n⇒ for the OpenWRT One:\n:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/mediatek/filogic/{openwrt-\u0026quot;${v}\u0026quot;-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb,sha256sums}\n⇒ for the Ubiquiti EdgeRouter X:\n:#curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/ramips/mt7621/{openwrt-\u0026quot;${v}\u0026quot;-ramips-mt7621-ubnt_edgerouter-x-squashfs-sysupgrade.bin,sha256sums}\n⇒ for the Xiaomi Mi Router AX3000T:\n:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/mediatek/filogic/{openwrt-\u0026quot;${v}\u0026quot;-mediatek-filogic-xiaomi_mi-router-ax3000t-squashfs-sysupgrade.bin,sha256sums}\n⇒ for the Xiaomi Redmi Router AC2100:\n:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/ramips/mt7621/{openwrt-\u0026quot;${v}\u0026quot;-ramips-mt7621-xiaomi_redmi-router-ac2100-squashfs-sysupgrade.bin,sha256sums}\nAnd, we check the checksum: :# sha256sum -c sha256sums 2\u0026gt; /dev/null | grep OK\n⇒ Correct result for OpenWRT One: openwrt-24.10.4-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb: OK\nDangerATTENTION: If the verification fails, go to discuss it on the forum!\nDon\u0026rsquo;t try to upgrade with a corrupted firmware!\nBackup configuration The next step check the backup configuration:\n# sysupgrade -l\nIf necessary, you can edit the file /etc/sysupgrade.conf to add some folders/files; for instance, in the case where a user has been added to the sudo group, you need to add those:\n/etc/sudoers /etc/sudoers.d/ Check again; and, backup the configuration:\n:# sysupgrade -b /tmp/backup-${HOSTNAME}-$(date +%F).tar.gz And, after, it is necessary to retrieve this backup: :$ scp root@openwrt:/tmp/backup*.tar.gz $(pwd) (where \u0026lsquo;openwrt\u0026rsquo; is the adresse IP about your router)\nInfoIf you obtain this error message: ash: /usr/libexec/sftp-server: not found\nPlease, see this note, belowe, about SSH v9.0 and higher\nThe note Freeing memory may be interesting, but it\u0026rsquo;s not very useful on Ubiquiti EdgeRouter X or Xiaomi Redmi Router AC2100.\nUpgrade system Now, it\u0026rsquo;s time to upgrade the system:\n:# sysupgrade -v openwrt-\u0026quot;${v}\u0026quot;-*-sysupgrade.bin or :# sysupgrade -v openwrt-\u0026quot;${v}\u0026quot;-*-sysupgrade.itb depends on the router.\nExample, for the OpenWRT One:\n:# sysupgrade -v openwrt-\u0026#34;$v\u0026#34;-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb (date) upgrade: Saving config files... etc/config/attendedsysupgrade etc/config/dhcp etc/config/dropbear etc/config/firewall etc/config/https-dns-proxy etc/config/luci etc/config/network etc/config/opkg.installed etc/config/rpcd etc/config/system etc/config/ubihealthd etc/config/ubootenv etc/config/uhttpd etc/config/unbound etc/config/wifi_schedule etc/config/wireless etc/crontabs/root etc/dropbear/authorized_keys etc/dropbear/dropbear_ed25519_host_key etc/dropbear/dropbear_rsa_host_key etc/fw_env.config etc/group etc/hosts etc/inittab etc/luci-uploads/.placeholder etc/nftables.d/10-custom-filter-chains.nft etc/nftables.d/README etc/opkg/keys/8a11255d14aef6c8 etc/opkg/keys/d310c6f2833e97f7 etc/passwd etc/profile etc/profile.d/busybox-history-file.sh etc/rc.local etc/shadow etc/shells etc/shinit etc/sysctl.conf etc/sysupgrade.conf etc/uhttpd.crt etc/uhttpd.key etc/unbound/unbound.conf etc/unbound/unbound_ext.conf root/opkgscript.sh (date) upgrade: Commencing upgrade. Closing all shell sessions. TipNotice the presence of the file /etc/config/opkg.installed into the backup. At this moment, your SSH session close, and the router reboot!\nInfoWhen reconnecting to your router from your SSH client, it may happen that the SSH connection fails with the following error message: WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED. In this case, please see the note SSH Remote Host Identification\nIf you migrate from 19.07.x to ≥ 21.02.x, please read carefully the note Migration to ≥ 21.02.*\nAfter rebooting, if your router cant access to the Internet, check the nameserver on /etc/resolv.conf.\nVerify the new OS version After the reboot, you will find the information about the new version:\nIn LuCI, go to Status \u0026gt; Overview, see the section \u0026ldquo;System\u0026rdquo; and \u0026ldquo;Firmware version\u0026rdquo;. In SSH, the login banner has the release information. As instance: BusyBox v1.36.1 (2025-12-17 21:08:22 UTC) built-in shell (ash) _______ ________ __ | |.-----.-----.-----.| | | |.----.| |_ | - || _ | -__| || | | || _|| _| |_______|| __|_____|__|__||________||__| |____| |__| W I R E L E S S F R E E D O M ----------------------------------------------------- OpenWrt 24.10.5, r29087-d9c5716d1d ----------------------------------------------------- Upgrade packages WarningNote that on a device with only 4MB of NVRAM, these updates may not fit; ensure there is at least 600KB or so free.\nCheck your router\u0026rsquo;s specifications!\nLet\u0026rsquo;s upgrade the third-party packages:\n⇒ On the SSH console, do:\n:# opkg update \u0026amp;\u0026amp; opkg list-upgradable\nIf the result show some binaries to update, launch this command:\n:# for name in `opkg list-upgradable | awk \u0026#39;{print $1}\u0026#39;`; do opkg upgrade \u0026#34;${name}\u0026#34;; done Restore \u0026ldquo;user profil\u0026rdquo; To restore the user profile:\nAfter repeating the step about curl and the script opkgscript.sh, we run the script to reinstall all packages previously intalled by you:\n:# ./opkgscript.sh -v install\nAnd, after… the last but not the least: reboot!\nUltimates Checks Check your configuration:\nyour various network interfaces are always present and operational? your firewall configuration is correct? your different services run correctly? Have you a IPv6 tunnel, OpenVPN, or others services, usually, accessed by the menu \u0026ldquo;Services\u0026rdquo;? Voila!\nNotes You will find various useful informations, only for certain contexts:\nFlash on LuCI Since the menu \u0026ldquo;System\u0026rdquo; \u0026gt; \u0026ldquo;Backup / Flash firmware\u0026rdquo;:\n1/ It can be usefull in the \u0026lsquo;Configuration\u0026rsquo; tab to modify the list of custom files to save… If you installed some packages, relatives files and folders are not backuped if there are not wroted here.\n2/ Make a backup of your OpenWRT configuration before, from the \u0026lsquo;Actions\u0026rsquo; tab.\n3/ During the process of flashing a new sysupgrade image:\n⇒ use those options:\nKEEP SETTINGS AND RETAIN THE CURRENT CONFIGURATION, at least INCLUDE IN BACKUP A LIST OF CURRENT INSTALLED PACKAGES AT /ETC/BACKUP/INSTALLED_PACKAGES.TXT. If those are not checked, you lost your entire configuration of OpenWRT.\nIn all cases, all previous installed packages need to be reinstall, perhaps to configure again.\nKeep on mind that changes included by upgrades to major version can cause problems during migration. There may be critical changes.\nSSH v9.0 and higher If your SSH client version is ≥ 9.0:\nSince SSH v9.0, the behavior of scp has changed.\nThe above command will fail with the error message:\nscp router:/tmp/backup-***-2022-04-21.tar.gz . ash: /usr/libexec/sftp-server: not found scp: Connection closed In the fact, Dropbrear cant discuss with… To resolve this, add the -O option to the command, instance: $ scp -O root@openwrt:/tmp/backup*.tar.gz $(pwd) (this restore the old SFTP behavior of scp)\nAnother tips is to install the OpenSSH server instead of Dropbear.\nFreeing memory This section is most useful if /tmp is not enough large to store the sysupgrade OpenWRT image. The following actions will temporary free up space in RAM.\nLet\u0026rsquo;s make sure of the memory and disk space with the commands free and df, or cat /proc/meminfo; the goal is to verify that the size of free RAM is larger than the size of the downloaded image. If it\u0026rsquo;s the case, then go to continue the process… else, \u0026ldquo;houston, we have a problem\u0026rdquo; and go to discuss on the OpenWRT forum!\nTake an example to better understand:\n⇒ the size of the sysupgrade binary to the current version:\n:$ ll -h (…) -rw-rw-r-- 1 root root 6.7M Sep 10 13:53 openwrt-22.03.0-ramips-mt7621-xiaomi_redmi-router-ac2100-squashfs-sysupgrade.bin (…) it is 6.7 Mb.\n⇒ the available space in /tmp:\n:# df -h Filesystem Size Used Available Use% Mounted on /dev/root 3.8M 3.8M 0 100% /rom tmpfs 59.7M 540.0K 59.1M 1% /tmp /dev/ubi0_1 97.2M 7.8M 84.7M 8% /overlay overlayfs:/overlay 97.2M 7.8M 84.7M 8% / tmpfs 512.0K 0 512.0K 0% /dev In the context of the Xiaomi Redmi AC2100, the available space is 59.1Mb, which is more enough to retrieve the sysupgrade image and manage it.\n⇒ Also, the space freed memory:\n:# free -m total used free shared buff/cache available Mem: 122220 40532 61400 540 20288 46700 Swap: 0 0 0 In this context, the free memory space is about 60Mb. Again, there is enough space to manage the sysupgrade image.\nIf, in your context, the total space available, i.e. memory + space /tmp is not enough, it\u0026rsquo;s possible to try the following actions — delete what is not useless:\npackage list files: :# rm -r /tmp/opkg-lists/ caches: :# sync \u0026amp;\u0026amp; echo 3 \u0026gt; /proc/sys/vm/drop_caches the following wifi drivers: :# rm /etc/modules.d/*{80211,ath9k,b43}* and, finally, check that there are no symbolic links into /etc/modules.d; if, it\u0026rsquo;s the cas, delete-them. This which will free up RAM at the next startup. And reboot before the sysupgrade process. SSH Remote Host Identification When connecting again via SSH, it is normally possible that you will get the following error message:\n@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Someone could be eavesdropping on you right now (man-in-the-middle attack)! It is also possible that a host key has just been changed. The fingerprint for the ED25519 key sent by the remote host is SHA256:0atP7BnQQ98EVJciOCBDYAUD245lKm2tbau8BgWMpQ0. Please contact your system administrator. Add correct host key in /home/you/.ssh/known_hosts to get rid of this message. Offending RSA key in /home/you/.ssh/known_hosts:93 remove with: ssh-keygen -f \u0026#34;/home/you/.ssh/known_hosts\u0026#34; -R \u0026#34;192.168.xyz.1\u0026#34; ED25519 host key for 192.168.xyz.1 has changed and you have requested strict checking. Host key verification failed. DO NOT PANIC! It\u0026rsquo;s a normal process.\nWe changed the version, and the identification host, too. Apply the ssh-keygen command, like wroted, to delete the older. And, after retry your connection.\nWarningAfter the upgrade, the machines behind the router no longer have proper access to the Internet; it\u0026rsquo;s normal; do not panic!\nDont forget: in fact, sysupgrade remove all user configuration datas.\nMigration to ≥ 21.02.* Warningminimum hardware requirements:\nSince version 21.02.0, devices now need at least 8 MB of flash and 64 MB of RAM to run a default build of OpenWRT.\nSee: https://openwrt.org/supported_devices/864_warning\nYou chose to migrate at the 21.02.* version from v19.7.*, it\u0026rsquo;s fine!\nBut, you need to connect on the WebUI, and click on the \u0026ldquo;Interfaces\u0026rdquo; menu. The interface will propose you to migrate the configuration, do-it now!\nAnd after, reboot!\nresolv.conf Check the /etc/resolv.conf, and if necessary, modify it to write IP address of a reachable DNS server.\nAs instance:\n:# sed -i -e \u0026#39;s/127.0.0.1/9.9.9.9/\u0026#39; /etc/resolv.conf Documentations As you can read in the documentation of the OpenWRT wiki, there are other methods; the one I propose seems the most relevant…\nUpgrading OpenWrt firmware using LuCI and CLI Upgrading OpenWrt firmware using LuCI Upgrading OpenWrt firmware using CLI ","content_html":"\u003cdiv class=\"tab-info i-deprecated\"\u003e\u003cstrong\u003eopkg → apk\u003c/strong\u003e\u003c/div\u003e\n\u003cdiv class=\"alert alert-deprecated\" role=\"alert\"\u003e\u003cstrong\u003eSince OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition.\u003c/strong\u003e\u003c/div\u003e\n\n\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\n\u003cdiv class=\"tab-info i-danger\"\u003eDanger\u003c/div\u003e\u003cdiv class=\"alert alert-danger\" role=\"alert\"\u003e\u003cp\u003eBefore updating your system, it is ESSENTIAL that you read the following the OpenWRT release announcement, especially the chapters “Upgrading to…” and “ Known issues”.\u003c/p\u003e\n\u003cp\u003eThese chapters may contain information relating to your router; skipping them could damage your damage your equipment and render it unusable!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003e\u003cstrong\u003eOpenWRT\u003c/strong\u003e has a tool to upgrade the system, named \u003cstrong\u003esysupgrade\u003c/strong\u003e. You can invoque on the Luci\u0026rsquo;s web admin.\u003c/p\u003e\n\u003cp\u003eIf you are more interesting by sysupgrade on LuCI, go to this note:\n\u003ca href=\"/en/sys/openwrt/sysupgrade/#flash-on-luci\"\u003eFlash on LuCI\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThe following procedure explains step by step the sysupgrade in CLI mode, while preserving the user configuration…\u003c/p\u003e\n\u003ch2 id=\"process\"\u003eProcess\u003c/h2\u003e\n\u003cp\u003eThe first action is install the tool \u003ccode\u003ecurl\u003c/code\u003e, because the native \u003ccode\u003ewget\u003c/code\u003e does not support TLS.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# opkg install curl\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"opkgscriptsh\"\u003eopkgscript.sh\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003eopkgscript.sh\u003c/code\u003e script is used to save the list of packages installed in addition to the base.\u003c/p\u003e\n\u003cp\u003e⇒ Now, fetch \u003ca href=\"https://raw.githubusercontent.com/richb-hanover/OpenWrtScripts/master/opkgscript.sh\" rel=\"external\"\u003eopkgscript.sh\u003c/a\u003e: \u003cbr\u003e\n\u003ccode\u003e:$ curl -O https://raw.githubusercontent.com/richb-hanover/OpenWrtScripts/master/opkgscript.sh\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ Put the \u003ccode\u003e+x\u003c/code\u003e needed rights: \u003cbr\u003e\n\u003ccode\u003e:# chmod 0700 opkgscript.sh\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ backup the list of installed packages; \u003cem\u003eto re-install easy them after the sysupgrade process\u003c/em\u003e: \\\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# ./opkgscript.sh -v write\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eThis script write the list into file \u003ccode\u003e/etc/config/opkg.installed\u003c/code\u003e.\u003c/p\u003e\n\u003ch3 id=\"download-firmware\"\u003eDownload firmware\u003c/h3\u003e\n\u003cp\u003eLet\u0026rsquo;s retrieve the new firmware version:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ee.g. the current version:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003e:# v=\u0026quot;24.10.5\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ for the \u003cstrong\u003eOpenWRT One\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/mediatek/filogic/{openwrt-\u0026quot;${v}\u0026quot;-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb,sha256sums}\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ for the \u003cstrong\u003eUbiquiti EdgeRouter X\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:#curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/ramips/mt7621/{openwrt-\u0026quot;${v}\u0026quot;-ramips-mt7621-ubnt_edgerouter-x-squashfs-sysupgrade.bin,sha256sums}\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ for the \u003cstrong\u003eXiaomi Mi Router AX3000T\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/mediatek/filogic/{openwrt-\u0026quot;${v}\u0026quot;-mediatek-filogic-xiaomi_mi-router-ax3000t-squashfs-sysupgrade.bin,sha256sums}\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ for the \u003cstrong\u003eXiaomi Redmi Router AC2100\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# curl -O https://downloads.openwrt.org/releases/\u0026quot;${v}\u0026quot;/targets/ramips/mt7621/{openwrt-\u0026quot;${v}\u0026quot;-ramips-mt7621-xiaomi_redmi-router-ac2100-squashfs-sysupgrade.bin,sha256sums}\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eAnd, we check the checksum: \u003cbr\u003e\n\u003ccode\u003e:# sha256sum -c sha256sums 2\u0026gt; /dev/null | grep OK\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e⇒ Correct result for \u003cstrong\u003eOpenWRT One\u003c/strong\u003e: \u003cbr\u003e\n\u003ccode\u003eopenwrt-24.10.4-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb: OK\u003c/code\u003e\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-danger\"\u003eDanger\u003c/div\u003e\u003cdiv class=\"alert alert-danger\" role=\"alert\"\u003e\u003cp\u003e\u003cstrong\u003eATTENTION\u003c/strong\u003e: If the verification fails, go to discuss it on the forum!\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eDon\u0026rsquo;t try to upgrade with a corrupted firmware!\u003c/strong\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"backup-configuration\"\u003eBackup configuration\u003c/h3\u003e\n\u003cp\u003eThe next step check the backup configuration:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e# sysupgrade -l\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIf necessary, you can edit the file \u003ccode\u003e/etc/sysupgrade.conf\u003c/code\u003e to add some folders/files; for instance, in the case where \u003ca href=\"/en/sys/openwrt/sudo\"\u003ea user has been added to the \u003cstrong\u003esudo\u003c/strong\u003e group\u003c/a\u003e, you need to add those:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e/etc/sudoers\u003c/li\u003e\n\u003cli\u003e/etc/sudoers.d/\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eCheck again; and, backup the configuration:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e:# sysupgrade -b /tmp/backup-${HOSTNAME}-$(date +%F).tar.gz\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eAnd, after, it is necessary to retrieve this backup: \u003cbr\u003e\n\u003ccode\u003e:$ scp root@openwrt:/tmp/backup*.tar.gz $(pwd)\u003c/code\u003e  \u003cbr\u003e\n\u003cem\u003e(where \u0026lsquo;openwrt\u0026rsquo; is the adresse IP about your router)\u003c/em\u003e\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eIf you obtain this error message: \u003cbr\u003e\n\u003ccode\u003eash: /usr/libexec/sftp-server: not found\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003ePlease, see this note, belowe, about \u003ca href=\"/en/sys/openwrt/sysupgrade/#ssh-v90-and-higher\"\u003eSSH v9.0 and higher\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eThe note \u003ca href=\"/en/sys/openwrt/sysupgrade/#freeing-memory\"\u003eFreeing memory\u003c/a\u003e may be interesting, but it\u0026rsquo;s not very useful on Ubiquiti EdgeRouter X or Xiaomi Redmi Router AC2100.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"upgrade-system\"\u003eUpgrade system\u003c/h3\u003e\n\u003cp\u003eNow, it\u0026rsquo;s time to upgrade the system:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# sysupgrade -v openwrt-\u0026quot;${v}\u0026quot;-*-sysupgrade.bin\u003c/code\u003e or \u003cbr\u003e\n\u003ccode\u003e:# sysupgrade -v openwrt-\u0026quot;${v}\u0026quot;-*-sysupgrade.itb\u003c/code\u003e depends on the router.\u003c/p\u003e\n\u003cp\u003eExample, for the \u003cstrong\u003eOpenWRT One\u003c/strong\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# sysupgrade -v openwrt-\u0026#34;$v\u0026#34;-mediatek-filogic-openwrt_one-squashfs-sysupgrade.itb\n(date) upgrade: Saving config files...\netc/config/attendedsysupgrade\netc/config/dhcp\netc/config/dropbear\netc/config/firewall\netc/config/https-dns-proxy\netc/config/luci\netc/config/network\netc/config/opkg.installed\netc/config/rpcd\netc/config/system\netc/config/ubihealthd\netc/config/ubootenv\netc/config/uhttpd\netc/config/unbound\netc/config/wifi_schedule\netc/config/wireless\netc/crontabs/root\netc/dropbear/authorized_keys\netc/dropbear/dropbear_ed25519_host_key\netc/dropbear/dropbear_rsa_host_key\netc/fw_env.config\netc/group\netc/hosts\netc/inittab\netc/luci-uploads/.placeholder\netc/nftables.d/10-custom-filter-chains.nft\netc/nftables.d/README\netc/opkg/keys/8a11255d14aef6c8\netc/opkg/keys/d310c6f2833e97f7\netc/passwd\netc/profile\netc/profile.d/busybox-history-file.sh\netc/rc.local\netc/shadow\netc/shells\netc/shinit\netc/sysctl.conf\netc/sysupgrade.conf\netc/uhttpd.crt\netc/uhttpd.key\netc/unbound/unbound.conf\netc/unbound/unbound_ext.conf\nroot/opkgscript.sh\n(date) upgrade: Commencing upgrade. Closing all shell sessions.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eNotice the presence of the file \u003ccode\u003e/etc/config/opkg.installed\u003c/code\u003e into the\nbackup.\u003c/div\u003e\n\n\u003cp\u003eAt this moment, your SSH session close, and the router reboot!\u003c/p\u003e\n\u003chr\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eWhen reconnecting to your router from your SSH client, it may happen that the SSH connection fails with the following error message: \u003cbr\u003e\n\u003ccode\u003eWARNING: REMOTE HOST IDENTIFICATION HAS CHANGED\u003c/code\u003e. \u003cbr\u003e\nIn this case, please see the note \u003ca href=\"/en/sys/openwrt/sysupgrade/#ssh-remote-host-identification\"\u003eSSH Remote Host Identification\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eIf you migrate from 19.07.x to ≥ 21.02.x, please read carefully the note \u003ca href=\"/en/sys/openwrt/sysupgrade/#migration-to--2102\"\u003eMigration to ≥ 21.02.*\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eAfter rebooting, if your router cant access to the Internet, check the nameserver on \u003ccode\u003e/etc/resolv.conf\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003chr\u003e\n\u003ch4 id=\"verify-the-new-os-version\"\u003eVerify the new OS version\u003c/h4\u003e\n\u003cp\u003eAfter the reboot, you will find the information about the new version:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIn LuCI, go to Status \u0026gt; Overview, see the section \u0026ldquo;System\u0026rdquo; and \u0026ldquo;Firmware version\u0026rdquo;.\u003c/li\u003e\n\u003cli\u003eIn SSH, the login banner has the release information. As instance:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003eBusyBox v1.36.1 (2025-12-17 21:08:22 UTC) built-in shell (ash)\n\n  _______                     ________        __\n |       |.-----.-----.-----.|  |  |  |.----.|  |_\n |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|\n |_______||   __|_____|__|__||________||__|  |____|\n          |__| W I R E L E S S   F R E E D O M\n -----------------------------------------------------\n OpenWrt 24.10.5, r29087-d9c5716d1d\n -----------------------------------------------------\n\u003c/code\u003e\u003c/pre\u003e\u003ch3 id=\"upgrade-packages\"\u003eUpgrade packages\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eNote that on a device with only 4MB of NVRAM, these updates may not fit; ensure there is at least 600KB or so free.\u003c/p\u003e\n\u003cp\u003eCheck your router\u0026rsquo;s specifications!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eLet\u0026rsquo;s upgrade the third-party packages:\u003c/p\u003e\n\u003cp\u003e⇒ On the SSH console, do:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# opkg update \u0026amp;\u0026amp; opkg list-upgradable\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIf the result show some binaries to update, launch this command:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e name in \u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003eopkg list-upgradable | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{print $1}\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e opkg upgrade \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ename\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"restore-user-profil\"\u003eRestore \u0026ldquo;user profil\u0026rdquo;\u003c/h3\u003e\n\u003cp\u003eTo restore the user profile:\u003c/p\u003e\n\u003cp\u003eAfter repeating the step about curl and the script \u003ccode\u003eopkgscript.sh\u003c/code\u003e, we run the script to reinstall all packages previously intalled by you:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e:# ./opkgscript.sh -v install\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eAnd, after… the last but not the least: reboot!\u003c/p\u003e\n\u003ch2 id=\"ultimates-checks\"\u003eUltimates Checks\u003c/h2\u003e\n\u003cp\u003eCheck your configuration:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eyour various network interfaces are always present and operational?\u003c/li\u003e\n\u003cli\u003eyour firewall configuration is correct?\u003c/li\u003e\n\u003cli\u003eyour different services run correctly? Have you a IPv6 tunnel, OpenVPN,\nor others services, usually, accessed by the menu \u0026ldquo;Services\u0026rdquo;?\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"notes\"\u003eNotes\u003c/h2\u003e\n\u003cp\u003eYou will find various useful informations, only for certain contexts:\u003c/p\u003e\n\u003ch3 id=\"flash-on-luci\"\u003eFlash on LuCI\u003c/h3\u003e\n\u003cp\u003eSince the menu \u0026ldquo;System\u0026rdquo; \u0026gt; \u0026ldquo;Backup / Flash firmware\u0026rdquo;:\u003c/p\u003e\n\u003cp\u003e1/ It can be usefull in the \u0026lsquo;Configuration\u0026rsquo; tab to modify the list of custom files to save… \u003cbr\u003e\nIf you installed some packages, relatives files and folders are not backuped if there are not wroted here.\u003c/p\u003e\n\u003cp\u003e2/ Make a backup of your OpenWRT configuration before, from the \u0026lsquo;Actions\u0026rsquo; tab.\u003c/p\u003e\n\u003cp\u003e3/ During the process of flashing a new sysupgrade image:\u003c/p\u003e\n\u003cp\u003e⇒ use those options:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eKEEP SETTINGS AND RETAIN THE CURRENT CONFIGURATION\u003c/strong\u003e, at least\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eINCLUDE IN BACKUP A LIST OF CURRENT INSTALLED PACKAGES AT /ETC/BACKUP/INSTALLED_PACKAGES.TXT\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIf those are not checked, you lost your entire configuration of OpenWRT.\u003c/p\u003e\n\u003cp\u003eIn all cases, all previous installed packages need to be reinstall, perhaps to configure again.\u003c/p\u003e\n\u003cp\u003eKeep on mind that changes included by upgrades to major version can cause problems during migration. There may be critical changes.\u003c/p\u003e\n\u003ch3 id=\"ssh-v90-and-higher\"\u003eSSH v9.0 and higher\u003c/h3\u003e\n\u003cp\u003eIf your SSH client version is ≥ 9.0:\u003c/p\u003e\n\u003cp\u003eSince SSH v9.0, the behavior of \u003ccode\u003escp\u003c/code\u003e has changed.\u003c/p\u003e\n\u003cp\u003eThe above command will fail with the error message:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003escp router:/tmp/backup-***-2022-04-21.tar.gz .\nash: /usr/libexec/sftp-server: not found\nscp: Connection closed\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eIn the fact, Dropbrear cant discuss with… \u003cbr\u003e\nTo resolve this, add the \u003ccode\u003e-O\u003c/code\u003e option to the command, instance: \u003cbr\u003e\n\u003ccode\u003e$ scp -O root@openwrt:/tmp/backup*.tar.gz $(pwd)\u003c/code\u003e \u003cbr\u003e\n\u003cem\u003e(this restore the old SFTP behavior of scp)\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eAnother tips is to \u003ca href=\"/en/sys/openwrt/openssh/\"\u003einstall the OpenSSH server instead of Dropbear\u003c/a\u003e.\u003c/p\u003e\n\u003ch3 id=\"freeing-memory\"\u003eFreeing memory\u003c/h3\u003e\n\u003cp\u003eThis section is most useful if \u003ccode\u003e/tmp\u003c/code\u003e is not enough large to store the sysupgrade OpenWRT image. The following actions will temporary free up space in RAM.\u003c/p\u003e\n\u003cp\u003eLet\u0026rsquo;s make sure of the memory and disk space with the commands \u003ccode\u003efree\u003c/code\u003e and \u003ccode\u003edf\u003c/code\u003e, or \u003ccode\u003ecat /proc/meminfo\u003c/code\u003e; the goal is to verify that \u003cstrong\u003ethe size of \u003cem\u003efree\u003c/em\u003e RAM is larger than the size of the downloaded image\u003c/strong\u003e. \u003cbr\u003e\nIf it\u0026rsquo;s the case, then go to continue the process… else, \u0026ldquo;houston, we have a problem\u0026rdquo; and go to discuss on the OpenWRT forum!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eTake an example to better understand:\u003c/p\u003e\n\u003cp\u003e⇒ the size of the sysupgrade binary to the current version:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:$ ll -h\n(…)\n-rw-rw-r-- 1 root root 6.7M Sep  10 13:53 openwrt-22.03.0-ramips-mt7621-xiaomi_redmi-router-ac2100-squashfs-sysupgrade.bin\n(…)\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eit is 6.7 Mb.\u003c/p\u003e\n\u003cp\u003e⇒ the available space in \u003ccode\u003e/tmp\u003c/code\u003e:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# df -h\nFilesystem                Size      Used Available Use% Mounted on\n/dev/root                 3.8M      3.8M         0 100% /rom\ntmpfs                    59.7M    540.0K     59.1M   1% /tmp\n/dev/ubi0_1              97.2M      7.8M     84.7M   8% /overlay\noverlayfs:/overlay       97.2M      7.8M     84.7M   8% /\ntmpfs                   512.0K         0    512.0K   0% /dev\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eIn the context of the Xiaomi Redmi AC2100, the available space is 59.1Mb, which is more enough to retrieve the sysupgrade image and manage it.\u003c/p\u003e\n\u003cp\u003e⇒ Also, the space freed memory:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e:# free -m\n              total        used        free      shared  buff/cache   available\nMem:         122220       40532       61400         540       20288       46700\nSwap:             0           0           0\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eIn this context, the free memory space is about 60Mb. Again, there is\nenough space to manage the sysupgrade image.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eIf\u003c/strong\u003e, in your context, the total space available, i.e. memory + space \u003ccode\u003e/tmp\u003c/code\u003e is not enough, it\u0026rsquo;s possible to try the following actions — delete what is not useless:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003epackage list files:\n\u003ccode\u003e:# rm -r /tmp/opkg-lists/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ecaches:\n\u003ccode\u003e:# sync \u0026amp;\u0026amp; echo 3 \u0026gt; /proc/sys/vm/drop_caches\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ethe following wifi drivers:\n\u003ccode\u003e:# rm /etc/modules.d/*{80211,ath9k,b43}*\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eand, finally, check that there are no symbolic links into \u003ccode\u003e/etc/modules.d\u003c/code\u003e; if, it\u0026rsquo;s the cas, delete-them. This which will free up RAM at the next startup.\u003c/li\u003e\n\u003cli\u003eAnd \u003cstrong\u003ereboot\u003c/strong\u003e before the sysupgrade process.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"ssh-remote-host-identification\"\u003eSSH Remote Host Identification\u003c/h3\u003e\n\u003cp\u003eWhen connecting again via SSH, it is normally possible that you will get the following error message:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eIT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSomeone could be eavesdropping on you right now \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eman-in-the-middle attack\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e!\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eIt is also possible that a host key has just been changed.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eThe fingerprint \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e the ED25519 key sent by the remote host is\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSHA256:0atP7BnQQ98EVJciOCBDYAUD245lKm2tbau8BgWMpQ0.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ePlease contact your system administrator.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAdd correct host key in /home/you/.ssh/known_hosts to get rid of this message.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eOffending RSA key in /home/you/.ssh/known_hosts:93\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  remove with:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  ssh-keygen -f \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/home/you/.ssh/known_hosts\u0026#34;\u003c/span\u003e -R \u003cspan style=\"color:#48b685\"\u003e\u0026#34;192.168.xyz.1\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eED25519 host key \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e 192.168.xyz.1 has changed and you have requested strict checking.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eHost key verification failed.\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eDO NOT PANIC! It\u0026rsquo;s a normal process.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eWe changed the version, and the identification host, too. \u003cbr\u003e\nApply the ssh-keygen command, like wroted, to delete the older. And, after retry your connection.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eAfter the upgrade, the machines behind the router no longer have proper access to the Internet; it\u0026rsquo;s normal; do not panic!\u003c/p\u003e\n\u003cp\u003eDont forget: in fact, \u003ccode\u003esysupgrade\u003c/code\u003e remove all user configuration datas.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"migration-to--2102\"\u003eMigration to ≥ 21.02.*\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003e\u003cstrong\u003eminimum hardware requirements\u003c/strong\u003e:\u003c/p\u003e\n\u003cp\u003eSince version 21.02.0, devices now need at least 8 MB of flash and 64 MB of RAM to run a default build of OpenWRT.\u003c/p\u003e\n\u003cp\u003eSee: \u003ca href=\"https://openwrt.org/supported_devices/864_warning\" rel=\"external\"\u003ehttps://openwrt.org/supported_devices/864_warning\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eYou chose to migrate at the 21.02.* version from v19.7.*, it\u0026rsquo;s fine!\u003c/p\u003e\n\u003cp\u003eBut, you need to connect on the WebUI, and click on the \u0026ldquo;Interfaces\u0026rdquo; menu. \u003cbr\u003e\nThe interface will propose you to migrate the configuration, do-it now!\u003c/p\u003e\n\u003cp\u003eAnd after, reboot!\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"resolvconf\"\u003eresolv.conf\u003c/h3\u003e\n\u003cp\u003eCheck the \u003ccode\u003e/etc/resolv.conf\u003c/code\u003e, and if necessary, modify it to write IP address of a reachable DNS server.\u003c/p\u003e\n\u003cp\u003eAs instance:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# sed -i -e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;s/127.0.0.1/9.9.9.9/\u0026#39;\u003c/span\u003e /etc/resolv.conf\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cp\u003eAs you can read in the documentation of the OpenWRT wiki, there are other methods; the one I propose seems the most relevant…\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://openwrt.org/docs/guide-user/installation/generic.sysupgrade\" rel=\"external\"\u003eUpgrading OpenWrt firmware using LuCI and CLI\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://openwrt.org/docs/guide-quick-start/sysupgrade.luci\" rel=\"external\"\u003eUpgrading OpenWrt firmware using LuCI\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://openwrt.org/docs/guide-user/installation/sysupgrade.cli\" rel=\"external\"\u003eUpgrading OpenWrt firmware using CLI\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Howto upgrade correctly OpenWRT… without losing user configuration datas; and some explains to migrate versions, on routers like OpenWRT One, Ubiquiti EdgeRouter X, Xiaomi Redmi AC2100, Xiaomi Mi Router AX3000T","tags":["OpenWRT","sysupgrade","opkg","sysadmin","router","Ubiquiti","EdgeRouter","Xiaomi","Mi","Redmi","AC2100","AX3000T","One"],"date_published":"2020-09-14T18:03:35+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-08-25:/en/web/hugo/hugo-search-jqueryui-autocomplete-json","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-search-jqueryui-autocomplete-json/","title":"Hugo Search: a 'build-in' search engine (JQueryUI: Autocomplete + JSON)","author":{"name":"Stéphane HUC"},"content_text":"Description Few months ago, I wrote this first article to build a \u0026lsquo;build-in\u0026rsquo; base search engine, with JQueryUI autocomplete(). (See Hugo search)\nOn this blog, Hugo generates one feed at the JSON format, named feed.json, available on the homepage. And, Hugo has a native function getJSON…\nLet\u0026rsquo;s go back to the code !\nCode Hugo Firstly, I write a $feed variable; her value is the absolute path for the file feed.json.\n{{- $baseURL := site.BaseURL | absLangURL -}} {{- $feed := urls.JoinPath $baseURL \u0026#34;/feed.json\u0026#34; | absLangURL -}} JQuery JQuery code is quasi the same: except this difference, Hugo\u0026rsquo;s range function will directly call the content returned by the getJSON function.\nThe code:\n{{- with resources.Get $feed -}} \u0026lt;!-- Javascript --\u0026gt; \u0026lt;script\u0026gt; $(function() { var projects = [ {{- range .items -}} { value: \u0026#34;{{ safeHTML .title }}\u0026#34;, label: \u0026#34;{{ safeHTML .summary }}\u0026#34;, url:\u0026#34;{{ safeURL .url }}\u0026#34; }, {{- end -}} ]; $(\u0026#34;#search\u0026#34;).autocomplete({ minLength: 0, source: projects, focus: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); return false; }, select: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); $(\u0026#34;#replyer\u0026#34;).val( ui.item.value ); return false; } }) .data(\u0026#39;ui-autocomplete\u0026#39;)._renderItem = function(ul, item) { return $(\u0026#39;\u0026lt;li\u0026gt;\u0026#39;) .append(\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39; + item.url + \u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;+ item.label + \u0026#39;\u0026#34;\u0026gt;\u0026#39; + item.value + \u0026#39;\u0026lt;/a\u0026gt;\u0026#39; ) .appendTo(ul); }; }); \u0026lt;/script\u0026gt; {{- end -}} HTML Make HTML is always so simple:\n\u0026lt;input class=\u0026#34;form-control\u0026#34; id=\u0026#34;search\u0026#34; placeholder=\u0026#34;{{ T \u0026#34;searchHolderTitle\u0026#34; }}\u0026#34;\u0026gt; \u0026lt;input aria-hidden=\u0026#34;true\u0026#34; id=\u0026#34;replyer\u0026#34; class=\u0026#34;hidden\u0026#34;\u0026gt; TL;DR \u0026lt;div id=\u0026#34;search\u0026#34;\u0026gt; \u0026lt;input class=\u0026#34;form-control\u0026#34; id=\u0026#34;search\u0026#34; placeholder=\u0026#34;{{ T \u0026#34;searchHolderTitle\u0026#34; }}\u0026#34;\u0026gt; \u0026lt;input aria-hidden=\u0026#34;true\u0026#34; id=\u0026#34;replyer\u0026#34; class=\u0026#34;hidden\u0026#34;\u0026gt; {{- $baseURL := site.BaseURL | absLangURL -}} {{- $feed := urls.JoinPath $baseURL \u0026#34;/feed.json\u0026#34; | absLangURL -}} {{- with resources.Get $feed -}} \u0026lt;!-- Javascript --\u0026gt; \u0026lt;script\u0026gt; $(function() { var projects = [ {{- range .items -}} { value: \u0026#34;{{ safeHTML .title }}\u0026#34;, label: \u0026#34;{{ safeHTML .summary }}\u0026#34;, url:\u0026#34;{{ safeURL .url }}\u0026#34; }, {{- end -}} ]; $(\u0026#34;#search\u0026#34;).autocomplete({ minLength: 0, source: projects, focus: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); return false; }, select: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); $(\u0026#34;#replyer\u0026#34;).val( ui.item.value ); return false; } }) .data(\u0026#39;ui-autocomplete\u0026#39;)._renderItem = function(ul, item) { return $(\u0026#39;\u0026lt;li\u0026gt;\u0026#39;) .append(\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39; + item.url + \u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;+ item.label + \u0026#39;\u0026#34;\u0026gt;\u0026#39; + item.value + \u0026#39;\u0026lt;/a\u0026gt;\u0026#39; ) .appendTo(ul); }; }); \u0026lt;/script\u0026gt; {{- end -}} \u0026lt;/div\u0026gt; Voila!\nError Q : When you use Hugo into its environment development, it made severals errors, and stop, as: ERROR 2020/08/27 08:16:41 Failed to get JSON resource “http://localhost:1313/fr/feed.json”: Get “http://localhost:1313/fr/feed.json”: dial tcp [::1]:1313: connect: connection refused\nA : The server is not able to call a data not builded.\nDocumentations Hugo Documentation: Tools \u0026gt; Search Hugo getJSON function: Hugo Documentation: Templates \u0026gt; Data templates JQuery UI autocomplete() method: https://jqueryui.com/autocomplete ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eFew months ago, I wrote this first article to build a \u0026lsquo;build-in\u0026rsquo; base search engine, with JQueryUI \u003ccode\u003eautocomplete()\u003c/code\u003e. (See \u003ca href=\"/en/web/hugo/hugo-search/\"\u003eHugo search\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eOn this blog, Hugo generates one feed at the JSON format, named \u003cstrong\u003efeed.json\u003c/strong\u003e, \u003cem\u003eavailable on the homepage\u003c/em\u003e. And, Hugo has a native function \u003ccode\u003egetJSON\u003c/code\u003e…\u003c/p\u003e\n\u003cp\u003eLet\u0026rsquo;s go back to the code !\u003c/p\u003e\n\u003ch2 id=\"code\"\u003eCode\u003c/h2\u003e\n\u003ch3 id=\"hugo\"\u003eHugo\u003c/h3\u003e\n\u003cp\u003eFirstly, I write a \u003ccode\u003e$feed\u003c/code\u003e variable; her value is the absolute path for the file \u003cstrong\u003efeed.json\u003c/strong\u003e.\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-hugo\" data-lang=\"hugo\"\u003e{{- $baseURL := site.BaseURL | absLangURL -}}\n{{- $feed :=  urls.JoinPath $baseURL \u0026#34;/feed.json\u0026#34; | absLangURL -}}\n\u003c/code\u003e\u003c/pre\u003e\u003ch3 id=\"jquery\"\u003eJQuery\u003c/h3\u003e\n\u003cp\u003eJQuery code is quasi the same: except this difference, Hugo\u0026rsquo;s \u003ccode\u003erange\u003c/code\u003e function will directly call the content returned by the \u003ccode\u003egetJSON\u003c/code\u003e function.\u003c/p\u003e\n\u003cp\u003eThe code:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-js\" data-lang=\"js\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003ewith\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eresources\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eGet\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$feed\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e\u0026lt;!--\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eJavascript\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e--\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003escript\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e() {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003evar\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erange\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eitems\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeHTML .title }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeHTML .summary }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeURL .url }}\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eautocomplete\u003c/span\u003e({\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eminLength\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003esource\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003efocus\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eselect\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#replyer\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    })\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    .\u003cspan style=\"color:#06b6ef\"\u003edata\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;ui-autocomplete\u0026#39;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003e_renderItem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;li\u0026gt;\u0026#39;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappend\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34;\u0026gt;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;/a\u0026gt;\u0026#39;\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappendTo\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    };\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e});\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e/script\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"html\"\u003eHTML\u003c/h3\u003e\n\u003cp\u003eMake HTML is always so simple:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;form-control\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eplaceholder\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003esearchHolderTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003earia-hidden\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;true\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;replyer\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;hidden\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"tldr\"\u003eTL;DR\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;form-control\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eplaceholder\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003esearchHolderTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003earia-hidden\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;true\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;replyer\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;hidden\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {{- $baseURL := site.BaseURL | absLangURL -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {{- $feed :=  urls.JoinPath $baseURL \u0026#34;/feed.json\u0026#34; | absLangURL -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {{- with resources.Get $feed -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e\u0026lt;!-- Javascript --\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003escript\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e() {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003evar\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erange\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eitems\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeHTML .title }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeHTML .summary }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ safeURL .url }}\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        ];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eautocomplete\u003c/span\u003e({\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eminLength\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003esource\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003efocus\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eselect\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#replyer\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    })\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    .\u003cspan style=\"color:#06b6ef\"\u003edata\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;ui-autocomplete\u0026#39;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003e_renderItem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;li\u0026gt;\u0026#39;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappend\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34;\u0026gt;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;/a\u0026gt;\u0026#39;\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappendTo\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    };\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e});\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003escript\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {{- end -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003ch3 id=\"error\"\u003eError\u003c/h3\u003e\n\u003cp\u003e\u003cabbr title=\"Question\"\u003eQ\u003c/abbr\u003e\n: When you use Hugo into its environment development,\nit made severals errors, and stop, as: \u003cbr\u003e\n\u003ccode\u003eERROR 2020/08/27 08:16:41 Failed to get JSON resource “http://localhost:1313/fr/feed.json”: Get “http://localhost:1313/fr/feed.json”: dial tcp [::1]:1313: connect: connection refused\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003e\u003cabbr title=\"Answer\"\u003eA\u003c/abbr\u003e\n: The server is not able to call a data not builded.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/tools/search/\" title=\"Link to the official site Hugo: Tools \u0026gt; Search\"\u003eHugo Documentation: Tools \u0026gt; Search\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eHugo \u003ccode\u003egetJSON\u003c/code\u003e function: \u003ca href=\"https://gohugo.io/templates/data-templates/#load-local-files\" title=\"Link to the official site Hugo: Templates \u0026gt; Data templates\"\u003eHugo Documentation: Templates \u0026gt; Data templates\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eJQuery UI \u003ccode\u003eautocomplete()\u003c/code\u003e method: \u003ca href=\"https://jqueryui.com/autocomplete\" rel=\"external\"\u003ehttps://jqueryui.com/autocomplete\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Using the JSON feed to integrate a 'search engine' in Hugo, with JQuery UI autocomplete()","tags":["Hugo","search","JQuery","JSON"],"date_published":"2020-08-25T23:32:48+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-05-28:/en/web/httpd/httpd-deliver-compressed-files","url":"https://it-log.fr.eu.org/en/web/httpd/httpd-delivers-compressed-files/","title":"httpd: deliver compressed static files (+slowcgi)","author":{"name":"Stéphane HUC"},"content_text":"Description OpenBSD has, by default, in basesystem:\na webserver, named httpd, since 5.7\na server CGI, named slowcgi, since 5.4\nOpenBSD : 6.6, 6.7\nPrinciple: if web client accepts datas compression in the deflate, gzip, brotli format, then httpd redirects to slowcgi to deliver the compressed static content.\nWarningThis is not means compression dynamicly, or \u0026ldquo;compression on the fly!\u0026rdquo; httpd is not able to manage delivery about compressed static content.\nThe tip is to use the server slowcgi CGI for.\nIn facts, by CGI script shell, we\u0026rsquo;ll assume the delivery of those compressed static content:\nfor the format: atom, css, html, js, json, svg, txt, xml to both compression: gzip, and brotli. Installation You do to download my script sbw.cgi.\nWhen it\u0026rsquo;s done, you need to put into the cgi-bin folder on web chroot. For this, use the command install as: :# install -o www -g bin -m 0550 sbw.cgi /var/www/cgi-bin/sbw.cgi\nIndeed, we install correctly with minimals/needed rights to the web user www and the group bin.\nDependencies This script need the installation in the web chroot of several binaries and some libraries, to run correctly:\nCopy from:\nfirst: sh, and binaries: cat, date and sha256 — which are all in the /bin system directory. all others binaries: basename, logger 1 , stat - which are all in the /usr/bin system directory. the shared libc: /usr/lib/libc.so.xx.0 2 the library to execution: /usr/libexec/ld.so to the respective folders into web chroot /var/www/.\nAll need root user and bin group rights:\nwith 0555 mode for the binaries, e.g.: sh:\n:# install -o root -g bin -m 0555 /bin/sh /var/www/bin/ stat:\n:# iinstall -o root -g bin -m 0555 /usr/bin/stat /var/www/usr/bin/ and 0444 mode for the libraries, as: libc:\n:# iinstall -o root -g bin -m 0444 /usr/lib/libc.so.xx.0 /var/www/usr/lib/ ld.so:\n:# iinstall -o root -g bin -m 0444 /usr/libexec/ld.so /var/www/usr/libexec/ Before, you need to create the corresponding directories in the web chroot!\nSee my dependencies script.\n1 about the interest of the binary logger: Normaly, ideally, we don\u0026rsquo;t need the logger. It is about logging some actions, which in case of failure, have written in the logs /var/log/{daemon,messages}.\nAlso, if the debug variable is set to 1, on the main function, then the logger will return the values corresponding to the different variables, for analysis: ensure that variable receive one value, and what value‽\n2 The libc.so change name, at each version of OpenBSD:\nv6.7 : libc.so.96.0 v6.6 : libc.so.95.1 This detail is important, can be hardly scripted. You need to modify the script, at the new version of OpenBSD, to change the name of the library, otherwise, it will not work!\nTipTo known, what are the dependencies from a binary, use the command ldd. Configuration httpd Add at your context server, all following needed location statements:\nlocation \u0026#34;/*.atom\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.css\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.html\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.js\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.json\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.svg\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.txt\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } location \u0026#34;/*.xml\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; } The file sbw.conf contains the following fastcgi statements:\nroot \u0026#34;/cgi-bin/sbw.cgi\u0026#34; fastcgi param realroot \u0026#34;/htdocs/domaine.tld/www\u0026#34; fastcgi param cachecontrol \u0026#34;1814400\u0026#34; fastcgi param file404 \u0026#34;/404.html\u0026#34; Explainations :\nIt\u0026rsquo;s important to define, at least:\nroot: the relative path of script CGI, into the web chroot. realroot: a parameter for your web root and optionals paramaters, specially of the cache. slowcgi The server slowcgi does not require any configuration. Only, you enable and start with the tool rcctl.\nHistory Vulnerabilities In fact, the story of the HTTP (HyperText Transfer Protocol) protocol reveals us two majors vulnerabilities related to the on-the-fly compression: CRIME and BREACH — the second is forked on the first. Thoses vulnerabilities can even impact TLS (Transport Layer Secure) .\nAmong the countermeasures has been the adoption since HTTP 1.1 of block encoding transfer — the famous Transfer-Encoding: chunked header; similarly, it is strongly recommended to implement a Referrer policy to allow delivery of compressed content ONLY from the current domain, and to refuse it from any other domain.\nabout httpd Reyk Floeter, the httpd author/developer, denies support for the compressed content. Even, one request had be done to support pre-compressed content, it\u0026rsquo;s not ready to be integrated.\nbrotli brotli is a compression format invented by a team from the company Google. It is considered to be the successor to gzip because it is faster and has a better compression ratio.\nFor more informations, see:\nhttps://brotli.org/ Does your web client support it: https://caniuse.com/#search=brotli curl, since v7.57.0, support brotli, by adding the option --compressed, or -H — this manage finely HTTP headers. (see the manpage)*\nunsupported clients On OpenBSD, curl seems not supported brotli. Egual, on all OS, lynx, w3m does not support it. Firefox Since v64, Firefox does not support Atom or RSS feed.\nActually, it\u0026rsquo;s more subtle than it sounds:\nif you deliver Atom or RSS with mime type text/xml, both are XML files, Firefox accepts to read and native display. if you deliver it with their mime type, respectively application/atom+xml and application/rss+xml, a RFC standard, then Firefox ask you what to do with. \u0026ldquo;A nameless aberration!!!\u0026rdquo;\nthe little story For the little story, Xavier Cartron @prx is the original author of this genious idea to deliver compressed static content, by adding the header ETag. This is an id for the delivered ressource.\nIt is in this context, that the binary sha256 is useful.\nMy work, based on his first version, was to add several things:\nAbout brotli, so I resumed/continued writing in order to be able to deliver static content previously compressed with this format.\nNext, I added code to manage others needed headers:\nContent-Length: to send weight of delivered document. It is in this context, that the binary stat is useful. Last-Modified: to get the modification date of the delivered document; someone considers this header is more relevant than ETag. It is in this context, that the binaries date and stat are useful. Transfer-Encoding: to send the delivered document with the good compression format, if necessary. Then, I wrote the necessary code to detect if the useful dependencies were in the web chroot, otherwise the script can\u0026rsquo;t work. If it\u0026rsquo;s the case, the serveur send an error 500, with an explicit HTML message.\nATTENTION: the script not installs and can not install the dependancies; because, it on the web chroot, it can not \u0026ldquo;view\u0026rdquo; the OS filesystem.\nNext, after some research on the web, I understant that the format deflate, that may be requested by some web clients, is managed by the format gzip; then, the script supports too.\nBut I was confronted with dysfunctions that I couldn\u0026rsquo;t understand, let alone solve. I stopped the project :(\nBut, two \u0026ldquo;things\u0026rdquo; helped seriously to continue:\nSolène Rapenne, from the OpenBSD team, helped to understand I was making the mistake of sending too many line breaks, when I need only one, at the right time, one between the sending of the different headers and the document itself, whether it is compressed or not. the idea to implement a variable debug and use the binary logger to ensure some differents returns. One tips that Solène gave me is the local use of this command:\nenv HTTP_ACCEPT_ENCODING=br realroot=/var/www/htdocs/domaine.tld/dev/ PATH_INFO=index.html /var/www/cgi-bin/sbw.cgi | less\nexplaining me that it is possible to query the CGI server locally directly, by sending it the different possible values before the call.\nAmazing! :D\nAbout this, since we installed the CGI shell script sbw.cgi with the user rights to 0550, we had this erreur: env: /var/www/cgi-bin/sbw2.cgi: Permission denied you need to change the other rights to +x (or, 0551). ;-)\nI improved the detection of the mime type by getting it from the file called on the filesystem — this need to use the binary basename - and the management of the mime type about feed Atom or RSS.\nFinally, I wrote the necessary code to detect if the user agent was Firefox:\nIf yes, to obtain his version number. A little hack to deliver feed Atom and RSS to the \u0026ldquo;false\u0026rdquo; mime-type text/xml. Also, Firefox accepts to read the feed instead asking to open with another application! I wrote the first draft of this hack requiring the addition of the binaries grep and awk — but, this functional solution did not satisfy me. When, an user on the forum about the french community \u0026ldquo;OpenBSD pour tous\u0026rdquo;, @eol makes me to think to use shell expansion.\n\u0026ldquo;Et, voilà!\u0026quot;\nActualy, @prx rewrote his script in C:\nthe advantage is that there is no need for any dependency; too, it\u0026rsquo;s \u0026ldquo;protected\u0026rdquo; by the system call security measures pledge(2) and unveil(2). however, it ONLY supports gzip compression; egual, no header Last-Modified, or brotli, and deflate support, at least not directly|automatically. Documentation For more documentation about referrer policy.\nmanpage install slowcgi(8) , rcctl(8) pledge(2) , unveil(2) Wikipédia About the BREACH vulnerability: https://en.wikipedia.org/wiki/BREACH and the CRIME exploit: https://en.wikipedia.org/wiki/CRIME_(security_exploit) ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenBSD\u003c/strong\u003e has, by default, in basesystem:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003ea webserver, named \u003cstrong\u003ehttpd\u003c/strong\u003e, since 5.7\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ea server CGI, named \u003cstrong\u003eslowcgi\u003c/strong\u003e, since 5.4\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOpenBSD : \u003cstrong\u003e6.6, 6.7\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003ePrinciple\u003c/strong\u003e: if web client accepts datas compression in the deflate, gzip,\nbrotli format, then \u003cstrong\u003ehttpd\u003c/strong\u003e redirects to \u003cstrong\u003eslowcgi\u003c/strong\u003e to deliver the\ncompressed static content.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eThis is not means compression dynamicly, or \u0026ldquo;compression on the fly!\u0026rdquo;\u003c/div\u003e\n\n\u003cp\u003e\u003cstrong\u003ehttpd\u003c/strong\u003e is not able to manage delivery about compressed static content.\u003c/p\u003e\n\u003cp\u003eThe tip is to use the server \u003cstrong\u003eslowcgi\u003c/strong\u003e CGI for.\u003c/p\u003e\n\u003cp\u003eIn facts, by CGI script shell, we\u0026rsquo;ll assume the delivery of those compressed\nstatic content:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efor the format: \u003cstrong\u003eatom\u003c/strong\u003e, \u003cstrong\u003ecss\u003c/strong\u003e, \u003cstrong\u003ehtml\u003c/strong\u003e, \u003cstrong\u003ejs\u003c/strong\u003e, \u003cstrong\u003ejson\u003c/strong\u003e, \u003cstrong\u003esvg\u003c/strong\u003e,\n\u003cstrong\u003etxt\u003c/strong\u003e, \u003cstrong\u003exml\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eto both compression: \u003cstrong\u003egzip\u003c/strong\u003e, and \u003cstrong\u003ebrotli\u003c/strong\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eYou do to \u003ca href=\"https://framagit.org/hucste/tools/-/raw/master/OpenBSD/slowcgi/sbw.cgi\" rel=\"external\"\u003edownload my script \u003cstrong\u003esbw.cgi\u003c/strong\u003e\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWhen it\u0026rsquo;s done, you need to put into the \u003ccode\u003ecgi-bin\u003c/code\u003e folder on web chroot.\nFor this, use the command \u003ccode\u003einstall\u003c/code\u003e as: \u003cbr\u003e\n\u003ccode\u003e:# install -o www -g bin -m 0550 sbw.cgi /var/www/cgi-bin/sbw.cgi\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIndeed, we install correctly with minimals/needed rights to the web user\n\u003ccode\u003ewww\u003c/code\u003e and the group \u003ccode\u003ebin\u003c/code\u003e.\u003c/p\u003e\n\u003ch3 id=\"dependencies\"\u003eDependencies\u003c/h3\u003e\n\u003cp\u003eThis script need the installation in the web chroot of several binaries\nand some libraries, to run correctly:\u003c/p\u003e\n\u003cp\u003eCopy from:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003efirst: \u003cstrong\u003esh\u003c/strong\u003e, and binaries: \u003cstrong\u003ecat\u003c/strong\u003e, \u003cstrong\u003edate\u003c/strong\u003e and \u003cstrong\u003esha256\u003c/strong\u003e —\n\u003cem\u003ewhich are all in the \u003ccode\u003e/bin\u003c/code\u003e system directory\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003eall others binaries: \u003cstrong\u003ebasename\u003c/strong\u003e, \u003cstrong\u003elogger\u003c/strong\u003e \u003csup\u003e\u003cspan class=\"orange\"\u003e1\u003c/span\u003e\n\u003c/sup\u003e,\n\u003cstrong\u003estat\u003c/strong\u003e - \u003cem\u003ewhich are all in the \u003ccode\u003e/usr/bin\u003c/code\u003e system directory\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003ethe shared libc: \u003ccode\u003e/usr/lib/libc.so.xx.0\u003c/code\u003e \u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e\u003c/li\u003e\n\u003cli\u003ethe library to execution: \u003ccode\u003e/usr/libexec/ld.so\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eto the respective folders into web chroot \u003ccode\u003e/var/www/\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAll need \u003ccode\u003eroot\u003c/code\u003e user and \u003ccode\u003ebin\u003c/code\u003e group rights:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ewith 0555 mode for the binaries, e.g.:\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003esh\u003c/strong\u003e:\u003cbr\u003e\n\u003ccode\u003e:# install -o root -g bin -m 0555 /bin/sh /var/www/bin/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003estat\u003c/strong\u003e:\u003cbr\u003e\n\u003ccode\u003e:# iinstall -o root -g bin -m 0555 /usr/bin/stat /var/www/usr/bin/\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eand 0444 mode for the libraries, as:\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003elibc\u003c/strong\u003e:\u003cbr\u003e\n\u003ccode\u003e:# iinstall -o root -g bin -m 0444 /usr/lib/libc.so.xx.0 /var/www/usr/lib/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eld.so\u003c/strong\u003e:\u003cbr\u003e\n\u003ccode\u003e:# iinstall -o root -g bin -m 0444 /usr/libexec/ld.so /var/www/usr/libexec/\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBefore, you need to create the corresponding directories in the web chroot!\u003c/p\u003e\n\u003cp\u003eSee my \u003ca href=\"https://framagit.org/hucste/tools/-/blob/master/OpenBSD/chroot_deps\" rel=\"external\"\u003edependencies script\u003c/a\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003csup\u003e\u003cspan class=\"orange\"\u003e1\u003c/span\u003e\n\u003c/sup\u003e about the interest of the binary \u003ccode\u003elogger\u003c/code\u003e:\nNormaly, ideally, we don\u0026rsquo;t need the logger. It is about logging some actions,\nwhich in case of failure, have written in the logs \u003ccode\u003e/var/log/{daemon,messages}\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eAlso, if the \u003ccode\u003edebug\u003c/code\u003e variable is set to \u003ccode\u003e1\u003c/code\u003e, on the main function, then\nthe logger will return the values corresponding to the different variables,\nfor analysis: ensure that variable receive one value, and what value‽\u003c/p\u003e\n\u003cp\u003e\u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e The \u003cstrong\u003elibc.so\u003c/strong\u003e change name,\nat each version of OpenBSD:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ev6.7 : \u003ccode\u003elibc.so.96.0\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ev6.6 : \u003ccode\u003elibc.so.95.1\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis detail is important, can be hardly scripted. You need to modify the\nscript, at the new version of OpenBSD, to change the name of the library,\notherwise, it will not work!\u003c/p\u003e\n\u003chr\u003e\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eTo known, what are the dependencies from a binary, use the command \u003ccode\u003eldd\u003c/code\u003e.\u003c/div\u003e\n\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"httpd\"\u003ehttpd\u003c/h3\u003e\n\u003cp\u003eAdd at your context \u003ccode\u003eserver\u003c/code\u003e, all following needed \u003ccode\u003elocation\u003c/code\u003e statements:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-httpd\" data-lang=\"httpd\"\u003elocation \u0026#34;/*.atom\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.css\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.html\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.js\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.json\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.svg\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.txt\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\nlocation \u0026#34;/*.xml\u0026#34; { include \u0026#34;/etc/httpd.d/sbw.conf\u0026#34; }\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThe file \u003ccode\u003esbw.conf\u003c/code\u003e contains the following \u003ccode\u003efastcgi\u003c/code\u003e statements:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eroot \u0026#34;/cgi-bin/sbw.cgi\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efastcgi param realroot \u0026#34;/htdocs/domaine.tld/www\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efastcgi param cachecontrol \u0026#34;1814400\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003efastcgi param file404 \u0026#34;/404.html\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e :\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s important to define, at least:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eroot\u003c/strong\u003e: the relative path of script CGI, into the web chroot.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003erealroot\u003c/strong\u003e: a parameter for your web root\u003c/li\u003e\n\u003cli\u003eand optionals paramaters, specially of the cache.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"slowcgi\"\u003eslowcgi\u003c/h3\u003e\n\u003cp\u003eThe server \u003cstrong\u003eslowcgi\u003c/strong\u003e does not require any configuration. Only, you enable\nand start with the tool \u003ccode\u003ercctl\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"history\"\u003eHistory\u003c/h2\u003e\n\u003ch3 id=\"vulnerabilities\"\u003eVulnerabilities\u003c/h3\u003e\n\u003cp\u003eIn fact, the story of the \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eHTTP \u003cem\u003e(HyperText Transfer Protocol)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n protocol\nreveals us two majors vulnerabilities related to the on-the-fly compression:\n\u003cstrong\u003eCRIME\u003c/strong\u003e and \u003cstrong\u003eBREACH\u003c/strong\u003e — \u003cem\u003ethe second is forked on the first\u003c/em\u003e. \u003cbr\u003e\nThoses vulnerabilities can even impact \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eTLS \u003cem\u003e(Transport Layer Secure)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n.\u003c/p\u003e\n\u003cp\u003eAmong the countermeasures has been the adoption since \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"HyperText Transfer Protocol\"\u003eHTTP\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n 1.1 of\nblock encoding transfer — \u003cem\u003ethe famous \u003ccode\u003eTransfer-Encoding: chunked\u003c/code\u003e header\u003c/em\u003e;\nsimilarly, it is strongly recommended to implement a \u003cstrong\u003eReferrer\u003c/strong\u003e policy\nto allow delivery of compressed content ONLY from the current domain,\nand to refuse it from any other domain.\u003c/p\u003e\n\u003ch3 id=\"about-httpd\"\u003eabout httpd\u003c/h3\u003e\n\u003cp\u003eReyk Floeter, the httpd author/developer, \u003ca href=\"https://github.com/reyk/httpd/issues/21\" rel=\"external\"\u003edenies support for the compressed\ncontent\u003c/a\u003e. Even, one \u003ca href=\"https://github.com/reyk/httpd/issues/80\" rel=\"external\"\u003erequest\u003c/a\u003e had be done to support pre-compressed\ncontent, it\u0026rsquo;s not ready to be integrated.\u003c/p\u003e\n\u003ch3 id=\"brotli\"\u003ebrotli\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003ebrotli\u003c/strong\u003e is a compression format invented by a team from the company Google.\nIt is considered to be the successor to gzip because it is faster and has\na better compression ratio.\u003c/p\u003e\n\u003cp\u003eFor more informations, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://brotli.org/\" rel=\"external\"\u003ehttps://brotli.org/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDoes your web client support it: \u003ca href=\"https://caniuse.com/#search=brotli\" rel=\"external\"\u003ehttps://caniuse.com/#search=brotli\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003ecurl\u003c/strong\u003e, since v7.57.0, support brotli, by adding the option \u003ccode\u003e--compressed\u003c/code\u003e,\nor \u003ccode\u003e-H\u003c/code\u003e — \u003cem\u003ethis manage finely HTTP headers\u003c/em\u003e. (see the \u003ca href=\"https://curl.haxx.se/docs/manpage.html\" rel=\"external\"\u003emanpage\u003c/a\u003e)*\u003c/p\u003e\n\u003ch4 id=\"unsupported-clients\"\u003eunsupported clients\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eOn OpenBSD, \u003cstrong\u003ecurl\u003c/strong\u003e seems not supported brotli.\u003c/li\u003e\n\u003cli\u003eEgual, on all OS, \u003cstrong\u003elynx\u003c/strong\u003e, \u003cstrong\u003ew3m\u003c/strong\u003e does not support it.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"firefox\"\u003eFirefox\u003c/h3\u003e\n\u003cp\u003eSince v64, \u003ca href=\"https://support.mozilla.org/en-US/kb/feed-reader-replacements-firefox\" rel=\"external\"\u003eFirefox does not support Atom or RSS feed\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eActually, it\u0026rsquo;s more subtle than it sounds:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eif you deliver Atom or RSS with mime type \u003cstrong\u003etext/xml\u003c/strong\u003e, both are XML files,\nFirefox accepts to read and native display.\u003c/li\u003e\n\u003cli\u003eif you deliver it with their mime type, respectively \u003cstrong\u003eapplication/atom+xml\u003c/strong\u003e\nand \u003cstrong\u003eapplication/rss+xml\u003c/strong\u003e, a RFC standard, then Firefox ask you what\nto do with.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u0026ldquo;A nameless aberration!!!\u0026rdquo;\u003c/p\u003e\n\u003ch3 id=\"the-little-story\"\u003ethe little story\u003c/h3\u003e\n\u003cp\u003eFor the little story, Xavier Cartron @prx is the original author of this\ngenious idea to deliver compressed static content, by adding the header\n\u003ccode\u003eETag\u003c/code\u003e. \u003cem\u003eThis is an id for the delivered ressource\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eIt is in this context, that the binary \u003cstrong\u003esha256\u003c/strong\u003e is useful.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eMy work, based on his first version, was to add several things:\u003c/p\u003e\n\u003cp\u003eAbout \u003ca href=\"/en/web/httpd/httpd-delivers-compressed-files/#brotli\"\u003ebrotli\u003c/a\u003e, so I resumed/continued writing in order to be able to\ndeliver static content previously compressed with this format.\u003c/p\u003e\n\u003cp\u003eNext, I added code to manage others needed headers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eContent-Length\u003c/code\u003e: to send weight of delivered document. \u003cbr\u003e\n\u003cem\u003eIt is in this context, that the binary \u003cstrong\u003estat\u003c/strong\u003e is useful\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eLast-Modified\u003c/code\u003e: to get the modification date of the delivered document;\nsomeone considers this header is more relevant than \u003cstrong\u003eETag\u003c/strong\u003e. \u003cbr\u003e\n\u003cem\u003eIt is in this context, that the binaries \u003cstrong\u003edate\u003c/strong\u003e and \u003cstrong\u003estat\u003c/strong\u003e are useful\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTransfer-Encoding\u003c/code\u003e: to send the delivered document with the good compression\nformat, if necessary.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThen, I wrote the necessary code to detect if the useful dependencies were\nin the web chroot, otherwise the script can\u0026rsquo;t work. If it\u0026rsquo;s the case, the\nserveur send an error 500, with an explicit HTML message.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eATTENTION\u003c/strong\u003e: the script not installs and can not install the dependancies;\nbecause, it on the web chroot, it can not \u0026ldquo;view\u0026rdquo; the OS filesystem.\u003c/p\u003e\n\u003cp\u003eNext, after some research on the web, I understant that the format \u003cstrong\u003edeflate\u003c/strong\u003e,\nthat may be requested by some web clients, is managed by the format \u003cstrong\u003egzip\u003c/strong\u003e;\nthen, the script supports too.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eBut I was confronted with dysfunctions that I couldn\u0026rsquo;t understand, let alone solve.\n\u003cem\u003eI stopped the project\u003c/em\u003e :(\u003c/p\u003e\n\u003cp\u003eBut, two \u0026ldquo;things\u0026rdquo; helped seriously to continue:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSolène Rapenne, from the OpenBSD team, helped to understand I was making\nthe mistake of sending too many line breaks, when I need only one,\nat the right time, one between the sending of the different headers\nand the document itself, whether it is compressed or not.\u003c/li\u003e\n\u003cli\u003ethe idea to implement a variable \u003ccode\u003edebug\u003c/code\u003e and use the binary \u003ccode\u003elogger\u003c/code\u003e to\nensure some differents returns.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOne tips that Solène gave me is the local use of this command:\u003cbr\u003e\n\u003ccode\u003eenv HTTP_ACCEPT_ENCODING=br realroot=/var/www/htdocs/domaine.tld/dev/ PATH_INFO=index.html /var/www/cgi-bin/sbw.cgi | less\u003c/code\u003e\u003cbr\u003e\nexplaining me that it is possible to query the CGI server locally directly,\nby sending it the different possible values before the call.\u003cbr\u003e\nAmazing! :D\u003c/p\u003e\n\u003cp\u003eAbout this, since we installed the CGI shell script \u003cstrong\u003esbw.cgi\u003c/strong\u003e with the\nuser rights to \u003cstrong\u003e0550\u003c/strong\u003e, we had this erreur: \u003cbr\u003e\n\u003ccode\u003eenv: /var/www/cgi-bin/sbw2.cgi: Permission denied\u003c/code\u003e \u003cbr\u003e\nyou need to change the other rights to \u003ccode\u003e+x\u003c/code\u003e \u003cem\u003e(or, \u003ccode\u003e0551\u003c/code\u003e)\u003c/em\u003e. ;-)\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eI improved the detection of the mime type by getting it from the file\ncalled on the filesystem — \u003cem\u003ethis need to use the binary \u003cstrong\u003ebasename\u003c/strong\u003e\u003c/em\u003e -\nand the management of the mime type about feed Atom or RSS.\u003c/p\u003e\n\u003cp\u003eFinally, I wrote the necessary code to detect if the user agent was\n\u003ca href=\"/en/web/httpd/httpd-delivers-compressed-files/#firefox\"\u003eFirefox\u003c/a\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIf yes, to obtain his version number. A little hack to deliver feed Atom\nand RSS to the \u0026ldquo;false\u0026rdquo; mime-type \u003cstrong\u003etext/xml\u003c/strong\u003e. Also, Firefox accepts\nto read the feed instead asking to open with another application!\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eI wrote the first draft of this hack requiring the addition of the binaries\n\u003ccode\u003egrep\u003c/code\u003e and \u003ccode\u003eawk\u003c/code\u003e — \u003cem\u003ebut, this functional solution did not satisfy me\u003c/em\u003e.\nWhen, an user on the forum about the french community \u0026ldquo;OpenBSD pour tous\u0026rdquo;,\n@eol makes me to think to use shell expansion.\u003c/p\u003e\n\u003cp\u003e\u003cspan lang=\"fr\"\u003e\u0026ldquo;Et, voilà!\u0026quot;\u003c/span\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eActualy, @prx rewrote his script in C:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe advantage is that there is no need for any dependency; too, it\u0026rsquo;s\n\u0026ldquo;protected\u0026rdquo; by the system call security measures pledge(2) and unveil(2).\u003c/li\u003e\n\u003cli\u003ehowever, it ONLY supports gzip compression; egual, no header \u003cstrong\u003eLast-Modified\u003c/strong\u003e,\nor brotli, and deflate support, at least not directly|automatically.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cp\u003eFor more documentation about \u003ca href=\"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referrer-Policy\" rel=\"external\"\u003ereferrer policy\u003c/a\u003e.\u003c/p\u003e\n\u003ch3 id=\"manpage\"\u003emanpage\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/install\" title=\"OpenBSD Manual Page Server for: install\"\u003einstall\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/slowcgi.8\" title=\"OpenBSD Manual Page Server for: slowcgi\"\u003eslowcgi(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/rcctl.8\" title=\"OpenBSD Manual Page Server for: rcctl\"\u003ercctl(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/pledge.2\" title=\"OpenBSD Manual Page Server for: pledge\"\u003epledge(2)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/unveil.2\" title=\"OpenBSD Manual Page Server for: unveil\"\u003eunveil(2)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"wikipédia\"\u003eWikipédia\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAbout the \u003cstrong\u003eBREACH\u003c/strong\u003e vulnerability: \u003ca href=\"https://en.wikipedia.org/wiki/BREACH\" rel=\"external\"\u003ehttps://en.wikipedia.org/wiki/BREACH\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eand the \u003cstrong\u003eCRIME\u003c/strong\u003e exploit: \u003ca href=\"https://en.wikipedia.org/wiki/CRIME_(security_exploit)\" rel=\"external\"\u003ehttps://en.wikipedia.org/wiki/CRIME_(security_exploit)\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"To deliver compressed static content (in the deflate, gzip, brotli format) by httpd+slowcgi, natives servers on OpenBSD","tags":["httpd","slowcgi","OpenBSD","CGI","deflate","gzip","brotli"],"date_published":"2020-05-28T20:00:11+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-05-17:/en/web/httpd/relayd-log","url":"https://it-log.fr.eu.org/en/web/httpd/relayd-log/","title":"Relayd: Log","author":{"name":"Stéphane HUC"},"content_text":"Description OpenBSD has, by default, in basesystem, since 5.7, the relay server named relayd.\nWebsite: https://bsd.plumbing/\nOpenBSD: 6.6, 6.7\nThe purpose of this article is to learn how to set up a logging of the HTTP(S) stream that passes through relayd.\nSo very simple!\nConfiguration File configuration is: /etc/relayd.conf Global Configuration In first, we need to declare the global parameter log into the file config. relayd.conf(5)#log Explainations\nThe following log declarations are those signification:\nlog state changes and log host checks are useful to follow the state of the host or the checks. Those states can be of type: up: if state is positive down: if the host is down, or the checks are not good. unknown: if the host is disable or not yet controled. log connection: to log all the traffic TCP, only if relayd act as relay. 1 .\nNote: the option errors is useful when we will log only if TCP connections send errors. 1 In fact, relayd can be configured too as a router, or redirection server.\nFilters rules Relays are able to filter the connections by adding specific filters parameters.\nWe will use the action match on which we apply the logging option log. relayd.conf(5)#match This corresponding action will apply on:\ncookie: an action on a cookie. 2 relayd.conf(5)#cookie header: to target an HTTP header. relayd.conf(5)#header path: to scan the asked URL. 2 relayd.conf(5)#path query: to analyse the URL queries. 2 relayd.conf(5)#query url: to get complete URL. 2 relayd.conf(5)#url 2 only available on HTTP request.\nConfiguration: example The follow exampe show us five filters rules:\nthe first four on the matching header the last log the complete URL ### ips externe auth ip4 = \u0026#34;addresse-ipv4-public\u0026#34; ### manage logs log state changes log connection #log connection errors http protocol \u0026#34;hw\u0026#34; { match header log \u0026#34;Host\u0026#34; match header log \u0026#34;X-Forwarded-For\u0026#34; match header log \u0026#34;User-Agent\u0026#34; match header log \u0026#34;Referer\u0026#34; match url log block (…) } relay \u0026#34;www\u0026#34; { listen on $ip4 port 80 protocol hw forward to 127.0.0.1 port 80 } Logs All logs are visibles into:\n/var/log/daemon, /var/log/message. log daemon: example $ grep relayd /var/log/daemon May 17 16:37:21 sh1 relayd[25237]: relay www, session 13 (2 active), 0, 192.168.1.1 -\u0026gt; :80, done May 17 16:37:21 sh1 relayd[45869]: relay www, session 7 (2 active), 0, 192.168.1.1 -\u0026gt; :80, done May 17 16:37:21 sh1 relayd[45869]: relay www, session 8 (1 active), 0, 192.168.1.1 -\u0026gt; :80, done May 17 16:37:22 sh1 relayd[25237]: relay www, session 14 (1 active), 0, 192.168.1.1 -\u0026gt; :80, done May 17 17:01:19 sh1 relayd[45869]: relay www, session 9 (1 active), 0, 207.180.140.98 -\u0026gt; :80, Forbidden (403 Forbidden), [\u0026lt;em\u0026gt;Stop scanning for PHP: none\u0026lt;/em\u0026gt;!, User-Agent: polaris] GET: Invalid argument May 17 17:01:19 sh1 relayd[45869]: relay www, session 10 (1 active), 0, 207.180.140.98 -\u0026gt; :80, done May 17 17:02:43 sh1 relayd[7531]: relay www, session 13 (1 active), 0, 84.161.80.36 -\u0026gt; :80, Forbidden (403 Forbidden), [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, Host: 88.136.16.221] [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36] [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, 88.136.16.221/phpmyadmin/] GET: Invalid argument Into this example, we have:\ndone connections failed connections, error 403, bloqued by filters rule block log message: example $ grep relayd /var/log/messages May 17 16:22:23 sh1 relayd[7531]: relay www, session 11 (1 active), 0, 37.49.230.25 -\u0026gt; :80, Forbidden (403 Forbidden), [\u0026lt;em\u0026gt;Stop scanning for PHP: none\u0026lt;/em\u0026gt;!, User-Agent: Uirusu/2.0] GET: Invalid argument May 17 17:01:19 sh1 relayd[45869]: relay www, session 9 (1 active), 0, 207.180.140.98 -\u0026gt; :80, Forbidden (403 Forbidden), [\u0026lt;em\u0026gt;Stop scanning for PHP: none\u0026lt;/em\u0026gt;!, User-Agent: polaris] GET: Invalid argument May 17 17:02:43 sh1 relayd[7531]: relay www, session 13 (1 active), 0, 84.161.80.36 -\u0026gt; :80, Forbidden (403 Forbidden), [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, Host: 88.136.16.221] [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36] [\u0026lt;em\u0026gt;Stop scanning for an admin interface: none\u0026lt;/em\u0026gt;!, 88.136.16.221/phpmyadmin/] GET: Invalid argument In this other example, we see 3 writing about bloqued rules, with error 403.\nDocumentations Manpages relayd.conf(5) ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenBSD\u003c/strong\u003e has, by default, in basesystem, since 5.7, the relay server\nnamed \u003cstrong\u003erelayd\u003c/strong\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eWebsite: \u003ca href=\"https://bsd.plumbing/\" rel=\"external\"\u003ehttps://bsd.plumbing/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOpenBSD: \u003cstrong\u003e6.6, 6.7\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eThe purpose of this article is to learn how to set up a logging of the\nHTTP(S) stream that passes through \u003cstrong\u003erelayd\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003eSo very simple!\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFile configuration is: \u003ccode\u003e/etc/relayd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"global-configuration\"\u003eGlobal Configuration\u003c/h3\u003e\n\u003cp\u003eIn first, we need to declare the global parameter \u003ccode\u003elog\u003c/code\u003e into the file config.\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#log\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#log\u003c/a\u003e\n\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe following log declarations are those signification:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elog state changes\u003c/code\u003e and \u003ccode\u003elog host checks\u003c/code\u003e are useful to follow the state\nof the host or the checks. Those states can be of type:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eup\u003c/code\u003e: if state is positive\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edown\u003c/code\u003e: if the host is down, or the checks are not good.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eunknown\u003c/code\u003e: if the host is disable or not yet controled.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elog connection\u003c/code\u003e: to log all the traffic TCP, only \u003cstrong\u003eif relayd act as\nrelay\u003c/strong\u003e. \u003csup\u003e\u003cspan class=\"orange\"\u003e1\u003c/span\u003e\n\u003c/sup\u003e.\u003cbr\u003e\nNote:  the option \u003ccode\u003eerrors\u003c/code\u003e is useful when we will log only if TCP connections\nsend errors.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003csup\u003e\u003cspan class=\"orange\"\u003e1\u003c/span\u003e\n\u003c/sup\u003e \u003cem\u003eIn fact, \u003cstrong\u003erelayd\u003c/strong\u003e can be\nconfigured too as a router, or redirection server\u003c/em\u003e.\u003c/p\u003e\n\u003ch3 id=\"filters-rules\"\u003eFilters rules\u003c/h3\u003e\n\u003cp\u003eRelays are able to filter the connections by adding specific filters parameters.\u003c/p\u003e\n\u003cp\u003eWe will use the action \u003ccode\u003ematch\u003c/code\u003e on which we apply the logging option \u003ccode\u003elog\u003c/code\u003e.\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#match\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#match\u003c/a\u003e\n\u003c/em\u003e\u003cbr\u003e\nThis corresponding action will apply on:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecookie\u003c/code\u003e: an action on a cookie. \u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#cookie\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#cookie\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eheader\u003c/code\u003e: to target an HTTP header.\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#header\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#header\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epath\u003c/code\u003e: to scan the asked URL. \u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#path\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#path\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003equery\u003c/code\u003e: to analyse the URL queries. \u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#query\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#query\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eurl\u003c/code\u003e: to get complete URL. \u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/relayd.conf.5#url\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)#url\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003csup\u003e\u003cspan class=\"orange\"\u003e2\u003c/span\u003e\n\u003c/sup\u003e \u003cem\u003eonly available on HTTP request.\u003c/em\u003e\u003c/p\u003e\n\u003ch3 id=\"configuration-example\"\u003eConfiguration: example\u003c/h3\u003e\n\u003cp\u003eThe follow exampe show us five filters rules:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe first four on the matching header\u003c/li\u003e\n\u003cli\u003ethe last log the complete URL\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### ips externe auth\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip4\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;addresse-ipv4-public\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### manage logs\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elog state changes\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elog connection\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#log connection errors\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ehttp protocol \u0026#34;hw\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch header log \u0026#34;Host\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch header log \u0026#34;X-Forwarded-For\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch header log \u0026#34;User-Agent\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch header log \u0026#34;Referer\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch url log\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eblock\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e(…)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003erelay \u0026#34;www\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003elisten on $ip4 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eprotocol hw\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward to 127.0.0.1 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"logs\"\u003eLogs\u003c/h2\u003e\n\u003cp\u003eAll logs are visibles into:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e/var/log/daemon\u003c/code\u003e,\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e/var/log/message\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"log-daemon-example\"\u003elog daemon: example\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ grep relayd /var/log/daemon\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 16:37:21 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e25237\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e13\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 192.168.1.1 -\u0026gt; :80, \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 16:37:21 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e45869\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 192.168.1.1 -\u0026gt; :80, \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 16:37:21 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e45869\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e8\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 192.168.1.1 -\u0026gt; :80, \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 16:37:22 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e25237\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e14\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 192.168.1.1 -\u0026gt; :80, \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 17:01:19 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e45869\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e9\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 207.180.140.98 -\u0026gt; :80, Forbidden \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e403\u003c/span\u003e Forbidden\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e PHP: none\u0026lt;/em\u0026gt;!, User-Agent: polaris\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e GET: Invalid argument\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 17:01:19 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e45869\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 207.180.140.98 -\u0026gt; :80, \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 17:02:43 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e7531\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e13\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 84.161.80.36 -\u0026gt; :80, Forbidden \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e403\u003c/span\u003e Forbidden\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, Host: 88.136.16.221\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, User-Agent: Mozilla/5.0 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eWindows NT 10.0; WOW64\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e AppleWebKit/537.36 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eKHTML, like Gecko\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e Chrome/51.0.2704.103 Safari/537.36\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, 88.136.16.221/phpmyadmin/\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e GET: Invalid argument\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eInto this example, we have:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edone connections\u003c/li\u003e\n\u003cli\u003efailed connections, error 403, bloqued by filters rule \u003ccode\u003eblock\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"log-message-example\"\u003elog message: example\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ grep relayd /var/log/messages\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 16:22:23 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e7531\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e11\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 37.49.230.25 -\u0026gt; :80, Forbidden \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e403\u003c/span\u003e Forbidden\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e PHP: none\u0026lt;/em\u0026gt;!, User-Agent: Uirusu/2.0\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e GET: Invalid argument\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 17:01:19 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e45869\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e9\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 207.180.140.98 -\u0026gt; :80, Forbidden \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e403\u003c/span\u003e Forbidden\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e PHP: none\u0026lt;/em\u0026gt;!, User-Agent: polaris\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e GET: Invalid argument\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMay \u003cspan style=\"color:#f99b15\"\u003e17\u003c/span\u003e 17:02:43 sh1 relayd\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e7531\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e: relay www, session \u003cspan style=\"color:#f99b15\"\u003e13\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e active\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, 0, 84.161.80.36 -\u0026gt; :80, Forbidden \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e403\u003c/span\u003e Forbidden\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, Host: 88.136.16.221\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, User-Agent: Mozilla/5.0 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eWindows NT 10.0; WOW64\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e AppleWebKit/537.36 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eKHTML, like Gecko\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e Chrome/51.0.2704.103 Safari/537.36\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;em\u0026gt;Stop scanning \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e an admin interface: none\u0026lt;/em\u0026gt;!, 88.136.16.221/phpmyadmin/\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e GET: Invalid argument\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIn this other example, we see 3 writing about bloqued rules, with error 403.\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/relayd.conf.5\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"How to log with relayd, relay server on OpenBSD","tags":["relayd","log","OpenBSD","astuce"],"date_published":"2020-05-17T13:09:05+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-05-07:/en/web/httpd/relayd-cache-httpd","url":"https://it-log.fr.eu.org/en/web/httpd/relayd-cache-httpd/","title":"Relayd: Web caching for httpd","author":{"name":"Stéphane HUC"},"content_text":"Description OpenBSD has, by default, in basesystem, since 5.7:\na webserver, named httpd,\nun server relay, named relayd\nWebsite: https://bsd.plumbing/\nOpenBSD: 6.6, 6.7\nhttpd is not able to manage delivery about cache static content.\nSo we pass the relay to the relayd server which is able to do it; so, it does in the global manner, not-domain specific.\nConfiguration We need to modify the httpd and relayd configuration, i.e.:\nrelayd will receive all traffic on web port and redirects to localhost on corresponding ports. Off course, il possible to act on both IPv4 and IPv6 protocols. httpd will query only the localhost on the dedicated ports. Do not forget to restart both daemons after modyfing the configuration.\nrelayd File configuration is: /etc/relayd.conf In the contexte of the http protocol:\nWe target all static files, by scanning all web requests: for the image GIF, JPEG, PNG, SVG for the CSS and JS files and others HTML and XML files (as Atom, RSS, Sitemap, etc.) we apply a tag policy, with the option tag. and finally, we send an header Cache-Control, labelled by the tag. Next, we apply the http protocol to a target relay.\nrelayd: example ip4 = \u0026#34;public-address-ipv4\u0026#34; http protocol \u0026#34;hw\u0026#34; { match request path \u0026#34;/*.atom\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.css\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.gif\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.html\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.ico\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.jpg\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.js\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.png\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.rss\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.svg\u0026#34; tag \u0026#34;CACHE\u0026#34; match request path \u0026#34;/*.xml\u0026#34; tag \u0026#34;CACHE\u0026#34; match response tagged \u0026#34;CACHE\u0026#34; header set \u0026#34;Cache-Control\u0026#34; value \u0026#34;public, max-age=86400\u0026#34; tcp { nodelay, sack, socket buffer 65536, backlog 100 } pass } relay \u0026#34;www\u0026#34; { listen on $ip4 port 80 protocol hw forward to 127.0.0.1 port 80 } Documentations Manpages httpd(8) , httpd.conf(5) ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenBSD\u003c/strong\u003e has, by default, in basesystem, since 5.7:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003ea webserver, named \u003cstrong\u003ehttpd\u003c/strong\u003e,\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eun server relay, named \u003cstrong\u003erelayd\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eWebsite: \u003ca href=\"https://bsd.plumbing/\" rel=\"external\"\u003ehttps://bsd.plumbing/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOpenBSD: \u003cstrong\u003e6.6, 6.7\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003ehttpd\u003c/strong\u003e is not able to manage delivery about cache static content.\u003c/p\u003e\n\u003cp\u003eSo we pass the relay to the \u003cstrong\u003erelayd\u003c/strong\u003e server which is able to do it; so,\nit does in the global manner, not-domain specific.\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eWe need to modify the \u003cstrong\u003ehttpd\u003c/strong\u003e and \u003cstrong\u003erelayd\u003c/strong\u003e configuration, i.e.:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erelayd\u003c/strong\u003e will receive all traffic on web port and redirects to localhost\non corresponding ports. Off course, il possible to act on both IPv4\nand IPv6 protocols.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehttpd\u003c/strong\u003e will query only the localhost on the dedicated ports.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDo not forget to restart both daemons after modyfing the configuration.\u003c/p\u003e\n\u003ch3 id=\"relayd\"\u003erelayd\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile configuration is: \u003ccode\u003e/etc/relayd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIn the contexte of the \u003ccode\u003ehttp\u003c/code\u003e protocol:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWe target all static files, by scanning all web requests:\n\u003cul\u003e\n\u003cli\u003efor the image GIF, JPEG, PNG, SVG\u003c/li\u003e\n\u003cli\u003efor the CSS and JS files\u003c/li\u003e\n\u003cli\u003eand others HTML and XML files (as Atom, RSS, Sitemap, etc.)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ewe apply a tag policy, with the option \u003ccode\u003etag\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eand finally, we send an header \u003ccode\u003eCache-Control\u003c/code\u003e, labelled by the tag.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eNext, we apply the http protocol to a target relay.\u003c/p\u003e\n\u003ch4 id=\"relayd-example\"\u003erelayd: example\u003c/h4\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip4\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;public-address-ipv4\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ehttp protocol \u0026#34;hw\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.atom\u0026#34; tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.css\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.gif\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.html\u0026#34; tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.ico\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.jpg\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.js\u0026#34;   tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.png\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.rss\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.svg\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request path \u0026#34;/*.xml\u0026#34;  tag \u0026#34;CACHE\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response tagged \u0026#34;CACHE\u0026#34; header set \u0026#34;Cache-Control\u0026#34; value \u0026#34;public, max-age\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e86400\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003etcp { nodelay, sack, socket buffer 65536, backlog 100 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003epass\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003erelay \u0026#34;www\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003elisten on $ip4 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eprotocol hw\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward to 127.0.0.1 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/httpd.8\" title=\"OpenBSD Manual Page Server for: httpd\"\u003ehttpd(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/httpd.conf.5\" title=\"OpenBSD Manual Page Server for: httpd.conf\"\u003ehttpd.conf(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"How to caching static content with httpd \u0026 relayd, natives servers on OpenBSD","tags":["relayd","Cache","httpd","HTTP","OpenBSD"],"date_published":"2020-05-07T16:49:36+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-05-06:/en/web/httpd/relayd-headers-httpd","url":"https://it-log.fr.eu.org/en/web/httpd/relayd-headers-httpd/","title":"Relayd: Manage HTTP headers","author":{"name":"Stéphane HUC"},"content_text":"Description OpenBSD has, by default, in basesystem, since 5.7:\na webserver, named httpd,\nun server relay, named relayd\nWebiste: https://bsd.plumbing/\nOpenBSD: 6.6, 6.7\nhttpd is not able to manage HTTP headers; and the author do not want it!\nSo we pass the relay to the relayd server which is able to do it; so, it does in the global manner, not-domain specific.\nConfiguration We need to modify the httpd and relayd configuration, i.e.:\nrelayd will receive all traffic on web port and redirects to localhost on corresponding ports. Off course, il possible to act on both IPv4 and IPv6 protocols. httpd will query only the localhost on the dedicated ports. Do not forget to restart both daemons after modyfing the configuration.\nhttpd File configuration is: /etc/httpd.conf Into the context server, we need to set 3 importants details:\nlisten on: the listener on the localhost — cf : listen on log: the logger; you need to modify the option style to forwarder paramater — cf : style InfoSomeone wrote a redirection to port 8080, instead of 80. It\u0026rsquo;s up to you! Only, the HSTS header is managed differently:\nhttpd: HSTS We can modify the HSTS header by using simply the option hsts (cf : hsts).\nIt is managed, of course, in the context of the HTTPS protocol, via TLS .\nhttpd: example server \u0026#34;domain.tld\u0026#34; { listen on 127.0.0.1 port 80 listen on ::1 port 80 # enable hsts only if you use TLS for HTTPS hsts { max-age 63072000 preload subdomains } location \u0026#34;/.well-known/acme-challenge/*\u0026#34; { root \u0026#34;/acme\u0026#34; request strip 2 } location \u0026#34;/\u0026#34; { directory index index.html } log { access \u0026#34;domain.tld/access.log\u0026#34; error \u0026#34;domain.tld/errors.log\u0026#34; style forwarded } root \u0026#34;/htdocs/domain.tld/www\u0026#34; } httpd: log Here is a log example:\ndomain.tld 127.0.0.1 - - [06/May/2020:04:08:51 +0200] \u0026#34;GET / HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)\u0026#34; 66.249.79.202 - domain.tld 127.0.0.1 - - [06/May/2020:09:48:36 +0200] \u0026#34;GET /robots.txt HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)\u0026#34; 5.196.87.174 - domain.tld 127.0.0.1 - - [06/May/2020:10:29:29 +0200] \u0026#34;GET / HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)\u0026#34; 54.36.148.31 - We remark that address IP of the client is specified on the end of the line.\nIt\u0026rsquo;s due to the parameter forwarder.\nrelayd File configuration is: /etc/relayd.conf In the facts:\nWe declare a http protocol the matching filters match to create the responses headers. both first values are needed to capture and redirect correctly: $SERVER_ADDR:$SERVER_PORT for X-Forwarded-By parameter, $REMOTE_ADDR for X-Forwarded-For parameter. next, we relay by setting the matching relay : listen: the listener on the public address IP and the web port, when we target the http protocol to apply the rules on the headers forward: to redirect to the localhost, and the choosed port, matching to the one the httpd server listen on. relayd: Httpoxy Someone, more attentives, have seen the follow declaration:\nmatch request header remove \u0026quot;Proxy\u0026quot;\nThis is usefull to mitigate the Httpoxy vulnerability that affect CGI, PHP applications.\nIt is recognized as the best way to block this.\nAnother way to protect you is to use HTTPS .\nrelayd: example ip4 = \u0026#34;ipv4_public_address\u0026#34; ip6 = \u0026#34;ipv6_public_address\u0026#34; http protocol \u0026#34;hw\u0026#34; { match request header set \u0026#34;X-Forwarded-By\u0026#34; value \u0026#34;$SERVER_ADDR:$SERVER_PORT\u0026#34; match request header set \u0026#34;X-Forwarded-For\u0026#34; value \u0026#34;$REMOTE_ADDR\u0026#34; match request header remove \u0026#34;Proxy\u0026#34; match response header set \u0026#34;Cache-Control\u0026#34; value \u0026#34;max-age=1814400\u0026#34; match response header set \u0026#34;Content-Security-Policy\u0026#34; value \u0026#34;upgrade-insecure-requests; default-src https: \u0026#39;self\u0026#39;\u0026#34; match response header set \u0026#34;Permissions-Policy\u0026#34; value \u0026#34;fullscreen=(), geolocation=(), microphone()\u0026#34; match response header set \u0026#34;Frame-Options\u0026#34; value \u0026#34;SAMEORIGIN\u0026#34; match response header set \u0026#34;Referrer-Policy\u0026#34; value \u0026#34;strict-origin\u0026#34; match response header set \u0026#34;Server\u0026#34; value \u0026#34;OpenBSD Relayd+httpd\u0026#34; match response header set \u0026#34;X-Content-Type-Options\u0026#34; value \u0026#34;nosniff\u0026#34; match response header set \u0026#34;X-Download-Options\u0026#34; value \u0026#34;noopen\u0026#34; match response header set \u0026#34;X-Frame-Options\u0026#34; value \u0026#34;SAMEORIGIN\u0026#34; match response header set \u0026#34;X-Powered-By\u0026#34; value \u0026#34;!\u0026#34; match response header set \u0026#34;X-Robots-Tag\u0026#34; value \u0026#34;index, nofollow\u0026#34; match response header set \u0026#34;X-Xss-Protection\u0026#34; value \u0026#34;1; mode=block\u0026#34; tcp { nodelay, sack, socket buffer 65536, backlog 100 } pass } relay \u0026#34;www\u0026#34; { listen on $ip4 port 80 protocol hw forward to 127.0.0.1 port 80 } relay \u0026#34;www6\u0026#34; { listen on $ip6 port 80 protocol hw forward to ::1 port 80 } Documentations Manpages httpd(8) , httpd.conf(5) relayd(8) , relayd.conf(5) , relayctl(8) Autres documentations Here a very complete example, with TLS. ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenBSD\u003c/strong\u003e has, by default, in basesystem, since 5.7:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003ea webserver, named \u003cstrong\u003ehttpd\u003c/strong\u003e,\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eun server relay, named \u003cstrong\u003erelayd\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eWebiste: \u003ca href=\"https://bsd.plumbing/\" rel=\"external\"\u003ehttps://bsd.plumbing/\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eOpenBSD: \u003cstrong\u003e6.6, 6.7\u003c/strong\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003ehttpd\u003c/strong\u003e is not able to manage HTTP headers; and \u003ca href=\"https://marc.info/?l=openbsd-misc\u0026amp;m=142407262812306\u0026amp;w=2\" rel=\"external\"\u003ethe author do not want it\u003c/a\u003e!\u003c/p\u003e\n\u003cp\u003eSo we pass the relay to the \u003cstrong\u003erelayd\u003c/strong\u003e server which is able to do it; so,\nit does in the global manner, not-domain specific.\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eWe need to modify the \u003cstrong\u003ehttpd\u003c/strong\u003e and \u003cstrong\u003erelayd\u003c/strong\u003e configuration, i.e.:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003erelayd\u003c/strong\u003e will receive all traffic on web port and redirects to localhost\non corresponding ports. Off course, il possible to act on both IPv4\nand IPv6 protocols.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ehttpd\u003c/strong\u003e will query only the localhost on the dedicated ports.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDo not forget to restart both daemons after modyfing the configuration.\u003c/p\u003e\n\u003ch3 id=\"httpd\"\u003ehttpd\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile configuration is: \u003ccode\u003e/etc/httpd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eInto the context \u003ccode\u003eserver\u003c/code\u003e, we need to set 3 importants details:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elisten on\u003c/code\u003e: the listener on the localhost — \u003cem\u003ecf : \u003ca href=\"https://man.openbsd.org/httpd.conf#listen\" rel=\"external\"\u003elisten on\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elog\u003c/code\u003e: the logger; you need to modify the option \u003ccode\u003estyle\u003c/code\u003e to \u003ccode\u003eforwarder\u003c/code\u003e\nparamater — \u003cem\u003ecf : \u003ca href=\"https://man.openbsd.org/httpd.conf#style\" rel=\"external\"\u003estyle\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eSomeone wrote a redirection to port 8080, instead of 80. It\u0026rsquo;s up to you!\u003c/div\u003e\n\n\u003cp\u003eOnly, the \u003cabbr title=\"HTTP Strict Transport Security\"\u003eHSTS\u003c/abbr\u003e\n header is managed\ndifferently:\u003c/p\u003e\n\u003ch4 id=\"httpd-hsts\"\u003ehttpd: HSTS\u003c/h4\u003e\n\u003cp\u003eWe can modify the \u003cstrong\u003eHSTS\u003c/strong\u003e header by using simply the option \u003ccode\u003ehsts\u003c/code\u003e \u003cem\u003e(cf : \u003ca href=\"https://man.openbsd.org/httpd.conf#hsts\" rel=\"external\"\u003ehsts\u003c/a\u003e)\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eIt is managed, of course, in the context of the\n\u003cabbr title=\"HyperText Transport Protocol Secure\"\u003eHTTPS\u003c/abbr\u003e\n protocol, via\n\u003cabbr title=\"Transport Layer Secure\"\u003eTLS\u003c/abbr\u003e\n.\u003c/p\u003e\n\u003ch4 id=\"httpd-example\"\u003ehttpd: example\u003c/h4\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-httpd\" data-lang=\"httpd\"\u003eserver \u0026#34;domain.tld\u0026#34; {\n\n    listen on 127.0.0.1 port 80\n    listen on ::1 port 80\n\n    # enable hsts only if you use TLS for HTTPS\n    hsts {\n        max-age 63072000\n        preload\n        subdomains\n    }\n\n    location \u0026#34;/.well-known/acme-challenge/*\u0026#34; {\n        root \u0026#34;/acme\u0026#34;\n        request strip 2\n    }\n\n    location \u0026#34;/\u0026#34; {\n        directory index index.html\n    }\n\n    log {\n        access \u0026#34;domain.tld/access.log\u0026#34;\n        error  \u0026#34;domain.tld/errors.log\u0026#34;\n        style forwarded\n    }\n\n    root \u0026#34;/htdocs/domain.tld/www\u0026#34;\n}\n\u003c/code\u003e\u003c/pre\u003e\u003ch4 id=\"httpd-log\"\u003ehttpd: log\u003c/h4\u003e\n\u003cp\u003eHere is a log example:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-log\" data-lang=\"log\"\u003edomain.tld 127.0.0.1 - - [06/May/2020:04:08:51 +0200] \u0026#34;GET / HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)\u0026#34; 66.249.79.202 -\ndomain.tld 127.0.0.1 - - [06/May/2020:09:48:36 +0200] \u0026#34;GET /robots.txt HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)\u0026#34; 5.196.87.174 -\ndomain.tld 127.0.0.1 - - [06/May/2020:10:29:29 +0200] \u0026#34;GET / HTTP/1.1\u0026#34; 200 0 \u0026#34;\u0026#34; \u0026#34;Mozilla/5.0 (compatible; AhrefsBot/6.1; +http://ahrefs.com/robot/)\u0026#34; 54.36.148.31 -\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eWe remark that address IP of the client is specified on the end of the line.\u003cbr\u003e\nIt\u0026rsquo;s due to the parameter \u003ccode\u003eforwarder\u003c/code\u003e.\u003c/p\u003e\n\u003ch3 id=\"relayd\"\u003erelayd\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile configuration is: \u003ccode\u003e/etc/relayd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIn the facts:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWe declare a \u003cstrong\u003ehttp\u003c/strong\u003e protocol\u003c/li\u003e\n\u003cli\u003ethe matching filters \u003ccode\u003ematch\u003c/code\u003e to create the responses \u003ccode\u003eheader\u003c/code\u003es.\n\u003cul\u003e\n\u003cli\u003eboth first values are needed to capture and redirect correctly:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e$SERVER_ADDR:$SERVER_PORT\u003c/code\u003e for \u003ccode\u003eX-Forwarded-By\u003c/code\u003e parameter,\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e$REMOTE_ADDR\u003c/code\u003e for \u003ccode\u003eX-Forwarded-For\u003c/code\u003e parameter.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003enext, we relay by setting the matching \u003ccode\u003erelay\u003c/code\u003e :\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elisten\u003c/code\u003e: the listener on the public address IP and the web port,\u003c/li\u003e\n\u003cli\u003ewhen we target the \u003cstrong\u003ehttp\u003c/strong\u003e protocol to apply the rules on the headers\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eforward\u003c/code\u003e: to redirect to the localhost, and the choosed port, matching\nto the one the \u003cstrong\u003ehttpd\u003c/strong\u003e server listen on.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"relayd-httpoxy\"\u003erelayd: Httpoxy\u003c/h4\u003e\n\u003cp\u003eSomeone, more attentives, have seen the follow declaration:\u003cbr\u003e\n\u003ccode\u003ematch request header remove \u0026quot;Proxy\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eThis is usefull to mitigate the \u003cstrong\u003e\u003ca href=\"https://httpoxy.org/\" rel=\"external\"\u003eHttpoxy\u003c/a\u003e\u003c/strong\u003e vulnerability that affect\nCGI, PHP applications.\u003c/p\u003e\n\u003cp\u003eIt is recognized as the best way to block this.\u003cbr\u003e\nAnother way to protect you is to use \u003cabbr title=\"HyperText Transfert Protocol Secure\"\u003eHTTPS\u003c/abbr\u003e\n.\u003c/p\u003e\n\u003ch4 id=\"relayd-example\"\u003erelayd: example\u003c/h4\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip4\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ipv4_public_address\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ipv6_public_address\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ehttp protocol \u0026#34;hw\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request header set \u0026#34;X-Forwarded-By\u0026#34;   value \u0026#34;$SERVER_ADDR:$SERVER_PORT\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request header set \u0026#34;X-Forwarded-For\u0026#34;  value \u0026#34;$REMOTE_ADDR\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch request header remove \u0026#34;Proxy\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;Cache-Control\u0026#34;           value \u0026#34;max-age\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e1814400\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    match response header set \u0026#34;Content-Security-Policy\u0026#34; value \u0026#34;upgrade-insecure-requests; default-src https: \u0026#39;self\u0026#39;\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    match response header set \u0026#34;Permissions-Policy\u0026#34;      value \u0026#34;fullscreen=(), geolocation=(), microphone()\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    match response header set \u0026#34;Frame-Options\u0026#34;           value \u0026#34;SAMEORIGIN\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    match response header set \u0026#34;Referrer-Policy\u0026#34;         value \u0026#34;strict-origin\u0026#34;\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e    match response header set \u0026#34;Server\u0026#34;                  value \u0026#34;OpenBSD Relayd+httpd\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Content-Type-Options\u0026#34; value \u0026#34;nosniff\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Download-Options\u0026#34;     value \u0026#34;noopen\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Frame-Options\u0026#34;        value \u0026#34;SAMEORIGIN\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Powered-By\u0026#34;           value \u0026#34;!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Robots-Tag\u0026#34;           value \u0026#34;index, nofollow\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ematch response header set \u0026#34;X-Xss-Protection\u0026#34;       value \u0026#34;1; mode\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003eblock\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003etcp { nodelay, sack, socket buffer 65536, backlog 100 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003epass\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003erelay \u0026#34;www\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003elisten on $ip4 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eprotocol hw\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward to 127.0.0.1 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003erelay \u0026#34;www6\u0026#34; {\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003elisten on $ip6 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eprotocol hw\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eforward to ::1 port 80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/httpd.8\" title=\"OpenBSD Manual Page Server for: httpd\"\u003ehttpd(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/httpd.conf.5\" title=\"OpenBSD Manual Page Server for: httpd.conf\"\u003ehttpd.conf(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/relayd.8\" title=\"OpenBSD Manual Page Server for: relayd\"\u003erelayd(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/relayd.conf.5\" title=\"OpenBSD Manual Page Server for: relayd.conf\"\u003erelayd.conf(5)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/relayctl.8\" title=\"OpenBSD Manual Page Server for: relayctl\"\u003erelayctl(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"autres-documentations\"\u003eAutres documentations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cdel\u003eHere a \u003ca href=\"https://www.alexander-pluhar.de/openbsd-webserver.html\" rel=\"external\"\u003every complete example\u003c/a\u003e, with TLS.\u003c/del\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"How to manage HTTP headers with both natives servers: httpd \u0026 relayd on OpenBSD","tags":["relayd","Header","httpd","HTTP","OpenBSD"],"date_published":"2020-05-06T15:00:23+02:00","date_modified":"2020-05-07T18:20:36+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-04-27:/en/sys/debian/devuan_opensmtpd-client-auth","url":"https://it-log.fr.eu.org/en/sys/debian/devuan_opensmtpd-client-auth/","title":"Devuan: Opensmtpd Client Auth","author":{"name":"Stéphane HUC"},"content_text":"Description OpenSMTPD is a free implementation of the SMTP protocol, as defined in RFC 5321 , with some additional standard extensions. It allows the machines to exchange mail.\nOpenSMTPD is a part the OpenBSD base system. It was ported to others OSes, as Devuan.\nInformations:\nWebsite: https://www.opensmtpd.org Q : Why do I use OpenSMTPD?\nBecause, OpenSMTPD is:\neasy to config: only one file text! recognized as reliable AND secure. Fully functional and tested on:\nDebian Sid, Devuan Ceres Linux Mint Installation apt install opensmtpd\nthe file log: /var/log/mail.log Configuration The file config: /etc/smtpd.conf To send a mail by SMTP to a mail service requiring identification, it is necessary to first create a file secrets with the appropriate rights on your system, then we have to configure the file smtpd.conf.\nFile secrets To create the secrets file:\n:$ mkdir -p .config/mail :$ touch .config/mail/secrets :$ chmod 0640 .config/mail/secrets Then, it\u0026rsquo;s necessary to write: identifiant username:password Do Not Write TEXTUALLY this information , replace with:\nidentifiant: your choosed id — this will use later on your config file. username: usually, your email. password: the password for your email identification. WarningIt\u0026rsquo;s possible to (re?)name the secrets file as you want, and put in other place on your system.\nIt\u0026rsquo;s better put rights 0400 on this secrets file. Default: 0640.\nEven, it\u0026rsquo;s possible for the service to access at your secrets file, with your personal rights as $USER:$USER, it\u0026rsquo;s better to put the group right opensmtpd.\nFile smtpd.conf Now, edit the config file /etc/smtpd.conf\n# $OpenBSD: smtpd.conf,v 1.10 2018/05/24 11:40:17 gilles Exp $ # This is the smtpd server system-wide configuration file. # See smtpd.conf(5) for more information. table aliases file:/etc/aliases table secrets file:/home/your-id/.config/mail/secrets queue compression # To accept external mail, replace with: listen on all listen on localhost action \u0026#34;local\u0026#34; maildir alias \u0026lt;aliases\u0026gt; action \u0026#34;relay\u0026#34; relay host smtp+tls://identifiant@server auth \u0026lt;secrets\u0026gt; mail-from \u0026#34;@your-domain.tld\u0026#34; # Uncomment the following to accept external mail for domain \u0026#34;example.org\u0026#34; # # match from any for domain \u0026#34;example.org\u0026#34; action \u0026#34;local\u0026#34; match for local action \u0026#34;local\u0026#34; match from local for any action \u0026#34;relay\u0026#34; Explainations\nSo compared to the original version, we added:\nthe line table secrets: it call the secrets file — write your custom filename. the line action relay: to define the necessary action to send emails to the server. NOTE about identifiant@serveur: you have to replace the string identifiant by your created. and too, to replace the serveur by the name of SMTP server. the string smtp+tls is the used protocol to connect at the SMTP server. others protocols are: lmtp: to connect on a LMTP session. smtp: to attempt a connection with a STARTTLS session, if possible. smtp+tls: to force the connection on a STARTTLS session. smtp+notls: to use a plain text SMTP session without TLS. smtps: to force the connexion via TLS — default port: 465 with no specified protocol, the connection will be done on the default port: 25. the string auth: to specify the secrets table. the string mail-from: to specify the domain name to use. the line match … action \u0026quot;relay\u0026quot;: this is the action that will be triggered to send the emails. aliases About aliases system:\nIt is interesting to manage the alias related to your root account or even that of your main user…\nEdit the file /etc/aliases, with rights admin. At the end of file, modify root with your desired address email. Do the same for your system user. ;)\nAnd, do not forget to reload the aliases base, with the command newaliases!\nUtilisation WarningBefore restart the opensmtpd service, we need to test the config file: :# smtpd -n\nIf the result is: configuration OK that\u0026rsquo;s folk!\nOtherwise, re-edit the file, at the line indicated first!\nNow, restart the service: :# service opensmtpd restart\nSend So:\necho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; email or, echo \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; root For all cases, the log will display messages, as:\n(…) Apr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp connected address=local host=*** Apr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp message msgid=85868a25 size=474 nrcpt=1 proto=ESMTP Apr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp envelope evpid=85868a25fcb1569a from=\u0026lt;my-id@***\u0026gt; to=\u0026lt;my-id@***\u0026gt; Apr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp disconnected reason=quit Apr 27 09:16:51 pc-z smtpd[1718]: 09cca27892fa38ea mta delivery evpid=85868a25fcb1569a from=\u0026lt;my-id@huc.fr.eu.org\u0026gt; to=\u0026lt;email@nom-de-domaine.tld\u0026gt; rcpt=\u0026lt;my-id@***\u0026gt; source=\u0026#34;192.168.47.47\u0026#34; relay=\u0026#34;80.67.160.70 (lautre.net)\u0026#34; delay=4s result=\u0026#34;Ok\u0026#34; stat=\u0026#34;250 2.0.0 Ok: queued as 53C92112839\u0026#34; Apr 27 09:17:02 pc-z smtpd[1718]: 09cca27892fa38ea mta disconnected reason=quit messages=2 (…) Now, you can send email from console/terminal or yours scripts shell with SMTP authentification!\nErrors Look the different possible errors on my article\nDocumentations The SMTP protocol defined by RFC 5321:\nRFC 5321 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT Manpages smtpd.conf(5) Wikipedia Local_Mail_Transfer_Protocol WP ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenSMTPD\u003c/strong\u003e is a free implementation of the SMTP protocol, as defined in \u003ca href=\"https://www.rfc-editor.org/info/rfc5321\" title=\"RFC Editor: Information on RFC 5321\"\u003eRFC 5321\u003c/a\u003e\n, with some additional standard extensions. It allows the machines to exchange mail.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eOpenSMTPD\u003c/strong\u003e is a part the OpenBSD base system. It was ported to others OSes, as Devuan.\u003c/p\u003e\n\u003cp\u003eInformations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWebsite: \u003ca href=\"https://www.opensmtpd.org\" rel=\"external\"\u003ehttps://www.opensmtpd.org\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cabbr title=\"Question\"\u003eQ\u003c/abbr\u003e\n : \u003cstrong\u003eWhy do I use OpenSMTPD?\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eBecause, OpenSMTPD is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eeasy to \u003ca href=\"/en/sys/debian/devuan_opensmtpd-client-auth/#configuration\"\u003econfig\u003c/a\u003e:\u003c/strong\u003e only one file text!\u003c/li\u003e\n\u003cli\u003erecognized as reliable AND secure.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eFully functional and tested on:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDebian Sid, Devuan Ceres\u003c/li\u003e\n\u003cli\u003eLinux Mint\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003eapt install opensmtpd\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe file log: \u003ccode\u003e/var/log/mail.log\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe file config: \u003ccode\u003e/etc/smtpd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eTo send a mail by SMTP to a mail service requiring identification, it is necessary to first create a file \u003ccode\u003esecrets\u003c/code\u003e with the appropriate rights on your system, then we have to configure the file \u003ccode\u003esmtpd.conf\u003c/code\u003e.\u003c/p\u003e\n\u003ch3 id=\"file-secrets\"\u003eFile secrets\u003c/h3\u003e\n\u003cp\u003eTo create the secrets file:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e:$ mkdir -p .config/mail\n:$ touch .config/mail/secrets\n:$ chmod 0640 .config/mail/secrets\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eThen, it\u0026rsquo;s necessary to write: \u003cbr\u003e\n\u003ccode\u003eidentifiant username:password\u003c/code\u003e \u003cbr\u003e\n\u003cspan class=\"red\"\u003eDo Not Write TEXTUALLY this information\u003c/span\u003e\n,\nreplace with:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eidentifiant\u003c/code\u003e: your choosed id — \u003cem\u003ethis will use later on your config file\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eusername\u003c/code\u003e: usually, your email.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epassword\u003c/code\u003e: the password for your email identification.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eIt\u0026rsquo;s possible to (re?)name the secrets file as you want, and put in other place on your system.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s better put rights \u003ccode\u003e0400\u003c/code\u003e on this secrets file. \u003cem\u003eDefault: \u003ccode\u003e0640\u003c/code\u003e\u003c/em\u003e.\u003c/p\u003e\n\u003cp\u003eEven, it\u0026rsquo;s possible for the service to access at your secrets file, with your personal rights as \u003ccode\u003e$USER:$USER\u003c/code\u003e, it\u0026rsquo;s better to put the group right \u003ccode\u003eopensmtpd\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"file-smtpdconf\"\u003eFile smtpd.conf\u003c/h3\u003e\n\u003cp\u003eNow, edit the config file \u003ccode\u003e/etc/smtpd.conf\u003c/code\u003e\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   $OpenBSD: smtpd.conf,v 1.10 2018/05/24 11:40:17 gilles Exp $\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# This is the smtpd server system-wide configuration file.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# See smtpd.conf(5) for more information.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etable aliases file:/etc/aliases\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etable secrets file:/home/your-id/.config/mail/secrets\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003equeue compression\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# To accept external mail, replace with: listen on all\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elisten on localhost\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eaction \u0026#34;local\u0026#34; maildir alias \u0026lt;aliases\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eaction \u0026#34;relay\u0026#34; relay host smtp+tls://identifiant@server auth \u0026lt;secrets\u0026gt; mail-from \u0026#34;@your-domain.tld\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Uncomment the following to accept external mail for domain \u0026#34;example.org\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# match from any for domain \u0026#34;example.org\u0026#34; action \u0026#34;local\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ematch for local action \u0026#34;local\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ematch from local for any action \u0026#34;relay\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSo compared to the original version, we added:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe line \u003ccode\u003etable secrets\u003c/code\u003e: it call the secrets file\n— \u003cem\u003ewrite your custom filename\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003ethe line \u003ccode\u003eaction relay\u003c/code\u003e: to define the necessary action to send emails to the server.\n\u003cul\u003e\n\u003cli\u003eNOTE about \u003ccode\u003eidentifiant@serveur\u003c/code\u003e:\n\u003cul\u003e\n\u003cli\u003eyou have to replace the string \u003ccode\u003eidentifiant\u003c/code\u003e by your created.\u003c/li\u003e\n\u003cli\u003eand too, to replace the \u003ccode\u003eserveur\u003c/code\u003e by the name of SMTP server.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ethe string \u003ccode\u003esmtp+tls\u003c/code\u003e is the used protocol to connect at the SMTP server. \u003cbr\u003e\nothers protocols are:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elmtp\u003c/code\u003e: to connect on a \u003cabbr title=\"Local Mail Transfer Protocol\"\u003eLMTP\u003c/abbr\u003e\n session.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp\u003c/code\u003e: to attempt a connection with a STARTTLS session, if possible.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp+tls\u003c/code\u003e: to force the connection on a STARTTLS session.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp+notls\u003c/code\u003e: to use a plain text SMTP session without TLS.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtps\u003c/code\u003e: to force the connexion via \u003cabbr title=\"Transport Layer Secure\"\u003eTLS\u003c/abbr\u003e\n — \u003cem\u003edefault port: 465\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003ewith no specified protocol, the connection will be done on the default port: 25.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ethe string \u003ccode\u003eauth\u003c/code\u003e: to specify the secrets table.\u003c/li\u003e\n\u003cli\u003ethe string \u003ccode\u003email-from\u003c/code\u003e: to specify the domain name to use.\u003c/li\u003e\n\u003cli\u003ethe line \u003ccode\u003ematch … action \u0026quot;relay\u0026quot;\u003c/code\u003e: this is the action that will be triggered to send the emails.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"aliases\"\u003ealiases\u003c/h3\u003e\n\u003cp\u003eAbout aliases system:\u003c/p\u003e\n\u003cp\u003eIt is interesting to manage the alias related to your \u003ccode\u003eroot\u003c/code\u003e account or even that of your main user…\u003c/p\u003e\n\u003cp\u003eEdit the file \u003ccode\u003e/etc/aliases\u003c/code\u003e, with rights admin. \u003cbr\u003e\nAt the end of file, modify \u003ccode\u003eroot\u003c/code\u003e with your desired address email. \u003cbr\u003e\nDo the same for your system user. ;)\u003c/p\u003e\n\u003cp\u003eAnd, do not forget to reload the aliases base, with the command \u003ccode\u003enewaliases\u003c/code\u003e!\u003c/p\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eBefore restart the \u003cstrong\u003eopensmtpd\u003c/strong\u003e service, we need to test the config file: \u003cbr\u003e\n\u003ccode\u003e:# smtpd -n\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eIf the result is: \u003ccode\u003econfiguration OK\u003c/code\u003e \u003cbr\u003e\nthat\u0026rsquo;s folk!\u003c/p\u003e\n\u003cp\u003eOtherwise, re-edit the file, at the line indicated first!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eNow, restart the service: \u003cbr\u003e\n\u003ccode\u003e:# service opensmtpd restart\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"send\"\u003eSend\u003c/h3\u003e\n\u003cp\u003eSo:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eecho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; email\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eor, \u003ccode\u003eecho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; root\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor all cases, the log will display messages, as:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-log\" data-lang=\"log\"\u003e(…)\nApr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp connected address=local host=***\nApr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp message msgid=85868a25 size=474 nrcpt=1 proto=ESMTP\nApr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp envelope evpid=85868a25fcb1569a from=\u0026lt;my-id@***\u0026gt; to=\u0026lt;my-id@***\u0026gt;\nApr 27 09:16:47 pc-z smtpd[1718]: 09cca279ca1178e4 smtp disconnected reason=quit\nApr 27 09:16:51 pc-z smtpd[1718]: 09cca27892fa38ea mta delivery evpid=85868a25fcb1569a from=\u0026lt;my-id@huc.fr.eu.org\u0026gt; to=\u0026lt;email@nom-de-domaine.tld\u0026gt; rcpt=\u0026lt;my-id@***\u0026gt; source=\u0026#34;192.168.47.47\u0026#34; relay=\u0026#34;80.67.160.70 (lautre.net)\u0026#34; delay=4s result=\u0026#34;Ok\u0026#34; stat=\u0026#34;250 2.0.0 Ok: queued as 53C92112839\u0026#34;\nApr 27 09:17:02 pc-z smtpd[1718]: 09cca27892fa38ea mta disconnected reason=quit messages=2\n(…)\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eNow, you can send email from console/terminal or yours scripts shell with SMTP authentification!\u003c/p\u003e\n\u003ch3 id=\"errors\"\u003eErrors\u003c/h3\u003e\n\u003cp\u003eLook the different possible errors on my \u003ca href=\"/en/sys/openbsd/smtpd-config-auth/\"\u003earticle\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cp\u003eThe SMTP protocol defined by RFC 5321:\u003c/p\u003e\n\n\u003ch3 id=\"rfc-5321\"\u003eRFC 5321\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc5321\" title=\"RFC 5321: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc5321\" title=\"RFC 5321: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc5321.txt\" title=\"RFC 5321: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5321.html\" title=\"RFC 5321: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc5321.txt.pdf\" title=\"RFC 5321: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5321.txt\" title=\"RFC 5321: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/smtpd.conf.5\" title=\"OpenBSD Manual Page Server for: smtpd.conf\"\u003esmtpd.conf(5)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"wikipedia\"\u003eWikipedia\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Local_Mail_Transfer_Protocol\" title=\"Wikipedia Article: Local_Mail_Transfer_Protocol\"\u003e\n    Local_Mail_Transfer_Protocol\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Howto Install OpenSMTPD on Devuan, and config as client with auth SMTP","tags":["Debian","Devuan","Linux Mint","OpenSMPTD","smtp","client","mail","auth"],"date_published":"2020-04-27T09:19:56+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-04-25:/en/sys/debian/devuan_openntpd","url":"https://it-log.fr.eu.org/en/sys/debian/devuan_openntpd/","title":"Devuan: use the OpenNTPD time synchronization client","author":{"name":"Stéphane HUC"},"content_text":"Description OpenNTPD is a service that can be used to synchronize the system clock to the time servers using the NTP (Network Time Protocol) .\nOpenNTPD is a part the OpenBSD base system. It was ported to others OSes, as Devuan.\nInstallation With the apt tool: apt install openntpd\nConfiguration The file config is: /etc/opennptd/ntpd.conf By default, it runs without no needed modification.\n# $OpenBSD: ntpd.conf,v 1.14 2015/07/15 20:28:37 ajacoutot Exp $ # sample ntpd configuration file, see ntpd.conf(5) # Addresses to listen on (ntpd does not listen by default) #listen on * #listen on 127.0.0.1 #listen on ::1 # sync to a single server #server ntp.example.org # use a random selection of NTP Pool Time Servers # see http://support.ntp.org/bin/view/Servers/NTPPoolServers #servers pool.ntp.org # Choose servers announced from Debian NTP Pool servers 0.debian.pool.ntp.org servers 1.debian.pool.ntp.org servers 2.debian.pool.ntp.org servers 3.debian.pool.ntp.org # use a specific local timedelta sensor (radio clock, etc) #sensor nmea0 # use all detected timedelta sensors #sensor * Explanations\nAbout options:\nserver: to target on time server, in particular. servers: to targer a pool of time servers - prefer this sensor: to use local timedelta sensor Utilisation Checks To check the file config, use the option -n, as-is:\n:# openntpd -n configuration OK If not good, you need to review the file config.\nntpctl is the tool to control the time informations.\nthe option -s all - or -sa - is to display availables informations. :# ntpctl -sa 4/4 peers valid, clock unsynced, clock offset is -552.476ms peer wt tl st next poll offset delay jitter 82.64.42.185 from pool 0.debian.pool.ntp.org 1 10 2 6s 32s 0.203ms 60.784ms 31.533ms 194.177.34.116 from pool 0.debian.pool.ntp.org 1 10 3 9s 32s 2.000ms 54.595ms 17.411ms 212.129.10.70 from pool 0.debian.pool.ntp.org 1 10 2 9s 33s 5.552ms 51.518ms 4.078ms 162.159.200.1 from pool 0.debian.pool.ntp.org 1 10 3 7s 33s -0.176ms 55.383ms 17.593ms InfoTo known all usefull options, please see the manpage ntpctl. Service The service name is openntpd, to manage with the service.\nservice openntpd command\ncommand is one of possibles actions on a service, as start, stop, restart. Troubleshooting It can happen at startup that there is a time lag. Using the option -s solve:\n:# openntpd -s -d adjtimex returns frequency of 0.000000ppm /var/lib/openntpd/db/ntpd.drift is empty ntp engine ready reply from 212.83.179.156: offset -522.890034 delay 0.054365, next query 7s set local clock to Sat Apr 25 12:09:03 CEST 2020 (offset -522.890034s) reply from 5.135.3.88: negative delay -522.825725s, next query 3203s reply from 46.105.237.136: negative delay -522.823915s, next query 3197s reply from 185.21.216.198: negative delay -522.821620s, next query 3012s reply from 51.15.175.180: negative delay -522.821769s, next query 3010s reply from 37.187.104.44: negative delay -522.820949s, next query 3031s reply from 46.235.141.130: negative delay -522.816360s, next query 3274s reply from 162.159.200.1: negative delay -522.816819s, next query 3030s reply from 5.39.60.244: negative delay -522.816297s, next query 3254s reply from 95.81.173.155: negative delay -522.812132s, next query 3176s reply from 51.15.191.239: negative delay -522.810759s, next query 3017s reply from 5.39.60.244: negative delay -522.809750s, next query 3082s reply from 51.158.147.92: negative delay -522.805041s, next query 3250s reply from 212.85.158.10: negative delay -522.800165s, next query 3041s reply from 88.212.196.95: negative delay -522.784156s, next query 3179s reply from 156.38.0.219: negative delay -522.657588s, next query 3023s reply from 212.83.179.156: offset -0.004612 delay 0.049539, next query 7s reply from 212.83.179.156: offset -0.007646 delay 0.049241, next query 9s peer 212.83.179.156 now valid Constraint It seems the constraint option is not available!\nInfoThis option constraint ensures that time queries are made on the protocol\nHTTPS (HyperText Transfer Protocol Secure)\n, via\nTLS (Transport Layer Secure)\n.\npeer not valid You have this message:\nwt tl st next poll offset delay jitter 95.81.173.8 from pool 0.debian.pool.ntp.org 1 4 2 8s 9s ---- peer not valid ---- Wait a little for the ntp queries to be returned. Normally at the next query, this should no longer be the case.\nOtherwise, check that the NTP servers registered in the file config are well written, reachable and functional.\nDocumentation The NTP protocol is defined in:\nversion 3 by RFC 1305 version 4 by RFC 5905 RFC 1305 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 5905 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT Manpages Please, read the manpages:\nntpd(8) , ntpd.conf(5) , ntpctl(8) ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenNTPD\u003c/strong\u003e is a service that can be used to synchronize the system clock to the time servers using the \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eNTP \u003cem\u003e(Network Time Protocol)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eOpenNTPD\u003c/strong\u003e is a part the OpenBSD base system. It was ported to others OSes, as Devuan.\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eWith the \u003ccode\u003eapt\u003c/code\u003e tool: \u003ccode\u003eapt install openntpd\u003c/code\u003e\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe file config is: \u003ccode\u003e/etc/opennptd/ntpd.conf\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBy default, it runs without no needed modification.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# $OpenBSD: ntpd.conf,v 1.14 2015/07/15 20:28:37 ajacoutot Exp $\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sample ntpd configuration file, see ntpd.conf(5)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Addresses to listen on (ntpd does not listen by default)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#listen on *\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#listen on 127.0.0.1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#listen on ::1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# sync to a single server\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#server ntp.example.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# use a random selection of NTP Pool Time Servers\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# see http://support.ntp.org/bin/view/Servers/NTPPoolServers\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#servers pool.ntp.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Choose servers announced from Debian NTP Pool\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eservers 0.debian.pool.ntp.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eservers 1.debian.pool.ntp.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eservers 2.debian.pool.ntp.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eservers 3.debian.pool.ntp.org\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# use a specific local timedelta sensor (radio clock, etc)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#sensor nmea0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# use all detected timedelta sensors\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#sensor *\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eExplanations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eAbout options:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eserver\u003c/code\u003e: to target on time server, in particular.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eservers\u003c/code\u003e: to targer a pool of time servers - \u003cem\u003eprefer this\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esensor\u003c/code\u003e: to use local timedelta sensor\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\u003ch3 id=\"checks\"\u003eChecks\u003c/h3\u003e\n\u003cp\u003eTo check the file config, use the option \u003ccode\u003e-n\u003c/code\u003e, as-is:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# openntpd -n\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003econfiguration OK\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIf not good, you need to review the file config.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003ccode\u003entpctl\u003c/code\u003e is the tool to control the time informations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe option \u003ccode\u003e-s all\u003c/code\u003e - or \u003ccode\u003e-sa\u003c/code\u003e - is to display availables informations.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# ntpctl -sa\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e4/4 peers valid, clock unsynced, clock offset is -552.476ms\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epeer\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   wt tl st  next  poll          offset       delay      jitter\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e82.64.42.185 from pool 0.debian.pool.ntp.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e    6s   32s         0.203ms    60.784ms    31.533ms\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e194.177.34.116 from pool 0.debian.pool.ntp.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e    9s   32s         2.000ms    54.595ms    17.411ms\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e212.129.10.70 from pool 0.debian.pool.ntp.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e    9s   33s         5.552ms    51.518ms     4.078ms\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e162.159.200.1 from pool 0.debian.pool.ntp.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e10\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e    7s   33s        -0.176ms    55.383ms    17.593ms\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eTo known all usefull options, please see the manpage \u003ca href=\"/en/sys/debian/devuan_openntpd/#manpages\"\u003entpctl\u003c/a\u003e.\u003c/div\u003e\n\n\u003ch3 id=\"service\"\u003eService\u003c/h3\u003e\n\u003cp\u003eThe service name is \u003cstrong\u003eopenntpd\u003c/strong\u003e, to manage with the \u003ccode\u003eservice\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eservice openntpd command\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecommand\u003c/code\u003e is one of possibles actions on a service, as \u003ccode\u003estart\u003c/code\u003e, \u003ccode\u003estop\u003c/code\u003e, \u003ccode\u003erestart\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003cp\u003eIt can happen at startup that there is a time lag. Using the option \u003ccode\u003e-s\u003c/code\u003e solve:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# openntpd -s -d\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eadjtimex returns frequency of 0.000000ppm\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/var/lib/openntpd/db/ntpd.drift is empty\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003entp engine ready\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 212.83.179.156: offset -522.890034 delay 0.054365, next query 7s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eset local clock to Sat Apr \u003cspan style=\"color:#f99b15\"\u003e25\u003c/span\u003e 12:09:03 CEST \u003cspan style=\"color:#f99b15\"\u003e2020\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eoffset -522.890034s\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 5.135.3.88: negative delay -522.825725s, next query 3203s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 46.105.237.136: negative delay -522.823915s, next query 3197s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 185.21.216.198: negative delay -522.821620s, next query 3012s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 51.15.175.180: negative delay -522.821769s, next query 3010s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 37.187.104.44: negative delay -522.820949s, next query 3031s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 46.235.141.130: negative delay -522.816360s, next query 3274s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 162.159.200.1: negative delay -522.816819s, next query 3030s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 5.39.60.244: negative delay -522.816297s, next query 3254s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 95.81.173.155: negative delay -522.812132s, next query 3176s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 51.15.191.239: negative delay -522.810759s, next query 3017s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 5.39.60.244: negative delay -522.809750s, next query 3082s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 51.158.147.92: negative delay -522.805041s, next query 3250s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 212.85.158.10: negative delay -522.800165s, next query 3041s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 88.212.196.95: negative delay -522.784156s, next query 3179s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 156.38.0.219: negative delay -522.657588s, next query 3023s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 212.83.179.156: offset -0.004612 delay 0.049539, next query 7s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ereply from 212.83.179.156: offset -0.007646 delay 0.049241, next query 9s\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epeer 212.83.179.156 now valid\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"constraint\"\u003eConstraint\u003c/h3\u003e\n\u003cp\u003eIt seems the constraint option is not available!\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eThis option \u003ccode\u003econstraint\u003c/code\u003e ensures that time queries are made on the protocol\u003c/p\u003e\n\u003cp\u003e\u003cspan lang=\"en\"\u003eHTTPS \u003cem\u003e(HyperText Transfer Protocol Secure)\u003c/em\u003e\u003c/span\u003e\u003c/p\u003e\n\u003cp\u003e, via\u003c/p\u003e\n\u003cp\u003e\u003cspan lang=\"en\"\u003eTLS \u003cem\u003e(Transport Layer Secure)\u003c/em\u003e\u003c/span\u003e\u003c/p\u003e\n\u003cp\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"peer-not-valid\"\u003epeer not valid\u003c/h3\u003e\n\u003cp\u003eYou have this message:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   wt tl st  next  poll          offset       delay      jitter\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e95.81.173.8 from pool 0.debian.pool.ntp.org\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e  \u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e    8s    9s             ---- peer not valid ----\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eWait a little for the ntp queries to be returned. \u003cbr\u003e\nNormally at the next query, this should no longer be the case.\u003c/p\u003e\n\u003cp\u003eOtherwise, check that the NTP servers registered in the file config are well written, reachable and functional.\u003c/p\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cp\u003eThe NTP protocol is defined in:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eversion \u003cstrong\u003e3\u003c/strong\u003e by \u003ca href=\"/en/sys/debian/devuan_openntpd/#rfc-1305\"\u003eRFC 1305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eversion \u003cstrong\u003e4\u003c/strong\u003e by \u003ca href=\"/en/sys/debian/devuan_openntpd/#rfc-5905\"\u003eRFC 5905\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\n\u003ch3 id=\"rfc-1305\"\u003eRFC 1305\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc1305\" title=\"RFC 1305: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc1305\" title=\"RFC 1305: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc1305.txt\" title=\"RFC 1305: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc1305.html\" title=\"RFC 1305: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc1305.txt.pdf\" title=\"RFC 1305: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc1305.txt\" title=\"RFC 1305: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-5905\"\u003eRFC 5905\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc5905\" title=\"RFC 5905: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc5905\" title=\"RFC 5905: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc5905.txt\" title=\"RFC 5905: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5905.html\" title=\"RFC 5905: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc5905.txt.pdf\" title=\"RFC 5905: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5905.txt\" title=\"RFC 5905: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/p\u003e\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cp\u003ePlease, read the manpages:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/ntpd.8\" title=\"OpenBSD Manual Page Server for: ntpd\"\u003entpd(8)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/ntpd.conf.5\" title=\"OpenBSD Manual Page Server for: ntpd.conf\"\u003entpd.conf(5)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/ntpctl.8\" title=\"OpenBSD Manual Page Server for: ntpctl\"\u003entpctl(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"To use on Devuan the OpenNTPD time synchronization client","tags":["Devuan","OpenNTPD","ntp","client","temps"],"date_published":"2020-04-25T12:17:36+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-04-14:/en/web/hugo/hugo-opensearch","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-opensearch/","title":"Hugo: Opensearch","author":{"name":"Stéphane HUC"},"content_text":"Description Opensearch is a collection of simple formats for the sharing of search results on your website.\nMost browsers web will offer you to add your site as a search engine, you need to manage the autodiscovery.\nHugo, by default, not manage Opensearch. We are going to modify the configuration to create a new custom output format.\nDocumentation the Hugo official documentation:\nHugo Documentation: Templates \u0026gt; Output formats the Opensearch official documentation:\nhttps://github.com/dewitt/opensearch/blob/master/opensearch-1-1-draft-6.md Configuration the main config file: config.toml It\u0026rsquo;s necessary to modify this file config to create a new:\nMedia Type Output Format Template for the Opensearch file. MediaType The related MimeType to the Opensearch description format is: application/opensearchdescription+xml.\nHugo \u0026gt;= 0.20 Since Hugo 0.20, you need to add:\n[mediaTypes] [mediaTypes.\u0026#34;application/opensearchdescription+xml\u0026#34;] suffix = \u0026#34;xml\u0026#34; Here, we added a new type of format for the mime type: application/opensearchdescription+xml, with the extension name: xml.\nHugo \u0026gt;= 0.44 Since Hugo 0.44, you need to add:\n[mediaTypes] [mediaTypes.\u0026#34;application/opensearchdescription+xml\u0026#34;] suffixes = [\u0026#34;xml\u0026#34;] TipIf your old configuration was before the v0.44, you have to transform the variable suffix to suffixes = ['xml'] ! OuputFormat The output format declaration to add:\n[outputs] [outputFormats.OpenSearch] baseName = \u0026#34;opensearch\u0026#34; isHTML = false isPlainText = false mediaType = \u0026#34;application/opensearchdescription+xml\u0026#34; noUgly = true Next, you need to add \u0026quot;OpenSearch\u0026quot; at your home variable:\n[outputs] home = [\u0026#34;HTML\u0026#34;, \u0026#34;OpenSearch\u0026#34;] Template Simply, create the template as layouts/_default/index.opensearch.xml.\nIf your site is multilingual, the alternates links to the version of language are generated. InfoATTENTION: the presented template manages a multilingual website. {{ printf `\u0026lt;?xml version=\u0026#34;1.0\u0026#34; encoding=\u0026#34;utf-8\u0026#34; ?\u0026gt;` | safeHTML }} \u0026lt;OpenSearchDescription xmlns=\u0026#34;http://a9.com/-/spec/opensearch/1.1/\u0026#34; xmlns:ie=\u0026#34;http://schemas.microsoft.com/Search/2008/\u0026#34; xmlns:moz=\u0026#34;http://www.mozilla.org/2006/browser/search/\u0026#34;\u0026gt; \u0026lt;Attribution\u0026gt;© {{ $.Date.Format \u0026#34;2006\u0026#34; | safeHTML }} {{ site.Author.name }}; http://creativecommons.org/publicdomain/zero/1.0/legalcode.{{ site.Language.Lang }}\u0026lt;/Attribution\u0026gt; \u0026lt;Contact\u0026gt;{{ site.Author.email | safeHTML }}\u0026lt;/Contact\u0026gt; \u0026lt;Description\u0026gt;{{ i18n \u0026#34;opensearchDescription\u0026#34; }}\u0026lt;/Description\u0026gt; \u0026lt;Developer\u0026gt;{{ site.Author.name | safeHTML }}\u0026lt;/Developer\u0026gt; \u0026lt;InputEncoding\u0026gt;utf-8\u0026lt;/InputEncoding\u0026gt; \u0026lt;Image width=\u0026#34;64\u0026#34; height=\u0026#34;64\u0026#34; type=\u0026#34;image/png\u0026#34;\u0026gt;{{ site.BaseURL }}img/Logo-64px.png\u0026lt;/Image\u0026gt; \u0026lt;Image width=\u0026#34;16\u0026#34; height=\u0026#34;16\u0026#34; type=\u0026#34;image/vnd.microsoft.icon\u0026#34;\u0026gt;{{ site.BaseURL }}img/favicon.ico\u0026lt;/Image\u0026gt; \u0026lt;Language\u0026gt;{{ site.LanguageCode }}\u0026lt;/Language\u0026gt; \u0026lt;LongName\u0026gt;{{ site.Title }} :: {{ site.Language.Lang }}\u0026lt;/LongName\u0026gt; \u0026lt;OutputEncoding\u0026gt;UTF-8\u0026lt;/OutputEncoding\u0026gt; \u0026lt;ShortName\u0026gt;Websearch\u0026lt;/ShortName\u0026gt; \u0026lt;SyndicationRight\u0026gt;open\u0026lt;/SyndicationRight\u0026gt; \u0026lt;ie:PreviewUrl type=\u0026#34;text/html\u0026#34; method=\u0026#34;GET\u0026#34; template=\u0026#34;{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u0026#34;/\u0026gt; \u0026lt;moz:SearchForm\u0026gt;{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u0026lt;/moz:SearchForm\u0026gt; \u0026lt;Url template=\u0026#34;{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u0026#34; type=\u0026#34;text/html\u0026#34; /\u0026gt; \u0026lt;Url rel=\u0026#34;self\u0026#34; template=\u0026#34;{{ site.BaseURL }}opensearch.xml\u0026#34; type=\u0026#34;application/opensearchdescription+xml\u0026#34; /\u0026gt; \u0026lt;/OpenSearchDescription\u0026gt; autodiscovery The autodiscovery is the method to inform the web clients about the Opensearch format description in your web site.\nWarningMake sure that the value of the title attribute matches that of the ShortName element! Atom If you have modified your Hugo configuration to generate an Atom feed, you will need to modify it to add the following:\n\u0026lt;link href=\u0026#34;{{ site.BaseURL }}/opensearch.xml\u0026#34; rel=\u0026#34;search\u0026#34; type=\u0026#34;application/opensearchdescription+xml\u0026#34; title=\u0026#34;Websearch\u0026#34; /\u0026gt; HTML Add a link element:\n\u0026lt;link rel=\u0026#34;search\u0026#34; href=\u0026#34;/opensearch.xml\u0026#34; title=\u0026#34;Websearch\u0026#34; type=\u0026#34;application/opensearchdescription+xml\u0026#34;\u0026gt; RSS If you generate your RSS feed, make sure to edit it, to add:\nthe xmlns:atom=\u0026quot;http://www.w3.org/2005/Atom\u0026quot; attribute, into your rss element: \u0026lt;rss version=\u0026#34;2.0\u0026#34; xmlns:atom=\u0026#34;http://www.w3.org/2005/Atom\u0026#34;\u0026gt; in order to declarate atom:link item, as: \u0026lt;atom:link href=\u0026#34;{{ site.BaseURL }}/opensearch.xml\u0026#34; rel=\u0026#34;search\u0026#34; type=\u0026#34;application/opensearchdescription+xml\u0026#34; title=\u0026#34;Websearch\u0026#34; /\u0026gt; Acknowledgments Once again, a thruly thank you @solene who introduced me to Opensearch.\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpensearch\u003c/strong\u003e is a collection of simple formats for the sharing of search results on your website.\u003c/p\u003e\n\u003cp\u003eMost browsers web will offer you to add your site as a search engine, you need to manage the \u003ca href=\"/en/web/hugo/hugo-opensearch/#autodiscovery\"\u003eautodiscovery\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eHugo\u003c/strong\u003e, by default, not manage Opensearch. We are going to modify the \u003ca href=\"/en/web/hugo/hugo-opensearch/#configuration\"\u003econfiguration\u003c/a\u003e to create a new custom output format.\u003c/p\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cp\u003ethe Hugo official documentation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/templates/output-formats/\" title=\"Link to the official site Hugo: Templates \u0026gt; Output formats\"\u003eHugo Documentation: Templates \u0026gt; Output formats\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ethe Opensearch official documentation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dewitt/opensearch/blob/master/opensearch-1-1-draft-6.md\" rel=\"external\"\u003ehttps://github.com/dewitt/opensearch/blob/master/opensearch-1-1-draft-6.md\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ethe main config file: \u003ccode\u003econfig.toml\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIt\u0026rsquo;s necessary to modify this file config to create a new:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/en/web/hugo/hugo-opensearch/#mediatype\"\u003eMedia Type\u003c/a\u003e \u003ca href=\"/en/web/hugo/hugo-opensearch/#\" title=\"Go to the anchor: \"\u003e\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/en/web/hugo/hugo-opensearch/#ouputformat\"\u003eOutput Format\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/en/web/hugo/hugo-opensearch/#template\"\u003eTemplate\u003c/a\u003e for the Opensearch file.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"mediatype\"\u003eMediaType\u003c/h3\u003e\n\u003cp\u003eThe related MimeType to the Opensearch description format is: \u003ccode\u003eapplication/opensearchdescription+xml\u003c/code\u003e.\u003c/p\u003e\n\u003ch4 id=\"hugo--020\"\u003eHugo \u0026gt;= 0.20\u003c/h4\u003e\n\u003cp\u003eSince Hugo 0.20, you need to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-toml\" data-lang=\"toml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[\u003cspan style=\"color:#06b6ef\"\u003emediaTypes\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    [\u003cspan style=\"color:#06b6ef\"\u003emediaTypes\u003c/span\u003e.\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003esuffix\u003c/span\u003e = \u003cspan style=\"color:#48b685\"\u003e\u0026#34;xml\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eHere, we added a new type of format for the mime type: \u003ccode\u003eapplication/opensearchdescription+xml\u003c/code\u003e, with the extension name: \u003ccode\u003exml\u003c/code\u003e.\u003c/p\u003e\n\u003ch4 id=\"hugo--044\"\u003eHugo \u0026gt;= 0.44\u003c/h4\u003e\n\u003cp\u003eSince Hugo 0.44, you need to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-toml\" data-lang=\"toml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[\u003cspan style=\"color:#06b6ef\"\u003emediaTypes\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    [\u003cspan style=\"color:#06b6ef\"\u003emediaTypes\u003c/span\u003e.\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003esuffixes\u003c/span\u003e = [\u003cspan style=\"color:#48b685\"\u003e\u0026#34;xml\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eIf your old configuration was before the v0.44, you have to transform the variable \u003ccode\u003esuffix\u003c/code\u003e to \u003ccode\u003esuffixes = ['xml']\u003c/code\u003e !\u003c/div\u003e\n\n\u003ch3 id=\"ouputformat\"\u003eOuputFormat\u003c/h3\u003e\n\u003cp\u003eThe output format declaration to add:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-toml\" data-lang=\"toml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[\u003cspan style=\"color:#06b6ef\"\u003eoutputs\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    [\u003cspan style=\"color:#06b6ef\"\u003eoutputFormats\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eOpenSearch\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ebaseName\u003c/span\u003e = \u003cspan style=\"color:#48b685\"\u003e\u0026#34;opensearch\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eisHTML\u003c/span\u003e = \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eisPlainText\u003c/span\u003e = \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003emediaType\u003c/span\u003e = \u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003enoUgly\u003c/span\u003e = \u003cspan style=\"color:#815ba4\"\u003etrue\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNext, you need to add \u003ccode\u003e\u0026quot;OpenSearch\u0026quot;\u003c/code\u003e at your \u003ccode\u003ehome\u003c/code\u003e variable:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-toml\" data-lang=\"toml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[\u003cspan style=\"color:#06b6ef\"\u003eoutputs\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ehome\u003c/span\u003e = [\u003cspan style=\"color:#48b685\"\u003e\u0026#34;HTML\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;OpenSearch\u0026#34;\u003c/span\u003e]\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"template\"\u003eTemplate\u003c/h3\u003e\n\u003cp\u003eSimply, create the template as \u003ccode\u003elayouts/_default/index.opensearch.xml\u003c/code\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIf your site is multilingual, the alternates links to the version of\nlanguage are generated.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eATTENTION: the presented template manages a multilingual website.\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-xml\" data-lang=\"xml\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ printf `\u003cspan style=\"color:#776e71\"\u003e\u0026lt;?xml version=\u0026#34;1.0\u0026#34; encoding=\u0026#34;utf-8\u0026#34; ?\u0026gt;\u003c/span\u003e` | safeHTML }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;OpenSearchDescription\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003exmlns=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;http://a9.com/-/spec/opensearch/1.1/\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003exmlns:ie=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;http://schemas.microsoft.com/Search/2008/\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003exmlns:moz=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;http://www.mozilla.org/2006/browser/search/\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Attribution\u0026gt;\u003c/span\u003e© {{ $.Date.Format \u0026#34;2006\u0026#34; | safeHTML }} {{ site.Author.name }}; http://creativecommons.org/publicdomain/zero/1.0/legalcode.{{ site.Language.Lang }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Attribution\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Contact\u0026gt;\u003c/span\u003e{{ site.Author.email | safeHTML }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Contact\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Description\u0026gt;\u003c/span\u003e{{ i18n \u0026#34;opensearchDescription\u0026#34; }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Description\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Developer\u0026gt;\u003c/span\u003e{{ site.Author.name | safeHTML }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Developer\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;InputEncoding\u0026gt;\u003c/span\u003eutf-8\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/InputEncoding\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Image\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ewidth=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;64\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eheight=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;64\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;image/png\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026gt;\u003c/span\u003e{{ site.BaseURL }}img/Logo-64px.png\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Image\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Image\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ewidth=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;16\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eheight=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;16\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;image/vnd.microsoft.icon\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026gt;\u003c/span\u003e{{ site.BaseURL }}img/favicon.ico\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Image\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Language\u0026gt;\u003c/span\u003e{{ site.LanguageCode }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/Language\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;LongName\u0026gt;\u003c/span\u003e{{ site.Title }} :: {{ site.Language.Lang }}\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/LongName\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;OutputEncoding\u0026gt;\u003c/span\u003eUTF-8\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/OutputEncoding\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;ShortName\u0026gt;\u003c/span\u003eWebsearch\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/ShortName\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;SyndicationRight\u0026gt;\u003c/span\u003eopen\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/SyndicationRight\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;ie:PreviewUrl\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;text/html\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003emethod=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;GET\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etemplate=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e/\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;moz:SearchForm\u0026gt;\u003c/span\u003e{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/moz:SearchForm\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Url\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etemplate=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ site.BaseURL }}{{ site.Language.Lang }}/tags/{searchTerms}/\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;text/html\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e/\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;Url\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erel=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;self\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etemplate=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ site.BaseURL }}opensearch.xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e/\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;/OpenSearchDescription\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"autodiscovery\"\u003eautodiscovery\u003c/h2\u003e\n\u003cp\u003eThe autodiscovery is the method to inform the web clients about the\nOpensearch format description in your web site.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eMake sure that the value of the \u003ccode\u003etitle\u003c/code\u003e attribute matches that of the\n\u003ccode\u003eShortName\u003c/code\u003e element!\u003c/div\u003e\n\n\u003ch3 id=\"atom\"\u003eAtom\u003c/h3\u003e\n\u003cp\u003eIf you have modified your Hugo configuration to generate an \u003ca href=\"/en/web/hugo/hugo-feed/\"\u003eAtom\u003c/a\u003e feed, you will need to modify it to add the following:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003elink\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ site.BaseURL }}/opensearch.xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;Websearch\u0026#34;\u003c/span\u003e /\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"html\"\u003eHTML\u003c/h3\u003e\n\u003cp\u003eAdd a \u003ccode\u003elink\u003c/code\u003e element:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003elink\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/opensearch.xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;Websearch\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"rss\"\u003eRSS\u003c/h3\u003e\n\u003cp\u003eIf you generate your \u003ca href=\"/en/web/hugo/hugo-feed/\"\u003eRSS\u003c/a\u003e feed, make sure to edit it, to add:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ccode\u003exmlns:atom=\u0026quot;http://www.w3.org/2005/Atom\u0026quot;\u003c/code\u003e attribute, into your \u003ccode\u003erss\u003c/code\u003e element:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003erss\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eversion\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;2.0\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003exmlns:atom\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;http://www.w3.org/2005/Atom\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003ein order to declarate \u003ccode\u003eatom:link\u003c/code\u003e item, as:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eatom:link\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ site.BaseURL }}/opensearch.xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;application/opensearchdescription+xml\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;Websearch\u0026#34;\u003c/span\u003e /\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003ch2 id=\"acknowledgments\"\u003eAcknowledgments\u003c/h2\u003e\n\u003cp\u003eOnce again, a thruly thank you @\u003ca href=\"https://dataswamp.org/~solene/\" rel=\"external\"\u003esolene\u003c/a\u003e who introduced me to Opensearch.\u003c/p\u003e\n\u003chr\u003e\n","summary":"Howto set up the Opensearch description format into Hugo!","tags":["Hugo","Opensearch","search"],"date_published":"2020-04-14T16:54:07+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-02-26:/en/sys/openwrt/ssh-tunnel","url":"https://it-log.fr.eu.org/en/sys/openwrt/ssh-tunnel/","title":"OpenWRT: Tunnel SSH for LuCI","author":{"name":"Stéphane HUC"},"content_text":"Description In this article, we explain how to encapsule the LuCI HTTP access by SSH .\nConfiguration SSH Tunnel By default, the LuCI web admin is available only on HTTP protocol, listen all interfaces, and everywhere.\nOne way to protect is to redirect the web flow to the local interface into an SSH tunnel.\nAfter your SSH connection at your OpenWRT router:\nFirst, on OpenWRT, you need to reconfigure the uhttpd webserver; edit the file configuration /etc/config/uhttpd:\ncomment the both lines, by adding the # symbol before: list listen_http 0.0.0.0:80 and list listen_https 0.0.0.0:443\nadd: list listen_http 127.0.0.1:80 (and for IPv6: list listen_http [::1]:80)\nrestart the web service: /etc/init.d/uhttpd restart\nand, check that the web service only listens to port 80 on the local interface:\n:$ netstat -ant | grep -E \u0026#34;:80\u0026#34; tcp 0 0 127.0.0.1:80 0.0.0.0:* LISTEN tcp 0 0 ::1:80 :::* LISTEN Next, the command to redirect on SSH is: ssh -L 127.0.0.1:8080:127.0.0.1:80 -p 22 id@address-ip where: -p 22: ssh number port id: your id; See: sudo. address-ip: IPv4 address, on your LAN, in your OpenWRT router. See this example:\nHost luciweb Ciphers aes256-ctr Hostname 192.168.1.1 IdentityFile ~/.ssh/id_rsa LocalForward 127.0.0.1:8080 127.0.0.1:80 MACs hmac-sha2-256 Port 22 User identifiant So, you will only have to execute: $ ssh luciweb\nAnd, on your web browser: localhost:8080\nVoila!\nShell The file config: /etc/config/dropbear the dropbear service: /etc/init.d/dropbear. Troubleshooting Error: no matching cipher found. Their offer: aes128-ctr,aes256-ctr The dropbear SSH server is not able to handle strong encryptions other than those given in the error message. Add to your SSH client configuration: Ciphers aes256-ctr\nError: no matching host key type found. Their offer: ssh-rsa The dropbear SSH server is not able to handle host key types other than those given in the error message. Add to your SSH client configuration: HostKeyAlgorithms ssh-rsa\nError: no matching MAC found. Their offer: hmac-sha1,hmac-sha2-256 The dropbear SSH server is not able to handle MAC other than those given in the error message. Add to your SSH client configuration: MACs hmac-sha2-256\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eIn this article, we explain how to encapsule the LuCI HTTP access by \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"Secure SHell\"\u003eSSH\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n.\u003c/p\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"ssh-tunnel\"\u003eSSH Tunnel\u003c/h3\u003e\n\u003cp\u003eBy default, the LuCI web admin is available only on \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"HyperText Transfer Protocol\"\u003eHTTP\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n protocol, listen all interfaces, and everywhere.\u003c/p\u003e\n\u003cp\u003eOne way to protect is to redirect the web flow to the local interface into an \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"Secure SHell\"\u003eSSH\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n tunnel.\u003c/p\u003e\n\u003cp\u003eAfter your SSH connection at your OpenWRT router:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003e\n\u003cp\u003eFirst, on OpenWRT, you need to reconfigure the \u003cstrong\u003euhttpd\u003c/strong\u003e webserver; edit the file configuration \u003ccode\u003e/etc/config/uhttpd\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003ecomment the both lines, by adding the \u003ccode\u003e#\u003c/code\u003e symbol before: \u003ccode\u003elist listen_http 0.0.0.0:80\u003c/code\u003e and \u003ccode\u003elist listen_https   0.0.0.0:443\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eadd: \u003ccode\u003elist listen_http  127.0.0.1:80\u003c/code\u003e \u003cem\u003e(and for IPv6: \u003ccode\u003elist listen_http [::1]:80\u003c/code\u003e)\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003erestart the web service: \u003ccode\u003e/etc/init.d/uhttpd restart\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eand, check that the web service only listens to port 80 on the local interface:\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e:$ netstat -ant | grep -E \u0026#34;:80\u0026#34;\ntcp        0      0 127.0.0.1:80            0.0.0.0:*               LISTEN\ntcp        0      0 ::1:80                  :::*                    LISTEN\n\u003c/code\u003e\u003c/pre\u003e\u003col start=\"2\"\u003e\n\u003cli\u003eNext, the command to redirect on SSH is: \u003cbr\u003e\n\u003ccode\u003essh -L 127.0.0.1:8080:127.0.0.1:80 -p 22 id@address-ip\u003c/code\u003e \u003cbr\u003e\nwhere:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e-p 22\u003c/code\u003e: ssh number port\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eid\u003c/code\u003e: your id; See: \u003ca href=\"/en/sys/openwrt/sudo/\"\u003esudo\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eaddress-ip\u003c/code\u003e: IPv4 address, on your LAN, in your OpenWRT router.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee this example:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eHost luciweb\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eCiphers aes256-ctr\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eHostname 192.168.1.1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eIdentityFile ~/.ssh/id_rsa\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eLocalForward 127.0.0.1:8080 127.0.0.1:80\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eMACs hmac-sha2-256\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003ePort 22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003eUser identifiant\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eSo, you will only have to execute: \u003ccode\u003e$ ssh luciweb\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eAnd, on your web browser: \u003ccode\u003elocalhost:8080\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eVoila!\u003c/p\u003e\n\u003ch3 id=\"shell\"\u003eShell\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe file config: \u003ccode\u003e/etc/config/dropbear\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003cstrong\u003edropbear\u003c/strong\u003e service: \u003ccode\u003e/etc/init.d/dropbear\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"troubleshooting\"\u003eTroubleshooting\u003c/h2\u003e\n\u003ch3 id=\"error-no-matching-cipher-found-their-offer-aes128-ctraes256-ctr\"\u003eError: no matching cipher found. Their offer: aes128-ctr,aes256-ctr\u003c/h3\u003e\n\u003cp\u003eThe \u003cstrong\u003edropbear\u003c/strong\u003e SSH server is not able to handle strong encryptions other than those given in the error message. \u003cbr\u003e\nAdd to your SSH client configuration: \u003ccode\u003eCiphers aes256-ctr\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"error-no-matching-host-key-type-found-their-offer-ssh-rsa\"\u003eError: no matching host key type found. Their offer: ssh-rsa\u003c/h3\u003e\n\u003cp\u003eThe \u003cstrong\u003edropbear\u003c/strong\u003e SSH server is not able to handle host key types other than those given in the error message. \u003cbr\u003e\nAdd to your SSH client configuration: \u003ccode\u003eHostKeyAlgorithms ssh-rsa\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"error-no-matching-mac-found-their-offer-hmac-sha1hmac-sha2-256\"\u003eError: no matching MAC found. Their offer: hmac-sha1,hmac-sha2-256\u003c/h3\u003e\n\u003cp\u003eThe \u003cstrong\u003edropbear\u003c/strong\u003e SSH server is not able to handle \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cabbr lang=\"en\" title=\"Message Authentication Code\"\u003eMAC\u003c/abbr\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n other than those given in the error message. \u003cbr\u003e\nAdd to your SSH client configuration: \u003ccode\u003eMACs hmac-sha2-256\u003c/code\u003e\u003c/p\u003e\n\u003chr\u003e\n","summary":"Howto set OpenWRT to use SSH to connect on the LuCI web admin!","tags":["OpenWRT","SSH","tunnel"],"date_published":"2020-02-26T15:44:44+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-02-24:/en/sys/openwrt/sudo","url":"https://it-log.fr.eu.org/en/sys/openwrt/sudo/","title":"OpenWRT: sudo","author":{"name":"Stéphane HUC"},"content_text":"opkg → apk Since OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition. Description By default, OpenWRT has one only user: the root admin.\nWe will create a new user, without privilege, only the one to administrate correctly the system with the tool sudo.\nInstallation As root, execute all those commands:\n# opkg update # opkg install shadow-useradd sudo TipIt\u0026rsquo;s possible to install the shadow-usermod package; this intents to set the user account. Configuration user configuration Now, config the user account:\n# useradd ego: ego is the account name - it\u0026rsquo;s up to your convenience… # passwd ego: define the password # mkdir -p /home/ego/.ssh: make the main home, and the ssh folder. # touch /home/ego/.ssh/authorized_keys: create empty file (to copy your SSH public keys) # chown -R ego:ego /home/ego: give the user rights on his home. # chmod 0700 /home/ego: auth only this user. sudo configuration I would only talk about the sudo most secure method of configuration: This method allows you to simply use the administrator\u0026rsquo;s password without having to login with the administrator account. The command sudo must be preceded by any other necessary command.\nWe edit the /etc/sudoers with the visudo command:\n# visudo\nPlace at the bottom of the file, and uncomment the both lignes, to remove the # symbol:\n# Defaults targetpw # Ask for the password of the target user # ALL ALL=(ALL) ALL # WARNING: only use this together with \u0026#39;Defaults targetpw\u0026#39; TipTo save the file, after the modification, type: :wq! After saving and quit, your user can use any administration commands.\nSSH configuration Now, it\u0026rsquo;s the good time to add your ssh auth key into the /home/ego/.ssh/authorized_keys file.\nWarningBe sure to copy your public key, only with the .pub extension! sysupgrade configuration Think to edit the file /etc/sysupgrade.conf to add:\nyour home folder, and /etc/sudoers.d (only if you add config into this folder) and check with the command sysupgrade -l.\nSo, for the future upgrade, yours personals datas will be saved.\nDocumentation https://openwrt.org/docs/guide-user/security/secure.access#create_a_non-privileged_user_in_openwrt ","content_html":"\u003cdiv class=\"tab-info i-deprecated\"\u003e\u003cstrong\u003eopkg → apk\u003c/strong\u003e\u003c/div\u003e\n\u003cdiv class=\"alert alert-deprecated\" role=\"alert\"\u003e\u003cstrong\u003eSince OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition.\u003c/strong\u003e\u003c/div\u003e\n\n\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eBy default, \u003cstrong\u003eOpenWRT\u003c/strong\u003e has one only user: the \u003cstrong\u003eroot\u003c/strong\u003e admin.\u003c/p\u003e\n\u003cp\u003eWe will create a new user, without privilege, only the one to administrate correctly the system with the tool \u003ccode\u003esudo\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eAs \u003cstrong\u003eroot\u003c/strong\u003e, execute all those commands:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-ash\" data-lang=\"ash\"\u003e# opkg update\n# opkg install shadow-useradd sudo\n\u003c/code\u003e\u003c/pre\u003e\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eIt\u0026rsquo;s possible to install the \u003ccode\u003eshadow-usermod\u003c/code\u003e package; this intents to set the user account.\u003c/div\u003e\n\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003ch3 id=\"user-configuration\"\u003euser configuration\u003c/h3\u003e\n\u003cp\u003eNow, config the user account:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e# useradd ego\u003c/code\u003e: \u003ccode\u003eego\u003c/code\u003e is the account name - \u003cem\u003eit\u0026rsquo;s up to your convenience…\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e# passwd ego\u003c/code\u003e: define the password\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e# mkdir -p /home/ego/.ssh\u003c/code\u003e: make the main home, and the ssh folder.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e# touch /home/ego/.ssh/authorized_keys\u003c/code\u003e: create empty file \u003cem\u003e(to copy your SSH public keys)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e# chown -R ego:ego /home/ego\u003c/code\u003e: give the user rights on his home.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e# chmod 0700 /home/ego\u003c/code\u003e: auth only this user.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"sudo-configuration\"\u003esudo configuration\u003c/h3\u003e\n\u003cp\u003eI would only talk about the sudo most secure method of configuration: \u003cbr\u003e\nThis method allows you to simply use the administrator\u0026rsquo;s password without having to login with the administrator account. \u003cbr\u003e\nThe command \u003ccode\u003esudo\u003c/code\u003e must be preceded by any other necessary command.\u003c/p\u003e\n\u003cp\u003eWe edit the \u003ccode\u003e/etc/sudoers\u003c/code\u003e with the \u003ccode\u003evisudo\u003c/code\u003e command:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e# visudo\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003ePlace at the bottom of the file, and uncomment the both lignes, to remove the \u003ccode\u003e#\u003c/code\u003e symbol:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Defaults targetpw  # Ask for the password of the target user\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# ALL ALL=(ALL) ALL  # WARNING: only use this together with \u0026#39;Defaults targetpw\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eTo save the file, after the modification, type: \u003ccode\u003e:wq!\u003c/code\u003e\u003c/div\u003e\n\n\u003cp\u003eAfter saving and quit, your user can use any administration commands.\u003c/p\u003e\n\u003ch3 id=\"ssh-configuration\"\u003eSSH configuration\u003c/h3\u003e\n\u003cp\u003eNow, it\u0026rsquo;s the good time to add your ssh auth key into the \u003ccode\u003e/home/ego/.ssh/authorized_keys\u003c/code\u003e file.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eBe sure to copy your public key, only with the \u003ccode\u003e.pub\u003c/code\u003e extension!\u003c/div\u003e\n\n\u003ch3 id=\"sysupgrade-configuration\"\u003esysupgrade configuration\u003c/h3\u003e\n\u003cp\u003eThink to edit the file \u003ccode\u003e/etc/sysupgrade.conf\u003c/code\u003e to add:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eyour home folder,\u003c/li\u003e\n\u003cli\u003eand \u003ccode\u003e/etc/sudoers.d\u003c/code\u003e \u003cem\u003e(only if you add config into this folder)\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eand check with the command \u003ccode\u003esysupgrade -l\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eSo, for the \u003ca href=\"/en/sys/openwrt/sysupgrade\"\u003efuture upgrade\u003c/a\u003e, yours personals datas will be saved.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://openwrt.org/docs/guide-user/security/secure.access#create_a_non-privileged_user_in_openwrt\" rel=\"external\"\u003ehttps://openwrt.org/docs/guide-user/security/secure.access#create_a_non-privileged_user_in_openwrt\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Howto create a non-privileged user, to use sudo temporarily and correctly!","tags":["OpenWRT","sudo","sysadmin"],"date_published":"2020-02-24T19:41:07+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-02-24:/en/sys/openwrt/opkg-upgrade","url":"https://it-log.fr.eu.org/en/sys/openwrt/opkg-upgrade/","title":"OpenWRT : opkg upgrade (tips)","author":{"name":"Stéphane HUC"},"content_text":"opkg → apk Since OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition. Description OpenWRT has a native tool to manage package: opkg.\nBut, by default, there are not plan to upgrade easily all packages, even upgrade option exists.\nThis is the tips:\n# for name in `opkg list-upgradable | awk \u0026#39;{print $1}\u0026#39;`; do opkg upgrade \u0026#34;${name}\u0026#34;; done Or, if you you have created a user who has the right to use the sudo command:\n$ for name in `sudo opkg list-upgradable | awk \u0026#39;{print $1}\u0026#39;`; do sudo opkg upgrade \u0026#34;${name}\u0026#34;; done ","content_html":"\u003cdiv class=\"tab-info i-deprecated\"\u003e\u003cstrong\u003eopkg → apk\u003c/strong\u003e\u003c/div\u003e\n\u003cdiv class=\"alert alert-deprecated\" role=\"alert\"\u003e\u003cstrong\u003eSince OpenWRT 25.12.0, **apk** *(Alpine Package Keeper)* is the new package manager; the oldier `opkg` is no longer maintened! See the relative page: https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet to the official transition.\u003c/strong\u003e\u003c/div\u003e\n\n\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eOpenWRT has a native tool to manage package: \u003ccode\u003eopkg\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBut, by default, there are not plan to upgrade easily all packages, even \u003ccode\u003eupgrade\u003c/code\u003e option exists.\u003c/p\u003e\n\u003cp\u003eThis is the tips:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# for name in `opkg list-upgradable | awk \u0026#39;{print $1}\u0026#39;`; do opkg upgrade \u0026#34;${name}\u0026#34;; done\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eOr, if you you have created a user who has the right to use the \u003ccode\u003esudo\u003c/code\u003e\ncommand:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e name in \u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003esudo opkg list-upgradable | awk \u003cspan style=\"color:#48b685\"\u003e\u0026#39;{print $1}\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e sudo opkg upgrade \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ename\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n","summary":"howto upgrade packages on OpenWRT with the tool opkg!","tags":["OpenWRT","upgrade","opkg","tips","sysadmin"],"date_published":"2020-02-24T19:17:42+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-02-21:/en/don","url":"https://it-log.fr.eu.org/en/don/","title":"Donate Page","author":{"name":"Stéphane HUC"},"content_text":"Description You appreciate my articles for the quality, their seriousness… you want to make a nice gesture, a donate like the price of a coffee, a beer… or, just to thank me, to encourage-me ;-) :p\nMake a donate. So simply, so easy!\nBy advance: Thank you! :D\n⇒ If you do, and you desire: your name or nickname/pseudo/alias will be displayed here, with your agreement, on the date of the donation…\n⇒ Please, if you desire to display your informations, said-it me on your message…\nHow Ko-fi https://ko-fi.com/hucste One Ko-fi for Stéphane HUC Liberapay https://fr.liberapay.com/HucSte/donate Donate for Stéphane HUC by Liberapay Paypal https://paypal.me/hucste Donate for Stéphane HUC by Paypal Tipeee https://fr.tipeee.com/hucste Reward Stéphane HUC Who 2020 ⇒ In October:\n@scorpus 2022 ⇒ In November:\n@Cascador What 2020 one trappiste rochefort 10 beer: 5€ 2022 5 dozens of € ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eYou appreciate my articles for the quality, their seriousness… \u003cbr\u003e\nyou want to make a nice gesture, a donate like the price of a coffee, a beer… \u003cbr\u003e\nor, just to thank me, to encourage-me ;-) :p\u003c/p\u003e\n\u003cp\u003eMake a donate. So simply, so easy!\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eBy advance: Thank you!\u003c/strong\u003e :D\u003c/p\u003e\n\u003cp\u003e⇒ If you do, and you desire: your name or nickname/pseudo/alias will be\ndisplayed here, with your agreement, on the date of the donation…\u003c/p\u003e\n\u003cp\u003e⇒ Please, if you desire to display your informations, said-it me on your\nmessage…\u003c/p\u003e\n\u003ch2 id=\"how\"\u003eHow\u003c/h2\u003e\n\u003ch3 id=\"ko-fi\"\u003eKo-fi\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://ko-fi.com/hucste\" rel=\"external\"\u003ehttps://ko-fi.com/hucste\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\n\u003cfigure class=\"pure-img\"\u003e\n    \u003ca href=\"/svg/qrcode/ko-fi.svg\" title=\"One Ko-fi for Stéphane HUC\"\u003e\n    \u003csvg xmlns=\"http://www.w3.org/2000/svg\" class=\"qr-svg \" height=\"128\" viewBox=\"0 0 53 53\" width=\"128\"\u003e\n\u003cdefs\u003e\u003cstyle\u003erect{shape-rendering:crispEdges}\u003c/style\u003e\u003c/defs\u003e\n\u003cpath class=\"qr-4 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M16 4 h2 v1 h-2Z M19 4 h1 v1 h-1Z M24 4 h1 v1 h-1Z M28 4 h1 v1 h-1Z M30 4 h2 v1 h-2Z M36 4 h1 v1 h-1Z M13 5 h4 v1 h-4Z M20 5 h2 v1 h-2Z M23 5 h1 v1 h-1Z M25 5 h2 v1 h-2Z M29 5 h1 v1 h-1Z M31 5 h4 v1 h-4Z M37 5 h1 v1 h-1Z M14 6 h3 v1 h-3Z M19 6 h1 v1 h-1Z M21 6 h2 v1 h-2Z M24 6 h3 v1 h-3Z M29 6 h4 v1 h-4Z M36 6 h1 v1 h-1Z M13 7 h3 v1 h-3Z M17 7 h3 v1 h-3Z M21 7 h4 v1 h-4Z M26 7 h3 v1 h-3Z M30 7 h1 v1 h-1Z M32 7 h1 v1 h-1Z M35 7 h2 v1 h-2Z M13 8 h1 v1 h-1Z M19 8 h1 v1 h-1Z M21 8 h2 v1 h-2Z M29 8 h5 v1 h-5Z M36 8 h1 v1 h-1Z M14 9 h1 v1 h-1Z M17 9 h4 v1 h-4Z M22 9 h1 v1 h-1Z M29 9 h1 v1 h-1Z M33 9 h1 v1 h-1Z M35 9 h3 v1 h-3Z M14 11 h3 v1 h-3Z M20 11 h4 v1 h-4Z M31 11 h1 v1 h-1Z M34 11 h4 v1 h-4Z M39 11 h1 v1 h-1Z M14 12 h1 v1 h-1Z M17 12 h3 v1 h-3Z M33 12 h2 v1 h-2Z M37 12 h1 v1 h-1Z M39 12 h1 v1 h-1Z M5 13 h3 v1 h-3Z M11 13 h1 v1 h-1Z M13 13 h3 v1 h-3Z M20 13 h4 v1 h-4Z M25 13 h1 v1 h-1Z M30 13 h3 v1 h-3Z M34 13 h2 v1 h-2Z M38 13 h1 v1 h-1Z M40 13 h1 v1 h-1Z M45 13 h1 v1 h-1Z M47 13 h2 v1 h-2Z M4 14 h2 v1 h-2Z M8 14 h2 v1 h-2Z M13 14 h4 v1 h-4Z M18 14 h2 v1 h-2Z M26 14 h2 v1 h-2Z M33 14 h1 v1 h-1Z M39 14 h5 v1 h-5Z M4 15 h2 v1 h-2Z M7 15 h1 v1 h-1Z M12 15 h4 v1 h-4Z M21 15 h2 v1 h-2Z M24 15 h2 v1 h-2Z M28 15 h2 v1 h-2Z M33 15 h1 v1 h-1Z M36 15 h3 v1 h-3Z M40 15 h6 v1 h-6Z M47 15 h1 v1 h-1Z M6 16 h1 v1 h-1Z M8 16 h1 v1 h-1Z M12 16 h1 v1 h-1Z M16 16 h2 v1 h-2Z M22 16 h5 v1 h-5Z M35 16 h4 v1 h-4Z M41 16 h2 v1 h-2Z M44 16 h1 v1 h-1Z M5 17 h4 v1 h-4Z M12 17 h1 v1 h-1Z M17 17 h1 v1 h-1Z M19 17 h2 v1 h-2Z M22 17 h1 v1 h-1Z M25 17 h1 v1 h-1Z M28 17 h1 v1 h-1Z M30 17 h1 v1 h-1Z M32 17 h2 v1 h-2Z M36 17 h4 v1 h-4Z M42 17 h5 v1 h-5Z M48 17 h1 v1 h-1Z M4 18 h1 v1 h-1Z M8 18 h2 v1 h-2Z M12 18 h5 v1 h-5Z M19 18 h2 v1 h-2Z M22 18 h5 v1 h-5Z M28 18 h1 v1 h-1Z M31 18 h1 v1 h-1Z M35 18 h2 v1 h-2Z M44 18 h2 v1 h-2Z M47 18 h2 v1 h-2Z M5 19 h1 v1 h-1Z M8 19 h2 v1 h-2Z M11 19 h1 v1 h-1Z M13 19 h1 v1 h-1Z M16 19 h4 v1 h-4Z M22 19 h3 v1 h-3Z M28 19 h1 v1 h-1Z M34 19 h2 v1 h-2Z M37 19 h1 v1 h-1Z M39 19 h1 v1 h-1Z M44 19 h1 v1 h-1Z M48 19 h1 v1 h-1Z M4 20 h3 v1 h-3Z M11 20 h2 v1 h-2Z M19 20 h3 v1 h-3Z M23 20 h4 v1 h-4Z M30 20 h5 v1 h-5Z M36 20 h1 v1 h-1Z M40 20 h1 v1 h-1Z M42 20 h2 v1 h-2Z M46 20 h3 v1 h-3Z M4 21 h2 v1 h-2Z M8 21 h2 v1 h-2Z M11 21 h2 v1 h-2Z M14 21 h1 v1 h-1Z M16 21 h1 v1 h-1Z M19 21 h1 v1 h-1Z M23 21 h1 v1 h-1Z M27 21 h3 v1 h-3Z M32 21 h1 v1 h-1Z M34 21 h4 v1 h-4Z M41 21 h2 v1 h-2Z M46 21 h2 v1 h-2Z M6 22 h2 v1 h-2Z M9 22 h1 v1 h-1Z M12 22 h1 v1 h-1Z M14 22 h4 v1 h-4Z M20 22 h2 v1 h-2Z M25 22 h2 v1 h-2Z M29 22 h1 v1 h-1Z M33 22 h1 v1 h-1Z M36 22 h1 v1 h-1Z M38 22 h2 v1 h-2Z M41 22 h1 v1 h-1Z M43 22 h1 v1 h-1Z M45 22 h4 v1 h-4Z M4 23 h1 v1 h-1Z M6 23 h2 v1 h-2Z M9 23 h1 v1 h-1Z M11 23 h2 v1 h-2Z M14 23 h1 v1 h-1Z M16 23 h1 v1 h-1Z M20 23 h3 v1 h-3Z M24 23 h4 v1 h-4Z M29 23 h3 v1 h-3Z M33 23 h1 v1 h-1Z M35 23 h1 v1 h-1Z M38 23 h5 v1 h-5Z M48 23 h1 v1 h-1Z M4 24 h2 v1 h-2Z M13 24 h2 v1 h-2Z M18 24 h1 v1 h-1Z M20 24 h1 v1 h-1Z M35 24 h5 v1 h-5Z M45 24 h3 v1 h-3Z M4 25 h4 v1 h-4Z M17 25 h2 v1 h-2Z M20 25 h1 v1 h-1Z M22 25 h1 v1 h-1Z M33 25 h1 v1 h-1Z M38 25 h1 v1 h-1Z M46 25 h2 v1 h-2Z M6 26 h2 v1 h-2Z M14 26 h1 v1 h-1Z M20 26 h1 v1 h-1Z M29 26 h1 v1 h-1Z M37 26 h3 v1 h-3Z M45 26 h2 v1 h-2Z M48 26 h1 v1 h-1Z M5 27 h1 v1 h-1Z M14 27 h9 v1 h-9Z M30 27 h1 v1 h-1Z M33 27 h1 v1 h-1Z M35 27 h3 v1 h-3Z M39 27 h1 v1 h-1Z M46 27 h3 v1 h-3Z M5 28 h1 v1 h-1Z M7 28 h1 v1 h-1Z M13 28 h4 v1 h-4Z M21 28 h1 v1 h-1Z M29 28 h3 v1 h-3Z M39 28 h1 v1 h-1Z M45 28 h1 v1 h-1Z M47 28 h1 v1 h-1Z M8 29 h1 v1 h-1Z M11 29 h1 v1 h-1Z M13 29 h1 v1 h-1Z M16 29 h1 v1 h-1Z M18 29 h3 v1 h-3Z M22 29 h1 v1 h-1Z M26 29 h1 v1 h-1Z M28 29 h8 v1 h-8Z M37 29 h1 v1 h-1Z M42 29 h4 v1 h-4Z M47 29 h2 v1 h-2Z M7 30 h3 v1 h-3Z M13 30 h3 v1 h-3Z M18 30 h3 v1 h-3Z M24 30 h2 v1 h-2Z M27 30 h2 v1 h-2Z M30 30 h3 v1 h-3Z M38 30 h1 v1 h-1Z M41 30 h3 v1 h-3Z M5 31 h2 v1 h-2Z M11 31 h1 v1 h-1Z M13 31 h4 v1 h-4Z M20 31 h1 v1 h-1Z M23 31 h6 v1 h-6Z M30 31 h1 v1 h-1Z M33 31 h2 v1 h-2Z M36 31 h2 v1 h-2Z M39 31 h2 v1 h-2Z M42 31 h2 v1 h-2Z M45 31 h1 v1 h-1Z M47 31 h1 v1 h-1Z M5 32 h1 v1 h-1Z M8 32 h2 v1 h-2Z M12 32 h7 v1 h-7Z M20 32 h1 v1 h-1Z M22 32 h4 v1 h-4Z M27 32 h1 v1 h-1Z M32 32 h1 v1 h-1Z M34 32 h4 v1 h-4Z M43 32 h1 v1 h-1Z M8 33 h2 v1 h-2Z M11 33 h4 v1 h-4Z M16 33 h2 v1 h-2Z M22 33 h2 v1 h-2Z M25 33 h1 v1 h-1Z M27 33 h2 v1 h-2Z M31 33 h4 v1 h-4Z M36 33 h3 v1 h-3Z M40 33 h2 v1 h-2Z M43 33 h2 v1 h-2Z M46 33 h1 v1 h-1Z M48 33 h1 v1 h-1Z M4 34 h2 v1 h-2Z M7 34 h3 v1 h-3Z M12 34 h3 v1 h-3Z M18 34 h2 v1 h-2Z M21 34 h1 v1 h-1Z M23 34 h1 v1 h-1Z M27 34 h1 v1 h-1Z M30 34 h3 v1 h-3Z M35 34 h2 v1 h-2Z M40 34 h1 v1 h-1Z M44 34 h5 v1 h-5Z M4 35 h6 v1 h-6Z M11 35 h1 v1 h-1Z M14 35 h1 v1 h-1Z M16 35 h1 v1 h-1Z M18 35 h2 v1 h-2Z M22 35 h1 v1 h-1Z M24 35 h2 v1 h-2Z M28 35 h1 v1 h-1Z M30 35 h1 v1 h-1Z M32 35 h5 v1 h-5Z M38 35 h2 v1 h-2Z M41 35 h4 v1 h-4Z M46 35 h1 v1 h-1Z M48 35 h1 v1 h-1Z M6 36 h4 v1 h-4Z M12 36 h1 v1 h-1Z M16 36 h2 v1 h-2Z M19 36 h1 v1 h-1Z M21 36 h4 v1 h-4Z M28 36 h4 v1 h-4Z M33 36 h2 v1 h-2Z M37 36 h1 v1 h-1Z M39 36 h7 v1 h-7Z M47 36 h2 v1 h-2Z M5 37 h1 v1 h-1Z M7 37 h1 v1 h-1Z M9 37 h1 v1 h-1Z M11 37 h1 v1 h-1Z M13 37 h1 v1 h-1Z M15 37 h1 v1 h-1Z M19 37 h2 v1 h-2Z M23 37 h2 v1 h-2Z M26 37 h2 v1 h-2Z M29 37 h2 v1 h-2Z M33 37 h1 v1 h-1Z M35 37 h1 v1 h-1Z M37 37 h3 v1 h-3Z M42 37 h1 v1 h-1Z M44 37 h1 v1 h-1Z M47 37 h2 v1 h-2Z M13 38 h1 v1 h-1Z M18 38 h1 v1 h-1Z M20 38 h1 v1 h-1Z M26 38 h1 v1 h-1Z M28 38 h7 v1 h-7Z M37 38 h1 v1 h-1Z M39 38 h1 v1 h-1Z M41 38 h5 v1 h-5Z M11 39 h1 v1 h-1Z M15 39 h1 v1 h-1Z M17 39 h2 v1 h-2Z M22 39 h3 v1 h-3Z M27 39 h4 v1 h-4Z M32 39 h3 v1 h-3Z M38 39 h3 v1 h-3Z M42 39 h1 v1 h-1Z M44 39 h1 v1 h-1Z M47 39 h1 v1 h-1Z M13 40 h1 v1 h-1Z M16 40 h1 v1 h-1Z M19 40 h2 v1 h-2Z M22 40 h1 v1 h-1Z M29 40 h3 v1 h-3Z M34 40 h1 v1 h-1Z M36 40 h3 v1 h-3Z M46 40 h1 v1 h-1Z M13 41 h1 v1 h-1Z M15 41 h2 v1 h-2Z M20 41 h4 v1 h-4Z M29 41 h2 v1 h-2Z M38 41 h2 v1 h-2Z M45 41 h1 v1 h-1Z M47 41 h1 v1 h-1Z M13 42 h1 v1 h-1Z M16 42 h2 v1 h-2Z M19 42 h1 v1 h-1Z M22 42 h2 v1 h-2Z M30 42 h3 v1 h-3Z M35 42 h4 v1 h-4Z M46 42 h1 v1 h-1Z M48 42 h1 v1 h-1Z M14 43 h1 v1 h-1Z M18 43 h2 v1 h-2Z M33 43 h3 v1 h-3Z M37 43 h1 v1 h-1Z M47 43 h1 v1 h-1Z M13 44 h4 v1 h-4Z M18 44 h4 v1 h-4Z M29 44 h2 v1 h-2Z M32 44 h2 v1 h-2Z M36 44 h1 v1 h-1Z M45 44 h2 v1 h-2Z M48 44 h1 v1 h-1Z M15 45 h7 v1 h-7Z M24 45 h3 v1 h-3Z M28 45 h1 v1 h-1Z M31 45 h2 v1 h-2Z M34 45 h1 v1 h-1Z M37 45 h1 v1 h-1Z M39 45 h4 v1 h-4Z M44 45 h2 v1 h-2Z M48 45 h1 v1 h-1Z M15 46 h2 v1 h-2Z M21 46 h1 v1 h-1Z M23 46 h1 v1 h-1Z M29 46 h1 v1 h-1Z M31 46 h2 v1 h-2Z M35 46 h1 v1 h-1Z M38 46 h1 v1 h-1Z M43 46 h1 v1 h-1Z M47 46 h2 v1 h-2Z M13 47 h1 v1 h-1Z M16 47 h5 v1 h-5Z M22 47 h2 v1 h-2Z M25 47 h6 v1 h-6Z M32 47 h1 v1 h-1Z M36 47 h1 v1 h-1Z M38 47 h1 v1 h-1Z M40 47 h3 v1 h-3Z M45 47 h1 v1 h-1Z M47 47 h2 v1 h-2Z M13 48 h1 v1 h-1Z M15 48 h5 v1 h-5Z M23 48 h1 v1 h-1Z M25 48 h1 v1 h-1Z M27 48 h2 v1 h-2Z M30 48 h1 v1 h-1Z M32 48 h1 v1 h-1Z M34 48 h5 v1 h-5Z M40 48 h1 v1 h-1Z M43 48 h1 v1 h-1Z M48 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-6 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M5 5 h5 v1 h-5Z M43 5 h5 v1 h-5Z M5 6 h1 v1 h-1Z M9 6 h1 v1 h-1Z M43 6 h1 v1 h-1Z M47 6 h1 v1 h-1Z M5 7 h1 v1 h-1Z M9 7 h1 v1 h-1Z M43 7 h1 v1 h-1Z M47 7 h1 v1 h-1Z M5 8 h1 v1 h-1Z M9 8 h1 v1 h-1Z M43 8 h1 v1 h-1Z M47 8 h1 v1 h-1Z M5 9 h5 v1 h-5Z M43 9 h5 v1 h-5Z M5 43 h5 v1 h-5Z M5 44 h1 v1 h-1Z M9 44 h1 v1 h-1Z M5 45 h1 v1 h-1Z M9 45 h1 v1 h-1Z M5 46 h1 v1 h-1Z M9 46 h1 v1 h-1Z M5 47 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-8 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M11 4 h1 v1 h-1Z M41 4 h1 v1 h-1Z M11 5 h1 v1 h-1Z M41 5 h1 v1 h-1Z M11 6 h1 v1 h-1Z M41 6 h1 v1 h-1Z M11 7 h1 v1 h-1Z M41 7 h1 v1 h-1Z M11 8 h1 v1 h-1Z M41 8 h1 v1 h-1Z M11 9 h1 v1 h-1Z M41 9 h1 v1 h-1Z M11 10 h1 v1 h-1Z M41 10 h1 v1 h-1Z M4 11 h8 v1 h-8Z M41 11 h8 v1 h-8Z M4 41 h8 v1 h-8Z M11 42 h1 v1 h-1Z M11 43 h1 v1 h-1Z M11 44 h1 v1 h-1Z M11 45 h1 v1 h-1Z M11 46 h1 v1 h-1Z M11 47 h1 v1 h-1Z M11 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-10 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M25 9 h3 v1 h-3Z M25 10 h1 v1 h-1Z M27 10 h1 v1 h-1Z M25 11 h3 v1 h-3Z M9 25 h3 v1 h-3Z M25 25 h3 v1 h-3Z M41 25 h3 v1 h-3Z M9 26 h1 v1 h-1Z M11 26 h1 v1 h-1Z M25 26 h1 v1 h-1Z M27 26 h1 v1 h-1Z M41 26 h1 v1 h-1Z M43 26 h1 v1 h-1Z M9 27 h3 v1 h-3Z M25 27 h3 v1 h-3Z M41 27 h3 v1 h-3Z M25 41 h3 v1 h-3Z M41 41 h3 v1 h-3Z M25 42 h1 v1 h-1Z M27 42 h1 v1 h-1Z M41 42 h1 v1 h-1Z M43 42 h1 v1 h-1Z M25 43 h3 v1 h-3Z M41 43 h3 v1 h-3Z \" /\u003e\u003cpath class=\"qr-12 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M13 10 h1 v1 h-1Z M15 10 h1 v1 h-1Z M17 10 h1 v1 h-1Z M19 10 h1 v1 h-1Z M21 10 h1 v1 h-1Z M23 10 h1 v1 h-1Z M29 10 h1 v1 h-1Z M31 10 h1 v1 h-1Z M33 10 h1 v1 h-1Z M35 10 h1 v1 h-1Z M37 10 h1 v1 h-1Z M39 10 h1 v1 h-1Z M10 13 h1 v1 h-1Z M10 15 h1 v1 h-1Z M10 17 h1 v1 h-1Z M10 19 h1 v1 h-1Z M10 21 h1 v1 h-1Z M10 23 h1 v1 h-1Z M10 29 h1 v1 h-1Z M10 31 h1 v1 h-1Z M10 33 h1 v1 h-1Z M10 35 h1 v1 h-1Z M10 37 h1 v1 h-1Z M10 39 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-14 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M12 7 h1 v1 h-1Z M12 8 h1 v1 h-1Z M4 12 h2 v1 h-2Z M9 12 h1 v1 h-1Z M11 12 h1 v1 h-1Z M44 12 h2 v1 h-2Z M12 42 h1 v1 h-1Z M12 43 h1 v1 h-1Z M12 47 h1 v1 h-1Z M12 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-16 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M38 4 h2 v1 h-2Z M38 5 h1 v1 h-1Z M40 5 h1 v1 h-1Z M38 6 h1 v1 h-1Z M40 6 h1 v1 h-1Z M38 7 h1 v1 h-1Z M38 9 h3 v1 h-3Z M4 38 h4 v1 h-4Z M9 38 h1 v1 h-1Z M4 39 h1 v1 h-1Z M9 39 h1 v1 h-1Z M5 40 h2 v1 h-2Z M9 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-18 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M0 0 h53 v1 h-53Z M0 1 h53 v1 h-53Z M0 2 h53 v1 h-53Z M0 3 h53 v1 h-53Z M0 4 h4 v1 h-4Z M49 4 h4 v1 h-4Z M0 5 h4 v1 h-4Z M49 5 h4 v1 h-4Z M0 6 h4 v1 h-4Z M49 6 h4 v1 h-4Z M0 7 h4 v1 h-4Z M49 7 h4 v1 h-4Z M0 8 h4 v1 h-4Z M49 8 h4 v1 h-4Z M0 9 h4 v1 h-4Z M49 9 h4 v1 h-4Z M0 10 h4 v1 h-4Z M49 10 h4 v1 h-4Z M0 11 h4 v1 h-4Z M49 11 h4 v1 h-4Z M0 12 h4 v1 h-4Z M49 12 h4 v1 h-4Z M0 13 h4 v1 h-4Z M49 13 h4 v1 h-4Z M0 14 h4 v1 h-4Z M49 14 h4 v1 h-4Z M0 15 h4 v1 h-4Z M49 15 h4 v1 h-4Z M0 16 h4 v1 h-4Z M49 16 h4 v1 h-4Z M0 17 h4 v1 h-4Z M49 17 h4 v1 h-4Z M0 18 h4 v1 h-4Z M49 18 h4 v1 h-4Z M0 19 h4 v1 h-4Z M49 19 h4 v1 h-4Z M0 20 h4 v1 h-4Z M49 20 h4 v1 h-4Z M0 21 h4 v1 h-4Z M49 21 h4 v1 h-4Z M0 22 h4 v1 h-4Z M49 22 h4 v1 h-4Z M0 23 h4 v1 h-4Z M49 23 h4 v1 h-4Z M0 24 h4 v1 h-4Z M49 24 h4 v1 h-4Z M0 25 h4 v1 h-4Z M49 25 h4 v1 h-4Z M0 26 h4 v1 h-4Z M49 26 h4 v1 h-4Z M0 27 h4 v1 h-4Z M49 27 h4 v1 h-4Z M0 28 h4 v1 h-4Z M49 28 h4 v1 h-4Z M0 29 h4 v1 h-4Z M49 29 h4 v1 h-4Z M0 30 h4 v1 h-4Z M49 30 h4 v1 h-4Z M0 31 h4 v1 h-4Z M49 31 h4 v1 h-4Z M0 32 h4 v1 h-4Z M49 32 h4 v1 h-4Z M0 33 h4 v1 h-4Z M49 33 h4 v1 h-4Z M0 34 h4 v1 h-4Z M49 34 h4 v1 h-4Z M0 35 h4 v1 h-4Z M49 35 h4 v1 h-4Z M0 36 h4 v1 h-4Z M49 36 h4 v1 h-4Z M0 37 h4 v1 h-4Z M49 37 h4 v1 h-4Z M0 38 h4 v1 h-4Z M49 38 h4 v1 h-4Z M0 39 h4 v1 h-4Z M49 39 h4 v1 h-4Z M0 40 h4 v1 h-4Z M49 40 h4 v1 h-4Z M0 41 h4 v1 h-4Z M49 41 h4 v1 h-4Z M0 42 h4 v1 h-4Z M49 42 h4 v1 h-4Z M0 43 h4 v1 h-4Z M49 43 h4 v1 h-4Z M0 44 h4 v1 h-4Z M49 44 h4 v1 h-4Z M0 45 h4 v1 h-4Z M49 45 h4 v1 h-4Z M0 46 h4 v1 h-4Z M49 46 h4 v1 h-4Z M0 47 h4 v1 h-4Z M49 47 h4 v1 h-4Z M0 48 h4 v1 h-4Z M49 48 h4 v1 h-4Z M0 49 h53 v1 h-53Z M0 50 h53 v1 h-53Z M0 51 h53 v1 h-53Z M0 52 h53 v1 h-53Z \" /\u003e\u003cpath class=\"qr-512 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 41 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-1024 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M13 4 h3 v1 h-3Z M18 4 h1 v1 h-1Z M20 4 h4 v1 h-4Z M25 4 h3 v1 h-3Z M29 4 h1 v1 h-1Z M32 4 h4 v1 h-4Z M37 4 h1 v1 h-1Z M17 5 h3 v1 h-3Z M22 5 h1 v1 h-1Z M24 5 h1 v1 h-1Z M27 5 h2 v1 h-2Z M30 5 h1 v1 h-1Z M35 5 h2 v1 h-2Z M13 6 h1 v1 h-1Z M17 6 h2 v1 h-2Z M20 6 h1 v1 h-1Z M23 6 h1 v1 h-1Z M27 6 h2 v1 h-2Z M33 6 h3 v1 h-3Z M37 6 h1 v1 h-1Z M16 7 h1 v1 h-1Z M20 7 h1 v1 h-1Z M25 7 h1 v1 h-1Z M29 7 h1 v1 h-1Z M31 7 h1 v1 h-1Z M33 7 h2 v1 h-2Z M37 7 h1 v1 h-1Z M14 8 h5 v1 h-5Z M20 8 h1 v1 h-1Z M23 8 h1 v1 h-1Z M34 8 h2 v1 h-2Z M37 8 h1 v1 h-1Z M13 9 h1 v1 h-1Z M15 9 h2 v1 h-2Z M21 9 h1 v1 h-1Z M23 9 h1 v1 h-1Z M30 9 h3 v1 h-3Z M34 9 h1 v1 h-1Z M13 11 h1 v1 h-1Z M17 11 h3 v1 h-3Z M29 11 h2 v1 h-2Z M32 11 h2 v1 h-2Z M38 11 h1 v1 h-1Z M40 11 h1 v1 h-1Z M13 12 h1 v1 h-1Z M15 12 h2 v1 h-2Z M20 12 h4 v1 h-4Z M29 12 h4 v1 h-4Z M35 12 h2 v1 h-2Z M38 12 h1 v1 h-1Z M40 12 h1 v1 h-1Z M4 13 h1 v1 h-1Z M8 13 h2 v1 h-2Z M12 13 h1 v1 h-1Z M16 13 h4 v1 h-4Z M24 13 h1 v1 h-1Z M26 13 h4 v1 h-4Z M33 13 h1 v1 h-1Z M36 13 h2 v1 h-2Z M39 13 h1 v1 h-1Z M41 13 h4 v1 h-4Z M46 13 h1 v1 h-1Z M6 14 h2 v1 h-2Z M11 14 h2 v1 h-2Z M17 14 h1 v1 h-1Z M20 14 h6 v1 h-6Z M28 14 h5 v1 h-5Z M34 14 h5 v1 h-5Z M44 14 h5 v1 h-5Z M6 15 h1 v1 h-1Z M8 15 h2 v1 h-2Z M11 15 h1 v1 h-1Z M16 15 h5 v1 h-5Z M23 15 h1 v1 h-1Z M26 15 h2 v1 h-2Z M30 15 h3 v1 h-3Z M34 15 h2 v1 h-2Z M39 15 h1 v1 h-1Z M46 15 h1 v1 h-1Z M48 15 h1 v1 h-1Z M4 16 h2 v1 h-2Z M7 16 h1 v1 h-1Z M9 16 h1 v1 h-1Z M11 16 h1 v1 h-1Z M13 16 h3 v1 h-3Z M18 16 h4 v1 h-4Z M27 16 h8 v1 h-8Z M39 16 h2 v1 h-2Z M43 16 h1 v1 h-1Z M45 16 h4 v1 h-4Z M4 17 h1 v1 h-1Z M9 17 h1 v1 h-1Z M11 17 h1 v1 h-1Z M13 17 h4 v1 h-4Z M18 17 h1 v1 h-1Z M21 17 h1 v1 h-1Z M23 17 h2 v1 h-2Z M26 17 h2 v1 h-2Z M29 17 h1 v1 h-1Z M31 17 h1 v1 h-1Z M34 17 h2 v1 h-2Z M40 17 h2 v1 h-2Z M47 17 h1 v1 h-1Z M5 18 h3 v1 h-3Z M11 18 h1 v1 h-1Z M17 18 h2 v1 h-2Z M21 18 h1 v1 h-1Z M27 18 h1 v1 h-1Z M29 18 h2 v1 h-2Z M32 18 h3 v1 h-3Z M37 18 h7 v1 h-7Z M46 18 h1 v1 h-1Z M4 19 h1 v1 h-1Z M6 19 h2 v1 h-2Z M12 19 h1 v1 h-1Z M14 19 h2 v1 h-2Z M20 19 h2 v1 h-2Z M25 19 h3 v1 h-3Z M29 19 h5 v1 h-5Z M36 19 h1 v1 h-1Z M38 19 h1 v1 h-1Z M40 19 h4 v1 h-4Z M45 19 h3 v1 h-3Z M7 20 h3 v1 h-3Z M13 20 h6 v1 h-6Z M22 20 h1 v1 h-1Z M27 20 h3 v1 h-3Z M35 20 h1 v1 h-1Z M37 20 h3 v1 h-3Z M41 20 h1 v1 h-1Z M44 20 h2 v1 h-2Z M6 21 h2 v1 h-2Z M13 21 h1 v1 h-1Z M15 21 h1 v1 h-1Z M17 21 h2 v1 h-2Z M20 21 h3 v1 h-3Z M24 21 h3 v1 h-3Z M30 21 h2 v1 h-2Z M33 21 h1 v1 h-1Z M38 21 h3 v1 h-3Z M43 21 h3 v1 h-3Z M48 21 h1 v1 h-1Z M4 22 h2 v1 h-2Z M8 22 h1 v1 h-1Z M11 22 h1 v1 h-1Z M13 22 h1 v1 h-1Z M18 22 h2 v1 h-2Z M22 22 h3 v1 h-3Z M27 22 h2 v1 h-2Z M30 22 h3 v1 h-3Z M34 22 h2 v1 h-2Z M37 22 h1 v1 h-1Z M40 22 h1 v1 h-1Z M42 22 h1 v1 h-1Z M44 22 h1 v1 h-1Z M5 23 h1 v1 h-1Z M8 23 h1 v1 h-1Z M13 23 h1 v1 h-1Z M15 23 h1 v1 h-1Z M17 23 h3 v1 h-3Z M23 23 h1 v1 h-1Z M28 23 h1 v1 h-1Z M32 23 h1 v1 h-1Z M34 23 h1 v1 h-1Z M36 23 h2 v1 h-2Z M43 23 h5 v1 h-5Z M6 24 h2 v1 h-2Z M15 24 h3 v1 h-3Z M19 24 h1 v1 h-1Z M21 24 h3 v1 h-3Z M29 24 h6 v1 h-6Z M48 24 h1 v1 h-1Z M13 25 h4 v1 h-4Z M19 25 h1 v1 h-1Z M21 25 h1 v1 h-1Z M23 25 h1 v1 h-1Z M29 25 h4 v1 h-4Z M34 25 h4 v1 h-4Z M39 25 h1 v1 h-1Z M45 25 h1 v1 h-1Z M48 25 h1 v1 h-1Z M4 26 h2 v1 h-2Z M13 26 h1 v1 h-1Z M15 26 h5 v1 h-5Z M21 26 h3 v1 h-3Z M30 26 h7 v1 h-7Z M47 26 h1 v1 h-1Z M4 27 h1 v1 h-1Z M6 27 h2 v1 h-2Z M13 27 h1 v1 h-1Z M23 27 h1 v1 h-1Z M29 27 h1 v1 h-1Z M31 27 h2 v1 h-2Z M34 27 h1 v1 h-1Z M38 27 h1 v1 h-1Z M45 27 h1 v1 h-1Z M4 28 h1 v1 h-1Z M6 28 h1 v1 h-1Z M17 28 h4 v1 h-4Z M22 28 h2 v1 h-2Z M32 28 h7 v1 h-7Z M46 28 h1 v1 h-1Z M48 28 h1 v1 h-1Z M4 29 h4 v1 h-4Z M9 29 h1 v1 h-1Z M12 29 h1 v1 h-1Z M14 29 h2 v1 h-2Z M17 29 h1 v1 h-1Z M21 29 h1 v1 h-1Z M23 29 h3 v1 h-3Z M27 29 h1 v1 h-1Z M36 29 h1 v1 h-1Z M38 29 h4 v1 h-4Z M46 29 h1 v1 h-1Z M4 30 h3 v1 h-3Z M11 30 h2 v1 h-2Z M16 30 h2 v1 h-2Z M21 30 h3 v1 h-3Z M26 30 h1 v1 h-1Z M29 30 h1 v1 h-1Z M33 30 h5 v1 h-5Z M39 30 h2 v1 h-2Z M44 30 h5 v1 h-5Z M4 31 h1 v1 h-1Z M7 31 h3 v1 h-3Z M12 31 h1 v1 h-1Z M17 31 h3 v1 h-3Z M21 31 h2 v1 h-2Z M29 31 h1 v1 h-1Z M31 31 h2 v1 h-2Z M35 31 h1 v1 h-1Z M38 31 h1 v1 h-1Z M41 31 h1 v1 h-1Z M44 31 h1 v1 h-1Z M46 31 h1 v1 h-1Z M48 31 h1 v1 h-1Z M4 32 h1 v1 h-1Z M6 32 h2 v1 h-2Z M11 32 h1 v1 h-1Z M19 32 h1 v1 h-1Z M21 32 h1 v1 h-1Z M26 32 h1 v1 h-1Z M28 32 h4 v1 h-4Z M33 32 h1 v1 h-1Z M38 32 h5 v1 h-5Z M44 32 h5 v1 h-5Z M4 33 h4 v1 h-4Z M15 33 h1 v1 h-1Z M18 33 h4 v1 h-4Z M24 33 h1 v1 h-1Z M26 33 h1 v1 h-1Z M29 33 h2 v1 h-2Z M35 33 h1 v1 h-1Z M39 33 h1 v1 h-1Z M42 33 h1 v1 h-1Z M45 33 h1 v1 h-1Z M47 33 h1 v1 h-1Z M6 34 h1 v1 h-1Z M11 34 h1 v1 h-1Z M15 34 h3 v1 h-3Z M20 34 h1 v1 h-1Z M22 34 h1 v1 h-1Z M24 34 h3 v1 h-3Z M28 34 h2 v1 h-2Z M33 34 h2 v1 h-2Z M37 34 h3 v1 h-3Z M41 34 h3 v1 h-3Z M12 35 h2 v1 h-2Z M15 35 h1 v1 h-1Z M17 35 h1 v1 h-1Z M20 35 h2 v1 h-2Z M23 35 h1 v1 h-1Z M26 35 h2 v1 h-2Z M29 35 h1 v1 h-1Z M31 35 h1 v1 h-1Z M37 35 h1 v1 h-1Z M40 35 h1 v1 h-1Z M45 35 h1 v1 h-1Z M47 35 h1 v1 h-1Z M4 36 h2 v1 h-2Z M11 36 h1 v1 h-1Z M13 36 h3 v1 h-3Z M18 36 h1 v1 h-1Z M20 36 h1 v1 h-1Z M25 36 h3 v1 h-3Z M32 36 h1 v1 h-1Z M35 36 h2 v1 h-2Z M38 36 h1 v1 h-1Z M46 36 h1 v1 h-1Z M4 37 h1 v1 h-1Z M6 37 h1 v1 h-1Z M8 37 h1 v1 h-1Z M12 37 h1 v1 h-1Z M14 37 h1 v1 h-1Z M16 37 h3 v1 h-3Z M21 37 h2 v1 h-2Z M25 37 h1 v1 h-1Z M28 37 h1 v1 h-1Z M31 37 h2 v1 h-2Z M34 37 h1 v1 h-1Z M36 37 h1 v1 h-1Z M40 37 h2 v1 h-2Z M43 37 h1 v1 h-1Z M45 37 h2 v1 h-2Z M11 38 h2 v1 h-2Z M14 38 h4 v1 h-4Z M19 38 h1 v1 h-1Z M21 38 h5 v1 h-5Z M27 38 h1 v1 h-1Z M35 38 h2 v1 h-2Z M38 38 h1 v1 h-1Z M40 38 h1 v1 h-1Z M46 38 h3 v1 h-3Z M12 39 h3 v1 h-3Z M16 39 h1 v1 h-1Z M19 39 h3 v1 h-3Z M25 39 h2 v1 h-2Z M31 39 h1 v1 h-1Z M35 39 h3 v1 h-3Z M41 39 h1 v1 h-1Z M43 39 h1 v1 h-1Z M45 39 h2 v1 h-2Z M48 39 h1 v1 h-1Z M11 40 h2 v1 h-2Z M14 40 h2 v1 h-2Z M17 40 h2 v1 h-2Z M21 40 h1 v1 h-1Z M23 40 h1 v1 h-1Z M32 40 h2 v1 h-2Z M35 40 h1 v1 h-1Z M39 40 h1 v1 h-1Z M45 40 h1 v1 h-1Z M47 40 h2 v1 h-2Z M14 41 h1 v1 h-1Z M17 41 h3 v1 h-3Z M31 41 h7 v1 h-7Z M46 41 h1 v1 h-1Z M48 41 h1 v1 h-1Z M14 42 h2 v1 h-2Z M18 42 h1 v1 h-1Z M20 42 h2 v1 h-2Z M29 42 h1 v1 h-1Z M33 42 h2 v1 h-2Z M39 42 h1 v1 h-1Z M45 42 h1 v1 h-1Z M47 42 h1 v1 h-1Z M13 43 h1 v1 h-1Z M15 43 h3 v1 h-3Z M20 43 h4 v1 h-4Z M29 43 h4 v1 h-4Z M36 43 h1 v1 h-1Z M38 43 h2 v1 h-2Z M45 43 h2 v1 h-2Z M48 43 h1 v1 h-1Z M17 44 h1 v1 h-1Z M22 44 h2 v1 h-2Z M31 44 h1 v1 h-1Z M34 44 h2 v1 h-2Z M37 44 h3 v1 h-3Z M47 44 h1 v1 h-1Z M13 45 h2 v1 h-2Z M22 45 h2 v1 h-2Z M27 45 h1 v1 h-1Z M29 45 h2 v1 h-2Z M33 45 h1 v1 h-1Z M35 45 h2 v1 h-2Z M38 45 h1 v1 h-1Z M43 45 h1 v1 h-1Z M46 45 h2 v1 h-2Z M13 46 h2 v1 h-2Z M17 46 h4 v1 h-4Z M22 46 h1 v1 h-1Z M24 46 h5 v1 h-5Z M30 46 h1 v1 h-1Z M33 46 h2 v1 h-2Z M36 46 h2 v1 h-2Z M39 46 h4 v1 h-4Z M44 46 h3 v1 h-3Z M14 47 h2 v1 h-2Z M21 47 h1 v1 h-1Z M24 47 h1 v1 h-1Z M31 47 h1 v1 h-1Z M33 47 h3 v1 h-3Z M37 47 h1 v1 h-1Z M39 47 h1 v1 h-1Z M43 47 h2 v1 h-2Z M46 47 h1 v1 h-1Z M14 48 h1 v1 h-1Z M20 48 h3 v1 h-3Z M24 48 h1 v1 h-1Z M26 48 h1 v1 h-1Z M29 48 h1 v1 h-1Z M31 48 h1 v1 h-1Z M33 48 h1 v1 h-1Z M39 48 h1 v1 h-1Z M41 48 h2 v1 h-2Z M44 48 h4 v1 h-4Z \" /\u003e\u003cpath class=\"qr-1536 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M4 4 h7 v1 h-7Z M42 4 h7 v1 h-7Z M4 5 h1 v1 h-1Z M10 5 h1 v1 h-1Z M42 5 h1 v1 h-1Z M48 5 h1 v1 h-1Z M4 6 h1 v1 h-1Z M10 6 h1 v1 h-1Z M42 6 h1 v1 h-1Z M48 6 h1 v1 h-1Z M4 7 h1 v1 h-1Z M10 7 h1 v1 h-1Z M42 7 h1 v1 h-1Z M48 7 h1 v1 h-1Z M4 8 h1 v1 h-1Z M10 8 h1 v1 h-1Z M42 8 h1 v1 h-1Z M48 8 h1 v1 h-1Z M4 9 h1 v1 h-1Z M10 9 h1 v1 h-1Z M42 9 h1 v1 h-1Z M48 9 h1 v1 h-1Z M4 10 h7 v1 h-7Z M42 10 h7 v1 h-7Z M4 42 h7 v1 h-7Z M4 43 h1 v1 h-1Z M10 43 h1 v1 h-1Z M4 44 h1 v1 h-1Z M10 44 h1 v1 h-1Z M4 45 h1 v1 h-1Z M10 45 h1 v1 h-1Z M4 46 h1 v1 h-1Z M10 46 h1 v1 h-1Z M4 47 h1 v1 h-1Z M10 47 h1 v1 h-1Z M4 48 h7 v1 h-7Z \" /\u003e\u003cpath class=\"qr-2560 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M24 8 h5 v1 h-5Z M24 9 h1 v1 h-1Z M28 9 h1 v1 h-1Z M24 10 h1 v1 h-1Z M26 10 h1 v1 h-1Z M28 10 h1 v1 h-1Z M24 11 h1 v1 h-1Z M28 11 h1 v1 h-1Z M24 12 h5 v1 h-5Z M8 24 h5 v1 h-5Z M24 24 h5 v1 h-5Z M40 24 h5 v1 h-5Z M8 25 h1 v1 h-1Z M12 25 h1 v1 h-1Z M24 25 h1 v1 h-1Z M28 25 h1 v1 h-1Z M40 25 h1 v1 h-1Z M44 25 h1 v1 h-1Z M8 26 h1 v1 h-1Z M10 26 h1 v1 h-1Z M12 26 h1 v1 h-1Z M24 26 h1 v1 h-1Z M26 26 h1 v1 h-1Z M28 26 h1 v1 h-1Z M40 26 h1 v1 h-1Z M42 26 h1 v1 h-1Z M44 26 h1 v1 h-1Z M8 27 h1 v1 h-1Z M12 27 h1 v1 h-1Z M24 27 h1 v1 h-1Z M28 27 h1 v1 h-1Z M40 27 h1 v1 h-1Z M44 27 h1 v1 h-1Z M8 28 h5 v1 h-5Z M24 28 h5 v1 h-5Z M40 28 h5 v1 h-5Z M24 40 h5 v1 h-5Z M40 40 h5 v1 h-5Z M24 41 h1 v1 h-1Z M28 41 h1 v1 h-1Z M40 41 h1 v1 h-1Z M44 41 h1 v1 h-1Z M24 42 h1 v1 h-1Z M26 42 h1 v1 h-1Z M28 42 h1 v1 h-1Z M40 42 h1 v1 h-1Z M42 42 h1 v1 h-1Z M44 42 h1 v1 h-1Z M24 43 h1 v1 h-1Z M28 43 h1 v1 h-1Z M40 43 h1 v1 h-1Z M44 43 h1 v1 h-1Z M24 44 h5 v1 h-5Z M40 44 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-3072 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 10 h1 v1 h-1Z M14 10 h1 v1 h-1Z M16 10 h1 v1 h-1Z M18 10 h1 v1 h-1Z M20 10 h1 v1 h-1Z M22 10 h1 v1 h-1Z M30 10 h1 v1 h-1Z M32 10 h1 v1 h-1Z M34 10 h1 v1 h-1Z M36 10 h1 v1 h-1Z M38 10 h1 v1 h-1Z M40 10 h1 v1 h-1Z M10 12 h1 v1 h-1Z M10 14 h1 v1 h-1Z M10 16 h1 v1 h-1Z M10 18 h1 v1 h-1Z M10 20 h1 v1 h-1Z M10 22 h1 v1 h-1Z M10 30 h1 v1 h-1Z M10 32 h1 v1 h-1Z M10 34 h1 v1 h-1Z M10 36 h1 v1 h-1Z M10 38 h1 v1 h-1Z M10 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-3584 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 4 h1 v1 h-1Z M12 5 h1 v1 h-1Z M12 6 h1 v1 h-1Z M12 9 h1 v1 h-1Z M12 11 h1 v1 h-1Z M6 12 h3 v1 h-3Z M12 12 h1 v1 h-1Z M41 12 h3 v1 h-3Z M46 12 h3 v1 h-3Z M12 44 h1 v1 h-1Z M12 45 h1 v1 h-1Z M12 46 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-4096 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M40 4 h1 v1 h-1Z M39 5 h1 v1 h-1Z M39 6 h1 v1 h-1Z M39 7 h2 v1 h-2Z M38 8 h3 v1 h-3Z M8 38 h1 v1 h-1Z M5 39 h4 v1 h-4Z M4 40 h1 v1 h-1Z M7 40 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-5632 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M6 6 h3 v1 h-3Z M44 6 h3 v1 h-3Z M6 7 h3 v1 h-3Z M44 7 h3 v1 h-3Z M6 8 h3 v1 h-3Z M44 8 h3 v1 h-3Z M6 44 h3 v1 h-3Z M6 45 h3 v1 h-3Z M6 46 h3 v1 h-3Z \" /\u003e\u003c/svg\u003e\n\n    \u003c/a\u003e\n    \u003cfigcaption aria-hidden=\"true\" class=\"hidden\" hidden\u003eOne Ko-fi for Stéphane HUC\u003c/figcaption\u003e\n\u003c/figure\u003e\n\n\n\u003ch3 id=\"liberapay\"\u003eLiberapay\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://fr.liberapay.com/HucSte/donate\" rel=\"external\"\u003ehttps://fr.liberapay.com/HucSte/donate\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\n\u003cfigure class=\"pure-img\"\u003e\n    \u003ca href=\"/svg/qrcode/liberapay.svg\" title=\"Donate for Stéphane HUC by Liberapay\"\u003e\n    \u003csvg xmlns=\"http://www.w3.org/2000/svg\" class=\"qr-svg \" height=\"128\" viewBox=\"0 0 53 53\" width=\"128\"\u003e\n\u003cdefs\u003e\u003cstyle\u003erect{shape-rendering:crispEdges}\u003c/style\u003e\u003c/defs\u003e\n\u003cpath class=\"qr-4 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M14 4 h2 v1 h-2Z M18 4 h1 v1 h-1Z M22 4 h5 v1 h-5Z M28 4 h1 v1 h-1Z M30 4 h2 v1 h-2Z M35 4 h1 v1 h-1Z M13 5 h1 v1 h-1Z M15 5 h2 v1 h-2Z M18 5 h1 v1 h-1Z M20 5 h1 v1 h-1Z M23 5 h1 v1 h-1Z M26 5 h3 v1 h-3Z M30 5 h2 v1 h-2Z M36 5 h1 v1 h-1Z M17 6 h1 v1 h-1Z M26 6 h1 v1 h-1Z M28 6 h2 v1 h-2Z M31 6 h2 v1 h-2Z M35 6 h3 v1 h-3Z M13 7 h3 v1 h-3Z M17 7 h3 v1 h-3Z M21 7 h8 v1 h-8Z M30 7 h1 v1 h-1Z M35 7 h2 v1 h-2Z M13 8 h1 v1 h-1Z M15 8 h2 v1 h-2Z M18 8 h3 v1 h-3Z M22 8 h2 v1 h-2Z M29 8 h2 v1 h-2Z M32 8 h1 v1 h-1Z M34 8 h1 v1 h-1Z M37 8 h1 v1 h-1Z M13 9 h1 v1 h-1Z M16 9 h2 v1 h-2Z M20 9 h1 v1 h-1Z M23 9 h1 v1 h-1Z M29 9 h1 v1 h-1Z M33 9 h1 v1 h-1Z M36 9 h1 v1 h-1Z M13 11 h1 v1 h-1Z M20 11 h4 v1 h-4Z M29 11 h1 v1 h-1Z M33 11 h3 v1 h-3Z M40 11 h1 v1 h-1Z M13 12 h1 v1 h-1Z M15 12 h4 v1 h-4Z M20 12 h1 v1 h-1Z M22 12 h2 v1 h-2Z M29 12 h1 v1 h-1Z M31 12 h5 v1 h-5Z M38 12 h3 v1 h-3Z M4 13 h3 v1 h-3Z M9 13 h1 v1 h-1Z M11 13 h2 v1 h-2Z M14 13 h2 v1 h-2Z M18 13 h2 v1 h-2Z M21 13 h1 v1 h-1Z M23 13 h1 v1 h-1Z M25 13 h1 v1 h-1Z M27 13 h3 v1 h-3Z M31 13 h2 v1 h-2Z M35 13 h1 v1 h-1Z M38 13 h1 v1 h-1Z M40 13 h1 v1 h-1Z M45 13 h1 v1 h-1Z M47 13 h2 v1 h-2Z M5 14 h4 v1 h-4Z M11 14 h1 v1 h-1Z M13 14 h4 v1 h-4Z M19 14 h1 v1 h-1Z M21 14 h2 v1 h-2Z M24 14 h1 v1 h-1Z M26 14 h1 v1 h-1Z M29 14 h1 v1 h-1Z M31 14 h1 v1 h-1Z M36 14 h2 v1 h-2Z M41 14 h1 v1 h-1Z M45 14 h2 v1 h-2Z M48 14 h1 v1 h-1Z M7 15 h1 v1 h-1Z M9 15 h1 v1 h-1Z M12 15 h2 v1 h-2Z M16 15 h4 v1 h-4Z M21 15 h1 v1 h-1Z M23 15 h3 v1 h-3Z M27 15 h2 v1 h-2Z M31 15 h5 v1 h-5Z M37 15 h2 v1 h-2Z M42 15 h1 v1 h-1Z M45 15 h2 v1 h-2Z M7 16 h1 v1 h-1Z M11 16 h3 v1 h-3Z M17 16 h1 v1 h-1Z M19 16 h1 v1 h-1Z M22 16 h3 v1 h-3Z M26 16 h2 v1 h-2Z M31 16 h2 v1 h-2Z M36 16 h7 v1 h-7Z M44 16 h1 v1 h-1Z M4 17 h3 v1 h-3Z M8 17 h1 v1 h-1Z M11 17 h1 v1 h-1Z M13 17 h1 v1 h-1Z M15 17 h2 v1 h-2Z M18 17 h4 v1 h-4Z M24 17 h4 v1 h-4Z M31 17 h2 v1 h-2Z M34 17 h1 v1 h-1Z M37 17 h4 v1 h-4Z M44 17 h1 v1 h-1Z M48 17 h1 v1 h-1Z M4 18 h2 v1 h-2Z M8 18 h2 v1 h-2Z M11 18 h1 v1 h-1Z M16 18 h2 v1 h-2Z M19 18 h3 v1 h-3Z M23 18 h3 v1 h-3Z M27 18 h3 v1 h-3Z M31 18 h1 v1 h-1Z M34 18 h1 v1 h-1Z M36 18 h3 v1 h-3Z M41 18 h1 v1 h-1Z M43 18 h1 v1 h-1Z M45 18 h4 v1 h-4Z M8 19 h2 v1 h-2Z M11 19 h1 v1 h-1Z M13 19 h1 v1 h-1Z M15 19 h1 v1 h-1Z M17 19 h1 v1 h-1Z M19 19 h1 v1 h-1Z M21 19 h1 v1 h-1Z M24 19 h1 v1 h-1Z M32 19 h1 v1 h-1Z M34 19 h2 v1 h-2Z M37 19 h2 v1 h-2Z M40 19 h4 v1 h-4Z M47 19 h2 v1 h-2Z M5 20 h2 v1 h-2Z M9 20 h1 v1 h-1Z M12 20 h2 v1 h-2Z M16 20 h2 v1 h-2Z M20 20 h1 v1 h-1Z M24 20 h2 v1 h-2Z M27 20 h4 v1 h-4Z M37 20 h3 v1 h-3Z M44 20 h2 v1 h-2Z M47 20 h2 v1 h-2Z M4 21 h1 v1 h-1Z M6 21 h2 v1 h-2Z M9 21 h1 v1 h-1Z M13 21 h1 v1 h-1Z M18 21 h1 v1 h-1Z M20 21 h1 v1 h-1Z M23 21 h1 v1 h-1Z M25 21 h1 v1 h-1Z M27 21 h3 v1 h-3Z M31 21 h1 v1 h-1Z M35 21 h1 v1 h-1Z M40 21 h3 v1 h-3Z M44 21 h3 v1 h-3Z M4 22 h1 v1 h-1Z M7 22 h1 v1 h-1Z M9 22 h1 v1 h-1Z M11 22 h8 v1 h-8Z M20 22 h1 v1 h-1Z M22 22 h1 v1 h-1Z M24 22 h2 v1 h-2Z M32 22 h2 v1 h-2Z M44 22 h3 v1 h-3Z M48 22 h1 v1 h-1Z M8 23 h2 v1 h-2Z M11 23 h1 v1 h-1Z M14 23 h2 v1 h-2Z M18 23 h4 v1 h-4Z M23 23 h2 v1 h-2Z M26 23 h1 v1 h-1Z M28 23 h5 v1 h-5Z M34 23 h5 v1 h-5Z M40 23 h1 v1 h-1Z M43 23 h1 v1 h-1Z M45 23 h2 v1 h-2Z M5 24 h2 v1 h-2Z M16 24 h3 v1 h-3Z M20 24 h1 v1 h-1Z M22 24 h2 v1 h-2Z M29 24 h1 v1 h-1Z M31 24 h1 v1 h-1Z M34 24 h1 v1 h-1Z M36 24 h1 v1 h-1Z M39 24 h1 v1 h-1Z M45 24 h1 v1 h-1Z M4 25 h2 v1 h-2Z M7 25 h1 v1 h-1Z M13 25 h7 v1 h-7Z M21 25 h3 v1 h-3Z M29 25 h2 v1 h-2Z M33 25 h1 v1 h-1Z M35 25 h1 v1 h-1Z M38 25 h1 v1 h-1Z M47 25 h1 v1 h-1Z M4 26 h1 v1 h-1Z M13 26 h4 v1 h-4Z M18 26 h1 v1 h-1Z M20 26 h1 v1 h-1Z M23 26 h1 v1 h-1Z M30 26 h2 v1 h-2Z M33 26 h3 v1 h-3Z M38 26 h1 v1 h-1Z M45 26 h2 v1 h-2Z M6 27 h1 v1 h-1Z M13 27 h1 v1 h-1Z M15 27 h1 v1 h-1Z M18 27 h1 v1 h-1Z M21 27 h2 v1 h-2Z M30 27 h1 v1 h-1Z M33 27 h2 v1 h-2Z M36 27 h1 v1 h-1Z M38 27 h2 v1 h-2Z M46 27 h1 v1 h-1Z M4 28 h1 v1 h-1Z M7 28 h1 v1 h-1Z M15 28 h2 v1 h-2Z M20 28 h1 v1 h-1Z M23 28 h1 v1 h-1Z M30 28 h1 v1 h-1Z M32 28 h3 v1 h-3Z M39 28 h1 v1 h-1Z M45 28 h2 v1 h-2Z M48 28 h1 v1 h-1Z M5 29 h4 v1 h-4Z M11 29 h5 v1 h-5Z M19 29 h2 v1 h-2Z M23 29 h1 v1 h-1Z M25 29 h1 v1 h-1Z M28 29 h3 v1 h-3Z M32 29 h2 v1 h-2Z M35 29 h2 v1 h-2Z M39 29 h3 v1 h-3Z M44 29 h1 v1 h-1Z M46 29 h2 v1 h-2Z M9 30 h1 v1 h-1Z M11 30 h1 v1 h-1Z M13 30 h1 v1 h-1Z M15 30 h3 v1 h-3Z M23 30 h2 v1 h-2Z M26 30 h3 v1 h-3Z M30 30 h1 v1 h-1Z M32 30 h1 v1 h-1Z M35 30 h1 v1 h-1Z M37 30 h1 v1 h-1Z M40 30 h5 v1 h-5Z M46 30 h2 v1 h-2Z M5 31 h2 v1 h-2Z M11 31 h1 v1 h-1Z M14 31 h5 v1 h-5Z M20 31 h1 v1 h-1Z M22 31 h1 v1 h-1Z M25 31 h4 v1 h-4Z M33 31 h1 v1 h-1Z M36 31 h2 v1 h-2Z M39 31 h3 v1 h-3Z M44 31 h2 v1 h-2Z M47 31 h1 v1 h-1Z M5 32 h1 v1 h-1Z M7 32 h3 v1 h-3Z M12 32 h2 v1 h-2Z M16 32 h1 v1 h-1Z M22 32 h1 v1 h-1Z M28 32 h1 v1 h-1Z M31 32 h3 v1 h-3Z M35 32 h1 v1 h-1Z M39 32 h2 v1 h-2Z M42 32 h1 v1 h-1Z M45 32 h2 v1 h-2Z M48 32 h1 v1 h-1Z M7 33 h2 v1 h-2Z M13 33 h1 v1 h-1Z M17 33 h2 v1 h-2Z M20 33 h1 v1 h-1Z M22 33 h1 v1 h-1Z M24 33 h1 v1 h-1Z M26 33 h2 v1 h-2Z M34 33 h3 v1 h-3Z M48 33 h1 v1 h-1Z M4 34 h6 v1 h-6Z M11 34 h4 v1 h-4Z M16 34 h4 v1 h-4Z M21 34 h1 v1 h-1Z M23 34 h1 v1 h-1Z M25 34 h3 v1 h-3Z M31 34 h3 v1 h-3Z M35 34 h2 v1 h-2Z M40 34 h1 v1 h-1Z M44 34 h5 v1 h-5Z M5 35 h2 v1 h-2Z M8 35 h1 v1 h-1Z M11 35 h2 v1 h-2Z M16 35 h1 v1 h-1Z M19 35 h1 v1 h-1Z M21 35 h1 v1 h-1Z M23 35 h5 v1 h-5Z M31 35 h2 v1 h-2Z M34 35 h3 v1 h-3Z M40 35 h2 v1 h-2Z M44 35 h2 v1 h-2Z M4 36 h4 v1 h-4Z M9 36 h1 v1 h-1Z M15 36 h4 v1 h-4Z M20 36 h2 v1 h-2Z M24 36 h1 v1 h-1Z M30 36 h2 v1 h-2Z M35 36 h5 v1 h-5Z M42 36 h1 v1 h-1Z M45 36 h4 v1 h-4Z M5 37 h1 v1 h-1Z M9 37 h1 v1 h-1Z M12 37 h2 v1 h-2Z M15 37 h1 v1 h-1Z M17 37 h2 v1 h-2Z M20 37 h1 v1 h-1Z M23 37 h2 v1 h-2Z M26 37 h2 v1 h-2Z M29 37 h2 v1 h-2Z M32 37 h2 v1 h-2Z M35 37 h1 v1 h-1Z M37 37 h3 v1 h-3Z M42 37 h1 v1 h-1Z M44 37 h1 v1 h-1Z M47 37 h2 v1 h-2Z M12 38 h1 v1 h-1Z M17 38 h1 v1 h-1Z M20 38 h1 v1 h-1Z M22 38 h1 v1 h-1Z M24 38 h1 v1 h-1Z M26 38 h4 v1 h-4Z M32 38 h1 v1 h-1Z M36 38 h2 v1 h-2Z M40 38 h2 v1 h-2Z M44 38 h1 v1 h-1Z M46 38 h1 v1 h-1Z M11 39 h1 v1 h-1Z M13 39 h2 v1 h-2Z M17 39 h1 v1 h-1Z M19 39 h4 v1 h-4Z M24 39 h1 v1 h-1Z M28 39 h1 v1 h-1Z M30 39 h3 v1 h-3Z M38 39 h1 v1 h-1Z M40 39 h4 v1 h-4Z M46 39 h2 v1 h-2Z M13 40 h1 v1 h-1Z M15 40 h3 v1 h-3Z M19 40 h3 v1 h-3Z M29 40 h3 v1 h-3Z M36 40 h2 v1 h-2Z M39 40 h1 v1 h-1Z M46 40 h1 v1 h-1Z M15 41 h7 v1 h-7Z M23 41 h1 v1 h-1Z M29 41 h1 v1 h-1Z M32 41 h1 v1 h-1Z M36 41 h1 v1 h-1Z M38 41 h2 v1 h-2Z M45 41 h4 v1 h-4Z M13 42 h1 v1 h-1Z M16 42 h1 v1 h-1Z M20 42 h4 v1 h-4Z M32 42 h3 v1 h-3Z M36 42 h4 v1 h-4Z M46 42 h3 v1 h-3Z M16 43 h2 v1 h-2Z M19 43 h1 v1 h-1Z M23 43 h1 v1 h-1Z M29 43 h2 v1 h-2Z M32 43 h3 v1 h-3Z M37 43 h1 v1 h-1Z M47 43 h2 v1 h-2Z M14 44 h1 v1 h-1Z M17 44 h4 v1 h-4Z M23 44 h1 v1 h-1Z M29 44 h1 v1 h-1Z M31 44 h1 v1 h-1Z M34 44 h1 v1 h-1Z M37 44 h1 v1 h-1Z M45 44 h1 v1 h-1Z M48 44 h1 v1 h-1Z M14 45 h2 v1 h-2Z M17 45 h1 v1 h-1Z M19 45 h1 v1 h-1Z M23 45 h6 v1 h-6Z M30 45 h3 v1 h-3Z M38 45 h2 v1 h-2Z M42 45 h2 v1 h-2Z M45 45 h2 v1 h-2Z M13 46 h1 v1 h-1Z M19 46 h4 v1 h-4Z M25 46 h3 v1 h-3Z M29 46 h1 v1 h-1Z M31 46 h2 v1 h-2Z M36 46 h1 v1 h-1Z M38 46 h1 v1 h-1Z M43 46 h1 v1 h-1Z M46 46 h3 v1 h-3Z M14 47 h1 v1 h-1Z M16 47 h2 v1 h-2Z M21 47 h1 v1 h-1Z M27 47 h7 v1 h-7Z M37 47 h2 v1 h-2Z M40 47 h2 v1 h-2Z M43 47 h1 v1 h-1Z M45 47 h3 v1 h-3Z M13 48 h1 v1 h-1Z M15 48 h1 v1 h-1Z M18 48 h1 v1 h-1Z M20 48 h1 v1 h-1Z M22 48 h3 v1 h-3Z M29 48 h2 v1 h-2Z M32 48 h1 v1 h-1Z M34 48 h1 v1 h-1Z M36 48 h1 v1 h-1Z M39 48 h3 v1 h-3Z M44 48 h1 v1 h-1Z M46 48 h3 v1 h-3Z \" /\u003e\u003cpath class=\"qr-6 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M5 5 h5 v1 h-5Z M43 5 h5 v1 h-5Z M5 6 h1 v1 h-1Z M9 6 h1 v1 h-1Z M43 6 h1 v1 h-1Z M47 6 h1 v1 h-1Z M5 7 h1 v1 h-1Z M9 7 h1 v1 h-1Z M43 7 h1 v1 h-1Z M47 7 h1 v1 h-1Z M5 8 h1 v1 h-1Z M9 8 h1 v1 h-1Z M43 8 h1 v1 h-1Z M47 8 h1 v1 h-1Z M5 9 h5 v1 h-5Z M43 9 h5 v1 h-5Z M5 43 h5 v1 h-5Z M5 44 h1 v1 h-1Z M9 44 h1 v1 h-1Z M5 45 h1 v1 h-1Z M9 45 h1 v1 h-1Z M5 46 h1 v1 h-1Z M9 46 h1 v1 h-1Z M5 47 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-8 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M11 4 h1 v1 h-1Z M41 4 h1 v1 h-1Z M11 5 h1 v1 h-1Z M41 5 h1 v1 h-1Z M11 6 h1 v1 h-1Z M41 6 h1 v1 h-1Z M11 7 h1 v1 h-1Z M41 7 h1 v1 h-1Z M11 8 h1 v1 h-1Z M41 8 h1 v1 h-1Z M11 9 h1 v1 h-1Z M41 9 h1 v1 h-1Z M11 10 h1 v1 h-1Z M41 10 h1 v1 h-1Z M4 11 h8 v1 h-8Z M41 11 h8 v1 h-8Z M4 41 h8 v1 h-8Z M11 42 h1 v1 h-1Z M11 43 h1 v1 h-1Z M11 44 h1 v1 h-1Z M11 45 h1 v1 h-1Z M11 46 h1 v1 h-1Z M11 47 h1 v1 h-1Z M11 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-10 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M25 9 h3 v1 h-3Z M25 10 h1 v1 h-1Z M27 10 h1 v1 h-1Z M25 11 h3 v1 h-3Z M9 25 h3 v1 h-3Z M25 25 h3 v1 h-3Z M41 25 h3 v1 h-3Z M9 26 h1 v1 h-1Z M11 26 h1 v1 h-1Z M25 26 h1 v1 h-1Z M27 26 h1 v1 h-1Z M41 26 h1 v1 h-1Z M43 26 h1 v1 h-1Z M9 27 h3 v1 h-3Z M25 27 h3 v1 h-3Z M41 27 h3 v1 h-3Z M25 41 h3 v1 h-3Z M41 41 h3 v1 h-3Z M25 42 h1 v1 h-1Z M27 42 h1 v1 h-1Z M41 42 h1 v1 h-1Z M43 42 h1 v1 h-1Z M25 43 h3 v1 h-3Z M41 43 h3 v1 h-3Z \" /\u003e\u003cpath class=\"qr-12 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M13 10 h1 v1 h-1Z M15 10 h1 v1 h-1Z M17 10 h1 v1 h-1Z M19 10 h1 v1 h-1Z M21 10 h1 v1 h-1Z M23 10 h1 v1 h-1Z M29 10 h1 v1 h-1Z M31 10 h1 v1 h-1Z M33 10 h1 v1 h-1Z M35 10 h1 v1 h-1Z M37 10 h1 v1 h-1Z M39 10 h1 v1 h-1Z M10 13 h1 v1 h-1Z M10 15 h1 v1 h-1Z M10 17 h1 v1 h-1Z M10 19 h1 v1 h-1Z M10 21 h1 v1 h-1Z M10 23 h1 v1 h-1Z M10 29 h1 v1 h-1Z M10 31 h1 v1 h-1Z M10 33 h1 v1 h-1Z M10 35 h1 v1 h-1Z M10 37 h1 v1 h-1Z M10 39 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-14 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M12 4 h1 v1 h-1Z M12 5 h1 v1 h-1Z M12 6 h1 v1 h-1Z M12 7 h1 v1 h-1Z M12 9 h1 v1 h-1Z M4 12 h2 v1 h-2Z M8 12 h2 v1 h-2Z M43 12 h1 v1 h-1Z M45 12 h4 v1 h-4Z M12 43 h1 v1 h-1Z M12 44 h1 v1 h-1Z M12 47 h1 v1 h-1Z M12 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-16 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M38 4 h2 v1 h-2Z M38 5 h1 v1 h-1Z M40 5 h1 v1 h-1Z M38 6 h1 v1 h-1Z M40 6 h1 v1 h-1Z M38 7 h1 v1 h-1Z M38 9 h3 v1 h-3Z M4 38 h4 v1 h-4Z M9 38 h1 v1 h-1Z M4 39 h1 v1 h-1Z M9 39 h1 v1 h-1Z M5 40 h2 v1 h-2Z M9 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-18 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M0 0 h53 v1 h-53Z M0 1 h53 v1 h-53Z M0 2 h53 v1 h-53Z M0 3 h53 v1 h-53Z M0 4 h4 v1 h-4Z M49 4 h4 v1 h-4Z M0 5 h4 v1 h-4Z M49 5 h4 v1 h-4Z M0 6 h4 v1 h-4Z M49 6 h4 v1 h-4Z M0 7 h4 v1 h-4Z M49 7 h4 v1 h-4Z M0 8 h4 v1 h-4Z M49 8 h4 v1 h-4Z M0 9 h4 v1 h-4Z M49 9 h4 v1 h-4Z M0 10 h4 v1 h-4Z M49 10 h4 v1 h-4Z M0 11 h4 v1 h-4Z M49 11 h4 v1 h-4Z M0 12 h4 v1 h-4Z M49 12 h4 v1 h-4Z M0 13 h4 v1 h-4Z M49 13 h4 v1 h-4Z M0 14 h4 v1 h-4Z M49 14 h4 v1 h-4Z M0 15 h4 v1 h-4Z M49 15 h4 v1 h-4Z M0 16 h4 v1 h-4Z M49 16 h4 v1 h-4Z M0 17 h4 v1 h-4Z M49 17 h4 v1 h-4Z M0 18 h4 v1 h-4Z M49 18 h4 v1 h-4Z M0 19 h4 v1 h-4Z M49 19 h4 v1 h-4Z M0 20 h4 v1 h-4Z M49 20 h4 v1 h-4Z M0 21 h4 v1 h-4Z M49 21 h4 v1 h-4Z M0 22 h4 v1 h-4Z M49 22 h4 v1 h-4Z M0 23 h4 v1 h-4Z M49 23 h4 v1 h-4Z M0 24 h4 v1 h-4Z M49 24 h4 v1 h-4Z M0 25 h4 v1 h-4Z M49 25 h4 v1 h-4Z M0 26 h4 v1 h-4Z M49 26 h4 v1 h-4Z M0 27 h4 v1 h-4Z M49 27 h4 v1 h-4Z M0 28 h4 v1 h-4Z M49 28 h4 v1 h-4Z M0 29 h4 v1 h-4Z M49 29 h4 v1 h-4Z M0 30 h4 v1 h-4Z M49 30 h4 v1 h-4Z M0 31 h4 v1 h-4Z M49 31 h4 v1 h-4Z M0 32 h4 v1 h-4Z M49 32 h4 v1 h-4Z M0 33 h4 v1 h-4Z M49 33 h4 v1 h-4Z M0 34 h4 v1 h-4Z M49 34 h4 v1 h-4Z M0 35 h4 v1 h-4Z M49 35 h4 v1 h-4Z M0 36 h4 v1 h-4Z M49 36 h4 v1 h-4Z M0 37 h4 v1 h-4Z M49 37 h4 v1 h-4Z M0 38 h4 v1 h-4Z M49 38 h4 v1 h-4Z M0 39 h4 v1 h-4Z M49 39 h4 v1 h-4Z M0 40 h4 v1 h-4Z M49 40 h4 v1 h-4Z M0 41 h4 v1 h-4Z M49 41 h4 v1 h-4Z M0 42 h4 v1 h-4Z M49 42 h4 v1 h-4Z M0 43 h4 v1 h-4Z M49 43 h4 v1 h-4Z M0 44 h4 v1 h-4Z M49 44 h4 v1 h-4Z M0 45 h4 v1 h-4Z M49 45 h4 v1 h-4Z M0 46 h4 v1 h-4Z M49 46 h4 v1 h-4Z M0 47 h4 v1 h-4Z M49 47 h4 v1 h-4Z M0 48 h4 v1 h-4Z M49 48 h4 v1 h-4Z M0 49 h53 v1 h-53Z M0 50 h53 v1 h-53Z M0 51 h53 v1 h-53Z M0 52 h53 v1 h-53Z \" /\u003e\u003cpath class=\"qr-512 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 41 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-1024 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M13 4 h1 v1 h-1Z M16 4 h2 v1 h-2Z M19 4 h3 v1 h-3Z M27 4 h1 v1 h-1Z M29 4 h1 v1 h-1Z M32 4 h3 v1 h-3Z M36 4 h2 v1 h-2Z M14 5 h1 v1 h-1Z M17 5 h1 v1 h-1Z M19 5 h1 v1 h-1Z M21 5 h2 v1 h-2Z M24 5 h2 v1 h-2Z M29 5 h1 v1 h-1Z M32 5 h4 v1 h-4Z M37 5 h1 v1 h-1Z M13 6 h4 v1 h-4Z M18 6 h8 v1 h-8Z M27 6 h1 v1 h-1Z M30 6 h1 v1 h-1Z M33 6 h2 v1 h-2Z M16 7 h1 v1 h-1Z M20 7 h1 v1 h-1Z M29 7 h1 v1 h-1Z M31 7 h4 v1 h-4Z M37 7 h1 v1 h-1Z M14 8 h1 v1 h-1Z M17 8 h1 v1 h-1Z M21 8 h1 v1 h-1Z M31 8 h1 v1 h-1Z M33 8 h1 v1 h-1Z M35 8 h2 v1 h-2Z M14 9 h2 v1 h-2Z M18 9 h2 v1 h-2Z M21 9 h2 v1 h-2Z M30 9 h3 v1 h-3Z M34 9 h2 v1 h-2Z M37 9 h1 v1 h-1Z M14 11 h6 v1 h-6Z M30 11 h3 v1 h-3Z M36 11 h4 v1 h-4Z M14 12 h1 v1 h-1Z M19 12 h1 v1 h-1Z M21 12 h1 v1 h-1Z M30 12 h1 v1 h-1Z M36 12 h2 v1 h-2Z M7 13 h2 v1 h-2Z M13 13 h1 v1 h-1Z M16 13 h2 v1 h-2Z M20 13 h1 v1 h-1Z M22 13 h1 v1 h-1Z M24 13 h1 v1 h-1Z M26 13 h1 v1 h-1Z M30 13 h1 v1 h-1Z M33 13 h2 v1 h-2Z M36 13 h2 v1 h-2Z M39 13 h1 v1 h-1Z M41 13 h4 v1 h-4Z M46 13 h1 v1 h-1Z M4 14 h1 v1 h-1Z M9 14 h1 v1 h-1Z M12 14 h1 v1 h-1Z M17 14 h2 v1 h-2Z M20 14 h1 v1 h-1Z M23 14 h1 v1 h-1Z M25 14 h1 v1 h-1Z M27 14 h2 v1 h-2Z M30 14 h1 v1 h-1Z M32 14 h4 v1 h-4Z M38 14 h3 v1 h-3Z M42 14 h3 v1 h-3Z M47 14 h1 v1 h-1Z M4 15 h3 v1 h-3Z M8 15 h1 v1 h-1Z M11 15 h1 v1 h-1Z M14 15 h2 v1 h-2Z M20 15 h1 v1 h-1Z M22 15 h1 v1 h-1Z M26 15 h1 v1 h-1Z M29 15 h2 v1 h-2Z M36 15 h1 v1 h-1Z M39 15 h3 v1 h-3Z M43 15 h2 v1 h-2Z M47 15 h2 v1 h-2Z M4 16 h3 v1 h-3Z M8 16 h2 v1 h-2Z M14 16 h3 v1 h-3Z M18 16 h1 v1 h-1Z M20 16 h2 v1 h-2Z M25 16 h1 v1 h-1Z M28 16 h3 v1 h-3Z M33 16 h3 v1 h-3Z M43 16 h1 v1 h-1Z M45 16 h4 v1 h-4Z M7 17 h1 v1 h-1Z M9 17 h1 v1 h-1Z M12 17 h1 v1 h-1Z M14 17 h1 v1 h-1Z M17 17 h1 v1 h-1Z M22 17 h2 v1 h-2Z M28 17 h3 v1 h-3Z M33 17 h1 v1 h-1Z M35 17 h2 v1 h-2Z M41 17 h3 v1 h-3Z M45 17 h3 v1 h-3Z M6 18 h2 v1 h-2Z M12 18 h4 v1 h-4Z M18 18 h1 v1 h-1Z M22 18 h1 v1 h-1Z M26 18 h1 v1 h-1Z M30 18 h1 v1 h-1Z M32 18 h2 v1 h-2Z M35 18 h1 v1 h-1Z M39 18 h2 v1 h-2Z M42 18 h1 v1 h-1Z M44 18 h1 v1 h-1Z M4 19 h4 v1 h-4Z M12 19 h1 v1 h-1Z M14 19 h1 v1 h-1Z M16 19 h1 v1 h-1Z M18 19 h1 v1 h-1Z M20 19 h1 v1 h-1Z M22 19 h2 v1 h-2Z M25 19 h7 v1 h-7Z M33 19 h1 v1 h-1Z M36 19 h1 v1 h-1Z M39 19 h1 v1 h-1Z M44 19 h3 v1 h-3Z M4 20 h1 v1 h-1Z M7 20 h2 v1 h-2Z M11 20 h1 v1 h-1Z M14 20 h2 v1 h-2Z M18 20 h2 v1 h-2Z M21 20 h3 v1 h-3Z M26 20 h1 v1 h-1Z M31 20 h6 v1 h-6Z M40 20 h4 v1 h-4Z M46 20 h1 v1 h-1Z M5 21 h1 v1 h-1Z M8 21 h1 v1 h-1Z M11 21 h2 v1 h-2Z M14 21 h4 v1 h-4Z M19 21 h1 v1 h-1Z M21 21 h2 v1 h-2Z M24 21 h1 v1 h-1Z M26 21 h1 v1 h-1Z M30 21 h1 v1 h-1Z M32 21 h3 v1 h-3Z M36 21 h4 v1 h-4Z M43 21 h1 v1 h-1Z M47 21 h2 v1 h-2Z M5 22 h2 v1 h-2Z M8 22 h1 v1 h-1Z M19 22 h1 v1 h-1Z M21 22 h1 v1 h-1Z M23 22 h1 v1 h-1Z M26 22 h6 v1 h-6Z M34 22 h10 v1 h-10Z M47 22 h1 v1 h-1Z M4 23 h4 v1 h-4Z M12 23 h2 v1 h-2Z M16 23 h2 v1 h-2Z M22 23 h1 v1 h-1Z M25 23 h1 v1 h-1Z M27 23 h1 v1 h-1Z M33 23 h1 v1 h-1Z M39 23 h1 v1 h-1Z M41 23 h2 v1 h-2Z M44 23 h1 v1 h-1Z M47 23 h2 v1 h-2Z M4 24 h1 v1 h-1Z M7 24 h1 v1 h-1Z M13 24 h3 v1 h-3Z M19 24 h1 v1 h-1Z M21 24 h1 v1 h-1Z M30 24 h1 v1 h-1Z M32 24 h2 v1 h-2Z M35 24 h1 v1 h-1Z M37 24 h2 v1 h-2Z M46 24 h3 v1 h-3Z M6 25 h1 v1 h-1Z M20 25 h1 v1 h-1Z M31 25 h2 v1 h-2Z M34 25 h1 v1 h-1Z M36 25 h2 v1 h-2Z M39 25 h1 v1 h-1Z M45 25 h2 v1 h-2Z M48 25 h1 v1 h-1Z M5 26 h3 v1 h-3Z M17 26 h1 v1 h-1Z M19 26 h1 v1 h-1Z M21 26 h2 v1 h-2Z M29 26 h1 v1 h-1Z M32 26 h1 v1 h-1Z M36 26 h2 v1 h-2Z M39 26 h1 v1 h-1Z M47 26 h2 v1 h-2Z M4 27 h2 v1 h-2Z M7 27 h1 v1 h-1Z M14 27 h1 v1 h-1Z M16 27 h2 v1 h-2Z M19 27 h2 v1 h-2Z M23 27 h1 v1 h-1Z M29 27 h1 v1 h-1Z M31 27 h2 v1 h-2Z M35 27 h1 v1 h-1Z M37 27 h1 v1 h-1Z M45 27 h1 v1 h-1Z M47 27 h2 v1 h-2Z M5 28 h2 v1 h-2Z M13 28 h2 v1 h-2Z M17 28 h3 v1 h-3Z M21 28 h2 v1 h-2Z M29 28 h1 v1 h-1Z M31 28 h1 v1 h-1Z M35 28 h4 v1 h-4Z M47 28 h1 v1 h-1Z M4 29 h1 v1 h-1Z M9 29 h1 v1 h-1Z M16 29 h3 v1 h-3Z M21 29 h2 v1 h-2Z M24 29 h1 v1 h-1Z M26 29 h2 v1 h-2Z M31 29 h1 v1 h-1Z M34 29 h1 v1 h-1Z M37 29 h2 v1 h-2Z M42 29 h2 v1 h-2Z M45 29 h1 v1 h-1Z M48 29 h1 v1 h-1Z M4 30 h5 v1 h-5Z M12 30 h1 v1 h-1Z M14 30 h1 v1 h-1Z M18 30 h5 v1 h-5Z M25 30 h1 v1 h-1Z M29 30 h1 v1 h-1Z M31 30 h1 v1 h-1Z M33 30 h2 v1 h-2Z M36 30 h1 v1 h-1Z M38 30 h2 v1 h-2Z M45 30 h1 v1 h-1Z M48 30 h1 v1 h-1Z M4 31 h1 v1 h-1Z M7 31 h3 v1 h-3Z M12 31 h2 v1 h-2Z M19 31 h1 v1 h-1Z M21 31 h1 v1 h-1Z M23 31 h2 v1 h-2Z M29 31 h4 v1 h-4Z M34 31 h2 v1 h-2Z M38 31 h1 v1 h-1Z M42 31 h2 v1 h-2Z M46 31 h1 v1 h-1Z M48 31 h1 v1 h-1Z M4 32 h1 v1 h-1Z M6 32 h1 v1 h-1Z M11 32 h1 v1 h-1Z M14 32 h2 v1 h-2Z M17 32 h5 v1 h-5Z M23 32 h5 v1 h-5Z M29 32 h2 v1 h-2Z M34 32 h1 v1 h-1Z M36 32 h3 v1 h-3Z M41 32 h1 v1 h-1Z M43 32 h2 v1 h-2Z M47 32 h1 v1 h-1Z M4 33 h3 v1 h-3Z M9 33 h1 v1 h-1Z M11 33 h2 v1 h-2Z M14 33 h3 v1 h-3Z M19 33 h1 v1 h-1Z M21 33 h1 v1 h-1Z M23 33 h1 v1 h-1Z M25 33 h1 v1 h-1Z M28 33 h6 v1 h-6Z M37 33 h11 v1 h-11Z M15 34 h1 v1 h-1Z M20 34 h1 v1 h-1Z M22 34 h1 v1 h-1Z M24 34 h1 v1 h-1Z M28 34 h3 v1 h-3Z M34 34 h1 v1 h-1Z M37 34 h3 v1 h-3Z M41 34 h3 v1 h-3Z M4 35 h1 v1 h-1Z M7 35 h1 v1 h-1Z M9 35 h1 v1 h-1Z M13 35 h3 v1 h-3Z M17 35 h2 v1 h-2Z M20 35 h1 v1 h-1Z M22 35 h1 v1 h-1Z M28 35 h3 v1 h-3Z M33 35 h1 v1 h-1Z M37 35 h3 v1 h-3Z M42 35 h2 v1 h-2Z M46 35 h3 v1 h-3Z M8 36 h1 v1 h-1Z M11 36 h4 v1 h-4Z M19 36 h1 v1 h-1Z M22 36 h2 v1 h-2Z M25 36 h5 v1 h-5Z M32 36 h3 v1 h-3Z M40 36 h2 v1 h-2Z M43 36 h2 v1 h-2Z M4 37 h1 v1 h-1Z M6 37 h3 v1 h-3Z M11 37 h1 v1 h-1Z M14 37 h1 v1 h-1Z M16 37 h1 v1 h-1Z M19 37 h1 v1 h-1Z M21 37 h2 v1 h-2Z M25 37 h1 v1 h-1Z M28 37 h1 v1 h-1Z M31 37 h1 v1 h-1Z M34 37 h1 v1 h-1Z M36 37 h1 v1 h-1Z M40 37 h2 v1 h-2Z M43 37 h1 v1 h-1Z M45 37 h2 v1 h-2Z M11 38 h1 v1 h-1Z M13 38 h4 v1 h-4Z M18 38 h2 v1 h-2Z M21 38 h1 v1 h-1Z M23 38 h1 v1 h-1Z M25 38 h1 v1 h-1Z M30 38 h2 v1 h-2Z M33 38 h3 v1 h-3Z M38 38 h2 v1 h-2Z M42 38 h2 v1 h-2Z M45 38 h1 v1 h-1Z M47 38 h2 v1 h-2Z M12 39 h1 v1 h-1Z M15 39 h2 v1 h-2Z M18 39 h1 v1 h-1Z M23 39 h1 v1 h-1Z M25 39 h3 v1 h-3Z M29 39 h1 v1 h-1Z M33 39 h5 v1 h-5Z M39 39 h1 v1 h-1Z M44 39 h2 v1 h-2Z M48 39 h1 v1 h-1Z M11 40 h2 v1 h-2Z M14 40 h1 v1 h-1Z M18 40 h1 v1 h-1Z M22 40 h2 v1 h-2Z M32 40 h4 v1 h-4Z M38 40 h1 v1 h-1Z M45 40 h1 v1 h-1Z M47 40 h2 v1 h-2Z M13 41 h2 v1 h-2Z M22 41 h1 v1 h-1Z M30 41 h2 v1 h-2Z M33 41 h3 v1 h-3Z M37 41 h1 v1 h-1Z M14 42 h2 v1 h-2Z M17 42 h3 v1 h-3Z M29 42 h3 v1 h-3Z M35 42 h1 v1 h-1Z M45 42 h1 v1 h-1Z M13 43 h3 v1 h-3Z M18 43 h1 v1 h-1Z M20 43 h3 v1 h-3Z M31 43 h1 v1 h-1Z M35 43 h2 v1 h-2Z M38 43 h2 v1 h-2Z M45 43 h2 v1 h-2Z M13 44 h1 v1 h-1Z M15 44 h2 v1 h-2Z M21 44 h2 v1 h-2Z M30 44 h1 v1 h-1Z M32 44 h2 v1 h-2Z M35 44 h2 v1 h-2Z M38 44 h2 v1 h-2Z M46 44 h2 v1 h-2Z M13 45 h1 v1 h-1Z M16 45 h1 v1 h-1Z M18 45 h1 v1 h-1Z M20 45 h3 v1 h-3Z M29 45 h1 v1 h-1Z M33 45 h5 v1 h-5Z M40 45 h2 v1 h-2Z M44 45 h1 v1 h-1Z M47 45 h2 v1 h-2Z M14 46 h5 v1 h-5Z M23 46 h2 v1 h-2Z M28 46 h1 v1 h-1Z M30 46 h1 v1 h-1Z M33 46 h3 v1 h-3Z M37 46 h1 v1 h-1Z M39 46 h4 v1 h-4Z M44 46 h2 v1 h-2Z M13 47 h1 v1 h-1Z M15 47 h1 v1 h-1Z M18 47 h3 v1 h-3Z M22 47 h5 v1 h-5Z M34 47 h3 v1 h-3Z M39 47 h1 v1 h-1Z M42 47 h1 v1 h-1Z M44 47 h1 v1 h-1Z M48 47 h1 v1 h-1Z M14 48 h1 v1 h-1Z M16 48 h2 v1 h-2Z M19 48 h1 v1 h-1Z M21 48 h1 v1 h-1Z M25 48 h4 v1 h-4Z M31 48 h1 v1 h-1Z M33 48 h1 v1 h-1Z M35 48 h1 v1 h-1Z M37 48 h2 v1 h-2Z M42 48 h2 v1 h-2Z M45 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-1536 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M4 4 h7 v1 h-7Z M42 4 h7 v1 h-7Z M4 5 h1 v1 h-1Z M10 5 h1 v1 h-1Z M42 5 h1 v1 h-1Z M48 5 h1 v1 h-1Z M4 6 h1 v1 h-1Z M10 6 h1 v1 h-1Z M42 6 h1 v1 h-1Z M48 6 h1 v1 h-1Z M4 7 h1 v1 h-1Z M10 7 h1 v1 h-1Z M42 7 h1 v1 h-1Z M48 7 h1 v1 h-1Z M4 8 h1 v1 h-1Z M10 8 h1 v1 h-1Z M42 8 h1 v1 h-1Z M48 8 h1 v1 h-1Z M4 9 h1 v1 h-1Z M10 9 h1 v1 h-1Z M42 9 h1 v1 h-1Z M48 9 h1 v1 h-1Z M4 10 h7 v1 h-7Z M42 10 h7 v1 h-7Z M4 42 h7 v1 h-7Z M4 43 h1 v1 h-1Z M10 43 h1 v1 h-1Z M4 44 h1 v1 h-1Z M10 44 h1 v1 h-1Z M4 45 h1 v1 h-1Z M10 45 h1 v1 h-1Z M4 46 h1 v1 h-1Z M10 46 h1 v1 h-1Z M4 47 h1 v1 h-1Z M10 47 h1 v1 h-1Z M4 48 h7 v1 h-7Z \" /\u003e\u003cpath class=\"qr-2560 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M24 8 h5 v1 h-5Z M24 9 h1 v1 h-1Z M28 9 h1 v1 h-1Z M24 10 h1 v1 h-1Z M26 10 h1 v1 h-1Z M28 10 h1 v1 h-1Z M24 11 h1 v1 h-1Z M28 11 h1 v1 h-1Z M24 12 h5 v1 h-5Z M8 24 h5 v1 h-5Z M24 24 h5 v1 h-5Z M40 24 h5 v1 h-5Z M8 25 h1 v1 h-1Z M12 25 h1 v1 h-1Z M24 25 h1 v1 h-1Z M28 25 h1 v1 h-1Z M40 25 h1 v1 h-1Z M44 25 h1 v1 h-1Z M8 26 h1 v1 h-1Z M10 26 h1 v1 h-1Z M12 26 h1 v1 h-1Z M24 26 h1 v1 h-1Z M26 26 h1 v1 h-1Z M28 26 h1 v1 h-1Z M40 26 h1 v1 h-1Z M42 26 h1 v1 h-1Z M44 26 h1 v1 h-1Z M8 27 h1 v1 h-1Z M12 27 h1 v1 h-1Z M24 27 h1 v1 h-1Z M28 27 h1 v1 h-1Z M40 27 h1 v1 h-1Z M44 27 h1 v1 h-1Z M8 28 h5 v1 h-5Z M24 28 h5 v1 h-5Z M40 28 h5 v1 h-5Z M24 40 h5 v1 h-5Z M40 40 h5 v1 h-5Z M24 41 h1 v1 h-1Z M28 41 h1 v1 h-1Z M40 41 h1 v1 h-1Z M44 41 h1 v1 h-1Z M24 42 h1 v1 h-1Z M26 42 h1 v1 h-1Z M28 42 h1 v1 h-1Z M40 42 h1 v1 h-1Z M42 42 h1 v1 h-1Z M44 42 h1 v1 h-1Z M24 43 h1 v1 h-1Z M28 43 h1 v1 h-1Z M40 43 h1 v1 h-1Z M44 43 h1 v1 h-1Z M24 44 h5 v1 h-5Z M40 44 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-3072 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 10 h1 v1 h-1Z M14 10 h1 v1 h-1Z M16 10 h1 v1 h-1Z M18 10 h1 v1 h-1Z M20 10 h1 v1 h-1Z M22 10 h1 v1 h-1Z M30 10 h1 v1 h-1Z M32 10 h1 v1 h-1Z M34 10 h1 v1 h-1Z M36 10 h1 v1 h-1Z M38 10 h1 v1 h-1Z M40 10 h1 v1 h-1Z M10 12 h1 v1 h-1Z M10 14 h1 v1 h-1Z M10 16 h1 v1 h-1Z M10 18 h1 v1 h-1Z M10 20 h1 v1 h-1Z M10 22 h1 v1 h-1Z M10 30 h1 v1 h-1Z M10 32 h1 v1 h-1Z M10 34 h1 v1 h-1Z M10 36 h1 v1 h-1Z M10 38 h1 v1 h-1Z M10 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-3584 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 8 h1 v1 h-1Z M12 11 h1 v1 h-1Z M6 12 h2 v1 h-2Z M11 12 h2 v1 h-2Z M41 12 h2 v1 h-2Z M44 12 h1 v1 h-1Z M12 42 h1 v1 h-1Z M12 45 h1 v1 h-1Z M12 46 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-4096 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M40 4 h1 v1 h-1Z M39 5 h1 v1 h-1Z M39 6 h1 v1 h-1Z M39 7 h2 v1 h-2Z M38 8 h3 v1 h-3Z M8 38 h1 v1 h-1Z M5 39 h4 v1 h-4Z M4 40 h1 v1 h-1Z M7 40 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-5632 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M6 6 h3 v1 h-3Z M44 6 h3 v1 h-3Z M6 7 h3 v1 h-3Z M44 7 h3 v1 h-3Z M6 8 h3 v1 h-3Z M44 8 h3 v1 h-3Z M6 44 h3 v1 h-3Z M6 45 h3 v1 h-3Z M6 46 h3 v1 h-3Z \" /\u003e\u003c/svg\u003e\n\n    \u003c/a\u003e\n    \u003cfigcaption aria-hidden=\"true\" class=\"hidden\" hidden\u003eDonate for Stéphane HUC by Liberapay\u003c/figcaption\u003e\n\u003c/figure\u003e\n\n\n\u003ch3 id=\"paypal\"\u003ePaypal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://paypal.me/hucste\" rel=\"external\"\u003ehttps://paypal.me/hucste\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\n\u003cfigure class=\"pure-img\"\u003e\n    \u003ca href=\"/svg/qrcode/paypal.svg\" title=\"Donate for Stéphane HUC by Paypal\"\u003e\n    \u003csvg xmlns=\"http://www.w3.org/2000/svg\" class=\"qr-svg \" height=\"128\" viewBox=\"0 0 53 53\" width=\"128\"\u003e\n\u003cdefs\u003e\u003cstyle\u003erect{shape-rendering:crispEdges}\u003c/style\u003e\u003c/defs\u003e\n\u003cpath class=\"qr-4 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M15 4 h1 v1 h-1Z M18 4 h3 v1 h-3Z M24 4 h1 v1 h-1Z M27 4 h7 v1 h-7Z M35 4 h1 v1 h-1Z M16 5 h6 v1 h-6Z M25 5 h2 v1 h-2Z M29 5 h4 v1 h-4Z M34 5 h1 v1 h-1Z M36 5 h1 v1 h-1Z M13 6 h5 v1 h-5Z M19 6 h7 v1 h-7Z M30 6 h2 v1 h-2Z M35 6 h2 v1 h-2Z M13 7 h1 v1 h-1Z M15 7 h1 v1 h-1Z M17 7 h1 v1 h-1Z M20 7 h3 v1 h-3Z M25 7 h4 v1 h-4Z M32 7 h1 v1 h-1Z M35 7 h1 v1 h-1Z M37 7 h1 v1 h-1Z M13 8 h1 v1 h-1Z M15 8 h1 v1 h-1Z M18 8 h2 v1 h-2Z M22 8 h1 v1 h-1Z M29 8 h1 v1 h-1Z M31 8 h2 v1 h-2Z M13 9 h1 v1 h-1Z M15 9 h1 v1 h-1Z M21 9 h2 v1 h-2Z M29 9 h1 v1 h-1Z M31 9 h1 v1 h-1Z M35 9 h2 v1 h-2Z M13 11 h4 v1 h-4Z M19 11 h4 v1 h-4Z M29 11 h2 v1 h-2Z M34 11 h1 v1 h-1Z M39 11 h1 v1 h-1Z M17 12 h1 v1 h-1Z M19 12 h1 v1 h-1Z M29 12 h1 v1 h-1Z M32 12 h4 v1 h-4Z M37 12 h3 v1 h-3Z M5 13 h1 v1 h-1Z M8 13 h1 v1 h-1Z M11 13 h2 v1 h-2Z M15 13 h1 v1 h-1Z M17 13 h2 v1 h-2Z M21 13 h3 v1 h-3Z M34 13 h4 v1 h-4Z M40 13 h1 v1 h-1Z M42 13 h4 v1 h-4Z M47 13 h1 v1 h-1Z M4 14 h3 v1 h-3Z M8 14 h1 v1 h-1Z M12 14 h3 v1 h-3Z M16 14 h1 v1 h-1Z M18 14 h2 v1 h-2Z M21 14 h1 v1 h-1Z M24 14 h1 v1 h-1Z M30 14 h1 v1 h-1Z M36 14 h1 v1 h-1Z M40 14 h2 v1 h-2Z M43 14 h1 v1 h-1Z M45 14 h1 v1 h-1Z M48 14 h1 v1 h-1Z M4 15 h2 v1 h-2Z M8 15 h2 v1 h-2Z M12 15 h1 v1 h-1Z M22 15 h1 v1 h-1Z M24 15 h2 v1 h-2Z M27 15 h3 v1 h-3Z M31 15 h2 v1 h-2Z M36 15 h1 v1 h-1Z M39 15 h4 v1 h-4Z M47 15 h1 v1 h-1Z M5 16 h1 v1 h-1Z M9 16 h1 v1 h-1Z M11 16 h2 v1 h-2Z M14 16 h3 v1 h-3Z M18 16 h5 v1 h-5Z M25 16 h1 v1 h-1Z M27 16 h1 v1 h-1Z M29 16 h2 v1 h-2Z M32 16 h2 v1 h-2Z M37 16 h1 v1 h-1Z M39 16 h1 v1 h-1Z M45 16 h1 v1 h-1Z M47 16 h2 v1 h-2Z M8 17 h1 v1 h-1Z M11 17 h1 v1 h-1Z M13 17 h1 v1 h-1Z M17 17 h1 v1 h-1Z M19 17 h1 v1 h-1Z M22 17 h3 v1 h-3Z M28 17 h2 v1 h-2Z M31 17 h3 v1 h-3Z M35 17 h1 v1 h-1Z M38 17 h2 v1 h-2Z M41 17 h1 v1 h-1Z M44 17 h4 v1 h-4Z M5 18 h1 v1 h-1Z M9 18 h1 v1 h-1Z M12 18 h2 v1 h-2Z M15 18 h3 v1 h-3Z M20 18 h3 v1 h-3Z M24 18 h2 v1 h-2Z M28 18 h2 v1 h-2Z M31 18 h2 v1 h-2Z M36 18 h1 v1 h-1Z M38 18 h1 v1 h-1Z M41 18 h1 v1 h-1Z M45 18 h1 v1 h-1Z M48 18 h1 v1 h-1Z M6 19 h2 v1 h-2Z M9 19 h1 v1 h-1Z M11 19 h1 v1 h-1Z M14 19 h1 v1 h-1Z M16 19 h2 v1 h-2Z M20 19 h2 v1 h-2Z M23 19 h1 v1 h-1Z M25 19 h2 v1 h-2Z M28 19 h1 v1 h-1Z M31 19 h2 v1 h-2Z M34 19 h3 v1 h-3Z M38 19 h2 v1 h-2Z M43 19 h1 v1 h-1Z M4 20 h1 v1 h-1Z M6 20 h2 v1 h-2Z M9 20 h1 v1 h-1Z M11 20 h1 v1 h-1Z M16 20 h1 v1 h-1Z M18 20 h6 v1 h-6Z M25 20 h3 v1 h-3Z M29 20 h4 v1 h-4Z M34 20 h1 v1 h-1Z M39 20 h2 v1 h-2Z M43 20 h1 v1 h-1Z M45 20 h3 v1 h-3Z M4 21 h2 v1 h-2Z M11 21 h1 v1 h-1Z M13 21 h1 v1 h-1Z M20 21 h1 v1 h-1Z M23 21 h1 v1 h-1Z M25 21 h2 v1 h-2Z M28 21 h1 v1 h-1Z M30 21 h2 v1 h-2Z M33 21 h4 v1 h-4Z M38 21 h2 v1 h-2Z M41 21 h7 v1 h-7Z M4 22 h1 v1 h-1Z M6 22 h3 v1 h-3Z M11 22 h1 v1 h-1Z M15 22 h2 v1 h-2Z M18 22 h1 v1 h-1Z M21 22 h1 v1 h-1Z M23 22 h3 v1 h-3Z M30 22 h1 v1 h-1Z M32 22 h1 v1 h-1Z M35 22 h1 v1 h-1Z M42 22 h3 v1 h-3Z M47 22 h1 v1 h-1Z M5 23 h1 v1 h-1Z M7 23 h3 v1 h-3Z M13 23 h2 v1 h-2Z M16 23 h5 v1 h-5Z M23 23 h1 v1 h-1Z M26 23 h1 v1 h-1Z M29 23 h3 v1 h-3Z M33 23 h1 v1 h-1Z M35 23 h6 v1 h-6Z M43 23 h1 v1 h-1Z M45 23 h1 v1 h-1Z M47 23 h1 v1 h-1Z M4 24 h2 v1 h-2Z M7 24 h1 v1 h-1Z M13 24 h1 v1 h-1Z M15 24 h1 v1 h-1Z M17 24 h2 v1 h-2Z M23 24 h1 v1 h-1Z M29 24 h1 v1 h-1Z M32 24 h1 v1 h-1Z M35 24 h3 v1 h-3Z M39 24 h1 v1 h-1Z M45 24 h2 v1 h-2Z M48 24 h1 v1 h-1Z M6 25 h1 v1 h-1Z M13 25 h2 v1 h-2Z M16 25 h2 v1 h-2Z M19 25 h1 v1 h-1Z M21 25 h1 v1 h-1Z M29 25 h1 v1 h-1Z M31 25 h3 v1 h-3Z M37 25 h1 v1 h-1Z M46 25 h3 v1 h-3Z M6 26 h2 v1 h-2Z M13 26 h3 v1 h-3Z M18 26 h1 v1 h-1Z M20 26 h2 v1 h-2Z M31 26 h1 v1 h-1Z M33 26 h1 v1 h-1Z M35 26 h1 v1 h-1Z M37 26 h2 v1 h-2Z M46 26 h1 v1 h-1Z M5 27 h3 v1 h-3Z M16 27 h3 v1 h-3Z M22 27 h1 v1 h-1Z M30 27 h2 v1 h-2Z M33 27 h4 v1 h-4Z M38 27 h1 v1 h-1Z M45 27 h4 v1 h-4Z M6 28 h2 v1 h-2Z M14 28 h1 v1 h-1Z M16 28 h3 v1 h-3Z M20 28 h1 v1 h-1Z M23 28 h1 v1 h-1Z M31 28 h1 v1 h-1Z M34 28 h3 v1 h-3Z M38 28 h1 v1 h-1Z M48 28 h1 v1 h-1Z M5 29 h3 v1 h-3Z M9 29 h1 v1 h-1Z M12 29 h1 v1 h-1Z M14 29 h1 v1 h-1Z M16 29 h2 v1 h-2Z M20 29 h1 v1 h-1Z M22 29 h2 v1 h-2Z M25 29 h2 v1 h-2Z M28 29 h1 v1 h-1Z M31 29 h2 v1 h-2Z M34 29 h1 v1 h-1Z M36 29 h1 v1 h-1Z M41 29 h1 v1 h-1Z M44 29 h2 v1 h-2Z M5 30 h1 v1 h-1Z M7 30 h3 v1 h-3Z M11 30 h1 v1 h-1Z M13 30 h1 v1 h-1Z M15 30 h1 v1 h-1Z M18 30 h2 v1 h-2Z M25 30 h6 v1 h-6Z M32 30 h1 v1 h-1Z M35 30 h1 v1 h-1Z M42 30 h2 v1 h-2Z M47 30 h1 v1 h-1Z M5 31 h1 v1 h-1Z M7 31 h3 v1 h-3Z M11 31 h2 v1 h-2Z M15 31 h2 v1 h-2Z M19 31 h1 v1 h-1Z M24 31 h1 v1 h-1Z M31 31 h2 v1 h-2Z M38 31 h3 v1 h-3Z M44 31 h2 v1 h-2Z M47 31 h2 v1 h-2Z M5 32 h2 v1 h-2Z M8 32 h1 v1 h-1Z M13 32 h2 v1 h-2Z M16 32 h1 v1 h-1Z M19 32 h5 v1 h-5Z M25 32 h1 v1 h-1Z M27 32 h1 v1 h-1Z M30 32 h1 v1 h-1Z M32 32 h4 v1 h-4Z M37 32 h1 v1 h-1Z M39 32 h1 v1 h-1Z M42 32 h2 v1 h-2Z M45 32 h1 v1 h-1Z M48 32 h1 v1 h-1Z M7 33 h1 v1 h-1Z M9 33 h1 v1 h-1Z M11 33 h2 v1 h-2Z M15 33 h2 v1 h-2Z M18 33 h6 v1 h-6Z M26 33 h1 v1 h-1Z M28 33 h1 v1 h-1Z M36 33 h1 v1 h-1Z M39 33 h3 v1 h-3Z M45 33 h2 v1 h-2Z M48 33 h1 v1 h-1Z M4 34 h1 v1 h-1Z M6 34 h4 v1 h-4Z M11 34 h1 v1 h-1Z M13 34 h1 v1 h-1Z M15 34 h1 v1 h-1Z M19 34 h2 v1 h-2Z M29 34 h1 v1 h-1Z M31 34 h1 v1 h-1Z M33 34 h1 v1 h-1Z M37 34 h6 v1 h-6Z M46 34 h1 v1 h-1Z M4 35 h1 v1 h-1Z M8 35 h1 v1 h-1Z M12 35 h3 v1 h-3Z M16 35 h2 v1 h-2Z M20 35 h1 v1 h-1Z M22 35 h1 v1 h-1Z M24 35 h3 v1 h-3Z M28 35 h2 v1 h-2Z M31 35 h4 v1 h-4Z M37 35 h3 v1 h-3Z M44 35 h1 v1 h-1Z M46 35 h2 v1 h-2Z M5 36 h3 v1 h-3Z M9 36 h1 v1 h-1Z M11 36 h2 v1 h-2Z M14 36 h1 v1 h-1Z M16 36 h2 v1 h-2Z M19 36 h1 v1 h-1Z M21 36 h2 v1 h-2Z M24 36 h3 v1 h-3Z M28 36 h1 v1 h-1Z M30 36 h6 v1 h-6Z M37 36 h4 v1 h-4Z M42 36 h2 v1 h-2Z M45 36 h1 v1 h-1Z M48 36 h1 v1 h-1Z M5 37 h2 v1 h-2Z M8 37 h2 v1 h-2Z M11 37 h2 v1 h-2Z M14 37 h2 v1 h-2Z M17 37 h1 v1 h-1Z M20 37 h1 v1 h-1Z M23 37 h1 v1 h-1Z M26 37 h2 v1 h-2Z M29 37 h1 v1 h-1Z M31 37 h3 v1 h-3Z M35 37 h2 v1 h-2Z M39 37 h1 v1 h-1Z M43 37 h1 v1 h-1Z M47 37 h1 v1 h-1Z M12 38 h2 v1 h-2Z M15 38 h1 v1 h-1Z M19 38 h2 v1 h-2Z M22 38 h1 v1 h-1Z M24 38 h1 v1 h-1Z M26 38 h4 v1 h-4Z M31 38 h2 v1 h-2Z M34 38 h1 v1 h-1Z M36 38 h2 v1 h-2Z M41 38 h1 v1 h-1Z M43 38 h2 v1 h-2Z M48 38 h1 v1 h-1Z M11 39 h1 v1 h-1Z M13 39 h2 v1 h-2Z M17 39 h4 v1 h-4Z M22 39 h3 v1 h-3Z M26 39 h1 v1 h-1Z M28 39 h4 v1 h-4Z M34 39 h1 v1 h-1Z M37 39 h1 v1 h-1Z M40 39 h1 v1 h-1Z M42 39 h2 v1 h-2Z M45 39 h1 v1 h-1Z M47 39 h1 v1 h-1Z M12 40 h4 v1 h-4Z M17 40 h3 v1 h-3Z M23 40 h1 v1 h-1Z M30 40 h6 v1 h-6Z M37 40 h1 v1 h-1Z M39 40 h1 v1 h-1Z M45 40 h4 v1 h-4Z M17 41 h6 v1 h-6Z M29 41 h3 v1 h-3Z M35 41 h5 v1 h-5Z M46 41 h1 v1 h-1Z M48 41 h1 v1 h-1Z M13 42 h1 v1 h-1Z M16 42 h1 v1 h-1Z M19 42 h4 v1 h-4Z M29 42 h1 v1 h-1Z M31 42 h1 v1 h-1Z M36 42 h2 v1 h-2Z M45 42 h4 v1 h-4Z M20 43 h3 v1 h-3Z M29 43 h1 v1 h-1Z M33 43 h4 v1 h-4Z M38 43 h1 v1 h-1Z M47 43 h1 v1 h-1Z M13 44 h2 v1 h-2Z M16 44 h1 v1 h-1Z M19 44 h3 v1 h-3Z M29 44 h1 v1 h-1Z M31 44 h2 v1 h-2Z M39 44 h1 v1 h-1Z M46 44 h2 v1 h-2Z M13 45 h2 v1 h-2Z M16 45 h3 v1 h-3Z M21 45 h1 v1 h-1Z M24 45 h1 v1 h-1Z M27 45 h2 v1 h-2Z M31 45 h6 v1 h-6Z M38 45 h1 v1 h-1Z M40 45 h4 v1 h-4Z M48 45 h1 v1 h-1Z M13 46 h2 v1 h-2Z M17 46 h2 v1 h-2Z M20 46 h1 v1 h-1Z M24 46 h2 v1 h-2Z M27 46 h1 v1 h-1Z M29 46 h1 v1 h-1Z M31 46 h3 v1 h-3Z M39 46 h1 v1 h-1Z M41 46 h5 v1 h-5Z M14 47 h2 v1 h-2Z M20 47 h1 v1 h-1Z M22 47 h1 v1 h-1Z M24 47 h1 v1 h-1Z M26 47 h3 v1 h-3Z M31 47 h5 v1 h-5Z M37 47 h2 v1 h-2Z M40 47 h1 v1 h-1Z M43 47 h1 v1 h-1Z M45 47 h1 v1 h-1Z M13 48 h1 v1 h-1Z M15 48 h2 v1 h-2Z M18 48 h3 v1 h-3Z M25 48 h6 v1 h-6Z M32 48 h3 v1 h-3Z M36 48 h2 v1 h-2Z M40 48 h2 v1 h-2Z M43 48 h2 v1 h-2Z M47 48 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-6 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M5 5 h5 v1 h-5Z M43 5 h5 v1 h-5Z M5 6 h1 v1 h-1Z M9 6 h1 v1 h-1Z M43 6 h1 v1 h-1Z M47 6 h1 v1 h-1Z M5 7 h1 v1 h-1Z M9 7 h1 v1 h-1Z M43 7 h1 v1 h-1Z M47 7 h1 v1 h-1Z M5 8 h1 v1 h-1Z M9 8 h1 v1 h-1Z M43 8 h1 v1 h-1Z M47 8 h1 v1 h-1Z M5 9 h5 v1 h-5Z M43 9 h5 v1 h-5Z M5 43 h5 v1 h-5Z M5 44 h1 v1 h-1Z M9 44 h1 v1 h-1Z M5 45 h1 v1 h-1Z M9 45 h1 v1 h-1Z M5 46 h1 v1 h-1Z M9 46 h1 v1 h-1Z M5 47 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-8 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M11 4 h1 v1 h-1Z M41 4 h1 v1 h-1Z M11 5 h1 v1 h-1Z M41 5 h1 v1 h-1Z M11 6 h1 v1 h-1Z M41 6 h1 v1 h-1Z M11 7 h1 v1 h-1Z M41 7 h1 v1 h-1Z M11 8 h1 v1 h-1Z M41 8 h1 v1 h-1Z M11 9 h1 v1 h-1Z M41 9 h1 v1 h-1Z M11 10 h1 v1 h-1Z M41 10 h1 v1 h-1Z M4 11 h8 v1 h-8Z M41 11 h8 v1 h-8Z M4 41 h8 v1 h-8Z M11 42 h1 v1 h-1Z M11 43 h1 v1 h-1Z M11 44 h1 v1 h-1Z M11 45 h1 v1 h-1Z M11 46 h1 v1 h-1Z M11 47 h1 v1 h-1Z M11 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-10 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M25 9 h3 v1 h-3Z M25 10 h1 v1 h-1Z M27 10 h1 v1 h-1Z M25 11 h3 v1 h-3Z M9 25 h3 v1 h-3Z M25 25 h3 v1 h-3Z M41 25 h3 v1 h-3Z M9 26 h1 v1 h-1Z M11 26 h1 v1 h-1Z M25 26 h1 v1 h-1Z M27 26 h1 v1 h-1Z M41 26 h1 v1 h-1Z M43 26 h1 v1 h-1Z M9 27 h3 v1 h-3Z M25 27 h3 v1 h-3Z M41 27 h3 v1 h-3Z M25 41 h3 v1 h-3Z M41 41 h3 v1 h-3Z M25 42 h1 v1 h-1Z M27 42 h1 v1 h-1Z M41 42 h1 v1 h-1Z M43 42 h1 v1 h-1Z M25 43 h3 v1 h-3Z M41 43 h3 v1 h-3Z \" /\u003e\u003cpath class=\"qr-12 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M13 10 h1 v1 h-1Z M15 10 h1 v1 h-1Z M17 10 h1 v1 h-1Z M19 10 h1 v1 h-1Z M21 10 h1 v1 h-1Z M23 10 h1 v1 h-1Z M29 10 h1 v1 h-1Z M31 10 h1 v1 h-1Z M33 10 h1 v1 h-1Z M35 10 h1 v1 h-1Z M37 10 h1 v1 h-1Z M39 10 h1 v1 h-1Z M10 13 h1 v1 h-1Z M10 15 h1 v1 h-1Z M10 17 h1 v1 h-1Z M10 19 h1 v1 h-1Z M10 21 h1 v1 h-1Z M10 23 h1 v1 h-1Z M10 29 h1 v1 h-1Z M10 31 h1 v1 h-1Z M10 33 h1 v1 h-1Z M10 35 h1 v1 h-1Z M10 37 h1 v1 h-1Z M10 39 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-14 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M12 4 h1 v1 h-1Z M12 5 h1 v1 h-1Z M12 8 h1 v1 h-1Z M12 9 h1 v1 h-1Z M12 11 h1 v1 h-1Z M4 12 h3 v1 h-3Z M9 12 h1 v1 h-1Z M12 12 h1 v1 h-1Z M41 12 h4 v1 h-4Z M47 12 h2 v1 h-2Z M12 43 h1 v1 h-1Z M12 46 h1 v1 h-1Z M12 47 h1 v1 h-1Z M12 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-16 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M38 4 h2 v1 h-2Z M38 5 h1 v1 h-1Z M40 5 h1 v1 h-1Z M38 6 h1 v1 h-1Z M40 6 h1 v1 h-1Z M38 7 h1 v1 h-1Z M38 9 h3 v1 h-3Z M4 38 h4 v1 h-4Z M9 38 h1 v1 h-1Z M4 39 h1 v1 h-1Z M9 39 h1 v1 h-1Z M5 40 h2 v1 h-2Z M9 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-18 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M0 0 h53 v1 h-53Z M0 1 h53 v1 h-53Z M0 2 h53 v1 h-53Z M0 3 h53 v1 h-53Z M0 4 h4 v1 h-4Z M49 4 h4 v1 h-4Z M0 5 h4 v1 h-4Z M49 5 h4 v1 h-4Z M0 6 h4 v1 h-4Z M49 6 h4 v1 h-4Z M0 7 h4 v1 h-4Z M49 7 h4 v1 h-4Z M0 8 h4 v1 h-4Z M49 8 h4 v1 h-4Z M0 9 h4 v1 h-4Z M49 9 h4 v1 h-4Z M0 10 h4 v1 h-4Z M49 10 h4 v1 h-4Z M0 11 h4 v1 h-4Z M49 11 h4 v1 h-4Z M0 12 h4 v1 h-4Z M49 12 h4 v1 h-4Z M0 13 h4 v1 h-4Z M49 13 h4 v1 h-4Z M0 14 h4 v1 h-4Z M49 14 h4 v1 h-4Z M0 15 h4 v1 h-4Z M49 15 h4 v1 h-4Z M0 16 h4 v1 h-4Z M49 16 h4 v1 h-4Z M0 17 h4 v1 h-4Z M49 17 h4 v1 h-4Z M0 18 h4 v1 h-4Z M49 18 h4 v1 h-4Z M0 19 h4 v1 h-4Z M49 19 h4 v1 h-4Z M0 20 h4 v1 h-4Z M49 20 h4 v1 h-4Z M0 21 h4 v1 h-4Z M49 21 h4 v1 h-4Z M0 22 h4 v1 h-4Z M49 22 h4 v1 h-4Z M0 23 h4 v1 h-4Z M49 23 h4 v1 h-4Z M0 24 h4 v1 h-4Z M49 24 h4 v1 h-4Z M0 25 h4 v1 h-4Z M49 25 h4 v1 h-4Z M0 26 h4 v1 h-4Z M49 26 h4 v1 h-4Z M0 27 h4 v1 h-4Z M49 27 h4 v1 h-4Z M0 28 h4 v1 h-4Z M49 28 h4 v1 h-4Z M0 29 h4 v1 h-4Z M49 29 h4 v1 h-4Z M0 30 h4 v1 h-4Z M49 30 h4 v1 h-4Z M0 31 h4 v1 h-4Z M49 31 h4 v1 h-4Z M0 32 h4 v1 h-4Z M49 32 h4 v1 h-4Z M0 33 h4 v1 h-4Z M49 33 h4 v1 h-4Z M0 34 h4 v1 h-4Z M49 34 h4 v1 h-4Z M0 35 h4 v1 h-4Z M49 35 h4 v1 h-4Z M0 36 h4 v1 h-4Z M49 36 h4 v1 h-4Z M0 37 h4 v1 h-4Z M49 37 h4 v1 h-4Z M0 38 h4 v1 h-4Z M49 38 h4 v1 h-4Z M0 39 h4 v1 h-4Z M49 39 h4 v1 h-4Z M0 40 h4 v1 h-4Z M49 40 h4 v1 h-4Z M0 41 h4 v1 h-4Z M49 41 h4 v1 h-4Z M0 42 h4 v1 h-4Z M49 42 h4 v1 h-4Z M0 43 h4 v1 h-4Z M49 43 h4 v1 h-4Z M0 44 h4 v1 h-4Z M49 44 h4 v1 h-4Z M0 45 h4 v1 h-4Z M49 45 h4 v1 h-4Z M0 46 h4 v1 h-4Z M49 46 h4 v1 h-4Z M0 47 h4 v1 h-4Z M49 47 h4 v1 h-4Z M0 48 h4 v1 h-4Z M49 48 h4 v1 h-4Z M0 49 h53 v1 h-53Z M0 50 h53 v1 h-53Z M0 51 h53 v1 h-53Z M0 52 h53 v1 h-53Z \" /\u003e\u003cpath class=\"qr-512 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 41 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-1024 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M13 4 h2 v1 h-2Z M16 4 h2 v1 h-2Z M21 4 h3 v1 h-3Z M25 4 h2 v1 h-2Z M34 4 h1 v1 h-1Z M36 4 h2 v1 h-2Z M13 5 h3 v1 h-3Z M22 5 h3 v1 h-3Z M27 5 h2 v1 h-2Z M33 5 h1 v1 h-1Z M35 5 h1 v1 h-1Z M37 5 h1 v1 h-1Z M18 6 h1 v1 h-1Z M26 6 h4 v1 h-4Z M32 6 h3 v1 h-3Z M37 6 h1 v1 h-1Z M14 7 h1 v1 h-1Z M16 7 h1 v1 h-1Z M18 7 h2 v1 h-2Z M23 7 h2 v1 h-2Z M29 7 h3 v1 h-3Z M33 7 h2 v1 h-2Z M36 7 h1 v1 h-1Z M14 8 h1 v1 h-1Z M16 8 h2 v1 h-2Z M20 8 h2 v1 h-2Z M23 8 h1 v1 h-1Z M30 8 h1 v1 h-1Z M33 8 h5 v1 h-5Z M14 9 h1 v1 h-1Z M16 9 h5 v1 h-5Z M23 9 h1 v1 h-1Z M30 9 h1 v1 h-1Z M32 9 h3 v1 h-3Z M37 9 h1 v1 h-1Z M17 11 h2 v1 h-2Z M23 11 h1 v1 h-1Z M31 11 h3 v1 h-3Z M35 11 h4 v1 h-4Z M40 11 h1 v1 h-1Z M13 12 h4 v1 h-4Z M18 12 h1 v1 h-1Z M20 12 h4 v1 h-4Z M30 12 h2 v1 h-2Z M36 12 h1 v1 h-1Z M40 12 h1 v1 h-1Z M4 13 h1 v1 h-1Z M6 13 h2 v1 h-2Z M9 13 h1 v1 h-1Z M13 13 h2 v1 h-2Z M16 13 h1 v1 h-1Z M19 13 h2 v1 h-2Z M24 13 h10 v1 h-10Z M38 13 h2 v1 h-2Z M41 13 h1 v1 h-1Z M46 13 h1 v1 h-1Z M48 13 h1 v1 h-1Z M7 14 h1 v1 h-1Z M9 14 h1 v1 h-1Z M11 14 h1 v1 h-1Z M15 14 h1 v1 h-1Z M17 14 h1 v1 h-1Z M20 14 h1 v1 h-1Z M22 14 h2 v1 h-2Z M25 14 h5 v1 h-5Z M31 14 h5 v1 h-5Z M37 14 h3 v1 h-3Z M42 14 h1 v1 h-1Z M44 14 h1 v1 h-1Z M46 14 h2 v1 h-2Z M6 15 h2 v1 h-2Z M11 15 h1 v1 h-1Z M13 15 h9 v1 h-9Z M23 15 h1 v1 h-1Z M26 15 h1 v1 h-1Z M30 15 h1 v1 h-1Z M33 15 h3 v1 h-3Z M37 15 h2 v1 h-2Z M43 15 h4 v1 h-4Z M48 15 h1 v1 h-1Z M4 16 h1 v1 h-1Z M6 16 h3 v1 h-3Z M13 16 h1 v1 h-1Z M17 16 h1 v1 h-1Z M23 16 h2 v1 h-2Z M26 16 h1 v1 h-1Z M28 16 h1 v1 h-1Z M31 16 h1 v1 h-1Z M34 16 h3 v1 h-3Z M38 16 h1 v1 h-1Z M40 16 h5 v1 h-5Z M46 16 h1 v1 h-1Z M4 17 h4 v1 h-4Z M9 17 h1 v1 h-1Z M12 17 h1 v1 h-1Z M14 17 h3 v1 h-3Z M18 17 h1 v1 h-1Z M20 17 h2 v1 h-2Z M25 17 h3 v1 h-3Z M30 17 h1 v1 h-1Z M34 17 h1 v1 h-1Z M36 17 h2 v1 h-2Z M40 17 h1 v1 h-1Z M42 17 h2 v1 h-2Z M48 17 h1 v1 h-1Z M4 18 h1 v1 h-1Z M6 18 h3 v1 h-3Z M11 18 h1 v1 h-1Z M14 18 h1 v1 h-1Z M18 18 h2 v1 h-2Z M23 18 h1 v1 h-1Z M26 18 h2 v1 h-2Z M30 18 h1 v1 h-1Z M33 18 h3 v1 h-3Z M37 18 h1 v1 h-1Z M39 18 h2 v1 h-2Z M42 18 h3 v1 h-3Z M46 18 h2 v1 h-2Z M4 19 h2 v1 h-2Z M8 19 h1 v1 h-1Z M12 19 h2 v1 h-2Z M15 19 h1 v1 h-1Z M18 19 h2 v1 h-2Z M22 19 h1 v1 h-1Z M24 19 h1 v1 h-1Z M27 19 h1 v1 h-1Z M29 19 h2 v1 h-2Z M33 19 h1 v1 h-1Z M37 19 h1 v1 h-1Z M40 19 h3 v1 h-3Z M44 19 h5 v1 h-5Z M5 20 h1 v1 h-1Z M8 20 h1 v1 h-1Z M12 20 h4 v1 h-4Z M17 20 h1 v1 h-1Z M24 20 h1 v1 h-1Z M28 20 h1 v1 h-1Z M33 20 h1 v1 h-1Z M35 20 h4 v1 h-4Z M41 20 h2 v1 h-2Z M44 20 h1 v1 h-1Z M48 20 h1 v1 h-1Z M6 21 h4 v1 h-4Z M12 21 h1 v1 h-1Z M14 21 h6 v1 h-6Z M21 21 h2 v1 h-2Z M24 21 h1 v1 h-1Z M27 21 h1 v1 h-1Z M29 21 h1 v1 h-1Z M32 21 h1 v1 h-1Z M37 21 h1 v1 h-1Z M40 21 h1 v1 h-1Z M48 21 h1 v1 h-1Z M5 22 h1 v1 h-1Z M9 22 h1 v1 h-1Z M12 22 h3 v1 h-3Z M17 22 h1 v1 h-1Z M19 22 h2 v1 h-2Z M22 22 h1 v1 h-1Z M26 22 h4 v1 h-4Z M31 22 h1 v1 h-1Z M33 22 h2 v1 h-2Z M36 22 h6 v1 h-6Z M45 22 h2 v1 h-2Z M48 22 h1 v1 h-1Z M4 23 h1 v1 h-1Z M6 23 h1 v1 h-1Z M11 23 h2 v1 h-2Z M15 23 h1 v1 h-1Z M21 23 h2 v1 h-2Z M24 23 h2 v1 h-2Z M27 23 h2 v1 h-2Z M32 23 h1 v1 h-1Z M34 23 h1 v1 h-1Z M41 23 h2 v1 h-2Z M44 23 h1 v1 h-1Z M46 23 h1 v1 h-1Z M48 23 h1 v1 h-1Z M6 24 h1 v1 h-1Z M14 24 h1 v1 h-1Z M16 24 h1 v1 h-1Z M19 24 h4 v1 h-4Z M30 24 h2 v1 h-2Z M33 24 h2 v1 h-2Z M38 24 h1 v1 h-1Z M47 24 h1 v1 h-1Z M4 25 h2 v1 h-2Z M7 25 h1 v1 h-1Z M15 25 h1 v1 h-1Z M18 25 h1 v1 h-1Z M20 25 h1 v1 h-1Z M22 25 h2 v1 h-2Z M30 25 h1 v1 h-1Z M34 25 h3 v1 h-3Z M38 25 h2 v1 h-2Z M45 25 h1 v1 h-1Z M4 26 h2 v1 h-2Z M16 26 h2 v1 h-2Z M19 26 h1 v1 h-1Z M22 26 h2 v1 h-2Z M29 26 h2 v1 h-2Z M32 26 h1 v1 h-1Z M34 26 h1 v1 h-1Z M36 26 h1 v1 h-1Z M39 26 h1 v1 h-1Z M45 26 h1 v1 h-1Z M47 26 h2 v1 h-2Z M4 27 h1 v1 h-1Z M13 27 h3 v1 h-3Z M19 27 h3 v1 h-3Z M23 27 h1 v1 h-1Z M29 27 h1 v1 h-1Z M32 27 h1 v1 h-1Z M37 27 h1 v1 h-1Z M39 27 h1 v1 h-1Z M4 28 h2 v1 h-2Z M13 28 h1 v1 h-1Z M15 28 h1 v1 h-1Z M19 28 h1 v1 h-1Z M21 28 h2 v1 h-2Z M29 28 h2 v1 h-2Z M32 28 h2 v1 h-2Z M37 28 h1 v1 h-1Z M39 28 h1 v1 h-1Z M45 28 h3 v1 h-3Z M4 29 h1 v1 h-1Z M8 29 h1 v1 h-1Z M11 29 h1 v1 h-1Z M13 29 h1 v1 h-1Z M15 29 h1 v1 h-1Z M18 29 h2 v1 h-2Z M21 29 h1 v1 h-1Z M24 29 h1 v1 h-1Z M27 29 h1 v1 h-1Z M29 29 h2 v1 h-2Z M33 29 h1 v1 h-1Z M35 29 h1 v1 h-1Z M37 29 h4 v1 h-4Z M42 29 h2 v1 h-2Z M46 29 h3 v1 h-3Z M4 30 h1 v1 h-1Z M6 30 h1 v1 h-1Z M12 30 h1 v1 h-1Z M14 30 h1 v1 h-1Z M16 30 h2 v1 h-2Z M20 30 h5 v1 h-5Z M31 30 h1 v1 h-1Z M33 30 h2 v1 h-2Z M36 30 h6 v1 h-6Z M44 30 h3 v1 h-3Z M48 30 h1 v1 h-1Z M4 31 h1 v1 h-1Z M6 31 h1 v1 h-1Z M13 31 h2 v1 h-2Z M17 31 h2 v1 h-2Z M20 31 h4 v1 h-4Z M25 31 h6 v1 h-6Z M33 31 h5 v1 h-5Z M41 31 h3 v1 h-3Z M46 31 h1 v1 h-1Z M4 32 h1 v1 h-1Z M7 32 h1 v1 h-1Z M9 32 h1 v1 h-1Z M11 32 h2 v1 h-2Z M15 32 h1 v1 h-1Z M17 32 h2 v1 h-2Z M24 32 h1 v1 h-1Z M26 32 h1 v1 h-1Z M28 32 h2 v1 h-2Z M31 32 h1 v1 h-1Z M36 32 h1 v1 h-1Z M38 32 h1 v1 h-1Z M40 32 h2 v1 h-2Z M44 32 h1 v1 h-1Z M46 32 h2 v1 h-2Z M4 33 h3 v1 h-3Z M8 33 h1 v1 h-1Z M13 33 h2 v1 h-2Z M17 33 h1 v1 h-1Z M24 33 h2 v1 h-2Z M27 33 h1 v1 h-1Z M29 33 h7 v1 h-7Z M37 33 h2 v1 h-2Z M42 33 h3 v1 h-3Z M47 33 h1 v1 h-1Z M5 34 h1 v1 h-1Z M12 34 h1 v1 h-1Z M14 34 h1 v1 h-1Z M16 34 h3 v1 h-3Z M21 34 h8 v1 h-8Z M30 34 h1 v1 h-1Z M32 34 h1 v1 h-1Z M34 34 h3 v1 h-3Z M43 34 h3 v1 h-3Z M47 34 h2 v1 h-2Z M5 35 h3 v1 h-3Z M9 35 h1 v1 h-1Z M11 35 h1 v1 h-1Z M15 35 h1 v1 h-1Z M18 35 h2 v1 h-2Z M21 35 h1 v1 h-1Z M23 35 h1 v1 h-1Z M27 35 h1 v1 h-1Z M30 35 h1 v1 h-1Z M35 35 h2 v1 h-2Z M40 35 h4 v1 h-4Z M45 35 h1 v1 h-1Z M48 35 h1 v1 h-1Z M4 36 h1 v1 h-1Z M8 36 h1 v1 h-1Z M13 36 h1 v1 h-1Z M15 36 h1 v1 h-1Z M18 36 h1 v1 h-1Z M20 36 h1 v1 h-1Z M23 36 h1 v1 h-1Z M27 36 h1 v1 h-1Z M29 36 h1 v1 h-1Z M36 36 h1 v1 h-1Z M41 36 h1 v1 h-1Z M44 36 h1 v1 h-1Z M46 36 h2 v1 h-2Z M4 37 h1 v1 h-1Z M7 37 h1 v1 h-1Z M13 37 h1 v1 h-1Z M16 37 h1 v1 h-1Z M18 37 h2 v1 h-2Z M21 37 h2 v1 h-2Z M24 37 h2 v1 h-2Z M28 37 h1 v1 h-1Z M30 37 h1 v1 h-1Z M34 37 h1 v1 h-1Z M37 37 h2 v1 h-2Z M40 37 h3 v1 h-3Z M44 37 h3 v1 h-3Z M48 37 h1 v1 h-1Z M11 38 h1 v1 h-1Z M14 38 h1 v1 h-1Z M16 38 h3 v1 h-3Z M21 38 h1 v1 h-1Z M23 38 h1 v1 h-1Z M25 38 h1 v1 h-1Z M30 38 h1 v1 h-1Z M33 38 h1 v1 h-1Z M35 38 h1 v1 h-1Z M38 38 h3 v1 h-3Z M42 38 h1 v1 h-1Z M45 38 h3 v1 h-3Z M12 39 h1 v1 h-1Z M15 39 h2 v1 h-2Z M21 39 h1 v1 h-1Z M25 39 h1 v1 h-1Z M27 39 h1 v1 h-1Z M32 39 h2 v1 h-2Z M35 39 h2 v1 h-2Z M38 39 h2 v1 h-2Z M41 39 h1 v1 h-1Z M44 39 h1 v1 h-1Z M46 39 h1 v1 h-1Z M48 39 h1 v1 h-1Z M11 40 h1 v1 h-1Z M16 40 h1 v1 h-1Z M20 40 h3 v1 h-3Z M29 40 h1 v1 h-1Z M36 40 h1 v1 h-1Z M38 40 h1 v1 h-1Z M13 41 h4 v1 h-4Z M23 41 h1 v1 h-1Z M32 41 h3 v1 h-3Z M45 41 h1 v1 h-1Z M47 41 h1 v1 h-1Z M14 42 h2 v1 h-2Z M17 42 h2 v1 h-2Z M23 42 h1 v1 h-1Z M30 42 h1 v1 h-1Z M32 42 h4 v1 h-4Z M38 42 h2 v1 h-2Z M13 43 h7 v1 h-7Z M23 43 h1 v1 h-1Z M30 43 h3 v1 h-3Z M37 43 h1 v1 h-1Z M39 43 h1 v1 h-1Z M45 43 h2 v1 h-2Z M48 43 h1 v1 h-1Z M15 44 h1 v1 h-1Z M17 44 h2 v1 h-2Z M22 44 h2 v1 h-2Z M30 44 h1 v1 h-1Z M33 44 h6 v1 h-6Z M45 44 h1 v1 h-1Z M48 44 h1 v1 h-1Z M15 45 h1 v1 h-1Z M19 45 h2 v1 h-2Z M22 45 h2 v1 h-2Z M25 45 h2 v1 h-2Z M29 45 h2 v1 h-2Z M37 45 h1 v1 h-1Z M39 45 h1 v1 h-1Z M44 45 h4 v1 h-4Z M15 46 h2 v1 h-2Z M19 46 h1 v1 h-1Z M21 46 h3 v1 h-3Z M26 46 h1 v1 h-1Z M28 46 h1 v1 h-1Z M30 46 h1 v1 h-1Z M34 46 h5 v1 h-5Z M40 46 h1 v1 h-1Z M46 46 h3 v1 h-3Z M13 47 h1 v1 h-1Z M16 47 h4 v1 h-4Z M21 47 h1 v1 h-1Z M23 47 h1 v1 h-1Z M25 47 h1 v1 h-1Z M29 47 h2 v1 h-2Z M36 47 h1 v1 h-1Z M39 47 h1 v1 h-1Z M41 47 h2 v1 h-2Z M44 47 h1 v1 h-1Z M46 47 h3 v1 h-3Z M14 48 h1 v1 h-1Z M17 48 h1 v1 h-1Z M21 48 h4 v1 h-4Z M31 48 h1 v1 h-1Z M35 48 h1 v1 h-1Z M38 48 h2 v1 h-2Z M42 48 h1 v1 h-1Z M45 48 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-1536 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M4 4 h7 v1 h-7Z M42 4 h7 v1 h-7Z M4 5 h1 v1 h-1Z M10 5 h1 v1 h-1Z M42 5 h1 v1 h-1Z M48 5 h1 v1 h-1Z M4 6 h1 v1 h-1Z M10 6 h1 v1 h-1Z M42 6 h1 v1 h-1Z M48 6 h1 v1 h-1Z M4 7 h1 v1 h-1Z M10 7 h1 v1 h-1Z M42 7 h1 v1 h-1Z M48 7 h1 v1 h-1Z M4 8 h1 v1 h-1Z M10 8 h1 v1 h-1Z M42 8 h1 v1 h-1Z M48 8 h1 v1 h-1Z M4 9 h1 v1 h-1Z M10 9 h1 v1 h-1Z M42 9 h1 v1 h-1Z M48 9 h1 v1 h-1Z M4 10 h7 v1 h-7Z M42 10 h7 v1 h-7Z M4 42 h7 v1 h-7Z M4 43 h1 v1 h-1Z M10 43 h1 v1 h-1Z M4 44 h1 v1 h-1Z M10 44 h1 v1 h-1Z M4 45 h1 v1 h-1Z M10 45 h1 v1 h-1Z M4 46 h1 v1 h-1Z M10 46 h1 v1 h-1Z M4 47 h1 v1 h-1Z M10 47 h1 v1 h-1Z M4 48 h7 v1 h-7Z \" /\u003e\u003cpath class=\"qr-2560 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M24 8 h5 v1 h-5Z M24 9 h1 v1 h-1Z M28 9 h1 v1 h-1Z M24 10 h1 v1 h-1Z M26 10 h1 v1 h-1Z M28 10 h1 v1 h-1Z M24 11 h1 v1 h-1Z M28 11 h1 v1 h-1Z M24 12 h5 v1 h-5Z M8 24 h5 v1 h-5Z M24 24 h5 v1 h-5Z M40 24 h5 v1 h-5Z M8 25 h1 v1 h-1Z M12 25 h1 v1 h-1Z M24 25 h1 v1 h-1Z M28 25 h1 v1 h-1Z M40 25 h1 v1 h-1Z M44 25 h1 v1 h-1Z M8 26 h1 v1 h-1Z M10 26 h1 v1 h-1Z M12 26 h1 v1 h-1Z M24 26 h1 v1 h-1Z M26 26 h1 v1 h-1Z M28 26 h1 v1 h-1Z M40 26 h1 v1 h-1Z M42 26 h1 v1 h-1Z M44 26 h1 v1 h-1Z M8 27 h1 v1 h-1Z M12 27 h1 v1 h-1Z M24 27 h1 v1 h-1Z M28 27 h1 v1 h-1Z M40 27 h1 v1 h-1Z M44 27 h1 v1 h-1Z M8 28 h5 v1 h-5Z M24 28 h5 v1 h-5Z M40 28 h5 v1 h-5Z M24 40 h5 v1 h-5Z M40 40 h5 v1 h-5Z M24 41 h1 v1 h-1Z M28 41 h1 v1 h-1Z M40 41 h1 v1 h-1Z M44 41 h1 v1 h-1Z M24 42 h1 v1 h-1Z M26 42 h1 v1 h-1Z M28 42 h1 v1 h-1Z M40 42 h1 v1 h-1Z M42 42 h1 v1 h-1Z M44 42 h1 v1 h-1Z M24 43 h1 v1 h-1Z M28 43 h1 v1 h-1Z M40 43 h1 v1 h-1Z M44 43 h1 v1 h-1Z M24 44 h5 v1 h-5Z M40 44 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-3072 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 10 h1 v1 h-1Z M14 10 h1 v1 h-1Z M16 10 h1 v1 h-1Z M18 10 h1 v1 h-1Z M20 10 h1 v1 h-1Z M22 10 h1 v1 h-1Z M30 10 h1 v1 h-1Z M32 10 h1 v1 h-1Z M34 10 h1 v1 h-1Z M36 10 h1 v1 h-1Z M38 10 h1 v1 h-1Z M40 10 h1 v1 h-1Z M10 12 h1 v1 h-1Z M10 14 h1 v1 h-1Z M10 16 h1 v1 h-1Z M10 18 h1 v1 h-1Z M10 20 h1 v1 h-1Z M10 22 h1 v1 h-1Z M10 30 h1 v1 h-1Z M10 32 h1 v1 h-1Z M10 34 h1 v1 h-1Z M10 36 h1 v1 h-1Z M10 38 h1 v1 h-1Z M10 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-3584 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 6 h1 v1 h-1Z M12 7 h1 v1 h-1Z M7 12 h2 v1 h-2Z M11 12 h1 v1 h-1Z M45 12 h2 v1 h-2Z M12 42 h1 v1 h-1Z M12 44 h1 v1 h-1Z M12 45 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-4096 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M40 4 h1 v1 h-1Z M39 5 h1 v1 h-1Z M39 6 h1 v1 h-1Z M39 7 h2 v1 h-2Z M38 8 h3 v1 h-3Z M8 38 h1 v1 h-1Z M5 39 h4 v1 h-4Z M4 40 h1 v1 h-1Z M7 40 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-5632 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M6 6 h3 v1 h-3Z M44 6 h3 v1 h-3Z M6 7 h3 v1 h-3Z M44 7 h3 v1 h-3Z M6 8 h3 v1 h-3Z M44 8 h3 v1 h-3Z M6 44 h3 v1 h-3Z M6 45 h3 v1 h-3Z M6 46 h3 v1 h-3Z \" /\u003e\u003c/svg\u003e\n\n    \u003c/a\u003e\n    \u003cfigcaption aria-hidden=\"true\" class=\"hidden\" hidden\u003eDonate for Stéphane HUC by Paypal\u003c/figcaption\u003e\n\u003c/figure\u003e\n\n\n\u003ch3 id=\"tipeee\"\u003eTip\u003cem\u003eeee\u003c/em\u003e\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://fr.tipeee.com/hucste\" rel=\"external\"\u003ehttps://fr.tipeee.com/hucste\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\n\u003cfigure class=\"pure-img\"\u003e\n    \u003ca href=\"/svg/qrcode/tipee.svg\" title=\"Reward Stéphane HUC\"\u003e\n    \u003csvg xmlns=\"http://www.w3.org/2000/svg\" height=\"128\" viewBox=\"0 0 53 53\" width=\"128\"\u003e\n\u003cdefs\u003e\u003cstyle\u003erect{shape-rendering:crispEdges}\u003c/style\u003e\u003c/defs\u003e\n\u003cpath class=\"qr-4 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M14 4 h1 v1 h-1Z M16 4 h1 v1 h-1Z M18 4 h1 v1 h-1Z M20 4 h1 v1 h-1Z M22 4 h2 v1 h-2Z M25 4 h1 v1 h-1Z M27 4 h4 v1 h-4Z M35 4 h2 v1 h-2Z M17 5 h5 v1 h-5Z M23 5 h1 v1 h-1Z M27 5 h1 v1 h-1Z M32 5 h2 v1 h-2Z M35 5 h1 v1 h-1Z M13 6 h1 v1 h-1Z M15 6 h3 v1 h-3Z M19 6 h1 v1 h-1Z M22 6 h2 v1 h-2Z M25 6 h1 v1 h-1Z M29 6 h1 v1 h-1Z M31 6 h1 v1 h-1Z M35 6 h1 v1 h-1Z M13 7 h1 v1 h-1Z M15 7 h1 v1 h-1Z M17 7 h1 v1 h-1Z M19 7 h1 v1 h-1Z M21 7 h2 v1 h-2Z M26 7 h3 v1 h-3Z M31 7 h1 v1 h-1Z M33 7 h3 v1 h-3Z M37 7 h1 v1 h-1Z M13 8 h3 v1 h-3Z M17 8 h1 v1 h-1Z M23 8 h1 v1 h-1Z M30 8 h2 v1 h-2Z M35 8 h3 v1 h-3Z M14 9 h3 v1 h-3Z M19 9 h1 v1 h-1Z M22 9 h2 v1 h-2Z M29 9 h2 v1 h-2Z M32 9 h1 v1 h-1Z M35 9 h1 v1 h-1Z M13 11 h1 v1 h-1Z M15 11 h2 v1 h-2Z M20 11 h1 v1 h-1Z M23 11 h1 v1 h-1Z M30 11 h1 v1 h-1Z M32 11 h1 v1 h-1Z M34 11 h4 v1 h-4Z M39 11 h1 v1 h-1Z M13 12 h1 v1 h-1Z M16 12 h1 v1 h-1Z M19 12 h1 v1 h-1Z M21 12 h3 v1 h-3Z M31 12 h2 v1 h-2Z M35 12 h1 v1 h-1Z M38 12 h1 v1 h-1Z M4 13 h1 v1 h-1Z M6 13 h2 v1 h-2Z M11 13 h3 v1 h-3Z M15 13 h2 v1 h-2Z M23 13 h1 v1 h-1Z M26 13 h2 v1 h-2Z M30 13 h1 v1 h-1Z M34 13 h3 v1 h-3Z M38 13 h1 v1 h-1Z M40 13 h1 v1 h-1Z M42 13 h4 v1 h-4Z M47 13 h2 v1 h-2Z M4 14 h4 v1 h-4Z M9 14 h1 v1 h-1Z M12 14 h2 v1 h-2Z M15 14 h3 v1 h-3Z M19 14 h3 v1 h-3Z M23 14 h3 v1 h-3Z M28 14 h3 v1 h-3Z M32 14 h1 v1 h-1Z M35 14 h1 v1 h-1Z M37 14 h2 v1 h-2Z M43 14 h1 v1 h-1Z M45 14 h3 v1 h-3Z M5 15 h1 v1 h-1Z M9 15 h1 v1 h-1Z M14 15 h2 v1 h-2Z M17 15 h2 v1 h-2Z M20 15 h2 v1 h-2Z M24 15 h4 v1 h-4Z M30 15 h1 v1 h-1Z M33 15 h1 v1 h-1Z M36 15 h2 v1 h-2Z M40 15 h1 v1 h-1Z M42 15 h1 v1 h-1Z M44 15 h2 v1 h-2Z M47 15 h2 v1 h-2Z M4 16 h2 v1 h-2Z M7 16 h1 v1 h-1Z M13 16 h1 v1 h-1Z M20 16 h1 v1 h-1Z M22 16 h2 v1 h-2Z M25 16 h2 v1 h-2Z M29 16 h1 v1 h-1Z M33 16 h2 v1 h-2Z M36 16 h1 v1 h-1Z M38 16 h2 v1 h-2Z M41 16 h1 v1 h-1Z M44 16 h2 v1 h-2Z M47 16 h1 v1 h-1Z M4 17 h1 v1 h-1Z M9 17 h1 v1 h-1Z M12 17 h3 v1 h-3Z M16 17 h1 v1 h-1Z M18 17 h2 v1 h-2Z M24 17 h2 v1 h-2Z M29 17 h2 v1 h-2Z M32 17 h2 v1 h-2Z M37 17 h3 v1 h-3Z M41 17 h2 v1 h-2Z M47 17 h1 v1 h-1Z M6 18 h1 v1 h-1Z M9 18 h1 v1 h-1Z M12 18 h1 v1 h-1Z M14 18 h1 v1 h-1Z M16 18 h1 v1 h-1Z M18 18 h2 v1 h-2Z M21 18 h2 v1 h-2Z M24 18 h2 v1 h-2Z M27 18 h3 v1 h-3Z M31 18 h3 v1 h-3Z M36 18 h5 v1 h-5Z M42 18 h1 v1 h-1Z M44 18 h2 v1 h-2Z M5 19 h2 v1 h-2Z M11 19 h1 v1 h-1Z M13 19 h1 v1 h-1Z M16 19 h5 v1 h-5Z M23 19 h6 v1 h-6Z M30 19 h1 v1 h-1Z M34 19 h2 v1 h-2Z M38 19 h2 v1 h-2Z M41 19 h2 v1 h-2Z M44 19 h4 v1 h-4Z M5 20 h1 v1 h-1Z M11 20 h1 v1 h-1Z M13 20 h1 v1 h-1Z M15 20 h3 v1 h-3Z M20 20 h1 v1 h-1Z M22 20 h1 v1 h-1Z M24 20 h2 v1 h-2Z M28 20 h4 v1 h-4Z M39 20 h2 v1 h-2Z M43 20 h1 v1 h-1Z M46 20 h2 v1 h-2Z M6 21 h2 v1 h-2Z M11 21 h4 v1 h-4Z M16 21 h1 v1 h-1Z M20 21 h1 v1 h-1Z M22 21 h2 v1 h-2Z M25 21 h1 v1 h-1Z M27 21 h1 v1 h-1Z M29 21 h3 v1 h-3Z M34 21 h1 v1 h-1Z M36 21 h1 v1 h-1Z M38 21 h3 v1 h-3Z M42 21 h2 v1 h-2Z M46 21 h2 v1 h-2Z M5 22 h1 v1 h-1Z M8 22 h2 v1 h-2Z M12 22 h2 v1 h-2Z M15 22 h1 v1 h-1Z M18 22 h1 v1 h-1Z M21 22 h4 v1 h-4Z M27 22 h1 v1 h-1Z M29 22 h1 v1 h-1Z M35 22 h2 v1 h-2Z M40 22 h3 v1 h-3Z M44 22 h2 v1 h-2Z M9 23 h1 v1 h-1Z M16 23 h1 v1 h-1Z M18 23 h2 v1 h-2Z M21 23 h1 v1 h-1Z M23 23 h2 v1 h-2Z M27 23 h2 v1 h-2Z M32 23 h2 v1 h-2Z M37 23 h1 v1 h-1Z M40 23 h2 v1 h-2Z M45 23 h4 v1 h-4Z M7 24 h1 v1 h-1Z M15 24 h1 v1 h-1Z M18 24 h5 v1 h-5Z M30 24 h1 v1 h-1Z M33 24 h3 v1 h-3Z M37 24 h3 v1 h-3Z M45 24 h4 v1 h-4Z M5 25 h1 v1 h-1Z M7 25 h1 v1 h-1Z M17 25 h1 v1 h-1Z M19 25 h2 v1 h-2Z M23 25 h1 v1 h-1Z M29 25 h3 v1 h-3Z M33 25 h1 v1 h-1Z M37 25 h1 v1 h-1Z M39 25 h1 v1 h-1Z M45 25 h2 v1 h-2Z M4 26 h1 v1 h-1Z M7 26 h1 v1 h-1Z M14 26 h1 v1 h-1Z M23 26 h1 v1 h-1Z M30 26 h1 v1 h-1Z M33 26 h1 v1 h-1Z M35 26 h1 v1 h-1Z M37 26 h1 v1 h-1Z M39 26 h1 v1 h-1Z M45 26 h1 v1 h-1Z M6 27 h1 v1 h-1Z M13 27 h1 v1 h-1Z M16 27 h1 v1 h-1Z M20 27 h4 v1 h-4Z M29 27 h1 v1 h-1Z M33 27 h1 v1 h-1Z M35 27 h2 v1 h-2Z M38 27 h1 v1 h-1Z M45 27 h4 v1 h-4Z M4 28 h4 v1 h-4Z M13 28 h5 v1 h-5Z M20 28 h2 v1 h-2Z M30 28 h2 v1 h-2Z M35 28 h1 v1 h-1Z M39 28 h1 v1 h-1Z M45 28 h2 v1 h-2Z M48 28 h1 v1 h-1Z M4 29 h1 v1 h-1Z M6 29 h2 v1 h-2Z M9 29 h1 v1 h-1Z M14 29 h2 v1 h-2Z M17 29 h2 v1 h-2Z M24 29 h6 v1 h-6Z M31 29 h6 v1 h-6Z M38 29 h3 v1 h-3Z M43 29 h3 v1 h-3Z M47 29 h2 v1 h-2Z M7 30 h2 v1 h-2Z M11 30 h1 v1 h-1Z M13 30 h1 v1 h-1Z M15 30 h1 v1 h-1Z M19 30 h2 v1 h-2Z M23 30 h3 v1 h-3Z M27 30 h2 v1 h-2Z M30 30 h3 v1 h-3Z M35 30 h1 v1 h-1Z M40 30 h1 v1 h-1Z M42 30 h1 v1 h-1Z M45 30 h3 v1 h-3Z M4 31 h1 v1 h-1Z M7 31 h1 v1 h-1Z M9 31 h1 v1 h-1Z M13 31 h1 v1 h-1Z M17 31 h1 v1 h-1Z M19 31 h1 v1 h-1Z M23 31 h1 v1 h-1Z M26 31 h1 v1 h-1Z M28 31 h4 v1 h-4Z M33 31 h1 v1 h-1Z M36 31 h2 v1 h-2Z M40 31 h1 v1 h-1Z M42 31 h4 v1 h-4Z M47 31 h2 v1 h-2Z M5 32 h1 v1 h-1Z M8 32 h2 v1 h-2Z M13 32 h1 v1 h-1Z M16 32 h1 v1 h-1Z M18 32 h1 v1 h-1Z M21 32 h1 v1 h-1Z M23 32 h2 v1 h-2Z M26 32 h4 v1 h-4Z M33 32 h2 v1 h-2Z M36 32 h1 v1 h-1Z M38 32 h4 v1 h-4Z M44 32 h2 v1 h-2Z M47 32 h1 v1 h-1Z M4 33 h2 v1 h-2Z M7 33 h1 v1 h-1Z M9 33 h1 v1 h-1Z M13 33 h2 v1 h-2Z M16 33 h2 v1 h-2Z M19 33 h1 v1 h-1Z M21 33 h1 v1 h-1Z M23 33 h2 v1 h-2Z M26 33 h1 v1 h-1Z M28 33 h1 v1 h-1Z M30 33 h2 v1 h-2Z M33 33 h1 v1 h-1Z M37 33 h2 v1 h-2Z M40 33 h5 v1 h-5Z M46 33 h1 v1 h-1Z M48 33 h1 v1 h-1Z M5 34 h5 v1 h-5Z M12 34 h1 v1 h-1Z M19 34 h2 v1 h-2Z M23 34 h1 v1 h-1Z M25 34 h1 v1 h-1Z M28 34 h1 v1 h-1Z M31 34 h1 v1 h-1Z M33 34 h1 v1 h-1Z M36 34 h4 v1 h-4Z M41 34 h1 v1 h-1Z M43 34 h1 v1 h-1Z M48 34 h1 v1 h-1Z M4 35 h1 v1 h-1Z M6 35 h1 v1 h-1Z M8 35 h2 v1 h-2Z M13 35 h2 v1 h-2Z M16 35 h5 v1 h-5Z M23 35 h5 v1 h-5Z M30 35 h1 v1 h-1Z M32 35 h6 v1 h-6Z M41 35 h4 v1 h-4Z M46 35 h1 v1 h-1Z M5 36 h2 v1 h-2Z M8 36 h2 v1 h-2Z M12 36 h1 v1 h-1Z M15 36 h1 v1 h-1Z M20 36 h1 v1 h-1Z M22 36 h3 v1 h-3Z M27 36 h2 v1 h-2Z M32 36 h2 v1 h-2Z M35 36 h1 v1 h-1Z M42 36 h2 v1 h-2Z M48 36 h1 v1 h-1Z M5 37 h2 v1 h-2Z M11 37 h1 v1 h-1Z M13 37 h2 v1 h-2Z M17 37 h4 v1 h-4Z M24 37 h1 v1 h-1Z M26 37 h2 v1 h-2Z M30 37 h1 v1 h-1Z M33 37 h1 v1 h-1Z M35 37 h2 v1 h-2Z M38 37 h2 v1 h-2Z M43 37 h1 v1 h-1Z M45 37 h3 v1 h-3Z M11 38 h9 v1 h-9Z M23 38 h3 v1 h-3Z M27 38 h4 v1 h-4Z M33 38 h3 v1 h-3Z M37 38 h2 v1 h-2Z M40 38 h1 v1 h-1Z M42 38 h4 v1 h-4Z M11 39 h1 v1 h-1Z M13 39 h3 v1 h-3Z M18 39 h5 v1 h-5Z M24 39 h3 v1 h-3Z M30 39 h1 v1 h-1Z M37 39 h1 v1 h-1Z M40 39 h1 v1 h-1Z M42 39 h2 v1 h-2Z M45 39 h3 v1 h-3Z M12 40 h4 v1 h-4Z M18 40 h1 v1 h-1Z M20 40 h3 v1 h-3Z M32 40 h3 v1 h-3Z M37 40 h3 v1 h-3Z M46 40 h2 v1 h-2Z M13 41 h5 v1 h-5Z M32 41 h1 v1 h-1Z M34 41 h2 v1 h-2Z M37 41 h1 v1 h-1Z M39 41 h1 v1 h-1Z M45 41 h2 v1 h-2Z M13 42 h1 v1 h-1Z M15 42 h2 v1 h-2Z M20 42 h2 v1 h-2Z M29 42 h6 v1 h-6Z M36 42 h2 v1 h-2Z M39 42 h1 v1 h-1Z M18 43 h5 v1 h-5Z M30 43 h1 v1 h-1Z M33 43 h1 v1 h-1Z M35 43 h1 v1 h-1Z M38 43 h1 v1 h-1Z M45 43 h2 v1 h-2Z M48 43 h1 v1 h-1Z M13 44 h2 v1 h-2Z M16 44 h1 v1 h-1Z M18 44 h1 v1 h-1Z M20 44 h3 v1 h-3Z M29 44 h2 v1 h-2Z M32 44 h3 v1 h-3Z M39 44 h1 v1 h-1Z M45 44 h2 v1 h-2Z M13 45 h3 v1 h-3Z M17 45 h1 v1 h-1Z M19 45 h2 v1 h-2Z M22 45 h2 v1 h-2Z M26 45 h5 v1 h-5Z M32 45 h1 v1 h-1Z M38 45 h1 v1 h-1Z M42 45 h7 v1 h-7Z M13 46 h2 v1 h-2Z M18 46 h1 v1 h-1Z M20 46 h1 v1 h-1Z M22 46 h1 v1 h-1Z M25 46 h1 v1 h-1Z M27 46 h1 v1 h-1Z M29 46 h2 v1 h-2Z M42 46 h2 v1 h-2Z M47 46 h1 v1 h-1Z M13 47 h1 v1 h-1Z M15 47 h1 v1 h-1Z M18 47 h1 v1 h-1Z M20 47 h1 v1 h-1Z M22 47 h4 v1 h-4Z M29 47 h3 v1 h-3Z M33 47 h2 v1 h-2Z M36 47 h2 v1 h-2Z M42 47 h3 v1 h-3Z M46 47 h1 v1 h-1Z M48 47 h1 v1 h-1Z M13 48 h5 v1 h-5Z M19 48 h2 v1 h-2Z M22 48 h1 v1 h-1Z M25 48 h3 v1 h-3Z M30 48 h5 v1 h-5Z M36 48 h3 v1 h-3Z M40 48 h1 v1 h-1Z M42 48 h2 v1 h-2Z M45 48 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-6 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M5 5 h5 v1 h-5Z M43 5 h5 v1 h-5Z M5 6 h1 v1 h-1Z M9 6 h1 v1 h-1Z M43 6 h1 v1 h-1Z M47 6 h1 v1 h-1Z M5 7 h1 v1 h-1Z M9 7 h1 v1 h-1Z M43 7 h1 v1 h-1Z M47 7 h1 v1 h-1Z M5 8 h1 v1 h-1Z M9 8 h1 v1 h-1Z M43 8 h1 v1 h-1Z M47 8 h1 v1 h-1Z M5 9 h5 v1 h-5Z M43 9 h5 v1 h-5Z M5 43 h5 v1 h-5Z M5 44 h1 v1 h-1Z M9 44 h1 v1 h-1Z M5 45 h1 v1 h-1Z M9 45 h1 v1 h-1Z M5 46 h1 v1 h-1Z M9 46 h1 v1 h-1Z M5 47 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-8 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M11 4 h1 v1 h-1Z M41 4 h1 v1 h-1Z M11 5 h1 v1 h-1Z M41 5 h1 v1 h-1Z M11 6 h1 v1 h-1Z M41 6 h1 v1 h-1Z M11 7 h1 v1 h-1Z M41 7 h1 v1 h-1Z M11 8 h1 v1 h-1Z M41 8 h1 v1 h-1Z M11 9 h1 v1 h-1Z M41 9 h1 v1 h-1Z M11 10 h1 v1 h-1Z M41 10 h1 v1 h-1Z M4 11 h8 v1 h-8Z M41 11 h8 v1 h-8Z M4 41 h8 v1 h-8Z M11 42 h1 v1 h-1Z M11 43 h1 v1 h-1Z M11 44 h1 v1 h-1Z M11 45 h1 v1 h-1Z M11 46 h1 v1 h-1Z M11 47 h1 v1 h-1Z M11 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-10 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M25 9 h3 v1 h-3Z M25 10 h1 v1 h-1Z M27 10 h1 v1 h-1Z M25 11 h3 v1 h-3Z M9 25 h3 v1 h-3Z M25 25 h3 v1 h-3Z M41 25 h3 v1 h-3Z M9 26 h1 v1 h-1Z M11 26 h1 v1 h-1Z M25 26 h1 v1 h-1Z M27 26 h1 v1 h-1Z M41 26 h1 v1 h-1Z M43 26 h1 v1 h-1Z M9 27 h3 v1 h-3Z M25 27 h3 v1 h-3Z M41 27 h3 v1 h-3Z M25 41 h3 v1 h-3Z M41 41 h3 v1 h-3Z M25 42 h1 v1 h-1Z M27 42 h1 v1 h-1Z M41 42 h1 v1 h-1Z M43 42 h1 v1 h-1Z M25 43 h3 v1 h-3Z M41 43 h3 v1 h-3Z \" /\u003e\u003cpath class=\"qr-12 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M13 10 h1 v1 h-1Z M15 10 h1 v1 h-1Z M17 10 h1 v1 h-1Z M19 10 h1 v1 h-1Z M21 10 h1 v1 h-1Z M23 10 h1 v1 h-1Z M29 10 h1 v1 h-1Z M31 10 h1 v1 h-1Z M33 10 h1 v1 h-1Z M35 10 h1 v1 h-1Z M37 10 h1 v1 h-1Z M39 10 h1 v1 h-1Z M10 13 h1 v1 h-1Z M10 15 h1 v1 h-1Z M10 17 h1 v1 h-1Z M10 19 h1 v1 h-1Z M10 21 h1 v1 h-1Z M10 23 h1 v1 h-1Z M10 29 h1 v1 h-1Z M10 31 h1 v1 h-1Z M10 33 h1 v1 h-1Z M10 35 h1 v1 h-1Z M10 37 h1 v1 h-1Z M10 39 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-14 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M12 5 h1 v1 h-1Z M12 6 h1 v1 h-1Z M12 8 h1 v1 h-1Z M12 9 h1 v1 h-1Z M12 11 h1 v1 h-1Z M4 12 h2 v1 h-2Z M7 12 h1 v1 h-1Z M11 12 h1 v1 h-1Z M42 12 h3 v1 h-3Z M46 12 h2 v1 h-2Z M12 42 h1 v1 h-1Z M12 45 h1 v1 h-1Z M12 47 h1 v1 h-1Z M12 48 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-16 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M38 4 h2 v1 h-2Z M38 5 h1 v1 h-1Z M40 5 h1 v1 h-1Z M38 6 h1 v1 h-1Z M40 6 h1 v1 h-1Z M38 7 h1 v1 h-1Z M38 9 h3 v1 h-3Z M4 38 h4 v1 h-4Z M9 38 h1 v1 h-1Z M4 39 h1 v1 h-1Z M9 39 h1 v1 h-1Z M5 40 h2 v1 h-2Z M9 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-18 \" stroke=\"transparent\" fill=\"#fff\" fill-opacity=\"1\" d=\"M0 0 h53 v1 h-53Z M0 1 h53 v1 h-53Z M0 2 h53 v1 h-53Z M0 3 h53 v1 h-53Z M0 4 h4 v1 h-4Z M49 4 h4 v1 h-4Z M0 5 h4 v1 h-4Z M49 5 h4 v1 h-4Z M0 6 h4 v1 h-4Z M49 6 h4 v1 h-4Z M0 7 h4 v1 h-4Z M49 7 h4 v1 h-4Z M0 8 h4 v1 h-4Z M49 8 h4 v1 h-4Z M0 9 h4 v1 h-4Z M49 9 h4 v1 h-4Z M0 10 h4 v1 h-4Z M49 10 h4 v1 h-4Z M0 11 h4 v1 h-4Z M49 11 h4 v1 h-4Z M0 12 h4 v1 h-4Z M49 12 h4 v1 h-4Z M0 13 h4 v1 h-4Z M49 13 h4 v1 h-4Z M0 14 h4 v1 h-4Z M49 14 h4 v1 h-4Z M0 15 h4 v1 h-4Z M49 15 h4 v1 h-4Z M0 16 h4 v1 h-4Z M49 16 h4 v1 h-4Z M0 17 h4 v1 h-4Z M49 17 h4 v1 h-4Z M0 18 h4 v1 h-4Z M49 18 h4 v1 h-4Z M0 19 h4 v1 h-4Z M49 19 h4 v1 h-4Z M0 20 h4 v1 h-4Z M49 20 h4 v1 h-4Z M0 21 h4 v1 h-4Z M49 21 h4 v1 h-4Z M0 22 h4 v1 h-4Z M49 22 h4 v1 h-4Z M0 23 h4 v1 h-4Z M49 23 h4 v1 h-4Z M0 24 h4 v1 h-4Z M49 24 h4 v1 h-4Z M0 25 h4 v1 h-4Z M49 25 h4 v1 h-4Z M0 26 h4 v1 h-4Z M49 26 h4 v1 h-4Z M0 27 h4 v1 h-4Z M49 27 h4 v1 h-4Z M0 28 h4 v1 h-4Z M49 28 h4 v1 h-4Z M0 29 h4 v1 h-4Z M49 29 h4 v1 h-4Z M0 30 h4 v1 h-4Z M49 30 h4 v1 h-4Z M0 31 h4 v1 h-4Z M49 31 h4 v1 h-4Z M0 32 h4 v1 h-4Z M49 32 h4 v1 h-4Z M0 33 h4 v1 h-4Z M49 33 h4 v1 h-4Z M0 34 h4 v1 h-4Z M49 34 h4 v1 h-4Z M0 35 h4 v1 h-4Z M49 35 h4 v1 h-4Z M0 36 h4 v1 h-4Z M49 36 h4 v1 h-4Z M0 37 h4 v1 h-4Z M49 37 h4 v1 h-4Z M0 38 h4 v1 h-4Z M49 38 h4 v1 h-4Z M0 39 h4 v1 h-4Z M49 39 h4 v1 h-4Z M0 40 h4 v1 h-4Z M49 40 h4 v1 h-4Z M0 41 h4 v1 h-4Z M49 41 h4 v1 h-4Z M0 42 h4 v1 h-4Z M49 42 h4 v1 h-4Z M0 43 h4 v1 h-4Z M49 43 h4 v1 h-4Z M0 44 h4 v1 h-4Z M49 44 h4 v1 h-4Z M0 45 h4 v1 h-4Z M49 45 h4 v1 h-4Z M0 46 h4 v1 h-4Z M49 46 h4 v1 h-4Z M0 47 h4 v1 h-4Z M49 47 h4 v1 h-4Z M0 48 h4 v1 h-4Z M49 48 h4 v1 h-4Z M0 49 h53 v1 h-53Z M0 50 h53 v1 h-53Z M0 51 h53 v1 h-53Z M0 52 h53 v1 h-53Z \" /\u003e\u003cpath class=\"qr-512 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 41 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-1024 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M13 4 h1 v1 h-1Z M15 4 h1 v1 h-1Z M17 4 h1 v1 h-1Z M19 4 h1 v1 h-1Z M21 4 h1 v1 h-1Z M24 4 h1 v1 h-1Z M26 4 h1 v1 h-1Z M31 4 h4 v1 h-4Z M37 4 h1 v1 h-1Z M13 5 h4 v1 h-4Z M22 5 h1 v1 h-1Z M24 5 h3 v1 h-3Z M28 5 h4 v1 h-4Z M34 5 h1 v1 h-1Z M36 5 h2 v1 h-2Z M14 6 h1 v1 h-1Z M18 6 h1 v1 h-1Z M20 6 h2 v1 h-2Z M24 6 h1 v1 h-1Z M26 6 h3 v1 h-3Z M30 6 h1 v1 h-1Z M32 6 h3 v1 h-3Z M36 6 h2 v1 h-2Z M14 7 h1 v1 h-1Z M16 7 h1 v1 h-1Z M18 7 h1 v1 h-1Z M20 7 h1 v1 h-1Z M23 7 h3 v1 h-3Z M29 7 h2 v1 h-2Z M32 7 h1 v1 h-1Z M36 7 h1 v1 h-1Z M16 8 h1 v1 h-1Z M18 8 h5 v1 h-5Z M29 8 h1 v1 h-1Z M32 8 h3 v1 h-3Z M13 9 h1 v1 h-1Z M17 9 h2 v1 h-2Z M20 9 h2 v1 h-2Z M31 9 h1 v1 h-1Z M33 9 h2 v1 h-2Z M36 9 h2 v1 h-2Z M14 11 h1 v1 h-1Z M17 11 h3 v1 h-3Z M21 11 h2 v1 h-2Z M29 11 h1 v1 h-1Z M31 11 h1 v1 h-1Z M33 11 h1 v1 h-1Z M38 11 h1 v1 h-1Z M40 11 h1 v1 h-1Z M14 12 h2 v1 h-2Z M17 12 h2 v1 h-2Z M20 12 h1 v1 h-1Z M29 12 h2 v1 h-2Z M33 12 h2 v1 h-2Z M36 12 h2 v1 h-2Z M39 12 h2 v1 h-2Z M5 13 h1 v1 h-1Z M8 13 h2 v1 h-2Z M14 13 h1 v1 h-1Z M17 13 h6 v1 h-6Z M24 13 h2 v1 h-2Z M28 13 h2 v1 h-2Z M31 13 h3 v1 h-3Z M37 13 h1 v1 h-1Z M39 13 h1 v1 h-1Z M41 13 h1 v1 h-1Z M46 13 h1 v1 h-1Z M8 14 h1 v1 h-1Z M11 14 h1 v1 h-1Z M14 14 h1 v1 h-1Z M18 14 h1 v1 h-1Z M22 14 h1 v1 h-1Z M26 14 h2 v1 h-2Z M31 14 h1 v1 h-1Z M33 14 h2 v1 h-2Z M36 14 h1 v1 h-1Z M39 14 h4 v1 h-4Z M44 14 h1 v1 h-1Z M48 14 h1 v1 h-1Z M4 15 h1 v1 h-1Z M6 15 h3 v1 h-3Z M11 15 h3 v1 h-3Z M16 15 h1 v1 h-1Z M19 15 h1 v1 h-1Z M22 15 h2 v1 h-2Z M28 15 h2 v1 h-2Z M31 15 h2 v1 h-2Z M34 15 h2 v1 h-2Z M38 15 h2 v1 h-2Z M41 15 h1 v1 h-1Z M43 15 h1 v1 h-1Z M46 15 h1 v1 h-1Z M6 16 h1 v1 h-1Z M8 16 h2 v1 h-2Z M11 16 h2 v1 h-2Z M14 16 h6 v1 h-6Z M21 16 h1 v1 h-1Z M24 16 h1 v1 h-1Z M27 16 h2 v1 h-2Z M30 16 h3 v1 h-3Z M35 16 h1 v1 h-1Z M37 16 h1 v1 h-1Z M40 16 h1 v1 h-1Z M42 16 h2 v1 h-2Z M46 16 h1 v1 h-1Z M48 16 h1 v1 h-1Z M5 17 h4 v1 h-4Z M11 17 h1 v1 h-1Z M15 17 h1 v1 h-1Z M17 17 h1 v1 h-1Z M20 17 h4 v1 h-4Z M26 17 h3 v1 h-3Z M31 17 h1 v1 h-1Z M34 17 h3 v1 h-3Z M40 17 h1 v1 h-1Z M43 17 h4 v1 h-4Z M48 17 h1 v1 h-1Z M4 18 h2 v1 h-2Z M7 18 h2 v1 h-2Z M11 18 h1 v1 h-1Z M13 18 h1 v1 h-1Z M15 18 h1 v1 h-1Z M17 18 h1 v1 h-1Z M20 18 h1 v1 h-1Z M23 18 h1 v1 h-1Z M26 18 h1 v1 h-1Z M30 18 h1 v1 h-1Z M34 18 h2 v1 h-2Z M41 18 h1 v1 h-1Z M43 18 h1 v1 h-1Z M46 18 h3 v1 h-3Z M4 19 h1 v1 h-1Z M7 19 h3 v1 h-3Z M12 19 h1 v1 h-1Z M14 19 h2 v1 h-2Z M21 19 h2 v1 h-2Z M29 19 h1 v1 h-1Z M31 19 h3 v1 h-3Z M36 19 h2 v1 h-2Z M40 19 h1 v1 h-1Z M43 19 h1 v1 h-1Z M48 19 h1 v1 h-1Z M4 20 h1 v1 h-1Z M6 20 h4 v1 h-4Z M12 20 h1 v1 h-1Z M14 20 h1 v1 h-1Z M18 20 h2 v1 h-2Z M21 20 h1 v1 h-1Z M23 20 h1 v1 h-1Z M26 20 h2 v1 h-2Z M32 20 h7 v1 h-7Z M41 20 h2 v1 h-2Z M44 20 h2 v1 h-2Z M48 20 h1 v1 h-1Z M4 21 h2 v1 h-2Z M8 21 h2 v1 h-2Z M15 21 h1 v1 h-1Z M17 21 h3 v1 h-3Z M21 21 h1 v1 h-1Z M24 21 h1 v1 h-1Z M26 21 h1 v1 h-1Z M28 21 h1 v1 h-1Z M32 21 h2 v1 h-2Z M35 21 h1 v1 h-1Z M37 21 h1 v1 h-1Z M41 21 h1 v1 h-1Z M44 21 h2 v1 h-2Z M48 21 h1 v1 h-1Z M4 22 h1 v1 h-1Z M6 22 h2 v1 h-2Z M11 22 h1 v1 h-1Z M14 22 h1 v1 h-1Z M16 22 h2 v1 h-2Z M19 22 h2 v1 h-2Z M25 22 h2 v1 h-2Z M28 22 h1 v1 h-1Z M30 22 h5 v1 h-5Z M37 22 h3 v1 h-3Z M43 22 h1 v1 h-1Z M46 22 h3 v1 h-3Z M4 23 h5 v1 h-5Z M11 23 h5 v1 h-5Z M17 23 h1 v1 h-1Z M20 23 h1 v1 h-1Z M22 23 h1 v1 h-1Z M25 23 h2 v1 h-2Z M29 23 h3 v1 h-3Z M34 23 h3 v1 h-3Z M38 23 h2 v1 h-2Z M42 23 h3 v1 h-3Z M4 24 h3 v1 h-3Z M13 24 h2 v1 h-2Z M16 24 h2 v1 h-2Z M23 24 h1 v1 h-1Z M29 24 h1 v1 h-1Z M31 24 h2 v1 h-2Z M36 24 h1 v1 h-1Z M4 25 h1 v1 h-1Z M6 25 h1 v1 h-1Z M13 25 h4 v1 h-4Z M18 25 h1 v1 h-1Z M21 25 h2 v1 h-2Z M32 25 h1 v1 h-1Z M34 25 h3 v1 h-3Z M38 25 h1 v1 h-1Z M47 25 h2 v1 h-2Z M5 26 h2 v1 h-2Z M13 26 h1 v1 h-1Z M15 26 h8 v1 h-8Z M29 26 h1 v1 h-1Z M31 26 h2 v1 h-2Z M34 26 h1 v1 h-1Z M36 26 h1 v1 h-1Z M38 26 h1 v1 h-1Z M46 26 h3 v1 h-3Z M4 27 h2 v1 h-2Z M7 27 h1 v1 h-1Z M14 27 h2 v1 h-2Z M17 27 h3 v1 h-3Z M30 27 h3 v1 h-3Z M34 27 h1 v1 h-1Z M37 27 h1 v1 h-1Z M39 27 h1 v1 h-1Z M18 28 h2 v1 h-2Z M22 28 h2 v1 h-2Z M29 28 h1 v1 h-1Z M32 28 h3 v1 h-3Z M36 28 h3 v1 h-3Z M47 28 h1 v1 h-1Z M5 29 h1 v1 h-1Z M8 29 h1 v1 h-1Z M11 29 h3 v1 h-3Z M16 29 h1 v1 h-1Z M19 29 h5 v1 h-5Z M30 29 h1 v1 h-1Z M37 29 h1 v1 h-1Z M41 29 h2 v1 h-2Z M46 29 h1 v1 h-1Z M4 30 h3 v1 h-3Z M9 30 h1 v1 h-1Z M12 30 h1 v1 h-1Z M14 30 h1 v1 h-1Z M16 30 h3 v1 h-3Z M21 30 h2 v1 h-2Z M26 30 h1 v1 h-1Z M29 30 h1 v1 h-1Z M33 30 h2 v1 h-2Z M36 30 h4 v1 h-4Z M41 30 h1 v1 h-1Z M43 30 h2 v1 h-2Z M48 30 h1 v1 h-1Z M5 31 h2 v1 h-2Z M8 31 h1 v1 h-1Z M11 31 h2 v1 h-2Z M14 31 h3 v1 h-3Z M18 31 h1 v1 h-1Z M20 31 h3 v1 h-3Z M24 31 h2 v1 h-2Z M27 31 h1 v1 h-1Z M32 31 h1 v1 h-1Z M34 31 h2 v1 h-2Z M38 31 h2 v1 h-2Z M41 31 h1 v1 h-1Z M46 31 h1 v1 h-1Z M4 32 h1 v1 h-1Z M6 32 h2 v1 h-2Z M11 32 h2 v1 h-2Z M14 32 h2 v1 h-2Z M17 32 h1 v1 h-1Z M19 32 h2 v1 h-2Z M22 32 h1 v1 h-1Z M25 32 h1 v1 h-1Z M30 32 h3 v1 h-3Z M35 32 h1 v1 h-1Z M37 32 h1 v1 h-1Z M42 32 h2 v1 h-2Z M46 32 h1 v1 h-1Z M48 32 h1 v1 h-1Z M6 33 h1 v1 h-1Z M8 33 h1 v1 h-1Z M11 33 h2 v1 h-2Z M15 33 h1 v1 h-1Z M18 33 h1 v1 h-1Z M20 33 h1 v1 h-1Z M22 33 h1 v1 h-1Z M25 33 h1 v1 h-1Z M27 33 h1 v1 h-1Z M29 33 h1 v1 h-1Z M32 33 h1 v1 h-1Z M34 33 h3 v1 h-3Z M39 33 h1 v1 h-1Z M45 33 h1 v1 h-1Z M47 33 h1 v1 h-1Z M4 34 h1 v1 h-1Z M11 34 h1 v1 h-1Z M13 34 h6 v1 h-6Z M21 34 h2 v1 h-2Z M24 34 h1 v1 h-1Z M26 34 h2 v1 h-2Z M29 34 h2 v1 h-2Z M32 34 h1 v1 h-1Z M34 34 h2 v1 h-2Z M40 34 h1 v1 h-1Z M42 34 h1 v1 h-1Z M44 34 h4 v1 h-4Z M5 35 h1 v1 h-1Z M7 35 h1 v1 h-1Z M11 35 h2 v1 h-2Z M15 35 h1 v1 h-1Z M21 35 h2 v1 h-2Z M28 35 h2 v1 h-2Z M31 35 h1 v1 h-1Z M38 35 h3 v1 h-3Z M45 35 h1 v1 h-1Z M47 35 h2 v1 h-2Z M4 36 h1 v1 h-1Z M7 36 h1 v1 h-1Z M11 36 h1 v1 h-1Z M13 36 h2 v1 h-2Z M16 36 h4 v1 h-4Z M21 36 h1 v1 h-1Z M25 36 h2 v1 h-2Z M29 36 h3 v1 h-3Z M34 36 h1 v1 h-1Z M36 36 h6 v1 h-6Z M44 36 h4 v1 h-4Z M4 37 h1 v1 h-1Z M7 37 h3 v1 h-3Z M12 37 h1 v1 h-1Z M15 37 h2 v1 h-2Z M21 37 h3 v1 h-3Z M25 37 h1 v1 h-1Z M28 37 h2 v1 h-2Z M31 37 h2 v1 h-2Z M34 37 h1 v1 h-1Z M37 37 h1 v1 h-1Z M40 37 h3 v1 h-3Z M44 37 h1 v1 h-1Z M48 37 h1 v1 h-1Z M20 38 h3 v1 h-3Z M26 38 h1 v1 h-1Z M31 38 h2 v1 h-2Z M36 38 h1 v1 h-1Z M39 38 h1 v1 h-1Z M41 38 h1 v1 h-1Z M46 38 h3 v1 h-3Z M12 39 h1 v1 h-1Z M16 39 h2 v1 h-2Z M23 39 h1 v1 h-1Z M27 39 h3 v1 h-3Z M31 39 h6 v1 h-6Z M38 39 h2 v1 h-2Z M41 39 h1 v1 h-1Z M44 39 h1 v1 h-1Z M48 39 h1 v1 h-1Z M11 40 h1 v1 h-1Z M16 40 h2 v1 h-2Z M19 40 h1 v1 h-1Z M23 40 h1 v1 h-1Z M29 40 h3 v1 h-3Z M35 40 h2 v1 h-2Z M45 40 h1 v1 h-1Z M48 40 h1 v1 h-1Z M18 41 h6 v1 h-6Z M29 41 h3 v1 h-3Z M33 41 h1 v1 h-1Z M36 41 h1 v1 h-1Z M38 41 h1 v1 h-1Z M47 41 h2 v1 h-2Z M14 42 h1 v1 h-1Z M17 42 h3 v1 h-3Z M22 42 h2 v1 h-2Z M35 42 h1 v1 h-1Z M38 42 h1 v1 h-1Z M45 42 h4 v1 h-4Z M13 43 h5 v1 h-5Z M23 43 h1 v1 h-1Z M29 43 h1 v1 h-1Z M31 43 h2 v1 h-2Z M34 43 h1 v1 h-1Z M36 43 h2 v1 h-2Z M39 43 h1 v1 h-1Z M47 43 h1 v1 h-1Z M15 44 h1 v1 h-1Z M17 44 h1 v1 h-1Z M19 44 h1 v1 h-1Z M23 44 h1 v1 h-1Z M31 44 h1 v1 h-1Z M35 44 h4 v1 h-4Z M47 44 h2 v1 h-2Z M16 45 h1 v1 h-1Z M18 45 h1 v1 h-1Z M21 45 h1 v1 h-1Z M24 45 h2 v1 h-2Z M31 45 h1 v1 h-1Z M33 45 h5 v1 h-5Z M39 45 h3 v1 h-3Z M15 46 h3 v1 h-3Z M19 46 h1 v1 h-1Z M21 46 h1 v1 h-1Z M23 46 h2 v1 h-2Z M26 46 h1 v1 h-1Z M28 46 h1 v1 h-1Z M31 46 h11 v1 h-11Z M44 46 h3 v1 h-3Z M48 46 h1 v1 h-1Z M14 47 h1 v1 h-1Z M16 47 h2 v1 h-2Z M19 47 h1 v1 h-1Z M21 47 h1 v1 h-1Z M26 47 h3 v1 h-3Z M32 47 h1 v1 h-1Z M35 47 h1 v1 h-1Z M38 47 h4 v1 h-4Z M45 47 h1 v1 h-1Z M47 47 h1 v1 h-1Z M18 48 h1 v1 h-1Z M21 48 h1 v1 h-1Z M23 48 h2 v1 h-2Z M28 48 h2 v1 h-2Z M35 48 h1 v1 h-1Z M39 48 h1 v1 h-1Z M41 48 h1 v1 h-1Z M44 48 h1 v1 h-1Z M47 48 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-1536 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M4 4 h7 v1 h-7Z M42 4 h7 v1 h-7Z M4 5 h1 v1 h-1Z M10 5 h1 v1 h-1Z M42 5 h1 v1 h-1Z M48 5 h1 v1 h-1Z M4 6 h1 v1 h-1Z M10 6 h1 v1 h-1Z M42 6 h1 v1 h-1Z M48 6 h1 v1 h-1Z M4 7 h1 v1 h-1Z M10 7 h1 v1 h-1Z M42 7 h1 v1 h-1Z M48 7 h1 v1 h-1Z M4 8 h1 v1 h-1Z M10 8 h1 v1 h-1Z M42 8 h1 v1 h-1Z M48 8 h1 v1 h-1Z M4 9 h1 v1 h-1Z M10 9 h1 v1 h-1Z M42 9 h1 v1 h-1Z M48 9 h1 v1 h-1Z M4 10 h7 v1 h-7Z M42 10 h7 v1 h-7Z M4 42 h7 v1 h-7Z M4 43 h1 v1 h-1Z M10 43 h1 v1 h-1Z M4 44 h1 v1 h-1Z M10 44 h1 v1 h-1Z M4 45 h1 v1 h-1Z M10 45 h1 v1 h-1Z M4 46 h1 v1 h-1Z M10 46 h1 v1 h-1Z M4 47 h1 v1 h-1Z M10 47 h1 v1 h-1Z M4 48 h7 v1 h-7Z \" /\u003e\u003cpath class=\"qr-2560 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M24 8 h5 v1 h-5Z M24 9 h1 v1 h-1Z M28 9 h1 v1 h-1Z M24 10 h1 v1 h-1Z M26 10 h1 v1 h-1Z M28 10 h1 v1 h-1Z M24 11 h1 v1 h-1Z M28 11 h1 v1 h-1Z M24 12 h5 v1 h-5Z M8 24 h5 v1 h-5Z M24 24 h5 v1 h-5Z M40 24 h5 v1 h-5Z M8 25 h1 v1 h-1Z M12 25 h1 v1 h-1Z M24 25 h1 v1 h-1Z M28 25 h1 v1 h-1Z M40 25 h1 v1 h-1Z M44 25 h1 v1 h-1Z M8 26 h1 v1 h-1Z M10 26 h1 v1 h-1Z M12 26 h1 v1 h-1Z M24 26 h1 v1 h-1Z M26 26 h1 v1 h-1Z M28 26 h1 v1 h-1Z M40 26 h1 v1 h-1Z M42 26 h1 v1 h-1Z M44 26 h1 v1 h-1Z M8 27 h1 v1 h-1Z M12 27 h1 v1 h-1Z M24 27 h1 v1 h-1Z M28 27 h1 v1 h-1Z M40 27 h1 v1 h-1Z M44 27 h1 v1 h-1Z M8 28 h5 v1 h-5Z M24 28 h5 v1 h-5Z M40 28 h5 v1 h-5Z M24 40 h5 v1 h-5Z M40 40 h5 v1 h-5Z M24 41 h1 v1 h-1Z M28 41 h1 v1 h-1Z M40 41 h1 v1 h-1Z M44 41 h1 v1 h-1Z M24 42 h1 v1 h-1Z M26 42 h1 v1 h-1Z M28 42 h1 v1 h-1Z M40 42 h1 v1 h-1Z M42 42 h1 v1 h-1Z M44 42 h1 v1 h-1Z M24 43 h1 v1 h-1Z M28 43 h1 v1 h-1Z M40 43 h1 v1 h-1Z M44 43 h1 v1 h-1Z M24 44 h5 v1 h-5Z M40 44 h5 v1 h-5Z \" /\u003e\u003cpath class=\"qr-3072 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 10 h1 v1 h-1Z M14 10 h1 v1 h-1Z M16 10 h1 v1 h-1Z M18 10 h1 v1 h-1Z M20 10 h1 v1 h-1Z M22 10 h1 v1 h-1Z M30 10 h1 v1 h-1Z M32 10 h1 v1 h-1Z M34 10 h1 v1 h-1Z M36 10 h1 v1 h-1Z M38 10 h1 v1 h-1Z M40 10 h1 v1 h-1Z M10 12 h1 v1 h-1Z M10 14 h1 v1 h-1Z M10 16 h1 v1 h-1Z M10 18 h1 v1 h-1Z M10 20 h1 v1 h-1Z M10 22 h1 v1 h-1Z M10 30 h1 v1 h-1Z M10 32 h1 v1 h-1Z M10 34 h1 v1 h-1Z M10 36 h1 v1 h-1Z M10 38 h1 v1 h-1Z M10 40 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-3584 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M12 4 h1 v1 h-1Z M12 7 h1 v1 h-1Z M6 12 h1 v1 h-1Z M8 12 h2 v1 h-2Z M12 12 h1 v1 h-1Z M41 12 h1 v1 h-1Z M45 12 h1 v1 h-1Z M48 12 h1 v1 h-1Z M12 43 h1 v1 h-1Z M12 44 h1 v1 h-1Z M12 46 h1 v1 h-1Z \" /\u003e\u003cpath class=\"qr-4096 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M40 4 h1 v1 h-1Z M39 5 h1 v1 h-1Z M39 6 h1 v1 h-1Z M39 7 h2 v1 h-2Z M38 8 h3 v1 h-3Z M8 38 h1 v1 h-1Z M5 39 h4 v1 h-4Z M4 40 h1 v1 h-1Z M7 40 h2 v1 h-2Z \" /\u003e\u003cpath class=\"qr-5632 \" stroke=\"transparent\" fill=\"#000\" fill-opacity=\"1\" d=\"M6 6 h3 v1 h-3Z M44 6 h3 v1 h-3Z M6 7 h3 v1 h-3Z M44 7 h3 v1 h-3Z M6 8 h3 v1 h-3Z M44 8 h3 v1 h-3Z M6 44 h3 v1 h-3Z M6 45 h3 v1 h-3Z M6 46 h3 v1 h-3Z \" /\u003e\u003c/svg\u003e\n\n    \u003c/a\u003e\n    \u003cfigcaption aria-hidden=\"true\" class=\"hidden\" hidden\u003eReward Stéphane HUC\u003c/figcaption\u003e\n\u003c/figure\u003e\n\n\n\u003ch2 id=\"who\"\u003eWho\u003c/h2\u003e\n\u003ch3 id=\"2020\"\u003e2020\u003c/h3\u003e\n\u003cp\u003e⇒ In October:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e@scorpus\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"2022\"\u003e2022\u003c/h3\u003e\n\u003cp\u003e⇒ In November:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e@Cascador\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"what\"\u003eWhat\u003c/h2\u003e\n\u003ch3 id=\"2020-1\"\u003e2020\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eone \u003cstrong\u003etrappiste rochefort 10\u003c/strong\u003e beer: 5€\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"2022-1\"\u003e2022\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e5 dozens of €\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"About donations","tags":["Don"],"date_published":"2020-02-21T19:59:41+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2020-01-02:/en/web/hugo/hugo-openbsd","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-openbsd/","title":"Hugo: Use the tool build by the project on OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description It\u0026rsquo;s really easy to use, without troubles, Hugo on OpenBSD.\nTo install the package: :# pkg_add hugo\nHugo version: 0.53 : Hugo Static Site Generator v0.53 openbsd/amd64 BuildDate: unknown OpenBSD: 6.6 Architecture: amd64 But, this version is more year old, and has a lot of bugs.\nUtilisation The Hugo project build releases to download and uncompress; there are 3 files, the binary hugo, and files LICENSE, README.md.\nThe archives are intended for 32-bits (i386), 64-bits (amd64), and ARM architectures.\nTipAdd your personal folder bin/ at the environment variable PATH, and put hugo binary in this folder, or symlink-it! The purpose of this article is to \u0026ldquo;show up\u0026rdquo; the various pitfalls related to t hese official binaries, which sometimes generate changes in Hugo\u0026rsquo;s configuration, or even malfunctions.\nThe ultimage version really functionnal is: 0.59.1.\nImportants Changes v0.54.0 version: Hugo Static Site Generator v0.54.0-B1A82C61 openbsd/amd64 BuildDate: 2019-02-01T09:41:10Z In fact, hugo server not run, and exit with error: Error: Error building site: EOF\nBye-bye!\nv0.55.0 version: Hugo Static Site Generator v0.55.0-4333CC77 openbsd/amd64 BuildDate: 2019-04-08T16:41:18Z WarningThis version brings changes in the execution of shortcodes, taxonomy, … v0.6x versions 0.60.(x), 0.61.0, 0.62.(x) Since version 0.60.0, there is a new engine: the goldmark.\nIt\u0026rsquo;s necessary to change your file configuration, as (for the toml format):\n[markup.goldmark.renderer] unsafe = true But, it exists this bug, in the rendering of HTML code within the shortcodes.\nFor the moment, prefer to use v0.59.1!\nDeprecated Page.Hugo is deprecated This message Page.Hugo is deprecated and will be removed in a future release. Use the global hugo function. says .Hugo variable is deprecated.\nYou need to replace by the global hugo function.\nSee: Hugo Documentation: Variables \u0026gt; Hugo Page\u0026rsquo;s .RSSLink is deprecated This message Page's .RSSLink is deprecated and will be removed in a future release. Use the Output Format's link informs .RSSLink variable is deprecated.\nPrefer to use: {{`` with .OutputFormats.Get \u0026quot;RSS\u0026quot; }}{{ .RelPermalink }}{{ end }}\nSee: Hugo Documentation: Templates \u0026gt; Output formats Page\u0026rsquo;s .URL is deprecated The message Page's .URL is deprecated and will be removed in a future release. Use .Permalink or .RelPermalink. notifies to stop using the .URL variable.\nYou need to replace by .Permalink.\nInfoNot confuse with the .URL variable into menu or pagination contexts!\n(cf: Hugo Documentation: Variables \u0026gt; Menus )\nRecommandations Shortcodes It is therefore recommended that you no longer use the {{``% shortcode %}} syntax, but prefer {{``\u0026lt; shortcode \u0026gt;}} syntax and use the markdownify function.\nSee: Hugo Documentation: Functions \u0026gt; Markdownify .\nTaxonomy Taxonomy nodes have a new accessor named .Page. It simplifies the use of differents variables, as .Titre.\nInstead of using {{ range .Data.Terms.Alphabetical }}, use {{ range .Site.Taxonomies.tags }}.\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eIt\u0026rsquo;s really easy to use, without troubles, Hugo on OpenBSD.\u003c/p\u003e\n\u003cp\u003eTo install the package: \u003cbr\u003e\n\u003ccode\u003e:# pkg_add hugo\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eHugo version: \u003cstrong\u003e0.53\u003c/strong\u003e : \u003ccode\u003eHugo Static Site Generator v0.53 openbsd/amd64 BuildDate: unknown\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eOpenBSD: \u003cstrong\u003e6.6\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eArchitecture: \u003cstrong\u003eamd64\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBut, this version is more year old, and has a lot of bugs.\u003c/p\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\u003cp\u003eThe Hugo project build releases to download and uncompress; there are 3 files,\nthe binary \u003ccode\u003ehugo\u003c/code\u003e, and files \u003ccode\u003eLICENSE\u003c/code\u003e, \u003ccode\u003eREADME.md\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eThe archives are intended for 32-bits \u003cem\u003e(i386)\u003c/em\u003e, 64-bits \u003cem\u003e(amd64)\u003c/em\u003e, and ARM\narchitectures.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eAdd your personal folder \u003ccode\u003ebin/\u003c/code\u003e at the environment variable \u003ccode\u003ePATH\u003c/code\u003e, and put\nhugo binary in this folder, or symlink-it!\u003c/div\u003e\n\n\u003cp\u003eThe purpose of this article is to \u0026ldquo;show up\u0026rdquo; the various pitfalls related to t\nhese official binaries, which sometimes generate changes in Hugo\u0026rsquo;s configuration,\nor even malfunctions.\u003c/p\u003e\n\u003cp\u003eThe ultimage version really functionnal is: \u003cstrong\u003e0.59.1\u003c/strong\u003e.\u003c/p\u003e\n\u003ch2 id=\"importants-changes\"\u003eImportants Changes\u003c/h2\u003e\n\u003ch3 id=\"v0540\"\u003ev0.54.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eversion: \u003ccode\u003eHugo Static Site Generator v0.54.0-B1A82C61 openbsd/amd64 BuildDate: 2019-02-01T09:41:10Z\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIn fact, \u003ccode\u003ehugo server\u003c/code\u003e not run, and exit with error: \u003ccode\u003eError: Error building site: EOF\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eBye-bye!\u003c/p\u003e\n\u003ch3 id=\"v0550\"\u003ev0.55.0\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eversion: \u003ccode\u003eHugo Static Site Generator v0.55.0-4333CC77 openbsd/amd64 BuildDate: 2019-04-08T16:41:18Z\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eThis version brings changes in the execution of \u003ca href=\"/en/web/hugo/hugo-openbsd/#shortcodes\"\u003eshortcodes\u003c/a\u003e,\n\u003ca href=\"/en/web/hugo/hugo-openbsd/#taxonomy\"\u003etaxonomy\u003c/a\u003e, …\u003c/div\u003e\n\n\u003ch3 id=\"v06x\"\u003ev0.6x\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eversions 0.60.(x), 0.61.0, 0.62.(x)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSince version 0.60.0, there is a new engine: the \u003cstrong\u003egoldmark\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s necessary to change your file configuration, as (for the toml format):\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode\u003e[markup.goldmark.renderer]\n    unsafe = true\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eBut, it exists this \u003ca href=\"https://github.com/gohugoio/hugo/issues/6553\" rel=\"external\"\u003ebug\u003c/a\u003e, in the\nrendering of HTML code within the shortcodes.\u003c/p\u003e\n\u003cp\u003eFor the moment, prefer to use v0.59.1!\u003c/p\u003e\n\u003ch2 id=\"deprecated\"\u003eDeprecated\u003c/h2\u003e\n\u003ch3 id=\"pagehugo-is-deprecated\"\u003ePage.Hugo is deprecated\u003c/h3\u003e\n\u003cp\u003eThis message \u003ccode\u003ePage.Hugo is deprecated and will be removed in a future release. Use the global hugo function.\u003c/code\u003e says \u003ccode\u003e.Hugo\u003c/code\u003e variable is deprecated.\u003c/p\u003e\n\u003cp\u003eYou need to replace by the global \u003ccode\u003ehugo\u003c/code\u003e function.\u003c/p\u003e\n\u003cp\u003eSee: \u003ca href=\"https://gohugo.io/variables/hugo/\" title=\"Link to the official site Hugo: Variables \u0026gt; Hugo\"\u003eHugo Documentation: Variables \u0026gt; Hugo\u003c/a\u003e\n\u003c/p\u003e\n\u003ch3 id=\"pages-rsslink-is-deprecated\"\u003ePage\u0026rsquo;s .RSSLink is deprecated\u003c/h3\u003e\n\u003cp\u003eThis message \u003ccode\u003ePage's .RSSLink is deprecated and will be removed in a future release. Use the Output Format's link\u003c/code\u003e informs \u003ccode\u003e.RSSLink\u003c/code\u003e variable is deprecated.\u003c/p\u003e\n\u003cp\u003ePrefer to use: \u003ccode\u003e{{`` with .OutputFormats.Get \u0026quot;RSS\u0026quot; }}{{ .RelPermalink }}{{ end }}\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eSee: \u003ca href=\"https://gohugo.io/templates/output-formats/\" title=\"Link to the official site Hugo: Templates \u0026gt; Output formats\"\u003eHugo Documentation: Templates \u0026gt; Output formats\u003c/a\u003e\n\u003c/p\u003e\n\u003ch3 id=\"pages-url-is-deprecated\"\u003ePage\u0026rsquo;s .URL is deprecated\u003c/h3\u003e\n\u003cp\u003eThe message \u003ccode\u003ePage's .URL is deprecated and will be removed in a future release. Use .Permalink or .RelPermalink.\u003c/code\u003e notifies to stop using the \u003ccode\u003e.URL\u003c/code\u003e variable.\u003c/p\u003e\n\u003cp\u003eYou need to replace by \u003ccode\u003e.Permalink\u003c/code\u003e.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eNot confuse with the \u003ccode\u003e.URL\u003c/code\u003e variable into menu or pagination contexts!\u003c/p\u003e\n\u003cp\u003e(cf: \u003ca href=\"https://gohugo.io/variables/menus/#menu-entry-variables\" title=\"Link to the official site Hugo: Variables \u0026gt; Menus\"\u003eHugo Documentation: Variables \u0026gt; Menus\u003c/a\u003e\n)\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"recommandations\"\u003eRecommandations\u003c/h2\u003e\n\u003ch3 id=\"shortcodes\"\u003eShortcodes\u003c/h3\u003e\n\u003cp\u003eIt is therefore recommended that you no longer use the \u003ccode\u003e{{``% shortcode %}}\u003c/code\u003e\nsyntax, but prefer \u003ccode\u003e{{``\u0026lt; shortcode \u0026gt;}}\u003c/code\u003e syntax and use the \u003ccode\u003emarkdownify\u003c/code\u003e\nfunction.\u003c/p\u003e\n\u003cp\u003eSee: \u003ca href=\"https://gohugo.io/functions/markdownify/\" title=\"Link to the official site Hugo: Functions \u0026gt; Markdownify\"\u003eHugo Documentation: Functions \u0026gt; Markdownify\u003c/a\u003e\n.\u003c/p\u003e\n\u003ch3 id=\"taxonomy\"\u003eTaxonomy\u003c/h3\u003e\n\u003cp\u003eTaxonomy nodes have a new accessor named \u003ccode\u003e.Page\u003c/code\u003e. It simplifies the use of\ndifferents variables, as \u003ccode\u003e.Titre\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eInstead of using \u003ccode\u003e{{ range .Data.Terms.Alphabetical }}\u003c/code\u003e, use\n\u003ccode\u003e{{ range .Site.Taxonomies.tags }}\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n","summary":"Review about differents versions of Hugo build by the project on OpenBSD stable","tags":["Hugo","OpenBSD"],"date_published":"2020-01-02T16:02:59+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-12-23:/en/web/nextcloud/nextcloud-loop-login","url":"https://it-log.fr.eu.org/en/web/nextcloud/nextcloud-loop-login/","title":"(tip) Nextcloud : loop login","author":{"name":"Stéphane HUC"},"content_text":"Description \u0026ldquo;Once upon a time…\u0026rdquo;, you need to connect at your WebUI Nextcloud, with your ids. Normal!\nBut, this day, you cant: impossible to connect. You\u0026rsquo;re redirected on login?redirect_url=/apps/files/ and your ids are asked again! Booo.\n\u0026ldquo;You\u0026rsquo;re under a loop login!\u0026rdquo;\nResolution Check :\nread an write permissions on thoses folders: netcloud : 0750 cache : 0755 and, for the sessions PHP: 0750 seems to be functional, else 0755. user rights on same folders: those of your web user and group; default, on OpenBSD www, but this depends on your web architecture (i.e, Apache, Nginx, etc) and your OS . OpenBSD On OpenBSD, I noticied this little problem: after a PHP upgrade, user rights on folders cache, tmp in the chroot are reset for root:daemon and 0700 with sticky bit.\nIt seems necessary to set at the web user, web group and change again read and write permissions to 0755.\nAcknowledgement source ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u0026ldquo;Once upon a time…\u0026rdquo;, you need to connect at your WebUI Nextcloud, with your ids.\nNormal!\u003c/p\u003e\n\u003cp\u003eBut, this day, you cant: impossible to connect. You\u0026rsquo;re redirected on\n\u003ccode\u003elogin?redirect_url=/apps/files/\u003c/code\u003e and your ids are asked again! Booo.\u003c/p\u003e\n\u003cp\u003e\u0026ldquo;You\u0026rsquo;re under a loop login!\u0026rdquo;\u003c/p\u003e\n\u003ch2 id=\"resolution\"\u003eResolution\u003c/h2\u003e\n\u003cp\u003e\u003cspan class=\"red\"\u003eCheck\u003c/span\u003e\n :\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eread an write permissions\u003c/strong\u003e on thoses folders:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003enetcloud\u003c/code\u003e : \u003ccode\u003e0750\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ecache\u003c/code\u003e : \u003ccode\u003e0755\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eand, for the sessions PHP: \u003ccode\u003e0750\u003c/code\u003e seems to be functional, else \u003ccode\u003e0755\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003euser rights\u003c/strong\u003e on same folders: those of your web user and group; default,\non OpenBSD \u003ccode\u003ewww\u003c/code\u003e, but this depends on your web architecture \u003cem\u003e(i.e, Apache, Nginx, etc)\u003c/em\u003e\nand your \u003cabbr title=\"Operating System\"\u003eOS\u003c/abbr\u003e\n.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"openbsd\"\u003eOpenBSD\u003c/h3\u003e\n\u003cp\u003eOn OpenBSD, I noticied this little problem: after a PHP upgrade, user rights on\nfolders \u003ccode\u003ecache\u003c/code\u003e, \u003ccode\u003etmp\u003c/code\u003e in the chroot are reset for \u003ccode\u003eroot:daemon\u003c/code\u003e and \u003ccode\u003e0700\u003c/code\u003e\nwith \u003ccode\u003esticky bit\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIt seems necessary to set at the web user, web group and change again read and\nwrite permissions to \u003ccode\u003e0755\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"acknowledgement\"\u003eAcknowledgement\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e\u003ca href=\"https://www.ryadel.com/en/nextcloud-13-login-page-redirect-loop-how-to-fix-it/\" rel=\"external\"\u003esource\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Nextcloud : How to resolve the loop login problem…","tags":["Nextcloud","login","tip"],"date_published":"2019-12-23T18:27:34+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-12-06:/en/web/hugo/hugo-search-jqueryui-autocomplete","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-search-jqueryui-autocomplete/","title":"Hugo Search: an internal search engine (JQueryUI autocomplete)","author":{"name":"Stéphane HUC"},"content_text":"Description Adding a function search into static website made with Hugo can be done in differents ways.\nWe will code this simply with JQuery+UI, in few minutes.\nWe will use the Hugo site.Pages variable, and the JQueryUI autocomplete() method.\nI assume you known how to add correctly the both JQuery and JQueryUI librairies on your site.\nCodes JQueryUI As explain into the description section, we use the events of the method autocomplete(). We build the $projects variable to iterate over the Hugo $pages variable with the Hugo range function.\nThe JQuery code:\n\u0026lt;script\u0026gt; $(function() { var projects = [ {{- range site.Pages -}} {{- $url := .RelPermalink -}} {{- $title := .LinkTitle -}} { value: \u0026#34;{{ $title }}\u0026#34;, label: \u0026#34;{{- if eq $url $baseURL }}{{ site.Params.description }}{{ else if in $url \u0026#34;tags\u0026#34; }}{{- T \u0026#34;pageListTitle\u0026#34; }}{{ $title }}{{ else }}{{- safeHTML .Params.description -}}{{ end -}}\u0026#34;, url:\u0026#34;{{ $url }}\u0026#34; }, {{- end -}} ]; $(\u0026#34;#search\u0026#34;).autocomplete({ minLength: 0, source: projects, focus: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); return false; }, select: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); $(\u0026#34;#replyer\u0026#34;).val( ui.item.value ); return false; } }) .data(\u0026#39;ui-autocomplete\u0026#39;)._renderItem = function(ul, item) { return $(\u0026#39;\u0026lt;li\u0026gt;\u0026#39;) .append(\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39; + item.url + \u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;+ item.label + \u0026#39;\u0026#34;\u0026gt;\u0026#39; + item.value + \u0026#39;\u0026lt;/a\u0026gt;\u0026#39; ) .appendTo(ul); }; }); \u0026lt;/script\u0026gt; HTML And for the simplest code HTML, we use two elements input as:\n\u0026lt;input class=\u0026#34;form-control\u0026#34; id=\u0026#34;search\u0026#34; placeholder=\u0026#34;{{ T \u0026#34;searchHolderTitle\u0026#34; }}\u0026#34;\u0026gt; \u0026lt;input aria-hidden=\u0026#34;true\u0026#34; id=\u0026#34;replyer\u0026#34; class=\u0026#34;hidden\u0026#34;\u0026gt; the first catch the searched text the second return all found titles, and in the background the equivalent URL. the syntax {{ i18n \u0026quot;searchHolderTitle\u0026quot; }} exists for the multilanguage context on this website; You can replace with your personal text. TL;DR The fully code:\n\u0026lt;div id=\u0026#34;search\u0026#34;\u0026gt; \u0026lt;input class=\u0026#34;form-control\u0026#34; id=\u0026#34;search\u0026#34; placeholder=\u0026#34;{{ T \u0026#34;searchHolderTitle\u0026#34; }}\u0026#34;\u0026gt; \u0026lt;input aria-hidden=\u0026#34;true\u0026#34; id=\u0026#34;replyer\u0026#34; class=\u0026#34;hidden\u0026#34;\u0026gt; {{- $baseURL := site.BaseURL | absLangURL -}} \u0026lt;!-- Javascript --\u0026gt; \u0026lt;script\u0026gt; $(function() { var projects = [ {{- range site.Pages -}} {{- $url := .RelPermalink -}} {{- $title := .LinkTitle -}} { value: \u0026#34;{{ $title }}\u0026#34;, label: \u0026#34;{{- if eq $url $baseURL }}{{ site.Params.description }}{{ else if in $url \u0026#34;tags\u0026#34; }}{{- T \u0026#34;pageListTitle\u0026#34; }}{{ $title }}{{ else }}{{- safeHTML .Params.description -}}{{ end -}}\u0026#34;, url:\u0026#34;{{ $url }}\u0026#34; }, {{- end -}} ]; $(\u0026#34;#search\u0026#34;).autocomplete({ minLength: 0, source: projects, focus: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); return false; }, select: function( event, ui ) { $(\u0026#34;#search\u0026#34;).val( ui.item.label ); $(\u0026#34;#replyer\u0026#34;).val( ui.item.value ); return false; } }) .data(\u0026#39;ui-autocomplete\u0026#39;)._renderItem = function(ul, item) { return $(\u0026#39;\u0026lt;li\u0026gt;\u0026#39;) .append(\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39; + item.url + \u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;+ item.label + \u0026#39;\u0026#34;\u0026gt;\u0026#39; + item.value + \u0026#39;\u0026lt;/a\u0026gt;\u0026#39; ) .appendTo(ul); }; }); \u0026lt;/script\u0026gt; \u0026lt;/div\u0026gt; Demo Voilà ! In few minutes, an \u0026ldquo;internal search engine\u0026rdquo; is born on your static website Hugo.\nSee, the search holder on the menu navigation, at top right side ;)\nDocumentation Hugo Documentation: Tools \u0026gt; Search Hugo Documentation: Functions \u0026gt; Range Hugo Documentation: Functions \u0026gt; I18n Others Documentations Inspired by Dot theme - (cf : banner.html) JQuery UI autocomplete() method: https://jqueryui.com/autocomplete More explains about JQueryUI Autocomplete() method: See the documentation Another method to build internal search engine, with VueJS + Axios librairies ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eAdding a function \u003ccode\u003esearch\u003c/code\u003e into static website made with Hugo can be done in differents ways.\u003c/p\u003e\n\u003cp\u003eWe will code this simply with JQuery+UI, in few minutes.\u003c/p\u003e\n\u003cp\u003eWe will use the Hugo \u003ccode\u003esite.Pages\u003c/code\u003e variable, and the JQueryUI \u003ccode\u003eautocomplete()\u003c/code\u003e method.\u003c/p\u003e\n\u003cp\u003eI assume you known how to add correctly the both JQuery and JQueryUI librairies on your site.\u003c/p\u003e\n\u003ch2 id=\"codes\"\u003eCodes\u003c/h2\u003e\n\u003ch3 id=\"jqueryui\"\u003eJQueryUI\u003c/h3\u003e\n\u003cp\u003eAs explain into the description section, we use the events of the method \u003ccode\u003eautocomplete()\u003c/code\u003e.\nWe build the \u003ccode\u003e$projects\u003c/code\u003e variable to iterate over the Hugo \u003ccode\u003e$pages\u003c/code\u003e variable\nwith the Hugo \u003ccode\u003erange\u003c/code\u003e function.\u003c/p\u003e\n\u003cp\u003eThe JQuery code:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-js\" data-lang=\"js\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003escript\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e() {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003evar\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erange\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esite\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003ePages\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$url\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e:=\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eRelPermalink\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$title\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e:=\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eLinkTitle\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $title }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{- if eq $url $baseURL }}{{ site.Params.description }}{{ else if in $url \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etags\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; }}{{- T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003epageListTitle\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; }}{{ $title }}{{ else }}{{- safeHTML .Params.description -}}{{ end -}}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    ];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eautocomplete\u003c/span\u003e({\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#06b6ef\"\u003eminLength\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003esource\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003efocus\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eselect\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#replyer\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    })\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    .\u003cspan style=\"color:#06b6ef\"\u003edata\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;ui-autocomplete\u0026#39;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003e_renderItem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;li\u0026gt;\u0026#39;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappend\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34;\u0026gt;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;/a\u0026gt;\u0026#39;\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappendTo\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    };\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e});\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e/script\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"html\"\u003eHTML\u003c/h3\u003e\n\u003cp\u003eAnd for the simplest code HTML, we use two elements \u003ccode\u003einput\u003c/code\u003e as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;form-control\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eplaceholder\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003esearchHolderTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003earia-hidden\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;true\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;replyer\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;hidden\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003ethe first catch the searched text\u003c/li\u003e\n\u003cli\u003ethe second return all found titles, and in the background the equivalent URL.\u003c/li\u003e\n\u003cli\u003ethe syntax \u003ccode\u003e{{ i18n \u0026quot;searchHolderTitle\u0026quot; }}\u003c/code\u003e exists for the multilanguage\ncontext on this website; You can replace with your personal text.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"tldr\"\u003eTL;DR\u003c/h3\u003e\n\u003cp\u003eThe fully code:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;form-control\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;search\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eplaceholder\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003esearchHolderTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003einput\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003earia-hidden\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;true\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;replyer\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;hidden\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    {{- $baseURL := site.BaseURL | absLangURL -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e\u0026lt;!-- Javascript --\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003escript\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e() {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003evar\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e [\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erange\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esite\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003ePages\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$url\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e:=\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eRelPermalink\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$title\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e:=\u003c/span\u003e .\u003cspan style=\"color:#06b6ef\"\u003eLinkTitle\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $title }}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{- if eq $url $baseURL }}{{ site.Params.description }}{{ else if in $url \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etags\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; }}{{- T \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003epageListTitle\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; }}{{ $title }}{{ else }}{{- safeHTML .Params.description -}}{{ end -}}\u0026#34;\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e            \u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        {{\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003e}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    ];\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eautocomplete\u003c/span\u003e({\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\u003cspan style=\"color:#06b6ef\"\u003eminLength\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003esource\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprojects\u003c/span\u003e,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003efocus\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        },\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#06b6ef\"\u003eselect\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e:\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eevent\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e ) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#search\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;#replyer\u0026#34;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003eval\u003c/span\u003e( \u003cspan style=\"color:#06b6ef\"\u003eui\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e );\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\t\t\t\u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efalse\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        }\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    })\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    .\u003cspan style=\"color:#06b6ef\"\u003edata\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;ui-autocomplete\u0026#39;\u003c/span\u003e).\u003cspan style=\"color:#06b6ef\"\u003e_renderItem\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e, \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e) {\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e$\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;li\u0026gt;\u0026#39;\u003c/span\u003e)\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappend\u003c/span\u003e(\u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;a href=\u0026#34;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003eurl\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34; alt=\u0026#34;\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003elabel\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026#34;\u0026gt;\u0026#39;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eitem\u003c/span\u003e.\u003cspan style=\"color:#06b6ef\"\u003evalue\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e+\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;\u0026lt;/a\u0026gt;\u0026#39;\u003c/span\u003e )\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        .\u003cspan style=\"color:#06b6ef\"\u003eappendTo\u003c/span\u003e(\u003cspan style=\"color:#06b6ef\"\u003eul\u003c/span\u003e);\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    };\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e});\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003escript\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003ch2 id=\"demo\"\u003eDemo\u003c/h2\u003e\n\u003cp\u003eVoilà ! \u003cbr\u003e\nIn few minutes, an \u0026ldquo;internal search engine\u0026rdquo; is born on your static website Hugo.\u003c/p\u003e\n\u003cp\u003eSee, the search holder on the menu navigation, at top right side ;)\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/tools/search/\" title=\"Link to the official site Hugo: Tools \u0026gt; Search\"\u003eHugo Documentation: Tools \u0026gt; Search\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/functions/range/\" title=\"Link to the official site Hugo: Functions \u0026gt; Range\"\u003eHugo Documentation: Functions \u0026gt; Range\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/functions/i18n/\" title=\"Link to the official site Hugo: Functions \u0026gt; I18n\"\u003eHugo Documentation: Functions \u0026gt; I18n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"others-documentations\"\u003eOthers Documentations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eInspired by \u003ca href=\"https://themes.gohugo.io/theme/dot-hugo-documentation-theme/\" rel=\"external\"\u003eDot theme\u003c/a\u003e - \u003cem\u003e(cf : \u003ca href=\"https://github.com/themefisher/dot/blob/master/layouts/partials/banner.html\" rel=\"external\"\u003ebanner.html\u003c/a\u003e)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eJQuery UI \u003ccode\u003eautocomplete()\u003c/code\u003e method: \u003ca href=\"https://jqueryui.com/autocomplete\" rel=\"external\"\u003ehttps://jqueryui.com/autocomplete\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMore explains about JQueryUI \u003ccode\u003eAutocomplete()\u003c/code\u003e method: See the \u003ca href=\"https://www.tutorialspoint.com/jqueryui/jqueryui_autocomplete.htm\" rel=\"external\"\u003edocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAnother method to \u003ca href=\"https://en.jeffprod.com/blog/2018/build-your-own-hugo-website-search-engine/\" rel=\"external\"\u003ebuild internal search engine\u003c/a\u003e, with VueJS + Axios librairies\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Howto add an 'internal search engine' into the static website, made with Hugo, and JQueryUI","tags":["Hugo","search","JQuery"],"date_published":"2019-12-06T01:21:00+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-11-29:/en/web/hugo/hugo-shortcodes","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-shortcodes/","title":"Hugo: Shortcodes","author":{"name":"Stéphane HUC"},"content_text":"Description As you see on Hugo\u0026rsquo;s page shortcodes, a shortcode is a simple snippet inside a content file that Hugo will render using a predefined template.\nSome times, you need to include/add raw HTML into the MD content. The shortcode add correctly this. By this way, you can include too MD syntax.\nPut your shortcodes into layout/shortcodes/.\nActually, I use the official third package providen by the team OpenBSD:\nOpenBSD : 6.6 Version d\u0026rsquo;Hugo : 0.53 : Hugo Static Site Generator v0.53 openbsd/amd64 BuildDate: unknown Documentation official : Hugo Documentation: Content management \u0026gt; Shortcodes My shortcodes abbr To manage element HTML abbr RAW source of the shortcode: abbr\nThe shortcode:\n\u0026lt;abbr {{ .Get 1 | printf `title=%q` | safeHTMLAttr }}\u0026gt;{{ .Get 0 | safeHTML }}\u0026lt;/abbr\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; abbr accronym \u0026#34;Meaning of Acronym\u0026#34; \u0026gt;}} Example: HTML is written as: Code:\u0026nbsp;shortcode\n{{\u0026lt; abbr HTML \u0026#34;HyperText Markup Language\u0026#34; \u0026gt;}} anchor To manage the anchor into one page is a little complex:\nRAW source of the shortcode: anchor\n{{ $txt := .Get 0 | safeHTML }}{{ $name := .Get 1 | lower | safeHTML }}{{ $anchor := anchorize $name }} \u0026lt;a href=\u0026#34;{{ printf \u0026#34;%s\u0026#34; .Page.RelPermalink }}#{{ $anchor }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;shortcodeAnchorTitle\u0026#34; }}{{ $name }}\u0026#34;\u0026gt;{{ $txt }}\u0026lt;/a\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; anchor \u0026#34;Texte\u0026#34; \u0026#34;Cible\u0026#34; \u0026gt;}} Example: this link refers to the section Description; his writing is: Code:\u0026nbsp;shortcode\n{{\u0026lt; anchor \u0026#34;link\u0026#34; \u0026#34;description\u0026#34; \u0026gt;}} blockquote Writing a basic element HTML blockquote, you need only:\n\u0026lt;blockquote\u0026gt;{{ $file := .Get 0 | readFile | htmlUnescape | safeHTML }}{{ $file }}\u0026lt;/blockquote\u0026gt; But, my shorcode is more evolved, because as you see, this site is multilanguage. Also:\nRAW source of the shortcode: blockquote\n\u0026lt;div class=\u0026#34;info-quote\u0026#34;\u0026gt;\u0026lt;p class=\u0026#34;text-white-50\u0026#34;\u0026gt;{{ T \u0026#34;quoteTitle\u0026#34; }}{{ if .Get 1 }} \u0026lt;em\u0026gt;{{ .Get 1 | safeHTML }}\u0026lt;/em\u0026gt;{{ end }}\u0026lt;/p\u0026gt;\u0026lt;/div\u0026gt;\u0026lt;div class=\u0026#34;quote\u0026#34;\u0026gt;\u0026lt;blockquote\u0026gt;{{ $name := .Get 0 }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile | htmlUnescape | safeHTML }}{{ $file }}\u0026lt;/blockquote\u0026gt;\u0026lt;/div\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; blockquote \u0026#34;blockquote-filename\u0026#34; lang \u0026gt;}} blockquote-filename: the file to call where the blockquote is written lang: the lang, i.e en, fr, etc. - To avoid specifying an code, use \u0026quot;\u0026quot;. Example: Quotes: fr\nCode To include some example code, I created into content/ folder a directory named inc. You can named as you want; it\u0026rsquo;s up to you!\nAnd after, create needed files, and call them as /content/folder_name/file_name.\nBy default: Code:\u0026nbsp;html\n{{ $file := .Get 0 | readFile }}{{ $lang := .Get 1 }}{{ $opt := \u0026#34;\u0026#34; }}\u0026lt;div class=\u0026#34;code\u0026#34;\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/div\u0026gt; For my needs, my shortcode is \u0026ldquo;a little more\u0026rdquo; advanced:\nRAW source of the shortcode: code\n{{ $name := .Get 0 }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile }}{{ $lang := .Get 1 }}{{ $opt := \u0026#34;\u0026#34; }} \u0026lt;div class=\u0026#34;info-code\u0026#34;\u0026gt;\u0026lt;p class=\u0026#34;text-white-50\u0026#34;\u0026gt;{{ i18n \u0026#34;codeTitle\u0026#34; }}\u0026amp;nbsp;\u0026lt;em\u0026gt;{{ $lang }}\u0026lt;/em\u0026gt;\u0026lt;/p\u0026gt;\u0026lt;/div\u0026gt;\u0026lt;div class=\u0026#34;code\u0026#34;\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/div\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; code \u0026#34;code-filename\u0026#34; language \u0026gt;}} code-filename: the file to call language: the language, i.e sh, PHP, python, etc. To avoid specifying an code, use \u0026quot;\u0026quot;. Example: Look, you have one just above it!\nColor A very small shortcode to add color on text.\nInto my CSS , I had some definitions with named colors.\nRAW source of the shortcode: color\nThe shortcode:\n\u0026lt;span {{ .Get 0 | printf `class=%q` | safeHTMLAttr }}\u0026gt;{{ .Inner }}\u0026lt;/span\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; color \u0026#34;css-name\u0026#34; \u0026gt;}}text{{\u0026lt; /color \u0026gt;}} css-name: the CSS name text: the text Example: This is green text , or orange , and this other is red , etc…\nFile To include a file content example, I fork the shortcode code . It\u0026rsquo;s quasy-same code.\nBut, for my need, I wrote an advanced as: RAW source of the shortcode: file\n{{ $name := .Get 0 | safeHTML }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile }}{{ $lang := .Get 1}}{{ $filename := .Get 2 }}{{ $opt := \u0026#34;linenos=table\u0026#34; }} \u0026lt;div class=\u0026#34;info-file\u0026#34;\u0026gt;\u0026lt;p class=\u0026#34;text-white-50\u0026#34;\u0026gt;{{ i18n \u0026#34;fileTitle\u0026#34; }}\u0026lt;em\u0026gt;{{ $filename }}\u0026lt;/em\u0026gt;\u0026lt;/p\u0026gt;\u0026lt;/div\u0026gt;\u0026lt;div class=\u0026#34;code\u0026#34;\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/div\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; file \u0026#34;example-file\u0026#34; language \u0026#34;filename\u0026#34; \u0026gt;}} /example-file: file to call language: language, i.e. sh, PHP, python, etc… To avoid specifying an code, use \u0026quot;\u0026quot;. filename: filename to display ;) Example: Look above to see!\nImage Yes, I known Markdown had his code to include basically image.\nPNG/JPG/Tiff This shortcode exists to specify width of image, and link to the raw image.\nRAW source of the shortcode: img\n1{{/* runner for assets/image */}} 2{{- $src := resources.Get (printf \u0026#34;%s%s\u0026#34; \u0026#34;/images/\u0026#34; (.Get \u0026#34;s\u0026#34;)) -}}{{- $alt := .Get \u0026#34;a\u0026#34; | safeHTML -}}{{- $width := printf \u0026#34;%s\u0026#34; (.Get \u0026#34;w\u0026#34;) -}} 3{{- $img := $src -}} 4{{- with $width -}}{{- $img = $src.Resize (printf \u0026#34;%sx\u0026#34; $width) -}}{{- end -}} 5{{- with $img -}} 6\u0026lt;figure\u0026gt; 7 \u0026lt;a href=\u0026#34;{{ $src.RelPermalink }}\u0026#34; title=\u0026#34;{{ $alt }}\u0026#34;\u0026gt; 8 \u0026lt;picture\u0026gt; 9 \u0026lt;!-- \u0026lt;source srcset=\u0026#34;/img/.avif\u0026#34; type=\u0026#34;image/avif\u0026#34;\u0026gt; --\u0026gt; 10 {{- with .Resize (printf \u0026#34;%dx%d webp\u0026#34; .Width .Height) }} 11 \u0026lt;source srcset=\u0026#34;{{ .RelPermalink }}\u0026#34; type=\u0026#34;image/webp\u0026#34;\u0026gt; 12 {{ end }} 13 \u0026lt;img alt=\u0026#34;{{ $alt }}\u0026#34; loading=\u0026#34;lazy\u0026#34; src=\u0026#34;{{ .RelPermalink }}\u0026#34; type=\u0026#34;{{ .MediaType }}\u0026#34; height=\u0026#34;{{ .Height }}\u0026#34; width=\u0026#34;{{ .Width }}\u0026#34;\u0026gt; 14 \u0026lt;/picture\u0026gt; 15 \u0026lt;/a\u0026gt; 16 \u0026lt;figcaption\u0026gt;{{ $alt }}\u0026lt;/figcaption\u0026gt; 17\u0026lt;/figure\u0026gt; 18{{- end -}} Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; img a=\u0026#34;alt\u0026#34; s=\u0026#34;src\u0026#34; w=\u0026#34;width\u0026#34; \u0026gt;}} The named parameters are:\na: equivalent for attribute alt s: equivalent for attribute src w: equivalent for attribute width Example:\nMy Logo This image is my logo, named \u0026ldquo;My Logo\u0026rdquo;, with an original width at 192 px , resized at 124 px, into PNG format.\nSVG About the SVG picture, I manage them like as:\nRAW source of the shortcode: figure-svg\n1{{/* runner for assets/svg */}} 2{{- $class := .Get \u0026#34;class\u0026#34; -}}{{- $src := resources.Get (printf \u0026#34;%s%s\u0026#34; \u0026#34;/svg/\u0026#34; (.Get \u0026#34;src\u0026#34;)) -}}{{ $title := .Get \u0026#34;title\u0026#34; }} 3{{ with $src }} 4\u0026lt;figure class=\u0026#34;{{ if $class }}{{ $class }}{{ end }}\u0026#34;\u0026gt; 5 \u0026lt;a href=\u0026#34;{{ .RelPermalink }}\u0026#34; title=\u0026#34;{{ $title }}\u0026#34;\u0026gt; 6 {{ .Content | safeHTML }} 7 \u0026lt;/a\u0026gt; 8 {{ if $title }}\u0026lt;figcaption aria-hidden=\u0026#34;true\u0026#34; class=\u0026#34;hidden\u0026#34; hidden\u0026gt;{{ $title }}\u0026lt;/figcaption\u0026gt;{{ end }} 9\u0026lt;/figure\u0026gt; 10{{ end }} Call the shortcode: Code:\u0026nbsp;shortcode\n{{\u0026lt; figure-svg class=\u0026#34;class-name\u0026#34; src=\u0026#34;image.svg\u0026#34; title=\u0026#34;the title\u0026#34; \u0026gt;}} Example : \u003c?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"no\"?\u003e Logo Emblème Stéphane HUC Logo Emblème Stéphane HUC My Logo kbd This shorcode manage HTML item kbd.\nRAW source of the shortcode: kbd\nThe shortcode is:\n{{ $k := .Get 0 | safeHTML }}\u0026lt;kbd\u0026gt;{{ $k }}\u0026lt;/kbd\u0026gt; Call shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; kbd key \u0026gt;}} key: the key name into the keyboard! Example : this is for the s key!\nInside link This shortcode, now, had two versions. I started with the first , and one day, I wonder how add anchor too; the v2 was born!\nInside v1 To manage inside link between pages of this site, I wrote this shortcode:\nRAW source of the shortcode: inside\n1{{ $link := .Get 0 }}{{ $link := replace $link \u0026#34;:\u0026#34; \u0026#34;/\u0026#34; }}{{ $url := (print ( relLangURL $link ) \u0026#34;/\u0026#34;) }} 2{{ if .Get 1 }}{{ $txt := .Get 1 }} 3\u0026lt;a class=\u0026#34;inside\u0026#34; href=\u0026#34;{{ $url }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;lnkInsideTitle\u0026#34; }}{{ with .Site.GetPage $link }}{{ .Title }}{{ end }}\u0026#34;\u0026gt;{{ $txt }}\u0026lt;/a\u0026gt; 4{{ else }} 5{{ with .Site.GetPage $link }}{{ $title := .Title }}\u0026lt;a class=\u0026#34;inside\u0026#34; href=\u0026#34;{{ $url }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;lnkInsideTitle\u0026#34; }}{{ $title }}\u0026#34;\u0026gt;{{ $title }}\u0026lt;/a\u0026gt;{{ end }} 6{{ end }} And, I created into my CSS, a named inside definition.\nCall the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; inside \u0026#34;section:subsection:pagename\u0026#34; \u0026#34;Title\u0026#34; \u0026gt;}} sections and pages names are separated by the symbol : the title can be avoid. In this case, it will display the title of called page. Examples:\nIn this exemple, I call the page Hugo: Deploy SFTP ; this is its title that is displayed. With this other example, I override the title when I call the same page Static deploy with Hugo Inside v2 This version is subtle different:\nRAW source of the shortcode: inside2\n1{{ $link := .Get \u0026#34;l\u0026#34; }}{{ $link := replace $link \u0026#34;:\u0026#34; \u0026#34;/\u0026#34; }}{{ $url := (print ( relLangURL $link ) \u0026#34;/\u0026#34;) }}{{ $anchor := .Get \u0026#34;a\u0026#34; }} 2{{ if .Get \u0026#34;t\u0026#34; }}{{ $txt := .Get \u0026#34;t\u0026#34; }}\u0026lt;a class=\u0026#34;inside\u0026#34; href=\u0026#34;{{ $url }}{{ if $anchor }}#{{ $anchor }}{{ end }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;lnkInsideTitle\u0026#34; }}\u0026#39;{{ with .Site.GetPage $link }}{{ .Title }}{{ end }}\u0026#39;\u0026#34;\u0026gt;{{ $txt }}\u0026lt;/a\u0026gt; 3{{ else }} 4{{ with .Site.GetPage $link }}{{ $title := .Title }}\u0026lt;a class=\u0026#34;inside\u0026#34; href=\u0026#34;{{ $url }}{{ if $anchor }}#{{ $anchor }}{{ end }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;lnkInsideTitle\u0026#34; }}\u0026#39;{{ $title }}\u0026#39;\u0026#34;\u0026gt;{{ $title }}\u0026lt;/a\u0026gt;{{ end }} 5{{ end }} Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; inside2 l=\u0026#34;section:subsection:pagename\u0026#34; t=\u0026#34;title\u0026#34; a=\u0026#34;anchor-name\u0026#34; \u0026gt;}} The named parameters are:\na: target an anchor into called page. this anchor need to exists into the page. May be omitted! l: name of internal link; sections and pages names are separated by the symbol :. t: the title. May be omitted. In this case, it will display tye title of the called page. Example:\nHere, I call the page Hugo: Deploy SFTP. Her title is displayed, but it links to the section named rsync, targeted anchor. And this example, I override the title as Static deploy with Hugo but I not wrote anchor param. Note The blocs of alert or note are HTML blocs to display a text, with an identifiant, translated segun the used lang.\nThe possible values of this identifiant may be:\ndanger: to display an alert \u0026lsquo;danger\u0026rsquo;, with a red background. info: to display an informational note, with a blue background. success: to display a success message, with a green background. tip: to display a tip note, with a yellow background. warning: to display a warning message/alert, with an amber background. And, all thoses background colors alert-$id are written on CSS file.\nThe shortcode:\nRAW source of the shortcode: note\n{{ $class := .Get 0 }}{{ $wrd := T (printf \u0026#34;alert-%s\u0026#34; $class) }} \u0026lt;div class=\u0026#34;info-tab {{ $class }}-icon\u0026#34;\u0026gt;{{ $wrd }}\u0026lt;/div\u0026gt;\u0026lt;div class=\u0026#34;alert alert-{{ $class }}\u0026#34; role=\u0026#34;alert\u0026#34;\u0026gt;{{ .Inner | .Page.RenderString }}\u0026lt;/div\u0026gt; The shortcode is: Code:\u0026nbsp;shortcode\n{{\u0026lt; note id \u0026gt;}} This is your message {{\u0026lt; /note \u0026gt;}} Examples:\nDangerATTENTION: this message display a risk or danger for you! This example includes MD code to strong the word \u0026lsquo;ATTENTION\u0026rsquo;.\nInfoA little information. Keep this in your mind! :D SuccessYou succeeded the test! Be happy. TipThis is a tip. Yeah, man, interesting! WarningPlease, be careful at the message: it seems a malfunction exists. See more attentive! Tag This shortcode not exists to manage Hugo tags, but to manage tag into MD file.\nInto CSS, I defined attribute .tag::after to display (tag).\nRAW source of the shortcode: tag\nThe shortcode:\n{{ $txt := .Get 0 }}{{ $href := \u0026#34;/\u0026#34; | relLangURL}}{{ $href := (printf \u0026#34;%s%s%s\u0026#34; $href \u0026#34;/tags/\u0026#34; $txt) | urlize }}\u0026lt;a class=\u0026#34;tag\u0026#34; href=\u0026#34;{{ $href }}\u0026#34;\u0026gt;{{ $txt }}\u0026lt;/a\u0026gt; Call the shortcode as: Code:\u0026nbsp;shortcode\n{{\u0026lt; tag tag-name \u0026gt;}} Example: This word Hugo is a link to the tag page with \u0026ldquo;Hugo\u0026rdquo; name.\nOthers shortcodes GoHugo Just to link to official documentation Hugo, I wrote this shortcode: Code:\u0026nbsp;shortcode\n{{\u0026lt; gohugo n=\u0026#34;pagename\u0026#34; s=\u0026#34;section\u0026#34; a=\u0026#34;anchor-name\u0026#34; \u0026gt;}} RAW source of the shortcode: gohugo\nThe shortcode:\n{{ $section := .Get \u0026#34;s\u0026#34; }}{{ $name := .Get \u0026#34;n\u0026#34; }}{{ $anchor := .Get \u0026#34;a\u0026#34; }}\u0026lt;a href=\u0026#34;https://gohugo.io/{{ $section }}/{{ $name }}/{{ if $anchor }}#{{ $anchor}}{{ end }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;shortcodeGoHugoTitle\u0026#34; }}{{ humanize $section }} \u0026amp;gt; {{ humanize $name }}\u0026#34;\u0026gt;{{ i18n \u0026#34;shortcodeGoHugoDocTitle\u0026#34; }}{{ humanize $section }} \u0026amp;gt; {{ humanize $name }}\u0026lt;/a\u0026gt; Example: Link to Hugo Documentation: Content management \u0026gt; Shortcodes Hugo page with: Code:\u0026nbsp;shortcode\n{{\u0026lt; gohugo n=\u0026#34;shortcodes\u0026#34; s=\u0026#34;content-management\u0026#34; \u0026gt;}} Manpage As I use many times links to official manpage OpenBSD, I wrote this shortcode: Code:\u0026nbsp;shortcode\n{{\u0026lt; man title digit \u0026gt;}} If a digit is written, the shortcode build the URL as title.digit and the text as txt(digit). RAW source of the shortcode: man\nThe shortcode:\n{{ $txt := .Get 0 }}{{ $nb := .Get 1}} \u0026lt;a class=\u0026#34;man\u0026#34; href=\u0026#34;https://man.openbsd.org/{{ $txt }}{{ if $nb }}{{ print \u0026#34;.\u0026#34; $nb }}{{ end }}\u0026#34; title=\u0026#34;{{ i18n \u0026#34;manpageTitle\u0026#34; }}{{ $txt }}\u0026#34;\u0026gt;{{ $txt }}{{ if $nb }}{{ print \u0026#34;(\u0026#34; $nb \u0026#34;)\u0026#34; }}{{ end }}\u0026lt;/a\u0026gt; Examples:\nLink to the manpage Packet Filter: pf(4) Other link: httpd(8) And, the last but not the least: man Wikipedia Egual, for the Wikipedia, the shortcode is: Code:\u0026nbsp;shortcode\n{{\u0026lt; wp \u0026#34;url-article\u0026#34; \u0026gt;}} RAW source of the shortcode: wp\nThe shortcode:\n{{ $txt := .Get 0 }}{{ $title := print (i18n \u0026#34;wpTitleArticle\u0026#34;) $txt }}\u0026lt;a href=\u0026#34;https://{{ .Site.Language.Lang }}.wikipedia.org/wiki/{{ $txt }}\u0026#34; title=\u0026#34;{{ $title }}\u0026#34;\u0026gt;Wikipedia :: {{ $txt }}\u0026lt;/a\u0026gt; Examples:\nThis is an article to promote OpenBSD: OpenBSD WP This other is for Debian: Debian WP And, a third more complex: Firewall_(computing) WP Somewhere Finally, do not hesitate to have fun with the shortcodes; get help on the commmunity forum.\nhttps://after-dark.habd.as/shortcode/ ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eAs you see on Hugo\u0026rsquo;s page shortcodes,\n\u003cquote\u003ea shortcode is a simple snippet inside a content file that Hugo will render using a predefined template.\u003c/quote\u003e\u003c/p\u003e\n\u003cp\u003eSome times, you need to include/add raw \u003cabbr title=\"HyperText Markup Language\"\u003eHTML\u003c/abbr\u003e\n\ninto the \u003cabbr title=\"MarkDown\"\u003eMD\u003c/abbr\u003e\n content. The shortcode add correctly this.\nBy this way, you can include too MD syntax.\u003c/p\u003e\n\u003cp\u003ePut your shortcodes into  \u003ccode\u003elayout/shortcodes/\u003c/code\u003e.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eActually, I use the official third package  providen by the team OpenBSD:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eOpenBSD : \u003cstrong\u003e6.6\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eVersion d\u0026rsquo;Hugo : \u003cstrong\u003e0.53\u003c/strong\u003e : \u003ccode\u003eHugo Static Site Generator v0.53 openbsd/amd64 BuildDate: unknown\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eofficial : \u003ca href=\"https://gohugo.io/content-management/shortcodes/\" title=\"Link to the official site Hugo: Content management \u0026gt; Shortcodes\"\u003eHugo Documentation: Content management \u0026gt; Shortcodes\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"my-shortcodes\"\u003eMy shortcodes\u003c/h2\u003e\n\u003ch3 id=\"abbr\"\u003eabbr\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eTo manage element HTML \u003ccode\u003eabbr\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"abbr.html\" title=\"\"\u003eabbr\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eabbr\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eGet\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e1\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e|\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprintf\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e`\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e%q`\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e|\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esafeHTMLAttr\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u003c/span\u003e\u0026gt;{{ .Get 0 | safeHTML }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eabbr\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; abbr accronym \u0026#34;Meaning of Acronym\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eExample: \u003cabbr title=\"HyperText Markup Language\"\u003eHTML\u003c/abbr\u003e\n is written as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; abbr HTML \u0026#34;HyperText Markup Language\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003ch3 id=\"anchor\"\u003eanchor\u003c/h3\u003e\n\u003cp\u003eTo manage the anchor into one page is a little complex:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"anchor.html\" title=\"\"\u003eanchor\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $txt := .Get 0 | safeHTML }}{{ $name := .Get 1 | lower | safeHTML }}{{ $anchor := anchorize $name }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ printf \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e%\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003es\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003ePage\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eRelPermalink\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}#{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eanchor\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eshortcodeAnchorTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003ename\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;{{ $txt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as: \u003cbr\u003e\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; anchor \u0026#34;Texte\u0026#34; \u0026#34;Cible\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eExample: this \u003ca href=\"/en/web/hugo/hugo-shortcodes/#description\" title=\"Go to the anchor: description\"\u003elink\u003c/a\u003e\n refers to the section\nDescription; his writing is: \u003cbr\u003e\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; anchor \u0026#34;link\u0026#34; \u0026#34;description\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003ch3 id=\"blockquote\"\u003eblockquote\u003c/h3\u003e\n\u003cp\u003eWriting a basic element HTML \u003ccode\u003eblockquote\u003c/code\u003e, you need only:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eblockquote\u003c/span\u003e\u0026gt;{{ $file := .Get 0 | readFile | htmlUnescape | safeHTML }}{{ $file }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eblockquote\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eBut, my shorcode is more evolved, because as you see, this site is multilanguage. Also:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"blockquote.html\" title=\"\"\u003eblockquote\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;info-quote\u0026#34;\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;text-white-50\u0026#34;\u003c/span\u003e\u0026gt;{{ T \u0026#34;quoteTitle\u0026#34; }}{{ if .Get 1 }} \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;{{ .Get 1 | safeHTML }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;{{ end }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;quote\u0026#34;\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eblockquote\u003c/span\u003e\u0026gt;{{ $name := .Get 0 }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile | htmlUnescape | safeHTML }}{{ $file }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eblockquote\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as: \u003cbr\u003e\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; blockquote \u0026#34;blockquote-filename\u0026#34; lang \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eblockquote-filename\u003c/code\u003e: the file to call where the blockquote is written\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elang\u003c/code\u003e: the lang, i.e \u003ccode\u003een\u003c/code\u003e, \u003ccode\u003efr\u003c/code\u003e, etc. - \u003cem\u003eTo avoid specifying an code, use \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample:\n\u003cdiv class=\"info-quote\"\u003e\n    \u003cp\u003eQuotes: \u003cem\u003efr\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"quote\"\u003e\n    \u003cfigure\u003e\n        \u003cblockquote lang=\"fr\"\u003e\u003c/blockquote\u003e\n    \u003c/figure\u003e\n\u003c/div\u003e\n\u003c/p\u003e\n\u003ch3 id=\"code\"\u003eCode\u003c/h3\u003e\n\u003cp\u003eTo include some example code, I created into \u003ccode\u003econtent/\u003c/code\u003e folder a directory named \u003ccode\u003einc\u003c/code\u003e. \u003cem\u003eYou can named as you want; it\u0026rsquo;s up to you!\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eAnd after, create needed files, and call them as \u003ccode\u003e/content/folder_name/file_name\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBy default:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003ehtml\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $file := .Get 0 | readFile }}{{ $lang := .Get 1 }}{{ $opt := \u0026#34;\u0026#34; }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cp\u003eFor my needs, my shortcode is \u0026ldquo;a little more\u0026rdquo; advanced:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"code.html\" title=\"\"\u003ecode\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $name := .Get 0 }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile }}{{ $lang := .Get 1 }}{{ $opt := \u0026#34;\u0026#34; }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;info-code\u0026#34;\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;text-white-50\u0026#34;\u003c/span\u003e\u0026gt;{{ i18n \u0026#34;codeTitle\u0026#34; }}\u0026amp;nbsp;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;{{ $lang }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; code \u0026#34;code-filename\u0026#34; language \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecode-filename\u003c/code\u003e: the file to call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elanguage\u003c/code\u003e: the language, i.e \u003ccode\u003esh\u003c/code\u003e, \u003ccode\u003ePHP\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, etc. \u003cem\u003eTo avoid specifying an code, use \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample: Look, you have one just above it!\u003c/p\u003e\n\u003ch3 id=\"color\"\u003eColor\u003c/h3\u003e\n\u003cp\u003eA very small shortcode to add color on text.\u003c/p\u003e\n\u003cp\u003eInto my \u003cabbr title=\"Cascaded Style Sheet\"\u003eCSS\u003c/abbr\u003e\n, I had some definitions with named colors.\u003c/p\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"color.html\" title=\"\"\u003ecolor\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003espan\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eGet\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e|\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eprintf\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e`\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e%q`\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e|\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esafeHTMLAttr\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u003c/span\u003e\u0026gt;{{ .Inner }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003espan\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; color \u0026#34;css-name\u0026#34; \u0026gt;}}text{{\u0026lt; /color \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecss-name\u003c/code\u003e: the CSS name\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etext\u003c/code\u003e: the text\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample: This is \u003cspan class=\"dark-green\"\u003egreen text\u003c/span\u003e\n, or \u003cspan class=\"orange\"\u003eorange\u003c/span\u003e\n, and this other is \u003cspan class=\"red\"\u003ered\u003c/span\u003e\n, etc…\u003c/p\u003e\n\u003ch3 id=\"file\"\u003eFile\u003c/h3\u003e\n\u003cp\u003eTo include a file content example, I fork the shortcode \u003ca href=\"/en/web/hugo/hugo-shortcodes/#code\" title=\"Go to the anchor: code\"\u003ecode\u003c/a\u003e\n. It\u0026rsquo;s quasy-same code.\u003c/p\u003e\n\u003cp\u003eBut, for my need, I wrote an advanced as:\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"file.html\" title=\"\"\u003efile\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $name := .Get 0 | safeHTML }}{{ $file := urlize (print \u0026#34;/content/inc/\u0026#34; $name) | readFile }}{{ $lang := .Get 1}}{{ $filename := .Get 2 }}{{  $opt := \u0026#34;linenos=table\u0026#34; }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;info-file\u0026#34;\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;text-white-50\u0026#34;\u003c/span\u003e\u0026gt;{{ i18n \u0026#34;fileTitle\u0026#34; }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;{{ $filename }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003eem\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ep\u003c/span\u003e\u0026gt;\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;code\u0026#34;\u003c/span\u003e\u0026gt;{{ highlight $file $lang $opt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as: \u003cbr\u003e\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; file \u0026#34;example-file\u0026#34; language \u0026#34;filename\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e/example-file\u003c/code\u003e: file to call\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elanguage\u003c/code\u003e: language, i.e. \u003ccode\u003esh\u003c/code\u003e, \u003ccode\u003ePHP\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, etc… \u003cem\u003eTo avoid specifying an code, use \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efilename\u003c/code\u003e: filename to display ;)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample: Look above to see!\u003c/p\u003e\n\u003ch3 id=\"image\"\u003eImage\u003c/h3\u003e\n\u003cp\u003eYes, I known Markdown had his code to include basically image.\u003c/p\u003e\n\u003chr\u003e\n\u003ch4 id=\"pngjpgtiff\"\u003ePNG/JPG/Tiff\u003c/h4\u003e\n\u003cp\u003eThis shortcode exists to specify width of image, and link to the raw image.\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"img.html\" title=\"\"\u003eimg\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 1\u003c/span\u003e\u003cspan\u003e{{/* runner for assets/image */}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 2\u003c/span\u003e\u003cspan\u003e{{- $src := resources.Get (printf \u0026#34;%s%s\u0026#34; \u0026#34;/images/\u0026#34; (.Get \u0026#34;s\u0026#34;)) -}}{{- $alt := .Get \u0026#34;a\u0026#34; | safeHTML -}}{{- $width := printf \u0026#34;%s\u0026#34; (.Get \u0026#34;w\u0026#34;) -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 3\u003c/span\u003e\u003cspan\u003e{{- $img := $src -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 4\u003c/span\u003e\u003cspan\u003e{{- with $width -}}{{- $img = $src.Resize (printf \u0026#34;%sx\u0026#34; $width) -}}{{- end -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 5\u003c/span\u003e\u003cspan\u003e{{- with $img -}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 6\u003c/span\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003efigure\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 7\u003c/span\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $src.RelPermalink }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $alt }}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 8\u003c/span\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003epicture\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 9\u003c/span\u003e\u003cspan\u003e        \u003cspan style=\"color:#776e71\"\u003e\u0026lt;!-- \u0026lt;source srcset=\u0026#34;/img/.avif\u0026#34; type=\u0026#34;image/avif\u0026#34;\u0026gt; --\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e10\u003c/span\u003e\u003cspan\u003e        {{- with .Resize (printf \u0026#34;%dx%d webp\u0026#34; .Width .Height) }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e11\u003c/span\u003e\u003cspan\u003e        \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003esource\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esrcset\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .RelPermalink }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;image/webp\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e12\u003c/span\u003e\u003cspan\u003e        {{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e13\u003c/span\u003e\u003cspan\u003e        \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003eimg\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ealt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $alt }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eloading\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;lazy\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003esrc\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .RelPermalink }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etype\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .MediaType }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eheight\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .Height }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ewidth\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .Width }}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e14\u003c/span\u003e\u003cspan\u003e    \u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003epicture\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e15\u003c/span\u003e\u003cspan\u003e    \u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e16\u003c/span\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003efigcaption\u003c/span\u003e\u0026gt;{{ $alt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003efigcaption\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e17\u003c/span\u003e\u003cspan\u003e\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003efigure\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e18\u003c/span\u003e\u003cspan\u003e{{- end -}}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; img a=\u0026#34;alt\u0026#34; s=\u0026#34;src\u0026#34; w=\u0026#34;width\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cp\u003eThe named parameters are:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ea\u003c/code\u003e: equivalent for attribute \u003ccode\u003ealt\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003es\u003c/code\u003e: equivalent for attribute \u003ccode\u003esrc\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ew\u003c/code\u003e: equivalent for attribute \u003ccode\u003ewidth\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample:\u003c/p\u003e\n\u003cfigure\u003e\n    \u003ca href=\"/images/Logo_full_192px.png\" title=\"My Logo\"\u003e\n    \u003cpicture\u003e\n        \n        \u003csource srcset=\"/images/Logo_full_192px_hu_e0b3cd9c38226f1f.webp\" type=\"image/webp\"\u003e\n        \n        \u003cimg alt=\"My Logo\" height=\"124\" loading=\"lazy\" src=\"/images/Logo_full_192px_hu_bfb19336d47c760c.png\" type=\"image/png\" width=\"124\"\u003e\n    \u003c/picture\u003e\n    \u003c/a\u003e\n    \u003cfigcaption\u003eMy Logo\u003c/figcaption\u003e\n\u003c/figure\u003e\n\u003cp\u003eThis image is my logo, named \u0026ldquo;My Logo\u0026rdquo;, with an original width at 192\n\u003cabbr title=\"pixels\"\u003epx\u003c/abbr\u003e\n, resized at 124 px, into\n\u003cabbr title=\"Portable Network Graphics\"\u003ePNG\u003c/abbr\u003e\n format.\u003c/p\u003e\n\u003ch4 id=\"svg\"\u003eSVG\u003c/h4\u003e\n\u003cp\u003eAbout the SVG picture, I manage them like as:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"figure-svg.html\" title=\"\"\u003efigure-svg\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 1\u003c/span\u003e\u003cspan\u003e{{/* runner for assets/svg */}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 2\u003c/span\u003e\u003cspan\u003e{{- $class := .Get \u0026#34;class\u0026#34; -}}{{- $src := resources.Get (printf \u0026#34;%s%s\u0026#34; \u0026#34;/svg/\u0026#34; (.Get \u0026#34;src\u0026#34;)) -}}{{ $title := .Get \u0026#34;title\u0026#34; }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 3\u003c/span\u003e\u003cspan\u003e{{ with $src }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 4\u003c/span\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003efigure\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ if $class }}{{ $class }}{{ end }}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 5\u003c/span\u003e\u003cspan\u003e    \u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ .RelPermalink }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $title }}\u0026#34;\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 6\u003c/span\u003e\u003cspan\u003e    {{ .Content | safeHTML }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 7\u003c/span\u003e\u003cspan\u003e    \u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 8\u003c/span\u003e\u003cspan\u003e    {{ if $title }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003efigcaption\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003earia-hidden\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;true\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;hidden\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehidden\u003c/span\u003e\u0026gt;{{ $title }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003efigcaption\u003c/span\u003e\u0026gt;{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e 9\u003c/span\u003e\u003cspan\u003e\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003efigure\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e10\u003c/span\u003e\u003cspan\u003e{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; figure-svg class=\u0026#34;class-name\u0026#34; src=\u0026#34;image.svg\u0026#34; title=\u0026#34;the title\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eExample :\n\n\n\u003cfigure class=\"pure-img\"\u003e\n    \u003ca href=\"/svg/Logo_final.svg\" title=\"My Logo\"\u003e\n    \u003c?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"no\"?\u003e\n\u003csvg\n   id=\"svg3108\"\n   version=\"1.1\"\n   inkscape:version=\"1.2.2 (b0a8486541, 2022-12-01)\"\n   sodipodi:docname=\"Logo_final.svg\"\n   width=\"64\"\n   height=\"64\"\n   xmlns:inkscape=\"http://www.inkscape.org/namespaces/inkscape\"\n   xmlns:sodipodi=\"http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd\"\n   xmlns=\"http://www.w3.org/2000/svg\"\n   xmlns:svg=\"http://www.w3.org/2000/svg\"\n   xmlns:rdf=\"http://www.w3.org/1999/02/22-rdf-syntax-ns#\"\n   xmlns:cc=\"http://creativecommons.org/ns#\"\n   xmlns:dc=\"http://purl.org/dc/elements/1.1/\"\u003e\n  \u003csodipodi:namedview\n     id=\"namedview30\"\n     pagecolor=\"#ffffff\"\n     bordercolor=\"#000000\"\n     borderopacity=\"0.25\"\n     inkscape:showpageshadow=\"2\"\n     inkscape:pageopacity=\"0.0\"\n     inkscape:pagecheckerboard=\"0\"\n     inkscape:deskcolor=\"#d1d1d1\"\n     showgrid=\"false\"\n     inkscape:zoom=\"3.0570583\"\n     inkscape:cx=\"30.421402\"\n     inkscape:cy=\"58.225909\"\n     inkscape:window-width=\"1920\"\n     inkscape:window-height=\"1031\"\n     inkscape:window-x=\"0\"\n     inkscape:window-y=\"25\"\n     inkscape:window-maximized=\"1\"\n     inkscape:current-layer=\"layer1\" /\u003e\n  \u003ctitle\n     id=\"title853\"\u003eLogo Emblème Stéphane HUC\u003c/title\u003e\n  \u003cdefs\n     id=\"defs3110\" /\u003e\n  \u003cmetadata\n     id=\"metadata3113\"\u003e\n    \u003crdf:RDF\u003e\n      \u003ccc:Work\n         rdf:about=\"\"\u003e\n        \u003cdc:title\u003eLogo Emblème Stéphane HUC\u003c/dc:title\u003e\n      \u003c/cc:Work\u003e\n    \u003c/rdf:RDF\u003e\n  \u003c/metadata\u003e\n  \u003cg\n     inkscape:label=\"Calque 1\"\n     inkscape:groupmode=\"layer\"\n     id=\"layer1\"\n     transform=\"translate(0.00367771,-0.00353708)\"\u003e\n    \u003cg\n       transform=\"matrix(0.02413578,0,0,0.02334611,-0.05137015,-0.00127009)\"\n       style=\"display:inline\"\n       id=\"g4250\"\n       inkscape:export-filename=\"/home/zou/Documents/Projets_sur_images/Stephane-huc.net/Logo_original.png\"\n       inkscape:export-xdpi=\"300\"\n       inkscape:export-ydpi=\"300\"\u003e\n      \u003cg\n         id=\"g3893\"\n         style=\"display:inline;fill:#4d4d4d\"\n         transform=\"matrix(0.06444778,0,0,0.06450434,865.42675,1541.6735)\"\u003e\n        \u003cpath\n           inkscape:connector-curvature=\"0\"\n           sodipodi:nodetypes=\"ccccccccccccccccccccccccccccccccccccsssc\"\n           id=\"path2385-6-1-2\"\n           d=\"m 23774.425,-13094.781 c -407.725,2.746 -749.397,40.026 -972.445,28.012 -4599.937,59.837 -9024.559,3454.6637 -10088.773,4551.7613 -1032.632,1431.3562 -1902.759,4120.4375 -3414.3254,6116.3965 C 7040.4567,1715.9353 4369.202,5321.9681 986.55523,8407.9766 -4389.5849,12448.032 -8602.0428,12402.637 -12768.187,12194.347 c -252.964,17.663 -415.823,306.287 -501.736,508.146 274.498,360.798 549.024,468.121 823.522,457.374 l 2991.3542,-94.976 c 3456.504,-296.023 6332.5254,-987.067 8247.1738,-2331.958 -1416.3389,1353.905 -8714.7449,3661.386 -9866.29,3397.271 -283.94,94.386 -9.166,418.668 -14.627,627.634 443.726,168.12 891.426,312.023 1382.8762,197.395 3340.0325,-1065.466 6699.0628,-1956.661 9899.08747,-4312.462 L -6089.161,17754.195 c -98.5516,407.272 -100.4203,652.783 -4.8749,736.614 l 355.0258,94.104 c 229.6322,33.856 492.0244,-81.828 782.3016,-323.448 L 2012.6316,9672.4329 C 2658.8638,14594.17 7818.5983,15351.227 11738.861,12799.22 l 127.65,-1168.167 C 7834.5326,14914.263 2650.1202,12909.869 3004.5788,9106.5143 L 5888.675,5359.9752 C 6887.5627,4011.8679 8068.294,2775.8085 9455.3418,1667.2698 h 8.8646 C 10742.256,691.78922 12091.181,-25.504325 13349.115,-1036.7181 c 1520.143,-1055.4722 4302.351,-1145.0617 5286.398,-2327.1449 1177.704,-1664.9321 2145.664,-3667.8767 2974.957,-5435.546 1020.536,-2296.596 2897.375,-2743.981 6123.216,-278.3644 -109.42,-1287.3486 -1023.595,-2502.5416 -1546.427,-3009.9256 -1021.529,-829.12 -1603.165,-855.9 -2412.834,-1007.082 z m -34848.588,27224.985 c 1.234,-0.42 2.29,-0.913 3.545,-1.315 h -9.309 c 1.838,0.451 3.895,0.882 5.764,1.315 z m 36292.522,-26286.618 c 206.696,0 374.086,206.617 374.086,461.752 0,255.135 -167.39,462.19 -374.086,462.19 -206.695,0 -374.529,-207.055 -374.529,-462.19 0,-255.135 167.834,-461.752 374.529,-461.752 z\"\n           style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:21.9289px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\" /\u003e\n        \u003cg\n           transform=\"matrix(14.180303,0.29145382,-0.29145382,14.180303,39070.285,-17179.84)\"\n           id=\"g3323-6-2\"\n           style=\"fill:#999999;fill-opacity:1;stroke:#990000;stroke-opacity:1\"\u003e\n          \u003cpath\n             inkscape:connector-curvature=\"0\"\n             style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             d=\"m -1938.7905,1344.2995 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n             id=\"path3190-2-0-4\"\n             sodipodi:nodetypes=\"cccccccccccccccccccccc\" /\u003e\n          \u003cpath\n             inkscape:connector-curvature=\"0\"\n             style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             d=\"m -1766.1814,1226.0731 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n             id=\"path3190-0-8-2-9\"\n             sodipodi:nodetypes=\"cccccccccccccccccccccc\" /\u003e\n        \u003c/g\u003e\n        \u003cg\n           id=\"g3607-7\"\n           style=\"fill:#999999;fill-opacity:1;stroke:#990000;stroke-opacity:1\"\n           transform=\"matrix(10.256384,0,0,10.256384,27740.017,-9419.2772)\"\u003e\n          \u003cpath\n             inkscape:connector-curvature=\"0\"\n             sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n             id=\"path2853-1-2-3\"\n             d=\"m -3334.7852,-1248.287 c 51.9752,263.91148 364.552,597.09982 649.489,723.58561 186.8994,102.74774 436.9783,80.34473 628.0009,153.0754 176.754,59.99791 336.6065,134.19234 455.7429,223.77162 v 0 c 95.6093,72.55212 166.8615,174.225196 178.8187,313.54167 -21.1645,58.71298 -67.8029,109.93553 -112.5308,161.38138 -108.9474,42.30362 -193.7664,43.94287 -273.1033,40.38991 v 0 c -289.559,-41.98012 -408.6126,-122.75609 -537.4682,-237.26062 -138.9061,-154.600767 -217.6672,-263.90172 -373.9094,-355.18101 -178.3851,-112.57744 -359.9805,-46.07103 -531.5855,-101.08503 -15.4761,-3.45827 -6.3053,-53.81809 36.6639,-43.63616 64.7876,15.3519 174.3223,-1.04389 174.3223,-1.04389 l -79.9048,-49.14253 v 0 l 36.7606,-7.32283 v 0 l 89.4837,49.88512 v 0 l 180.7667,8.58049 v 0 l -95.19,-169.30622 v 0 0 l -44.2175,-2.75208 v 0 l 1.9939,-18.56317 31.584,1.9656 c -91.0217,-150.25746 -222.4184,-249.74105 -339.9897,-366.61111 l 33.2464,-1.66844 v 0 l 33.3433,34.64483 v 0 c -87.3435,-107.03536 -156.5494,-220.39644 -185.2023,-347.90084 5.407,-25.6798 28.4059,-33.5554 42.8852,-9.3477 z\"\n             style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:3.14969px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\" /\u003e\n          \u003cpath\n             inkscape:connector-curvature=\"0\"\n             sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n             id=\"path2853-1-8-2-7\"\n             d=\"m -3964.5819,579.94648 c 232.1778,142.02444 696.5351,140.75989 988.106,18.70266 205.9526,-66.5673 362.6995,-264.70185 549.2022,-354.76022 167.1463,-88.31108 333.1245,-154.57977 482.3054,-180.583195 v 0 c 120.2135,-20.415854 245.1813,-3.15744 357.0123,83.134705 28.9606,55.52615 34.6919,124.56859 41.9136,192.36665 -44.1007,108.51739 -101.6932,171.65364 -159.3434,227.23914 v 0 c -231.9712,183.0827 -374.5522,215.03066 -548.9965,231.13768 -211.2129,-3.89591 -347.056,-20.86741 -523.2284,31.10727 -207.3545,53.63654 -283.8394,231.78243 -443.7115,319.72853 -13.3008,8.9568 -44.3697,-32.1019 -7.0087,-56.5744 56.3312,-36.899 120.0937,-128.17265 120.0937,-128.17265 l -91.9262,24.90186 v 0 l 20.0462,-31.87375 v 0 l 99.1198,-31.39936 v 0 l 131.7153,-126.31933 v 0 l -191.8305,-45.89202 v 0 0 l -32.7044,30.45368 v 0 l -12.4139,-14.12077 23.3603,-21.75279 c -174.7833,-35.94516 -339.8259,-7.73356 -508.2045,-1.49116 l 21.8121,-25.44723 v 0 l 48.8674,-0.74684 v 0 c -140.1103,-9.1506 -272.3455,-35.87817 -386.9742,-101.90494 -15.3362,-21.4712 -5.2426,-43.65993 22.7879,-37.73352 z\"\n             style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:3.1754px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\" /\u003e\n        \u003c/g\u003e\n      \u003c/g\u003e\n      \u003cpath\n         style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.41389px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n         d=\"m 2394.9999,689.06305 c -26.2769,0.17713 -48.2969,2.58185 -62.6719,1.8069 -296.4557,3.85975 -581.6127,222.84081 -650.199,293.60838 -66.5508,92.32867 -122.6286,265.78617 -220.0457,394.53417 -145.5504,265.4061 -317.7069,498.0109 -535.71096,697.0718 -346.48036,260.6012 -617.96395,257.673 -886.462661,244.2374 -16.303005,1.1393 -26.798914,19.7568 -32.3357924,32.7776 17.6907774,23.2731 35.3833394,30.1959 53.0741824,29.5026 l 192.786151,-6.1263 c 222.76402,-19.0948 408.11723,-63.6701 531.51204,-150.4215 -91.27986,87.3328 -561.64597,236.1754 -635.8605,219.1388 -18.29929,6.0883 -0.59073,27.0059 -0.94272,40.4851 28.59717,10.8445 57.45048,20.1269 89.12335,12.7328 215.25769,-68.7271 431.73976,-126.2131 637.97425,-278.1725 L 470.3581,2678.956 c -6.35143,26.2709 -6.47187,42.1074 -0.31418,47.5149 l 22.88063,6.0701 c 14.79923,2.1838 31.70983,-5.2783 50.41755,-20.8638 l 449.15854,-554.0299 c 41.64826,317.4734 374.18176,366.3069 626.83396,201.6913 l 8.2267,-75.3518 c -259.852,211.7813 -593.9759,82.4892 -571.1318,-162.8437 l 185.8736,-241.6681 c 64.3761,-86.9587 140.4715,-166.6899 229.8637,-238.1955 h 0.5713 c 82.3675,-62.9228 169.3027,-109.1913 250.3737,-174.419 97.9699,-68.0825 277.277,-73.8615 340.6967,-150.111 75.9004,-107.3953 138.2833,-236.5939 191.7294,-350.61629 65.7712,-148.14043 186.7294,-176.9987 394.6277,-17.95572 -7.0519,-83.03958 -65.9685,-161.4248 -99.6638,-194.15328 -65.8353,-53.48184 -103.3205,-55.20926 -155.5019,-64.96116 z M 149.08576,2445.1929 c 0.0795,-0.027 0.14754,-0.059 0.22845,-0.085 h -0.59993 c 0.11845,0.029 0.25098,0.057 0.37148,0.085 z M 2488.0583,749.5918 c 13.3211,0 24.109,13.32769 24.109,29.78501 0,16.45732 -10.7879,29.81326 -24.109,29.81326 -13.321,0 -24.1375,-13.35594 -24.1375,-29.81326 0,-16.45732 10.8165,-29.78501 24.1375,-29.78501 z\"\n         id=\"path2385-6-1-2-3\"\n         sodipodi:nodetypes=\"ccccccccccccccccccccccccccccccccccccsssc\"\n         inkscape:connector-curvature=\"0\" /\u003e\n      \u003cg\n         style=\"display:inline;fill:#999999;fill-opacity:1;stroke:#990000;stroke-opacity:1\"\n         id=\"g3323-6-2-4\"\n         transform=\"matrix(0.91388911,0.01880004,-0.01878355,0.91469117,3380.7843,425.559)\"\u003e\n        \u003cpath\n           sodipodi:nodetypes=\"cccccccccccccccccccccc\"\n           id=\"path3190-2-0-4-2\"\n           d=\"m -1938.7905,1344.2995 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n           style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n           inkscape:connector-curvature=\"0\" /\u003e\n        \u003cpath\n           sodipodi:nodetypes=\"cccccccccccccccccccccc\"\n           id=\"path3190-0-8-2-9-5\"\n           d=\"m -1766.1814,1226.0731 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n           style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n           inkscape:connector-curvature=\"0\" /\u003e\n      \u003c/g\u003e\n      \u003cpath\n         inkscape:connector-curvature=\"0\"\n         sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n         id=\"path2853-1-2-3-9\"\n         d=\"m 1071.448,12.565243 c -15.3369,146.179207 73.828,372.947977 180.7482,487.459287 67.2709,85.4026 180.411,116.49879 253.836,186.99056 68.9967,61.4286 128.5121,127.35333 167.9088,194.3213 v 0 c 31.5208,54.088 48.125,119.16171 33.2259,193.68211 -17.7944,26.9261 -45.6999,45.6007 -72.7982,64.718 -53.9976,3.3831 -91.5092,-10.2639 -125.8605,-25.6749 v 0 C 1387.3321,1042.7224 1346.6981,980.34835 1306.6359,898.75209 1267.9574,794.5785 1249.1568,724.2529 1193.6994,650.05735 1131.5923,560.99655 1042.1677,564.5514 974.71289,506.59578 c -6.30086,-4.44472 5.01449,-29.07557 22.42474,-16.43307 26.25067,19.06189 76.75837,29.25724 76.75837,29.25724 l -28.0058,-39.22499 v 0 l 17.2141,2.47464 v 0 l 32.108,41.24885 v 0 l 78.1981,35.36579 v 0 l -17.3399,-104.35052 v 0 0 l -19.0336,-8.99068 v 0 l 3.5616,-9.31623 13.5954,6.42185 c -18.2636,-93.72824 -61.6156,-167.94463 -96.3766,-248.84241 l 14.8517,4.81539 v 0 l 9.6413,23.72335 v 0 c -22.9001,-70.61432 -36.914,-141.418612 -31.0608,-212.64819 6.091,-12.4349571 17.3374,-12.6004057 20.1985,2.468443 z\"\n         style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:1.58535px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\" /\u003e\n      \u003cpath\n         inkscape:connector-curvature=\"0\"\n         sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n         id=\"path2853-1-8-2-7-4\"\n         d=\"m 346.99101,968.42886 c 122.89969,124.43284 416.59744,198.91414 621.36814,171.56464 141.34235,-7.3092 273.67225,-103.0072 406.66535,-127.8264 120.466,-26.88812 236.4935,-40.49317 335.1448,-32.21014 v 0 c 79.4054,7.00369 155.4909,37.80454 211.6845,108.67004 8.9823,38.6312 1.014,81.759 -5.8034,124.3677 -46.0902,59.1793 -93.0891,88.4349 -138.8571,113.0661 v 0 c -177.3468,74.3073 -272.8249,70.7271 -385.7821,52.3012 -132.8378,-36.6106 -215.845,-68.9985 -335.9157,-65.7821 -140.05758,-0.8213 -218.30441,95.6669 -334.11166,123.5108 -9.91006,3.3189 -22.65364,-26.8114 5.06783,-35.7143 41.79723,-13.4237 97.41938,-58.8771 97.41938,-58.8771 l -62.28015,0.3225 v 0 l 18.02055,-16.2327 v 0 l 67.9175,-3.1279 v 0 l 104.45336,-55.8609 v 0 l -113.53757,-59.1376 v 0 0 l -25.78236,13.3133 v 0 l -5.4754,-10.6425 18.41603,-9.5096 c -104.43314,-50.2954 -213.48017,-59.7993 -320.94769,-83.2716 l 18.0578,-12.0185 v 0 l 31.01082,7.463 v 0 c -87.0171,-28.2993 -166.10614,-66.0655 -227.47003,-124.99811 -6.08836,-15.60868 4.01601,-27.53473 20.7371,-19.36983 z\"\n         style=\"display:inline;fill:#999999;fill-opacity:1;fill-rule:evenodd;stroke:#990000;stroke-width:2.04192px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\" /\u003e\n      \u003cg\n         id=\"g2901\"\n         style=\"display:inline;fill:#990000;fill-opacity:1;stroke:#800000\"\n         inkscape:export-filename=\"/home/zou/Documents/Projets_sur_images/Stephane-huc.net/Logo_gris_999999_390px.png\"\n         inkscape:export-xdpi=\"90\"\n         inkscape:export-ydpi=\"90\"\n         transform=\"matrix(0.66100118,0,0,0.66158128,2645.7866,917.11829)\"\u003e\n        \u003cpath\n           style=\"display:inline;fill:#990000;fill-opacity:1;fill-rule:evenodd;stroke:#800000;stroke-width:2.13807px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n           d=\"m -386.64618,-358.3625 c -39.7533,0.2677 -73.0664,3.9025 -94.8137,2.7311 -448.495,5.8342 -879.89672,336.83061 -983.65782,443.797906 -100.6819,139.557584 -185.5195,401.743684 -332.8976,596.350184 -220.197,401.16931 -480.645,752.75841 -810.4539,1053.64501 -524.175,393.9064 -934.8907,389.4804 -1341.0908,369.1721 -24.6641,1.7221 -40.5428,29.863 -48.9194,49.5443 26.7636,35.1779 53.53,45.6419 80.2936,44.5941 l 291.6578,-9.2602 c 337.01,-28.8623 617.4228,-96.2393 804.1015,-227.3665 -138.0934,132.0061 -849.6898,356.9861 -961.9657,331.2348 -27.6843,9.2027 -0.8937,40.8202 -1.4262,61.1945 43.2634,16.3917 86.9143,30.4223 134.8308,19.246 325.654,-103.8832 653.1603,-190.7749 965.1635,-420.4661 l -612.5292,693.3656 c -9.6088,39.7091 -9.791,63.6465 -0.4753,71.8201 l 34.6151,9.1751 c 22.3892,3.301 47.9725,-7.9782 76.2746,-31.5362 l 679.5124,-837.4328 c 63.0078,479.8706 566.0832,553.6838 948.3098,304.8625 l 12.4459,-113.8966 c -393.1189,320.1138 -898.6004,124.6849 -864.0406,-246.1431 l 281.2001,-365.2885 c 97.3918,-131.4408 212.5134,-251.9569 347.7509,-360.0397 h 0.8643 c 124.6102,-95.1096 256.1307,-165.0459 378.7796,-263.6395 148.2143,-102.9088 419.48022,-111.6438 515.42512,-226.8972 114.8264,-162.3313 209.2027,-357.6189 290.059,-529.967097 99.5025,-223.918703 282.4948,-267.538803 597.0151,-27.1406 -10.6685,-125.5168 -99.8008,-243.998403 -150.777,-293.468503 -99.5993,-80.8394 -156.309,-83.4505 -235.2519,-98.1907 z M -3784.3922,2296.0803 c 0.1203,-0.041 0.2232,-0.089 0.3456,-0.1282 h -0.9076 c 0.1792,0.044 0.3797,0.086 0.562,0.1282 z M -245.86228,-266.8715 c 20.1529,0 36.4735,20.1452 36.4735,45.0209 0,24.8757 -16.3206,45.0637 -36.4735,45.0637 -20.1528,0 -36.5167,-20.188 -36.5167,-45.0637 0,-24.8757 16.3639,-45.0209 36.5167,-45.0209 z\"\n           id=\"path2385-6-1\"\n           sodipodi:nodetypes=\"ccccccccccccccccccccccccccccccccccccsssc\"\n           inkscape:connector-curvature=\"0\" /\u003e\n        \u003cg\n           style=\"fill:#990000;fill-opacity:1;stroke:#800000\"\n           id=\"g3323-6\"\n           transform=\"matrix(1.3825831,0.02841682,-0.02841682,1.3825831,1104.704,-756.6568)\"\u003e\n          \u003cpath\n             sodipodi:nodetypes=\"cccccccccccccccccccccc\"\n             id=\"path3190-2-0\"\n             d=\"m -1938.7905,1344.2995 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n             style=\"display:inline;fill:#990000;fill-opacity:1;fill-rule:evenodd;stroke:#800000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             inkscape:connector-curvature=\"0\" /\u003e\n          \u003cpath\n             sodipodi:nodetypes=\"cccccccccccccccccccccc\"\n             id=\"path3190-0-8-2\"\n             d=\"m -1766.1814,1226.0731 15.3955,-1.283 7.0562,-10.2637 -3.8488,-8.9807 3.8488,-8.9808 c 26.901,-8.9122 44.2829,-1.9591 55.8088,14.754 -0.1027,10.6945 -8.3234,15.9763 -18.6029,19.8859 -6.7082,-0.016 -14.6164,2.0346 -17.3412,-4.8053 v 0 c -16.1045,-1.7244 -11.7855,6.9433 -12.7007,9.072 3.8166,4.6142 10.3634,8.3754 23.8137,9.979 -7.6533,3.5761 -11.6619,14.8063 -24.7209,7.0307 -5.8792,-4.5108 -13.9229,-4.3322 -16.5562,-15.8758 -13.5829,-3.7285 -14.572,5.856 -14.515,11.1131 -0.352,5.6108 2.6918,10.0899 5.8967,14.5151 18.6918,9.7777 28.4118,11.6393 36.968,12.4739 11.2194,0.8225 24.7349,-15.9588 37.6483,-28.123 11.7646,0.4051 16.4086,-11.0571 23.1335,-19.0511 6.177,-27.5232 -20.7198,-44.6944 -30.8445,-51.7098 -19.6553,-8.2012 -39.8866,-7.5233 -50.5759,-3.6288 -9.4566,6.292 -15.9533,13.324 -23.1334,20.1851 -3.7507,11.7151 -4.9786,23.178 3.27,33.6932 z\"\n             style=\"display:inline;fill:#990000;fill-opacity:1;fill-rule:evenodd;stroke:#800000;stroke-width:1.55587px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             inkscape:connector-curvature=\"0\" /\u003e\n        \u003c/g\u003e\n        \u003cg\n           style=\"fill:#990000;fill-opacity:1;stroke:#800000\"\n           id=\"g3607\"\u003e\n          \u003cpath\n             style=\"display:inline;fill:#990000;fill-opacity:1;fill-rule:evenodd;stroke:#800000;stroke-width:3.14969px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             d=\"m -3334.7852,-1248.287 c 51.9752,263.91148 364.552,597.09982 649.489,723.58561 186.8994,102.74774 436.9783,80.34473 628.0009,153.0754 176.754,59.99791 336.6065,134.19234 455.7429,223.77162 v 0 c 95.6093,72.55212 166.8615,174.225196 178.8187,313.54167 -21.1645,58.71298 -67.8029,109.93553 -112.5308,161.38138 -108.9474,42.30362 -193.7664,43.94287 -273.1033,40.38991 v 0 c -289.559,-41.98012 -408.6126,-122.75609 -537.4682,-237.26062 -138.9061,-154.600767 -217.6672,-263.90172 -373.9094,-355.18101 -178.3851,-112.57744 -359.9805,-46.07103 -531.5855,-101.08503 -15.4761,-3.45827 -6.3053,-53.81809 36.6639,-43.63616 64.7876,15.3519 174.3223,-1.04389 174.3223,-1.04389 l -79.9048,-49.14253 v 0 l 36.7606,-7.32283 v 0 l 89.4837,49.88512 v 0 l 180.7667,8.58049 v 0 l -95.19,-169.30622 v 0 0 l -44.2175,-2.75208 v 0 l 1.9939,-18.56317 31.584,1.9656 c -91.0217,-150.25746 -222.4184,-249.74105 -339.9897,-366.61111 l 33.2464,-1.66844 v 0 l 33.3433,34.64483 v 0 c -87.3435,-107.03536 -156.5494,-220.39644 -185.2023,-347.90084 5.407,-25.6798 28.4059,-33.5554 42.8852,-9.3477 z\"\n             id=\"path2853-1-2\"\n             sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n             inkscape:connector-curvature=\"0\" /\u003e\n          \u003cpath\n             style=\"display:inline;fill:#990000;fill-opacity:1;fill-rule:evenodd;stroke:#800000;stroke-width:3.1754px;stroke-linecap:butt;stroke-linejoin:miter;stroke-opacity:1\"\n             d=\"m -3964.5819,579.94648 c 232.1778,142.02444 696.5351,140.75989 988.106,18.70266 205.9526,-66.5673 362.6995,-264.70185 549.2022,-354.76022 167.1463,-88.31108 333.1245,-154.57977 482.3054,-180.583195 v 0 c 120.2135,-20.415854 245.1813,-3.15744 357.0123,83.134705 28.9606,55.52615 34.6919,124.56859 41.9136,192.36665 -44.1007,108.51739 -101.6932,171.65364 -159.3434,227.23914 v 0 c -231.9712,183.0827 -374.5522,215.03066 -548.9965,231.13768 -211.2129,-3.89591 -347.056,-20.86741 -523.2284,31.10727 -207.3545,53.63654 -283.8394,231.78243 -443.7115,319.72853 -13.3008,8.9568 -44.3697,-32.1019 -7.0087,-56.5744 56.3312,-36.899 120.0937,-128.17265 120.0937,-128.17265 l -91.9262,24.90186 v 0 l 20.0462,-31.87375 v 0 l 99.1198,-31.39936 v 0 l 131.7153,-126.31933 v 0 l -191.8305,-45.89202 v 0 0 l -32.7044,30.45368 v 0 l -12.4139,-14.12077 23.3603,-21.75279 c -174.7833,-35.94516 -339.8259,-7.73356 -508.2045,-1.49116 l 21.8121,-25.44723 v 0 l 48.8674,-0.74684 v 0 c -140.1103,-9.1506 -272.3455,-35.87817 -386.9742,-101.90494 -15.3362,-21.4712 -5.2426,-43.65993 22.7879,-37.73352 z\"\n             id=\"path2853-1-8-2\"\n             sodipodi:nodetypes=\"ccccccccccccsccccccccccccccccccccccc\"\n             inkscape:connector-curvature=\"0\" /\u003e\n        \u003c/g\u003e\n      \u003c/g\u003e\n    \u003c/g\u003e\n  \u003c/g\u003e\n\u003c/svg\u003e\n\n    \u003c/a\u003e\n    \u003cfigcaption aria-hidden=\"true\" class=\"hidden\" hidden\u003eMy Logo\u003c/figcaption\u003e\n\u003c/figure\u003e\n\n\u003c/p\u003e\n\u003chr\u003e\n\u003ch3 id=\"kbd\"\u003ekbd\u003c/h3\u003e\n\u003cp\u003eThis shorcode manage HTML item \u003ccode\u003ekbd\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"kbd.html\" title=\"\"\u003ekbd\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode is:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $k := .Get 0 | safeHTML }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ekbd\u003c/span\u003e\u0026gt;{{ $k }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ekbd\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; kbd key \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ekey\u003c/code\u003e: the key name into the keyboard!\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample : this is for the  \u003ckbd\u003es\u003c/kbd\u003e\n key!\u003c/p\u003e\n\u003ch3 id=\"inside-link\"\u003eInside link\u003c/h3\u003e\n\u003cp\u003eThis shortcode, now, had two versions. I started with\n\u003ca href=\"/en/web/hugo/hugo-shortcodes/#inside-v1\" title=\"Go to the anchor: inside-v1\"\u003ethe first\u003c/a\u003e\n, and one day, I wonder how add\nanchor too; \u003ca href=\"/en/web/hugo/hugo-shortcodes/#inside-v2\" title=\"Go to the anchor: inside-v2\"\u003ethe v2\u003c/a\u003e\n was born!\u003c/p\u003e\n\u003ch4 id=\"inside-v1\"\u003eInside v1\u003c/h4\u003e\n\u003cp\u003eTo manage inside link between pages of this site, I wrote this shortcode:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"inside.html\" title=\"\"\u003einside\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e1\u003c/span\u003e\u003cspan\u003e{{ $link := .Get 0 }}{{ $link := replace $link \u0026#34;:\u0026#34; \u0026#34;/\u0026#34; }}{{ $url := (print ( relLangURL $link ) \u0026#34;/\u0026#34;) }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e2\u003c/span\u003e\u003cspan\u003e{{ if .Get 1 }}{{ $txt := .Get 1 }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e3\u003c/span\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;inside\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elnkInsideTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ewith\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eSite\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eGetPage\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elink\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eTitle\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;{{ $txt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e4\u003c/span\u003e\u003cspan\u003e{{ else }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e5\u003c/span\u003e\u003cspan\u003e{{ with .Site.GetPage $link }}{{ $title := .Title }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;inside\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elnkInsideTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;{{ $title }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e6\u003c/span\u003e\u003cspan\u003e{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eAnd, I created into my CSS, a named \u003ccode\u003einside\u003c/code\u003e definition.\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; inside \u0026#34;section:subsection:pagename\u0026#34; \u0026#34;Title\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003esections and pages names are separated by the symbol \u003ccode\u003e:\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ethe title can be avoid. In this case, it will display the title of called page.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExamples:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIn this exemple, I call the page \n\n\u003ca class=\"inside\" href=\"/en/web/hugo/hugo-deploy/\" title=\"Internal link to the article: 'Hugo: Deploy SFTP'\"\u003eHugo: Deploy SFTP\u003c/a\u003e\n\n; this is its title that is displayed.\u003c/li\u003e\n\u003cli\u003eWith this other example, I override the title when I call the same page \n\u003ca class=\"inside\" href=\"/en/web/hugo/hugo-deploy/\" title=\"Internal link to the article: 'Hugo: Deploy SFTP'\"\u003eStatic deploy with Hugo\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"inside-v2\"\u003eInside v2\u003c/h4\u003e\n\u003cp\u003eThis version is subtle different:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"inside2.html\" title=\"\"\u003einside2\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e1\u003c/span\u003e\u003cspan\u003e{{ $link := .Get \u0026#34;l\u0026#34; }}{{ $link := replace $link \u0026#34;:\u0026#34; \u0026#34;/\u0026#34; }}{{ $url := (print ( relLangURL $link ) \u0026#34;/\u0026#34;) }}{{ $anchor := .Get \u0026#34;a\u0026#34; }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e2\u003c/span\u003e\u003cspan\u003e{{ if .Get \u0026#34;t\u0026#34; }}{{ $txt := .Get \u0026#34;t\u0026#34; }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;inside\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}{{ if $anchor }}#{{ $anchor }}{{ end }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elnkInsideTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#39;{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ewith\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eSite\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eGetPage\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elink\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e.\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eTitle\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#39;\u0026#34;\u003c/span\u003e\u0026gt;{{ $txt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e3\u003c/span\u003e\u003cspan\u003e{{ else }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e4\u003c/span\u003e\u003cspan\u003e{{ with .Site.GetPage $link }}{{ $title := .Title }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;inside\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $url }}{{ if $anchor }}#{{ $anchor }}{{ end }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003elnkInsideTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#39;{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#39;\u0026#34;\u003c/span\u003e\u0026gt;{{ $title }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan style=\"white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\"\u003e5\u003c/span\u003e\u003cspan\u003e{{ end }}\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; inside2 l=\u0026#34;section:subsection:pagename\u0026#34; t=\u0026#34;title\u0026#34; a=\u0026#34;anchor-name\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cp\u003eThe named parameters are:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ea\u003c/code\u003e: target an anchor into called page. \u003cem\u003ethis anchor need to exists into the page\u003c/em\u003e. May be omitted!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003el\u003c/code\u003e: name of internal link; sections and pages names are separated by the symbol \u003ccode\u003e:\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003et\u003c/code\u003e: the title. May be omitted. In this case, it will display tye title of the called page.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003eExample:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eHere, I call the page \u003ca class=\"inside\" href=\"/en/web/hugo/hugo-deploy/#rsync\" title=\"Internal link to the article: 'Hugo: Deploy SFTP'\"\u003eHugo: Deploy SFTP\u003c/a\u003e. Her title is displayed, but it links to the section named \u003cstrong\u003ersync\u003c/strong\u003e, targeted anchor.\u003c/li\u003e\n\u003cli\u003eAnd this example, I override the title as \u003ca class=\"inside\" href=\"/en/web/hugo/hugo-deploy/\" title=\"Internal link to the article: 'Hugo: Deploy SFTP'\"\u003eStatic deploy with Hugo\u003c/a\u003e\n but I not wrote anchor param.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"note\"\u003eNote\u003c/h3\u003e\n\u003cp\u003eThe blocs of alert or note are HTML blocs to display a text, with an identifiant, translated segun the used lang.\u003c/p\u003e\n\u003cp\u003eThe possible values of this identifiant may be:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003edanger\u003c/code\u003e: to display an alert \u0026lsquo;danger\u0026rsquo;, with a red background.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003einfo\u003c/code\u003e: to display an informational note, with a blue background.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esuccess\u003c/code\u003e: to display a success message, with a green background.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etip\u003c/code\u003e: to display a tip note, with a yellow background.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ewarning\u003c/code\u003e: to display a warning message/alert, with an amber background.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd, all thoses background colors \u003ccode\u003ealert-$id\u003c/code\u003e are written on CSS file.\u003c/p\u003e\n\u003cp\u003eThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"note.html\" title=\"\"\u003enote\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $class := .Get 0 }}{{ $wrd := T (printf \u0026#34;alert-%s\u0026#34; $class) }}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;info-tab {{ $class }}-icon\u0026#34;\u003c/span\u003e\u0026gt;{{ $wrd }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;alert alert-{{ $class }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003erole\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;alert\u0026#34;\u003c/span\u003e\u0026gt;{{ .Inner | .Page.RenderString }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ediv\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eThe shortcode is:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; note id \u0026gt;}}\nThis is your message\n{{\u0026lt; /note \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eExamples:\u003c/p\u003e\n\u003cp\u003e\n\u003cdiv class=\"tab-info i-danger\"\u003eDanger\u003c/div\u003e\u003cdiv class=\"alert alert-danger\" role=\"alert\"\u003e\u003cstrong\u003eATTENTION\u003c/strong\u003e: this message display a risk or danger for you!\u003c/div\u003e\n\n\u003cem\u003eThis example includes MD code to strong the word \u0026lsquo;ATTENTION\u0026rsquo;.\u003c/em\u003e\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eA little \u003cstrong\u003einformation\u003c/strong\u003e. Keep this in your mind! :D\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-success\"\u003eSuccess\u003c/div\u003e\u003cdiv class=\"alert alert-success\" role=\"alert\"\u003eYou succeeded the test! Be happy.\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eThis is a tip. Yeah, man, interesting!\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003ePlease, be careful at the message: it seems a malfunction exists. See more attentive!\u003c/div\u003e\n\n\u003ch3 id=\"tag\"\u003eTag\u003c/h3\u003e\n\u003cp\u003eThis shortcode not exists to manage Hugo tags, but to manage tag into MD file.\u003c/p\u003e\n\u003cp\u003eInto CSS, I defined attribute \u003ccode\u003e.tag::after\u003c/code\u003e to display \u003ccode\u003e(tag)\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"tag.html\" title=\"\"\u003etag\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $txt := .Get 0 }}{{ $href := \u0026#34;/\u0026#34; | relLangURL}}{{ $href := (printf \u0026#34;%s%s%s\u0026#34; $href \u0026#34;/tags/\u0026#34; $txt) | urlize }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;tag\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $href }}\u0026#34;\u003c/span\u003e\u0026gt;{{ $txt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eCall the shortcode as:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; tag tag-name \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eExample: \u003cbr\u003e\nThis word \u003ca class=\"tag\" href=\"/en/tags/hugo\"\u003eHugo\u003c/a\u003e\n is a link to the tag page with \u0026ldquo;Hugo\u0026rdquo; name.\u003c/p\u003e\n\u003ch2 id=\"others-shortcodes\"\u003eOthers shortcodes\u003c/h2\u003e\n\u003ch3 id=\"gohugo\"\u003eGoHugo\u003c/h3\u003e\n\u003cp\u003eJust to link to official documentation Hugo, I wrote this shortcode:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; gohugo n=\u0026#34;pagename\u0026#34; s=\u0026#34;section\u0026#34; a=\u0026#34;anchor-name\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"gohugo.html\" title=\"\"\u003egohugo\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $section := .Get \u0026#34;s\u0026#34; }}{{ $name := .Get \u0026#34;n\u0026#34; }}{{ $anchor := .Get \u0026#34;a\u0026#34; }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;https://gohugo.io/{{ $section }}/{{ $name }}/{{ if $anchor }}#{{ $anchor}}{{ end }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003eshortcodeGoHugoTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehumanize\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003esection\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e\u0026amp;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003egt\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehumanize\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003ename\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;{{ i18n \u0026#34;shortcodeGoHugoDocTitle\u0026#34; }}{{ humanize $section }} \u0026amp;gt; {{ humanize $name }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eExample: Link to \u003ca href=\"https://gohugo.io/content-management/shortcodes/\" title=\"Link to the official site Hugo: Content management \u0026gt; Shortcodes\"\u003eHugo Documentation: Content management \u0026gt; Shortcodes\u003c/a\u003e\n\nHugo page with:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; gohugo n=\u0026#34;shortcodes\u0026#34; s=\u0026#34;content-management\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003ch3 id=\"manpage\"\u003eManpage\u003c/h3\u003e\n\u003cp\u003eAs I use many times links to official manpage OpenBSD, I wrote this shortcode:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; man title digit \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIf a \u003ccode\u003edigit\u003c/code\u003e is written, the shortcode build the URL as \u003ccode\u003etitle.digit\u003c/code\u003e\nand the text as \u003ccode\u003etxt(digit)\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"man.html\" title=\"\"\u003eman\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $txt := .Get 0 }}{{ $nb := .Get 1}}\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eclass\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;man\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;https://man.openbsd.org/{{ $txt }}{{ if $nb }}{{ print \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e.\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003enb\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003eend\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ i18n \u0026#34;\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003emanpageTitle\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}{{\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e\u003cspan style=\"color:#06b6ef\"\u003etxt\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e}}\u0026#34;\u003c/span\u003e\u0026gt;{{ $txt }}{{ if $nb }}{{ print \u0026#34;(\u0026#34; $nb \u0026#34;)\u0026#34; }}{{ end }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eExamples:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eLink to the manpage \u003cstrong\u003ePacket Filter\u003c/strong\u003e: \n\u003ca class=\"man\" href=\"https://man.openbsd.org/pf.4\" title=\"OpenBSD Manual Page Server for: pf\"\u003epf(4)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eOther link: \n\u003ca class=\"man\" href=\"https://man.openbsd.org/httpd.8\" title=\"OpenBSD Manual Page Server for: httpd\"\u003ehttpd(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAnd, the last but not the least: \n\u003ca class=\"man\" href=\"https://man.openbsd.org/man\" title=\"OpenBSD Manual Page Server for: man\"\u003eman\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"wikipedia\"\u003eWikipedia\u003c/h3\u003e\n\u003cp\u003eEgual, for the Wikipedia, the shortcode is:\n\u003cdiv class=\"info-code\"\u003e\n    \u003cp\u003eCode:\u0026nbsp;\u003cem\u003eshortcode\u003c/em\u003e\u003c/p\u003e\n\u003c/div\u003e\n\u003cdiv class=\"code\"\u003e\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-shortcode\" data-lang=\"shortcode\"\u003e\n{{\u0026lt; wp \u0026#34;url-article\u0026#34; \u0026gt;}}\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cdiv class=\"is-right\"\u003e\n    \u003cp class=\"is-italic is-white-50\"\u003eRAW source of the shortcode: \u003ca class=\"raw-src\" href=\"wp.html\" title=\"\"\u003ewp\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\nThe shortcode:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-html\" data-lang=\"html\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e{{ $txt := .Get 0 }}{{ $title := print (i18n \u0026#34;wpTitleArticle\u0026#34;) $txt }}\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003ehref\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;https://{{ .Site.Language.Lang }}.wikipedia.org/wiki/{{ $txt }}\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#06b6ef\"\u003etitle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{{ $title }}\u0026#34;\u003c/span\u003e\u0026gt;Wikipedia :: {{ $txt }}\u0026lt;/\u003cspan style=\"color:#5bc4bf\"\u003ea\u003c/span\u003e\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003eExamples:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThis is an article to promote OpenBSD: \u003ca href=\"https://en.wikipedia.org/wiki/OpenBSD\" title=\"Wikipedia Article: OpenBSD\"\u003e\n    OpenBSD\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eThis other is for Debian: \u003ca href=\"https://en.wikipedia.org/wiki/Debian\" title=\"Wikipedia Article: Debian\"\u003e\n    Debian\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eAnd, a third more complex: \u003ca href=\"https://en.wikipedia.org/wiki/Firewall_%28computing%29\" title=\"Wikipedia Article: Firewall_(computing)\"\u003e\n    Firewall_(computing)\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"somewhere\"\u003eSomewhere\u003c/h2\u003e\n\u003cp\u003eFinally, do not hesitate to have fun with the shortcodes; get help on \u003ca href=\"https://discourse.gohugo.io/\" rel=\"external\"\u003ethe commmunity forum\u003c/a\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://after-dark.habd.as/shortcode/\" rel=\"external\"\u003ehttps://after-dark.habd.as/shortcode/\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"My different Hugo shortcodes's presentation","tags":["Hugo","Shortcode"],"date_published":"2019-11-29T15:29:59+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-11-29:/en/web/hugo/hugo-deploy","url":"https://it-log.fr.eu.org/en/web/hugo/hugo-deploy/","title":"Hugo: Deploy SFTP","author":{"name":"Stéphane HUC"},"content_text":"Description To deploy a static website, made with Hugo, some solutions exist:\nthe easy is with the tool rsync. automated deployment solutions. I review a third for users SSH, under chroot contraints. Into the simple context deployment, you need to create a file named deploy at the root of your Hugo project.\nUtilisation rsync To deploy a site with rsync is really simple. rsync is the tool to synchronize datas; it\u0026rsquo;s just do it!\nInstall the tool:\non Debian/*Buntu : :# apt install rsync on OpenBSD : :# pkg_add rsync - FYI (for your information) , since OpenBSD 6.5, it exists the tool openrsync; it\u0026rsquo;s subject to the same problem described below! I presume you had an authentification SSH, with key is better.\n#!/bin/sh user=userid host=servername port=22 dir_dist=/remote_folder/ file_id=\u0026#34;$HOME/.ssh/id_ed25519\u0026#34; hugo \u0026amp;\u0026amp; rsync -avz --delete -e \u0026#34;ssh -i ${file_id} -p ${port}\u0026#34; public/ \u0026#34;${user}\u0026#34;@\u0026#34;${host}\u0026#34;:\u0026#34;${dir_dist}\u0026#34; This example show the deployment with rsync using a SSH connection.\nInfoExecuting the command hugo regenerate all page. This results rsync download again all page, and not only the modified. WarningThe problem: if the SSH user is under contraint chroot SSH, he can only connect by\nSFTP (SSH File Transfer Protocol)\n; he cant use rsync because the tool cant communicate on this protocol.\nTo bypass this problem, you need to use :\nsshfs solution, before using rsync, or the thin lftp, or the powerfull rclone. SshFS SshFS can be install with the package manager:\non Debian/*Buntu : :# apt install sshfs on OpenBSD : :# pkg_add sshfs InfoUnder OpenBSD, you need to run SshFS with rights admins; use doas .\nTo mount the filesystem: :$ doas sshfs -C -p $port -o allow_other -o uid=$(id -u $USER) -o gid=$(id -g $USER) ${id}@${host}:${dir_dist} \u0026quot;${dir_mount}\u0026quot;\nOnce the connection is established, the remote folder is mounted locally where you desired.\nNow, it\u0026rsquo;s time to use rsync as: :$ cd \u0026quot;${dir_local}\u0026quot; \u0026amp;\u0026amp; rsync -av --delete --human-readable --progress --stats \u0026quot;.\u0026quot; \u0026quot;${dir_mount}\u0026quot;\nTo unmount correctly: :$ doas umount \u0026quot;${dir_mount}\u0026quot;\nWith this in mind, see the file deploy under this SshFS+rsync context:\n#!/bin/sh #set -x [ -n \u0026#34;$TERM\u0026#34; ] \u0026amp;\u0026amp; clear ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; id=userid host=servername port=22 ### the directory where your web site files should go ## dir_dist: relative to chroot SSH dir_dist=\u0026#34;/www/\u0026#34; dir_local=\u0026#34;$ROOT/public/\u0026#34; dir_mount=\u0026#34;$HOME/servers/${id}/\u0026#34; file_id=\u0026#34;$HOME/.ssh/id_ed25519\u0026#34; rsync_opts=\u0026#34;--human-readable --progress --stats \u0026#34; ################################################################################ ### ## # Fonctions ## ### ################################################################################ _mount() { [ ! -d \u0026#34;${dir_mount}\u0026#34; ] \u0026amp;\u0026amp; mkdir -p \u0026#34;${dir_mount}\u0026#34; # for Debian [ -d \u0026#34;${dir_mount}\u0026#34; ] \u0026amp;\u0026amp; sshfs -C -p $port -o uid=$(id -u $USER) -o gid=$(id -g $USER) -o IdentityFile=\u0026#34;${file_id}\u0026#34; ${id}@${host}:${dir_dist} \u0026#34;${dir_mount}\u0026#34; # for OpenBSD [ -d \u0026#34;${dir_mount}\u0026#34; ] \u0026amp;\u0026amp; doas sshfs -C -p \u0026#34;${port}\u0026#34; -o allow_other -o uid=$(id -u $USER) -o gid=$(id -g $USER) -o IdentityFile=\u0026#34;${file_id}\u0026#34; \u0026#34;${id}\u0026#34;@\u0026#34;${host}\u0026#34;:\u0026#34;${dir_dist}\u0026#34; \u0026#34;${dir_mount}\u0026#34; } _rsync() { cd \u0026#34;${dir_local}\u0026#34; || exit rsync -av --delete $rsync_opts \u0026#34;.\u0026#34; \u0026#34;${dir_mount}\u0026#34; } _umount() { fusermount -u \u0026#34;${dir_mount}\u0026#34; # for Debian doas umount \u0026#34;${dir_mount}\u0026#34; # for OpenBSD } ################################################################################ ### ## # Execution ## ### ################################################################################ hugo status=\u0026#34;$?\u0026#34; if [ \u0026#34;${status}\u0026#34; -eq 0 ]; then if _mount; then _rsync _umount fi fi WarningBe carefull: DO NOT USE directly this script without comment lines, segun your OS! lftp lftp is a \u0026ldquo;Swiss Army knife\u0026rdquo; for the network connection. It run FTP(S), HTTP(S) protocols, on IPv4, IPv6; and too, bittorent and partial WebDAV. It can be mirroring documents and folders. And: SFTP!\nYes, you can mirror datas on SFTP!\nTo install by the package manager:\non Debian/*Buntu : :# apt install lftp on OpenBSD : :# pkg_add lftp See, this instance deployment:\n#!/bin/sh #set -x [ -n \u0026#34;$TERM\u0026#34; ] \u0026amp;\u0026amp; clear ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; id=userid host=servername port=22 ### the directory where your web site files should go ## dir_dist: relative to chroot SSH dir_dist=\u0026#34;/www/\u0026#34; dir_local=\u0026#34;$ROOT/public/\u0026#34; file_id=\u0026#34;$HOME/.ssh/id_ed25519\u0026#34; hugo lftp -e \u0026#34;set ftp:ssl-allow no; set sftp:connect-program ssh -a -x -i ${file_id}; mirror -e -R ${dir_local} ${dir_dist}; quit;\u0026#34; -p \u0026#34;${port}\u0026#34; sftp://\u0026#34;${id}\u0026#34;:\u0026#34;${passwd}\u0026#34;@\u0026#34;${host}\u0026#34; rclone rclone is a very powerfull CLI tool to duplicate on stockage solution, as Cloud, differents filesystems, but too with SFTP.\nInstall by the package manager:\non Debian/*Buntu: # apt install rclone on OpenBSD: # pkg_add rclone In first, you need to configure by using the option config: $ rclone config\nName your remote access, as you wish. This will be use as remote name connexion. Choose absolutly SFTP connexion, to write sftp when the invite asks. See the documentation Rclone:SFTP!\nFile config: ~/.config/rclone/rclone.conf, by default.\nHere this instance configuration:\n[nom_remote] type = sftp host = adresse_ip ou FQDN user = id_ssh port = 22 key_file = ~/.ssh/id_ed25519 key_use_agent = true pubkey_file = ~/.ssh/id_ed25519.pub use_insecure_cipher = false md5sum_command = none sha1sum_command = none And here, this instance deployment:\n#!/bin/sh #set -x [ -n \u0026#34;$TERM\u0026#34; ] \u0026amp;\u0026amp; clear ROOT=\u0026#34;$(dirname \u0026#34;$(readlink -f -- \u0026#34;$0\u0026#34;)\u0026#34;)\u0026#34; id=userid host=servername port=22 ### the directory where your web site files should go ## dir_dist: relative to chroot SSH dir_dist=\u0026#34;/www/\u0026#34; dir_local=\u0026#34;$ROOT/public/\u0026#34; file_id=\u0026#34;$HOME/.ssh/id_ed25519\u0026#34; rclone_remote=\u0026#34;nom_remote\u0026#34; hugo rclone sync -i \u0026#34;${dir_local}\u0026#34; \u0026#34;${rclone_remote}\u0026#34;:\u0026#34;${dir_dist}\u0026#34; FIN Voila: This is the end!\nNow, you known how to deploy your static website Hugo, with rsync/ssh, sshfs+rsync, lftp, or even by rclone.\nDocumentation Hugo Documentation: Hosting and deployment \u0026gt; Deployment with rsync Hugo Documentation: Hosting and deployment \u0026gt; the lftp website. the rclone, and rclone:sftp documentation page. ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eTo deploy a static website, made with Hugo, some solutions exist:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe easy is with the tool \u003ca href=\"/en/web/hugo/hugo-deploy/#rsync\"\u003ersync\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eautomated deployment solutions.\u003c/li\u003e\n\u003cli\u003eI review a third for users SSH, under chroot contraints.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eInto the simple context deployment, you need to create a file named \u003ccode\u003edeploy\u003c/code\u003e\nat the root of your Hugo project.\u003c/p\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\u003ch3 id=\"rsync\"\u003ersync\u003c/h3\u003e\n\u003cp\u003eTo deploy a site with \u003ccode\u003ersync\u003c/code\u003e is really simple. \u003cstrong\u003ersync\u003c/strong\u003e is the tool to\nsynchronize datas; it\u0026rsquo;s just do it!\u003c/p\u003e\n\u003cp\u003eInstall the tool:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eon Debian/*Buntu : \u003ccode\u003e:# apt install rsync\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eon OpenBSD : \u003ccode\u003e:# pkg_add rsync\u003c/code\u003e - \n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eFYI \u003cem\u003e(for your information)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n, since OpenBSD 6.5, it\nexists the tool \u003ccode\u003eopenrsync\u003c/code\u003e;\n\u003cem\u003eit\u0026rsquo;s subject to the same problem described below!\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eI presume you had an authentification SSH, \u003cem\u003ewith key is better\u003c/em\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003euser\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003euserid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eservername\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e/remote_folder/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.ssh/id_ed25519\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehugo \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e rsync -avz --delete -e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ssh -i \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e -p \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e public/ \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003euser\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e@\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThis example show the deployment with rsync using a SSH connection.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eExecuting the command \u003ccode\u003ehugo\u003c/code\u003e regenerate all page. This results \u003ccode\u003ersync\u003c/code\u003e\ndownload again all page, and not only the modified.\u003c/div\u003e\n\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eThe problem: if the SSH user is under contraint chroot SSH, he can only\nconnect by\u003c/p\u003e\n\u003cp\u003e\u003cspan lang=\"en\"\u003eSFTP \u003cem\u003e(SSH File Transfer Protocol)\u003c/em\u003e\u003c/span\u003e\u003c/p\u003e\n\u003cp\u003e; he cant use \u003cstrong\u003ersync\u003c/strong\u003e because the tool cant\ncommunicate on this protocol.\u003c/p\u003e\n\u003cp\u003eTo bypass this problem, you need to use :\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"/en/web/hugo/hugo-deploy/#sshfs\"\u003esshfs\u003c/a\u003e solution, before using \u003ccode\u003ersync\u003c/code\u003e, or\u003c/li\u003e\n\u003cli\u003ethe thin \u003ca href=\"/en/web/hugo/hugo-deploy/#lftp\"\u003elftp\u003c/a\u003e,\u003c/li\u003e\n\u003cli\u003eor the powerfull \u003ca href=\"/en/web/hugo/hugo-deploy/#rclone\"\u003erclone\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"sshfs\"\u003eSshFS\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003eSshFS\u003c/strong\u003e can be install with the package manager:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eon Debian/*Buntu : \u003ccode\u003e:# apt install sshfs\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eon OpenBSD : \u003ccode\u003e:# pkg_add sshfs\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003eUnder OpenBSD, you need to run SshFS with rights admins; use\n\u003ca class=\"man\" href=\"https://man.openbsd.org/doas\" title=\"OpenBSD Manual Page Server for: doas\"\u003edoas\u003c/a\u003e\n.\u003c/p\u003e\n\u003cp\u003eTo mount the filesystem: \u003cbr\u003e\n\u003ccode\u003e:$ doas sshfs -C -p $port -o allow_other -o uid=$(id -u $USER) -o gid=$(id -g $USER) ${id}@${host}:${dir_dist} \u0026quot;${dir_mount}\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eOnce the connection is established, the remote folder is mounted locally\nwhere you desired.\u003c/p\u003e\n\u003cp\u003eNow, it\u0026rsquo;s time to use \u003ccode\u003ersync\u003c/code\u003e as: \u003cbr\u003e\n\u003ccode\u003e:$ cd \u0026quot;${dir_local}\u0026quot; \u0026amp;\u0026amp; rsync -av --delete --human-readable --progress --stats  \u0026quot;.\u0026quot; \u0026quot;${dir_mount}\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eTo unmount correctly: \u003cbr\u003e\n\u003ccode\u003e:$ doas umount \u0026quot;${dir_mount}\u0026quot;\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eWith this in mind, see the file \u003ccode\u003edeploy\u003c/code\u003e under this SshFS+rsync context:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#set -x\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -n \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$TERM\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e clear\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003euserid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eservername\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### the directory where your web site files should go\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## dir_dist: relative to chroot SSH\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/www/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ROOT\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/public/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/servers/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.ssh/id_ed25519\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ersync_opts\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;--human-readable --progress --stats \u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   Fonctions\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_mount\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e ! -d \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e mkdir -p \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# for Debian\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -d \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e sshfs -C -p \u003cspan style=\"color:#ef6155\"\u003e$port\u003c/span\u003e -o \u003cspan style=\"color:#ef6155\"\u003euid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -u \u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e -o \u003cspan style=\"color:#ef6155\"\u003egid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -g \u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e -o \u003cspan style=\"color:#ef6155\"\u003eIdentityFile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e@\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e:\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# for OpenBSD\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -d \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e doas sshfs -C -p \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -o allow_other -o \u003cspan style=\"color:#ef6155\"\u003euid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -u \u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e -o \u003cspan style=\"color:#ef6155\"\u003egid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003eid -g \u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e -o \u003cspan style=\"color:#ef6155\"\u003eIdentityFile\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e@\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_rsync\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cd \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e||\u003c/span\u003e exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    rsync -av --delete \u003cspan style=\"color:#ef6155\"\u003e$rsync_opts\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;.\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e_umount\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    fusermount -u \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e    \u003cspan style=\"color:#776e71\"\u003e# for Debian\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    doas umount \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_mount\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# for OpenBSD\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   Execution\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e###\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e################################################################################\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehugo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003estatus\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$?\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003estatus\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e -eq \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e _mount; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        _rsync\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        _umount\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eBe carefull: DO NOT USE directly this script without comment lines, segun\nyour OS!\u003c/div\u003e\n\n\u003ch3 id=\"lftp\"\u003elftp\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003elftp\u003c/strong\u003e is a \u0026ldquo;Swiss Army knife\u0026rdquo; for the network connection. It run FTP(S),\nHTTP(S) protocols, on IPv4, IPv6; and too, bittorent and partial WebDAV.\nIt can be mirroring documents and folders. And: SFTP!\u003c/p\u003e\n\u003cp\u003eYes, you can mirror datas on SFTP!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eTo install by the package manager:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eon Debian/*Buntu : \u003ccode\u003e:# apt install lftp\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eon OpenBSD : \u003ccode\u003e:# pkg_add lftp\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSee, this instance deployment:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#set -x\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -n \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$TERM\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e clear\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003euserid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eservername\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### the directory where your web site files should go\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## dir_dist: relative to chroot SSH\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/www/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ROOT\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/public/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.ssh/id_ed25519\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehugo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003elftp -e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;set ftp:ssl-allow no; set sftp:connect-program ssh -a -x -i \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e; mirror -e -R \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e; quit;\u0026#34;\u003c/span\u003e -p \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e sftp://\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003epasswd\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e@\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"rclone\"\u003erclone\u003c/h3\u003e\n\u003cp\u003e\u003cstrong\u003erclone\u003c/strong\u003e is a very powerfull CLI tool to duplicate on stockage solution,\nas Cloud, differents filesystems, but too with SFTP.\u003c/p\u003e\n\u003cp\u003eInstall by the package manager:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eon Debian/*Buntu: \u003ccode\u003e# apt install rclone\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eon OpenBSD: \u003ccode\u003e# pkg_add rclone\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIn first, you need to configure by using the option \u003ccode\u003econfig\u003c/code\u003e: \u003ccode\u003e$ rclone config\u003c/code\u003e\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eName your \u003cstrong\u003eremote\u003c/strong\u003e access, as you wish. This will be use as remote\nname connexion.\u003c/li\u003e\n\u003cli\u003eChoose absolutly SFTP connexion, to write \u003ccode\u003esftp\u003c/code\u003e when the invite asks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003e\u003cem\u003eSee the \u003ca href=\"/en/web/hugo/hugo-deploy/#documentation\"\u003edocumentation\u003c/a\u003e Rclone:SFTP!\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eFile config: \u003ccode\u003e~/.config/rclone/rclone.conf\u003c/code\u003e\u003cem\u003e, by default.\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eHere this instance configuration:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-conf\" data-lang=\"conf\"\u003e[nom_remote]\ntype = sftp\nhost = adresse_ip ou FQDN\nuser = id_ssh\nport = 22\nkey_file = ~/.ssh/id_ed25519\nkey_use_agent = true\npubkey_file = ~/.ssh/id_ed25519.pub\nuse_insecure_cipher = false\nmd5sum_command = none\nsha1sum_command = none\n\u003c/code\u003e\u003c/pre\u003e\u003cp\u003eAnd here, this instance deployment:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/sh\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#set -x\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e -n \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$TERM\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e clear\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eROOT\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edirname \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003ereadlink -f -- \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$0\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eid\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003euserid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ehost\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eservername\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eport\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### the directory where your web site files should go\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## dir_dist: relative to chroot SSH\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;/www/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ROOT\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/public/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003efile_id\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.ssh/id_ed25519\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003erclone_remote\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;nom_remote\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehugo\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003erclone sync -i \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_local\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003erclone_remote\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edir_dist\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"fin\"\u003eFIN\u003c/h2\u003e\n\u003cp\u003eVoila: This is the end!\u003c/p\u003e\n\u003cp\u003eNow, you known how to deploy your static website Hugo, with \u003ccode\u003ersync/ssh\u003c/code\u003e,\n\u003ccode\u003esshfs+rsync\u003c/code\u003e, \u003ccode\u003elftp\u003c/code\u003e, or even by \u003ccode\u003erclone\u003c/code\u003e.\u003c/p\u003e\n\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/hosting-and-deployment/deployment-with-rsync/\" title=\"Link to the official site Hugo: Hosting and deployment \u0026gt; Deployment with rsync\"\u003eHugo Documentation: Hosting and deployment \u0026gt; Deployment with rsync\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://gohugo.io/hosting-and-deployment//\" title=\"Link to the official site Hugo: Hosting and deployment \u0026gt; \"\u003eHugo Documentation: Hosting and deployment \u0026gt; \u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://lftp.yar.ru/\" rel=\"external\"\u003elftp\u003c/a\u003e website.\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://rclone.org/\" rel=\"external\"\u003erclone\u003c/a\u003e, and \u003ca href=\"https://rclone.org/sftp/\" rel=\"external\"\u003erclone:sftp\u003c/a\u003e documentation page.\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Deploy a site, made with the generator Hugo, by rsync/ssh, SFTP+rsync, lftp client, or the powerfull rclone.","tags":["Hugo","deploy","chroot","lftp","rclone","rsync","SSH","SFTP"],"date_published":"2019-11-29T14:45:12+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-11-23:/en/web/nextcloud/occ","url":"https://it-log.fr.eu.org/en/web/nextcloud/occ/","title":"Nextcloud : manpage occ","author":{"name":"Stéphane HUC"},"content_text":"occ Usage: command [options] [arguments]\nOptions:\n-h, --help Display this help message -q, --quiet Do not output any message -V, --version Display this application version --ansi Force ANSI output --no-ansi Disable ANSI output -n, --no-interaction Do not ask any interactive question --no-warnings Skip global warnings, show command output only -v|vv|vvv, --verbose Increase the verbosity of messages: 1 for normal output, 2 for more verbose output and 3 for debug Available commands:\ncheck check dependencies of the server environment help displays help for a command list Lists commands status show some status information upgrade run upgrade routines after installation of a new release. The release has to be installed before. Manage configuration config\nconfig:app:delete Delete an app config value config:app:get Get an app config value config:app:set Set an app config value config:import Import a list of configs config:list List all configs config:system:delete Delete a system config value config:system:get Get a system config value config:system:set Set a system config value Manage Database db\ndb:add-missing-indices Add missing indices to the database tables db:convert-filecache-bigint Convert the ID columns of the filecache to BigInt db:convert-mysql-charset Convert charset of MySQL/MariaDB to use utf8mb4 db:convert-type Convert the Nextcloud database to the newly configured one Encryption Management encryption\nencryption:change-key-storage-root Change key storage root encryption:decrypt-all Disable server-side encryption and decrypt all files encryption:disable Disable encryption encryption:enable Enable encryption encryption:encrypt-all Encrypt all files for all users encryption:list-modules List all available encryption modules encryption:set-default-module Set the encryption default module encryption:show-key-storage-root Show current key storage root encryption:status Lists the current status of encryption Federation Management federation\nfederation:sync-addressbooks Synchronizes addressbooks of all federated clouds Files Management files\nfiles:cleanup cleanup filecache files:recommendations:recommend files:scan rescan filesystem files:scan-app-data rescan the AppData folder files:transfer-ownership All files and folders are moved to another user - shares are moved as well. Groups Management roup\ngroup:add Add a group group:adduser add a user to a group group:delete Remove a group group:list list configured groups group:removeuser remove a user from a group Integrity App, Core integrity\nintegrity:check-app Check integrity of an app using a signature. integrity:check-core Check integrity of core code using a signature. integrity:sign-app Signs an app using a private key. integrity:sign-core Sign core using a private key. Logs Management log\nlog:file manipulate logging backend log:manage manage logging configuration log:tail Tail the nextcloud logfile log:watch Watch the nextcloud logfile NC Background jobs background\nbackground:ajax Use ajax to run background jobs background:cron Use cron to run background jobs background:webcron Use webcron to run background jobs NC Maintenance maintenance\nmaintenance:data-fingerprint update the systems data-fingerprint after a backup is restored maintenance:mimetype:update-db Update database mimetypes and update filecache maintenance:mimetype:update-js Update mimetypelist.js maintenance:mode set maintenance mode maintenance:repair repair this installation maintenance:theme:update Apply custom theme changes maintenance:update:htaccess Updates the .htaccess file NC Migration migrations\nmigrations:execute Execute a single migration version manually. migrations:generate migrations:generate-from-schema migrations:migrate Execute a migration to a specified version or the latest available version. migrations:status View the status of a set of migrations. NC Security security\nsecurity:certificates list trusted certificates security:certificates:import import trusted certificate security:certificates:remove remove trusted certificate NC Update update\nupdate:check Check for server and app updates User management user\nuser:add adds a user user:delete deletes the specified user and all datas user user:disable disables the specified user user:enable enables the specified user user:info show user info user:lastseen shows when the user was logged in last time user:list list configured users user:report shows how many users have access user:resetpassword Resets the password of the named user user:setting Read and modify user settings notification\nnotification:generate Generate a notification for the given user versions\nversions:cleanup Delete versions: delete versions of the given user(s), if no user is given all versions will be deleted versions:expire Expires the users file versions: expire file versions of the given user(s), if no user is given file versions for all users will be expired. Manage applications app\napp:check-code check code to be compliant app:disable disable an app app:enable enable an app app:getpath Get an absolute path to the app directory app:install install an app app:list List all available apps app:remove remove an app app:update update an app or all apps Mail mail\nmail:account:create creates IMAP account mail:account:export Exports a user\u0026rsquo;s IMAP account(s) Circles circles\ncircles:clean remove all extra data from database circles:fixuniqueid fix Unique Id issue. Deck deck\ndeck:export Export a JSON dump of user data Talk talk\ntalk:command:add Add a new command talk:command:add-samples Adds some sample commands: /wiki, … talk:command:delete Remove an existing command talk:command:list List all available commands talk:command:update Add a new command talk:signaling:add Add an external signaling server. talk:signaling:delete Remove an existing signaling server. talk:signaling:list List external signaling servers. talk:stun:add Add a new STUN server. talk:stun:delete Remove an existing STUN server. talk:stun:list List STUN servers. talk:turn:add Add a TURN server. talk:turn:delete Remove an existing TURN server. talk:turn:list List TURN servers. 2FA: Two Factor Auth twofactorauth\ntwofactorauth:cleanup Clean up the two-factor user-provider association of an uninstalled/removed provider twofactorauth:disable Disable two-factor authentication for a user twofactorauth:enable Enable two-factor authentication for a user twofactorauth:enforce Enabled/disable enforced two-factor authentication twofactorauth:state Get the two-factor authentication (2FA) state of a user WebDAV dav\ndav:create-addressbook Create a dav addressbook dav:create-calendar Create a dav calendar dav:list-calendars List all calendars of a user dav:move-calendar Move a calendar from an user to another dav:remove-invalid-shares Remove invalid dav shares dav:send-event-reminders Sends event reminders dav:sync-birthday-calendar Synchronizes the birthday calendar dav:sync-system-addressbook Synchronizes users to the system addressbook ","content_html":"\u003ch2 id=\"occ\"\u003eocc\u003c/h2\u003e\n\u003cp\u003eUsage:\n\u003ccode\u003ecommand [options] [arguments]\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eOptions:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e-h\u003c/code\u003e, \u003ccode\u003e--help\u003c/code\u003e            Display this help message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-q\u003c/code\u003e, \u003ccode\u003e--quiet\u003c/code\u003e           Do not output any message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-V\u003c/code\u003e, \u003ccode\u003e--version\u003c/code\u003e         Display this application version\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--ansi\u003c/code\u003e              Force ANSI output\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e--no-ansi\u003c/code\u003e           Disable ANSI output\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-n\u003c/code\u003e, \u003ccode\u003e--no-interaction\u003c/code\u003e  Do not ask any interactive question\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e--no-warnings\u003c/code\u003e       Skip global warnings, show command output only\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-v\u003c/code\u003e|\u003ccode\u003evv\u003c/code\u003e|\u003ccode\u003evvv\u003c/code\u003e, \u003ccode\u003e--verbose\u003c/code\u003e  Increase the verbosity of messages: 1 for normal output, 2 for more verbose output and 3 for debug\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAvailable commands:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003echeck\u003c/code\u003e                   check dependencies of the server environment\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ehelp\u003c/code\u003e                    displays help for a command\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elist\u003c/code\u003e                    Lists commands\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003estatus\u003c/code\u003e                  show some status information\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eupgrade\u003c/code\u003e                 run upgrade routines after installation of a new release. The release has to be installed before.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"manage-configuration\"\u003eManage configuration\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003econfig\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econfig:app:delete\u003c/code\u003e                   Delete an app config value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:app:get\u003c/code\u003e                      Get an app config value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:app:set\u003c/code\u003e                      Set an app config value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:import\u003c/code\u003e                       Import a list of configs\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:list\u003c/code\u003e                         List all configs\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:system:delete\u003c/code\u003e                Delete a system config value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:system:get\u003c/code\u003e                   Get a system config value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003econfig:system:set\u003c/code\u003e                   Set a system config value\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"manage-database\"\u003eManage Database\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003edb\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003edb:add-missing-indices\u003c/code\u003e              Add missing indices to the database tables\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edb:convert-filecache-bigint\u003c/code\u003e         Convert the ID columns of the filecache to BigInt\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edb:convert-mysql-charset\u003c/code\u003e            Convert charset of MySQL/MariaDB to use utf8mb4\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edb:convert-type\u003c/code\u003e                     Convert the Nextcloud database to the newly configured one\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"encryption-management\"\u003eEncryption Management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003eencryption\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eencryption:change-key-storage-root\u003c/code\u003e  Change key storage root\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:decrypt-all\u003c/code\u003e              Disable server-side encryption and decrypt all files\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:disable\u003c/code\u003e                  Disable encryption\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:enable\u003c/code\u003e                   Enable encryption\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:encrypt-all\u003c/code\u003e              Encrypt all files for all users\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:list-modules\u003c/code\u003e             List all available encryption modules\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:set-default-module\u003c/code\u003e       Set the encryption default module\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:show-key-storage-root\u003c/code\u003e    Show current key storage root\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eencryption:status\u003c/code\u003e                   Lists the current status of encryption\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"federation-management\"\u003eFederation Management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003efederation\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efederation:sync-addressbooks\u003c/code\u003e        Synchronizes addressbooks of all federated clouds\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"files-management\"\u003eFiles Management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003efiles\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efiles:cleanup\u003c/code\u003e                       cleanup filecache\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efiles:recommendations:recommend\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efiles:scan\u003c/code\u003e                         rescan filesystem\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efiles:scan-app-data\u003c/code\u003e                rescan the AppData folder\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efiles:transfer-ownership\u003c/code\u003e           All files and folders are moved to another user - shares are moved as well.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"groups-management\"\u003eGroups Management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003eroup\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003egroup:add\u003c/code\u003e                           Add a group\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egroup:adduser\u003c/code\u003e                       add a user to a group\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egroup:delete\u003c/code\u003e                        Remove a group\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egroup:list\u003c/code\u003e                          list configured groups\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egroup:removeuser\u003c/code\u003e                    remove a user from a group\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"integrity-app-core\"\u003eIntegrity App, Core\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003eintegrity\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eintegrity:check-app\u003c/code\u003e                 Check integrity of an app using a signature.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eintegrity:check-core\u003c/code\u003e                Check integrity of core code using a signature.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eintegrity:sign-app\u003c/code\u003e                  Signs an app using a private key.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eintegrity:sign-core\u003c/code\u003e                 Sign core using a private key.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"logs-management\"\u003eLogs Management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003elog\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elog:file\u003c/code\u003e                           manipulate logging backend\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elog:manage\u003c/code\u003e                          manage logging configuration\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elog:tail\u003c/code\u003e                            Tail the nextcloud logfile\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003elog:watch\u003c/code\u003e                           Watch the nextcloud logfile\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"nc-background-jobs\"\u003eNC Background jobs\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ebackground\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ebackground:ajax\u003c/code\u003e                     Use ajax to run background jobs\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebackground:cron\u003c/code\u003e                     Use cron to run background jobs\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ebackground:webcron\u003c/code\u003e                  Use webcron to run background jobs\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"nc-maintenance\"\u003eNC Maintenance\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003emaintenance\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:data-fingerprint\u003c/code\u003e        update the systems data-fingerprint after a backup is restored\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:mimetype:update-db\u003c/code\u003e      Update database mimetypes and update filecache\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:mimetype:update-js\u003c/code\u003e      Update mimetypelist.js\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:mode\u003c/code\u003e                    set maintenance mode\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:repair\u003c/code\u003e                  repair this installation\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:theme:update\u003c/code\u003e            Apply custom theme changes\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emaintenance:update:htaccess\u003c/code\u003e         Updates the .htaccess file\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"nc-migration\"\u003eNC Migration\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003emigrations\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003emigrations:execute\u003c/code\u003e                  Execute a single migration version manually.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emigrations:generate\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emigrations:generate-from-schema\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emigrations:migrate\u003c/code\u003e                  Execute a migration to a specified version or the latest available version.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003emigrations:status\u003c/code\u003e                   View the status of a set of migrations.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"nc-security\"\u003eNC Security\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003esecurity\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003esecurity:certificates\u003c/code\u003e               list trusted certificates\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esecurity:certificates:import\u003c/code\u003e        import trusted certificate\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esecurity:certificates:remove\u003c/code\u003e        remove trusted certificate\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"nc-update\"\u003eNC Update\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003eupdate\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eupdate:check\u003c/code\u003e                        Check for server and app updates\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"user-management\"\u003eUser management\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003euser\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003euser:add\u003c/code\u003e                            adds a user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:delete\u003c/code\u003e                         deletes the specified user and all datas user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:disable\u003c/code\u003e                        disables the specified user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:enable\u003c/code\u003e                         enables the specified user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:info\u003c/code\u003e                           show user info\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:lastseen\u003c/code\u003e                       shows when the user was logged in last time\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:list\u003c/code\u003e                           list configured users\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:report\u003c/code\u003e                         shows how many users have access\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:resetpassword\u003c/code\u003e                  Resets the password of the named user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003euser:setting\u003c/code\u003e                        Read and modify user settings\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003enotification\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003enotification:generate\u003c/code\u003e               Generate a notification for the given user\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003eversions\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eversions:cleanup\u003c/code\u003e                    Delete versions: delete versions of the given user(s), if no user is given all versions will be deleted\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eversions:expire\u003c/code\u003e                     Expires the users file versions: expire file versions of the given user(s), if no user is given file versions for all users will be expired.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"manage-applications\"\u003eManage applications\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003eapp\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eapp:check-code\u003c/code\u003e                      check code to be compliant\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:disable\u003c/code\u003e                         disable an app\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:enable\u003c/code\u003e                          enable an app\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:getpath\u003c/code\u003e                         Get an absolute path to the app directory\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:install\u003c/code\u003e                         install an app\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:list\u003c/code\u003e                            List all available apps\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:remove\u003c/code\u003e                          remove an app\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eapp:update\u003c/code\u003e                          update an app or all apps\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"mail\"\u003eMail\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003email\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003email:account:create\u003c/code\u003e                 creates IMAP account\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003email:account:export\u003c/code\u003e                 Exports a user\u0026rsquo;s IMAP account(s)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"circles\"\u003eCircles\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003ecircles\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ecircles:clean\u003c/code\u003e                       remove all extra data from database\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ecircles:fixuniqueid\u003c/code\u003e                 fix Unique Id issue.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"deck\"\u003eDeck\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003edeck\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003edeck:export\u003c/code\u003e                         Export a JSON dump of user data\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"talk\"\u003eTalk\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003etalk\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003etalk:command:add\u003c/code\u003e                    Add a new command\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:command:add-samples\u003c/code\u003e            Adds some sample commands: /wiki, …\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:command:delete\u003c/code\u003e                 Remove an existing command\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:command:list\u003c/code\u003e                   List all available commands\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:command:update\u003c/code\u003e                 Add a new command\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:signaling:add\u003c/code\u003e                  Add an external signaling server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:signaling:delete\u003c/code\u003e               Remove an existing signaling server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:signaling:list\u003c/code\u003e                 List external signaling servers.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:stun:add\u003c/code\u003e                       Add a new STUN server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:stun:delete\u003c/code\u003e                    Remove an existing STUN server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:stun:list\u003c/code\u003e                      List STUN servers.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:turn:add\u003c/code\u003e                       Add a TURN server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:turn:delete\u003c/code\u003e                    Remove an existing TURN server.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etalk:turn:list\u003c/code\u003e                      List TURN servers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"2fa-two-factor-auth\"\u003e2FA: Two Factor Auth\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003etwofactorauth\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003etwofactorauth:cleanup\u003c/code\u003e               Clean up the two-factor user-provider association of an uninstalled/removed provider\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etwofactorauth:disable\u003c/code\u003e               Disable two-factor authentication for a user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etwofactorauth:enable\u003c/code\u003e                Enable two-factor authentication for a user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etwofactorauth:enforce\u003c/code\u003e               Enabled/disable enforced two-factor authentication\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003etwofactorauth:state\u003c/code\u003e                 Get the two-factor authentication (2FA) state of a user\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"webdav\"\u003eWebDAV\u003c/h4\u003e\n\u003cp\u003e\u003ccode\u003edav\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003edav:create-addressbook\u003c/code\u003e              Create a dav addressbook\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:create-calendar\u003c/code\u003e                 Create a dav calendar\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:list-calendars\u003c/code\u003e                  List all calendars of a user\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:move-calendar\u003c/code\u003e                   Move a calendar from an user to another\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:remove-invalid-shares\u003c/code\u003e           Remove invalid dav shares\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:send-event-reminders\u003c/code\u003e            Sends event reminders\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:sync-birthday-calendar\u003c/code\u003e          Synchronizes the birthday calendar\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edav:sync-system-addressbook\u003c/code\u003e         Synchronizes users to the system addressbook\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Nextcloud: manpage occ commander","tags":["Nextcloud","occ"],"date_published":"2019-11-23T21:59:23+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-11-23:/en/web/nextcloud/nextcloud-upgrade","url":"https://it-log.fr.eu.org/en/web/nextcloud/nextcloud-upgrade/","title":"(tip) Nextcloud: Manual upgrade on OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description Upgrade NC (Nextcloud ) is very easy… Either you do it:\nWith the web updater. Manually, as me. Via the packages management. FYI : This article explains the manual process under OpenBSD, with nginx, PHP 7.3.\nUpgrading Process This process used few years ago, since v 15.*, as KISS.\nStop Web Service The first action disables domain:\n# rm -f /etc/nginx/sites-enabled/mon-domaine.net # nginx -t \u0026amp;\u0026amp; rcctl restart nginx Preparations Presume user web is www.\nNeed to log as: $ su -l www\nGo to the nextcloud folder: cd www/nextcloud Need to modify the config file: sed -i -e 's#/htdocs#/var/www/htdocs#' config/config.php And enable the maintenance mode: php-7.3 occ maintenance:mode --on Download Go to the parent folder www\\ : Create an usefull version variable named v. Download the actual archive and her checksum sha256 file. Check the checksum $ cd ../ $ v=\u0026#34;17.0.1\u0026#34; $ for ext in bz2 bz2.sha256; do curl -O https://download.nextcloud.com/server/releases/nextcloud-$v.tar.$ext; done $ sha256 -c nextcloud-$v.tar.bz2.sha256 If the result of SHA is (SHA256) nextcloud-$v.tar.bz2: OK, it\u0026rsquo;s good; if not, re-download-it!\nInstallation moving actuel folder nextcloud with date and old number version. untar the archive. delete file CAN_INSTALL; (we\u0026rsquo;re not looking to reinstall)! $ oldvers=\u0026#34;16.0.6\u0026#34; $ date=\u0026#34;$(date \u0026#39;+%Y%m%d%H%M%S\u0026#39;)\u0026#34; $ oldnc=\u0026#34;nextcloud-${date}-${oldvers}\u0026#34; $ mv nextcloud ${oldnc} $ tar xjvf nextcloud-$v.tar.bz2 $ rm -fP config/CAN_INSTALL First Checks Here, you must be careful:\ncopy old config file to new folder config: cp ${oldnc}/config/config.php nextcloud/config/ Now, diff the oldier app folder with new folder to copy all not natives apps. Egual, with themes, if necessary. Permissions Put the rights users on all files and folders into the folder nextcloud/ And, others rights systems. $ webuser=\u0026#34;www\u0026#34; $ chown -R \u0026#34;${webuser}\u0026#34;:www nextcloud $ find nextcloud/ -type d -exec chmod 750 {} \\; $ find nextcloud/ -type f -exec chmod 640 {} \\; Upgrade NC himself Just go to the right folder: cd nextcloud/ Use the tool occ, as: php-7.3 occ upgrade if success, go out the maintenance mode: php-7.3 occ maintenance:mode --off And, at the final, re-sed the config file to delete /var/www : sed -i -e 's#/var/www/htdocs#/htdocs#' config/config.php\nRestart Web Service Enable domain and restart web server, as: # cd /etc/nginx/sites-available/ # ln -s mon-domaine.net ../sites-enabled/ # nginx -t \u0026amp;\u0026amp; rcctl restart nginx Now, connect you at the WebAdmin as admin user, et apply all updates for the apps. And, voilà!\nTL;DR BE CAREFULL: If you copy this TL;DR as-is, you will crash your install! // stop web services # rm -f /etc/nginx/sites-enabled/mon-domaine.net # nginx -t \u0026amp;\u0026amp; rcctl restart nginx // connexion as user web # webuser=\u0026#34;www\u0026#34; # su -l $webuser $ cd /var/www/htdocs/mon-domaine.net/www/nextcloud/ $ sed -i -e \u0026#39;s#/htdocs#/var/www/htdocs#\u0026#39; config/config.php $ php-7.3 occ maintenance:mode --on // downlad archives, and checksum $ cd ../ $ v=\u0026#34;17.0.1\u0026#34; $ for ext in bz2 bz2.sha256; do curl -O https://download.nextcloud.com/server/releases/nextcloud-$v.tar.$ext; done $ sha256 -c nextcloud-$v.tar.bz2.sha256 // Untar $ oldvers=\u0026#34;16.0.6\u0026#34; $ date=\u0026#34;$(date \u0026#39;+%Y%m%d%H%M%S\u0026#39;)\u0026#34; $ oldnc=\u0026#34;nextcloud-${date}-${oldvers}\u0026#34; $ mv nextcloud ${oldnc} $ tar xjvf nextcloud-$v.tar.bz2 $ rm -fP config/CAN_INSTALL // cp config $ cp ${oldnc}/config/config.php nextcloud/config/ // cp only apps not native; dont recopy this command as-is: $ cp all ${oldnc}/apps diff to new nextcloud/apps // egual for themes, if need $ cp all ${oldnc}/themes to new nextcloud/themes $ chown -R \u0026#34;${webuser}\u0026#34;:www nextcloud $ find nextcloud/ -type d -exec chmod 750 {} \\; $ find nextcloud/ -type f -exec chmod 640 {} \\; // occ upgrage process $ cd nextcloud/ $ php-7.3 occ upgrade $ php-7.3 occ maintenance:mode --off $ sed -i -e \u0026#39;s#/var/www/htdocs#/htdocs#\u0026#39; config/config.php // exit // restart web services # cd /etc/nginx/sites-available/ # ln -s mon-domaine.net ../sites-enabled/ # nginx -t \u0026amp;\u0026amp; rcctl restart nginx Caveats If the upgrade process fails with one of thoses errors messages:\nError: Nextcloud is not installed Example:\n$ php-7.3 occ help upgrade Nextcloud is not installed - only a limited number of commands are available Command \u0026#34;upgrade\u0026#34; is not defined. help [--format FORMAT] [--raw] [--] [\u0026lt;command_name\u0026gt;] Have you really copy the oldier config file to the new folder config? Try this tip: php-7.3 occ maintenance:repair Error: you are trying to reinstall your Nextcloud When you connect to the WebUI, you had this message:\nWarningError\nIt looks like you are trying to reinstall your Nextcloud. However the file CAN_INSTALL is missing from your config directory. Please create the file CAN_INSTALL in your config folder to continue.\nGo to delete the file CAN_INSTALL under the new folder config. the files are not visibles Try: php-7.3 console.php files:scan --all OCC Commands As a reminder, this usefull command occ: php occ list\nAnd see this \u0026ldquo;manpage\u0026rdquo;: occ.\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eUpgrade \u003cabbr title=\"Nextcloud\"\u003eNC\u003c/abbr\u003e\n \u003cem\u003e(Nextcloud )\u003c/em\u003e is very easy… Either you do it:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWith the web updater.\u003c/li\u003e\n\u003cli\u003eManually, as me.\u003c/li\u003e\n\u003cli\u003eVia the packages management.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cabbr title=\"For Your Information\"\u003eFYI\u003c/abbr\u003e\n: This article explains the manual process under OpenBSD, with nginx, PHP 7.3.\u003c/p\u003e\n\u003ch2 id=\"upgrading-process\"\u003eUpgrading Process\u003c/h2\u003e\n\u003cp\u003eThis process used few years ago, since v 15.*, as KISS.\u003c/p\u003e\n\u003ch3 id=\"stop-web-service\"\u003eStop Web Service\u003c/h3\u003e\n\u003cp\u003eThe first action disables domain:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rm -f /etc/nginx/sites-enabled/mon-domaine.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# nginx -t \u0026amp;\u0026amp; rcctl restart nginx\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"preparations\"\u003ePreparations\u003c/h3\u003e\n\u003cp\u003ePresume user web is \u003ccode\u003ewww\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eNeed to log as: \u003ccode\u003e$ su -l www\u003c/code\u003e\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eGo to the nextcloud folder: \u003ccode\u003ecd www/nextcloud\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"/en/web/nextcloud/nextcloud-php-chroot/\"\u003eNeed to modify\u003c/a\u003e the config file: \u003ccode\u003esed -i -e 's#/htdocs#/var/www/htdocs#' config/config.php\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAnd enable the maintenance mode: \u003ccode\u003ephp-7.3 occ maintenance:mode --on\u003c/code\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch4 id=\"download\"\u003eDownload\u003c/h4\u003e\n\u003col\u003e\n\u003cli\u003eGo to the parent folder \u003ccode\u003ewww\\\u003c/code\u003e :\u003c/li\u003e\n\u003cli\u003eCreate an usefull version variable named \u003ccode\u003ev\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDownload the actual archive and her checksum sha256 file.\u003c/li\u003e\n\u003cli\u003eCheck the checksum\u003c/li\u003e\n\u003c/ol\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd ../\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003ev\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;17.0.1\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e ext in bz2 bz2.sha256; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e curl -O https://download.nextcloud.com/server/releases/nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.\u003cspan style=\"color:#ef6155\"\u003e$ext\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sha256 -c nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.bz2.sha256\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIf the result of SHA is \u003ccode\u003e(SHA256) nextcloud-$v.tar.bz2: OK\u003c/code\u003e, it\u0026rsquo;s good; if not, re-download-it!\u003c/p\u003e\n\u003ch4 id=\"installation\"\u003eInstallation\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003emoving actuel folder \u003ccode\u003enextcloud\u003c/code\u003e with date and old number version.\u003c/li\u003e\n\u003cli\u003euntar the archive.\u003c/li\u003e\n\u003cli\u003edelete file \u003ccode\u003eCAN_INSTALL\u003c/code\u003e; \u003cem\u003e(we\u0026rsquo;re not looking to reinstall)!\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003eoldvers\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;16.0.6\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edate \u003cspan style=\"color:#48b685\"\u003e\u0026#39;+%Y%m%d%H%M%S\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;nextcloud-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldvers\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ mv nextcloud \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ tar xjvf nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.bz2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ rm -fP config/CAN_INSTALL\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"first-checks\"\u003eFirst Checks\u003c/h4\u003e\n\u003cp\u003eHere, you must be careful:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ecopy old config file to new folder config: \u003ccode\u003ecp ${oldnc}/config/config.php nextcloud/config/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eNow, diff the oldier app folder with new folder to copy all not natives apps.\u003c/li\u003e\n\u003cli\u003eEgual, with themes, if necessary.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"permissions\"\u003ePermissions\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePut the rights users on all files and folders into the folder \u003ccode\u003enextcloud/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAnd, others rights systems.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003ewebuser\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;www\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ chown -R \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ewebuser\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:www nextcloud\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ find nextcloud/ -type d -exec chmod \u003cspan style=\"color:#f99b15\"\u003e750\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{}\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e\\;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ find nextcloud/ -type f -exec chmod \u003cspan style=\"color:#f99b15\"\u003e640\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{}\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e\\;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"upgrade-nc-himself\"\u003eUpgrade NC himself\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eJust go to the right folder: \u003ccode\u003ecd nextcloud/\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUse the tool \u003ccode\u003eocc\u003c/code\u003e, as: \u003ccode\u003ephp-7.3 occ upgrade\u003c/code\u003e\n\u003cul\u003e\n\u003cli\u003eif success, go out the maintenance mode: \u003ccode\u003ephp-7.3 occ maintenance:mode --off\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd, at the final, re-sed the config file to delete \u003ccode\u003e/var/www\u003c/code\u003e :\n\u003ccode\u003esed -i -e 's#/var/www/htdocs#/htdocs#' config/config.php\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"restart-web-service\"\u003eRestart Web Service\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnable domain and restart web server, as:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# cd /etc/nginx/sites-available/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# ln -s mon-domaine.net ../sites-enabled/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# nginx -t \u0026amp;\u0026amp; rcctl restart nginx\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003eNow, connect you at the WebAdmin as admin user, et apply all updates for the apps.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd, voilà!\u003c/p\u003e\n\u003ch3 id=\"tldr\"\u003eTL;DR\u003c/h3\u003e\n\u003cspan class=\"error\"\u003e\nBE CAREFULL: If you copy this TL;DR as-is, you will crash your install!\n\u003c/span\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// stop web services\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rm -f /etc/nginx/sites-enabled/mon-domaine.net\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# nginx -t \u0026amp;\u0026amp; rcctl restart nginx\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// connexion as user web\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# webuser=\u0026#34;www\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# su -l $webuser\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd /var/www/htdocs/mon-domaine.net/www/nextcloud/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sed -i -e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;s#/htdocs#/var/www/htdocs#\u0026#39;\u003c/span\u003e config/config.php\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ php-7.3 occ maintenance:mode --on\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// downlad archives, and checksum\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd ../\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003ev\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;17.0.1\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e ext in bz2 bz2.sha256; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e curl -O https://download.nextcloud.com/server/releases/nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.\u003cspan style=\"color:#ef6155\"\u003e$ext\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sha256 -c nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.bz2.sha256\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// Untar\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003eoldvers\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;16.0.6\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003edate \u003cspan style=\"color:#48b685\"\u003e\u0026#39;+%Y%m%d%H%M%S\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ \u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;nextcloud-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003edate\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e-\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldvers\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ mv nextcloud \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ tar xjvf nextcloud-\u003cspan style=\"color:#ef6155\"\u003e$v\u003c/span\u003e.tar.bz2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ rm -fP config/CAN_INSTALL\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// cp config\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cp \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/config/config.php nextcloud/config/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// cp only apps not native; dont recopy this command as-is:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cp all \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/apps diff to new nextcloud/apps\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// egual \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e themes, \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e need\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cp all \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoldnc\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/themes to new nextcloud/themes\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ chown -R \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ewebuser\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e:www nextcloud\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ find nextcloud/ -type d -exec chmod \u003cspan style=\"color:#f99b15\"\u003e750\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{}\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e\\;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ find nextcloud/ -type f -exec chmod \u003cspan style=\"color:#f99b15\"\u003e640\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{}\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e\\;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// occ upgrage process\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ cd nextcloud/\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ php-7.3 occ upgrade\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ php-7.3 occ maintenance:mode --off\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ sed -i -e \u003cspan style=\"color:#48b685\"\u003e\u0026#39;s#/var/www/htdocs#/htdocs#\u0026#39;\u003c/span\u003e config/config.php\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e// restart web services\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# cd /etc/nginx/sites-available/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# ln -s mon-domaine.net ../sites-enabled/\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# nginx -t \u0026amp;\u0026amp; rcctl restart nginx\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"caveats\"\u003eCaveats\u003c/h3\u003e\n\u003cp\u003eIf the upgrade process fails with one of thoses errors messages:\u003c/p\u003e\n\u003ch4 id=\"error-nextcloud-is-not-installed\"\u003eError: Nextcloud is not installed\u003c/h4\u003e\n\u003cp\u003eExample:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e$ php-7.3 occ help upgrade\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNextcloud is not installed - only a limited number of commands are available\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e  Command \u003cspan style=\"color:#48b685\"\u003e\u0026#34;upgrade\u0026#34;\u003c/span\u003e is not defined.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ehelp \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e--format FORMAT\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e--raw\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e--\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u0026lt;command_name\u0026gt;\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cul\u003e\n\u003cli\u003eHave you really copy the oldier config file to the new folder config?\u003c/li\u003e\n\u003cli\u003eTry this tip: \u003ccode\u003ephp-7.3 occ maintenance:repair\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"error-you-are-trying-to-reinstall-your-nextcloud\"\u003eError: you are trying to reinstall your Nextcloud\u003c/h4\u003e\n\u003cp\u003eWhen you connect to the WebUI, you had this message:\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003e\u003cstrong\u003eError\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eIt looks like you are trying to reinstall your Nextcloud. However the file\nCAN_INSTALL is missing from your config directory. Please create the file\nCAN_INSTALL in your config folder to continue.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cul\u003e\n\u003cli\u003eGo to delete the file \u003ccode\u003eCAN_INSTALL\u003c/code\u003e under the new folder config.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"the-files-are-not-visibles\"\u003ethe files are not visibles\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eTry: \u003ccode\u003ephp-7.3 console.php files:scan --all\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"occ-commands\"\u003eOCC Commands\u003c/h2\u003e\n\u003cp\u003eAs a reminder, this usefull command occ: \u003ccode\u003ephp occ list\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eAnd see this \u0026ldquo;manpage\u0026rdquo;: \u003ca href=\"/en/web/nextcloud/occ/\"\u003eocc\u003c/a\u003e.\u003c/p\u003e\n\u003chr\u003e\n","summary":"Howto upgrade manually Nextcloud under OpenBSD server","tags":["Nextcloud","OpenBSD","upgrade","tip"],"date_published":"2019-11-23T20:45:23+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-10-31:/en/sec/firewall/pf-icmp","url":"https://it-log.fr.eu.org/en/sec/firewall/pf-icmp/","title":"Manage ICMP through PF (Packet-Filter)","author":{"name":"Stéphane HUC"},"content_text":"Description TipThis article can be usefull for the embedded PF on Debian GNU/kFreeBSD ! Following the recommendations from my Linux firewalling ICMP about the rules to be put in place to allow or block ICMP messages, here are the adequate rules for PF, for *BSD that use Packet Filter, including OpenBSD:\nManage ICMP Drop (…) icmp_block_types=\u0026#34;{ 4 6 15 16 17 18 31 32 33 34 35 36 37 38 39 }\u0026#34; (…) block drop quick on egress inet proto icmp icmp-type 3 code 6 block drop in quick on egress inet proto icmp icmp-type 3 code 7 block drop quick on egress inet proto icmp icmp-type 3 code 8 block drop quick on egress inet proto icmp icmp-type $icmp_block_types (…) WarningIt seems that PF does not manage 37 and 38 (respectly Domain Name Request, and Domain Name Reply)… Pass InfoThere is no limit equivalent for PF!\nIt seems that it\u0026rsquo;s finely managed by the kernel on OpenBSD. (…) icmp_types=\u0026#34;{ 8 11 12 }\u0026#34; (…) block log pass out (…) pass in quick on egress inet proto icmp from any to egress icmp-type { 3 code 3, 3 code 4 } pass in quick on egress inet proto icmp from any to egress icmp-type $icmp_types pass out quick on egress inet proto icmp from egress to any icmp-type { 3 code 3, 3 code 4 } pass out quick on egress inet proto icmp from egress to any icmp-type $icmp_types Or course, you can authorize all other codes that can be passed, and whose recommendations are to limit. The 3 highlighted codes are a minimum!\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eThis article can be usefull for the embedded PF on  \u003ca href=\"https://wiki.debian.org/fr/Debian_GNU/kFreeBSD\" rel=\"external\"\u003eDebian GNU/kFreeBSD\u003c/a\u003e !\u003c/div\u003e\n\n\u003cp\u003eFollowing the recommendations from my \u003ca href=\"/en/sec/firewall/linux-firewall-icmp/\"\u003eLinux firewalling ICMP\u003c/a\u003e about the rules to be put in place to allow or block ICMP messages, here are the adequate rules for PF, for *BSD that use Packet Filter, including\nOpenBSD:\u003c/p\u003e\n\u003ch2 id=\"manage-icmp\"\u003eManage ICMP\u003c/h2\u003e\n\u003ch3 id=\"drop\"\u003eDrop\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eicmp_block_types\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ 4 6 15 16 17 18 31 32 33 34 35 36 37 38 39 }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eblock drop quick on egress inet proto icmp icmp-type \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code \u003cspan style=\"color:#f99b15\"\u003e6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eblock drop in quick on egress inet proto icmp icmp-type \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eblock drop quick on egress inet proto icmp icmp-type \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code \u003cspan style=\"color:#f99b15\"\u003e8\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eblock drop quick on egress inet proto icmp icmp-type \u003cspan style=\"color:#ef6155\"\u003e$icmp_block_types\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eIt seems that PF does not manage \u003cstrong\u003e37\u003c/strong\u003e and \u003cstrong\u003e38\u003c/strong\u003e \u003cem\u003e(respectly\n\u003cstrong\u003eDomain Name Request\u003c/strong\u003e, and \u003cstrong\u003eDomain Name Reply\u003c/strong\u003e)\u003c/em\u003e…\u003c/div\u003e\n\n\u003ch3 id=\"pass\"\u003ePass\u003c/h3\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eThere is no \u003ccode\u003elimit\u003c/code\u003e equivalent for PF!\u003cbr\u003e\nIt seems that it\u0026rsquo;s finely managed by the kernel on OpenBSD.\u003c/div\u003e\n\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eicmp_types\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ 8 11 12 }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eblock log\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epass out\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e…\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epass in quick on egress inet proto icmp from any to egress icmp-type \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code 3, \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epass in quick on egress inet proto icmp from any to egress icmp-type \u003cspan style=\"color:#ef6155\"\u003e$icmp_types\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epass out quick on egress inet proto icmp from egress to any icmp-type \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code 3, \u003cspan style=\"color:#f99b15\"\u003e3\u003c/span\u003e code \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003epass out quick on egress inet proto icmp from egress to any icmp-type \u003cspan style=\"color:#ef6155\"\u003e$icmp_types\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eOr course, you can authorize all other codes that can be passed, and whose\nrecommendations are to limit. The 3 highlighted codes are a minimum!\u003c/p\u003e\n\u003chr\u003e\n","summary":"Example of rules to manage ICMP with the firewall Packet-Filter (PF)","tags":["firewall","PF","Packet-Filter","ICMP"],"date_published":"2019-10-31T12:38:55+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-10-31:/en/sec/firewall/pf-icmpv6","url":"https://it-log.fr.eu.org/en/sec/firewall/pf-icmpv6/","title":"Manage ICMPv6 through PF (Packet-Filter)","author":{"name":"Stéphane HUC"},"content_text":"Description TipThis article can be usefull for the embedded PF on Debian GNU/kFreeBSD ! Following the recommendations from my article about the rules to be put in place to allow or block ICMPv6 messages, here are the adequate rules for PF, for *BSD that use Packet Filter, including OpenBSD:\nWarningNEVER forget that the entire IPv6 stack, unlike IPv4, really relies on ICMPv6; thus, a bad configuration of ICMPv6 will certainly prevent all or part of the IPv6 stream from working correctly, or as expected! Manage ICMPv6 Drop These ICMPv6 types are to be rejected absolutely:\nicmp6_block = \u0026#34;{ 100 101 127 138 139 140 144 145 146 147 150 200 201 }\u0026#34; block drop quick log on egress inet6 proto icmp6 icmp6-type $icmp6_block InfoBe Carefull: About Mobile IPv6 messages types (144 → 147), there are needed to assist mobility, depending mobile nodes normally on the site, or foreign mobile nodes roaming (tablets, laptops, …)…\nIf necessary, you may need to pass and limit them.\nPass ⇒ For a station:\nicmp6_auth = \u0026#34;{ unreach toobig timex paramprob echoreq echoreq neighbradv neighbrsol }\u0026#34; pass out quick on egress inet6 proto icmp6 from any to ff02::2 icmp6-type { routersol, listenrepv2 } pass in quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv } pass quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts pass in quick on egress inet6 proto icmp6 from any to egress icmp6-type redir allow-opts Explainations\nThe first rule define all authorized ICMPv6 types required, a minimum.\nThe second rule authorize only in output:\nsolicitations messages from the station to the routeur — ff02::2 is the local multicast address of any router and the \u0026ldquo;Multicast Listener Report Message v2\u0026rdquo; messages, listenrepv2 - both ICMPv6 types are needed to communicate locally this rule is the first because the station announce that it needs a routable address to communicate with others. The third rule authorize only in input messages from router — type 143 — to the station\u0026rsquo;s local node — ff02::1.\nthis is the router\u0026rsquo;s reply to the previous request from the station The 4th rule autorise in input, and output all defined types from the first rule — the macro $icmp6_auth.\nThe 5 rule authorize only in input the redirection ICMPv6 message.\n⇒ Router case:\nPour débuter, faisons simplement :\nicmp6_auth = \u0026#34;{ echoreq echoreq neighbradv neighbrsol }\u0026#34; pass in quick on egress inet6 proto icmp6 icmp6-type { routersol, listenrepv2 } pass out quick on egress inet6 proto icmp6 icmp6-type routeradv pass quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth Limit To limit ICMPv6 traffic, PF can be use STO .\nTo continue the example above, using the max-src-conn-rate option:\nicmp6_auth = \u0026#34;{ unreach toobig timex paramprob echoreq neighbradv neighbrsol }\u0026#34; icmp6_sto = \u0026#34;( max-src-conn-rate 100/10 )\u0026#34; pass out quick on egress inet6 proto icmp6 from any to ff02::2 icmp6-type { routersol, listenrepv2 } pass in quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv } pass quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto pass in quick on egress inet6 proto icmp6 from any to egress icmp6-type redir allow-opts $icmp6_sto More paranoid icmp6_auth = \u0026#34;{ unreach, toobig, timex code 0, timex code 1, paramprob code 1, paramprob code 2, echorep, echoreq, neighbradv, neighbrsol }\u0026#34; icmp6_out = \u0026#34;{ echorep, echoreq, neighbradv, neighbrsol }\u0026#34; icmp6_sto = \u0026#34;( max-src-conn-rate 100/10 )\u0026#34; pass out quick on egress inet6 proto icmp6 from any to ff02::2 icmp6-type { routersol, listenrepv2 } pass in quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv, redir } pass quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto pass out quick on egress inet6 proto from egress to any icmp6 icmp6-type $icmp6_out allow-opts $icmp6_sto Explainations\nicmp6_auth: manage only what it\u0026rsquo;s absolutely necessary.\nicmp6_out: to manage echoes replies — the \u0026ldquo;Pong\u0026rdquo; ­— from routeur and neighbours messages\nin the first in rule, we have added management of redirection messages to a shorter route, only from a router to our machine. to our machine. WARNING: allowing redirection messages message in any other way will cause security problems, to the extent that that it seems advisable to remove them from the firewall context!\n⇒ Router case:\nicmp6_auth = \u0026#34;{ unreach toobig timex paramprob echoreq echoreq neighbradv neighbrsol }\u0026#34; icmp6_sto = \u0026#34;( max-src-conn-rate 100/10 )\u0026#34; pass in quick on egress inet6 proto icmp6 icmp6-type { routersol, listenrepv2 } pass out quick on egress inet6 proto icmp6 icmp6-type { routeradv, redir } pass quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto Documentation Link-local_address WP ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\n\u003cdiv class=\"tab-info i-tip\"\u003eTip\u003c/div\u003e\u003cdiv class=\"alert alert-tip\" role=\"alert\"\u003eThis article can be usefull for the embedded PF on \u003ca href=\"https://wiki.debian.org/fr/Debian_GNU/kFreeBSD\" rel=\"external\"\u003eDebian GNU/kFreeBSD\u003c/a\u003e !\u003c/div\u003e\n\n\u003cp\u003eFollowing the recommendations from my \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/\"\u003earticle\u003c/a\u003e about\nthe rules to be put in place to allow or block ICMPv6 messages, here are the adequate rules for PF, for *BSD that use Packet Filter, including OpenBSD:\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003eNEVER forget that the entire IPv6 stack, unlike IPv4, really relies on ICMPv6; thus, a bad configuration of ICMPv6 will certainly prevent all or part of the IPv6 stream from working correctly, or as expected!\u003c/div\u003e\n\n\u003ch2 id=\"manage-icmpv6\"\u003eManage ICMPv6\u003c/h2\u003e\n\u003ch3 id=\"drop\"\u003eDrop\u003c/h3\u003e\n\u003cp\u003eThese ICMPv6 types are to be rejected absolutely:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_block\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ 100 101 127 138 139 140 144 145 146 147 150 200 201 }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eblock drop quick log on egress inet6 proto icmp6 icmp6-type $icmp6_block\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003e\u003cp\u003e\u003cstrong\u003eBe Carefull:\u003c/strong\u003e About Mobile IPv6 messages types (144 → 147), there are needed to assist mobility, depending mobile nodes normally on the site, or foreign mobile nodes roaming \u003cem\u003e(tablets, laptops, …)\u003c/em\u003e…\u003c/p\u003e\n\u003cp\u003eIf necessary, you may need to pass and limit them.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003chr\u003e\n\u003ch3 id=\"pass\"\u003ePass\u003c/h3\u003e\n\u003cp\u003e⇒ For a station:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_auth\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ unreach toobig timex paramprob echoreq echoreq neighbradv neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto icmp6 from any       to ff02::2 icmp6-type { routersol, listenrepv2 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass     quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 from any to egress icmp6-type redir allow-opts\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eThe first rule define all authorized ICMPv6 types required, a minimum.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe second rule authorize only in output:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003esolicitations messages from the station to the routeur — \u003ccode\u003eff02::2\u003c/code\u003e is the local multicast address of any router\u003c/li\u003e\n\u003cli\u003eand the \u0026ldquo;Multicast Listener Report Message v2\u0026rdquo; messages, \u003ccode\u003elistenrepv2\u003c/code\u003e - both ICMPv6 types are needed to communicate locally\u003c/li\u003e\n\u003cli\u003ethis rule is the first because the station announce that it needs a routable address to communicate with others.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe third rule authorize only in input messages from router  — type 143 — to the station\u0026rsquo;s local node — \u003ccode\u003eff02::1\u003c/code\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethis is the router\u0026rsquo;s reply to the previous request from the station\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe 4th rule autorise in input, and output all defined types from the first rule — the macro \u003ccode\u003e$icmp6_auth\u003c/code\u003e.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe 5 rule authorize only in input the redirection ICMPv6 message.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e⇒ Router case:\u003c/p\u003e\n\u003cp\u003ePour débuter, faisons simplement :\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_auth\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ echoreq echoreq neighbradv neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 icmp6-type { routersol, listenrepv2 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto icmp6 icmp6-type routeradv\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass     quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"limit\"\u003eLimit\u003c/h4\u003e\n\u003cp\u003eTo limit ICMPv6 traffic, PF can be use\n\u003cabbr title=\"Stateful Tracking Options\"\u003eSTO\u003c/abbr\u003e\n.\u003c/p\u003e\n\u003cp\u003eTo continue the example above, using the \u003ccode\u003emax-src-conn-rate\u003c/code\u003e option:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_auth\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ unreach toobig timex paramprob echoreq neighbradv neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_sto\u003c/span\u003e  \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;( max-src-conn-rate 100/10 )\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto icmp6 from any       to ff02::2 icmp6-type { routersol, listenrepv2 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass     quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 from any to egress icmp6-type redir allow-opts $icmp6_sto\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch4 id=\"more-paranoid\"\u003eMore paranoid\u003c/h4\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_auth\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ unreach, toobig, timex code 0, timex code 1, paramprob code 1, paramprob code 2, echorep, echoreq, neighbradv, neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_out\u003c/span\u003e  \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ echorep, echoreq, neighbradv, neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_sto\u003c/span\u003e  \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;( max-src-conn-rate 100/10 )\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto icmp6 from any       to ff02::2 icmp6-type { routersol, listenrepv2 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 from fe80::/64 to ff02::1 icmp6-type { routeradv, redir }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass     quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto from egress to any icmp6 icmp6-type $icmp6_out allow-opts $icmp6_sto\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eicmp6_auth\u003c/code\u003e: manage only what it\u0026rsquo;s absolutely necessary.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eicmp6_out\u003c/code\u003e: to manage echoes replies — the \u0026ldquo;Pong\u0026rdquo; ­— from routeur and\nneighbours messages\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003ein the first \u003ccode\u003ein\u003c/code\u003e rule, we have added management of redirection messages to a shorter route, only from a router to our machine. to our machine. \u003cbr\u003e\n\u003cstrong\u003eWARNING\u003c/strong\u003e: allowing redirection messages message in any other way will cause security problems, to the extent that that it seems advisable to remove them from the firewall context!\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e⇒ Router case:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_auth\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;{ unreach toobig timex paramprob echoreq echoreq neighbradv neighbrsol }\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eicmp6_sto\u003c/span\u003e  \u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;( max-src-conn-rate 100/10 )\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass in  quick on egress inet6 proto icmp6 icmp6-type { routersol, listenrepv2 }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass out quick on egress inet6 proto icmp6 icmp6-type { routeradv, redir }\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003epass     quick on egress inet6 proto icmp6 icmp6-type $icmp6_auth allow-opts $icmp6_sto\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Link-local_address\" title=\"Wikipedia Article: Link-local_address\"\u003e\n    Link-local_address\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Example of rules to manage ICMPv6 with the firewall Packet-Filter (PF)","tags":["firewall","PF","Packet-Filter","ICMPv6"],"date_published":"2019-10-31T12:38:55+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-06-19:/en/dev/python/env-python-openbsd","url":"https://it-log.fr.eu.org/en/dev/python/env-python-openbsd/","title":"Python: virtual environment on OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description OS : OpenBSD 6.x Since OpenBSD 6.0, wxallowed is a mount option, by default on /usr/local.\nIf the partition has this option, the software is allowed to run from that partition, otherwise it won\u0026rsquo;t be able to run and will issue a W^X violation message:\n:$ dmesg | grep wxallowed /home/hs/.local/share/virtualenvs/mybeautifullproject-q1koN8ay/bin/python3(26392): W^X binary outside wxallowed mountpoint In fact, since only /usr/local had this actived option, if you attempt to run one program, by example on your $HOME, this one will not execute.\nThat\u0026rsquo;s the whole problem with Python environments that need to work in your home directory.\nHere the problem with virtualenv:\n:$ virtualenv mybeautifullproject Using base prefix \u0026#39;/usr/local\u0026#39; New python executable in $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python3 Also creating executable in $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python ERROR: The executable $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python3 could not be run: [Errno 13] Permission denied: \u0026#39;$HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python Egual for pipenv:\n:$ pipenv install requests Warning: the environment variable LANG is not set! We recommend setting this in ~/.profile (or equivalent) for proper expected behavior. Creating a virtualenv for this project… Pipfile: $HOME/python/mybeautifullproject.py/Pipfile Using /usr/local/bin/python3 (3.6.8) to create virtualenv… ⠇ Creating virtual environment...Already using interpreter /usr/local/bin/python3 Using base prefix \u0026#39;/usr/local\u0026#39; New python executable in $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3 Also creating executable in $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python ERROR: The executable $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3 could not be run: [Errno 13] Permission denied: \u0026#39;$HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3\u0026#39; ✘ Failed creating virtual environment [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/cli/command.py\u0026#34;, line 254, in install [pipenv.exceptions.VirtualenvCreationException]: editable_packages=state.installstate.editables, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 1741, in do_install [pipenv.exceptions.VirtualenvCreationException]: pypi_mirror=pypi_mirror, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 574, in ensure_project [pipenv.exceptions.VirtualenvCreationException]: pypi_mirror=pypi_mirror, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 506, in ensure_virtualenv [pipenv.exceptions.VirtualenvCreationException]: python=python, site_packages=site_packages, pypi_mirror=pypi_mirror [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 935, in do_create_virtualenv [pipenv.exceptions.VirtualenvCreationException]: extra=[crayons.blue(\u0026#34;{0}\u0026#34;.format(c.err)),] [pipenv.exceptions.VirtualenvCreationException]: Failed to create virtual environment. Configuration One only little system change will make our lives easier:\ncreate a folder user into /usr/local, i.e.:\n:# mkdir -p /usr/local/${my_user}/python chown user and group rights:\n:# chown -R ${my_user}:wheel /usr/local/${my_user} create symbolic link:\n:# ln -s /usr/local/${my_user}/python $home/python Of course, replace ${my_user} by your id! ;-)\nIf you use pipenv, you need to create a new folder and symlink; read the TL;DR below.\nTL;DR Replace ${my_user} by your session id!\n⇒ For virtualenv:\n:# mkdir -p /usr/local/${my_user}/python :# chown -R ${my_user}:wheel /usr/local/${my_user} :# ln -s /usr/local/${my_user}/python $home/python ⇒ For pipenv, you need to add more:\n:$ mkdir /usr/local/$USER/python/virtualenvs :$ ln -s /usr/local/$USER/python/virtualenvs $HOME/.local/share/virtualenvs Documentations The pipenv: https://pipenv.readthedocs.io/en/latest/ About the mount option wxallowed: EN Aknowledgements This article would not exists without Xavier… and, this other article: \u0026ldquo;Using cabal on OpenBSD\u0026rdquo; ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOS : OpenBSD 6.x\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSince OpenBSD 6.0, \u003ccode\u003ewxallowed\u003c/code\u003e is a mount option, by default on \u003ccode\u003e/usr/local\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf the partition has this option, the software is allowed to run from that\npartition, otherwise it won\u0026rsquo;t be able to run and will issue a \u003ccode\u003eW^X\u003c/code\u003e violation\nmessage:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ dmesg | grep wxallowed\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/home/hs/.local/share/virtualenvs/mybeautifullproject-q1koN8ay/bin/python3\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e26392\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: W^X binary outside wxallowed mountpoint\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIn fact, since only \u003ccode\u003e/usr/local\u003c/code\u003e had this actived option, if you attempt\nto run one program, by example on your \u003ccode\u003e$HOME\u003c/code\u003e, this one will not execute.\u003cbr\u003e\nThat\u0026rsquo;s the whole problem with Python environments that need to work in\nyour home directory.\u003c/p\u003e\n\u003cp\u003eHere the problem with \u003ccode\u003evirtualenv\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:\u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e virtualenv mybeautifullproject\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing base prefix \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/usr/local\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNew python executable \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAlso creating executable \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eERROR: The executable \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3 could \u003cspan style=\"color:#5bc4bf\"\u003enot\u003c/span\u003e be run: [Errno \u003cspan style=\"color:#f99b15\"\u003e13\u003c/span\u003e] Permission denied: \u003cspan style=\"color:#48b685\"\u003e\u0026#39;$HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eEgual for \u003ccode\u003epipenv\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-python\" data-lang=\"python\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:\u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003e pipenv install requests\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eWarning\u003c/span\u003e: the environment variable LANG \u003cspan style=\"color:#5bc4bf\"\u003eis\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003enot\u003c/span\u003e set\u003cspan style=\"color:#ef6155\"\u003e!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eWe recommend setting this \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e~/.\u003c/span\u003eprofile (\u003cspan style=\"color:#5bc4bf\"\u003eor\u003c/span\u003e equivalent) \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e proper expected behavior\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCreating a virtualenv \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e this project\u003cspan style=\"color:#ef6155\"\u003e…\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ePipfile: \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ePipfile\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing \u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003eusr\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003elocal\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3 (\u003cspan style=\"color:#f99b15\"\u003e3.6.8\u003c/span\u003e) to create virtualenv\u003cspan style=\"color:#ef6155\"\u003e…\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003e⠇\u003c/span\u003e Creating virtual environment\u003cspan style=\"color:#5bc4bf\"\u003e...\u003c/span\u003eAlready using interpreter \u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003eusr\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003elocal\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing base prefix \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/usr/local\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNew python executable \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/.\u003c/span\u003elocal\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003eshare\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003evirtualenvs\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003eoFlnu9vD\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAlso creating executable \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/.\u003c/span\u003elocal\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003eshare\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003evirtualenvs\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003eoFlnu9vD\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eERROR: The executable \u003cspan style=\"color:#ef6155\"\u003e$\u003c/span\u003eHOME\u003cspan style=\"color:#5bc4bf\"\u003e/.\u003c/span\u003elocal\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003eshare\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003evirtualenvs\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003emybeautifullproject\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003epy\u003cspan style=\"color:#5bc4bf\"\u003e-\u003c/span\u003eoFlnu9vD\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003ebin\u003cspan style=\"color:#5bc4bf\"\u003e/\u003c/span\u003epython3 could \u003cspan style=\"color:#5bc4bf\"\u003enot\u003c/span\u003e be run: [Errno \u003cspan style=\"color:#f99b15\"\u003e13\u003c/span\u003e] Permission denied: \u003cspan style=\"color:#48b685\"\u003e\u0026#39;$HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003e✘\u003c/span\u003e Failed creating virtual environment\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/cli/command.py\u0026#34;\u003c/span\u003e, line \u003cspan style=\"color:#f99b15\"\u003e254\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e install\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:       editable_packages\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003estate\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003einstallstate\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eeditables,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line \u003cspan style=\"color:#f99b15\"\u003e1741\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e do_install\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:       pypi_mirror\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line \u003cspan style=\"color:#f99b15\"\u003e574\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e ensure_project\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:       pypi_mirror\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line \u003cspan style=\"color:#f99b15\"\u003e506\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e ensure_virtualenv\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:       python\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epython, site_packages\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003esite_packages, pypi_mirror\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line \u003cspan style=\"color:#f99b15\"\u003e935\u003c/span\u003e, \u003cspan style=\"color:#5bc4bf\"\u003ein\u003c/span\u003e do_create_virtualenv\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:       extra\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e[crayons\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eblue(\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e{0}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eformat(c\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eerr)),]\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e[pipenv\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eexceptions\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003eVirtualenvCreationException]:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eFailed to create virtual environment\u003cspan style=\"color:#5bc4bf\"\u003e.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eOne only little system change will make our lives easier:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ecreate a folder user into \u003ccode\u003e/usr/local\u003c/code\u003e, i.e.:\u003cbr\u003e\n\u003ccode\u003e:# mkdir -p /usr/local/${my_user}/python\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003echown user and group rights:\u003cbr\u003e\n\u003ccode\u003e:# chown -R ${my_user}:wheel /usr/local/${my_user}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ecreate symbolic link:\u003cbr\u003e\n\u003ccode\u003e:# ln -s /usr/local/${my_user}/python $home/python\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cem\u003eOf course, replace \u003ccode\u003e${my_user}\u003c/code\u003e by your id!\u003c/em\u003e ;-)\u003c/p\u003e\n\u003cp\u003eIf you use \u003ccode\u003epipenv\u003c/code\u003e, you need to create a new folder and symlink; read the\n\u003ca href=\"/en/dev/python/env-python-openbsd/#tldr\"\u003eTL;DR\u003c/a\u003e below.\u003c/p\u003e\n\u003ch2 id=\"tldr\"\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003eReplace \u003ccode\u003e${my_user}\u003c/code\u003e by your session id!\u003c/p\u003e\n\u003cp\u003e⇒ For \u003cstrong\u003evirtualenv\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# mkdir -p /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/python\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# chown -R \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e:wheel /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# ln -s /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/python \u003cspan style=\"color:#ef6155\"\u003e$home\u003c/span\u003e/python\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ For \u003cstrong\u003epipenv\u003c/strong\u003e, you need to add more:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ mkdir /usr/local/\u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e/python/virtualenvs\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ln -s /usr/local/\u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e/python/virtualenvs \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/.local/share/virtualenvs\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003cstrong\u003epipenv\u003c/strong\u003e: \u003ca href=\"https://pipenv.readthedocs.io/en/latest/\" rel=\"external\"\u003ehttps://pipenv.readthedocs.io/en/latest/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAbout the mount option \u003cstrong\u003ewxallowed\u003c/strong\u003e: \u003ca href=\"https://www.openbsd.org/faq/upgrade60.html\" rel=\"external\"\u003eEN\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"aknowledgements\"\u003eAknowledgements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis article would not exists without \u003ca href=\"https://ybad.name/sdj.html\" rel=\"external\"\u003eXavier\u003c/a\u003e…\u003c/li\u003e\n\u003cli\u003eand, this other \u003ca href=\"https://deftly.net/posts/2017-10-12-using-cabal-on-openbsd.html\" rel=\"external\"\u003earticle\u003c/a\u003e: \u0026ldquo;\u003cem\u003e\u003cstrong\u003eUsing cabal on OpenBSD\u003c/strong\u003e\u003c/em\u003e\u0026rdquo;\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003chr\u003e\n","summary":"How to use virtuals environments Python on OpenBSD with W^X security.","tags":["Python","Environnement","OpenBSD"],"date_published":"2019-06-19T12:03:33+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-06-19:/en/sys/openbsd/env-python-openbsd","url":"https://it-log.fr.eu.org/en/sys/openbsd/env-python-openbsd/","title":"Python: virtual environment on OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Description OS : OpenBSD 6.x Since OpenBSD 6.0, wxallowed is a mount option, by default on /usr/local.\nIf the partition has this option, the software is allowed to run from that partition, otherwise it won\u0026rsquo;t be able to run and will issue a W^X violation message:\n:$ dmesg | grep wxallowed /home/hs/.local/share/virtualenvs/mybeautifullproject-q1koN8ay/bin/python3(26392): W^X binary outside wxallowed mountpoint In fact, since only /usr/local had this actived option, if you attempt to run one program, by example on your $HOME, this one will not execute.\nThat\u0026rsquo;s the whole problem with Python environments that need to work in your home directory.\nHere the problem with virtualenv:\n:$ virtualenv mybeautifullproject Using base prefix \u0026#39;/usr/local\u0026#39; New python executable in $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python3 Also creating executable in $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python ERROR: The executable $HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python3 could not be run: [Errno 13] Permission denied: \u0026#39;$HOME/python/mybeautifullproject.py/mybeautifullproject/bin/python Egual for pipenv:\n:$ pipenv install requests Warning: the environment variable LANG is not set! We recommend setting this in ~/.profile (or equivalent) for proper expected behavior. Creating a virtualenv for this project… Pipfile: $HOME/python/mybeautifullproject.py/Pipfile Using /usr/local/bin/python3 (3.6.8) to create virtualenv… ⠇ Creating virtual environment...Already using interpreter /usr/local/bin/python3 Using base prefix \u0026#39;/usr/local\u0026#39; New python executable in $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3 Also creating executable in $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python ERROR: The executable $HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3 could not be run: [Errno 13] Permission denied: \u0026#39;$HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3\u0026#39; ✘ Failed creating virtual environment [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/cli/command.py\u0026#34;, line 254, in install [pipenv.exceptions.VirtualenvCreationException]: editable_packages=state.installstate.editables, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 1741, in do_install [pipenv.exceptions.VirtualenvCreationException]: pypi_mirror=pypi_mirror, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 574, in ensure_project [pipenv.exceptions.VirtualenvCreationException]: pypi_mirror=pypi_mirror, [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 506, in ensure_virtualenv [pipenv.exceptions.VirtualenvCreationException]: python=python, site_packages=site_packages, pypi_mirror=pypi_mirror [pipenv.exceptions.VirtualenvCreationException]: File \u0026#34;$HOME/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;, line 935, in do_create_virtualenv [pipenv.exceptions.VirtualenvCreationException]: extra=[crayons.blue(\u0026#34;{0}\u0026#34;.format(c.err)),] [pipenv.exceptions.VirtualenvCreationException]: Failed to create virtual environment. Configuration One only little system change will make our lives easier:\ncreate a folder user into /usr/local, i.e.:\n# mkdir -p /usr/local/${my_user}/python chown user and group rights:\n# chown -R ${my_user}:wheel /usr/local/${my_user} create symbolic link:\n# ln -s /usr/local/${my_user}/python $home/python Of course, replace ${my_user} by your id! ;-)\nIf you use pipenv, you need to create a new folder and symlink; read the TL;DR below.\nTL;DR Replace ${my_user} by your session id!\n⇒ For virtualenv:\n:# mkdir -p /usr/local/${my_user}/python :# chown -R ${my_user}:wheel /usr/local/${my_user} :# ln -s /usr/local/${my_user}/python $home/python ⇒ For pipenv, you need to add more:\n:$ mkdir /usr/local/$USER/python/virtualenvs :$ ln -s /usr/local/$USER/python/virtualenvs $HOME/.local/share/virtualenvs Documentations The pipenv: https://pipenv.readthedocs.io/en/latest/ About the mount option wxallowed: EN Aknowledgements This article would not exists without Xavier… and, this other article: \u0026ldquo;Using cabal on OpenBSD\u0026rdquo; ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOS : OpenBSD 6.x\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSince OpenBSD 6.0, \u003ccode\u003ewxallowed\u003c/code\u003e is a mount option, by default on \u003ccode\u003e/usr/local\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIf the partition has this option, the software is allowed to run from that\npartition, otherwise it won\u0026rsquo;t be able to run and will issue a \u003ccode\u003eW^X\u003c/code\u003e violation\nmessage:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ dmesg | grep wxallowed\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/home/hs/.local/share/virtualenvs/mybeautifullproject-q1koN8ay/bin/python3\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e26392\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e: W^X binary outside wxallowed mountpoint\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eIn fact, since only \u003ccode\u003e/usr/local\u003c/code\u003e had this actived option, if you attempt\nto run one program, by example on your \u003ccode\u003e$HOME\u003c/code\u003e, this one will not execute.\u003cbr\u003e\nThat\u0026rsquo;s the whole problem with Python environments that need to work in\nyour home directory.\u003c/p\u003e\n\u003cp\u003eHere the problem with \u003ccode\u003evirtualenv\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ virtualenv mybeautifullproject\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing base prefix \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/usr/local\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNew python executable in \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/python/mybeautifullproject.py/mybeautifullproject/bin/python3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAlso creating executable in \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/python/mybeautifullproject.py/mybeautifullproject/bin/python\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eERROR: The executable \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/python/mybeautifullproject.py/mybeautifullproject/bin/python3 could not be run: \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eErrno 13\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e Permission denied: \u003cspan style=\"color:#ef6155\"\u003e\u0026#39;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/python/mybeautifullproject.py/mybeautifullproject/bin/python\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eEgual for \u003ccode\u003epipenv\u003c/code\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ pipenv install requests\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eWarning: the environment variable LANG is not set!\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eWe recommend setting this in ~/.profile \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eor equivalent\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e proper expected behavior.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCreating a virtualenv \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e this project…\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ePipfile: \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/python/mybeautifullproject.py/Pipfile\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing /usr/local/bin/python3 \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e3.6.8\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e to create virtualenv…\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e⠇ Creating virtual environment...Already using interpreter /usr/local/bin/python3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eUsing base prefix \u003cspan style=\"color:#48b685\"\u003e\u0026#39;/usr/local\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eNew python executable in \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAlso creating executable in \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eERROR: The executable \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3 could not be run: \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003eErrno 13\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e Permission denied: \u003cspan style=\"color:#48b685\"\u003e\u0026#39;$HOME/.local/share/virtualenvs/mybeautifullproject.py-oFlnu9vD/bin/python3\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e✘ Failed creating virtual environment\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.local/lib/python3.6/site-packages/pipenv/cli/command.py\u0026#34;\u003c/span\u003e, line 254, in install\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:       \u003cspan style=\"color:#ef6155\"\u003eeditable_packages\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003estate.installstate.editables,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line 1741, in do_install\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:       \u003cspan style=\"color:#ef6155\"\u003epypi_mirror\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line 574, in ensure_project\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:       \u003cspan style=\"color:#ef6155\"\u003epypi_mirror\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror,\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line 506, in ensure_virtualenv\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:       \u003cspan style=\"color:#ef6155\"\u003epython\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epython, \u003cspan style=\"color:#ef6155\"\u003esite_packages\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003esite_packages, \u003cspan style=\"color:#ef6155\"\u003epypi_mirror\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003epypi_mirror\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:   File \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e/.local/lib/python3.6/site-packages/pipenv/core.py\u0026#34;\u003c/span\u003e, line 935, in do_create_virtualenv\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:       \u003cspan style=\"color:#ef6155\"\u003eextra\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=[\u003c/span\u003ecrayons.blue\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;{0}\u0026#34;\u003c/span\u003e.format\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003ec.err\u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e,\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003epipenv.exceptions.VirtualenvCreationException\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eFailed to create virtual environment.\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eOne only little system change will make our lives easier:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ecreate a folder user into \u003ccode\u003e/usr/local\u003c/code\u003e, i.e.:\u003cbr\u003e\n\u003ccode\u003e# mkdir -p /usr/local/${my_user}/python\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003echown user and group rights:\u003cbr\u003e\n\u003ccode\u003e# chown -R ${my_user}:wheel /usr/local/${my_user}\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003ecreate symbolic link:\u003cbr\u003e\n\u003ccode\u003e# ln -s /usr/local/${my_user}/python $home/python\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cem\u003eOf course, replace \u003ccode\u003e${my_user}\u003c/code\u003e by your id!\u003c/em\u003e ;-)\u003c/p\u003e\n\u003cp\u003eIf you use \u003ccode\u003epipenv\u003c/code\u003e, you need to create a new folder and symlink; read the\n\u003ca href=\"/en/sys/openbsd/env-python-openbsd/#tldr\"\u003eTL;DR\u003c/a\u003e below.\u003c/p\u003e\n\u003ch2 id=\"tldr\"\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003eReplace \u003ccode\u003e${my_user}\u003c/code\u003e by your session id!\u003c/p\u003e\n\u003cp\u003e⇒ For \u003cstrong\u003evirtualenv\u003c/strong\u003e:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# mkdir -p /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/python\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# chown -R \u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e:wheel /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# ln -s /usr/local/\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003emy_user\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e/python \u003cspan style=\"color:#ef6155\"\u003e$home\u003c/span\u003e/python\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ For \u003cstrong\u003epipenv\u003c/strong\u003e, you need to add more:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ mkdir /usr/local/\u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e/python/virtualenvs\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ln -s /usr/local/\u003cspan style=\"color:#ef6155\"\u003e$USER\u003c/span\u003e/python/virtualenvs \u003cspan style=\"color:#ef6155\"\u003e$HOME\u003c/span\u003e/.local/share/virtualenvs\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003cstrong\u003epipenv\u003c/strong\u003e: \u003ca href=\"https://pipenv.readthedocs.io/en/latest/\" rel=\"external\"\u003ehttps://pipenv.readthedocs.io/en/latest/\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAbout the mount option \u003cstrong\u003ewxallowed\u003c/strong\u003e: \u003ca href=\"https://www.openbsd.org/faq/upgrade60.html\" rel=\"external\"\u003eEN\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"aknowledgements\"\u003eAknowledgements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThis article would not exists without \u003ca href=\"https://ybad.name/sdj.html\" rel=\"external\"\u003eXavier\u003c/a\u003e…\u003c/li\u003e\n\u003cli\u003eand, this other \u003ca href=\"https://deftly.net/posts/2017-10-12-using-cabal-on-openbsd.html\" rel=\"external\"\u003earticle\u003c/a\u003e: \u0026ldquo;\u003cem\u003e\u003cstrong\u003eUsing cabal on OpenBSD\u003c/strong\u003e\u003c/em\u003e\u0026rdquo;\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003chr\u003e\n","summary":"How to use virtuals environments Python on OpenBSD with W^X security.","tags":["Python","Environment","OpenBSD"],"date_published":"2019-06-19T12:03:33+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2019-05-02:/en/web/nextcloud/nextcloud-php-chroot","url":"https://it-log.fr.eu.org/en/web/nextcloud/nextcloud-php-chroot/","title":"(tip) Nextcloud PHP Chroot OpenBSD","author":{"name":"Stéphane HUC"},"content_text":"Error: Invalid data directory Under OpenBSD, Web service and PHP are under chroot. In fact, the command occ can not run!\nWhen you try, we get this message:\nYour data directory is invalid Ensure there is a file called \u0026#34;.ocdata\u0026#34; in the root of the data directory. Cannot create \u0026#34;data\u0026#34; directory This can usually be fixed by giving the webserver write access to the root directory. See https://docs.nextcloud.com/server/16/go.php?to=admin-dir_permissions To resolve this problem is very easy!\nEdit the file config nextcloud/config/config.php, to modify the value of datadirectory, as:\n'datadirectory' =\u0026gt; ((php_sapi_name() == 'cli') ? '/var/www' : '') . '/htdocs/data',\nOf course, the /htdocs/data directory must correspond to your real case.\nNow, you can use without problem the occ command.\nAfter, dont forget to delete yours modifications before going to the web interface, otherwise you will not to be able to connect!\nTL;DR KiSS:\nTo \u0026ldquo;enable\u0026rdquo; occ: sed -i -e 's#/htdocs#/var/www/htdocs#' nextcloud/config/config.php To \u0026ldquo;disable\u0026rdquo; occ: sed -i -e 's#/var/www/htdocs#/htdocs#' nextcloud/config/config.php Acknowledgement I would liket to thank @h3artbl33d who found this tips…\n","content_html":"\u003ch2 id=\"error-invalid-data-directory\"\u003eError: Invalid data directory\u003c/h2\u003e\n\u003cp\u003eUnder OpenBSD, Web service and PHP are under chroot. In fact, the command \u003ccode\u003eocc\u003c/code\u003e can not run!\u003c/p\u003e\n\u003cp\u003eWhen you try, we get this message:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eYour data directory is invalid\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eEnsure there is a file called \u003cspan style=\"color:#48b685\"\u003e\u0026#34;.ocdata\u0026#34;\u003c/span\u003e in the root of the data directory.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eCannot create \u003cspan style=\"color:#48b685\"\u003e\u0026#34;data\u0026#34;\u003c/span\u003e directory\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eThis can usually be fixed by giving the webserver write access to the root\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edirectory.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eSee https://docs.nextcloud.com/server/16/go.php?to\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003eadmin-dir_permissions\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e\u003cstrong\u003eTo resolve this problem is very easy!\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eEdit the file config \u003ccode\u003enextcloud/config/config.php\u003c/code\u003e, to modify the value of\n\u003ccode\u003edatadirectory\u003c/code\u003e, as:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e'datadirectory' =\u0026gt; ((php_sapi_name() == 'cli') ? '/var/www' : '') . '/htdocs/data',\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eOf course, the \u003ccode\u003e/htdocs/data\u003c/code\u003e directory must correspond to your real case.\u003c/p\u003e\n\u003cp\u003eNow, you can use without problem the \u003ccode\u003eocc\u003c/code\u003e command.\u003c/p\u003e\n\u003cp\u003eAfter, dont forget to delete yours modifications before going to the web\ninterface, otherwise you will not to be able to connect!\u003c/p\u003e\n\u003ch3 id=\"tldr\"\u003eTL;DR\u003c/h3\u003e\n\u003cp\u003eKiSS:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTo \u0026ldquo;enable\u0026rdquo; occ: \u003ccode\u003esed -i -e 's#/htdocs#/var/www/htdocs#' nextcloud/config/config.php\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eTo \u0026ldquo;disable\u0026rdquo; occ: \u003ccode\u003esed -i -e 's#/var/www/htdocs#/htdocs#' nextcloud/config/config.php\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"acknowledgement\"\u003eAcknowledgement\u003c/h2\u003e\n\u003cp\u003eI would liket to thank \u003ca href=\"https://chargen.one/h3artbl33d/fixing-nextcloud-on-openbsd-with-a-chroot\" rel=\"external\"\u003e@h3artbl33d\u003c/a\u003e\nwho found this tips…\u003c/p\u003e\n\u003chr\u003e\n","summary":"Howto resolve the problem for occ command Nextcloud, under chroot OpenBSD","tags":["Nextcloud","chroot","OpenBSD","tip"],"date_published":"2019-05-02T23:11:15+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2018-11-03:/en/sys/openbsd/smtpd-config-auth","url":"https://it-log.fr.eu.org/en/sys/openbsd/smtpd-config-auth/","title":"OpenBSD: configure smtpd.conf to auth email client (≥ v6.4)","author":{"name":"Stéphane HUC"},"content_text":"Description How to config your machine to send mail by terminal/console, on OpenBSD, on SMTP server with a required authentication?\nIntroduction OpenSMTPD is a free implementation of the SMTP protocol, as defined in RFC 5321 , with some additional standard extensions. It allows the machines to exchange mail.\nInformations:\nWebsite: https://www.opensmtpd.org OS: OpenBSD 6.4 → 7.8 Effectively tested with Gandi, and the association L\u0026rsquo;autre.net, and finally on my \u0026ldquo;owners\u0026rdquo; MX.\nInstallation Since OpenBSD 6.4, inton the base system, we have the new version of OpenSMTPD.\nTo start the service: :# rcctl start smtpd\nA small clarification on files:\nthe config file is: /etc/mail/smtpd.conf. the logfile is: /var/log/maillog. Configuration To send an email at one SMTP server require an authentication, as Gandi, it\u0026rsquo;s necessary to first create a secret file with the good rights on your system, and to set the config file.\nThe manpage show us on example:\nFile secrets Create the needed secret file: :# touch /etc/mail/secrets\nPut the secured rights:\n:# chmod 640 /etc/mail/secrets :# chown root:_smtpd /etc/mail/secrets Now, it\u0026rsquo;s necessary to write those informations: identifiant username:password Do Not Write TEXTUALLY this information , replace with:\nidentifiant: your choosed id — this will use later on your config file. (e.g.: as perso) username: usually, your email. password: the password for your email identification. WarningIt\u0026rsquo;s possible to (re?)name the secrets file as you want, and put in other place on your system.\nIt\u0026rsquo;s better put rights 0400 on this secrets file.\nEven, it\u0026rsquo;s possible for the service to access at your secrets file, with your personal rights as $USER:$USER, it\u0026rsquo;s better to put the right group _smtpd.\nFile smtpd.conf Now, we modify the config file /etc/mail/smtpd.conf.\n# $OpenBSD: smtpd.conf,v 1.14 2019/11/26 20:14:38 gilles Exp $ # This is the smtpd server system-wide configuration file. # See smtpd.conf(5) for more information. table aliases file:/etc/mail/aliases table secrets file:/etc/mail/secrets queue compression # To accept external mail, replace with: listen on all # ## add on 6.7 listen on socket listen on lo0 action \u0026#34;local_mail\u0026#34; mbox alias \u0026lt;aliases\u0026gt; action \u0026#34;unbound\u0026#34; relay host smtp+tls://identifiant@server auth \u0026lt;secrets\u0026gt; mail-from \u0026#34;@your-domain.tld\u0026#34; # Uncomment the following to accept external mail for domain \u0026#34;example.org\u0026#34; # # match from any for domain \u0026#34;example.org\u0026#34; action \u0026#34;local\u0026#34; ### 6.6 writings #match for local action \u0026#34;local_mail\u0026#34; #match for any action \u0026#34;unbound\u0026#34; ### 6.7 writings match from local for local action \u0026#34;local_mail\u0026#34; match from local for any action \u0026#34;outbound\u0026#34; Explainations\nSo compared to the original version, we added:\nthe line table secrets: it call the secrets file — write your custom filename. the line action unbound: to define the necessary action to send emails to the SMTP server. NOTE about identifiant@serveur: you have to replace the string identifiant by your created. (as wroted above: perso). and too, to replace the serveur by the name of SMTP server. the string smtp+tls is the used protocol to connect at the SMTP server. others protocols are: lmtp: to connect on a LMTP session. smtp: to attempt a connection with a STARTTLS session, if possible. smtp+tls: to force the connection on a STARTTLS session. smtp+notls: to use a plain text SMTP session without TLS. smtps: to force the connexion via TLS — default port: 465 with no specified protocol, the connection will be done on the default port: 25. the string auth: to specify the secret table. the string mail-from: to specify the domain name to use. the line match … action \u0026quot;relay\u0026quot;: this is the action that will be triggered to send the emails. Changes on 6.7 OpenBSD 6.7 makes minor syntax changes:\nadd listen on socket smtpd.conf(5)#listen~2 modification of match actions for the local queue manager smtpd.conf(5)#match : match from local for local action \u0026quot;local_mail\u0026quot; match from local for any action \u0026quot;outbound\u0026quot; \\ Changes on 6.6 The syntax of the action names has changed slightly between versions 6.4 and 6.6:\nlocal becomes local_mail relay becomes unbound aliases About aliases system:\nIt is interesting to manage the related alias root account or even that of your main user…\nEdit the file /etc/mail/aliases, with rights admin. At the end of file, modify root with your desired address email. Do the same for your system user. ;)\nAnd, do not forget to reload the aliases base, with the command newaliases!\nUtilisation WarningBefore restart the opensmtpd service, we need to test the config file: # smtpd -n \\\nIf the result is: configuration OK that\u0026rsquo;s folk!\nOtherwise, re-edit the file, at the line indicated first!\nNow, restart the service:\n# rcctl restart smtpd smtpd(ok) smtpd(ok) The log will display messages, as-is: Apr 3 07:17:05 sh1 smtpd[68810]: info: OpenSMTPD 7.0.0 starting\nToo, think to use the controller smtpctl… see the manpage smtpctl.8.\nSend So:\necho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; email or, echo \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; root For all cases, the log will display messages, as instance:\nApr 3 07:20:20 sh1 smtpd[56183]: 2cda1df4efff97f2 mta connecting address=smtp+tls://89.234.141.148:587 host=mail2.automario.eu Apr 3 07:20:20 sh1 smtpd[56183]: 2cda1df4efff97f2 mta connected Apr 3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta tls ciphers=TLSv1.3:AEAD-CHACHA20-POLY1305-SHA256:256 Apr 3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta cert-check result=\u0026#34;valid\u0026#34; fingerprint=\u0026#34;SHA256:17af91bcb27a530cc278cd8be90551593bee38ebaf6ade68053a508b14a8f817\u0026#34; Apr 3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta delivery evpid=4138560f4bd626cf from=\u0026lt;***@huc.fr.eu.org\u0026gt; to=\u0026lt;***@stephane-huc.net\u0026gt; rcpt=\u0026lt;-\u0026gt; source=\u0026#34;46.23.90.29\u0026#34; relay=\u0026#34;89.234.141.148 (mail2.automario.eu)\u0026#34; delay=1s result=\u0026#34;Ok\u0026#34; stat=\u0026#34;250 2.0.0 eb1a48cf Message accepted for delivery\u0026#34; Errors See, below, the possible commons errors:\nError: authentication failed Check again your username, password id wrote on your secret file!\nError: Cannot parse smarthost This message means the SMTP service can\u0026rsquo;t figure out the strings identifiant@serveur on your action rule.\nCheck your entries:\nyour string table secrets need to match with the good secret filename! your strings identifiant username:password in your secret file. have you replace correctly the string identifiant on the config file? too, for the string serveur: make sure the SMTP server name exists! Error: Sender address rejected: Domain not found This message means the SMTP service can\u0026rsquo;t match with the desired domain name.\nThe tips: use the param mail-from in your action rule, to target the good domain name, as: mail-from \u0026quot;@votre-domaine.tld\u0026quot; Do Not forget the symbol @.\nDocumentations The SMTP protocol is define by RFC 5321 :\nRFC 5321 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT Manpages smtpd.conf(5) , smtpctl(8) Others informations See the new changes syntaxe with the OpenSMTPD v6.4 ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eHow to config your machine to send mail by terminal/console, on OpenBSD,\non SMTP server with a required authentication?\u003c/strong\u003e\u003c/p\u003e\n\u003ch2 id=\"introduction\"\u003eIntroduction\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eOpenSMTPD\u003c/strong\u003e is a free implementation of the SMTP protocol, as\ndefined in \u003ca href=\"https://www.rfc-editor.org/info/rfc5321\" title=\"RFC Editor: Information on RFC 5321\"\u003eRFC 5321\u003c/a\u003e\n, with some additional standard extensions.\nIt allows the machines to exchange mail.\u003c/p\u003e\n\u003cp\u003eInformations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWebsite: \u003ca href=\"https://www.opensmtpd.org\" rel=\"external\"\u003ehttps://www.opensmtpd.org\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOS: OpenBSD \u003cdel\u003e6.4\u003c/del\u003e → \u003cstrong\u003e7.8\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cem\u003eEffectively tested with \u003ca href=\"https://gandi.net\" rel=\"external\"\u003eGandi\u003c/a\u003e, and the association \u003ca href=\"https://lautre.net\" rel=\"external\"\u003eL\u0026rsquo;autre.net\u003c/a\u003e,\nand finally on my \u0026ldquo;owners\u0026rdquo; MX\u003c/em\u003e.\u003c/p\u003e\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eSince OpenBSD 6.4, inton the base system, we have the new version of\nOpenSMTPD.\u003c/p\u003e\n\u003cp\u003eTo start the service: \u003ccode\u003e:# rcctl start smtpd\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eA small clarification on files:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe config file is: \u003ccode\u003e/etc/mail/smtpd.conf\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ethe logfile is: \u003ccode\u003e/var/log/maillog\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"configuration\"\u003eConfiguration\u003c/h2\u003e\n\u003cp\u003eTo send an email at one SMTP server require an authentication, as Gandi,\nit\u0026rsquo;s necessary to first create a secret file with the good rights on your\nsystem, and to set the config file.\u003c/p\u003e\n\u003cp\u003eThe manpage show us on \u003ca href=\"https://man.openbsd.org/smtpd.conf#EXAMPLES\" rel=\"external\"\u003eexample\u003c/a\u003e:\u003c/p\u003e\n\u003ch3 id=\"file-secrets\"\u003eFile secrets\u003c/h3\u003e\n\u003cp\u003eCreate the needed secret file: \u003ccode\u003e:# touch /etc/mail/secrets\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003ePut the secured rights:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# chmod \u003cspan style=\"color:#f99b15\"\u003e640\u003c/span\u003e /etc/mail/secrets\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# chown root:_smtpd /etc/mail/secrets\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eNow, it\u0026rsquo;s necessary to write those informations: \u003cbr\u003e\n\u003ccode\u003eidentifiant username:password\u003c/code\u003e \u003cbr\u003e\n\u003cspan class=\"red\"\u003eDo Not Write TEXTUALLY this information\u003c/span\u003e\n,\nreplace with:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eidentifiant\u003c/code\u003e: your choosed id — \u003cem\u003ethis will use later on your config file\u003c/em\u003e.\n\u003cem\u003e(e.g.: as \u003cstrong\u003eperso\u003c/strong\u003e)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eusername\u003c/code\u003e: usually, your email.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epassword\u003c/code\u003e: the password for your email identification.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eIt\u0026rsquo;s possible to (re?)name the secrets file as you want, and put in other\nplace on your system.\u003c/p\u003e\n\u003cp\u003eIt\u0026rsquo;s better put rights \u003ccode\u003e0400\u003c/code\u003e on this secrets file.\u003c/p\u003e\n\u003cp\u003eEven, it\u0026rsquo;s possible for the service to access at your secrets file, with\nyour personal rights as \u003ccode\u003e$USER:$USER\u003c/code\u003e, it\u0026rsquo;s better to put the right group\n\u003ccode\u003e_smtpd\u003c/code\u003e.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch3 id=\"file-smtpdconf\"\u003eFile \u003ccode\u003esmtpd.conf\u003c/code\u003e\u003c/h3\u003e\n\u003cp\u003eNow, we modify the config file \u003ccode\u003e/etc/mail/smtpd.conf\u003c/code\u003e.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#   $OpenBSD: smtpd.conf,v 1.14 2019/11/26 20:14:38 gilles Exp $\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# This is the smtpd server system-wide configuration file.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# See smtpd.conf(5) for more information.\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etable aliases file:/etc/mail/aliases\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003etable secrets file:/etc/mail/secrets\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003equeue compression\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# To accept external mail, replace with: listen on all\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e## add on 6.7\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elisten on socket\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003elisten on lo0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eaction \u0026#34;local_mail\u0026#34; mbox alias \u0026lt;aliases\u0026gt;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eaction \u0026#34;unbound\u0026#34; relay host smtp+tls://identifiant@server auth \u0026lt;secrets\u0026gt; mail-from \u0026#34;@your-domain.tld\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# Uncomment the following to accept external mail for domain \u0026#34;example.org\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# match from any for domain \u0026#34;example.org\u0026#34; action \u0026#34;local\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### 6.6 writings\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#match for local action \u0026#34;local_mail\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#match for any action \u0026#34;unbound\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e### 6.7 writings\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ematch from local for local action \u0026#34;local_mail\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003ematch from local for any action \u0026#34;outbound\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003eExplainations\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSo compared to the original version, we added:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe line \u003ccode\u003etable secrets\u003c/code\u003e: it call the secrets file\n— \u003cem\u003ewrite your custom filename\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003ethe line \u003ccode\u003eaction unbound\u003c/code\u003e: to define the necessary action to send emails\nto the SMTP server.\n\u003cul\u003e\n\u003cli\u003eNOTE about \u003ccode\u003eidentifiant@serveur\u003c/code\u003e:\n\u003cul\u003e\n\u003cli\u003eyou have to replace the string \u003ccode\u003eidentifiant\u003c/code\u003e by your created.\n\u003cem\u003e(as wroted above: \u003cstrong\u003eperso\u003c/strong\u003e)\u003c/em\u003e.\u003c/li\u003e\n\u003cli\u003eand too, to replace the \u003ccode\u003eserveur\u003c/code\u003e by the name of SMTP server.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ethe string \u003ca href=\"https://man.openbsd.org/smtpd.conf#host\" rel=\"external\"\u003e\u003ccode\u003esmtp+tls\u003c/code\u003e\u003c/a\u003e is\nthe used protocol to connect at the SMTP server. \u003cbr\u003e\nothers protocols are:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elmtp\u003c/code\u003e: to connect on a\n\u003cabbr title=\"Local Mail Transfer Protocol\"\u003eLMTP\u003c/abbr\u003e\n session.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp\u003c/code\u003e: to attempt a connection with a STARTTLS session, if\npossible.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp+tls\u003c/code\u003e: to force the connection on a STARTTLS session.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtp+notls\u003c/code\u003e: to use a plain text SMTP session without TLS.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003esmtps\u003c/code\u003e: to force the connexion via\n\u003cabbr title=\"Transport Layer Secure\"\u003eTLS\u003c/abbr\u003e\n\n— \u003cem\u003edefault port: 465\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003ewith no specified protocol, the connection will be done on the\ndefault port: 25.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ethe string \u003ca href=\"https://man.openbsd.org/smtpd.conf#auth\" rel=\"external\"\u003e\u003ccode\u003eauth\u003c/code\u003e\u003c/a\u003e: to\nspecify the secret table.\u003c/li\u003e\n\u003cli\u003ethe string \u003ca href=\"https://man.openbsd.org/smtpd.conf#mail_-from\" rel=\"external\"\u003e\u003ccode\u003email-from\u003c/code\u003e\u003c/a\u003e:\nto specify the domain name to use.\u003c/li\u003e\n\u003cli\u003ethe line \u003ccode\u003ematch … action \u0026quot;relay\u0026quot;\u003c/code\u003e: this is the action that will be\ntriggered to send the emails.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"changes-on-67\"\u003eChanges on 6.7\u003c/h4\u003e\n\u003cp\u003eOpenBSD 6.7 makes minor syntax changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003elisten on socket\u003c/code\u003e \u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/smtpd.conf.5#listen~2\" title=\"OpenBSD Manual Page Server for: smtpd.conf\"\u003esmtpd.conf(5)#listen~2\u003c/a\u003e\n\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003emodification of match actions for the \u003cstrong\u003elocal\u003c/strong\u003e queue manager\n\u003cem\u003e\n\u003ca class=\"\" href=\"https://man.openbsd.org/smtpd.conf.5#match\" title=\"OpenBSD Manual Page Server for: smtpd.conf\"\u003esmtpd.conf(5)#match\u003c/a\u003e\n\u003c/em\u003e: \u003cbr\u003e\n\u003ccode\u003ematch from local for local action \u0026quot;local_mail\u0026quot;\u003c/code\u003e \u003cbr\u003e\n\u003ccode\u003ematch from local for any action \u0026quot;outbound\u0026quot;\u003c/code\u003e \\\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"changes-on-66\"\u003eChanges on 6.6\u003c/h4\u003e\n\u003cp\u003eThe syntax of the action names has changed slightly between versions 6.4\nand 6.6:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003elocal\u003c/code\u003e becomes \u003ccode\u003elocal_mail\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erelay\u003c/code\u003e becomes \u003ccode\u003eunbound\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"aliases\"\u003ealiases\u003c/h3\u003e\n\u003cp\u003eAbout aliases system:\u003c/p\u003e\n\u003cp\u003eIt is interesting to manage the related alias \u003ccode\u003eroot\u003c/code\u003e account or\neven that of your main user…\u003c/p\u003e\n\u003cp\u003eEdit the file \u003ccode\u003e/etc/mail/aliases\u003c/code\u003e, with rights admin. \u003cbr\u003e\nAt the end of file, modify \u003ccode\u003eroot\u003c/code\u003e with your desired address email. \u003cbr\u003e\nDo the same for your system user. ;)\u003c/p\u003e\n\u003cp\u003eAnd, do not forget to reload the aliases base, with the command\n\u003ccode\u003enewaliases\u003c/code\u003e!\u003c/p\u003e\n\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eBefore restart the \u003cstrong\u003eopensmtpd\u003c/strong\u003e service, we need to test the config file:\n\u003cbr\u003e \u003ccode\u003e# smtpd -n\u003c/code\u003e \\\u003c/p\u003e\n\u003cp\u003eIf the result is: \u003ccode\u003econfiguration OK\u003c/code\u003e \u003cbr\u003e\nthat\u0026rsquo;s folk!\u003c/p\u003e\n\u003cp\u003eOtherwise, re-edit the file, at the line indicated first!\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003eNow, restart the service:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# rcctl restart smtpd\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esmtpd\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eok\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003esmtpd\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eok\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe log will display messages, as-is: \u003cbr\u003e\n\u003ccode\u003eApr  3 07:17:05 sh1 smtpd[68810]: info: OpenSMTPD 7.0.0 starting\u003c/code\u003e\u003c/p\u003e\n\u003cp\u003eToo, think to use the controller \u003ccode\u003esmtpctl\u003c/code\u003e… see the manpage \u003cstrong\u003esmtpctl.8\u003c/strong\u003e.\u003c/p\u003e\n\u003ch3 id=\"send\"\u003eSend\u003c/h3\u003e\n\u003cp\u003eSo:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eecho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; email\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eor, \u003ccode\u003eecho \u0026quot;Test to send email on $(hostname); date: $(date)\u0026quot; | mail -s \u0026quot;Email test\u0026quot; root\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFor all cases, the log will display messages, as instance:\u003c/p\u003e\n\u003cpre tabindex=\"0\"\u003e\u003ccode class=\"language-log\" data-lang=\"log\"\u003eApr  3 07:20:20 sh1 smtpd[56183]: 2cda1df4efff97f2 mta connecting address=smtp+tls://89.234.141.148:587 host=mail2.automario.eu\nApr  3 07:20:20 sh1 smtpd[56183]: 2cda1df4efff97f2 mta connected\nApr  3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta tls ciphers=TLSv1.3:AEAD-CHACHA20-POLY1305-SHA256:256\nApr  3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta cert-check result=\u0026#34;valid\u0026#34; fingerprint=\u0026#34;SHA256:17af91bcb27a530cc278cd8be90551593bee38ebaf6ade68053a508b14a8f817\u0026#34;\nApr  3 07:20:21 sh1 smtpd[56183]: 2cda1df4efff97f2 mta delivery evpid=4138560f4bd626cf from=\u0026lt;***@huc.fr.eu.org\u0026gt; to=\u0026lt;***@stephane-huc.net\u0026gt; rcpt=\u0026lt;-\u0026gt; source=\u0026#34;46.23.90.29\u0026#34; relay=\u0026#34;89.234.141.148 (mail2.automario.eu)\u0026#34; delay=1s result=\u0026#34;Ok\u0026#34; stat=\u0026#34;250 2.0.0 eb1a48cf Message accepted for delivery\u0026#34;\n\u003c/code\u003e\u003c/pre\u003e\u003ch2 id=\"errors\"\u003eErrors\u003c/h2\u003e\n\u003cp\u003eSee, below, the possible commons errors:\u003c/p\u003e\n\u003ch3 id=\"error-authentication-failed\"\u003eError: authentication failed\u003c/h3\u003e\n\u003cp\u003eCheck again your \u003ccode\u003eusername\u003c/code\u003e, \u003ccode\u003epassword\u003c/code\u003e id wrote on your\n\u003ca href=\"/en/sys/openbsd/smtpd-config-auth/#file-secrets\"\u003esecret file\u003c/a\u003e!\u003c/p\u003e\n\u003ch3 id=\"error-cannot-parse-smarthost\"\u003eError: Cannot parse smarthost\u003c/h3\u003e\n\u003cp\u003eThis message means the SMTP service can\u0026rsquo;t figure out the strings \u003ccode\u003eidentifiant@serveur\u003c/code\u003e\non your action rule.\u003c/p\u003e\n\u003cp\u003eCheck your entries:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eyour string \u003ccode\u003etable secrets\u003c/code\u003e need to match with the good secret filename!\u003c/li\u003e\n\u003cli\u003eyour strings \u003ccode\u003eidentifiant username:password\u003c/code\u003e in your secret file.\u003c/li\u003e\n\u003cli\u003ehave you replace correctly the string \u003ccode\u003eidentifiant\u003c/code\u003e on the config file?\u003c/li\u003e\n\u003cli\u003etoo, for the string \u003ccode\u003eserveur\u003c/code\u003e: make sure the SMTP server name exists!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"error-sender-address-rejected-domain-not-found\"\u003eError: Sender address rejected: Domain not found\u003c/h3\u003e\n\u003cp\u003eThis message means the SMTP service can\u0026rsquo;t match with the desired domain name.\u003c/p\u003e\n\u003cp\u003eThe tips: use the param \u003ca href=\"https://man.openbsd.org/smtpd.conf#mail_-from\" rel=\"external\"\u003email-from\u003c/a\u003e in\nyour action rule, to target the good domain name, as:  \u003cbr\u003e\n\u003ccode\u003email-from \u0026quot;@votre-domaine.tld\u0026quot;\u003c/code\u003e \u003cbr\u003e\n\u003cstrong\u003eDo Not forget the symbol \u003ccode\u003e@\u003c/code\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cp\u003eThe SMTP protocol is define by RFC 5321 :\u003c/p\u003e\n\n\u003ch3 id=\"rfc-5321\"\u003eRFC 5321\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc5321\" title=\"RFC 5321: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc5321\" title=\"RFC 5321: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc5321.txt\" title=\"RFC 5321: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5321.html\" title=\"RFC 5321: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc5321.txt.pdf\" title=\"RFC 5321: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5321.txt\" title=\"RFC 5321: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\u003ch3 id=\"manpages\"\u003eManpages\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/smtpd.conf.5\" title=\"OpenBSD Manual Page Server for: smtpd.conf\"\u003esmtpd.conf(5)\u003c/a\u003e\n, \n\u003ca class=\"man\" href=\"https://man.openbsd.org/smtpctl.8\" title=\"OpenBSD Manual Page Server for: smtpctl\"\u003esmtpctl(8)\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"others-informations\"\u003eOthers informations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://www.openbsd.org/faq/upgrade64.html\" rel=\"external\"\u003enew changes syntaxe with the OpenSMTPD v6.4\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003chr\u003e\n","summary":"Howto config the SMTPD service for a required authentication mail on OpenBSD (≥ v6.4)","tags":["OpenBSD","smtpd","auth","client","mail"],"date_published":"2018-11-03T21:38:54+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2018-03-22:/en/sys/openbsd/stubby","url":"https://it-log.fr.eu.org/en/sys/openbsd/stubby/","title":"Stubby: DoT DNS client on OpenBSD (EXPERIMENTAL) ","author":{"name":"Stéphane HUC"},"content_text":"Description Stubby is a DNS client, using secure protocol (DoT ). This encrypts DNS queries sent from your machine to a DNS resolver, or an authoritative DNS server to increase the confidentiality. It can request queries according DNSSEC protocol, too.\nWarningWarning: it does not act as DNS cache resolver, nor as an authoritative DNS server; it\u0026rsquo;s only a DNS client!\nIn addition, there is no package, nor port on OpenBSD stable. Hence is the reason of title \u0026ldquo;EXPERIMENTAL\u0026rdquo;. We\u0026rsquo;re going to retrieve sources, compil, install and configure them.\nInstallation The stubby client is/will be installed on OpenBSD stable.\nat this day, now: 6.3 Prerequisite OpenSSL : install by default Libyaml : to install… autoconf, automake : to install to configure, and build before installation. :# pkg_add autoconf automake libyaml quirks-2.414 signed on 2018-03-28T14:24:37Z Ambiguous: choose package for autoconf a 0: \u0026lt;None\u0026gt; 1: autoconf-2.13p4 2: autoconf-2.52p6 3: autoconf-2.54p5 4: autoconf-2.56p4 5: autoconf-2.57p4 6: autoconf-2.58p5 7: autoconf-2.59p5 8: autoconf-2.60p5 9: autoconf-2.61p5 10: autoconf-2.62p2 11: autoconf-2.63p1 12: autoconf-2.64p1 13: autoconf-2.65p1 14: autoconf-2.67p1 15: autoconf-2.68p1 16: autoconf-2.69p2 Your choice: 16 Ambiguous: choose package for automake a 0: \u0026lt;None\u0026gt; 1: automake-1.10.3p8 2: automake-1.11.6p2 3: automake-1.12.6p1 4: automake-1.13.4p1 5: automake-1.14.1p0 6: automake-1.15.1 7: automake-1.4.6p5 8: automake-1.8.5p9 9: automake-1.9.6p12 Your choice: 6 Then, we will follow the official installation recommandations from sources, by adapting them to OpenBSD, step by step.\nDownload :$ git clone https://github.com/getdnsapi/getdns.git :$ cd getdns :$ git checkout develop The second command git permits us to get/obtain the most recent sources .\nConfiguration :$ git submodule update --init :$ libtoolize -ci :$ export AUTOCONF_VERSION=2.69 :$ export AUTOMAKE_VERSION=1.15 :$ autoreconf -fi :$ mkdir build \u0026amp;\u0026amp; cd build :$ ../configure --prefix=/usr/local --without-libidn --enable-stub-only --with-stubby Compilation `:$ make `:# make install Of course, if you had configured doas , you can executed the ultimate command, as:\n:$ doas make install\nresolv.conf It\u0026rsquo;s necessary to modify your /etc/resolv.conf file in order to communicate directly with stubby:\nnameserver 127.0.0.1 nameserver ::1 stubby.yml The stubby\u0026rsquo;s configuration file is: /usr/local/etc/stubby/stubby.yml.\nYou can create your personal, as ~/.stubby.yml. It will be read in first.\nExecution To execute stubby, run as:\n:# stubby [12:57:39.896254] STUBBY: Read config from file /usr/local/etc/stubby/stubby.yml [12:57:39.898479] STUBBY: DNSSEC Validation is OFF [12:57:39.898585] STUBBY: Transport list is: [12:57:39.898617] STUBBY: - TLS [12:57:39.898681] STUBBY: Privacy Usage Profile is Strict (Authentication required) [12:57:39.898713] STUBBY: (NOTE a Strict Profile only applies when TLS is the ONLY transport!!) [12:57:39.898749] STUBBY: Starting DAEMON.... Some interesting informations, about flags:\n-C: to specify other configuration file. -g: to run in background mode. -i: to check the configuration! -l: to log. Actually, the output is only on the standard stdout! Test We use dig:\n⇒ IPv4:\n:$ dig @127.0.0.1 www.gandi.net ; \u0026lt;\u0026lt;\u0026gt;\u0026gt; DiG 9.4.2-P2 \u0026lt;\u0026lt;\u0026gt;\u0026gt; @127.0.0.1 www.gandi.net ; (1 server found) ;; global options: printcmd ;; Got answer: ;; -\u0026gt;\u0026gt;HEADER\u0026lt;\u0026lt;- opcode: QUERY, status: NOERROR, id: 40041 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: 0 ;; QUESTION SECTION: ;www.gandi.net. IN A ;; ANSWER SECTION: www.gandi.net. 21583 IN CNAME prod.gandi.map.fastly.net. prod.gandi.map.fastly.net. 3600 IN A 151.101.37.103 ;; AUTHORITY SECTION: fastly.net. 3600 IN NS ns1.fastly.net. fastly.net. 3600 IN NS ns2.fastly.net. fastly.net. 3600 IN NS ns3.fastly.net. fastly.net. 3600 IN NS ns4.fastly.net. ;; Query time: 1888 msec ;; SERVER: 127.0.0.1#53(127.0.0.1) ;; WHEN: Thu Mar 22 14:15:51 2018 ;; MSG SIZE rcvd: 155 ⇒ IPv6:\n:$ dig @::1 www.gandi.net ; \u0026lt;\u0026lt;\u0026gt;\u0026gt; DiG 9.4.2-P2 \u0026lt;\u0026lt;\u0026gt;\u0026gt; @::1 www.gandi.net ; (1 server found) ;; global options: printcmd ;; Got answer: ;; -\u0026gt;\u0026gt;HEADER\u0026lt;\u0026lt;- opcode: QUERY, status: NOERROR, id: 24688 ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: 4 ;; QUESTION SECTION: ;www.gandi.net. IN A ;; ANSWER SECTION: www.gandi.net. 84574 IN CNAME prod.gandi.map.fastly.net. prod.gandi.map.fastly.net. 3600 IN A 151.101.85.103 ;; AUTHORITY SECTION: fastly.net. 168207 IN NS ns4.fastly.net. fastly.net. 168207 IN NS ns2.fastly.net. fastly.net. 168207 IN NS ns1.fastly.net. fastly.net. 168207 IN NS ns3.fastly.net. ;; ADDITIONAL SECTION: ns1.fastly.net. 3600 IN A 23.235.32.32 ns2.fastly.net. 3600 IN A 104.156.80.32 ns3.fastly.net. 3600 IN A 23.235.36.32 ns4.fastly.net. 3600 IN A 104.156.84.32 ;; Query time: 1614 msec ;; SERVER: ::1#53(::1) ;; WHEN: Thu Mar 22 14:16:40 2018 ;; MSG SIZE rcvd: 219 ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/getdnsapi/stubby\" rel=\"external\"\u003eStubby\u003c/a\u003e is a DNS client, using secure\nprotocol \u003cem\u003e(\u003cabbr title=\"DNS-over-TLS\"\u003eDoT\u003c/abbr\u003e\n)\u003c/em\u003e.\nThis encrypts DNS queries sent from your machine to a DNS resolver, or an\nauthoritative DNS server to increase the confidentiality.\nIt can request queries according DNSSEC protocol, too.\u003c/p\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003eWarning: it does not act as DNS cache resolver, nor as an authoritative DNS\nserver; it\u0026rsquo;s only a DNS client!\u003c/p\u003e\n\u003cp\u003eIn addition, there is no package, nor port on OpenBSD stable.\nHence is the reason of title \u0026ldquo;EXPERIMENTAL\u0026rdquo;. We\u0026rsquo;re going to retrieve sources,\ncompil, install and configure them.\u003c/p\u003e\n\u003c/div\u003e\n\n\u003ch2 id=\"installation\"\u003eInstallation\u003c/h2\u003e\n\u003cp\u003eThe \u003cstrong\u003estubby\u003c/strong\u003e client is/will be installed on OpenBSD stable.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eat this day, now: 6.3\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"prerequisite\"\u003ePrerequisite\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eOpenSSL\u003c/code\u003e : install by default\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eLibyaml\u003c/code\u003e : to install…\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautoconf\u003c/code\u003e, \u003ccode\u003eautomake\u003c/code\u003e : to install to configure, and build before installation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# pkg_add autoconf automake libyaml\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003equirks-2.414 signed on 2018-03-28T14:24:37Z\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAmbiguous: choose package \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e autoconf\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ea       0: \u0026lt;None\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        1: autoconf-2.13p4\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        2: autoconf-2.52p6\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        3: autoconf-2.54p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        4: autoconf-2.56p4\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        5: autoconf-2.57p4\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        6: autoconf-2.58p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        7: autoconf-2.59p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        8: autoconf-2.60p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        9: autoconf-2.61p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        10: autoconf-2.62p2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        11: autoconf-2.63p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        12: autoconf-2.64p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        13: autoconf-2.65p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        14: autoconf-2.67p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        15: autoconf-2.68p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        16: autoconf-2.69p2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eYour choice: \u003cspan style=\"color:#f99b15\"\u003e16\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eAmbiguous: choose package \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e automake\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ea       0: \u0026lt;None\u0026gt;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        1: automake-1.10.3p8\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        2: automake-1.11.6p2\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        3: automake-1.12.6p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        4: automake-1.13.4p1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        5: automake-1.14.1p0\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        6: automake-1.15.1\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        7: automake-1.4.6p5\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        8: automake-1.8.5p9\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        9: automake-1.9.6p12\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eYour choice: \u003cspan style=\"color:#f99b15\"\u003e6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThen, we will follow the official installation recommandations from \u003ca href=\"https://dnsprivacy.org/wiki/pages/viewpage.action?pageId=3145786\" rel=\"external\"\u003esources\u003c/a\u003e, by adapting them to OpenBSD, step by step.\u003c/p\u003e\n\u003ch3 id=\"download\"\u003eDownload\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ git clone https://github.com/getdnsapi/getdns.git\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ cd getdns\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ git checkout develop\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eThe second command \u003ccode\u003egit\u003c/code\u003e permits us to get/obtain the most recent sources .\u003c/p\u003e\n\u003ch3 id=\"configuration\"\u003eConfiguration\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ git submodule update --init\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ libtoolize -ci\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ export \u003cspan style=\"color:#ef6155\"\u003eAUTOCONF_VERSION\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e2.69\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ export \u003cspan style=\"color:#ef6155\"\u003eAUTOMAKE_VERSION\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e1.15\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ autoreconf -fi\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ mkdir build \u003cspan style=\"color:#5bc4bf\"\u003e\u0026amp;\u0026amp;\u003c/span\u003e cd build\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ ../configure --prefix\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e/usr/local --without-libidn --enable-stub-only --with-stubby\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"compilation\"\u003eCompilation\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003e:$ make\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#48b685\"\u003e`\u003c/span\u003e:# make install\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eOf course, if you had configured \u003cem\u003e\n\u003ca class=\"man\" href=\"https://man.openbsd.org/doas\" title=\"OpenBSD Manual Page Server for: doas\"\u003edoas\u003c/a\u003e\n\u003c/em\u003e, you can executed the\nultimate command, as:\u003cbr\u003e\n\u003ccode\u003e:$ doas make install\u003c/code\u003e\u003c/p\u003e\n\u003ch3 id=\"resolvconf\"\u003eresolv.conf\u003c/h3\u003e\n\u003cp\u003eIt\u0026rsquo;s necessary to modify your \u003ccode\u003e/etc/resolv.conf\u003c/code\u003e file in order to communicate\ndirectly with stubby:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003enameserver 127.0.0.1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003enameserver ::1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"stubbyyml\"\u003estubby.yml\u003c/h3\u003e\n\u003cp\u003eThe stubby\u0026rsquo;s configuration file is: \u003ccode\u003e/usr/local/etc/stubby/stubby.yml\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eYou can create your personal, as \u003ccode\u003e~/.stubby.yml\u003c/code\u003e. It will be read in first.\u003c/p\u003e\n\u003ch2 id=\"execution\"\u003eExecution\u003c/h2\u003e\n\u003cp\u003eTo execute \u003cstrong\u003estubby\u003c/strong\u003e, run as:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:# stubby\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.896254\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: Read config from file /usr/local/etc/stubby/stubby.yml\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898479\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: DNSSEC Validation is OFF\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898585\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: Transport list is:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898617\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY:   - TLS\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898681\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: Privacy Usage Profile is Strict \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eAuthentication required\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898713\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003eNOTE a Strict Profile only applies when TLS is the ONLY transport!!\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e12:57:39.898749\u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e STUBBY: Starting DAEMON....\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003eSome interesting informations, about flags:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e-C\u003c/code\u003e: to specify other configuration file.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-g\u003c/code\u003e: to run in background mode.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-i\u003c/code\u003e: to check the configuration!\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-l\u003c/code\u003e: to log. Actually, the output is only on the standard \u003ccode\u003estdout\u003c/code\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"test\"\u003eTest\u003c/h3\u003e\n\u003cp\u003eWe use \u003ccode\u003edig\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e⇒ IPv4:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ dig @127.0.0.1 www.gandi.net\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e; \u0026lt;\u0026lt;\u0026gt;\u0026gt; DiG 9.4.2-P2 \u0026lt;\u0026lt;\u0026gt;\u0026gt; @127.0.0.1 www.gandi.net\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e; \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e server found\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; global options:  printcmd\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; Got answer:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; -\u0026gt;\u0026gt;HEADER\u003cspan style=\"color:#48b685\"\u003e\u0026lt;\u0026lt;- opco\u003c/span\u003ede: QUERY, status: NOERROR, id: \u003cspan style=\"color:#f99b15\"\u003e40041\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; QUESTION SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;www.gandi.net.                 IN      A\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; ANSWER SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww.gandi.net.          \u003cspan style=\"color:#f99b15\"\u003e21583\u003c/span\u003e   IN      CNAME   prod.gandi.map.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprod.gandi.map.fastly.net. \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e IN      A       151.101.37.103\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; AUTHORITY SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      NS      ns1.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      NS      ns2.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      NS      ns3.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      NS      ns4.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; Query time: \u003cspan style=\"color:#f99b15\"\u003e1888\u003c/span\u003e msec\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; SERVER: 127.0.0.1#53\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e127.0.0.1\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; WHEN: Thu Mar \u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e 14:15:51 \u003cspan style=\"color:#f99b15\"\u003e2018\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; MSG SIZE  rcvd: \u003cspan style=\"color:#f99b15\"\u003e155\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003cp\u003e⇒ IPv6:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e:$ dig @::1 www.gandi.net\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e; \u0026lt;\u0026lt;\u0026gt;\u0026gt; DiG 9.4.2-P2 \u0026lt;\u0026lt;\u0026gt;\u0026gt; @::1 www.gandi.net\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e; \u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e server found\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; global options:  printcmd\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; Got answer:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; -\u0026gt;\u0026gt;HEADER\u003cspan style=\"color:#48b685\"\u003e\u0026lt;\u0026lt;- opco\u003c/span\u003ede: QUERY, status: NOERROR, id: \u003cspan style=\"color:#f99b15\"\u003e24688\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; QUESTION SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;www.gandi.net.                 IN      A\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; ANSWER SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ewww.gandi.net.          \u003cspan style=\"color:#f99b15\"\u003e84574\u003c/span\u003e   IN      CNAME   prod.gandi.map.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eprod.gandi.map.fastly.net. \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e IN      A       151.101.85.103\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; AUTHORITY SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e168207\u003c/span\u003e  IN      NS      ns4.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e168207\u003c/span\u003e  IN      NS      ns2.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e168207\u003c/span\u003e  IN      NS      ns1.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003efastly.net.             \u003cspan style=\"color:#f99b15\"\u003e168207\u003c/span\u003e  IN      NS      ns3.fastly.net.\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; ADDITIONAL SECTION:\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ens1.fastly.net.         \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      A       23.235.32.32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ens2.fastly.net.         \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      A       104.156.80.32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ens3.fastly.net.         \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      A       23.235.36.32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ens4.fastly.net.         \u003cspan style=\"color:#f99b15\"\u003e3600\u003c/span\u003e    IN      A       104.156.84.32\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; Query time: \u003cspan style=\"color:#f99b15\"\u003e1614\u003c/span\u003e msec\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; SERVER: ::1#53\u003cspan style=\"color:#5bc4bf\"\u003e(\u003c/span\u003e::1\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; WHEN: Thu Mar \u003cspan style=\"color:#f99b15\"\u003e22\u003c/span\u003e 14:16:40 \u003cspan style=\"color:#f99b15\"\u003e2018\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e;; MSG SIZE  rcvd: \u003cspan style=\"color:#f99b15\"\u003e219\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n","summary":"Stubby installation experimentation, a DoT and DNSSEC client, on OpenBSD (6.3).","tags":["OpenBSD","stubby","experimental","DNS","DoT","DNSSEC"],"date_published":"2018-03-22T14:21:09+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2017-07-29:/en/dev/bash/function-array-key-exists","url":"https://it-log.fr.eu.org/en/dev/bash/function-array-key-exists/","title":"Bash: function array_key_exists()","author":{"name":"Stéphane HUC"},"content_text":"Description array_key_exists(): check if key exists into array!\nEquivalent to the PHP Function PHP array_key_exists()\nSource Code function array_key_exists() { # equivalent to PHP array_key_exists # call: array_key_exists key array local key=\u0026#34;$1\u0026#34; IFS=\u0026#34; \u0026#34;; shift; read -a array \u0026lt;\u0026lt;\u0026lt; \u0026#34;$@\u0026#34; if [[ \u0026#34;${array[$key]}\u0026#34; ]]; then return 0; else return 1; fi unset array key IFS } Parameters key is the searched key haystack is the array where to search Return Values Returns 0 if the key found into haystack; considere this value as TRUE Otherwise, returns 1: considere this value as FALSE Example declare -a color=(\u0026#34;blue\u0026#34;, \u0026#34;red\u0026#34;, \u0026#34;green\u0026#34;, \u0026#34;grey\u0026#34;); key=1 if array_key_exists \u0026#34;${key}\u0026#34; \u0026#34;${color[@]}\u0026#34;; then echo \u0026#34;key: ${key} exists!\u0026#34; else echo \u0026#34;This key: ${key} not exists!\u0026#34; fi ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003earray_key_exists()\u003c/code\u003e: check if key exists into array!\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eEquivalent to the PHP Function \u003ca href=\"http://php.net/manual/en/function.array-key-exists.php\" rel=\"external\"\u003ePHP array_key_exists\u003c/a\u003e()\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"source-code\"\u003eSource Code\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e array_key_exists\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   \u003cspan style=\"color:#776e71\"\u003e# equivalent to PHP array_key_exists\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   \u003cspan style=\"color:#776e71\"\u003e# call: array_key_exists key array\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   local \u003cspan style=\"color:#ef6155\"\u003ekey\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eIFS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; \u0026#34;\u003c/span\u003e; shift; read -a array \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u0026lt;\u0026lt;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$@\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003earray\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$key\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e 0; \u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e 1; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   unset array key IFS\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"parameters\"\u003eParameters\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ekey\u003c/code\u003e is the searched key\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ehaystack\u003c/code\u003e is the array where to search\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"return-values\"\u003eReturn Values\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturns \u003ccode\u003e0\u003c/code\u003e if the \u003ccode\u003ekey\u003c/code\u003e found into \u003ccode\u003ehaystack\u003c/code\u003e; considere this value as \u003ccode\u003eTRUE\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eOtherwise, returns \u003ccode\u003e1\u003c/code\u003e: considere this value as \u003ccode\u003eFALSE\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"example\"\u003eExample\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edeclare -a \u003cspan style=\"color:#ef6155\"\u003ecolor\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=(\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;blue\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;red\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;green\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;grey\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003ekey\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e array_key_exists \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ekey\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecolor\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;key: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ekey\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e exists!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e   echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;This key: \u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ekey\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e not exists!\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n","summary":"Function bash array_key_exists(), equivalent to PHP","tags":["Bash","array"],"date_published":"2017-07-29T18:56:36+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2017-07-29:/en/dev/bash/function-array-search","url":"https://it-log.fr.eu.org/en/dev/bash/function-array-search/","title":"Bash : function array_search()","author":{"name":"Stéphane HUC"},"content_text":"Description array_search(): Searches the array for a given value and returns the corresponding key if successful\nEquivalent to the PHP array_search function.\nSource Code function array_search() { # equivalent to PHP array_search # call: array_search needle array local needle=\u0026#34;$1\u0026#34; IFS=\u0026#34; \u0026#34;; shift; read -a array \u0026lt;\u0026lt;\u0026lt; \u0026#34;$@\u0026#34; for (( i=0; i \u0026lt; ${#array[*]}; i++ )); do if [[ \u0026#34;${array[$i]}\u0026#34; == \u0026#34;${needle}\u0026#34; ]]; then echo \u0026#34;$i\u0026#34;; fi done return 1 unset array needle IFS } Parameters needle is the searched value haystack is the array where to search Return Values Returns the key for needle, if is found into the array haystack Otherwise, returns 1: considere this value as FALSE. Example declare -a color=(\u0026#34;blue\u0026#34;, \u0026#34;red\u0026#34;, \u0026#34;green\u0026#34;, \u0026#34;grey\u0026#34;); echo \u0026#34;$(array_search \u0026#34;red\u0026#34; \u0026#34;${color[@]}\u0026#34;)\u0026#34; ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003earray_search()\u003c/code\u003e: Searches the array for a given value and returns the\ncorresponding key if successful\u003c/p\u003e\n\u003cp\u003e\u003cem\u003eEquivalent to the\n\u003ca href=\"http://php.net/manual/en/function.array-search.php\" rel=\"external\"\u003ePHP array_search\u003c/a\u003e function.\u003c/em\u003e\u003c/p\u003e\n\u003ch2 id=\"source-code\"\u003eSource Code\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e array_search\u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# equivalent to PHP array_search\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e# call: array_search needle array\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    local \u003cspan style=\"color:#ef6155\"\u003eneedle\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003eIFS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34; \u0026#34;\u003c/span\u003e; shift; read -a array \u003cspan style=\"color:#5bc4bf\"\u003e\u0026lt;\u0026lt;\u0026lt;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$@\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e0; i \u0026lt; \u003cspan style=\"color:#f99b15\"\u003e${#\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003earray\u003c/span\u003e[*]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e; i++ \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e        \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[[\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003earray\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eneedle\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ereturn\u003c/span\u003e \u003cspan style=\"color:#f99b15\"\u003e1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unset array needle IFS\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"parameters\"\u003eParameters\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eneedle\u003c/code\u003e is the searched value\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ehaystack\u003c/code\u003e is the array where to search\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"return-values\"\u003eReturn Values\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReturns the key for \u003ccode\u003eneedle\u003c/code\u003e, if is found into the array \u003ccode\u003ehaystack\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eOtherwise, returns \u003ccode\u003e1\u003c/code\u003e: considere this value as \u003ccode\u003eFALSE\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"example\"\u003eExample\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edeclare -a \u003cspan style=\"color:#ef6155\"\u003ecolor\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=(\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;blue\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;red\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;green\u0026#34;\u003c/span\u003e, \u003cspan style=\"color:#48b685\"\u003e\u0026#34;grey\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eecho \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e$(\u003c/span\u003earray_search \u003cspan style=\"color:#48b685\"\u003e\u0026#34;red\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ecolor\u003c/span\u003e[@]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#815ba4\"\u003e)\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003chr\u003e\n","summary":"Function bash array_search(), equivalent to PHP","tags":["Bash","array"],"date_published":"2017-07-29T18:19:29+01:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2017-07-26:/en/sec/firewall/linux-firewall-icmpv6","url":"https://it-log.fr.eu.org/en/sec/firewall/linux-firewall-icmpv6/","title":"Linux: firewall ICMPv6","author":{"name":"Stéphane HUC"},"content_text":"Description Filtering ICMPv6 on Linux!\nA few hours ago, I wrote this other article… now, it\u0026rsquo;s time to discuss about the filtering measures to be put in place around ICMPv6.\nI am not going to remind you why this protocol exists, nor the fact that it can be dangerous if misused; and, of course, unfortunately there will always be people who misuse it!\nManage ICMPv6 Refuse As a precaution, it is advisable to filter out all experimental codes, such as 100, 101, 200, and 201, as well as codes reserved for the future, namely codes 127 and 255.\nIt is recommended to block the following codes:\n5 ⇒ 99: unallocated error messages 100, 101: experimentals 102 ⇒ 126: unallocated error messages 137 - Redirect Message — except in case of necessity 138 - Router Renumbering 139 - ICMP Node Information Query 140 - ICMP Node Information Response 144 - Home Agent Address Discovery Request Message 145 - Home Agent Address Discovery Reply Message 146 - Mobile Prefix Solicitation 147 - Mobile Prefix Advertisement 150 - Seamoby Experimental — except in case of necessity 154 ⇒ 199: non assigned 200, 201: experimentals 202 ⇒ 254: non assigned Limit The recommendations are to limit, in input AND in input, all those codes:\n1 - Destination Unreachable 4 - Parameter Problem Message And to limit in input only those following codes:\n2/0 - Packet Too Big Message 3 - Time Exceeded Message and all other existing codes, especially: 128/0 - Echo Request message (le ping) - 129/0 - Echo reply message (le pong). Useful details For the following codes, in the corresponding RFC, the message format is specified as:\nall MLD (Multicast Listener Discovery) codes — 130, 131, 132, 143 - and MLDv2 must be sent from an address whose source is an IPv6 local link, with an hop limit of 1\nsee: RFC 2710 ; 143 is defined by RFC 3810. all ND (Neighbor Discovery) codes — from 133 to 137 — must be sent with an hop-limit to 255\nsee RFC 4861. About those codes, here are useful informations: 133 - Router Solicitation - must be sent from a source that must have an assigned IP address, or from an unspecified address if the network interface does not yet have an assigned IP address, to any router. 134 - Router Advertisement - must ABSOLUTELY be sent by a router, issuing a periodic router notification, or response to a router solicitation, to any multicast node or to the source address invoking the router. 135 - Neighbor Solicitation - must be sent from a source that must have an assigned IP address, or from an unspecified address if the network interface does not yet have an assigned IP address, to any multicast node. 136 - Neighbor Advertisement - must ABSOLUTELY be sent by an assigned IP address, to the source address invoking the 135 code, or to any multicast node, if there is no assigned address. 137 - Redirect Message - must ABSOLUTELY be sent by an assigned IP address, an IPv6 link-local, by a router to the source address that requested the redirection of the message. all NIQ (Node Information Queries) codes - 139: ICMP Node Information Query and 140: ICMP Node Information Response - must refuse all requests from IPv6 global addresses and should apply the use of the limit option. Note that there are more complex security measures…\nsee: RFC 4620 all ND ID (Neighbor Discovery Inverse Discovery) codes - 141: Inverse Neighbor Discovery Solicitation Message and 142: Inverse Neighbor Discovery Advertisement Message - both must have an assigned IP address as source;\n141 must be sent to any multicast node, whose format is FF02::1. 142 must respond only to a request of type 141. see: RFC 3122 all SEND (SEcure Neighbor Discovery) codes - 148: Certification Path Solicitation Message and 149: Certification Path Advertisement Message - must be sent with an hop-limit to 255\nsee: RFC 3971. all MRD (Multicast Router Discovery) codes - from 151 to 153 must be sent from an assigned address, an IPv6 local-link, and have an hop-limit to 255.\nsee RFC 4286 Examples Paranoid ICMPv6 In paranoid mode, here are this kind of rules:\n##ip6tables -A INPUT -p icmpv6 -m conntrack --ctstate INVALID -j DROP ip6tables -A INPUT -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT ip6tables -A INPUT -p icmpv6 -m limit --limit 3/s --limit-burst 7 -j ACCEPT ip6tables -A INPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT ip6tables -A INPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT ip6tables -A INPUT -s fe80::/64 -p icmpv6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT # Type: 134 ip6tables -A INPUT -p icmpv6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT # Type: 135 ip6tables -A INPUT -p icmpv6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT # Type: 136 ip6tables -A INPUT -p icmpv6 -j DROP ##ip6tables -A OUTPUT -p icmpv6 -m conntrack --ctstate INVALID -j DROP ip6tables -A OUTPUT -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT ip6tables -A OUTPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT ip6tables -A OUTPUT -p icmpv6 --icmpv6-type echo-reply -m conntrack --ctstate NEW -j ACCEPT ip6tables -A OUTPUT -d ff02::/16 -p icmpv6 --icmpv6-type router-solicitation -j ACCEPT # Type: 133 ip6tables -A OUTPUT -p icmpv6 --icmpv6-type neighbour-solicitation -j ACCEPT # Type: 135 ip6tables -A OUTPUT -p icmpv6 --icmpv6-type neighbour-advertisement -j ACCEPT # Type: 136 ip6tables -A OUTPUT -d ff02::/16 -p icmpv6 --icmpv6-type 143/0 -j ACCEPT # Type: 143/0 ip6tables -A OUTPUT -p icmpv6 -j DROP Limit ICMP Here is an example, based on the understanding of the IETF recommendations, of ICMP limited rules, and reject all others codes with the icmp6-adm-prohibited messages.\n# INPUT RULES ip6tables -N INPUT_ICMPV6 ##ip6tables -A INPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate INVALID -j DROP ip6tables -A INPUT_ICMPV6 -p icmpv6 -m limit --limit 3/s --limit-burst 7 -j ACCEPT ip6tables -A INPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 1 -m conntrack --ctstate NEW -j ACCEPT # destination-unreachable; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 2/0 -m conntrack --ctstate NEW -j ACCEPT # packet too big; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/0 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/1 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Should Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/0 -m conntrack --ctstate NEW -j ACCEPT # parameter pb: Erroneous header field encountered; Should Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/1 -m conntrack --ctstate NEW -j ACCEPT # parameter pb: Unrecognized Next Header Type encountered; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/2 -m conntrack --ctstate NEW -j ACCEPT # parameter pb: Unrecognized IPv6 option encountered; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 100 -j DROP # private experimentation ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 101 -j DROP # private experimentation ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 127 -j DROP # error messages ICMPv6 ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 128/0 -m conntrack --ctstate NEW -j ACCEPT # ping tool: echo request message; Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 129/0 -m conntrack --ctstate NEW -j ACCEPT # ping tool: echo reply message; Must Not Be Dropped # link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 130/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 131/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 132/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # address configuration and routeur selection mssg (received with hop limit = 255) ##ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 133/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -s fe80::/64 -p icmpv6 --icmpv6-type 134/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 135/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 136/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 137/0 -j DROP # Will Be Dropped Anyway ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 138/0 -j DROP # Will Be Dropped Anyway ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 139/0 -j DROP # Should Be Dropped Unless a Good Case Can Be Made ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 140/0 -j DROP # Should Be Dropped Unless a Good Case Can Be Made ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 141/0 -d ff02::1 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 142/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) # link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 143 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # needed for mobylity ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 144/0 -j DROP # Will Be Dropped Anyway ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 145/0 -j DROP # Will Be Dropped Anyway ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 146/0 -j DROP # Will Be Dropped Anyway ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 147 -j DROP # Will Be Dropped Anyway # SEND certificate path notification mssg (received with hop limit = 255) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 148 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 149 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED) # multicast routeur discovery mssg (need link-local src address and hop limit = 1) ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 151 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 152 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 153 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 200 -j DROP # private experimentation ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 201 -j DROP # private experimentation ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 255 -j DROP # error messages ICMPv6 # all others are dropped #ip6tables -A INPUT_ICMPV6 -p icmpv6 ! --icmpv6-type -j DROP or -j REJECT --reject-with icmp6-adm-prohibited ⇐ this type seems not correctly supported! ip6tables -A INPUT_ICMPV6 -p icmpv6 -j REJECT --reject-with no-route # OUTPUT RULES ip6tables -N OUTPUT_ICMPV6 ##ip6tables -A OUTPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate INVALID -j DROP ip6tables -A OUTPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 1 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT # destination-unreachable; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 2/0 -m conntrack --ctstate NEW -j ACCEPT # packet too big; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/0 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/1 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Should Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/0 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT # parameter pb: Erroneous header field encountered; Should Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/1 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT # parameter pb: Unrecognized Next Header Type encountered; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/2 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT # parameter pb: Unrecognized IPv6 option encountered; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 100 -j DROP # private experimentation ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 101 -j DROP # private experimentation ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 127 -j DROP # error messages ICMPv6 ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 128/0 -m conntrack --ctstate NEW -j ACCEPT # ping tool: echo request message; Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 129/0 -m conntrack --ctstate NEW -j ACCEPT # ping tool: echo reply message; Must Not Be Dropped # link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1) ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 130/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 131/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 132/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # address configuration and routeur selection mssg (received with hop limit = 255) ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 133/0 -d ff02::/16 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ##ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 134/0 -d fe80::/64 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 135/0 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 136/0 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 137/0 -j DROP # Will Be Dropped Anyway ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 138/0 -j DROP # Will Be Dropped Anyway ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 139/0 -j DROP # Should Be Dropped Unless a Good Case Can Be Made ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 140/0 -j DROP # Should Be Dropped Unless a Good Case Can Be Made ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 141/0 -d ff02::1 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 142/0 -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped # link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1) ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 143 -d ff02::/16 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # needed for mobylity: except if the context requires it, then it will be necessary to limit them ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 144/0 -j DROP # Will Be Dropped Anyway ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 145/0 -j DROP # Will Be Dropped Anyway ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 146/0 -j DROP # Will Be Dropped Anyway ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 147 -j DROP # Will Be Dropped Anyway # SEND certificate path notification mssg (received with hop limit = 255) ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 148 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 149 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT # Must Not Be Dropped # multicast routeur discovery mssg (need link-local src address and hop limit = 1) ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 151 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 152 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 153 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT # Must Not Be Dropped # ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 200 -j DROP # private experimentation ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 201 -j DROP # private experimentation ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 255 -j DROP # error messages ICMPv6 # all others are dropped #ip6tables -A OUTPUT_ICMPV6 -p icmpv6 ! --icmpv6-type -j DROP or -j REJECT --reject-with icmp6-adm-prohibited # ⇐ this type seems not correctly supported! ip6tables -A OUTPUT_ICMPV6 -p icmpv6 -j REJECT --reject-with no-route Documentations the ICMPv6 parameters RFC 4890 RFC 5927 draft ICMP filtering draft ICMPv6 filtering RFC 2710 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 3122 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 3810 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 3971 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 4286 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 4620 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 4861 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 4890 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 5927 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFiltering ICMPv6 on Linux!\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eA few hours ago, I wrote this other \u003ca href=\"/en/sec/firewall/linux-firewall-icmp/\"\u003earticle\u003c/a\u003e… \u003cbr\u003e\nnow, it\u0026rsquo;s time to discuss about the filtering measures to be put in place around ICMPv6.\u003c/p\u003e\n\u003cp\u003eI am not going to remind you why this protocol exists, nor the fact that it can be dangerous if misused; and, of course, unfortunately there will always be people who misuse it!\u003c/p\u003e\n\u003ch2 id=\"manage-icmpv6\"\u003eManage ICMPv6\u003c/h2\u003e\n\u003ch3 id=\"refuse\"\u003eRefuse\u003c/h3\u003e\n\u003cp\u003eAs a precaution, it is advisable to filter out all experimental codes, such as \u003ccode\u003e100\u003c/code\u003e, \u003ccode\u003e101\u003c/code\u003e, \u003ccode\u003e200\u003c/code\u003e, and \u003ccode\u003e201\u003c/code\u003e, as well as codes reserved for the future, namely codes \u003ccode\u003e127\u003c/code\u003e and \u003ccode\u003e255\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eIt is recommended to block the following codes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e5\u003c/code\u003e ⇒ \u003ccode\u003e99\u003c/code\u003e: unallocated error messages\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e100\u003c/code\u003e, \u003ccode\u003e101\u003c/code\u003e: experimentals\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e102\u003c/code\u003e ⇒ \u003ccode\u003e126\u003c/code\u003e: unallocated error messages\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e137\u003c/code\u003e - Redirect Message — except in case of necessity\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e138\u003c/code\u003e - Router Renumbering\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e139\u003c/code\u003e - ICMP Node Information Query\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e140\u003c/code\u003e - ICMP Node Information Response\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e144\u003c/code\u003e - Home Agent Address Discovery Request Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e145\u003c/code\u003e - Home Agent Address Discovery Reply Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e146\u003c/code\u003e - Mobile Prefix Solicitation\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e147\u003c/code\u003e - Mobile Prefix Advertisement\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e150\u003c/code\u003e - Seamoby Experimental — except in case of necessity\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e154\u003c/code\u003e ⇒ \u003ccode\u003e199\u003c/code\u003e: non assigned\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e200\u003c/code\u003e, \u003ccode\u003e201\u003c/code\u003e: experimentals\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e202\u003c/code\u003e ⇒ \u003ccode\u003e254\u003c/code\u003e: non assigned\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"limit\"\u003eLimit\u003c/h3\u003e\n\u003cp\u003eThe recommendations are to limit, in input AND in input, all those codes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e1\u003c/code\u003e - Destination Unreachable\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e4\u003c/code\u003e - Parameter Problem Message\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAnd to limit in input only those following codes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e2/0\u003c/code\u003e - Packet Too Big Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e3\u003c/code\u003e - Time Exceeded Message\u003c/li\u003e\n\u003cli\u003eand all other existing codes, especially:\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e128/0\u003c/code\u003e - Echo Request message \u003cem\u003e(le ping)\u003c/em\u003e -\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e129/0\u003c/code\u003e - Echo reply message \u003cem\u003e(le pong)\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"useful-details\"\u003eUseful details\u003c/h3\u003e\n\u003cp\u003eFor the following codes, in the corresponding RFC, the message format is specified as:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eMLD \u003cem\u003e(Multicast Listener Discovery)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes — \u003ccode\u003e130\u003c/code\u003e, \u003ccode\u003e131\u003c/code\u003e, \u003ccode\u003e132\u003c/code\u003e, \u003ccode\u003e143\u003c/code\u003e - and \u003cstrong\u003eMLDv2\u003c/strong\u003e must be sent from an address whose source is an IPv6 local link, with an \u003ccode\u003ehop limit\u003c/code\u003e of \u003ccode\u003e1\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee: \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-2710\"\u003eRFC 2710\u003c/a\u003e\u003c/em\u003e ;\n\u003cem\u003e\u003ccode\u003e143\u003c/code\u003e is defined by \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-3810\"\u003eRFC 3810\u003c/a\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eND \u003cem\u003e(Neighbor Discovery)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes — from \u003ccode\u003e133\u003c/code\u003e to \u003ccode\u003e137\u003c/code\u003e — must be sent with an \u003ccode\u003ehop-limit\u003c/code\u003e to \u003ccode\u003e255\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-4861\"\u003eRFC 4861\u003c/a\u003e\u003c/em\u003e. \u003cbr\u003e\nAbout those codes, here are useful informations:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e133\u003c/code\u003e - \u003cstrong\u003eRouter Solicitation\u003c/strong\u003e - must be sent from a source that must have an assigned IP address, or from an unspecified address if the network interface does not yet have an assigned IP address, to any router.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e134\u003c/code\u003e - \u003cstrong\u003eRouter Advertisement\u003c/strong\u003e - must ABSOLUTELY be sent by a router, issuing a periodic router notification, or response to a router solicitation, to any multicast node or to the source address invoking the router.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e135\u003c/code\u003e - \u003cstrong\u003eNeighbor Solicitation\u003c/strong\u003e - must be sent from a source that must have an assigned IP address, or from an unspecified address if the network interface does not yet have an assigned IP address, to any multicast node.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e136\u003c/code\u003e - \u003cstrong\u003eNeighbor Advertisement\u003c/strong\u003e - must ABSOLUTELY be sent by an assigned IP address, to the source address invoking the \u003ccode\u003e135\u003c/code\u003e code, or to any multicast node, if there is no assigned address.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e137\u003c/code\u003e - \u003cstrong\u003eRedirect Message\u003c/strong\u003e - must ABSOLUTELY be sent by an assigned IP address, an IPv6 link-local, by a router to the source address that requested the redirection of the message.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eNIQ \u003cem\u003e(Node Information Queries)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes - \u003ccode\u003e139\u003c/code\u003e: \u003cbr\u003e\n\u003cstrong\u003eICMP Node Information Query\u003c/strong\u003e and \u003ccode\u003e140\u003c/code\u003e: \u003cstrong\u003eICMP Node Information Response\u003c/strong\u003e - must refuse all requests from IPv6 global addresses and should apply the use of the \u003ccode\u003elimit\u003c/code\u003e option. \u003cbr\u003e\nNote that there are more complex security measures…\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee: \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-4620\"\u003eRFC 4620\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eND ID \u003cem\u003e(Neighbor Discovery Inverse Discovery)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes -\n\u003ccode\u003e141\u003c/code\u003e: \u003cstrong\u003eInverse Neighbor Discovery Solicitation Message\u003c/strong\u003e and\n\u003ccode\u003e142\u003c/code\u003e: \u003cstrong\u003eInverse Neighbor Discovery Advertisement Message\u003c/strong\u003e - both must have an assigned IP address as source;\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e141\u003c/code\u003e must be sent to any multicast node, whose format is \u003ccode\u003eFF02::1\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e142\u003c/code\u003e must respond only to a request of type \u003ccode\u003e141\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee: \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-3122\"\u003eRFC 3122\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eSEND \u003cem\u003e(SEcure Neighbor Discovery)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes - \u003ccode\u003e148\u003c/code\u003e: \u003cstrong\u003eCertification Path Solicitation Message\u003c/strong\u003e and \u003ccode\u003e149\u003c/code\u003e: \u003cstrong\u003eCertification Path Advertisement Message\u003c/strong\u003e - must be sent with an \u003ccode\u003ehop-limit\u003c/code\u003e to \u003ccode\u003e255\u003c/code\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee: \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-3971\"\u003eRFC 3971\u003c/a\u003e\u003c/em\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eall \u003cstrong\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003cspan lang=\"en\"\u003eMRD \u003cem\u003e(Multicast Router Discovery)\u003c/em\u003e\u003c/span\u003e\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\u003c/strong\u003e codes - from \u003ccode\u003e151\u003c/code\u003e to \u003ccode\u003e153\u003c/code\u003e must be sent from an assigned address, an IPv6 local-link, and have an \u003ccode\u003ehop-limit\u003c/code\u003e to \u003ccode\u003e255\u003c/code\u003e.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003esee \u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-4286\"\u003eRFC 4286\u003c/a\u003e\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"examples\"\u003eExamples\u003c/h2\u003e\n\u003ch3 id=\"paranoid-icmpv6\"\u003eParanoid ICMPv6\u003c/h3\u003e\n\u003cp\u003eIn paranoid mode, here are this kind of rules:\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A INPUT -p icmpv6 -m conntrack --ctstate INVALID -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 -m limit --limit 3/s --limit-burst 7 -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -s fe80::/64 -p icmpv6 --icmpv6-type router-advertisement -m hl --hl-eq 255 -j ACCEPT # Type: 134\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 --icmpv6-type neighbour-solicitation -m hl --hl-eq 255 -j ACCEPT # Type: 135\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 --icmpv6-type neighbour-advertisement -m hl --hl-eq 255 -j ACCEPT # Type: 136\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT -p icmpv6 -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A OUTPUT -p icmpv6 -m conntrack --ctstate INVALID -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 --icmpv6-type echo-request -m conntrack --ctstate NEW -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 --icmpv6-type echo-reply -m conntrack --ctstate NEW -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -d ff02::/16 -p icmpv6 --icmpv6-type router-solicitation -j ACCEPT # Type: 133\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 --icmpv6-type neighbour-solicitation -j ACCEPT # Type: 135\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 --icmpv6-type neighbour-advertisement -j ACCEPT # Type: 136\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -d ff02::/16 -p icmpv6 --icmpv6-type 143/0 -j ACCEPT # Type: 143/0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT -p icmpv6 -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"limit-icmp\"\u003eLimit ICMP\u003c/h3\u003e\n\u003cp\u003eHere is an example, based on the understanding of the IETF recommendations, of ICMP limited rules, and reject all others codes with the \u003ccode\u003eicmp6-adm-prohibited\u003c/code\u003e messages.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-cfg\" data-lang=\"cfg\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# INPUT RULES\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -N INPUT_ICMPV6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A INPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate INVALID -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 -m limit --limit 3/s --limit-burst 7 -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 1 -m conntrack --ctstate NEW -j ACCEPT   # destination-unreachable; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 2/0 -m conntrack --ctstate NEW -j ACCEPT   # packet too big; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/0 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/1 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Should Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/0 -m conntrack --ctstate NEW -j ACCEPT   # parameter pb: Erroneous header field encountered; Should Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/1 -m conntrack --ctstate NEW -j ACCEPT   # parameter pb: Unrecognized Next Header Type encountered; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/2 -m conntrack --ctstate NEW -j ACCEPT   # parameter pb: Unrecognized IPv6 option encountered; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 100 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 101 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 127 -j DROP   # error messages ICMPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 128/0 -m conntrack --ctstate NEW -j ACCEPT   # ping tool: echo request message; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 129/0 -m conntrack --ctstate NEW -j ACCEPT  # ping tool: echo reply message; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 130/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 131/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 132/0 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# address configuration and routeur selection mssg (received with hop limit = 255)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 133/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -s fe80::/64 -p icmpv6 --icmpv6-type 134/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 135/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 136/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 137/0 -j DROP   # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 138/0 -j DROP   # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 139/0 -j DROP   # Should Be Dropped Unless a Good Case Can Be Made\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 140/0 -j DROP   # Should Be Dropped Unless a Good Case Can Be Made\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 141/0 -d ff02::1 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 142/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 143 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# needed for mobylity\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 144/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 145/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 146/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 147 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# SEND certificate path notification mssg (received with hop limit = 255)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 148 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 149 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped (only RELATED,ESTABLISHED,UNTRACKED)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# multicast routeur discovery mssg (need link-local src address and hop limit = 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 151 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 152 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 153 -s fe80::/64 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 200 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 201 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 --icmpv6-type 255 -j DROP   # error messages ICMPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# all others are dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#ip6tables -A INPUT_ICMPV6 -p icmpv6 ! --icmpv6-type -j DROP or -j REJECT --reject-with icmp6-adm-prohibited ⇐ this type seems not correctly supported!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A INPUT_ICMPV6 -p icmpv6 -j REJECT --reject-with no-route\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# OUTPUT RULES\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -N OUTPUT_ICMPV6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A OUTPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate INVALID -j DROP\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 1 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT   # destination-unreachable; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 2/0 -m conntrack --ctstate NEW -j ACCEPT   # packet too big; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/0 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 3/1 -m conntrack --ctstate NEW -j ACCEPT # time exceeded; Should Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/0 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT   # parameter pb: Erroneous header field encountered; Should Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/1 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT   # parameter pb: Unrecognized Next Header Type encountered; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 4/2 -m conntrack --ctstate NEW -m limit --limit 3/s --limit-burst 7 -j ACCEPT   # parameter pb: Unrecognized IPv6 option encountered; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 100 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 101 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 127 -j DROP   # error messages ICMPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 128/0 -m conntrack --ctstate NEW -j ACCEPT   # ping tool: echo request message; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 129/0 -m conntrack --ctstate NEW -j ACCEPT  # ping tool: echo reply message; Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 130/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 131/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 132/0 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# address configuration and routeur selection mssg (received with hop limit = 255)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 133/0 -d ff02::/16 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e##ip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 134/0 -d fe80::/64 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 135/0 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 136/0 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 137/0 -j DROP   # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 138/0 -j DROP   # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 139/0 -j DROP   # Should Be Dropped Unless a Good Case Can Be Made\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 140/0 -j DROP   # Should Be Dropped Unless a Good Case Can Be Made\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 141/0 -d ff02::1 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 142/0 -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# link-local multicast receive notification mssg (need link-local src address, with hop-limit: 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 143 -d ff02::/16 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# needed for mobylity: except if the context requires it, then it will be necessary to limit them\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 144/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 145/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 146/0 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 147 -j DROP  # Will Be Dropped Anyway\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# SEND certificate path notification mssg (received with hop limit = 255)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 148 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 149 -m conntrack --ctstate NEW -m hl --hl-eq 255 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# multicast routeur discovery mssg (need link-local src address and hop limit = 1)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 151 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 152 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 153 -m conntrack --ctstate NEW -m hl --hl-eq 1 -j ACCEPT   # Must Not Be Dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 200 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 201 -j DROP   # private experimentation\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 --icmpv6-type 255 -j DROP   # error messages ICMPv6\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# all others are dropped\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#ip6tables -A OUTPUT_ICMPV6 -p icmpv6 ! --icmpv6-type -j DROP or -j REJECT --reject-with icmp6-adm-prohibited # ⇐ this type seems not correctly supported!\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#06b6ef\"\u003eip6tables -A OUTPUT_ICMPV6 -p icmpv6 -j REJECT --reject-with no-route\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentations\"\u003eDocumentations\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xhtml\" rel=\"external\"\u003eICMPv6 parameters\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-4890\"\u003eRFC 4890\u003c/a\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"/en/sec/firewall/linux-firewall-icmpv6/#rfc-5927\"\u003eRFC 5927\u003c/a\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tools.ietf.org/html/draft-ietf-opsec-icmp-filtering-04\" rel=\"external\"\u003edraft ICMP filtering\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tools.ietf.org/id/draft-ietf-v6ops-icmpv6-filtering-recs-02.txt\" rel=\"external\"\u003edraft ICMPv6 filtering\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003cp\u003e\n\u003ch3 id=\"rfc-2710\"\u003eRFC 2710\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc2710\" title=\"RFC 2710: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc2710\" title=\"RFC 2710: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc2710.txt\" title=\"RFC 2710: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc2710.html\" title=\"RFC 2710: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc2710.txt.pdf\" title=\"RFC 2710: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc2710.txt\" title=\"RFC 2710: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-3122\"\u003eRFC 3122\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc3122\" title=\"RFC 3122: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc3122\" title=\"RFC 3122: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc3122.txt\" title=\"RFC 3122: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3122.html\" title=\"RFC 3122: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc3122.txt.pdf\" title=\"RFC 3122: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3122.txt\" title=\"RFC 3122: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-3810\"\u003eRFC 3810\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc3810\" title=\"RFC 3810: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc3810\" title=\"RFC 3810: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc3810.txt\" title=\"RFC 3810: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3810.html\" title=\"RFC 3810: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc3810.txt.pdf\" title=\"RFC 3810: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3810.txt\" title=\"RFC 3810: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-3971\"\u003eRFC 3971\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc3971\" title=\"RFC 3971: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc3971\" title=\"RFC 3971: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc3971.txt\" title=\"RFC 3971: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3971.html\" title=\"RFC 3971: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc3971.txt.pdf\" title=\"RFC 3971: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc3971.txt\" title=\"RFC 3971: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-4286\"\u003eRFC 4286\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc4286\" title=\"RFC 4286: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc4286\" title=\"RFC 4286: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc4286.txt\" title=\"RFC 4286: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4286.html\" title=\"RFC 4286: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc4286.txt.pdf\" title=\"RFC 4286: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4286.txt\" title=\"RFC 4286: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-4620\"\u003eRFC 4620\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc4620\" title=\"RFC 4620: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc4620\" title=\"RFC 4620: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc4620.txt\" title=\"RFC 4620: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4620.html\" title=\"RFC 4620: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc4620.txt.pdf\" title=\"RFC 4620: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4620.txt\" title=\"RFC 4620: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-4861\"\u003eRFC 4861\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc4861\" title=\"RFC 4861: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc4861\" title=\"RFC 4861: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc4861.txt\" title=\"RFC 4861: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4861.html\" title=\"RFC 4861: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc4861.txt.pdf\" title=\"RFC 4861: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4861.txt\" title=\"RFC 4861: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-4890\"\u003eRFC 4890\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc4890\" title=\"RFC 4890: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc4890\" title=\"RFC 4890: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc4890.txt\" title=\"RFC 4890: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4890.html\" title=\"RFC 4890: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc4890.txt.pdf\" title=\"RFC 4890: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4890.txt\" title=\"RFC 4890: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-5927\"\u003eRFC 5927\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc5927\" title=\"RFC 5927: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc5927\" title=\"RFC 5927: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc5927.txt\" title=\"RFC 5927: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5927.html\" title=\"RFC 5927: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc5927.txt.pdf\" title=\"RFC 5927: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5927.txt\" title=\"RFC 5927: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/p\u003e\n\u003chr\u003e\n","summary":"Securely filtering the ICMP protocol under Linux: examples with ip6tables","tags":["Linux","firewall","ICMPv6","Ip6tables"],"date_published":"2017-07-26T22:22:02+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2017-07-26:/en/sec/firewall/linux-firewall-icmp","url":"https://it-log.fr.eu.org/en/sec/firewall/linux-firewall-icmp/","title":"Linux: firewall ICMP","author":{"name":"Stéphane HUC"},"content_text":"Description Filtering ICMP on Linux!\nSomeone say that it\u0026rsquo;s absolutely necessary to block all ICMP, and bye-bye all needed commands, like traceroute, ping…\nOthers replies:\nyes, but… it\u0026rsquo;s still convenient to use such commands except that…\nThe obvious purpose of ICMP is to report error messages, status informations, related to the IP protocol (including Internet), to the delivery of the IP packets.\nThis interesting goal has its flaws:\nmap your entire network, seek to attack your network, through some well-known attacks — such as DOS ; see Smurf, the famous Ping of the Death, … — Few attacks allow to attack others network protocols, such SlowLoris againt the TCP protocol, and the HTTP service…\nFrozen?\nstandard reaction…\nIn this article, we will learn how to handle ICMP correctly, taking into account the recommendations made by recognized organizations, such as the IETF, the IANA, through different RFCs, which will all be named.\nManage ICMP Refuse The following codes are known to be deprecated, dangerous to use, and therefore not to be used:\n3/6 - Destination Network Unknown 3/8 - Source Host Isolated 4/0 - Source Quench 15/0 - Information Request Message 16/0 - Information Reply Message WarningATTENTION: IANA, about the depreciation of Source Quench, recommends to log such packets and to remove them without warnings (DROP)\nSee: reference\nLet\u0026rsquo;s not even hesitate: the corresponding messages must ABSOLUTELY be refused!\nEgual, IANA considers the following codes to be deprecated and to be filtered — all discretion is left to the administrators to choose his filtering mode. See: reference\n6/0 - Alternate Host Address\n15 - Information Request\n16 - Information Reply\n17 - Address Mask Request\n18 - Address Mask Reply\n30 - Traceroute\n31 - Datagram Conversion Error\n32 - Mobile Host Redirect\n33 - IPv6 Where-Are-You\n34 - IPv6 I-Am-Here\n35 - Mobile Registration Request\n36 - Mobile Registration Reply\n37 - Domain Name Request\n38 - Domain Name Reply\n39 - SKIP\nIt\u0026rsquo;s your choice: will you destroy them in paranoid mode‽\nExtermination, extermination, extermination…\nInfoAnyway, if you decide to filter the code 30, do not forget that traceroute is able to work on UDP:53, TCP:80… and even imitate ICMP:8/0! Limit The recommendations are to limit, in input AND output:\n0/0 - Echo Reply Message - (the famous Ping reply: THE Pong, what else :p) all type 3 - Destination Unreachable - except a slightly special treatment for 3/7 - Destination Host Unknown - just to limit in ouput and ignore in input. all 5 - Redirect 8/0 - Echo Message - (the famous Ping) 9/0 - Router Advertisement Message 10/0 - Router Solicitation Message all 11 - Time Exceeded - Useful for traceroute, as well as the 30/0 code. all 12 - Parameter Problem 13/0 - Timestamp Message 14/0 - Timestamp Reply Message 17/0 - Address Mask Request 18/0 - Address Mask Reply As instance, in the context of Linux, use the Iptables match limit option…\nExamples Paranoid ICMP In paranoid mode, you can open:\nin output: 8/0, and in input, the relative 0/0 code — so you can ping yourself… and, prevent others doing same! and finally, drop all others code iptables -A INPUT -p icmp --icmp-type echo-reply -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -m limit --limit 3/s --limit-burst 7 -j ACCEPT iptables -A OUTPUT -p icmp --icmp-type echo-request -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -m limit --limit 3/s --limit-burst 7 -j ACCEPT iptables -A INPUT -p icmp -j DROP iptables -A OUTPUT -p icmp -j DROP Limit ICMP Here is an example, based on the understanding of the IETF recommendations, of ICMP limited rules, and reject all others codes with the icmp-host-prohibited messages.\n/sbin/iptables -A INPUT -i ethX -p icmp -m limit --limit 3/s --limit-burst 7 -j icmp4in /sbin/iptables -A icmp4in -p icmp -m conntrack --ctstate INVALID -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Echo reply\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Destination Net Unreachable\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/1 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Destination Host Unreachable\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/3 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Destination Port Unreachable\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/4 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP PathMTU Discovery\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/6 -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/8 -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 4 -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 5 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Redirect mssg\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 8/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Echo mssg\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 9/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Router Advertisement Message\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 10/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Router Solicitation Message\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 11 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Time exceeded\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 12 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Param pb\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 13/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Timestamp Message\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 14/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Timestamp Reply Message\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 15 -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 16 -j DROP /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 17/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Address Mask Request\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 18/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Address Mask Reply\u0026#34; /sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 30 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u0026#34;ICMP Traceroute\u0026#34; # REJECT Others /sbin/iptables -A icmp4in -p icmp -j REJECT --reject-with icmp-host-prohibited /sbin/iptables -A OUTPUT -o ethX -p icmp -m limit --limit 3/s --limit-burst 7 -j icmp4out /sbin/iptables -A icmp4out -p icmp -m conntrack --ctstate INVALID -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/1 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/3 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/4 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/6 -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/7 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/8 -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 4/0 -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 5 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 8/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 9/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 10/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 11 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 12 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 13/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 14/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 15 -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 16 -j DROP /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 17/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 18/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 30 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT /sbin/iptables -A icmp4out -p icmp -j REJECT --reject-with icmp-host-prohibited Documentation IETF IETF is a well-known recognized organization that writes many technical documents whose purpose is to improve the technicality, the security to use the network protocols.\nSome existing documents insist on filtering ICMP, even ICMPv6, as:\nRFC 4890 RFC 5927 draft ICMP filtering draft ICMPv6 filtering These documents are all interesting, some are old, others more recent, and have the goal to think seriously about the security, to set up around ICMP.\nThe \u0026ldquo;ICMP filtering\u0026rdquo; draft paper discuss about IPv4 and IPv6 protocols, and explains what attacks are possible, give useful recommendations, which range from refuse some packets to limit others.\nClearly, certain messages codes are absolutely to be block, to refuse, like ICMP 4/0, alias \u0026ldquo;Source Quench\u0026rdquo;, wich is explicetely deprecated, not to be used anymore… but it\u0026rsquo;s not the only one!\nRFC 4890 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 5927 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 6633 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT RFC 6918 IETF Tools HTML, PDF, TXT RFC Editor HTML, PDF, TXT Wikipedia Denial-of-service_attack#Attack_techniques WP Ping_of_death WP Slowloris_(computer_security) WP ","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eFiltering ICMP on Linux!\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSomeone say that it\u0026rsquo;s absolutely necessary to block all ICMP, and bye-bye all needed commands, like \u003ccode\u003etraceroute\u003c/code\u003e, \u003ccode\u003eping\u003c/code\u003e…\u003c/p\u003e\n\u003cp\u003eOthers replies:\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eyes, but… it\u0026rsquo;s still convenient to use such commands except that…\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003eThe obvious purpose of ICMP is to report error messages, status informations, related to the IP protocol (including Internet), to the delivery of the IP packets.\u003c/p\u003e\n\u003cp\u003eThis interesting goal has its flaws:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003emap your entire network,\u003c/li\u003e\n\u003cli\u003eseek to attack your network, through some well-known attacks — such as \u003cabbr title=\"Denial of Service\"\u003eDOS\u003c/abbr\u003e\n; see \u003cstrong\u003eSmurf\u003c/strong\u003e, the famous \u003cstrong\u003ePing of the Death\u003c/strong\u003e, … —\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFew attacks allow to attack others network protocols, such \u003cstrong\u003eSlowLoris\u003c/strong\u003e againt the TCP protocol, and the HTTP service…\u003c/p\u003e\n\u003cp\u003e\u003cq\u003eFrozen?\u003cbr\u003estandard reaction…\u003c/q\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eIn this article, we will learn how to handle ICMP correctly, taking into account the recommendations made by recognized organizations, such as the IETF, the IANA, through different RFCs, which will all be named.\u003c/p\u003e\n\u003ch2 id=\"manage-icmp\"\u003eManage ICMP\u003c/h2\u003e\n\u003ch3 id=\"refuse\"\u003eRefuse\u003c/h3\u003e\n\u003cp\u003eThe following codes are known to be deprecated, dangerous to use, and therefore \u003cstrong\u003enot to be used\u003c/strong\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e3/6\u003c/code\u003e - Destination Network Unknown\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e3/8\u003c/code\u003e - Source Host Isolated\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e4/0\u003c/code\u003e - Source Quench\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e15/0\u003c/code\u003e - Information Request Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e16/0\u003c/code\u003e - Information Reply Message\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cdiv class=\"tab-info i-warning\"\u003eWarning\u003c/div\u003e\u003cdiv class=\"alert alert-warning\" role=\"alert\"\u003e\u003cp\u003e\u003cstrong\u003eATTENTION\u003c/strong\u003e: IANA, about the \u003cstrong\u003edepreciation of Source Quench\u003c/strong\u003e, recommends to log such packets and to remove them without warnings (\u003ccode\u003eDROP\u003c/code\u003e)\u003c/p\u003e\n\u003cp\u003eSee: \u003ca href=\"https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml\" rel=\"external\"\u003ereference\u003c/a\u003e\u003c/p\u003e\n\u003c/div\u003e\n\n\u003cp\u003e\u003cstrong\u003eLet\u0026rsquo;s not even hesitate: the corresponding messages must ABSOLUTELY be refused!\u003c/strong\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003eEgual, IANA considers the following codes to be deprecated and to be filtered — \u003cem\u003eall discretion is left to the administrators to choose his filtering mode\u003c/em\u003e. See: \u003ca href=\"https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml\" rel=\"external\"\u003ereference\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e6/0\u003c/code\u003e - Alternate Host Address\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e15\u003c/code\u003e - Information Request\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e16\u003c/code\u003e - Information Reply\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e17\u003c/code\u003e - Address Mask Request\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e18\u003c/code\u003e - Address Mask Reply\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e30\u003c/code\u003e - Traceroute\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e31\u003c/code\u003e - Datagram Conversion Error\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e32\u003c/code\u003e - Mobile Host Redirect\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e33\u003c/code\u003e - IPv6 Where-Are-You\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e34\u003c/code\u003e - IPv6 I-Am-Here\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e35\u003c/code\u003e - Mobile Registration Request\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e36\u003c/code\u003e - Mobile Registration Reply\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e37\u003c/code\u003e - Domain Name Request\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e38\u003c/code\u003e - Domain Name Reply\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003e39\u003c/code\u003e - SKIP\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIt\u0026rsquo;s your choice: \u003cem\u003ewill you destroy them in paranoid mode‽\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eExtermination, extermination, extermination…\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003cdiv class=\"tab-info i-info\"\u003eInfo\u003c/div\u003e\u003cdiv class=\"alert alert-info\" role=\"alert\"\u003eAnyway, if you decide to filter the code 30, do not forget that \u003ccode\u003etraceroute\u003c/code\u003e is able to work on \u003ccode\u003eUDP:53\u003c/code\u003e, \u003ccode\u003eTCP:80\u003c/code\u003e… and even imitate \u003ccode\u003eICMP:8/0\u003c/code\u003e!\u003c/div\u003e\n\n\u003ch3 id=\"limit\"\u003eLimit\u003c/h3\u003e\n\u003cp\u003eThe recommendations are to limit, in input AND output:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e0/0\u003c/code\u003e - Echo Reply Message - \u003cem\u003e(the famous Ping reply: THE Pong, what else :p)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eall \u003ccode\u003etype 3\u003c/code\u003e - Destination Unreachable -\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eexcept\u003c/strong\u003e a slightly special treatment for \u003ccode\u003e3/7\u003c/code\u003e - Destination Host Unknown - just to limit in ouput and ignore in input.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eall \u003ccode\u003e5\u003c/code\u003e - Redirect\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e8/0\u003c/code\u003e - Echo Message - \u003cem\u003e(the famous Ping)\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e9/0\u003c/code\u003e - Router Advertisement Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e10/0\u003c/code\u003e - Router Solicitation Message\u003c/li\u003e\n\u003cli\u003eall \u003ccode\u003e11\u003c/code\u003e - Time Exceeded -\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003eUseful for \u003ccode\u003etraceroute\u003c/code\u003e, as well as the \u003ccode\u003e30/0\u003c/code\u003e code.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eall \u003ccode\u003e12\u003c/code\u003e - Parameter Problem\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e13/0\u003c/code\u003e - Timestamp Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e14/0\u003c/code\u003e - Timestamp Reply Message\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e17/0\u003c/code\u003e - Address Mask Request\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e18/0\u003c/code\u003e - Address Mask Reply\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAs instance, in the context of Linux, use the Iptables \u003ccode\u003ematch limit\u003c/code\u003e option…\u003c/p\u003e\n\u003ch2 id=\"examples\"\u003eExamples\u003c/h2\u003e\n\u003ch3 id=\"paranoid-icmp\"\u003eParanoid ICMP\u003c/h3\u003e\n\u003cp\u003eIn paranoid mode, you can open:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ein output: \u003ccode\u003e8/0\u003c/code\u003e,\u003c/li\u003e\n\u003cli\u003eand in input, the relative \u003ccode\u003e0/0\u003c/code\u003e code — so you can ping yourself…\u003c/li\u003e\n\u003cli\u003eand, prevent others doing same!\u003c/li\u003e\n\u003cli\u003eand finally, drop all others code\u003c/li\u003e\n\u003c/ul\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eiptables -A INPUT -p icmp --icmp-type echo-reply -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -m limit --limit 3/s --limit-burst \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eiptables -A OUTPUT -p icmp --icmp-type echo-request -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -m limit --limit 3/s --limit-burst \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eiptables -A INPUT -p icmp -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eiptables -A OUTPUT -p icmp -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch3 id=\"limit-icmp\"\u003eLimit ICMP\u003c/h3\u003e\n\u003cp\u003eHere is an example, based on the understanding of the IETF recommendations, of ICMP limited rules, and reject all others codes with the \u003ccode\u003eicmp-host-prohibited\u003c/code\u003e messages.\u003c/p\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-sh\" data-lang=\"sh\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A INPUT -i ethX -p icmp -m limit --limit 3/s --limit-burst \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e -j icmp4in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m conntrack --ctstate INVALID -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Echo reply\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Destination Net Unreachable\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/1 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Destination Host Unreachable\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/3 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Destination Port Unreachable\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/4 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP PathMTU Discovery\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/6 -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 3/8 -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e4\u003c/span\u003e -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e5\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Redirect mssg\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 8/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Echo mssg\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 9/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Router Advertisement Message\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 10/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Router Solicitation Message\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e11\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Time exceeded\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e12\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Param pb\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 13/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Timestamp Message\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 14/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Timestamp Reply Message\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e15\u003c/span\u003e -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e16\u003c/span\u003e -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 17/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Address Mask Request\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type 18/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Address Mask Reply\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e30\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT -m comment --comment \u003cspan style=\"color:#48b685\"\u003e\u0026#34;ICMP Traceroute\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# REJECT Others\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4in -p icmp -j REJECT --reject-with icmp-host-prohibited\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A OUTPUT -o ethX -p icmp -m limit --limit 3/s --limit-burst \u003cspan style=\"color:#f99b15\"\u003e7\u003c/span\u003e -j icmp4out\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m conntrack --ctstate INVALID -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/1 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/3 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/4 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/6 -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/7 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 3/8 -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 4/0 -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e5\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 8/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 9/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 10/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e11\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e12\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 13/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 14/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e15\u003c/span\u003e -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e16\u003c/span\u003e -j DROP\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 17/0 -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type 18/0 -m conntrack --ctstate RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -m icmp --icmp-type \u003cspan style=\"color:#f99b15\"\u003e30\u003c/span\u003e -m conntrack --ctstate NEW,RELATED,ESTABLISHED,UNTRACKED -j ACCEPT\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e/sbin/iptables -A icmp4out -p icmp -j REJECT --reject-with icmp-host-prohibited\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"documentation\"\u003eDocumentation\u003c/h2\u003e\n\u003ch3 id=\"ietf\"\u003eIETF\u003c/h3\u003e\n\u003cp\u003eIETF is a well-known recognized organization that writes many technical documents whose purpose is to improve the technicality, the security to use the network protocols.\u003c/p\u003e\n\u003cp\u003eSome existing documents insist on filtering ICMP, even ICMPv6, as:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"/en/sec/firewall/linux-firewall-icmp/#rfc-4890\"\u003eRFC 4890\u003c/a\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ca href=\"/en/sec/firewall/linux-firewall-icmp/#rfc-5927\"\u003eRFC 5927\u003c/a\u003e\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tools.ietf.org/html/draft-ietf-opsec-icmp-filtering-04\" rel=\"external\"\u003edraft ICMP filtering\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tools.ietf.org/id/draft-ietf-v6ops-icmpv6-filtering-recs-02.txt\" rel=\"external\"\u003edraft ICMPv6 filtering\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThese documents are all interesting, some are old, others more recent, and have the goal to think seriously about the security, to set up around ICMP.\u003c/p\u003e\n\u003cp\u003eThe \u0026ldquo;ICMP filtering\u0026rdquo; draft paper discuss about IPv4 and IPv6 protocols, and explains what attacks are possible, give useful recommendations, which range from refuse some packets to limit others.\u003c/p\u003e\n\u003cp\u003eClearly, certain messages codes are absolutely to be block, to refuse, like ICMP \u003ccode\u003e4/0\u003c/code\u003e, alias \u0026ldquo;\u003cstrong\u003eSource Quench\u003c/strong\u003e\u0026rdquo;, wich is explicetely deprecated, not to be used anymore… but it\u0026rsquo;s not the only one!\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\n\u003ch3 id=\"rfc-4890\"\u003eRFC 4890\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc4890\" title=\"RFC 4890: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc4890\" title=\"RFC 4890: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc4890.txt\" title=\"RFC 4890: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4890.html\" title=\"RFC 4890: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc4890.txt.pdf\" title=\"RFC 4890: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc4890.txt\" title=\"RFC 4890: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-5927\"\u003eRFC 5927\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc5927\" title=\"RFC 5927: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc5927\" title=\"RFC 5927: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc5927.txt\" title=\"RFC 5927: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5927.html\" title=\"RFC 5927: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc5927.txt.pdf\" title=\"RFC 5927: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc5927.txt\" title=\"RFC 5927: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-6633\"\u003eRFC 6633\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc6633\" title=\"RFC 6633: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc6633\" title=\"RFC 6633: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc6633.txt\" title=\"RFC 6633: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc6633.html\" title=\"RFC 6633: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc6633.txt.pdf\" title=\"RFC 6633: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc6633.txt\" title=\"RFC 6633: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\n\n\u003ch3 id=\"rfc-6918\"\u003eRFC 6918\u003c/h3\u003e\n\u003cdl class=\"rfc\"\u003e\n\t\u003cdt\u003eIETF Tools\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://tools.ietf.org/html/rfc6918\" title=\"RFC 6918: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/pdf/rfc6918\" title=\"RFC 6918: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://tools.ietf.org/rfc/rfc6918.txt\" title=\"RFC 6918: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\t\u003cdt\u003eRFC Editor\u003c/dt\u003e\n\t\u003cdd\u003e\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc6918.html\" title=\"RFC 6918: HTML format\"\u003eHTML\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/pdfrfc/rfc6918.txt.pdf\" title=\"RFC 6918: PDF format\"\u003ePDF\u003c/a\u003e,\n\t\t\u003ca href=\"https://www.rfc-editor.org/rfc/rfc6918.txt\" title=\"RFC 6918: TXT format\"\u003eTXT\u003c/a\u003e\n\t\u003c/dd\u003e\n\u003c/dl\u003e\n\u003c/p\u003e\n\u003ch3 id=\"wikipedia\"\u003eWikipedia\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Denial-of-service_attack#Attack_techniques\" title=\"Wikipedia Article: Denial-of-service_attack#Attack_techniques\"\u003e\n    Denial-of-service_attack#Attack_techniques\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Ping_of_death\" title=\"Wikipedia Article: Ping_of_death\"\u003e\n    Ping_of_death\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://en.wikipedia.org/wiki/Slowloris_%28computer_security%29\" title=\"Wikipedia Article: Slowloris_(computer_security)\"\u003e\n    Slowloris_(computer_security)\n    \u003csup\u003e\u003cabbr class=\"is-italic\" title=\"Wikipedia\"\u003eWP\u003c/abbr\u003e\u003c/sup\u003e\n\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n","summary":"Securely filtering the ICMP protocol under Linux: examples with iptables","tags":["Linux","firewall","ICMP","Iptables"],"date_published":"2017-07-26T21:03:54+02:00","date_modified":"2026-10-02T15:49:57+02:00"},{"id":"tag:doc.huc.fr.eu.org,2017-07-24:/en/dev/bash/script-convert-optimize-image","url":"https://it-log.fr.eu.org/en/dev/bash/script-convert-optimize-image/","title":"Bash: Convert, optimize image jpeg/png","author":{"name":"Stéphane HUC"},"content_text":"Description The script helps you to convert easy and optimize images jpg/png.\nThree options:\njpg2jpg: to optimize an image jpeg with a ratio to 70%. jpg2png: to convert an image jpg to an optimized image png. \u0026lt;span class\u0026quot;red\u0026quot;\u0026gt;Be carefull: the weigth grows up!. png2png: to optimize an image png. Please, install before using thoses tools:\nmogrify, by the package ImageMagick jpegtran, by the librarie libjpeg pngnq gvfs-info, by the package gvfs-bin The script : convert_image() #!/bin/bash # ./convert_image /name_dir/ options # options are: \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39;, \u0026#39;png2png\u0026#39; # you need ImageMagick tools, libjpeg (jpegtran), gvfs-bin # Convert image jpg # 1/ jpg to jpg, quality 70 and optimize : option jpg2jpg # 2/ jpg to png : option jp2png # 3/ png to optimize png : option png2png clear # define variables needed declare -a EXTS=( jpg JPG ) # extension accepted declare -i ARGS=2 # number of arguments accepted declare -i mssg=1 # to display message declare -i cmptr=0 # compteur declare -a MIME[1]=\u0026#34;image/jpeg\u0026#34; # mime type jpg declare -a MIME[2]=\u0026#34;image/png\u0026#34; # mime type png declare -a option=( jpg2jpg jpg2png png2png ) IFS=$\u0026#39;n\u0026#39; # functions needed ! function convert_image () { verify_args $1 $2 verify_bin create_vars_dir $1 $2 #empty_dir $dir_out empty_dir $dir_out2 create_dir $dir_out create_dir $dir_out2 for f in find $1 -type f; do create_vars_image case $mime in \u0026#34;${MIME[1]}\u0026#34;) case $2 in \u0026#34;${option[0]}\u0026#34;) increment jpg2jpg optimize_jpg empty_img_converted $dir_out $ff ;; \u0026#34;${option[1]}\u0026#34;) increment jpg2png optimize_png ;; *) exit ;; esac ;; \u0026#34;${MIME[2]}\u0026#34;) case $2 in \u0026#34;${option[2]}\u0026#34;) optimize_png ;; *) exit ;; esac ;; *) exit ;; esac done } function create_dir () { if [! -d $1](!_-d_$1); then if (( mssg == 1 )); then echo \u0026#34;*** Create directory $1 ***\u0026#34;; fi mkdir $1; fi } function create_vars_dir () { dir_out=$1\u0026#34;converted/\u0026#34; if (( mssg == 1 )); then echo \u0026#34;*** Create variables needed for $2 : dir_out ***\u0026#34;; fi dir_out2=$1\u0026#34;optim_jpg/\u0026#34; if (( mssg == 1 )); then echo \u0026#34;*** Create variables needed for $2 : dir_out2 ***\u0026#34;; fi } function create_vars_image () { dir=dirname $f ff=basename $f ext=${ff:(-3)}; name=basename $f .$ext #length=${#ff} #name=${ff:0:$length-4}; mime=gvfs-info --attributes=\u0026#34;standard::content-type\u0026#34; $f | grep \u0026#34;standard::content-type\u0026#34; | cut -c27- } function empty_dir () { if [ $1 ]; then if [-d $1](-d_$1); then cd $1 rm * if (( mssg == 1 )); then echo \u0026#34;~~~ Dir $1 empty! ~~~\u0026#34;; fi cd .. fi fi } function empty_img_converted () { if [ $1 ]; then if [-d $1](-d_$1); then if [$2]($2); then unlink $1$2; if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; 3/ Img $ff deleted in dir $1 !\u0026#34;; fi fi fi fi } function increment () { (( cptr++ )) if (( mssg == 1 )); then echo \u0026#34;$cptr :: Image $ff { Mime Type: $mime } to convert\u0026#34;; fi } function jpg2jpg () { cp $f $dir_out cd $dir_out if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; 1/ Convert image $ff to quality 70 ...\u0026#34;; fi mogrify -quality 70 $ff cd \u0026#34;..\u0026#34; } function jpg2png () { if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; Convert image $ff to PNG ...\u0026#34;; fi mogrify -format png $f } function optimize_jpg () { if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; 2/ Optimize image $ff with jpegtran ...\u0026#34;; fi jpegtran -optimize -progressive -perfect -copy all $dir_out$ff \u0026gt; $dir_out2$ff } function optimize_png () { if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; Deplace image $name.png to optimize-it! ...\u0026#34;; fi case $mime in \u0026#34;${MIME[1]}\u0026#34;) mv $1$name\u0026#34;.png\u0026#34; $dir_out ;; \u0026#34;${MIME[2]}\u0026#34;) cp $1$name\u0026#34;.png\u0026#34; $dir_out ;; *) exit ;; esac cd $dir_out if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; Optimize image $name.png with pngnq ...\u0026#34;; fi pngnq -vf -s1 \u0026#34;$name.png\u0026#34; if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; delete $name.png ...\u0026#34;; fi unlink \u0026#34;$name.png\u0026#34; if (( mssg == 1 )); then echo \u0026#34;=\u0026gt; Rename image PNG temporary in name $name.png ...\u0026#34;; fi mv \u0026#34;$name-nq8.png\u0026#34; \u0026#34;$name.png\u0026#34; #echo \u0026#34;=\u0026gt; Optimize image PNG {$name.png} with optipng ...\u0026#34; #optipng -o7 \u0026#34;$name.png\u0026#34; cd \u0026#34;..\u0026#34; } function status () { case $1 in 0) txt=\u0026#34;*** More argument; just call the script as: ./convert_image /name_dir/ \u0026#39;jpg2jpg|jpg2png|png2png\u0026#39; ***\u0026#34; ;; 1) txt=\u0026#34;*** Directory needed! ***\u0026#34; ;; 2) txt=\u0026#34;*** argument \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39; or \u0026#39;png2png\u0026#39; needed! ***\u0026#34; ;; 3) txt=\u0026#34;*** bad argument: argument is \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39; or \u0026#39;png2png\u0026#39;! ***\u0026#34; ;; 4) txt=\u0026#34;*** ERROR: Script stop here because the bin ***$2*** is not installed; in $3... ***\u0026#34; ;; esac if test -n \u0026#34;$txt\u0026#34;; then echo \u0026#34;$txt\u0026#34;; fi exit } function verify_args () { if test -z \u0026#34;$1\u0026#34;; then status 1; fi if [! -d $1](!_-d_$1); then exit; fi if test -z \u0026#34;$2\u0026#34;; then status 2; fi if (( $2 != \u0026#34;jpg2jpg\u0026#34; || $2 != \u0026#34;jpg2png\u0026#34; || $2 != \u0026#34;png2png\u0026#34; )); then status 3; fi } function verify_bin () { bin[1]=\u0026#34;jpegtran\u0026#34; bin[2]=\u0026#34;mogrify\u0026#34; bin[3]=\u0026#34;gvfs-info\u0026#34; get[1]=\u0026#34;libjpeg\u0026#34; get[2]=\u0026#34;ImageMagick Tools\u0026#34; get[3]=\u0026#34;gvfs-bin\u0026#34; for (( i=1 ; i\u0026lt;=3 ; i++ )) do if [[ ! -e \u0026#34;/usr/bin/${bin[$i]}\u0026#34; ]]; then status 4 \u0026#34;${bin[$i]}\u0026#34; \u0026#34;${get[$i]}\u0026#34;; fi done } # appel to the function convert_image if [ $# -ne \u0026#34;$ARGS\u0026#34; ]; then status 0 else convert_image $1 $2 fi Utilisation Use as exemple:\n$ chmod 0700 convert_image $ ./convert_image /name_dir/ option\n","content_html":"\u003ch2 id=\"description\"\u003eDescription\u003c/h2\u003e\n\u003cp\u003eThe script helps you to convert easy and optimize images jpg/png.\u003c/p\u003e\n\u003cp\u003eThree options:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003ejpg2jpg\u003c/code\u003e: to optimize an image jpeg with a ratio to 70%.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ejpg2png\u003c/code\u003e: to convert an image jpg to an optimized image png. \u0026lt;span class\u0026quot;red\u0026quot;\u0026gt;Be carefull: the weigth grows up!\u003c/span\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epng2png\u003c/code\u003e: to optimize an image png.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ePlease, install before using thoses tools:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003emogrify\u003c/code\u003e, by the package \u003cstrong\u003eImageMagick\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003ejpegtran\u003c/code\u003e, by the librarie \u003cstrong\u003elibjpeg\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003epngnq\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003egvfs-info\u003c/code\u003e, by the package \u003cstrong\u003egvfs-bin\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"the-script--convert_image\"\u003eThe script : convert_image()\u003c/h2\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre tabindex=\"0\" style=\"color:#e7e9db;background-color:#2f1e2e;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;\"\u003e\u003ccode class=\"language-bash\" data-lang=\"bash\"\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#!/bin/bash\n\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# ./convert_image /name_dir/ options\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# options are: \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39;, \u0026#39;png2png\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# you need ImageMagick tools, libjpeg (jpegtran), gvfs-bin\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  Convert image jpg\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  1/ jpg to jpg, quality 70 and optimize : option jpg2jpg\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  2/ jpg to png : option jp2png\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  3/ png to optimize png : option png2png\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eclear\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  define variables needed\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edeclare -a \u003cspan style=\"color:#ef6155\"\u003eEXTS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=(\u003c/span\u003e jpg JPG \u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# extension accepted\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003edeclare -i \u003cspan style=\"color:#ef6155\"\u003eARGS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e2\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# number of arguments accepted declare -i mssg=1 #\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eto display message declare -i \u003cspan style=\"color:#ef6155\"\u003ecmptr\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# compteur declare -a\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMIME\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e1\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;image/jpeg\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# mime type jpg declare -a\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003eMIME\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e2\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;image/png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#776e71\"\u003e# mime type png declare -a option=( jpg2jpg\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003ejpg2png png2png \u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#ef6155\"\u003eIFS\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e$\u0026#39;n\u0026#39;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e#  functions needed !\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e convert_image \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    verify_args \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    verify_bin\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    create_vars_dir \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#empty_dir $dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    empty_dir \u003cspan style=\"color:#ef6155\"\u003e$dir_out2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    create_dir \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    create_dir \u003cspan style=\"color:#ef6155\"\u003e$dir_out2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e     \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e f in find \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e -type f;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         create_vars_image\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$mime\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMIME\u003c/span\u003e[1]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                  \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoption\u003c/span\u003e[0]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             increment\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             jpg2jpg\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             optimize_jpg\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             empty_img_converted \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoption\u003c/span\u003e[1]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             increment\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             jpg2png\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             optimize_png\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMIME\u003c/span\u003e[2]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eoption\u003c/span\u003e[2]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             optimize_png\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                             exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                        ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e create_dir \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e! -d \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e](\u003c/span\u003e!_-d_\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** Create directory \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e ***\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         mkdir \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e create_vars_dir \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003edir_out\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;converted/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** Create variables needed for \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e : dir_out ***\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003edir_out2\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;optim_jpg/\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** Create variables needed for \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e : dir_out2 ***\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e create_vars_image \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e     \u003cspan style=\"color:#ef6155\"\u003edir\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003edirname \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e     \u003cspan style=\"color:#ef6155\"\u003eff\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ebasename \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#ef6155\"\u003eext\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eff\u003c/span\u003e:(-3)\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e     \u003cspan style=\"color:#ef6155\"\u003ename\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003ebasename \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e .\u003cspan style=\"color:#ef6155\"\u003e$ext\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#length=${#ff}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#name=${ff:0:$length-4};\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e     \u003cspan style=\"color:#ef6155\"\u003emime\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003egvfs-info --attributes\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;standard::content-type\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e | grep \u003cspan style=\"color:#48b685\"\u003e\u0026#34;standard::content-type\u0026#34;\u003c/span\u003e | cut -c27-\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e empty_dir \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e-d \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e](\u003c/span\u003e-d_\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              cd \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              rm *\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;~~~ Dir \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e empty! ~~~\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              cd ..\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e empty_img_converted \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e-d \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e](\u003c/span\u003e-d_\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e](\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   unlink \u003cspan style=\"color:#ef6155\"\u003e$1$2\u003c/span\u003e;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e                   \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; 3/ Img \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e deleted in dir \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e !\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e increment \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e cptr++ \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$cptr\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e :: Image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e { Mime Type: \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$mime\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e } to convert\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e jpg2jpg \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cp \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cd \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; 1/ Convert image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e to quality 70 ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    mogrify -quality 70 \u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e             \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cd \u003cspan style=\"color:#48b685\"\u003e\u0026#34;..\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e jpg2png \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; Convert image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e to PNG ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    mogrify -format png \u003cspan style=\"color:#ef6155\"\u003e$f\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e optimize_jpg \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; 2/ Optimize image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ff\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e with jpegtran ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    jpegtran -optimize -progressive -perfect -copy all \u003cspan style=\"color:#ef6155\"\u003e$dir_out$ff\u003c/span\u003e \u0026gt; \u003cspan style=\"color:#ef6155\"\u003e$dir_out2$ff\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e optimize_png \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; Deplace image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png to optimize-it! ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$mime\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMIME\u003c/span\u003e[1]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              mv \u003cspan style=\"color:#ef6155\"\u003e$1$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;.png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eMIME\u003c/span\u003e[2]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              cp \u003cspan style=\"color:#ef6155\"\u003e$1$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;.png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         *\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e              exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cd \u003cspan style=\"color:#ef6155\"\u003e$dir_out\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; Optimize image \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png with pngnq ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    pngnq -vf -s1 \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; delete \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    unlink \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003emssg\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e==\u003c/span\u003e 1 \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;=\u0026gt; Rename image PNG temporary in name \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png ...\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    mv \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e-nq8.png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$name\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e.png\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#echo \u0026#34;=\u0026gt; Optimize image PNG {$name.png} with optipng ...\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#776e71\"\u003e#optipng -o7 \u0026#34;$name.png\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    cd \u003cspan style=\"color:#48b685\"\u003e\u0026#34;..\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e status \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003ecase\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e in\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         0\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etxt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** More argument; just call the script as: ./convert_image /name_dir/ \u0026#39;jpg2jpg|jpg2png|png2png\u0026#39; ***\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         1\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etxt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** Directory needed! ***\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         2\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etxt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** argument \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39; or \u0026#39;png2png\u0026#39; needed! ***\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         3\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etxt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** bad argument: argument is \u0026#39;jpg2jpg\u0026#39;, \u0026#39;jpg2png\u0026#39; or \u0026#39;png2png\u0026#39;! ***\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         4\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003etxt\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;*** ERROR: Script stop here because the bin ***\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e*** is not installed; in \u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$3\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e... ***\u0026#34;\u003c/span\u003e ;;\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eesac\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e test -n \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$txt\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e echo \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$txt\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    exit\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e verify_args \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e test -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e status 1; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e! -d \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e](\u003c/span\u003e!_-d_\u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e)\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e exit; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e test -z \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e status 2; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;jpg2jpg\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e||\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;jpg2png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e||\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e !\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;png2png\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e status 3; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efunction\u003c/span\u003e verify_bin \u003cspan style=\"color:#5bc4bf\"\u003e()\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e{\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    bin\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e1\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;jpegtran\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    bin\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e2\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;mogrify\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    bin\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e3\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;gvfs-info\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    get\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e1\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;libjpeg\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    get\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e2\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;ImageMagick Tools\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    get\u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e3\u003cspan style=\"color:#5bc4bf\"\u003e]=\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;gvfs-bin\u0026#34;\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e      \n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003efor\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e((\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003ei\u003c/span\u003e\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e1 ; i\u0026lt;\u003cspan style=\"color:#5bc4bf\"\u003e=\u003c/span\u003e3 ; i++ \u003cspan style=\"color:#5bc4bf\"\u003e))\u003c/span\u003e \u003cspan style=\"color:#815ba4\"\u003edo\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e         \u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[[\u003c/span\u003e ! -e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;/usr/bin/\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ebin\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e status 4 \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003ebin\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#f99b15\"\u003e${\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003eget\u003c/span\u003e[\u003cspan style=\"color:#ef6155\"\u003e$i\u003c/span\u003e]\u003cspan style=\"color:#f99b15\"\u003e}\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    \u003cspan style=\"color:#815ba4\"\u003edone\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#5bc4bf\"\u003e}\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#776e71\"\u003e# appel to the function convert_image\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eif\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e[\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$#\u003c/span\u003e -ne \u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e\u003cspan style=\"color:#ef6155\"\u003e$ARGS\u003c/span\u003e\u003cspan style=\"color:#48b685\"\u003e\u0026#34;\u003c/span\u003e \u003cspan style=\"color:#5bc4bf\"\u003e]\u003c/span\u003e; \u003cspan style=\"color:#815ba4\"\u003ethen\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    status \u003cspan style=\"color:#f99b15\"\u003e0\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003eelse\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e    convert_image \u003cspan style=\"color:#ef6155\"\u003e$1\u003c/span\u003e \u003cspan style=\"color:#ef6155\"\u003e$2\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\n\u003c/span\u003e\u003c/span\u003e\u003cspan style=\"display:flex;\"\u003e\u003cspan\u003e\u003cspan style=\"color:#815ba4\"\u003efi\u003c/span\u003e\n\u003c/span\u003e\u003c/span\u003e\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\u003ch2 id=\"utilisation\"\u003eUtilisation\u003c/h2\u003e\n\u003cp\u003eUse as exemple:\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003e$ chmod 0700 convert_image $ ./convert_image /name_dir/ option\u003c/code\u003e\u003c/p\u003e\n\u003chr\u003e\n","summary":"Script bash to convert, optimize and minimize jpg or png image","tags":["Bash","convert","optimize","image"],"date_published":"2017-07-24T16:56:42+01:00","date_modified":"2017-07-28T12:34:17+01:00"}]}