Busy with updates – FreeBSD 14.3

Finally found some time and upgraded both servers to 14.3 and trying to establish a stable baseline of installed apps like Apache, MySql, PHP, Perl, and Samba so I can easily port the remaining services over to the “new” server and retire the older one before it expires.

Setting up a new Wifi SSID for the older devices meant the Washing Machine, and cycle computer now connect easily and the Cameras appear to be more stable.

iOS 26 dropped last month but with no real massive technical changes, but now waiting for a new iPhone 17 to see Apple Intelligence live and in action as current iPad and iPhone are too old to benefit.

Its been quite a successful month with just the iKettle left to fix, but this seems to be an issue with the App or backend server as I can see its connected to the Wifi fine and can ping it fine, and I don’t seem to be the only one with issues with the smarter.io kettle range.

Perl updated to 5.40

so that means another forced updated of everything built with PERL. Not sure why /usr/ports/UPDATING keeps pointing us back to 2023 when they could just post the postmaster commands to update from the last default version to new default version… heyho.

portmaster -o lang/perl5.40 lang/perl5.36

portmaster -f `pkg shlib -qR libperl.so.5.36`

Cyber Security Certifications

Often get asked which Cyber Security courses are worth doing. Well there is an absolute plethora of different courses available to suit relevant backgrounds. A colleague found this and it look pretty useful

Alexa+ – Alexa on Steriods with AI

Echo Dot

Amazon are adding new powers existing Alexas over the coming weeks and months.
More details here

Question is how much privacy will be sacrificed for the enhanced functionality. Scant detail on the original product launch blog.

Domain Name Mismatch – Your site is insecure

I don’t know if Apple, and Google upped the ante, or I had not noticed before, or the SSL tools on the server had not kept updated, but I started getting warnings that my site was not secure. Letsencrypt has done a pretty good job for the last 5 years so I was confused as to why suddenly now , the browsers no longer liked up. Even harder now that MS Edge do not let you easily view the full cert.

A quick test at SSLlabs confirmed that the SSL for farcorfe.org.uk was all ok, but the sub-domain of www.farcorfe.org,uk was the actual issue. The SSL cert had not been validated for the www redirect.

Some quick Googling found this page – https://stackoverflow.com/questions/41097696/letsencrypt-certificate-for-www-and-non-www-domain with the required Certbot commands to add the www to the cert and a restart of Apache got the issue fixed.

Upgrade complete. 13 >> 14.2

I was very wary about the jump to 14 due to the change in Openssl from 1.1 to 3.0 and the pain that might entail. Also the deprecation of portsnap and getting used to Git was just something I did not have time for.

As I have created a new mirror site , see earlier post, I finally decided to bite the bullet over the festive break and did the freebsd-update upgrade option to 14.2, skipping out 14.0 and 14.1 in the process.

I was a little daunted and it failed to automatically upgrade everything to openssl 3.0 and although built the kernel and rebooted nicely, user land was still doggedly sticking to 1.1. I tried tinkering with make.conf in /etc with various default entries for openssl , but in the end removing the ssl version and just ssl=openssl and then making the usr/ports/openssl allowed 3.0 to install side by side with 1.1 thereby not breaking SSH or anything else until I was able to rebuild all of user land port by port. I was then able to complete freebsd-update install and now have another stable freebsd server for testing and training purposes.

Now I only need to fire this box up when I need Samba to move files around the network or download stuff off YouTube or run a Clamav as a 2nd pass for AV scanning and when I have time to dabble some more with FreeBSD.

Disk space solved – ZFS snapshots – DRAFT

Finally resolved the diminishing lack of free disk space for future FreeBSD updates. It seems that since version xx.x each upgrade as made a ZFS snapshot taking 1-3Gb each for each successive version. As the hardware has been running since 2017 that’s an awful lot of major and point revision snapshots.

DU and DF hid those successive snapshots and I was blaming my ever expanding OneDrive offline sync for taking excessive amounts of disk space even though I was convinced I had move the sync folder to the slave disk some time ago.

As I have never needed to roll back a ZFS snapshot I had never needed to explore what amount of space they took, or even how to display their usage, even less so how to delete them. Necessity being the mother of all invention, or least the need for a proper Google session I finally found the commands and confidence to delete 12 previous incarnations of FreeBSD and give me back the free disk I need to apply the next edition of FreeBSD.

Windows 10 – the final curtain

It might seem odd that at work we are still in the final throes of migrating users to the latest version of Windows 10 and killing off the handful of Windows 7 devices that invariably turn up as you shutdown legacy domains and SCCM servers, but attention has now rapidly turned to Windows 11 now that the final support date for all versions of Windows 10 has been confirmed as 14th October 2025.

With over 30,000 devices to migrate in 18 months I dare say my project managers will be having a few sleepless nights as they calculate how many devices per week they need to cycle thru Win10 onto Win11 so we are ready.

Bulk Emailers and Spoofing email

Recent industry changes by Apple, Google and Yahoo have meant many queries at work as we have ramped up our SPF, DMARC and DKIM settings to prevent spammers spoofing our domains.

In short, 3rd party suppliers that provide web services for us are no longer able to just spoof our domains and need to register their email servers on our DNS SPDF record as an authorised sender. Many question why they need to do this, when its worked for years and trying to point out that was was ok in 2014 is not okay now in 2024 if we want to stop the spoofers and spammers trying to snare our users that rely on our services.

NCSC provide a service to report phishing emails to them as report@phishing.gov.uk and tools to check how secure a domain is when you want to see how likely it is to be spoofed, ie sent pretending to be someone else, available here.

Apple Beta Updates

Back from holiday so have now installed the new iPhone, Watch and AppleTV beta updates, and may have found a killer feature in the WatchOS update which allows the Watch to connect to my bike Bluetooth Cadence sensor, so effectively making the cycle computer redundant as the Apple Health cycle mode will replicate all the functions the cycle computer will do. Interesting to see how this might impact battery life though on the watch given it will be much more active during rides.

Seems to be lots of little changes to iPhone in terms of widgets and messaging integration, but probably more updates for the Instagram generation rather than myself. Early days yet so will probably find more useful features as I delve and others update so the SharePlay functions come into their own.