I tried this guide today but pita stucked due to firewall configuration, though sys-net configuration might have successful but don’t know for sure. So thinking about Mirage firewall now.
It would be helpful (if you are looking for help) if you were to say what
issues you had with “firewall configuration”. Was it a problem with
sys-firewall or with the firewall in the OpenBSD qube?
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
I was trying with linux firewall based on debian but I don’t know how to configure it with openbsd sys net.
I can’t find sha256sum of install76.iso.
That should be next to the ISO file (e.g. https://openbsd.cs.toronto.edu/pub/OpenBSD/7.6/amd64/SHA256).
Does sys-firewall in this guide means qubes-mirage-firewall always?
No, any firewall can be used, the author used qubes-mirage-firewall because the only configuration out-of-the-box is the kernelopts command line, whereas the linux sys-firewall needs some additional instructions inside the VM.
Pkg_add wget only working if I add nameserver something outside qubes has assigned to vm. Is this expected?
Also fw_update fails with timeout on reboot.
Yes.
Qubes using internal addresses which are simply passed up the
network chain until the DNS traffic is translated to the DNS assigned to
sys-net.
In this setup, that wouldn’t make sense, so you have to use the DNS
assigned by the upstream network,
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
You should probably read some of the OpenBSD documentation
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
Successfully setup openbsd with Mirage firewall today based on original post.
One minor caveat -
Will sys-net-openbsd window has to be visible all time it’s running or some option available so that it remain hidden.
I think there is no X11 headless integration (but I’ve never tried). You may reduce the window by scrolling the mouse wheel in the window title (but that remains manual) ?
I think there is a command line setting using qvm-prefs, but I don’t remember the setting name
Does any of you suggest that sys-net-openbsd should be disposable?
There are pros and cons to this. OpenBSD randomises the kernel for the next boot with KARL, so It will never happen again in a disposable.
I also think the seed for randomness is created on shutdown for the next boot so you will always start with the same random seed. The entropy will not be great.
But if you set it disposable, any successful attack would be wiped out on reboot.
I thought that there were two seed files which are rewritten at boot,
shutdown, and reboot, as well as many sources of randomness.
If you create an HVM template then any qube using it will be a
disposable.
Depends what you mean by “visible” - you can minimise it, or move it to
some Activity(KDE) reserved for such a purpose.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
Without any specific contextual reference and just as a general comment:
Many thanks for the support and documentation!
As much as I welcome the constant search for ways to minimise or even eliminate ‘systemic or conceptual weaknesses’, it cannot be pointed out often enough that we are sometimes creating two new problems with one solution.
I don’t want to make this exclusive to sys-net-openbsd. But with regard to some of the questions posed here, as well as the ‘secondary’ workarounds that are recommended, I would like to point out three essential principles of security architecture:
- Keep it simple. As simple as possible.
- As long as you don’t understand the problem that a supposed solution solves, the solution is not for you. (The same applies to understanding the solution.)
- It is wrong to judge (or advertise) the security and strength of a chain on the basis of a single link.
These are words of wisdom that should be engraved in stone.
Most users of Qubes would be best served by using the system as it
is provided.
I never presume to speak for the Qubes team.
When I comment in the Forum I speak for myself.
Hi, thank you for your feedback.
I want to point out that there were some guides available on this topic, but they were either outdated or quite unclear (like the unman notes). It’s interesting to see critiques suggesting that the approach isn’t simple or doesn’t solve a problem.
People have already been experimenting with this without any some sort of guide, and the purpose of this guide is to provide clarity so that others can try it out. There are also plans to implement a hardened sys-net (for instance, Demi’s comment about replacing sys-net with a hardened version, though I can’t find the specific thread right now). Additionally, I find it noteworthy that when unman was tagged in related discussions on other threads for help with this setup, he didn’t respond, yet now he is actively engaged with this guide. I also made sure to include a clear warning at the beginning, stating that this should not be attempted without some basic knowledge.
You can move the window to your next workspace it’ll will be out of sight