I just update Firefox from 13 to 14.0.1 and after I applied the trick described earlier this year, I was disappointed that it didn't work any more. First, I thought that Mozilla has changed its API too much so that Google Toolbar doesn't work any more. But I googled for a solution and found one in a few seconds:
http://www.philognosie.net/index.php/forum/message/2255/
And it worked! :-)
Donnerstag, 2. August 2012
Mittwoch, 1. August 2012
Renault Fluence ZE: Ein echtes E-Auto von Renault
Nachdem es mir der Renault Twizy ja nicht gerade so angetan hatte, wagte ich für heute und morgen eine Fahrt mit dem Renault Fluence ZE. Das ZE steht dabei für Zero Emission und meint, dass das Fahrzeug während der Fahrt keine Schadstoffe in die Luft emittiert. Wird der Fluence ZE mit Strom aus regenerativen Energien wie Wasserkraft, Photovoltaik und dergleichen geladen, stimmt das ZE auch für die Energiegewinnung und man fährt tatsächlich emissionsfrei (hinsichtlich Luftschadstoffen). Wie für Elektrofahrzeuge üblich hat der Fluence ZE eine außerordentlich gute Beschleunigung schon vom Stand weg (zum Vergleich mit dem Opel Ampera zieht er ein bisschen weniger rasant weg) und ist sehr leise (daher auch sehr geringe Lärmemissionen). Etwas störend finde ich, dass die Konsole mit den Anzeigen schräg ist.
Kurzes Video: http://youtu.be/EaulA_rf82k
Etwas enttäuscht war ich vom Kofferraum, der recht klein ist. Unser Kinderwagen passt hier wahrscheinlich nicht gut rein.
Die Reichweite des Renault Fluence ZE beträgt im Winter etwa 100 km und bei normaler Temperatur, d.h. wenn man weder Klimaanlage noch Heizung benötigt, etwa 150 km. Auf 100 km kostet er also zwischen etwa € 2,90 und € 4,40 (Batterie hat 22 kWh Kapazität). Außerdem ist das Parken in Graz in der Kurzparkzone mit diesem Fahrzeug kostenlos. Mit 3 Jahren Batteriemiete kommt er bei einer Kilometerleistung von 15.000 km pro Jahr auf etwa € 32.000 (Renault Fluence ZE Preisliste). Dafür erspart man sich in diesem Zeitraum, wenn man 15.000 km pro Jahr fährt und das Fahrzeug im Mittel € 3,65 für 100 km benötigt hat, gegenüber einem Fahrzeug mit 6 l Treibstoffverbrauch bei aktuell etwa € 1,40 pro Liter Treibstoff etwa € 2.100 an Verbrauchskosten.
Kurzes Video: http://youtu.be/EaulA_rf82k
Etwas enttäuscht war ich vom Kofferraum, der recht klein ist. Unser Kinderwagen passt hier wahrscheinlich nicht gut rein.
Die Reichweite des Renault Fluence ZE beträgt im Winter etwa 100 km und bei normaler Temperatur, d.h. wenn man weder Klimaanlage noch Heizung benötigt, etwa 150 km. Auf 100 km kostet er also zwischen etwa € 2,90 und € 4,40 (Batterie hat 22 kWh Kapazität). Außerdem ist das Parken in Graz in der Kurzparkzone mit diesem Fahrzeug kostenlos. Mit 3 Jahren Batteriemiete kommt er bei einer Kilometerleistung von 15.000 km pro Jahr auf etwa € 32.000 (Renault Fluence ZE Preisliste). Dafür erspart man sich in diesem Zeitraum, wenn man 15.000 km pro Jahr fährt und das Fahrzeug im Mittel € 3,65 für 100 km benötigt hat, gegenüber einem Fahrzeug mit 6 l Treibstoffverbrauch bei aktuell etwa € 1,40 pro Liter Treibstoff etwa € 2.100 an Verbrauchskosten.
Montag, 2. Juli 2012
Transparent proxy: Preventing redirection for specific hosts
Recently, I used a self-written application (C#, .net Framework 2.0) that uses a web service, and suddenly it didn't work any more. The first attempt to call the service threw a network connection exception (the underlying connection was closed unexpectedly), the second one an HTTP exception (417 Expectation Failed). I first thought that something on the server would be wrong, but after some googling, I found out that it was my proxy (squid3), which runs as a transparent proxy on my home network. Consequently, it was my goal to exclude the IP address of the server that runs the web service from the iptables rule that does the redirection. I already had excluded my LAN and iptables wouldn't allow to exclude more than one IP address or subnet. So, I had to dive into "ipset". The commands are quite simple:
"1.2.3.4" is just an example! You can replace it with any other IP address. Note that adding "192.168.1.0/24" effectively adds 256 hosts to the "noproxy" list! Unfortunately, ipset only allows to add 65.536 entries, so if you add a /16-subnet, the list is full already. Another (rather small) issue with ipset is that you cannot destroy a set while it is in use, so you always must delete the iptables rule that uses it before. But the really great advantage of ipset is that you can add and remove hosts from a set any time without touching iptables chains. For example, if I would like to allow transparent proxy for 192.168.1.6, I just do a
and iptables does what I want. The command means "remove 192.168.1.6" from set "noproxy".
ipset -N noproxy iphash
ipset -A noproxy 192.168.1.0/24
ipset -A noproxy 1.2.3.4
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -m set ! --set noproxy dst -j REDIRECT --to-port 3128
ipset -A noproxy 192.168.1.0/24
ipset -A noproxy 1.2.3.4
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -m set ! --set noproxy dst -j REDIRECT --to-port 3128
"1.2.3.4" is just an example! You can replace it with any other IP address. Note that adding "192.168.1.0/24" effectively adds 256 hosts to the "noproxy" list! Unfortunately, ipset only allows to add 65.536 entries, so if you add a /16-subnet, the list is full already. Another (rather small) issue with ipset is that you cannot destroy a set while it is in use, so you always must delete the iptables rule that uses it before. But the really great advantage of ipset is that you can add and remove hosts from a set any time without touching iptables chains. For example, if I would like to allow transparent proxy for 192.168.1.6, I just do a
ipset -D noproxy 192.168.1.6
and iptables does what I want. The command means "remove 192.168.1.6" from set "noproxy".
Donnerstag, 21. Juni 2012
Nicht ganz (wasser)dicht: Renault Twizy
Heute bin ich das erste Mal mit dem Renault Twizy gefahren. Das Auto (wenn es denn diese Bezeichnung schon verdient) ist bestenfalls witzig. Leider hatte ich die Wetterprognose nicht gelesen und es mir ausgeborgt, obwohl ich wusste, dass es keine Fenster hat. Bei Regen muss man es schnell wo unterstellen, denn da es keine Fenster hat, regnet es ins Fahrzeug hinein. Das Fahren damit ist generell ganz nett und sehr ähnlich wie mit anderen E-Autos. Ein kleiner Unterschied ist, dass er keinen Ganghebel für die Modi "D" (Drive), "N" (Neutral), "P" (Park) und "R" (Reverse) (und ggf. Weitere) hat sondern Knöpfe, wo man eben auf "D" oder "R" drückt.
Da es kein "P" gibt, hat das Auto eine manuell zu bedienende Handbremse. Es gibt auch ein kleines Handschuhfach, ich bezweifle jedoch, dass das irgendeinen Dieb auch nur annähernd abhalten könnte:
Die Beschleunigung kam mir subjektiv nicht so gut vor wie beim Think City oder Mitsubishi iMiev. Außerdem spürt man jedes kleine Steinchen. Selbst zum Stadtfahren (sonst ja die Stärke von E-Autos) eignet sich der Renault Twizy also nur bedingt. Sein Haupteinsatzgebiet sehe ich eher in Firmengeländen. Dadurch, dass er sehr klein ist, könnte man damit auch problemlos in Gebäuden herumfahren und zum Beispiel kleinere Güter befördern. Interessant ist, dass er nicht so wie andere Fahrzeuge beschleunigt, wenn man von der Bremse geht. Eine Anzeige auf der Konsole zeigt nebst Geschwindigkeit in Digitalform auch den Batteriestand an und wieviel Energie der Batterie gerade entzogen wird oder ob diese gerade geladen wird (wird durch einen Pfeil Richtung Batterie dargestellt).
Auch beim Laden unterscheidet sich der Renault Twizy von den anderen E-Autos, die ich kenne: Man steckt nicht den Ladestecker ins Auto, sondern zieht den Ladestecker aus dem Auto heraus, so ähnlich wie beim Staubsauger. Die Türen gehen nach oben hin auf, nicht seitlich so wie sonst üblich. Und so sieht er aus, der Renault Twizy:
So sehen Lenkrad und Amaturenbrett aus:
Fazit: Hätte Renault dem Auto Fenster verpasst und vielleicht eine etwas bessere Federung, wäre es ganz brauchbar, wenn man bspw. alleine damit in die Arbeit fährt (hinten kann nur eine kleine Person sitzen - mein Sohn Tobias (4) hat's ausprobiert, für ihn hat's geklappt). Aber so ist der Nutzen eben nur recht eingeschränkt.
Da es kein "P" gibt, hat das Auto eine manuell zu bedienende Handbremse. Es gibt auch ein kleines Handschuhfach, ich bezweifle jedoch, dass das irgendeinen Dieb auch nur annähernd abhalten könnte:
Die Beschleunigung kam mir subjektiv nicht so gut vor wie beim Think City oder Mitsubishi iMiev. Außerdem spürt man jedes kleine Steinchen. Selbst zum Stadtfahren (sonst ja die Stärke von E-Autos) eignet sich der Renault Twizy also nur bedingt. Sein Haupteinsatzgebiet sehe ich eher in Firmengeländen. Dadurch, dass er sehr klein ist, könnte man damit auch problemlos in Gebäuden herumfahren und zum Beispiel kleinere Güter befördern. Interessant ist, dass er nicht so wie andere Fahrzeuge beschleunigt, wenn man von der Bremse geht. Eine Anzeige auf der Konsole zeigt nebst Geschwindigkeit in Digitalform auch den Batteriestand an und wieviel Energie der Batterie gerade entzogen wird oder ob diese gerade geladen wird (wird durch einen Pfeil Richtung Batterie dargestellt).
Auch beim Laden unterscheidet sich der Renault Twizy von den anderen E-Autos, die ich kenne: Man steckt nicht den Ladestecker ins Auto, sondern zieht den Ladestecker aus dem Auto heraus, so ähnlich wie beim Staubsauger. Die Türen gehen nach oben hin auf, nicht seitlich so wie sonst üblich. Und so sieht er aus, der Renault Twizy:
So sehen Lenkrad und Amaturenbrett aus:
Fazit: Hätte Renault dem Auto Fenster verpasst und vielleicht eine etwas bessere Federung, wäre es ganz brauchbar, wenn man bspw. alleine damit in die Arbeit fährt (hinten kann nur eine kleine Person sitzen - mein Sohn Tobias (4) hat's ausprobiert, für ihn hat's geklappt). Aber so ist der Nutzen eben nur recht eingeschränkt.
Freitag, 15. Juni 2012
First Look At NetBSD 6.0 Beta 2
The NetBSD team recently announced Beta 2 of NetBSD 6.0 and I would like to know in special how good its IPv6 support is. Although I have no productive use of NetBSD and haven't used it in any project yet, nor did I ever work on a productive NetBSD system somewhere else, I'm interested in NetBSD and track its progress because its diversity of available platforms.
I downloaded the amd64 ISO and installed it in a virtual machine using VMware Player 4.0.0 on Windows Server 2008. The installation went quite quick, it didn't even need 10 minutes! One of the first thing that should be done after installation is activating the SSH server, which can be done by executing "chmod u+w /etc/ssh/sshd_config" to enable editing the configuration file of the SSH server and then "vi /etc/ssh/sshd_config", uncommenting "Port 22", "AddressFamily any" and "PermitRootLogin" by pressing the "x" key, than setting the cursor to the "n" of "no", pressing "xx", then "i" and enter "yes" and last but not least pressing ESC and ":wq" to write the file and exit that masochistic program. "/etc/rc.d/sshd restart" restarts the SSH server. Now you can log in using SSH which is much more comfortable, because you can use copy & paste if you find some tips on the web!
Next important thing is to configure "pkg_add" which is required to install software. Last time we need that program that got stuck in 1960! Do a "vi ~/.profile" and go the first line that begins with "export PKG_PATH", press "x" do delete the "#" sign and then ESC, ":wq" to write the file. Now log off and on again or reboot.
With "pkg_add -v nano" we can install an editor that has at least the usability of a 1980 program. Then you could again edit your .profile using "nano ~/.profile" and for example add your favorite aliases. Mine ones are "alias dir='ls -lh'" and "alias adir='ls -lha'". :-)
Helpful documents can be found here and here.
I downloaded the amd64 ISO and installed it in a virtual machine using VMware Player 4.0.0 on Windows Server 2008. The installation went quite quick, it didn't even need 10 minutes! One of the first thing that should be done after installation is activating the SSH server, which can be done by executing "chmod u+w /etc/ssh/sshd_config" to enable editing the configuration file of the SSH server and then "vi /etc/ssh/sshd_config", uncommenting "Port 22", "AddressFamily any" and "PermitRootLogin" by pressing the "x" key, than setting the cursor to the "n" of "no", pressing "xx", then "i" and enter "yes" and last but not least pressing ESC and ":wq" to write the file and exit that masochistic program. "/etc/rc.d/sshd restart" restarts the SSH server. Now you can log in using SSH which is much more comfortable, because you can use copy & paste if you find some tips on the web!
Next important thing is to configure "pkg_add" which is required to install software. Last time we need that program that got stuck in 1960! Do a "vi ~/.profile" and go the first line that begins with "export PKG_PATH", press "x" do delete the "#" sign and then ESC, ":wq" to write the file. Now log off and on again or reboot.
With "pkg_add -v nano" we can install an editor that has at least the usability of a 1980 program. Then you could again edit your .profile using "nano ~/.profile" and for example add your favorite aliases. Mine ones are "alias dir='ls -lh'" and "alias adir='ls -lha'". :-)
Helpful documents can be found here and here.
Donnerstag, 7. Juni 2012
Migration from dnsmasq to bind9 9.8.1
First I'd like to say, that dnsmasq is a great product, but there were some issues for me:
Forwarding DNS requests isn't difficult there, too. I just added this line to "/etc/bind/named.conf":
include "/etc/bind/named.conf.gspdc";
In "named.conf.gspdc", there are the definitions for the zones that should be forwarded:
zone "greatsoft.local" {
type forward;
forwarders { 192.168.1.2; };
};
zone "virtual" {
type forward;
forwarders { 192.168.1.2; };
};
After doing a "service bind9 restart", it did not work! With nslookup in Windows, I got errors like this one:
speedy.greatsoft.local can't find debian.greatsoft.local: Non-existent domain
In the log file on the server, entries like this one appeared:
Jun 7 22:18:15 speedy named[3725]: validating @0x7f3488535e10: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: validating @0x7f3480040480: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: error (no valid RRSIG) resolving 'debian.greatsoft.local.greatsoft.local/DS/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: error (insecurity proof failed) resolving 'debian.greatsoft.local.greatsoft.local/A/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: validating @0x7f347801bc80: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: error (no valid RRSIG) resolving 'debian.greatsoft.local/DS/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: error (insecurity proof failed) resolving 'debian.greatsoft.local/A/IN': 192.168.1.2#53
But that could be solved easily with changing the following in named.conf.options:
old: dnssec-validation auto;
new: dnssec-validation no;
I found the solution here: https://bugzilla.redhat.com/show_bug.cgi?id=682482
Conclusion: Migrating from dnsmasq to bind9 is easy and offers you enhanced possibilities. However, for small networks that only need a simple DNS cache, I still warmly recommend dnsmasq.
- It doesn't provide DNS64
- There have been troubles with DNS forwardings in my LAN
- I didn't find a way to allow requests from outside my LAN, I needed to allow at least one public IP address to request zone transfers from my DNS server
Forwarding DNS requests isn't difficult there, too. I just added this line to "/etc/bind/named.conf":
include "/etc/bind/named.conf.gspdc";
In "named.conf.gspdc", there are the definitions for the zones that should be forwarded:
zone "greatsoft.local" {
type forward;
forwarders { 192.168.1.2; };
};
zone "virtual" {
type forward;
forwarders { 192.168.1.2; };
};
After doing a "service bind9 restart", it did not work! With nslookup in Windows, I got errors like this one:
speedy.greatsoft.local can't find debian.greatsoft.local: Non-existent domain
In the log file on the server, entries like this one appeared:
Jun 7 22:18:15 speedy named[3725]: validating @0x7f3488535e10: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: validating @0x7f3480040480: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: error (no valid RRSIG) resolving 'debian.greatsoft.local.greatsoft.local/DS/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: error (insecurity proof failed) resolving 'debian.greatsoft.local.greatsoft.local/A/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: validating @0x7f347801bc80: greatsoft.local SOA: got insecure response; parent indicates it should be secure
Jun 7 22:18:15 speedy named[3725]: error (no valid RRSIG) resolving 'debian.greatsoft.local/DS/IN': 192.168.1.2#53
Jun 7 22:18:15 speedy named[3725]: error (insecurity proof failed) resolving 'debian.greatsoft.local/A/IN': 192.168.1.2#53
But that could be solved easily with changing the following in named.conf.options:
old: dnssec-validation auto;
new: dnssec-validation no;
I found the solution here: https://bugzilla.redhat.com/show_bug.cgi?id=682482
Conclusion: Migrating from dnsmasq to bind9 is easy and offers you enhanced possibilities. However, for small networks that only need a simple DNS cache, I still warmly recommend dnsmasq.
Samstag, 14. April 2012
Firefox 11: Catastrophic usability (add-ons upgrade)

What the f*** is that??? Does Mozilla want to loose even more users? Haven't they lost enough yet? If they continue that way, I'll go away from Mozilla Firefox to some other browser. To develop a shit like the new add-on update behavior is a huge provocation! If you have about 10 add-ons and three or four designs, like I have, you have to check "Allow this installation", click "Continue" and then close the tab (otherwise it would restart Firefox after every (!) installation) for every add-on! This is complete crap. Previously, there was a dialog where you could see all your add-ons in a list with check marks and could decide, which add-ons you would like to keep and those were updated. So simple. But now Mozilla decided to make it that complicated. Poor.
Abonnieren
Posts (Atom)
