"Free, Functional & Secure"
|Company / developer||The OpenBSD Project|
|OS family||Unix-like (BSD)|
|Source model||Open source|
|Initial release||1 October 1996|
|Latest release||5.4 (November 1, 2013[±])|
|Latest preview||5.5 -current (ongoing) [±]|
|Package manager||OpenBSD package tools and ports tree|
|Supported platforms||68000, Alpha, x86-64, i386, MIPS, PowerPC, SPARC 32/64, VAX, Zaurus and others|
|Default user interface||Modified pdksh, FVWM 2.2.5 for X11|
|License||BSD, ISC, ATU, other custom licenses|
OpenBSD is a Unix-like computer operating system descended from Berkeley Software Distribution (BSD), a Unix derivative developed at the University of California, Berkeley. It was forked from NetBSD by project leader Theo de Raadt in late 1995. As well as the operating system, the OpenBSD Project has produced portable versions of numerous subsystems, most notably PF, OpenSSH and OpenNTPD, which are very widely available as packages in other operating systems.
The project is also widely known for the developers' insistence on open-source code and quality documentation, uncompromising position on software licensing, and focus on security and code correctness. The project is coordinated from de Raadt's home in Calgary, Alberta, Canada. Its logo and mascot is a pufferfish named Puffy.
OpenBSD includes a number of security features absent or optional in other operating systems, and has a tradition in which developers audit the source code for software bugs and security problems. The project maintains strict policies on licensing and prefers the open-source BSD licence and its variants—in the past this has led to a comprehensive license audit and moves to remove or replace code under licences found less acceptable.
As with most other BSD-based operating systems, the OpenBSD kernel and userland programs, such as the shell and common tools like cat and ps, are developed together in one source code repository. Third-party software is available as binary packages or may be built from source using the ports tree. Also like most modern BSD operating systems, it is capable of running binary code compiled for Linux in a compatible computer architecture at full speed in compatibility mode.
The OpenBSD project maintains ports for 20 different hardware platforms, including the DEC Alpha, Intel i386, Hewlett-Packard PA-RISC, x86-64 and Motorola 68000 processors, Apple's PowerPC machines, Sun SPARC and SPARC64-based computers, the VAX and the Sharp Zaurus. The OpenBSD Foundation was accepted as a mentoring organization for Google Summer of Code 2014.
- 1 Uses
- 2 OpenBSD component projects
- 3 Third Party components in the base system
- 4 Development and release process
- 5 History and popularity
- 6 Open source and open documentation
- 7 Licensing
- 8 Funding
- 9 Security and code auditing
- 10 Distribution and marketing
- 11 Bibliography
- 12 See also
- 13 References
- 14 External links
Proprietary systems from several manufacturers are based on OpenBSD, including devices from Armorlogic (Profense web application firewall), Calyptix Security, GeNUA mbH, RTMX Inc, and .vantronix GmbH. Later versions of Microsoft's Services for UNIX, an extension to the Windows operating system which provides some Unix-like functionality, use much OpenBSD code included in the Interix interoperability suite, developed by Softway Systems Inc., which Microsoft acquired in 1999. Core Force, a security product for Windows, is based on OpenBSD's pf firewall.
OpenBSD ships with the X window system and is suitable for use on the desktop. Packages for popular desktop tools are available, including desktop environments GNOME, KDE, and Xfce; web browsers Konqueror, Mozilla Firefox and Chromium; and multimedia programs MPlayer, VLC media player and xine. The Project also supports minimalist window management philosophies by including the cwm stacking window manager in the main distribution.
OpenBSD features a full server suite and is easily configured as a mail server, web server, ftp server, DNS server, router, firewall, or NFS file server. Software providing support for other server protocols such as SMB (Samba) are available as packages.
OpenBSD component projects
Despite the small team size and relatively low usage of OpenBSD, the project has successfully spun off widely available portable versions of numerous parts of the base system, including:
- OpenBGPD, a free implementation of the Border Gateway Protocol 4 (BGP-4)
- OpenOSPFD, a free implementation of the Open Shortest Path First (OSPF) routing protocol
- OpenNTPD, a simple alternative to ntp.org's Network Time Protocol (NTP) daemon
- OpenSMTPD, a free Simple Mail Transfer Protocol (SMTP) daemon with IPv4/IPv6, PAM, Maildir and virtual domains support
- OpenSSH, a highly regarded implementation of the Secure Shell (ssh) protocol
- OpenIKED, a free implementation of the Internet Key Exchange (IKEv2) protocol
- Common Address Redundancy Protocol (CARP), a free alternative to Cisco's patented HSRP/VRRP server redundancy protocols
- PF, an IPv4/IPv6 stateful firewall with NAT, PAT, QoS and traffic normalization support
- pfsync, a firewall states synchronization protocol for PF firewall with High Availability support using CARP
- spamd, a spam filter with greylisting capability designed to inter-operate with the PF firewall
- tmux, a free, secure and maintainable alternative to the GNU Screen terminal multiplexer
- sndio, a compact audio and MIDI framework
- Xenocara, a customized X.Org build infrastructure
- cwm, a stacking window manager
Some of the subsystems have been integrated into the core system of several other BSD projects, and all are available widely as packages for use in other Unix-like systems, and in some cases in Microsoft Windows.
Third Party components in the base system
- X.org, the X Window environment, with local patches. Installed with the x*.tgz install file sets.
- GCC versions 4.2, 3.3 or 2.95 (depending on your platform) GNU C Compiler. Installed as part of the comp54.tgz file set.
- Perl, with patches and improvements from the OpenBSD team.
- Nginx web server, with patches.
- SQLite, with patches and improvements from the OpenBSD team.
- Sendmail mail server, with libmilter.
- BIND (plus patches) DNS server. OpenBSD has implemented many improvements in chroot operation and other security-related issues.
- NSD authoritative DNS server.
- Lynx text web browser. With HTTPS and IPv6 support added, plus patches from the OpenBSD team.
- Sudo, allowing users to run individual commands as root.
- Heimdal, an implementation of the Kerberos authentication protocol with patches.
- Binutils with patches.
- gdb with patches.
- Less 444 with patches.
Development and release process
Development is continuous, and team management is open and tiered. Anyone with appropriate skills may contribute, with commit rights being awarded on merit and de Raadt acting as coordinator. Two official releases are made per year, with the version number incremented by 0.1, and these are each supported for twelve months. Snapshot releases are also available at very frequent intervals. Maintenance patches for supported releases may be applied manually or by regularly updating the system against the patch branch of the CVS repository for that release.
Alternatively a system administrator may opt to upgrade using a snapshot release and then regularly update the system against the "current" branch of the CVS repository, in order to gain pre-release access to recently added features.
The standard GENERIC OpenBSD kernel, as maintained by the project, is strongly recommended for universal use, and customized kernels are not supported by the project, in line with the philosophy that 'attempts to customize or "optimize" the kernel causes more problems than they solve.'
Packages outside the main system build are maintained by CVS through a ports tree and are the responsibility of the individual maintainers (known as porters). As well as keeping the current branch up to date, the porter of a package is expected to apply appropriate bug-fixes and maintenance fixes to branches of the package for supported releases. Ports are not subject to the same continuous rigorous auditing as the main system because the project lacks the manpower to do this.
Binary packages are built centrally from the ports tree for each architecture. This process is applied for the current version, for each supported release, and for each snapshot. Administrators are recommended to use the package mechanism rather than build the package from the ports tree, unless they need to perform their own source changes.
With every new release a song is also released.
History and popularity
In December 1994, NetBSD co-founder Theo de Raadt was asked to resign from his position as a senior developer and member of the NetBSD core team. The reason for this is not wholly clear, although there are claims that it was due to personality clashes within the NetBSD project and on its mailing lists.
In October 1995, de Raadt founded OpenBSD, a new project forked from NetBSD 1.0. The initial release, OpenBSD 1.2, was made in July 1996, followed in October of the same year by OpenBSD 2.0. Since then, the project has followed a schedule of a release every six months, each of which is maintained and supported for one year. The latest release, OpenBSD 5.4, appeared on 1 Nov 2013.
On 25 July 2007, OpenBSD developer Bob Beck announced the formation of the OpenBSD Foundation, a Canadian not-for-profit corporation formed to "act as a single point of contact for persons and organizations requiring a legal entity to deal with when they wish to support OpenBSD."
Just how widely OpenBSD is used is hard to ascertain: its developers neither publish nor collect usage statistics, and there are few other sources of information. In September 2005, the nascent BSD Certification Group performed a usage survey which revealed that 32.8% of BSD users (1420 of 4330 respondents) were using OpenBSD, placing it second of the four major BSD variants, behind FreeBSD with 77% and ahead of NetBSD with 16.3%.
Open source and open documentation
When OpenBSD was created, Theo de Raadt decided that the source should be easily available for anyone to read at any time, so, with the assistance of Chuck Cranor, he set up a public, anonymous CVS server. This was the first of its kind in the software development world: at the time, the tradition was for only a small team of developers to have access to a project's source repository. Cranor and de Raadt concluded that this practice "runs counter to the open source philosophy" and is inconvenient to contributors. De Raadt's decision allowed "users to take a more active role", and signaled the project's belief in open and public access to source code.
OpenBSD developers do not permit the inclusion of closed source binary drivers in the source tree and are reluctant to sign non-disclosure agreements. When no documentation was forthcoming before the deadline for the release of OpenBSD 3.7, support for Adaptec AAC RAID controllers was removed from the standard OpenBSD kernel because of issues concerning open documentation.
The OpenBSD policy on openness extends to hardware documentation: in the slides for a December 2006 presentation, de Raadt explained that without it "developers often make mistakes writing drivers", and pointed out that "the [oh my god, I got it to work] rush is harder to achieve, and some developers just give up". He went on to say that vendor binary drivers are unacceptable to OpenBSD, that they have "no trust of vendor binaries running in our kernel" and that there is "no way to fix [them] ... when they break".
A goal of the OpenBSD project is to "maintain the spirit of the original Berkeley Unix copyrights", which permitted a "relatively un-encumbered Unix source distribution". To this end, the Internet Systems Consortium (ISC) licence, a simplified version of the BSD licence with wording removed that is unnecessary under the Berne convention, is preferred for new code, but the MIT or BSD licences are accepted. The widely used GNU General Public License is considered overly restrictive in comparison with these.
In June 2001, triggered by concerns over Darren Reed's modification of IPFilter's licence wording, a systematic licence audit of the OpenBSD ports and source trees was undertaken. Code in more than a hundred files throughout the system was found to be unlicensed, ambiguously licensed or in use against the terms of the licence. To ensure that all licences were properly adhered to, an attempt was made to contact all the relevant copyright holders: some pieces of code were removed, many were replaced, and others, including the multicast routing tools, mrinfo and map-mbone, which were licensed by Xerox for research only, were relicensed so that OpenBSD could continue to use them; also removed during this audit was all software produced by Daniel J. Bernstein. At the time, Bernstein requested that all modified versions of his code be approved by him prior to redistribution, a requirement to which OpenBSD developers were unwilling to devote time or effort. The removal led to a clash with Bernstein who felt the removal of his software to be uncalled for. He cited the Netscape web browser as much less freely licensed and accused the OpenBSD developers of hypocrisy for permitting Netscape to remain while removing his software. The OpenBSD project's stance was that Netscape, although not open source, had licence conditions that could be more easily met. They asserted that Bernstein's demand for control of derivatives would lead to a great deal of additional work and that removal was the most appropriate way to comply with his requirements.
The OpenBSD team has developed software from scratch, or adopted suitable existing software, because of licence concerns. Of particular note is the development, after licence restrictions were imposed on IPFilter, of the pf packet filter, which first appeared in OpenBSD 3.0 and is now available in DragonFly BSD, NetBSD and FreeBSD. OpenBSD developers have also replaced GPL licensed tools (such as diff, grep and pkg-config) with BSD licensed equivalents and founded new projects including the OpenBGPD routing daemon and OpenNTPD time service daemon.
Although the operating system and its portable components are widely used in commercial products, de Raadt says that little of the funding for the project comes from the industry: "traditionally all our funding has come from user donations and users buying our CDs (our other products don't really make us much money). Obviously, that has not been a lot of money."
For a two year period in the early 2000s, the project received DARPA funding, which "paid the salaries of 5 people to work completely fulltime, bought about $30k in hardware, and paid for 3 hackathons." 
De Raadt has expressed some concern about the asymmetry of funding: "I think that contributions should have come first from the vendors, secondly from the corporate users, and thirdly from individual users. But the response has been almost entirely the opposite, with almost a 15 to 1 dollar ratio in favor of the little people. Thanks a lot, little people!" 
On 14 January 2014, Bob Beck issued a request for funding to cover electrical costs. If sustainable funding was not found, Beck suggested OpenBSD would shut down. The project soon received a USD$ 20 000 donation from Mircea Popescu, the Romanian creator of the MPEx Bitcoin stock exchange, paid in Bitcoins. The project raised USD$150 000 in response to the appeal, enabling it to pay its bills and securing its short term future.
Security and code auditing
Shortly after OpenBSD's creation, Theo de Raadt was contacted by a local security software company named Secure Networks, Inc. or SNI. They were developing a "network security auditing tool" called Ballista (later renamed to Cybercop Scanner after SNI was purchased by Network Associates), which was intended to find and attempt to exploit possible software security flaws. This coincided well with de Raadt's own interest in security, so for a time the two cooperated, a relationship that was of particular usefulness leading up to the release of OpenBSD 2.3 and helped to define security as the focal point of the project.
OpenBSD includes features designed to improve security. These include API additions, such as the strlcat and strlcpy functions; toolchain alterations, including a static bounds checker; memory protection techniques to guard against invalid accesses, such as ProPolice and the W^X (W xor X) page protection feature; and cryptography and randomization features.
To reduce the risk of a vulnerability or misconfiguration allowing privilege escalation, some programs have been written or adapted to make use of privilege separation, privilege revocation and chrooting. Privilege separation is a technique, pioneered on OpenBSD and inspired by the principle of least privilege, where a program is split into two or more parts, one of which performs privileged operations and the other—almost always the bulk of the code—runs without privilege. Privilege revocation is similar and involves a program performing any necessary operations with the privileges it starts with then dropping them. Chrooting involves restricting an application to one section of the file system, prohibiting it from accessing areas that contain private or system files. Developers have applied these features to OpenBSD versions of common applications, including tcpdump and the Apache web server.
OpenBSD developers were instrumental in the birth of—and the project continues to develop—OpenSSH, a secure replacement for Telnet. OpenSSH is based on the original SSH suite and developed further by the OpenBSD team. It first appeared in OpenBSD 2.6 and is now the most popular SSH implementation, available on many operating systems.
The project has a policy of continually auditing code for problems, work that developer Marc Espie has described as "never finished ... more a question of process than of a specific bug being hunted". He went on to list several typical steps once a bug is found, including examining the entire source tree for the same and similar issues, "try[ing] to find out whether the documentation ought to be amended", and investigating whether "it's possible to augment the compiler to warn against this specific problem".
Alleged FBI backdoor investigated
On 11 December 2010, Gregory Perry sent an email to Theo de Raadt alleging that the FBI had paid some OpenBSD ex-developers 10 years previously to insert backdoors into the OpenBSD Cryptographic Framework. Theo de Raadt made the email public on 14 December by forwarding it to the openbsd-tech mailing list and suggested an audit of the IPsec codebase. De Raadt's response was skeptical of the report and he invited all developers to independently review the relevant code. In the weeks that followed, bugs were fixed but no evidence of backdoors were found.
The OpenBSD website features a prominent reference to the security record of the default install. Until June 2002, the wording read "Five years without a remote hole in the default install!" An OpenSSH bug was then discovered that made it possible for a remote attacker to gain root in OpenBSD and in any of the many other systems running OpenSSH at the time. It was quickly fixed, as is normal with known security holes. The slogan was modified to "One remote hole in the default install, in nearly 6 years!" In 2007 a network-related remote vulnerability was found, which was also quickly fixed. The quote was subsequently altered to "Only two remote holes in the default install, in a heck of a long time!" This wording remains to this day.
This statement has been criticized because the default install contains few running services—some critics observing that the slogan should be adjusted to "no working apps in the default install"—and most users will start more services and install additional software. The project states that the default install is intentionally minimal to ensure novice users "do not need to become security experts overnight", which fits with open-source and code auditing practices argued to be important elements of a security system.
Distribution and marketing
OpenBSD is available freely in various ways: the source can be retrieved by anonymous CVS, and binary releases and development snapshots can be downloaded either by FTP, HTTP, rsync or AFS. Prepackaged CD-ROM sets can be ordered online for a small fee, complete with an assortment of stickers and a copy of the release's theme song. These, with their artwork and other bonuses, are one of the project's few sources of income, funding hardware, bandwidth and other expenses.
In common with other operating systems, OpenBSD provides a package management system for easy installation and management of programs which are not part of the base operating system. Packages are binary files which are extracted, managed and removed using the package tools. On OpenBSD, the source of packages is the ports system, a collection of Makefiles and other infrastructure required to create packages. In OpenBSD, the ports and base operating system are developed and released together for each version: this means that the ports or packages released with, for example, 4.6 are not suitable for use with 4.5 and vice versa.
OpenBSD at first used the BSD daemon mascot created by Phil Foglio, updated by John Lasseter and copyright Marshall Kirk McKusick. Subsequent releases saw variations, eventually settling on Puffy, described as a pufferfish. Since then Puffy has appeared on OpenBSD promotional material and featured in release songs and artwork. The promotional material of early OpenBSD releases did not have a cohesive theme or design but later the CD-ROMs, release songs, posters and tee-shirts for each release have been produced with a single style and theme, sometimes contributed to by Ty Semaka of the Plaid Tongued Devils. These have become a part of OpenBSD advocacy, with each release expounding a moral or political point important to the project, often through parody. Past themes have included: in OpenBSD 3.8, the Hackers of the Lost RAID, a parody of Indiana Jones linked to the new RAID tools featured as part of the release; The Wizard of OS, making its debut in OpenBSD 3.7, based on the work of Pink Floyd and a parody of The Wizard of Oz related to the project's recent wireless work; and OpenBSD 3.3's Puff the Barbarian, including an 80s rock-style song and parody of Conan the Barbarian, alluding to open documentation.
- Absolute OpenBSD, 2nd Edition by Michael W. Lucas. ISBN 978-1-59327-476-4
- The OpenBSD Command-Line Companion, 1st ed. by Jacek Artymiak. ISBN 83-916651-8-6.
- Building Firewalls with OpenBSD and PF: Second Edition by Jacek Artymiak. ISBN 83-916651-1-9.
- Mastering FreeBSD and OpenBSD Security by Yanek Korff, Paco Hope and Bruce Potter. ISBN 0-596-00626-8.
- Absolute OpenBSD, Unix for the Practical Paranoid by Michael W. Lucas. ISBN 1-886411-99-9 (online copy here)
- Secure Architectures with OpenBSD by Brandon Palmer and Jose Nazario. ISBN 0-321-19366-0.
- The OpenBSD PF Packet Filter Book: PF for NetBSD, FreeBSD, DragonFly and OpenBSD published by Reed Media Services. ISBN 0-9790342-0-5.
- Building Linux and OpenBSD Firewalls by Wes Sonnenreich and Tom Yates. ISBN 0-471-35366-3.
- The OpenBSD 4.0 Crash Course by Jem Matzan. ISBN 0-596-51015-2.
- The Book of PF A No-Nonsense Guide to the OpenBSD Firewall, 2nd edition by Peter N.M. Hansteen ISBN 978-1-59327-274-6 .
- BSD Authentication
- BSD and GPL licensing
- Comparison of BSD operating systems
- Comparison of operating systems
- Comparison of operating system kernels
- Comparison of open source operating systems
- KAME project
- OpenBSD Journal
- POSSE project
- Security-focused operating system
- "Platforms", OpenBSD, retrieved 2011-12-13
- E.g. Atmel firmware may be redistributed in object code only. atu-license OpenSBD CVS Repository
- tigon license, tusb3410 license, custom license
- "'Google Summer Of Code 2014.' - MARC". Marc.info. 2014-02-25. Retrieved 2014-03-04.
- "GSOC 2014 with the OpenBSD Foundation". Openbsdfoundation.org. Retrieved 2014-03-04.
- McIntire, Tim (2006-08-08), "Take a closer look at OpenBSD", Developerworks (IBM), retrieved 2011-12-13, "Because OpenBSD is both thin and secure, one of the most common OpenBSD implementation purposes is as a firewall."
- "RTMX O/S IEEE Real Time POSIX Operating Systems", RTMX Inc., retrieved 2011-12-13, "RTMX O/S is a product extension to OpenBSD Unix-like operating system with emphasis on embedded, dedicated applications."
- ".vantronix secure system", Compumatica secure networks GmbH, retrieved 2011-12-13, "The Next Generation Firewall is not a standalone device, it is a Router for operation in security critical environments with high requirements for availability, comprehensive support as well as reliable and trusted systems powered by OpenBSD."
- "Microsoft Acquires Softway Systems To Strengthen Future Customer Interoperability Solutions", Microsoft News Center (Microsoft), 1999-09-17
- Dohnert, Roberto J. (2004-01-21), "Review of Windows Services for UNIX 3.5", OSNews (David Adams)
- "Core Force", Core Labs, retrieved 2011-12-13, "CORE FORCE provides inbound and outbound stateful packet filtering for TCP/IP protocols using a Windows port of OpenBSD's PF firewall, granular file system and registry access control and programs' integrity validation."
- "About Xenocara", Xenocara, retrieved 2011-12-13
- Tzanidakis, Manolis (2006-04-21), Using OpenBSD on the desktop, Linux.com, retrieved 2012-03-09
- "The OpenBSD 4.9 Release", OpenBSD, retrieved 2011-12-13, "Over 6,800 ports...Gnome 2.32.1, KDE 3.5.10."
- Jacoutot, Antoine (20110420), "A Puffy in the corporate aquarium", OpenBSD Journal (Daniel Hartmeier)
- Lucas, Michael W. (2003). Absolute OpenBSD, Unix for the Practical Paranoid (1st ed.). No Starch Press. ISBN 1-886411-99-9. Retrieved 2012-06-15.
- Andrews, Jeremy (20060502), "Interview: Theo de Raadt", KernelTrap (Jeremy Andrews)
- "Release Songs". OpenBSD. Retrieved 12/04/13.
- 2005 BSD Usage Survey Report (PDF), The BSD Certification Group, 2005-10-31, retrieved 2012-09-16
- Glass, Adam (1994-12-23). "Theo De Raadt". netbsd-users mailing list. http://mail-index.netbsd.org/netbsd-users/1994/12/23/0000.html.
- de Raadt, Theo (1996-10-18). "The OpenBSD 2.0 release". openbsd-announce mailing list. http://www.monkey.org/openbsd/archive2/announce/199610/msg00001.html.
- "The OpenBSD Foundation", OpenBSD Foundation, retrieved 2011-12-13
- Beck, Bob (2007-07-25). "Announcing: The OpenBSD Foundation". openbsd-misc mailing list. http://www.nabble.com/Announcing%3A-The-OpenBSD-Foundation-p11801927.html.
- Multiple selections were permitted as a user may use multiple BSD variants side by side.
- Cranor, Chuck D., Chuck Cranor's Home Page, retrieved 2011-12-13, "I also hosted and helped create the first Anonymous CVS server on the Internet (the original anoncvs.openbsd.org, which was also known as eap.ccrc.wustl.edu)."
- de Raadt, Theo (1999-06-11), Opening the Source Repository with Anonymous CVS, USENIX, retrieved 2011-12-13
- de Raadt, Theo (2010-04-07), "Revision 1.406", OpenBSD CVS repository
- de Raadt, Theo (2006-12-05), Presentation at OpenCON, retrieved 2011-12-13
- "Copyright Policy", OpenBSD, retrieved 2011-12-13
- Matzan, Jem (2005-06-15), "BSD cognoscenti on Linux", NewsForge (Linux.com), archived from the original on 2008-02-07
- Gasperson, Tina (2001-06-06), "OpenBSD and ipfilter still fighting over license disagreement", Linux.com, archived from the original on 2008-06-26
- "MRINFO(8)", OpenBSD Manual Pages, retrieved 2011-12-13
- "MAP-MBONE(8)", OpenBSD Manual Pages, retrieved 2011-12-13
- de Raadt, Theo (2001-08-24). "Re: Why were all DJB's ports removed? No more qmail?". openbsd-misc mailing list. http://archives.neohapsis.com/archives/openbsd/2001-08/2544.html.
- Bernstein, DJ (2001-08-27). "Re: Why were all DJB's ports removed? No more qmail?". openbsd-misc mailing list. http://archives.neohapsis.com/archives/openbsd/2001-08/2812.html.
- Espie, Marc (2001-08-28). "Re: Why were all DJB's ports removed? No more qmail?". openbsd-misc mailing list. http://archives.neohapsis.com/archives/openbsd/2001-08/2864.html.
- Hartmeier, Daniel, "Design and Performance of the OpenBSD Stateful Packet Filter (pf)", Systor AG, retrieved 2011-12-13
- OpenBSD CVS logs showing import of diff, grep and pkg-config. OpenBGPD and OpenNTPD man pages from OpenBSD.
- Beck, Bob (14 January 2014), "Request for Funding our Electricity", openbsd-misc (openbsd-misc)
- Bright, Peter (20 January 2014), "OpenBSD rescued from unpowered oblivion by $20K bitcoin donation", Ars Technica, retrieved 20 January 2014
- Varghese, Sam (2004-10-08), "Staying on the cutting edge", The Age, retrieved 2011-12-13
- Laird, Cameron; Staplin, George Peter (2003-07-17), "The Essence of OpenBSD", ONLamp, retrieved 2011-12-13
- de Raadt, Theo (2005-12-19). "2.3 release announcement". openbsd-misc mailing list. http://www.monkey.org/openbsd/archive/misc/9805/msg00308.html. "Without [SNI's] support at the right time, this release probably would not have happened"
- Wayner, Peter (2000-07-13), "18.3 Flames, Fights, and the Birth of OpenBSD", Free For All: How Linux and the Free Software Movement Undercut the High Tech Titans (1st ed.), HarperBusiness, ISBN 978-0-06-662050-3, retrieved 2011-12-13
- Todd C., Miller; de Raadt, Theo (1999-06-06), "strlcpy and strlcat – consistent, safe, string copy and concatenation", Proceedings of the 1999 USENIX Annual Technical Conference (USENIX): 175–178, retrieved 2011-12-13
- de Raadt, Theo; Hallqvist, Niklas; Grabowski, Artur; Keromytis, Angelos D. & Provos, Niels, Cryptography in OpenBSD: An overview (PDF), retrieved 2011-12-13
- Provos, Niels (2003-08-09), Privilege Separated OpenSSH, retrieved 2011-12-13
- OpenBSD CVS logs showing addition of privilege separation to tcpdump and httpd man page describing the chroot mechanism.
- "Project History and Credits", OpenSSH, retrieved 2011-12-13
- "SSH usage profiling", OpenSSH, retrieved 2011-12-13
- Biancuzzi, Federico (2004-03-18), "An Interview with OpenBSD's Marc Espie", ONLamp, retrieved 2011-12-13
- de Raadt, Theo (2010-12-14). "Allegations regarding OpenBSD IPSEC". openbsd-tech mailing list. http://marc.info/?l=openbsd-tech&m=129236621626462&w=2.
- Holwerda, Thom (2010-12-14), "FBI Added Secret Backdoors to OpenBSD IPSEC", OSNews, retrieved 2011-12-13
- Ryan, Paul (2010-12-23), "OpenBSD code audit uncovers bugs, but no evidence of backdoor", Ars Technica (Condé Nast Digital), retrieved 2011-01-09
- "OpenSSH Remote Challenge Vulnerability", Internet Security Systems Security Advisory (Internet Security Systems), 2002-06-26, retrieved 2011-12-13
- OpenSSH "Challenge-Response" authentication buffer overflow, Internet Security Systems, retrieved 2011-12-13
- "OpenBSD's IPv6 mbufs remote kernel buffer overflow", Core Security Technologies – CoreLabs Advisory (Core Security Technologies), 2007-03-13, retrieved 2011-12-13
- Brindle, Joshua (2008-03-30), "Secure doesn't mean anything", Security Blog, retrieved 2011-12-13
- "Security", OpenBSD, retrieved 2011-12-13, "Secure by Default"
- Wheeler, David A. (2003-03-03), "2.4. Is Open Source Good for Security?", Secure Programming for Linux and Unix HOWTO, retrieved 2011-12-13
- "Anonymous CVS", OpenBSD, retrieved 2011-12-13
- "Getting the OpenBSD distribution", OpenBSD, retrieved 2011-12-13
- "Ordering OpenBSD products", OpenBSD, retrieved 2011-12-13, "The proceeds from sale of these products is the primary funding of the OpenBSD project."
- "15 – The OpenBSD packages and ports system", OpenBSD FAQ, retrieved 2011-12-13
- "The OpenBSD 2.7 Release", OpenBSD FAQ, retrieved 2011-12-13
- Although in fact pufferfish do not possess spikes and images of Puffy are closer to a similar species, the porcupinefish.
- "Release Songs", OpenBSD FAQ, retrieved 2011-12-13
- Matzan, Jem (2006-12-01), "OpenBSD 4.0 review", Software In Review, retrieved 2011-12-13, "Each OpenBSD release has a graphical theme and a song that goes with it. The theme reflects a major concern that the OpenBSD programmers are addressing or bringing to light."
|Wikimedia Commons has media related to OpenBSD.|
|The Wikibook Guide to Unix has a page on the topic of: OpenBSD|
- Official website
- OpenBSD Journal
- Unofficial OpenBSD ports tracker
- OpenBSD ports web-site based on the ports-readmes port
- OpenBSD source tree search
- Video - Exploit Mitigation Techniques: an Update After 10 Years
- Video - An OpenBSD talk by Michael Lucas
Bigger mailing lists