Check your WPA2 Enterprise setup
Do you have to enter user name and password to establish a link with
your wireless network? If so chances are good that WPA2 Enterprise
with EAP-TTLS or PEAP are used. Sounds familiar? Better check your
setup then. An attacker might easily impersonate your access point
and steal your password if the client you are using isn’t configured
properly.
You are likely vulnerable if you’ve disabled certificate checks
or you’ve checked some button to use a public CA but didn’t specify
any “Subject” or “Common Name” that has to match. NetworkManager for
example doesn’t even allow to enter the latter.
Read more in the paper I’ve written.
Only a few days for the FLISOL in Venezuela
Venezuelan Linux community is finishing all the preparations for the April 24, the day that all Latin America celebrate the FLISOL, Latin American Festival of Free Software Installation.
Through the sponsorship of Novell, the collaboration of ambassadors from other distributions, and GoSVe, the user group from Venezuela openSUSE, our distro will be present in all the sites of the great event of free software in the region, giving away DVD’s, LiveCD’s, stickers, t-shirts, and more.
In the city of Merida, we will be giving talks and demonstrations of our distribution and giving away all the material of that will be common in all the sites and stuffed animals for those that choose to “free” their computers and install openSUSE Linux.
Next to come: A lot of pictures 
zypper-1.4.2: rewritten package selection code
I'll submit zypper 1.4.2 including this change to Factory soon. It seems to work fine for the most part, but if you spot something that used to work for you in 1.4.1, please let us know via bugzilla. Don't forget to attach both zypper.log and solver test case.
The new version already enables use of unified package arguments (in install, update, and remove commands) in the form of:
[+/-][repo:][type:]name[.arch][OPevr[.arch]]
± (or ~|!) ; install/remove modifier
repo = ; repo alias, number, or name
type = patch|pattern|product ; if not specified 'package' isimplied
name ; can even be a glob
OP = -|=|>=|<=|>|< ; version operator
evr = [epoch:]version[-release] ; edition (version)
E.g. $ zypper in packman:xine-ui-0.99.5cvs20091115-0.pm.1.4 (don't forget to quote the args, if they contain ?/*/</> or spaces).
More about all this (and about a few more features added in the last months) later ...
There is still some work to do to fully support this (especially don't try foo.arch :O), but the main focus now is to make sure that all that used to work before works also now. For future plans see roadmap and comments in the SolverRequester_test code. Don't hesitate to send feedback to or discuss this stuff on zypp-devel@opensuse.org or comment this blog post.
oSC09 videos
Well it’s been almost seven months since our inaugural conference, and there were a load of videos taken. The problem was that our usual VT gurus have been unavailable to do any of the editing etc. So the raw video has languished on the servers waiting for some kind soul to help edit them.
After multiple calls for help and nudges from the marketing team, I decided to see if I could slot it in anywhere (yay me, I’m such a hero :-P) Thankfully I had some brilliant help from SankarP who refreshed my memory on how to edit video, thanks chief!
Currently only Day 1 of the conference is available, you can view online (flash) or download (ogg) the talks from the openSUSE TV channel on BlipTV. I am working on getting a channel on YouTube to enable a wider reach, as some people have bandwidth issues with Blip. You can also subscribe to the feeds in multiple formats – rss, miro, itunes.
If anyone has any openSUSE related video that they would like put on the channel, then please let me know 
Community Discussion - Part 5
Conference in FLISOL Nicaragua 2010
The folks of the openSUSE Community in Nicaragua, are preparing a great event in the city of Granada, Nicaragua, in Central America.
Now we have a schedule for that special day:
| Sede | Hora | Tema | Ponente | ||
|---|---|---|---|---|---|
| Granada | 09:00 am – 09:40 am | Introduction to the world of GNU / linux with gnome, basic Aplicacions | Denis Torres | ||
| Granada | 09:50 am – 10:30 am | Introduction to the world of GNU / linux with KDE, basic Aplicacionss | Adolfo Fitoria | ||
| Granada | 10:40 am – 11:20 am | Openoffice.org | Carlos Leal | ||
| Granada | 11:30 am – 12:10 pm | Multimedia Aplication | Jose Angel Bonilla | ||
| Granada | 01:00 pm – 01:40 am | Introduction to the world of GNU / linux with gnome, basic Aplicacions | Denis Torres | ||
| Granada | 01:50 am – 02:30 am | Introduction to the world of GNU / linux with KDE, basic Aplicacions | Adolfo Fitoria | ||
| Granada | 02:40 pm – 03:20 pm |
|
Carlos Leal | ||
| Granada | 03:30 pm – 04:00 pm | Multimedia Aplication | Jose Angel Bonilla |
European Legal Network (ELN) Workshop Amsterdam Day-2
The topics of discussion in the final day were compliance, risk, patents and industry development. Different organizations made presentations in the morning regarding licensing compliance and how it pertains to the internal part of the organization, as well as, through to distribution. Intra-organization compliance systems were discussed in short and the various mediums that could be used in order to insure that the vendor(s) is complaint. Most all were in agreement that it was vital for an organization to integrate a compliance policy into the supply chain. Different measures on how this compliance policy could be constructed were discussed also.
The second topic discussed was Risk and how to evaluate and contain it. A balanced discussion on risk from both the legal and business sides of things gave a realistic case view on what open source companies are facing in the current and expanding market. Members of the ELN have also created and are developing a Risk Grid to address procurement of F/OSS and it's function within the supply chain. This grid aims to assist professionals in the field to regulate their actions with their suppliers and buyers by allocating risk to the appropriate actor within the supply chain.
A patent panel also discussed briefly about the pro's and con's of patents within the organization and argued how these patents can hinder, as well as, support innovation within an organization. The affects of patents on licensing and the various complications that arise were also discussed, but agreed that another workshop will be set aside to discuss patents in more detail.
Finally, Future developments were discussed and their impacts on the F/OSS industry. Technological innovations and shifts were discussed and weighed against the developments of the F/OSS movement in the past. We are seeing quite a shift from software as a product to more of a service driven industry with such developments as the cloud and embedded MID's. Awareness must be made now that assists professionals in evaluating legal risk in accordance to licensing and procurement, through educating professionals on the importance of compliance and how to properly implement a compliance policy within their respective organizations. Moreover, it is generally agreed that there must be more interaction with developers/engineers and management/legal counsel to work together and build a "best case" practice that incorporates the developer/engineers issues and needs together with the organizations compliance. The most sound method of accomplishing this is through working together to reach our common goal with special emphasis on proper education and documentation.
I would like to thank the Free Software Foundation Europe and everyone who attended the ELN workshop and especially thank them for allowing me to participate in this closed discussion. It definitely opened my eyes to topics in which I have only scratched the surface on. The complexities of the topics discussed were just another confirmation that we need to work even harder together to meet the ever growing issues faced by all levels of the F/OSS movement. I look forward to working together with you at the ELN and sharing the knowledge and contributions from the unique position I hold between industry and community.
File Transfers in KDE 4
Did you know every app built with KDE 4 can save files as easily to a FTP server or a remote computer using SSH as easily as it accesses your local hard disk? You should! This is a feature that I take for granted since it was introduced in the days of KDE 2.0, but it's easy to forget that the majority of KDE users only started using it since then.
A few of our community people got together and wrote this thorough overview of network transparent file management in KDE at the weekend. Cookies to them for writing it and even if you think you are an old KDE hand, give it a read - I didn't know about the handy protocol selector in Dolphin, and that let me discover the settings:/ protocol - now I can access my Settings directly in Dolphin.
libgphoto2 2.4.9
(And a dinner invitation to friends, and some biking through the south part of Nuernberg.)
News of 2.4.9 can be found here if you are curious.
First time I used a (more or less ad-hoc) testplan for the ptp2 driver.
I went through the currently 3 major types of remote controllable cameras and tested
generic common scenarios of remote control.
And I actually found I had to fix some EOS stuff before release during testing.
Testplan ptp2 driver
Canon Powershot series (currently: Powershot SX100IS)
--capture-image-and-download
--capture-image-and-download -F 3 -I 5
- via SDRAM (capturetarget=0): PASS
- via Card (capturetarget=1): PASS
- Card configured, but not inserted (capturetarget=1) PASS
--capture-preview
commandline tool PASS
gtkam PASS
mixed with --capture-image-and-download PASS
--list-config PASS
Canon EOS series (currently: Canon EOS 1000D)
--capture-image-and-download
- via SDRAM (capturetarget=0)
- JPEG PASS
- JPEG + RAW PASS
- via Card (SD) (capturetarget=1)
- JPEG xxxx
- JPEG + RAW xxxx
- no SD card inserted
- JPEG FAIL/IGNORE (hangs without error)
- JPEG + RAW FAIL/IGNORE (hangs without error)
--capture-image-and-download -F 3 -I 5
- via SDRAM (capturetarget=0)
- JPEG PASS
- JPEG + RAW PASS
- via Card (capturetarget=1)
- JPEG PASS
- JPEG + RAW PASS
- no SD card insert
- JPEG FAIL/IGNORE (hangs without error)
- JPEG + RAW FAIL/IGNORE (hangs without error)
--capture-preview
commandline tool PASS
gtkam PASS
mixed with --capture-image-and-download PASS
--wait-event-and-download
- JPEG PASS
- JPEG + RAW PASS
--list-config PASS
--get-config somevalue PASS
--set-config somevalue=value PASS
Nikon DSLR series (currently: Nikon D90)
--capture-image-and-download
- via SDRAM (capturetarget=0)
- JPEG PASS
- JPEG + RAW PASS
- via Card (SD) (capturetarget=1)
- JPEG PASS
- JPEG + RAW PASS
- no SD card inserted
- JPEG PASS reports error
- JPEG + RAW PASS reports error
--capture-image-and-download -F 3 -I 5
- via SDRAM (capturetarget=0)
- JPEG PASS
- JPEG + RAW PASS
- via Card (capturetarget=1)
- JPEG PASS
- JPEG + RAW PASS
- no SD card insert
- JPEG PASS reports error
- JPEG + RAW PASS reports error
--capture-preview
commandline tool PASS
gtkam PASS
mixed with --capture-image-and-download
- SDRAM mode PASS
- Card mode FAIL/IGNORE (returns PTP Device Busy)
--wait-event-and-download
- JPEG PASS
- JPEG + RAW FAIL (deleting NEF also deletes JPG I think)
--list-config PASS
--get-config somevalue PASS
--set-config somevalue=value PASS
AVCHD to MP4/H.264/AAC conversion
For posterity:
I have a Canon HF200 HD video camera, which records to AVCHD format. AVCHD is H.264 encoded video and AC-3 encoded audio in a MPEG-2 Transport Stream (m2ts, mts) container. This format is not supported by Aperture 3, which I use to store my video.
With Blizzard’s help, I figured out an ffmpeg command-line to convert to H.264 encoded video and AAC encoded audio in an MPEG-4 (mp4) container. This is supported by Aperture 3 and other Quicktime apps.
$ ffmpeg -sameq -ab 256k -i input-file.m2ts -s hd1080 output-file.mp4 -acodec aac
Command-line order is important, which is infuriating. If you move
the -s or -ab arguments, they may not work. Add -deinterlace if
the source videos are interlaced, which mine were originally until I
turned it off. The only downside to this is that it generates huge
output files, on the order of 4-5x greater than the input file.
Update, 28 April 2010: Alexander Wauck emailed me to say that re-encoding the video isn’t necessary, and that the existing H.264 video could be moved from the m2ts container to the mp4 container with a command-line like this:
$ ffmpeg -i input-file.m2ts -ab 256k -vcodec copy -acodec aac output-file.mp4
And he’s right… as long as you don’t need to deinterlace the video.
With the whatever-random-ffmpeg-trunk checkout I have, adding
-deinterlace to the command-line segfaults. I actually had tried
-vcodec copy early in my experiments but abandoned it after I found
that it didn’t deinterlace. I had forgotten to try it again after I
moved past my older interlaced videos. Thanks Alex!









