Thursday, December 1, 2011

Turn an Ubuntu Linux box a WAP (Wifi Access Point)

I recently helped a friend of mine James Miller setup an Ubuntu Linux box as a wireless access point. I had never done this before, but I found it to be pretty straightforward. Here is the very abbreviated version of the things that need to be done assuming that your wireless driver is supported by the nl80211 interface in the Linux kernel:
  1. Install hostapd
  2. Add a configuration file for hostapd
  3. Modify /etc/network/interfaces to bring up the hostapd config
James and I used an ath5k card to pull this off.

Installing hostapd:
At a root prompt, type: "apt-get install hostapd". Doing so will install all the machinery needed to bring up a WAP, but it will have no configuration.

Creating the config file for hostapd:
In /etc/hostapd/{essid}.conf, use the following contents for an unencrypted WAP:
interface=wlan0
driver=nl80211
ssid={essid} channel=1 # may want to replace with another channel
Of course, you should replace "{essid}" with your actual essid.

Modifying the /etc/network/interfaces file:
You'll need something similar to the following:
auto wlan0
iface wlan0 inet static
  address 192.168.1.1
  netmask 255.255.255.0
  hostapd /etc/hostapd/{essid}.conf

Conclusion:
That should get you a simple unencrypted WAP setup. If you want encryption, you can use hostapd to implement simple WPA2 personal or more interesting WPA2 enterprise style security (among other options). I would strongly recommend at least WPA2 personal (a.k.a. pre-shared key or PSK) encryption unless you have reasons to make it less secure.

Note also that this setup will leave you with your wireless network and other networks on separate layer 2 domains, which means that packets will need to be routed between them. You'll probably also want to get dhcp running so that you don't have to manually configure clients on the wireless network. I am going to leave getting these additional bits working as a exercise for the reader. As a hint, checkout the isc-dhcp-server package and the net.ipv4.forward (for IPv4). You might also want to check out the shorewall package as a nice firewall. :)

Good luck!

Tuesday, March 8, 2011

Samsung SCX-4623FW Supported by Fully Open Drivers

I was searching for a new smaller printer/scanner recently. I don't print out much, so I wanted a black-and-white laser printer. I also wanted a scanner so that I can get rid of my old printer/scanner since it's so big.

Finding a new printer that is supported by open drivers is really difficult, and configuring SANE backends is not my definition sanity. However, I looked on the SANE database and found that Samsung's SCX-4623 is supported. I couldn't find any support in the Linux Foundation's OpenPrinting database for the SCX-4623. So...I took a leap of faith and bought the printer for about $150.

To be clear, many vendors, including Samsung, offer binary drivers for their printers. However, I really wanted to use the open drivers so that I could contribute to the systems involved instead of being locked out.

The first step was to get the scanner working. At first, I tried to get the xerox_mfp backend working. I just added the following line into the /etc/sane.d/xerox_mfp.conf config file: "usb 0x04e8 0x3440". This did not work as the SANE backend did not seeing the scanner. After a significant troubleshooting effort, I found that the SANE backend had a bug that prevented USB scanners from being used with the xerox_mfp backend. I have reported the bug and presented a patch to the SANE community. See it here. After applying this patch, I was able to successfully scan at 1200dpi in color. That's full capacity for this machine. Success is mine!

This machine also supports ethernet and wireless. Both worked for scanning after configuring the xerox_mfp backend with the machine's network address and port. The same bug didn't affect the networked support for the xerox_mfp backend, so everything just worked.

Great, so the scanner works, now what?

So, now I had to get the printer working. The printer supports the ipp protocol. I was hoping that I could just use some generic CUPS filter to work with it. The printer claimed support for PCL5e in the web interface for the printer, so I just used the generic PCL5e driver and the ipp address of the printer. Everything just worked!

My next step is to write a PPD to properly describe this printer fully. I am also trying to figure out out to get this info integrated into the OpenPrinting database.

Having said all this, my printer/scanner is running totally on free and open source software, and I can recommend this to others looking for a printer that's fully supported by free and open source software.

I would also like to reach out to Samsung and encourage them to let their users know this information so that their users don't have to go through the hassle of installing binary only drivers that only work on x86_64 or i386 architectures.

This information probably also applies to the SCX-4623F, which doesn't have wireless support.

Sunday, September 26, 2010

Coreboot Config Cleanups

I have submitted a few patches to the coreboot team that cleanup some configuration items. Mostly, they remove duplicated and misplaced configuration items.

For instance, for some of the boards I looked at, they have a hard reset because their southbridge provides that functionality. However, the hard reset was configured in the mainboard config instead. I moved the configs to the southbridge and removed the config from the mainboard. There are a lot of config options similar to this one. I am going to try to get some more patched out tomorrow.

Tuesday, September 14, 2010

BIOS hacking

Previously, I had soldered an soic8 socket onto my motherboard in place of the soic8 surface mount chip so that I could replace the soic8 chip easily. Here's a picture:

BTW, does anyone know where I can buy more of the soic8 sockets pictured above? I was given one by a friend and I don't know where to get them.

I have finally soldered up a more permanent version of my soic8 serial flash programmer. The basic circuit design was by Uwe Hermann. I added a 3M test clip to make it easier to flash my chips. Here's a picture:

Update: The soic socket adapter is located at http://www.dediprog.com/SPI-flash-accessories/SPI-Flash-Socket-8pin. Whoa, that's expensive shipping.

Friday, September 3, 2010

Inteltool from Coreboot

I am doing some work trying to add Core i7 support to the inteltool utility from the Coreboot project.

Core i7 is very different from the previous intel chipsets, and figuring out how to represent some of the stuff in inteltool's view of the world is a challenge. The main problem I am facing right now is that inteltool thinks the northbridge chip contains the memory controller. However, in i7, that functionality has been moved into a PCI device on the processor itself. I am still trying to figure out a solution.

Saturday, July 18, 2009

Liberty Mutual web site disappoints on SSL security

I tried to login to the Liberty Mutual web site the other day and found some annoying things.
  1. The main Liberty Mutual web page at http://www.libertymutual.com/ includes a login form. Given that the page is not secured with SSL, I can't trust the login form. Given that https://www.libertymutual.com/ exists, the unsecured site should just redirect there.

    I looked at Wells Fargo's web site, and I am actually pretty happy with the way Wells Fargo handles this issue. Both http://wellsfargo.com/ and http://www.wellsfargo.com/ redirect to https://www.wellsfargo.com/.

    I am amazed at the frequecy with which this error is made. A login form should never appear on an unsecured page.
  2. Liberty Mutual has had a misconfigured SSL certificate on the site that handles their logins (https://pmeservice.libertymutual.com/LMAuth/eservicelog.fcc). See the screenshot to the left for the screenshot from Firefox. Basically, I think they don't have the whole certificate chain configured properly, so my browser can't check the authenticity of the certificate. I figured this out by looking at the certificate chain that my browser was getting from the site. See below.

    If you call their support line, they have the worst possible workaround. I was told to simply create a browser exception for the certificate. I might have been willing to do that if they would have least been able to verify the SHA1 fingerprint of the key, but the support folks didn't know what that was.

    Frankly, I think it's quite irresponsible to be running their website like this as I think it greatly increases the chances of an MITM attack.
  3. Finally, I also saw that the Liberty Mutual website is Cybertrust certified, so I sent an email the the support for that about the situation. They emailed back and claimed that I didn't understand how SSL certs worked. I replied with a more detailed description. Hopefully, they will understand what my problem is this time around.
All of these issues are still problem today. For (2), how does an SSL certificate error like that stay unfixed for days? That seems like a level of incompetence to me. Is there a better explanation?

UPDATE Sun. July 19, 2009: I just looked up their site report on Netcraft. Check it out. Is says the following for certificate check: "unable to get local issuer certificate". Someone should be answering some hard questions for letting this issue go on for the 4 or 5 days that it has been going on so far.

UPDATE: Mon. July 20, 2009: I just looked at the site again, and Liberty Mutual has finally fixed it. The fact that it took so long to fix the issue makes me want to corner the CIO and ask him what took so long. Since the issue is fixed, the Netcraft report also is able to verify the certificate now.

Monday, July 7, 2008

Married

As of last Friday, I am married to the love of my life Rachel. I am so glad I could trick her into doing this. :-)