6 ms·
It's a legit question, but if you have to ask, then most likely OpenBSD is not for you. I don't say that out of some elitist or gatekeeping motive, rather I th
by technofiend 3y ago
It's a legit question, but if you have to ask, then most likely OpenBSD is not for you. I don't say that out of some elitist or gatekeeping motive, rather I think most people who use it have a specific need for it, or feel strongly about the principles behind the OS, which are security first and secure-by-default.
Here's a breakdown of some technical differences between the two, but really if you want to explore alternatives to Linux or even Linux alternatives I highly recommend you do so, even OpenBSD, but I respectfully suggest you have a use case in mind first.
https://www.geeksforgeeks.org/difference-between-linux-and-openbsd/ https://www.geeksforgeeks.org/difference-between-linux-and-o...
The security first/secure-by-default mindset in OpenBSD means the core distribution is very locked down. By that I mean there's very little in the base OS in terms of services. OpenBSD had a robust "ports" selection for things you may need to add.
My use case for OpenBSD was as a firewall, but it was eventually retired because it just couldn't keep up with my network speeds. It still is a secure unix server for things like radius authentication of wireless clients.
- rubymamis 3y agoCompared to a Linux distro, would an end user have much better security out-of-the box, or would one need to be tech-savvy enough for that?
- opencl 3y agoOpenBSD out of the box is an extremely minimal setup compared to the default install of most Linux distros. A lot of the security of the default install comes from minimizing the attack surface by having very few services running. So you do not need to be tech-savvy to make it secure, but you might need to be tech-savvy to turn it into a usable system for your use case.
- seanw444 3y agoTo add: it's not just the fact that it's barely running anything that makes it secure, but the things that you do run have effort put into making their codebase secure as well. Such as the various daemons, like httpd.
- miah_ 3y agoAlso, the code for OpenBSD has been audited for "common" security issues, and hardened against various attack types. https://www.openbsd.org/security.html https://www.openbsd.org/security.html
- somat 3y agoOpenBSD out of the box is not minimal. As a base install it is more feature full than most linux base installs. It is small yes, but with a lot of high quality network focused services. I could easily run a company backend and network on only what is found in the base install. If I had a good solid group of people I could probably run the frontend on it. (the main thing it lacks is a web browser). mail, web, routing, tunnels, bgp, dns, hell there is even an ldap server in there for some reason. but no ldap client, which kind of sucks.
- kuon 3y agoI stil use OpenBSD as firewall as I love PF. But I have the same problem as it cannot easily firewall 10G link. I am curious, what did you migrate to?
- technofiend 3y agoI keep switching things around. Virtualization comes with its own limits but is a fast way to prototype things like 'how hard is it to get IPV6 PDUs working in this new os?' Pfsense is ok, but CE went a year without an update while they worked on other branches. Most recently their switch to kea dhcp broke some minor things like mapping static DHCP addresses to DNS entries. I believe that's fixed now, but need to confirm you can also still specify a DHCP option which some network devices need. Opnsense is also decent and has the advantage of a regular update cadence, but I believe the UI is less newbie friendly. Fedora has the advantage of a UI to let you quickly review firewall rules, although the cli is perfectly workable once you get the syntax down. Honestly I like OpenBSD's pf too but it couldn't keep up with a one gigabit network connection on your typical AliExpress firewall appliance, and I couldn't get it there virtually on an HP 360 Gen 8 or Gen 9 with decent Xeon CPUs and network cards. Probably a limitation of the network drivers for the network cards emulated by ESXi. I resisted being nerd sniped by that because my wife needs reliable Internet so there was no time to putter. What are you using that lets OpenBSD achieve better than gigabit speeds? tl;dr: For now I'm using PFSense because I have a friend I supply with tech support and he uses whatever I use and it's safe for him to play around in PFSense on his own.
- kuon 3y agoI have a ryzen with a Intel x520 nic and it handle gigabit easily. I plan to try 10gbit but my switches are not there yet, I am upgrading now.
- dbolgheroni 3y agoJust a minor note that you don't need a 3rd-party http daemon since there is one in base. https://man.openbsd.org/httpd https://man.openbsd.org/httpd
- technofiend 3y agoThank you, I stand corrected: it's been a while and my faulty memory had httpd outside of core. I edited my upline comment to remove the erroneous example because I don't want to add noise.
- Apocryphon 3y agoWhat's the most casual user-friendly distro of *BSD out there? GhostBSD?
- zilti 3y agoThey're derivatives with their own kernel each, so in that regard the question does not make much sense. Due to its large amount of binary packages though, I'd say FreeBSD it is out of the big three.
- Apocryphon 3y agoJust trying to identify what's the Mint/Ubuntu/Zorin/elementary OS equivalent of BSD in terms of ease of use.
- taylortbb 3y agoThe point is that they're not really comparable. Mint/Ubuntu/etc all ship the same Linux kernel, that's why they're called distros. They're different distributions (distros) of the same software (Linux kernel, etc). The different BSDs aren't distros, they are different kernels that are developed in parallel. Obviously there's shared history there, and some shared userspace, but FreeBSD and OpenBSD aren't just two different BSD distros of largely the same software.
- zilti 3y agoProbably still FreeBSD, even though I'd claim NetBSD's documentation is a tad better. (And Ubuntu really does not stand out as beginner-friendly compared to e.g. openSUSE)
- spookie 3y agoopenSUSE is a gem. I can't even fathom how many times I've made a mess from my impulses to tidy up my system and it just manages to "fix itself". There are also a lot of neat things, like being able to use multiple versions of GCC side by side. Not every distro behaves well on that regard.
- binkHN 3y ago> My use case for OpenBSD was as a firewall, but it was eventually retired because it just couldn't keep up with my network speeds. Are you doing over 10Gbps? A lot has been done in this space.
- technofiend 3y agoBased on someone else's comment I plan to revisit OpenBSD, because previously I wasn't able to get gigabit speeds out of a low-end appliance, even though FreeBSD and Fedora both could.
- binkHN 3y agoThings have definitely improved over time, but some of the best improvements are also related to utilizing advanced functionality from hardware that supports it.
- htamas 3y agoI respectfully disagree. I have very little Linux/Unix/xBSD maintenance knowledge, but I started running my own server for my personal email and website. Although I used a script as a crutch to set things up at the beginning (thanks to sive.rs/ti), when I started digging in how things work - and when I eventually run into some issues like expired certs - I managed to understand things much faster than when I was trying to run a server before with Ubuntu. For example, Googling things are easier since the tools don't change much over the years, so an answer from 10-15 years ago still works. Besides that, I could find most of my answers in the very well written man pages. There's also just fewer things happening so there's not much clutter to distract me finding the answers I need. I'm still a beginner of course, but I feel like OpenBSD is good for any application where you need to run something and then "forget about it" - be it a server or maybe even a "kiosk"/informational screen.