Skip to content
Damien Dye

Damien Dye

Infrastructure & homelab notes — Proxmox, Ceph, NetBox, Ansible, Certificates.

Recent Posts

A licence key moving from a PC's firmware into a single virtual machine

Moving an OEM Licence Into a Proxmox VM, and What Moves With It

An OEM licence for the Fisher-Price OS (Windows) lives in the PC’s firmware as an ACPI table called MSDM, and QEMU will pass any such table to a guest without checking it. This covers what the table holds, a validator that refuses malformed tables before QEMU silently repairs their headers, storing them in the private half of the Proxmox cluster filesystem, Microsoft’s terms on moving an OEM licence, the one case they plainly allow, taking the table straight from the host when the licensed machine is the hypervisor, and why MAK, KMS, Active Directory and AVMA activation never touch the table.

4th October 2026 Â· 11 min Â· 2595 words Â· Damien Dye
A virtual machine's boot screen with the hypervisor's logo replaced by a product's own

Branding a Proxmox VM, and Keeping It Branded Through the Next Upgrade

A stock Proxmox VM shows Proxmox’s logo at boot, says Proxmox in its firmware vendor string and calls itself QEMU in every SMBIOS table. This replaces all of it with your product’s name: SMBIOS types 0, 1, 2, 3 and 11 with the serial number and SKU filled from the VM’s own name and size, the SeaBIOS splash and its colour trap, a branded OVMF built from Proxmox’s own tree or an option ROM driver that replaces the logo and the BGRT under Secure Boot without touching the firmware, and the web interface logo. Every change is placed so an upgrade cannot quietly undo it, and the one an upgrade can leave dangerously stale, the firmware, gets a hook that says so.

4th October 2026 Â· 24 min Â· 5661 words Â· Damien Dye

NetBox: What It Holds, And How To Make It Hold Yours

A hands-on walk through NetBox 4.7.2 with an estate loaded into it rather than an empty demo. What each screen holds and what you do with it: rack elevations, cable traces, the IPAM tree, dual-stack interfaces, and the cabinet that turns out to be 90.7 per cent full of power while only 28.6 per cent full of kit. How to stand one up as a container stack and on a host from the packages, both run end to end. The order you have to fill it in, derived from which foreign keys are actually mandatory. How one install is carved into customers so another customer’s device returns 404 and an ungranted object type returns 403. Config contexts and the inheritance that makes them worth more than custom fields. Adding your own values to NetBox’s own status menus. Three ways to add the object your business runs on, including a datastore modelled with no code. How to write validation rules and validator classes so the database refuses what your house standard forbids. And the story of the 2021 fork that produced Nautobot, what it was for, and what has since converged. Plus driving the whole thing from the netbox.netbox Ansible collection, where the inventory is a query rather than a file and one module argument quietly allocates a new address every time it runs.

30th September 2026 Â· 53 min Â· 11569 words Â· Damien Dye
A chain of trust running from the signed root through a signed TLD and stopping at an unsigned second-level domain, with the counted figures beside each step

DNSSEC: Protecting Your Traffic From Forgery

The hard part of DNSSEC was finished years ago. Counted from the live root zone on 27 September 2026, 1,351 of 1,438 top level domains carry a DS record and every one of the 1,038 gTLDs is signed. Then it stops dead. A census of every gov.uk domain in the official register finds 39 signed out of 2,390 that still resolve, nine of them parish councils, while HMRC, the NHS, GCHQ and the National Cyber Security Centre are not among them. One certificate authority in nine has signed. So has one Linux distribution in three. windowsupdate.com has no DS at all. This is what a forged answer actually costs, what signing does about it, why the usual excuses do not survive contact with the numbers, and whether forty-two years after Mockapetris the real problem is that almost nobody understands what DNS actually promises.

27th September 2026 Â· 48 min Â· 10979 words Â· Damien Dye
A name lookup passing through systemd-resolved's stub listener into a cache, a validator and an encrypted transport, with the validator and the encryption switched off

Resolved: The Resolver You Are Already Running

systemd-resolved is running on most Linux desktops right now, caching every lookup and validating none of them. This walks the resolution path from nss-resolve to the two stub listeners, measures what the cache is worth on a real machine, turns DNSSEC on and shows the three verdicts it can return, and explains why validation is off by default when upstream ships it on. Then a census of how little of the web is actually signed, DNS over TLS and its strict-versus-opportunistic trap, and the DNS over HTTPS support that has been requested since 2018 and still does not exist. Ends with what Fedora, Ubuntu, Debian and the RHEL family each ship, how to wire it into each one, and why the features your distro disabled are defaults rather than missing code.

27th September 2026 Â· 38 min Â· 8443 words Â· Damien Dye