<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Linux on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/linux/</link>
    <description>Recent content in Linux on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Tue, 15 Sep 2026 09:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/linux/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Webex Is Looking For Your Certificates On A Cisco Build Server</title>
      <link>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</link>
      <pubDate>Tue, 15 Sep 2026 09:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</guid>
      <description>Webex on Linux says &amp;#34;Offline - No internet connection&amp;#34; on a machine whose network is fine: the OpenSSL Cisco ship looks for its trust store inside their own build container. What breaks, the fixes that fail, the one that works, what the build process got wrong, and how a security appliance vendor ships a client that cannot check a certificate.</description>
    </item>
    <item>
      <title>A VPN Out of Parts: PPP, Tap Devices and Netcat</title>
      <link>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</link>
      <pubDate>Mon, 14 Sep 2026 15:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</guid>
      <description>A VPN is a virtual link plus a carrier, and Linux ships a program for each: pppd or a tap device, and netcat. Building it both ways — over TCP, UDP, TLS and DTLS, with zstd compression — shows what a VPN is made of, and what egress really is: once an attacker has root and outbound is open, the tunnel is already installed.</description>
    </item>
    <item>
      <title>Ping: The Diagnostic Tool That Opens a Whole Lot More</title>
      <link>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</link>
      <pubDate>Tue, 01 Sep 2026 08:05:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</guid>
      <description>Why ping — ICMP echo, not the rest of the protocol — is a liability: a channel every host must answer, so a network that &amp;#39;only allows ping&amp;#39; has a full VPN out. The threat, who can open one, three tunnels (Hans, icmptunnel, a Python one with AES-128), and the rule that shuts it: nftables, pf, Cisco, Junos, MikroTik and Windows.</description>
    </item>
    <item>
      <title>The Firewall Is Eleven Hops Away</title>
      <link>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</link>
      <pubDate>Fri, 28 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</guid>
      <description>A connection that times out tells you nothing about where it died. TTL does. Here is how to count the hops to whatever is eating your port, on Linux, macOS, the BSDs, Solaris and Redox, with a script that needs no root on Linux.</description>
    </item>
  </channel>
</rss>
