<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8671583514969607875</id><updated>2011-12-27T14:13:21.046-08:00</updated><category term='linux'/><category term='Germany'/><category term='3D'/><category term='viewmaster'/><category term='Tea'/><category term='photography'/><category term='security'/><category term='politics'/><category term='debian'/><category term='religion'/><category term='samba'/><category term='email'/><category term='Drivers License'/><category term='Windows'/><category term='Munich'/><title type='text'>Deus ex machina</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>18</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-8571696653686729175</id><published>2011-08-05T06:42:00.000-07:00</published><updated>2011-08-05T08:16:26.608-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='3D'/><category scheme='http://www.blogger.com/atom/ns#' term='viewmaster'/><category scheme='http://www.blogger.com/atom/ns#' term='photography'/><title type='text'>Making stereo photos with the Viewmaster Mark II</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9RcmBVBVbqI/TjwI51YwA7I/AAAAAAAAADs/98aHYoRTA7E/s1600/chips.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-VVQh4bn7-bs/Tjv5knlcWjI/AAAAAAAAADg/R1sihZ0zpqk/s1600/film.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="96" src="http://1.bp.blogspot.com/-VVQh4bn7-bs/Tjv5knlcWjI/AAAAAAAAADg/R1sihZ0zpqk/s640/film.gif" width="640" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;In 2010, I bought a Viewmaster Mark II camera in a store in Munich. In     New Zealand I had never seen one for sale. They seem fairly common in Germany although not     cheap - I paid 169€ but the camera was basically mint (but no ERC or     manual).&lt;br /&gt;&lt;br /&gt;Naturally, the staff immediately brought out another Mark II, at a cheaper price, moments after I left the store.&lt;br /&gt;&lt;br /&gt;I think I've made every mistake possible so far in the production of my own viewmaster reels. I'm blogging this so that I have my own reference and perhaps I can save others from the same hassles. &lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-p6m0oD0Lu3c/TaGJmWEvqRI/AAAAAAAAAC8/an4pOM3vKvU/s1600/viewmaster1.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="327" src="http://2.bp.blogspot.com/-p6m0oD0Lu3c/TaGJmWEvqRI/AAAAAAAAAC8/an4pOM3vKvU/s400/viewmaster1.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;My Viewmaster "Mark II" from the 1960s&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;I put the first roll of film through the camera last year soon after     buying it, although it does take time to shoot 72 photos. The image itself is a quarter of the standard size, but you're taking two photos each time, so you get 72 scenes on a 36 exposure film.&lt;br /&gt;&lt;br /&gt;The VM Mk     II requires an exposure value (EV) of 8 to 15 to be set, rather than adjusting     aperture and speed. Although I collect cameras, I've never used a     camera that was only set with EV.&lt;br /&gt;&lt;br /&gt;After reading on the internet an explanation about the extra colour     dials on the front of the camera, I completely abandoned the idea of     adjusting those because I couldn't get my head around them. A manual would help.&lt;br /&gt;&lt;br /&gt;My initial problem was to take accurate EV readings. My     trusty Western light meter was tiring and no longer so trustworthy.     Luckily a friend by complete chance had an electronic meter that     actually gave EV readings. I was kind of surprised to find an     electronic meter that gave EV readings because I thought the idea     was arcane. He works in the film industry, I'm not sure if it's     still relevant there. Movie cameras shoot at a constant rate, so aperture is the only possible adjustment.&lt;br /&gt;&lt;br /&gt;So armed, with meter and camera, I got off a first roll that actually     wasn't so bad. I could see the shots improve dramatically from the     point that I obtained the electronic exposure meter. The next step was to mount them.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-sFIcRIfoE4E/Tjv8FtR7l7I/AAAAAAAAADk/RtYz3dQYg54/s1600/nichteinschneiden.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" height="160" src="http://2.bp.blogspot.com/-sFIcRIfoE4E/Tjv8FtR7l7I/AAAAAAAAADk/RtYz3dQYg54/s200/nichteinschneiden.jpg" width="200" /&gt;&lt;/a&gt;Something I hadn't considered, but the same friend who lent me the lightmeter pointed out that I should specify that the film should not be cut at processing time. So far I haven't forgotten to do that; it would be a disaster if the lab ignored the instructions.&lt;br /&gt;&lt;br /&gt;The cost of original empty discs left me reeling (geddit?), so     I bought some of the &lt;a href="http://www.3dstereo.com/Merchant2/merchant.mvc?Screen=PROD&amp;amp;Product_Code=RM-RLM"&gt;REEL Master 3D Mounts&lt;/a&gt; available at &lt;a href="http://www.3dstereo.com/"&gt;3dstereo.com&lt;/a&gt;. &lt;a href="http://www.3dstereo.com/"&gt;3dstereo.com&lt;/a&gt; are really  helpful. Don't be afraid to ask them a question before buying something  if you're unsure on some point about a product. I'm not affiliated with  them in any way, so consider this a genuine endorsement.&lt;br /&gt;&lt;br /&gt;&lt;table cellpadding="0" cellspacing="0" class="tr-caption-container" style="float: left; margin-right: 1em; text-align: left;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-BYeNQy_qKHk/TaGIoyZK8_I/AAAAAAAAACw/oXbS6ulUvRU/s1600/DSC_0104.JPG" imageanchor="1" style="clear: left; margin-bottom: 1em; margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="165" src="http://3.bp.blogspot.com/-BYeNQy_qKHk/TaGIoyZK8_I/AAAAAAAAACw/oXbS6ulUvRU/s200/DSC_0104.JPG" width="200" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;My "Model E" viewer from the 1950s&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;I picked up an old viewer for 7€ on eBay from a seller just down the road in Austria. &lt;br /&gt;&lt;br /&gt;My real problems started when I tried to mount the shots. I didn't     have a cutter. Imagine me, with a small pair of scissors, cursing     away as I tried to cut those little blighters out of the film. For the record, the blighters are actually known as "chips". I     didn't know how to cut them for mounting, I scratched other shots in     the process and by the time I'd mounted some with a very hairy     gluestick the results could be generously described as artistically     rusticated with a false patina.&lt;br /&gt;&lt;br /&gt;Certainly, the 3D affect was the least noticeable characteristic. At     that point I also discovered the hopelessness of photographing     things within 5 meters. Plants in particular gave the oddest effect     in that range. I subsequently discovered that was because I had mounted them the wrong way around and I was to make about 10 reels before I discovered this mistake. Now things look fine close up.&lt;br /&gt;&lt;br /&gt;After the scissor disaster, I was resigned to buying a cutter. Had I known in the     beginning, how difficult to find and how expensive a cutter was,     I may very well  never have embarked upon the enterprise and left the     camera on the shop shelf.&lt;br /&gt;&lt;br /&gt;I started to blindly bid on Viewmaster cutters on eBay. I nearly won a couple, but the auctions were sniped in the dying seconds at     outrageous prices (always more than the camera cost me). Sniped as I     was, I unwittingly dodged a bullet because I didn't realise that Viewmaster cutters were not all the same. I needed the right cutter for the     camera. I discovered this by chance while looking up some other     matter related to Viewmaster.&lt;br /&gt;&lt;br /&gt;Disheartened, I shelved the project, but continued to finish the     second roll of film in the camera. The goal of not only buying a     cutter in my price range but also finding one for the Mark II seemed     almost impossible.&lt;br /&gt;&lt;br /&gt;After a three     month hiatus, the project was reanimated. The networking company that I work for     has an interest in 3D TV technology and a Sensavis rep from The     Netherlands presented 3D TV working without glasses. It was the     touchpaper and I found myself once again trawling eBay for the right     cutter.&lt;br /&gt;&lt;br /&gt;I did find one, the right one, from a German seller. It cost about     140€ (including shipping) and it functions!&lt;br /&gt;&lt;br /&gt;Below: The cutter in use. Note the holes in the film to the left where the images have been cut out. One of the chips is lying in front of the cutter. To the left you can also see the cardboard mounts that the chips are glued into.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-OPwEgp7IQYk/TaGI7w69hRI/AAAAAAAAAC0/0Ba2sMFkwpw/s1600/DSC_0099.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="206" src="http://1.bp.blogspot.com/-OPwEgp7IQYk/TaGI7w69hRI/AAAAAAAAAC0/0Ba2sMFkwpw/s320/DSC_0099.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;Below: Looking from the top, you can see the two images before they are guillotined out of the film. There is a backlight to help see the picture. I really need to get a good magnifying glass because it is very hard to guage the quality of the image until you get it mounted.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-mGQrN9z_0EI/TaGJA0bwi1I/AAAAAAAAAC4/FCjIQzkS_R4/s1600/DSC_0101.JPG" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="214" src="http://2.bp.blogspot.com/-mGQrN9z_0EI/TaGJA0bwi1I/AAAAAAAAAC4/FCjIQzkS_R4/s320/DSC_0101.JPG" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;It wasn't until I bought some original "Personal View Mounts" that I realised I was mounting the pictures back to front. There is only one way to mount the chips into the original mounts. The downside to the original mounts is that they are hideously expensive. You also need to buy a "Pocket Expanding Tool" available at &lt;a href="http://www.3dstereo.com/"&gt;3dstereo.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-G74Ra3XlAUw/TjwIVkTahWI/AAAAAAAAADo/dfQ1ZBKYbd0/s1600/reel.gif" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="319" src="http://1.bp.blogspot.com/-G74Ra3XlAUw/TjwIVkTahWI/AAAAAAAAADo/dfQ1ZBKYbd0/s320/reel.gif" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-d49KFkrzs2A/TjvqzdHeBbI/AAAAAAAAADc/NeOt7p1hnaY/s1600/vm-reel-reel.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;Here's how they should be mounted. When the camera takes a picture it creates a notch as part of the image to indicate which chip is left and right. When the cutter cuts out the chip, you're left with an unexposed black strip on the same side as the angular or circular notch. It's hard to see in the photo, but the side with the black strip should go to the outer. My mistake was to put the notch side to the inner. Notice also that the chips (left of image) all have one corner nibbled of. &lt;br /&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-D_CWmCjL_Sc/TjvlTqk4YoI/AAAAAAAAADI/3wB8OBYaKqo/s1600/DSC_0273-blog.jpg" imageanchor="1" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="236" src="http://3.bp.blogspot.com/-D_CWmCjL_Sc/TjvlTqk4YoI/AAAAAAAAADI/3wB8OBYaKqo/s400/DSC_0273-blog.jpg" width="400" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;"Reel Master 3D mounts" available from&lt;a href="http://www.3dstereo.com/"&gt; 3dstereo.com&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;b&gt;Tips for mounting chips into the "Reel Master 3D" mounts&lt;/b&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Before doing anything, check that the mount windows have been cut out properly - check for chads and hairs.&amp;nbsp;&lt;/li&gt;&lt;li&gt;Use tweezers to drop the chip. Be careful not to scratch the chip. Use something soft, like a cotton bud to press down the image. The downside to a cotton bud is that you can get hairs caught in the image.&lt;/li&gt;&lt;li&gt;Chips go in with the notch on the outer side of the reel.&lt;/li&gt;&lt;li&gt;Butt the inner edge of the chip as close to the window edge as possible &lt;i&gt;unless &lt;/i&gt;the subject is quite close. If the subject is close, it's my experience that you need to achieve symmetry in the left and right image.&lt;/li&gt;&lt;li&gt;Watch out that you don't have gaps at the inner corners between the card and the chip. This is very distracting when you view the image.&lt;/li&gt;&lt;li&gt;Use a liquid (fast setting) glue on the outer edge only when placing the chip. Do not apply glue close to the window because it will spread out to the image itself, which looks horrible and can't be undone. With this technique you have a chance to move the chip a little after it is placed. You don't need a lot of glue to stick the chip, because after you seal the two cards together the chips will be firmly in place.&lt;/li&gt;&lt;li&gt;Use gluestick on the other side. I found that liquid glue works, but gluestick seemed to be easier and increased the thickness of the reel. My old viewer has trouble pulling through reels that are stuck down with liquid glue. To clarify, use liquid glue on the chips and then gluestick to glue the two cardboard halves together.&lt;/li&gt;&lt;li&gt;Don't get carried away with the gluestick, just make sure that you get the outer edges and the inner circle. Don't get any glue near the windows!&amp;nbsp; &lt;/li&gt;&lt;/ol&gt;&lt;b&gt;Tips for Personal Mounts&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Push the&lt;b&gt; &lt;/b&gt;pocket expanding tool evenly into the window. Make sure you're not favouring one side.&lt;/li&gt;&lt;li&gt;Push the pocket expanding tool right to the end of the window.&lt;b&gt;&amp;nbsp;&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Insert the chip with tweezers.&lt;/li&gt;&lt;li&gt;Push the chip right to the end of the window.&lt;/li&gt;&lt;li&gt;The pocket expanding tool is a bit flimsy, be careful that you don't bend the metal at the point where it meets the handle. &lt;/li&gt;&lt;/ol&gt;In all cases, check the finished product for hairs. Although the film is sensitive to moisture, you can gently huff on the images and clean them up with a cotton bud if necessary. Again, a cotton bud is sub-optimal because it can leave hairs behind, pull them off with tweezers. &lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;table align="center" cellpadding="0" cellspacing="0" class="tr-caption-container" style="margin-left: auto; margin-right: auto; text-align: center;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td style="text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-9RcmBVBVbqI/TjwI51YwA7I/AAAAAAAAADs/98aHYoRTA7E/s1600/chips.gif" style="margin-left: auto; margin-right: auto;"&gt;&lt;img border="0" height="476" src="http://3.bp.blogspot.com/-9RcmBVBVbqI/TjwI51YwA7I/AAAAAAAAADs/98aHYoRTA7E/s640/chips.gif" width="640" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="tr-caption" style="text-align: center;"&gt;Our trip to Munich's Botanic Gardens&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-8571696653686729175?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/8571696653686729175/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=8571696653686729175' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8571696653686729175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8571696653686729175'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2011/08/viewmaster-taking-photos-and-making.html' title='Making stereo photos with the Viewmaster Mark II'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-VVQh4bn7-bs/Tjv5knlcWjI/AAAAAAAAADg/R1sihZ0zpqk/s72-c/film.gif' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-4079309354497845219</id><published>2011-07-21T23:44:00.000-07:00</published><updated>2011-07-21T23:46:46.216-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Munich'/><title type='text'>How to spend an afternoon in Munich</title><content type='html'>&lt;div class="MsoPlainText"&gt;&lt;b&gt;Taxi&lt;/b&gt; &lt;/div&gt;&lt;div class="MsoPlainText"&gt;Expect to pay 15-25€ to get from your hotel into the centre of Munich by taxi. That's a complete guess by the way. That's OK if you share the cab. A taxi will be faster in the long run, I'd recommend it to maximize your time in Munich central.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;b&gt;Public Transport &lt;/b&gt;&lt;/div&gt;Buy either a group ticket or single day tickets. Typically you will stay in "zone 1" if you are seeing the normal Munich sites.&lt;br /&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;The group ticket is cheaper if you want to travel all at the same time to the same places. A single ticket in zone 1 costs 2.50€ and a group ticket "Partner-Tageskarte" costs 9,80€ and 5 can all travel (together) on that one ticket.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;From Hauptbahnhof (central station), you change to the S-Bahn (look for the green Ssymbol). When you get the platform you can jump on any train, just make sure you're on the platform that goes in the direction of Marienplatz (or wherever you want to end up).&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;a href="http://www.mvv-muenchen.de/web4archiv/objects/download/netz11a4englisch.pdf"&gt;http://www.mvv-muenchen.de/web4archiv/objects/download/netz11a4englisch.pdf&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;b&gt;Suggestions&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;A) Start at Marienplatz, Munich's most famous square and very picturesque with the New Rathaus in Neo Gothic style. Check out the dragon climbing the wall on the left front corner.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;B) Behind you, you can see the tower of St Peters church. Go climb it, at 1.50€ it's the cheapest thing you can do in Munich and the view is outstanding if the weather is clear.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;Inside St. Peters you'll find a very well dressed skeleton in a display case. As a New Zealander it was really weird to find such a thing, but now that we've been in Europe for a while it seems pretty run-of-the-mill. It doesn't cost to go in.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;C) Not far from St. Peter's you'll find Viktualienmarkt, with lots of stalls with interesting foods.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;D) If you like Museums then head around to the Stadtmuseum. They might have something on to interest you. Check out the special exhibitions page here, put it into google translate, there's no English version:&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;a href="http://www.stadtmuseum-online.de/aktuell/index.htm"&gt;http://www.stadtmuseum-online.de/aktuell/index.htm&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;While you're there, you'll also see the rather strange and interesting Jewish Museum. You might want to go in but for me the building itself is more interesting than the contents.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;E) Time for some shopping! Head to Kaufingerstrasse. It's a mixture of stores for the common man and stores for the common elite.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;F) While you're near, you should check out Frauenkirche. Of course, this is Munich's icon on the skyline. You won't spend long inside.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;G) Keep moving, there's still shopping to be done! Head up Kaufingerstrasse to Karlsplatz. If you're a real Munchner you don't call it Karlsplatz, because nobody liked the guy it was named after. We call it "Stachus" after a pub; we do love to drink.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;Wikipedia says of Stachus: Most important buildings dominating the square are on the east side the Karlstor, a gothic gate of the demolished medieval fortification and the rondell buildings on both sides next to the gate (constructed by Gabriel von Seidl 1899-1902). In front of the Karlstor, which was first documented in 1301 and called Neuhauser Tor until 1791, is during the summer period a big fountain. In winter an open-air ice rink is installed there. The most significant buildings on the opposite west side are the neo-baroque Justizpalast &lt;/div&gt;&lt;div class="MsoPlainText"&gt;(Palace of Justice) and the Kaufhof, the first postwar department store of Munich (by Theo Pabst,&amp;nbsp; 1950/1951).&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;Here you can deviate from the tour. If you want to go see some galaries and museums then catch the number 27 tram (Petuelring) from here to the Pinakotheken stop. The Neue Pinakothek, Alte Pinakothek, Modern and the Brandhorst Museum are all close by.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;iframe frameborder="0" height="350" marginheight="0" marginwidth="0" scrolling="no" src="http://maps.google.com/maps?oe=utf-8&amp;amp;ie=UTF8&amp;amp;q=pinakoteka+munchen&amp;amp;fb=1&amp;amp;hq=pinakoteka&amp;amp;hnear=Munich,+Bavaria,+Germany&amp;amp;sll=48.144397,11.575039&amp;amp;sspn=0.012649,0.012354&amp;amp;ll=48.148193,11.571994&amp;amp;spn=0.004388,0.006909&amp;amp;output=embed" width="425"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;small&gt;&lt;a href="http://maps.google.com/maps?oe=utf-8&amp;amp;ie=UTF8&amp;amp;q=pinakoteka+munchen&amp;amp;fb=1&amp;amp;hq=pinakoteka&amp;amp;hnear=Munich,+Bavaria,+Germany&amp;amp;sll=48.144397,11.575039&amp;amp;sspn=0.012649,0.012354&amp;amp;ll=48.148193,11.571994&amp;amp;spn=0.004388,0.006909&amp;amp;source=embed" style="color: blue; text-align: left;"&gt;View Larger Map&lt;/a&gt;&lt;/small&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;H) If you aren't already sick of churches you should definitely head up to Theatinerkirche. This is my favourite Church in Munich. Built from 1663 to 1690 in Italian high-Baroque style.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;a href="http://en.wikipedia.org/wiki/Theatine_Church,_Munich"&gt;http://en.wikipedia.org/wiki/Theatine_Church,_Munich&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;I/J) Across from Theatinerkirche is the Residenz and Hofgarten. The Residence is to the right and around the corner, the Hofgarten entrance faces Theatinerkirche. If you like bling, check out the Residenz Schatzkammer (treasury) this is something else. There's some beautiful items dating back to as early as the 12th century.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;a href="http://www.residenz-muenchen.de/deutsch/skammer/index.htm"&gt;http://www.residenz-muenchen.de/deutsch/skammer/index.htm&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;K) You've done well to get this far. It's time for dinner and a well &lt;/div&gt;&lt;div class="MsoPlainText"&gt;earned beer. If the weather is good, make the effort to walk 20 minutes &lt;/div&gt;&lt;div class="MsoPlainText"&gt;up to the Chinese Tower beer garden. Make sure you have a map, the place &lt;/div&gt;&lt;div class="MsoPlainText"&gt;is hard to find if you're as navigationally challenged as I am. If &lt;/div&gt;&lt;div class="MsoPlainText"&gt;you're in Munich you have to visit at least one beer garden.&lt;/div&gt;&lt;div class="MsoPlainText"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoPlainText"&gt;If the weather is a bit rubbish, walk back to Marienplatz, where you started and find the Ratskeller restaurant. The entrance is hard to spot. It's actually underneath the neo gothic Rathaus that you started at. Look for the U-Bahn exit, the Ratskeller entrance is a few metres away from that.&lt;/div&gt;&lt;br /&gt;&lt;iframe frameborder="0" height="700" marginheight="0" marginwidth="0" scrolling="no" src="http://maps.google.co.uk/maps?saddr=Marienplatz,+Munich,+Germany&amp;amp;daddr=Peterskirche,+munich+to:Viktualienmarkt,+Munich,+Germany+to:M%C3%BCnchner+Stadtmuseum,+M%C3%BCnchen,+Deutschland+to:Kaufingerstra%C3%9Fe,+M%C3%BCnchen,+Deutschland+to:Frauenkirche,+Frauenplatz,+M%C3%BCnchen,+Deutschland+to:Karlsplatz+-+Stachus,+Karlsplatz,+Munich,+Germany+to:48.1416789,11.5741464+to:48.14118,11.57637+to:Theatinerkirche,+Salvatorplatz,+M%C3%BCnchen,+Deutschland+to:Residenz+M%C3%BCnchen,+Max-Joseph-Platz,+Munich,+Germany+to:Hofgarten,+Odeonsplatz,+Munich,+Germany+to:Chinesischer+Turm,+Englischer+Garten,+M%C3%BCnchen,+Deutschland&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;sll=48.142552,11.58062&amp;amp;sspn=0.017211,0.033774&amp;amp;geocode=FU2D3gIdbqKwAClxKxTZinWeRzGqTEjojzvhnQ%3BFTmB3gIdd6GwACFnrNSOMPKRrg%3BFXx83gIdPKOwACH9raaX7LTfUA%3BFWN73gIdm5SwACEH6pHKQw4Qng%3BFZWF3gIdmpiwACnZ3EHh9HWeRzFumBlQqxWYIA%3BFXaJ3gIdypawACELfuX-vB4uDA%3BFReM3gIdDXywACEZwblUEGjhpg%3BFW6V3gIdgpuwAClnF7QI83WeRzGA4DzgoyUdEw%3BFXyT3gIdMqSwACkpoSQ683WeRzEg0jzgoyUdEw%3BFaGW3gId-aawACH7OdLwBlaIFA%3BFSCS3gIdXbSwACGudNI2jk-FZg%3BFYec3gId37iwACHqDdWaB9dTjQ%3BFd-_3gIdluGwACFBa1cVzypFGA&amp;amp;mra=ls&amp;amp;via=7,8&amp;amp;dirflg=w&amp;amp;ll=48.143697,11.579633&amp;amp;spn=0.020045,0.030041&amp;amp;z=15&amp;amp;output=embed" width="700"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;small&gt;&lt;a href="http://maps.google.co.uk/maps?saddr=Marienplatz,+Munich,+Germany&amp;amp;daddr=Peterskirche,+munich+to:Viktualienmarkt,+Munich,+Germany+to:M%C3%BCnchner+Stadtmuseum,+M%C3%BCnchen,+Deutschland+to:Kaufingerstra%C3%9Fe,+M%C3%BCnchen,+Deutschland+to:Frauenkirche,+Frauenplatz,+M%C3%BCnchen,+Deutschland+to:Karlsplatz+-+Stachus,+Karlsplatz,+Munich,+Germany+to:48.1416789,11.5741464+to:48.14118,11.57637+to:Theatinerkirche,+Salvatorplatz,+M%C3%BCnchen,+Deutschland+to:Residenz+M%C3%BCnchen,+Max-Joseph-Platz,+Munich,+Germany+to:Hofgarten,+Odeonsplatz,+Munich,+Germany+to:Chinesischer+Turm,+Englischer+Garten,+M%C3%BCnchen,+Deutschland&amp;amp;hl=en&amp;amp;ie=UTF8&amp;amp;sll=48.142552,11.58062&amp;amp;sspn=0.017211,0.033774&amp;amp;geocode=FU2D3gIdbqKwAClxKxTZinWeRzGqTEjojzvhnQ%3BFTmB3gIdd6GwACFnrNSOMPKRrg%3BFXx83gIdPKOwACH9raaX7LTfUA%3BFWN73gIdm5SwACEH6pHKQw4Qng%3BFZWF3gIdmpiwACnZ3EHh9HWeRzFumBlQqxWYIA%3BFXaJ3gIdypawACELfuX-vB4uDA%3BFReM3gIdDXywACEZwblUEGjhpg%3BFW6V3gIdgpuwAClnF7QI83WeRzGA4DzgoyUdEw%3BFXyT3gIdMqSwACkpoSQ683WeRzEg0jzgoyUdEw%3BFaGW3gId-aawACH7OdLwBlaIFA%3BFSCS3gIdXbSwACGudNI2jk-FZg%3BFYec3gId37iwACHqDdWaB9dTjQ%3BFd-_3gIdluGwACFBa1cVzypFGA&amp;amp;mra=ls&amp;amp;via=7,8&amp;amp;dirflg=w&amp;amp;ll=48.143697,11.579633&amp;amp;spn=0.020045,0.030041&amp;amp;z=15&amp;amp;source=embed" style="color: blue; text-align: left;"&gt;View Larger Map&lt;/a&gt;&lt;/small&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-4079309354497845219?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/4079309354497845219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=4079309354497845219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4079309354497845219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4079309354497845219'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2011/07/how-to-spend-afternoon-in-munich.html' title='How to spend an afternoon in Munich'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-6218607237615469688</id><published>2011-03-13T07:05:00.000-07:00</published><updated>2011-03-13T09:00:52.986-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='samba'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Permit samba to follow symbolic links to an unshared mount</title><content type='html'>I'm posting this because if you google for the answer you end up getting out of date answers and the wrong commands.&lt;br /&gt;&lt;br /&gt;What I wanted to do was simply make a symbolic link from my samba shared directory /storage to /home.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;server:/storage# ls -l /storage/&lt;br /&gt;lrwxrwxrwx&amp;nbsp; 1 root&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 Mar 13 14:14 home -&amp;gt; /home&lt;br /&gt;drwxr-x---&amp;nbsp; 4 michael users 4096 Mar&amp;nbsp; 9 00:33 music&lt;br /&gt;drwxr-xr-x&amp;nbsp; 5 michael users 4096 Mar&amp;nbsp; 9 00:33 photos&lt;/blockquote&gt;&lt;br /&gt;Samba won't let users follow a symbolic link if the link points to a place outside of (i.e. not under) the share defined in smb.conf. This kind of symbolic link is insecure because a user could set up a symbolic link to point to anywhere in the file system and attain access to it. Yep, that's pretty appalling if you have users who you don't know or trust. But this is my home network, so user level security is not a concern for me.&lt;br /&gt;&lt;br /&gt;The smb.conf man page explains it like so:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Turning this parameter on when UNIX extensions are enabled will allow UNIX clients to create symbolic links on the share that can point to files or directories outside restricted path exported by the share definition. This can cause access to areas outside of the share. Due to this problem, this parameter will be automatically disabled (with a message in the log file) if the unix extensions option is on.&lt;/blockquote&gt;The solution didn't even require google, I should have just read the manual to start off with. Here's the amendments to the smb.conf global section:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;[global]&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # default&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; follow symlinks = yes&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # allow symlinks&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; wide links = yes&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # Must be off for wide links&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unix extensions = no&amp;nbsp;&lt;/blockquote&gt;After restarting samba, no problem.&lt;br /&gt;&lt;br /&gt;A couple of tips relating to security. I use passwords on my accounts and disable the root user. Also, I make sure that if someone does gain access to the home network (somehow getting our WPA PSK), then only the permitted (authenticated) users can mount the Samba share. Also, eth1 is excluded from the bind interfaces because eth1 is attached to the cable modem and I don't want the samba server to make itself available to the internet. Setting up user passwords and authentication is not described below.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;[global]&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; invalid users = root&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interfaces = eth0 eth2 lo&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind interfaces only = yes&lt;br /&gt;&lt;br /&gt;...&lt;br /&gt;&lt;br /&gt;[storage]&lt;br /&gt;&lt;blockquote&gt;comment = Storage&lt;br /&gt;path = /storage&lt;br /&gt;valid users = usera userb&lt;br /&gt;guest ok = No&lt;br /&gt;read only = No&lt;br /&gt;browseable = Yes&lt;br /&gt;available = Yes&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-6218607237615469688?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/6218607237615469688/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=6218607237615469688' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6218607237615469688'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6218607237615469688'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2011/03/permit-samba-to-follow-symbolic-links.html' title='Permit samba to follow symbolic links to an unshared mount'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-7724184559910106485</id><published>2010-10-25T12:49:00.000-07:00</published><updated>2011-04-06T05:27:00.251-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Drivers License'/><category scheme='http://www.blogger.com/atom/ns#' term='Munich'/><category scheme='http://www.blogger.com/atom/ns#' term='Germany'/><title type='text'>How to convert a New Zealand driving license to a German one (in Munich).</title><content type='html'>This will instruct you how to convert your NZ license to a German one. In fact, these instructions are probably accurate for any person whose country of origin requires that the exchange involve a theory test and no practical exam. The requirement for a practical test was removed for New Zealanders a couple of years ago.&lt;br /&gt;&lt;br /&gt;Some countries can't convert their license, for other countries it can be very simple. Australians, for example, can exchange their license with nothing more involved than filing the paperwork with the KVR (I think they also need a translation).&lt;br /&gt;&lt;br /&gt;The prices I quote are in euros and what I paid for each step. They are obviously approximations of what you will have to pay.&lt;br /&gt;&lt;br /&gt;I did this in Munich so where you see KVR, read "Local administration body".&lt;br /&gt;&lt;br /&gt;Yes, this post is long, but I've tried to pre-empt all the questions and cover the many unknowns of trying to do this. You will get bad advice from all sorts of people, in my case, I got bad advice from the Polizei, a lawyer and someone from the TÜV. You have to make yourself right with the KVR, they're who're standing in between you and that glossy bit of plastic.&lt;br /&gt;&lt;br /&gt;So here it is, in tedious detail, written by someone who negotiated this winding road in mid 2010.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(1) Sit a first aid course. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The Red Cross run them irregularly in Munich in English. The basic course can take a couple of evenings. At the end of the course you will be issued with a certificate, which you must retain for later.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.drk.de/angebote/erste-hilfe-und-rettung/kurse-in-erster-hilfe.html"&gt;http://www.drk.de/angebote/erste-hilfe-und-rettung/kurse-in-erster-hilfe.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cost: 25.&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/__weDEiUqgTY/TMXdh83NELI/AAAAAAAAACc/rz1nAno1Dvw/s1600/first+aid+certification+-+smudged.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="226" src="http://1.bp.blogspot.com/__weDEiUqgTY/TMXdh83NELI/AAAAAAAAACc/rz1nAno1Dvw/s320/first+aid+certification+-+smudged.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;[sample certificate]&lt;/div&gt;&lt;br /&gt;&lt;b&gt;(2) Get an eyesight test.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;You can go to the mall to get one of those. Wander into an optician or even glasses retailer and they can probably do it on the spot. Take your passport, you will be asked for it.&lt;br /&gt;&lt;br /&gt;Cost (appoximate): 6.50.&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/__weDEiUqgTY/TMXdPf1PBLI/AAAAAAAAACY/2lWoXNpPTQY/s1600/eyesight+test+-+smudged.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://2.bp.blogspot.com/__weDEiUqgTY/TMXdPf1PBLI/AAAAAAAAACY/2lWoXNpPTQY/s320/eyesight+test+-+smudged.png" width="212" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;[sample eyesight test]&lt;/div&gt;&lt;br /&gt;&lt;b&gt;(3) Get a translation of your license. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;The translation has to be signed with a magic translator's stamp. I very much doubt that you can use the so-called permit that the AA issues in NZ. I didn't even bother trying that one. It's just better to make sure that your paperwork is order to minimise face time with the KVR.&lt;br /&gt;&lt;br /&gt;ADAC issue an official translation with the magic stamp. This is a sickening license to print money. It takes 10 minutes. For the peace of mind it may be worth it. I know of people who have had problems with translations&amp;nbsp; from official translators because of miscellaneous KVR pedantry. If you use a translator to save some euros then make sure that they conform to the ADAC standard.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe frameborder="0" height="350" marginheight="0" marginwidth="0" scrolling="no" src="http://maps.google.com/maps?q=S%C3%BCdbayerische+ADAC-Wirtschaftdienst+GmbH&amp;amp;hl=de&amp;amp;ie=UTF8&amp;amp;view=map&amp;amp;cid=17072110638335914159&amp;amp;hq=S%C3%BCdbayerische+ADAC-Wirtschaftdienst+GmbH&amp;amp;hnear=&amp;amp;ll=48.13252,11.53466&amp;amp;spn=0.006295,0.006295&amp;amp;t=h&amp;amp;iwloc=A&amp;amp;output=embed" width="425"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;small&gt;&lt;a href="http://maps.google.com/maps?q=S%C3%BCdbayerische+ADAC-Wirtschaftdienst+GmbH&amp;amp;hl=de&amp;amp;ie=UTF8&amp;amp;view=map&amp;amp;cid=17072110638335914159&amp;amp;hq=S%C3%BCdbayerische+ADAC-Wirtschaftdienst+GmbH&amp;amp;hnear=&amp;amp;ll=48.13252,11.53466&amp;amp;spn=0.006295,0.006295&amp;amp;t=h&amp;amp;iwloc=A&amp;amp;source=embed" style="color: blue; text-align: left;"&gt;Größere Kartenansicht&lt;/a&gt;&lt;/small&gt;&lt;br /&gt;&lt;br /&gt;Cost: 49.&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/__weDEiUqgTY/TMXdwUl5AwI/AAAAAAAAACg/q30Rvq6eVLU/s1600/nz+licence+translation+-+smudged.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="320" src="http://4.bp.blogspot.com/__weDEiUqgTY/TMXdwUl5AwI/AAAAAAAAACg/q30Rvq6eVLU/s320/nz+licence+translation+-+smudged.png" width="226" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;[sample translation]&lt;/div&gt;&lt;br /&gt;&lt;b&gt;(4) File an application for the exchange with the KVR. &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This is a nightmare. I had to wait for 2 hours before my number was called. It's always a good idea to go early in the morning. I arrived there about 8 AM, but they open at 7AM. Even if you arrive at 7AM you are guaranteed to encounter an early morning queue. Beware the Wartezone F zone of boredom, take a book - one that you're not close to the end of.&lt;br /&gt;&lt;br /&gt;Note: This is not the same KVR offices that deal with your residency. This is yet another KVR office.&lt;br /&gt;&lt;br /&gt;Eichstätter Str. 2, 80686 München, Germany&lt;br /&gt;&lt;br /&gt;&lt;a href="http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Eichst%C3%A4tter+Str.+2,+80686+M%C3%BCnchen,+Germany&amp;amp;sll=48.13172,11.51969&amp;amp;sspn=0.018102,0.034075&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Eichst%C3%A4tter+Stra%C3%9Fe+2,+M%C3%BCnchen+80686+M%C3%BCnchen,+Bayern,+Germany&amp;amp;t=h&amp;amp;z=16"&gt;http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Eichst%C3%A4tter+Str.+2,+80686+M%C3%BCnchen,+Germany&amp;amp;sll=48.13172,11.51969&amp;amp;sspn=0.018102,0.034075&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=Eichst%C3%A4tter+Stra%C3%9Fe+2,+M%C3%BCnchen+80686+M%C3%BCnchen,+Bayern,+Germany&amp;amp;t=h&amp;amp;z=16&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You do not fill out any forms beforehand but you absolutely must have the following documents with you:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Passport.&lt;/li&gt;&lt;li&gt;NZ Drivers License.&lt;/li&gt;&lt;li&gt;First aid certificate.&lt;/li&gt;&lt;li&gt;Eyesight test certificate.&lt;/li&gt;&lt;li&gt;License translation.&lt;/li&gt;&lt;li&gt;Cash or EC card.&lt;/li&gt;&lt;/ul&gt;The KVR will take your NZ license. They keep it stored and you can retrieve it if you really need to, but NOT after your German license has been issued. The deal is that you can't pick up your German license if they don't have your NZ license. Once you pick up the German license then your NZ license is sent back to NZ. I have no idea what agency in NZ ends up with it.&lt;br /&gt;&lt;br /&gt;At the front desk, just tell them that you want to exchange your license. If anyone asks you about a driving school, be sure in the knowledge that:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;You do not need to have a driving school. The KVR is your driving school because the KVR registers you for the&amp;nbsp; theory test at the TÜV.&lt;/li&gt;&lt;li&gt;The NZ to German license exchange no longer requires a practical test.&lt;/li&gt;&lt;li&gt;If you don't speak German tell them that the test should be in English..&lt;/li&gt;&lt;/ul&gt;The KVR give you a piece of paper with a reference number to check on this website:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www4.muenchen.de/Fuehrerschein/index.html"&gt;http://www4.muenchen.de/Fuehrerschein/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;When the application has been processed the webpage will look like this, pay attention to the last line, that's what you're waiting for:&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/__weDEiUqgTY/TMXeHTzRp2I/AAAAAAAAACk/RIRxdAP5c2Y/s1600/webpage-cropped.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="317" src="http://1.bp.blogspot.com/__weDEiUqgTY/TMXeHTzRp2I/AAAAAAAAACk/RIRxdAP5c2Y/s320/webpage-cropped.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;[sample webpage]&lt;/div&gt;&lt;br /&gt;The KVR say that it will take 4 to 6 weeks for them to approve the application. In fact I had to wait for 7 weeks. I recommend that you apply and then start to learn the road code while you're waiting. &lt;br /&gt;&lt;br /&gt;Believe it or not, they manufacture your license before you sit the theory test!&lt;br /&gt;&lt;br /&gt;In case you need to call someone, the Führerscheinstelle (Driver's license office) direct call is 233 36215 or fax -03.&lt;br /&gt;&lt;br /&gt;Cost: 35.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(5) Learn the road code.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;While you're waiting for the rusty wheels of KVR beauracracy to turn, you might want to familiarise yourself with the road code in preparation for the test. Actually, the test isn't so easy, there are a number of stinkers and in all reality the European road code is markedly different to NZ. It would be unwise to think that you can wing it.&lt;br /&gt;&lt;br /&gt;You can buy the road code book, or the test papers, all in English. You can also subscribe to a website for an online/computer exam that drills you on all the possible questions. Be sure, the test questions you can buy are exactly the same as the ones you will get in the test. But there is a huge array of questions to learn.&lt;br /&gt;&lt;br /&gt;Cost: I didn't pay for any of these learning tools. I can tell you that the online test websites are cheap, the hard copies (on paper) are expensive and bought separately.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(6) Take the test with the TÜV.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;When the muenchen.de website tells you to wenden Sie sich bitte an Ihre Fahrschule, don't call the KVR, call the TÜV and book a time to sit the test. They run tests all day, you need to call up a couple of days in advance to get a booking. They start as early as 8AM.&lt;br /&gt;&lt;br /&gt;You must take: &lt;br /&gt;&lt;ul&gt;&lt;li&gt;Your passport.&lt;/li&gt;&lt;li&gt;20.83 in cash.&lt;/li&gt;&lt;/ul&gt;The test is multiple choice with more than one possible answer. It's done on a touchpad style computer. If you buy the computer tests the interface will look just the same. It took me a few moments to get my head around the system. I think you have to answer about 25 questions in 30 minutes, but I finished in 10 minutes and got one question wrong (losing 4 points) - I was in too much of a hurry.&lt;br /&gt;&lt;br /&gt;My test was administered here (third floor):&lt;br /&gt;&lt;br /&gt;Ridlerstraße 57, 80339 München, Deutschland&lt;br /&gt;&lt;br /&gt;&lt;a href="http://maps.google.com/maps/ms?ie=UTF8&amp;amp;hl=en&amp;amp;msa=0&amp;amp;msid=102211286544224829938.00044fbce06a5d07002e8&amp;amp;ll=48.134132,11.532726&amp;amp;spn=0.004733,0.008519&amp;amp;t=h&amp;amp;z=17"&gt;http://maps.google.com/maps/ms?ie=UTF8&amp;amp;hl=en&amp;amp;msa=0&amp;amp;msid=102211286544224829938.00044fbce06a5d07002e8&amp;amp;ll=48.134132,11.532726&amp;amp;spn=0.004733,0.008519&amp;amp;t=h&amp;amp;z=17&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you fail the test, then you have to wait for a stand-down period before you can sit it again. I didn't fail so I don't have first hand experience of what happens.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;(7) Collect your license.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;When you pass the test you are issued a form that you must then take to the KVR (Eichstätter Str. 2). You can go straight from the TÜV to the KVR if you wish. Again, roll up early if you can. You must take:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;The printout from the TÜV that says you passed the test.&lt;/li&gt;&lt;li&gt;Your passport.&lt;/li&gt;&lt;/ul&gt;I didn't bring my passport on my first attempt to pick up the license, so they turned me away. This is despite the fact that they (probably) have a copy of my passport and my photo is actually printed on the license.&lt;br /&gt;&lt;br /&gt;The waiting time won't be as long this time. I arrived at 7AM and there was along queue of people all lining up to get their ticket. The KVR work pretty quickly to process the queue at the door, but joke's on you, you're queueing for a ticket to wait somewhere else. I ended up in Wartezone E where they seemed to be processing people quickly. It was no more than a 20 minute wait.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-7724184559910106485?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/7724184559910106485/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=7724184559910106485' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/7724184559910106485'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/7724184559910106485'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2010/10/how-to-convert-new-zealand-driving.html' title='How to convert a New Zealand driving license to a German one (in Munich).'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/__weDEiUqgTY/TMXdh83NELI/AAAAAAAAACc/rz1nAno1Dvw/s72-c/first+aid+certification+-+smudged.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-3602501115185302299</id><published>2010-09-17T01:49:00.000-07:00</published><updated>2010-09-17T01:49:23.715-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><category scheme='http://www.blogger.com/atom/ns#' term='email'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Configuring exim4 for mail relay with STARTTLS and authentication.</title><content type='html'>How to relay email over an encrypted SMTP connection with authentication using exim4 on Debian.&lt;br /&gt;&lt;br /&gt;The exim documentation leads you to believe that this is a lot simpler that it really is. Following the exim documentation and most websites alone just didn't get me to the final goal. This is possibly due to the fact that the Debian defaults may be different to other distro defaults. I really don't know.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;My&amp;nbsp; Setup&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I run my own mailserver for my own domains. It's reachable via the evil internet (as it has to be). I need to retrieve and &lt;i&gt;send &lt;/i&gt;email from my mail programme, regardless of where in the world I am and without the inconvenience of needing to open a VPN or SSh tunnel to do either.&lt;br /&gt;&lt;br /&gt;Naturally, security is the main concern. Dovecot provides secure imap, but I needed exim to allow me to relay my mail. If you turn on mail relay then it won't take long before the nice people from Nigeria and various other countries will be using your server as their spam hub.&lt;br /&gt;&lt;br /&gt;Relay is the practice of sending mail to a server for which the destination is not one of the server's domains. If relaying on the server is enabled, then the server will dutifully send that email to the correct server. Relay is what I needed, but I was reluctant to share my server bandwidth with spammers.&lt;br /&gt;&lt;br /&gt;On exim, you can enable relay for the specific case where the sender is authenticated. In other words, if I can prove to the server that I am an approved person, then the server will relay my emails. When you connect to the mail server to send your email, you just go through a username/password challenge.&lt;br /&gt;&lt;br /&gt;You don't want to do the authentication over plain text, so encrypting the traffic is key to reducing the likelihood that someone will crack your username and password. That's why I need STARTTLS.&lt;br /&gt;&lt;br /&gt;I'm not going into particular detail as to each setting, these you can look up for youself in the exim documentations. Here's the step-by-step configuration.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Configuration Files&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;After installing exim4 run:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;dpkg exim4-config&lt;/span&gt;&lt;/blockquote&gt;&amp;nbsp;&lt;span style="font-family: inherit;"&gt;The settings that you choose are up to you, but the critical thing is that you want to split the configuration out to smaller files. &lt;i&gt;If you don't choose this option then the rest of this description will not work&lt;/i&gt;.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: inherit;"&gt;Edit /etc/exim4/update-exim4.conf.conf and check that you can see this:&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;dc_use_split_config='true'&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-family: inherit;"&gt;Now add these lines to the end of the file:&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: inherit;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-family: inherit;"&gt;&lt;/span&gt;host_auth_accept_relay=*&lt;br /&gt;auth_over_tls_hosts=*&lt;br /&gt;auth_always_advertise=true&lt;/span&gt;&lt;/span&gt;&lt;/blockquote&gt;&amp;nbsp;Create a file called /etc/exim4/conf.d/main/00_my_macros and add this:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;/span&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;MAIN_TLS_ENABLE = true&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;AUTH_PLAINTEXT=yes&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;AUTH_CRAM_MD5=yes&lt;/span&gt;&lt;/blockquote&gt;Now edit /etc/exim4/conf.d/auth/30_exim4-config_examples and uncomment this section:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-size: x-small;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp;plain_server:&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; driver = plaintext&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; public_name = PLAIN&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; server_condition = "${if crypteq{$auth3}{${extract{1}{:}{${lookup{$auth2}lsearch{CONFDIR/passwd}{$value}{*:*}}}}}{1}{0}}"&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; server_set_id = $auth2&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; server_prompts = :&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; .ifndef AUTH_SERVER_ALLOW_NOTLS_PASSWORDS&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; server_advertise_condition = ${if eq{$tls_cipher}{}{}{*}}&lt;/span&gt;&lt;br style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;" /&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&amp;nbsp; .endif&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Because you've made changes to the split config, you must run the config updater:&lt;br /&gt;&lt;blockquote&gt; &lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;update-exim4.conf&lt;/span&gt;&lt;/blockquote&gt;&lt;b&gt;Certificate&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&amp;nbsp;&lt;/b&gt; &lt;br /&gt;That's the configuration, now generate your own certificate for exim to use in STARTTLS.&lt;br /&gt;&lt;blockquote style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;/usr/share/doc/exim4-base/examples/exim-gencert --force&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;You'll need to answer some questions, you can't get them wrong. It's an untrusted (self signed) certificate. If you want to be really flash and feel rich, buy a certificate!&lt;br /&gt;&lt;br /&gt;The certs will hopefully be dumped into the /etc/exim4/ as exim.crt and exim.key. Debian-exim will need to be able to read this if you don't have an all readable flag. An all-readable flag is a real security problem on your private key.&lt;br /&gt;&lt;blockquote style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;chmod 640 /etc/exim4/exim.*&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-size: x-small;"&gt;chown root.&lt;/span&gt;&lt;span style="font-size: x-small;"&gt;Debian-exim &lt;/span&gt;&lt;span style="font-size: x-small;"&gt;/etc/exim4/exim.*&lt;/span&gt;&lt;/blockquote&gt;&lt;blockquote style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace; font-size: x-small;"&gt;ls -l /etc/exim4/&lt;br /&gt;...&lt;br /&gt;-rw-r----- 1 root Debian-exim&amp;nbsp;&amp;nbsp; 790 Sep 16 14:12 exim.crt&lt;br /&gt;-rw-r----- 1 root Debian-exim&amp;nbsp;&amp;nbsp; 891 Sep 16 14:12 exim.key&lt;/span&gt;&lt;/blockquote&gt;You're all done. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Debug Mode&lt;/b&gt; &lt;br /&gt;&lt;br /&gt;There is an excellent debug mode that you can run exim in. If you have problems, stop exim and start it in debug mode:&lt;br /&gt;&lt;blockquote&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;/etc/init.d/exim4 stop &amp;nbsp;&lt;/div&gt;&lt;span style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;exim -bd -d -oX 25&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family: inherit;"&gt;Of course, when you want to start exim normally, use the "start" option instead of "stop".&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-3602501115185302299?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/3602501115185302299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=3602501115185302299' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3602501115185302299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3602501115185302299'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2010/09/configuring-exim4-for-mail-relay-with.html' title='Configuring exim4 for mail relay with STARTTLS and authentication.'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-4630367688714752888</id><published>2010-06-03T11:48:00.000-07:00</published><updated>2010-06-03T11:50:28.422-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>greylistd tinkering</title><content type='html'>I'm really sold on greylistd. It's dead easy to seamlessly install greylistd into exim with debian.&lt;br /&gt;&lt;br /&gt;Greylisting rejects an unknown sender's email address under the guise of a temporary failure. So it's essentially telling the remote mail server to come back later. It works well because most bulk spammers don't have the time or motivation to go back and retry bouncing email addresses.&lt;br /&gt;&lt;br /&gt;One thing I suspect is that I am missing google alerts because the google mail server isn't coming back to retry delivery. So I'm in the process of adding google's servers to the greylistd whitelist group.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;me@myserver:~$ sudo tail -vf /var/log/exim4/mainlog &lt;/blockquote&gt;&lt;blockquote&gt;2010-06-04 06:28:23 H=mail-pv0-f199.google.com [74.125.83.199] F=&amp;lt;3P_QHTBQKB4crzzrwplwp243-yz2p0w9rzzrwp.nzxxtnslpwxzqql44.z2r.yA@alerts.bounces.google.com&amp;gt; temporarily rejected RCPT &lt;me@myserver.com&gt;: greylisted.&lt;/me@myserver.com&gt;&lt;/blockquote&gt;&lt;br /&gt;&amp;nbsp;So there I can see one of google's mailservers. I'm going to have to check later on for more mail servers I am sure. For now, I have added one here:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;sudo vi /var/lib/greylistd/whitelist-hosts&lt;/blockquote&gt;&lt;blockquote&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 74.125.83.199&amp;nbsp;&amp;nbsp; # Google alerts&lt;/blockquote&gt;&lt;br /&gt;Immediate results:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;2010-06-04 06:33:58 1OKFEs-0000kq-8u &amp;lt;= 3P_QHTBQKB4crzzrwplwp243-yz2p0w9rzzrwp.nzxxtnslpwxzqql44.z2r.yA@alerts.bounces.google.com H=mail-pv0-f199.google.com [74.125.83.199] P=esmtp S=18656 id=0016e6408b12ac7d9d0488245e81@google.com&lt;br /&gt;2010-06-04 06:33:58 1OKFEs-0000kq-8u =&amp;gt; Me &lt;me@myserver.com&gt; R=local_user T=mail_spool&lt;br /&gt;2010-06-04 06:33:58 1OKFEs-0000kq-8u Completed&lt;/me@myserver.com&gt;&lt;/blockquote&gt;&lt;br /&gt;So I'll go back later and check the exim log for other mail servers to add:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;sudo cat /var/log/exim4/mainlog  | grep google&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-4630367688714752888?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/4630367688714752888/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=4630367688714752888' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4630367688714752888'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4630367688714752888'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2010/06/greylistd-tinkering.html' title='greylistd tinkering'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-8795175881066597323</id><published>2010-05-09T15:44:00.000-07:00</published><updated>2010-05-09T15:45:20.174-07:00</updated><title type='text'></title><content type='html'>Selected useful atheist news and articles:&lt;br /&gt;&lt;a href="http://www.atheistvault.com"&gt;http://www.atheistvault.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-8795175881066597323?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/8795175881066597323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=8795175881066597323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8795175881066597323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8795175881066597323'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2010/05/selected-useful-atheist-news-and.html' title=''/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-8774369042364423169</id><published>2010-01-19T12:13:00.000-08:00</published><updated>2010-01-19T13:03:09.220-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>exim4 error after upgrade</title><content type='html'>&lt;span style="font-family:arial;"&gt;After a long overdue upgrade of exim4 and greylistd my local debian mail server would not accept email from hosts on the local network. Oddly, exim4 did accept email from the internet.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Checking the exim logs revealed this message:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;server:/etc/exim4# tail -vf /var/log/exim4/rejectlog&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;br /&gt;2010-01-20 09:02:54 H=eth1 ([0.0.0.0]) [172.16.1.1] U=me F=&lt;/span&gt;&lt;me@medomain.org.nz style="font-family: courier new;"&gt; temporarily rejected RCPT &lt;myfriend@es.co.nz&gt;: unknown ACL verb "acl_whitelist_local_deny" in "acl_whitelist_local_deny"&lt;/myfriend@es.co.nz&gt;&lt;/me@medomain.org.nz&gt;&lt;me@medomain.org.nz&gt;&lt;myfriend@es.co.nz&gt;&lt;/myfriend@es.co.nz&gt;&lt;/me@medomain.org.nz&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;To clarify:&lt;/span&gt;&lt;br /&gt;&lt;ul style="font-family: arial;"&gt;&lt;li&gt;eth1 is the public facing interface (I was delivering mail over an SSh session).&lt;/li&gt;&lt;li&gt;172.16.1.1 is the server's local (non public) IP.&lt;/li&gt;&lt;li&gt;U is the user "me".&lt;/li&gt;&lt;li&gt;F is my email address (the sender).&lt;/li&gt;&lt;li&gt;myfriend@es.co.nz is obviously the person I was emailing (recipient).&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:arial;"&gt;Some web searching turned up this bug report in greylistd:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=452163&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div  style="text-align: left;font-family:arial;"&gt;&lt;blockquote&gt;&lt;span style="font-family:times new roman;"&gt;"acl_whitelist_local_deny was changed to acl_local_deny_exceptions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:times new roman;"&gt;This change needs to be reflected in the greylistd ACL changes."&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;According to this page, the bug was resolved in 2007!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;http://packages.debian.org/changelogs/pool/main/g/greylistd/greylistd_0.8.7+nmu1/changelog&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3  style="font-weight: bold;font-family:arial;" class="entry_header" id="versionversion0.8.6"&gt;  &lt;span style="font-size:100%;"&gt;&lt;a class="packagelink" href="http://packages.debian.org/src:greylistd"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;h3  style="font-weight: normal;font-family:arial;" class="entry_header" id="versionversion0.8.6"&gt;&lt;span style="font-size:100%;"&gt;&lt;a class="packagelink" href="http://packages.debian.org/src:greylistd"&gt;&lt;/a&gt;&lt;/span&gt;&lt;/h3&gt;&lt;blockquote&gt;&lt;h3  style="font-weight: normal;font-family:arial;" class="entry_header" id="versionversion0.8.6"&gt;&lt;span style="font-size:100%;"&gt;&lt;a class="packagelink" href="http://packages.debian.org/src:greylistd"&gt;greylistd&lt;/a&gt;   (0.8.6)  &lt;span class="unstable"&gt;unstable&lt;/span&gt;;  urgency=&lt;span class="low"&gt;low&lt;/span&gt;&lt;/span&gt; &lt;/h3&gt;  &lt;pre  style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;   * Change acl_whitelist_local_deny to acl_local_deny_exceptions&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;   for exim4 &gt;= 4.68 (Closes: &lt;/span&gt;&lt;a style="font-weight: normal;" class="buglink" href="http://bugs.debian.org/452163"&gt;#452163&lt;/a&gt;&lt;span style="font-weight: normal;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;pre  style="font-weight: bold;font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;My version of greylistd should have that bugfix:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote style="font-weight: normal;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;server:/etc/exim4# dpkg -l greylistd&lt;/span&gt;&lt;/span&gt;&lt;snip&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ii  greylistd                 0.8.7+nmu1                Greylisting daemon for use with Exim 4&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;server:/etc/exim4# dpkg -l exim4&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;snip&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:courier new;"&gt;...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:courier new;"&gt;ii  exim4                     4.69-9                    metapackage to ease Exim MTA (v4) installation&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/snip&gt;&lt;/snip&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;So I assume the fix didn't retroactively tidy up existing installs. I even tried:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote  style="font-weight: normal;font-family:courier new;"&gt;&lt;span style="font-size:85%;"&gt;dpkg-reconfigure exim4-config&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;and&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote  style="font-weight: normal;font-family:courier new;"&gt;&lt;span style="font-size:85%;"&gt;greylistd-setup-exim4 remove&lt;br /&gt;greylistd-setup-exim4 add&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;Note that you are supposed to run the greylistd "remove" script before uninstalling greylistd (should you ever want to).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;The solution was to change two files and replace &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: normal;"&gt;acl_whitelist_local_deny with acl_local_deny_exceptions&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote style="font-weight: normal;"&gt;&lt;span style=";font-family:courier new;font-size:85%;"  &gt;server:/etc/exim4# vi /etc/exim4/exim4.conf.template&lt;br /&gt;server:/etc/exim4# vi /etc/exim4/conf.d/acl/30_exim4-config_check_rcpt&lt;/span&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;If you're using vi, simply use this command while editing the each file:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;blockquote  style="font-weight: normal;font-family:courier new;"&gt;&lt;span xi="http://www.w3.org/2001/XInclude" class="example"  style="font-size:85%;"&gt;:%s/&lt;/span&gt;&lt;span style="font-size:85%;"&gt;acl_whitelist_local_deny&lt;/span&gt;&lt;span xi="http://www.w3.org/2001/XInclude" class="example"  style="font-size:85%;"&gt;/&lt;/span&gt;&lt;span style="font-size:85%;"&gt;acl_local_deny_exceptions&lt;/span&gt;&lt;span xi="http://www.w3.org/2001/XInclude" class="example"  style="font-size:85%;"&gt;/g&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;You might want to back up these files first, but do not back them up to the same directory or you will get these errors:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote  style="font-weight: normal;font-family:courier new;"&gt;&lt;span style="font-size:85%;"&gt;zurvan:/etc/exim4# cat /var/log/exim4/paniclog&lt;br /&gt;2010-01-20 09:02:32 Exim configuration error in line 447 of /var/lib/exim4/config.autogenerated.tmp:&lt;br /&gt;there are two ACLs called "acl_check_rcpt"&lt;/span&gt;&lt;/blockquote&gt;&lt;span style="font-weight: normal;"&gt;&lt;br /&gt;So back them up to your home directory or somewhere far far away!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: normal;"&gt;I guess if you did an "apt-get purge exim4" and "apt-get purge greylistd" and then reinstalled them that the config files would come out correctly. However, I have spent a little bit of time getting my exim configurations right, so purging packages (and as a result, the configs) might have caused me even more bother.&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-8774369042364423169?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/8774369042364423169/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=8774369042364423169' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8774369042364423169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8774369042364423169'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2010/01/exim4-error-after-upgrade.html' title='exim4 error after upgrade'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-6618140404231560954</id><published>2008-10-14T12:45:00.000-07:00</published><updated>2008-10-14T13:12:18.977-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Windows'/><title type='text'>Microsoft finally admits it</title><content type='html'>"On-ya Windows" as a co-worker of mine would say.  Finally, Microsoft admit that Windoze itself is a pernicious virus infecting a computer near you:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/__weDEiUqgTY/SPT3R93SMtI/AAAAAAAAAAs/ljehKJ8MH7M/s1600-h/data_executed.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/__weDEiUqgTY/SPT3R93SMtI/AAAAAAAAAAs/ljehKJ8MH7M/s320/data_executed.jpg" alt="" id="BLOGGER_PHOTO_ID_5257098553084490450" border="0" /&gt;&lt;/a&gt;It's well known that Microsoft has been executing data at a genocidal level for years.  Will this new dialogue box get The Hague off Microsoft's back?&lt;br /&gt;&lt;br /&gt;Yes, this really is a screenshot, it's not a mockup.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-6618140404231560954?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/6618140404231560954/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=6618140404231560954' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6618140404231560954'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6618140404231560954'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/10/microsoft-finally-admits-it.html' title='Microsoft finally admits it'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/__weDEiUqgTY/SPT3R93SMtI/AAAAAAAAAAs/ljehKJ8MH7M/s72-c/data_executed.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-4515636828524535059</id><published>2008-10-05T14:32:00.001-07:00</published><updated>2008-10-05T14:35:28.881-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='politics'/><title type='text'>More billboards, more slogans, fewer sense.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/__weDEiUqgTY/SOkyiQaB5GI/AAAAAAAAAAk/47oE81COV7E/s1600-h/billboard1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/__weDEiUqgTY/SOkyiQaB5GI/AAAAAAAAAAk/47oE81COV7E/s320/billboard1.jpg" alt="" id="BLOGGER_PHOTO_ID_5253786004405478498" border="0" /&gt;&lt;/a&gt;&lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-NZ"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt; This is what happens when you let Microsoft do the checking.  I wonder if National intends to balance the current account with Excel.&lt;br /&gt;&lt;br /&gt;So, are they intending to put a height restriction on new recruits or put all the existing bureaucrats on a diet?&lt;br /&gt;&lt;br /&gt;If there really is 19 football fields worth of bureaucrats in Wellington alone, as a politician I would tend to put the subject of lessening them aside.&lt;br /&gt;&lt;br /&gt;Yep, it’s election time.  More billboards, more slogans, fewer sense.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-4515636828524535059?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/4515636828524535059/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=4515636828524535059' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4515636828524535059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4515636828524535059'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/10/more-billboards-more-slogans-fewer.html' title='More billboards, more slogans, fewer sense.'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/__weDEiUqgTY/SOkyiQaB5GI/AAAAAAAAAAk/47oE81COV7E/s72-c/billboard1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-1212630294239887806</id><published>2008-07-21T18:11:00.000-07:00</published><updated>2008-07-21T18:24:55.222-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='religion'/><title type='text'>Borders on Outrageous</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/__weDEiUqgTY/SIU2linUrfI/AAAAAAAAAAc/90uY7pdk8B0/s1600-h/DSC00006.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://bp1.blogger.com/__weDEiUqgTY/SIU2linUrfI/AAAAAAAAAAc/90uY7pdk8B0/s320/DSC00006.JPG" alt="" id="BLOGGER_PHOTO_ID_5225642961208126962" border="0" /&gt;&lt;/a&gt;It doesn't get any worse than this.  Ian Wishart's "Divinity Code" in the Borders (Riccarton) biochemistry section.  Yep there it is, sandwiched between Robert Winston &lt;span style="font-style: italic;"&gt;Human Instinct&lt;/span&gt; and Carl Zimmer &lt;span style="font-style: italic;"&gt;Smithsonian Intimate Guide to Human Origins.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;The optimist in me wants to believe that the book ended up here because the "Mysticism and Wackos" section has has been canned and the Border's staff have just randomly scattered the whole section throughout the store.&lt;br /&gt;&lt;br /&gt;I've been keeping an eye on this title for the last while, expecting Borders to dump it in the discounts section sometime soon; secretly expecting that Borders will open a new "free" bin just for it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-1212630294239887806?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/1212630294239887806/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=1212630294239887806' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/1212630294239887806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/1212630294239887806'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/07/borders-on-outrageous.html' title='Borders on Outrageous'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/__weDEiUqgTY/SIU2linUrfI/AAAAAAAAAAc/90uY7pdk8B0/s72-c/DSC00006.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-8361430590811082048</id><published>2008-07-21T14:26:00.000-07:00</published><updated>2008-07-21T18:11:05.307-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='religion'/><title type='text'>Old Habits Die Hard</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/__weDEiUqgTY/SIUMZcCWXiI/AAAAAAAAAAM/j8RTEO36IUQ/s1600-h/mmm_brains.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://bp2.blogger.com/__weDEiUqgTY/SIUMZcCWXiI/AAAAAAAAAAM/j8RTEO36IUQ/s320/mmm_brains.jpg" alt="" id="BLOGGER_PHOTO_ID_5225596573795638818" border="0" /&gt;&lt;/a&gt;Pope Benedict XVI arrived in Australia and was immediately criticised after again eating a child at an outdoor rally.&lt;br /&gt;&lt;br /&gt;The Pope was unavailable for comment however Cardinal Anon said that while the consumption was unscheduled it should be celebrated in the wider context of a very successful trip.  "The Church has always had a special relationship with children, this form of impromptu transmogriphication, although rarely employed today, is found right throughout the rich history of the Catholic tradition."&lt;br /&gt;&lt;br /&gt;Police said that the suspected atheist (pictured above) who tried at the time to pull the child away from the Pope was arrested under Australia's tough new anti-terrorism laws and beaten to death.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/__weDEiUqgTY/SIUMkVZPXyI/AAAAAAAAAAU/BNTSOdg1MWw/s1600-h/pope_in_spain.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/__weDEiUqgTY/SIUMkVZPXyI/AAAAAAAAAAU/BNTSOdg1MWw/s320/pope_in_spain.gif" alt="" id="BLOGGER_PHOTO_ID_5225596760991162146" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-style: italic;"&gt;Above: An artist's depiction of Pope Benedict XVI's recent visit to Spain.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-8361430590811082048?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/8361430590811082048/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=8361430590811082048' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8361430590811082048'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/8361430590811082048'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/07/old-habits-die-hard.html' title='Old Habits Die Hard'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/__weDEiUqgTY/SIUMZcCWXiI/AAAAAAAAAAM/j8RTEO36IUQ/s72-c/mmm_brains.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-3738513577429997365</id><published>2008-06-06T21:31:00.000-07:00</published><updated>2010-01-19T13:03:31.745-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>chkrootkit: INFECTED (PORTS:  1008)</title><content type='html'>chkrootkit kept freaking me out with this daily email (debian etch system):&lt;br /&gt;&lt;br /&gt;/etc/cron.daily/chkrootkit:&lt;br /&gt;INFECTED (PORTS:  1008)&lt;br /&gt;eth0: PACKET SNIFFER(/usr/sbin/dhcpd[9876])&lt;br /&gt;&lt;br /&gt;The DHCP message is fine, I have a DHCP server running.&lt;br /&gt;&lt;br /&gt;Port 1008 is known to be used by a trojan or worm or some such.  So to find out what was listening on port 1008 I did this:&lt;br /&gt;&lt;br /&gt;server:/root# lsof -n | grep 1008&lt;br /&gt;rpc.statd  2104       statd    6u     IPv4       6556                 UDP *:1008&lt;br /&gt;&lt;br /&gt;(actually a tidier command would have been "lsof -i :1008").&lt;br /&gt;&lt;br /&gt;OK, so rpc.statd seems less of a worry.  From the rpc.statd man page:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;It is used by the NFS file locking service, rpc.lockd, to implement lock recovery when the NFS server machine crashes and reboots.&lt;br /&gt;...&lt;br /&gt;By default, rpc.statd will ask portmap(8) to assign it a port number. As of this writing, there is not a standard port number that portmap always or usually assigns. Specifying a port may be useful when implementing a firewall.&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;OK, so quick and dirty fix time:&lt;br /&gt;&lt;br /&gt;server:/root# /etc/init.d/nfs-common restart&lt;br /&gt;Stopping NFS common utilities: idmapd statd.&lt;br /&gt;Starting NFS common utilities: statd idmapd.&lt;br /&gt;server:/root# lsof -n :1008&lt;br /&gt;zurvan:/root#&lt;br /&gt;&lt;br /&gt;Yay!  If I was a pro, I'd specify the rpc.statd port with -p.  So next reboot, I might get another chkrootkit error on another known and troublesome port.  chkrootkit is a bit annoying for all these false positives.  But I'd rather work them out than not run it at all.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-3738513577429997365?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/3738513577429997365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=3738513577429997365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3738513577429997365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3738513577429997365'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/06/chkrootkit-kept-freaking-me-out-with.html' title='chkrootkit: INFECTED (PORTS:  1008)'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-4222824441184466430</id><published>2008-01-01T17:09:00.000-08:00</published><updated>2010-01-19T13:03:49.179-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>Generate a dovecot ssl certificate (10 year &amp; self signed)</title><content type='html'>Here's how to generate an ssl cert for dovecot that has a 10 year expiry (instead of the default 365 day). If the certificates are already there then you must do this:&lt;br /&gt;&lt;br /&gt;debianbox:/etc/ssl/certs# mv /etc/ssl/private/dovecot.pem /etc/ssl/private/dovecot.pem.old&lt;br /&gt;&lt;br /&gt;debianbox:/etc/ssl/certs# mv /etc/ssl/certs/dovecot.pem /etc/ssl/certs/dovecot.pem.old&lt;br /&gt;&lt;br /&gt;debianbox:/etc/ssl/certs# vi /var/lib/dpkg/info/dovecot-common.postinst           &lt;br /&gt;---&lt;br /&gt;# Change this line:&lt;br /&gt;   (openssl req -new -x509 -days 365 -nodes -out $SSL_CERT -keyout $SSL_KEY &gt; /dev/null 2&gt;&amp;amp;1 &lt;&lt;+ # To be this:     (openssl req -new -x509 -days 3650 -nodes -out $SSL_CERT -keyout $SSL_KEY &gt; /dev/null 2&gt;&amp;amp;1 &lt;&lt;+&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;debianbox:/etc/ssl/certs# dpkg-reconfigure dovecot-common&lt;br /&gt;Stopping mail server: dovecot .&lt;br /&gt;Creating generic self-signed certificate:  /etc/ssl/certs/dovecot.pem&lt;br /&gt;(replace with hand-crafted or authorized one if needed).&lt;br /&gt;Starting mail server: dovecot.&lt;br /&gt;&lt;br /&gt;... and that's it.&lt;br /&gt;&lt;br /&gt;As an aside: In the server's /etc/hosts file, make sure that the local IP interface address(es) to name mappings are formatted consistently.  The postinstall script uses `hostname -f` to determine the FQDN.  The script will then use the result as the name of the server for which the certificate applies.  If your client connects (internally) to the server with debianbox.test.co.nz and the server's /etc/hosts file reads like this...&lt;br /&gt;&lt;br /&gt;192.168.0.254  debianbox debianbox.test.co.nz&lt;br /&gt;203.10.10.10   www www.test.co.nz&lt;br /&gt;&lt;br /&gt;... then the cert will have been issued for the server "debianbox" but your client will complain that it was actually trying to talk to debianbox.test.co.nz.  Just change the /etc/hosts file to read as so...&lt;br /&gt;&lt;br /&gt;192.168.0.254  debianbox.test.co.nz debianbox&lt;br /&gt;203.10.10.10   www.test.co.nz www&lt;br /&gt;&lt;br /&gt;... and then rerun the postinst script as above.&lt;br /&gt;&lt;br /&gt;I don't connect to my imap server outside of the local network (192.168.0.0/24) so in actual fact the second line, a public IP address, is irrelevant in this example.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-4222824441184466430?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/4222824441184466430/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=4222824441184466430' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4222824441184466430'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4222824441184466430'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/01/generate-dovecot-ssl-certificate-10.html' title='Generate a dovecot ssl certificate (10 year &amp; self signed)'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-4484685506681705361</id><published>2008-01-01T16:31:00.000-08:00</published><updated>2010-01-19T13:04:05.586-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>Create apache2 ssl certificate (self signed)</title><content type='html'>At the time of writing this you couldn't edit "/usr/share/ssl-cert/ssleay.cnf", to change the day expiry time. make-ssl-cert generates 30 day certs.  So I edited the make-ssl-cert script, which is dead easy to do:&lt;br /&gt;&lt;br /&gt;I changed the default days to 10 years because having to renew the cert every 30 is quite annoying.&lt;br /&gt;&lt;br /&gt;debianbox:/etc/apache2/ssl# vi /usr/share/ssl-cert/ssleay.cnf&lt;br /&gt;---&lt;br /&gt;# Change this:&lt;br /&gt;   openssl req -config $TMPFILE -new -x509 -nodes -out $output -keyout $output &gt; /dev/null 2&gt;&amp;amp;1&lt;br /&gt;# To be this:&lt;br /&gt;   openssl req -config $TMPFILE -new -x509 -nodes -out $output -keyout $output -days 3650 &gt; /dev/null 2&gt;&amp;amp;1&lt;br /&gt;---&lt;br /&gt;&lt;br /&gt;debianbox:/etc/apache2/ssl# mv apache.pem apache.pem.old&lt;br /&gt;&lt;br /&gt;debianbox:/etc/apache2/ssl# make-ssl-cert /usr/share/ssl-cert/ssleay.cnf apache.pem&lt;br /&gt;[ answer the questions ]&lt;br /&gt;&lt;br /&gt;debianbox:/etc/apache2/ssl# ls -l&lt;br /&gt;total 8&lt;br /&gt;lrwxrwxrwx 1 root root   10 2008-01-02 13:40 32f1a9d7 -&gt; apache.pem&lt;br /&gt;-rw------- 1 root root 1860 2008-01-02 13:40 apache.pem&lt;br /&gt;-rw------- 1 root root 1860 2007-10-07 21:57 apache.pem.old&lt;br /&gt;&lt;br /&gt;Reload apache2 before so that the new certificate is issued to connecting hosts.&lt;br /&gt;&lt;br /&gt;debianbox:/etc/apache2/ssl# /etc/init.d/apache2 --help&lt;br /&gt;Usage: /etc/init.d/apache2 {start|stop|restart|reload|force-reload}&lt;br /&gt;debianbox:/etc/apache2/ssl# /etc/init.d/apache2 reload&lt;br /&gt;Reloading web server config...27817&lt;br /&gt;&lt;br /&gt;Visit the website with a browser and examine the certificate.  Expect a warning about the site's validity because the certificate is self signed.  Examine the issued certificate and check the expiry time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-4484685506681705361?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/4484685506681705361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=4484685506681705361' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4484685506681705361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/4484685506681705361'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2008/01/create-apache2-ssl-certificate-self.html' title='Create apache2 ssl certificate (self signed)'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-6714786948324829161</id><published>2007-07-31T18:49:00.000-07:00</published><updated>2007-08-20T14:10:10.499-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tea'/><title type='text'>Puttabong Clonal Exclusive (2007)</title><content type='html'>Darjeeling 1st flush.&lt;br /&gt;&lt;br /&gt;Apparently this tea estate is getting &lt;a href="http://en.wikipedia.org/wiki/ISO_9000"&gt;ISO 9002 (9001)&lt;/a&gt; certification.  I can't see the point in that.&lt;br /&gt;&lt;br /&gt;Recommended preparation:&lt;br /&gt;   3tsp / 500ml&lt;br /&gt;   85-95 deg C.&lt;br /&gt;   3.5-4.0 mins&lt;br /&gt;&lt;br /&gt;What I did:&lt;br /&gt;   3tsp / small cup (easy pot)&lt;br /&gt;    85-95 deg C.&lt;br /&gt;   10-&gt;15 secs / 2 mins / 2 mins / 4 mins&lt;br /&gt;&lt;br /&gt;I experimented by giving these leaves approximately 15 seconds on the first steeping.  The flavour was completely different to my limited darjeeling experiences and seemed a very grassy flavour, delicious.  I know - grass doesn't sound appealing!  The second steep was for 2 minutes and the beautiful and rich buttery flavour appeared.  The sweetness of the flavour was a great counterpoint to the mild astringency.&lt;br /&gt;&lt;br /&gt;The third steeping was noticeably less buttery!  I think it's important not to let the water get too cold.  Future experiments left me thinking that this method is the tastiest way to extract the flavour from this tea.  I adore the first 10 second steeping.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-6714786948324829161?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/6714786948324829161/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=6714786948324829161' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6714786948324829161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/6714786948324829161'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2007/07/puttabong-clonal-exclusive-2007.html' title='Puttabong Clonal Exclusive (2007)'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-1959219988946787429</id><published>2007-01-09T14:39:00.000-08:00</published><updated>2007-01-09T14:46:23.120-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tea'/><title type='text'>Milk wrecks the health benefits of tea</title><content type='html'>&lt;a href="http://www.newscientist.com/home.ns"&gt;New Scientist&lt;/a&gt; is &lt;a href="http://www.newscientist.com/channel/health/dn10913-milk-wrecks-the-health-benefits-of-tea.html"&gt;reporting&lt;/a&gt; the results of a German survey that points to milk negating the health benefits of tea. Interesting mention of NOS in the form of an enzyme.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-1959219988946787429?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/1959219988946787429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=1959219988946787429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/1959219988946787429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/1959219988946787429'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2007/01/milk-wrecks-health-benefits-of-tea.html' title='Milk wrecks the health benefits of tea'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8671583514969607875.post-3330905970494553755</id><published>2007-01-09T11:19:00.000-08:00</published><updated>2007-07-30T15:19:47.858-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tea'/><title type='text'>Sun-Moon Lake, Wild Mountain, Formosa (Taiwan)</title><content type='html'>This is the tea that I drank a lot of at work because it is easy to prepare.  I like it for two reasons.&lt;br /&gt;&lt;ol&gt;&lt;li&gt;The flavour!&lt;br /&gt;&lt;/li&gt;&lt;li&gt;If you oversteep it, the flavour isn't destroyed. That can happen at work because I get so distracted, so often I put in fewer leaves.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;Leaves: 4.5 tsp&lt;br /&gt;Steep: 4-5 mins&lt;br /&gt;Water: 0.5l&lt;br /&gt;Temp: 100C&lt;br /&gt;Bought From: &lt;a href="http://www.yayateahouse.co.nz/"&gt;Ya-Ya Tea House&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8671583514969607875-3330905970494553755?l=deuterblogomy.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://deuterblogomy.blogspot.com/feeds/3330905970494553755/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8671583514969607875&amp;postID=3330905970494553755' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3330905970494553755'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8671583514969607875/posts/default/3330905970494553755'/><link rel='alternate' type='text/html' href='http://deuterblogomy.blogspot.com/2007/01/sun-moon-lake-wild-mountain-formosa.html' title='Sun-Moon Lake, Wild Mountain, Formosa (Taiwan)'/><author><name>deus ex machina</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://3.bp.blogspot.com/__weDEiUqgTY/SPT7HK8ceLI/AAAAAAAAAA4/NVgwdNMnPz8/S220/DSC02746_2.JPG'/></author><thr:total>0</thr:total></entry></feed>
