So the issue was this nginx block, which deny access to .well-known like anything else starting with a dot:
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
May 5 2016
Apr 20 2016
$ letsencrypt renew [...] ------------------------------------------------------------------------------- Processing /usr/local/etc/letsencrypt/renewal/www.espace-win.org.conf ------------------------------------------------------------------------------- 2016-04-20 22:10:33,464:WARNING:letsencrypt.renewal:Attempting to renew cert from /usr/local/etc/letsencrypt/renewal/www.espace-win.org.conf produced an unexpected error: Failed authorization procedure. dropbox.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://dropbox.espace-win.org/.well-known/acme-challenge/AFcGawsTLFqpJwWWZDmMh4LHjMVRkIbAfbq13_6qM40 [212.83.187.132]: 403, files.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://files.espace-win.org/.well-known/acme-challenge/43QDyWupIPxeAlNMyXgvDezCIMf-6kGxvAn2SzBIrak [212.83.187.132]: 403, forum.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://forum.espace-win.org/.well-known/acme-challenge/rHPn1p3iNsjXBzgAC0Hk-npvdCRF1qmJTrohgFkmugM [212.83.187.132]: 403, espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://espace-win.org/.well-known/acme-challenge/o_7sf9acLUEuHzVQNOHBcHvTG73l7xlP8mMX6nhx22c [212.83.187.132]: 403, pastebin.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://pastebin.espace-win.org/.well-known/acme-challenge/QCzu4WhOSjhRPzH6BvjMgAn2tggV1qbBW0q9tdyYACs [212.83.187.132]: 403, assets.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://assets.espace-win.org/.well-known/acme-challenge/LU-KuSB2bzPYmxw2vACtLu6yZj8ygXkAZiPxwHOMcHE [212.83.187.132]: 403, excel.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://excel.espace-win.org/.well-known/acme-challenge/5iaG0F-_T5a2TKlFWDxTqvBxg6GD50B_YfY5sxolNQ0 [212.83.187.132]: 403, www.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://www.espace-win.org/.well-known/acme-challenge/Pw6LYupam92EIy330xYlAuHuKvNKpp6unoVU8UAOrmw [212.83.187.132]: 403, gd.espace-win.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://gd.espace-win.org/.well-known/acme-challenge/SP1gRHzjZR39Ai9lZXQvEsTi9i7f0dYSL2bbR_bPOY4 [212.83.187.132]: 403. Skipping.
Apr 2 2016
This works:
Apr 1 2016
Hmmm, we need to recompile another OpenSSH server to be able to change the PAM service name
New users are puzzled by the prompt.
Mar 28 2016
Mar 13 2016
Mar 10 2016
After a conversation on #wolfplex, debating about the domain name to use, we endly concluded that Eglide will be a standalone project, nonetheless supported by Nasqueron.
Therefore, the domain name reserved for this project is eglide.org.
Mar 7 2016
@xcombelle confirmed on #wikipedia-fr the code is safe as far as security is concerned.
Fixed issue reported by Scoopfinder.
Regression This commit introduces the following issue when the page IS NOT downloaded through this new method:
Feb 29 2016
+Page::encodeData
Feb 26 2016
The packages have been upgraded for the following containers:
Feb 21 2016
Fixed, silgraphite2 through ports, the others through binary packages.
Feb 20 2016
Feb 17 2016
Feb 12 2016
Could be related to Capsicum — https://lists.cam.ac.uk/pipermail/cl-capsicum-discuss/2014-December/msg00004.html
Feb 2 2016
Jan 23 2016
Dwellers is already in the whitelist.
Jan 22 2016
Actually, the application itself creates a security risk with a default valid key. That will be SomeRandomString.
SomeRandomString actually won't work.
Jan 20 2016
I've generated a SSL certificate valid for all the remaining domains hosted by Dwellers.
Added domains from Dwellers /etc/nginx.conf.
Jan 19 2016
I've generated and deployed a temporary mega certificate:
Jan 18 2016
Jan 17 2016
Done for nasqueron/nginx-php-fpm per D245 (and so Phabricator).
Ysul OpenSSH_6.6.1p1, OpenSSL 1.0.1l-freebsd 15 Jan 2015
Dwellers OpenSSH_6.6.1p1, OpenSSL 1.0.1e-fips 11 Feb 2013
Jan 14 2016
Lowered the priority as we've mitigated at places where there are ssh outgoing connections.
Done for Ysul, Dwellers, the containers for DevCentral and phabricator.wolfplex.be.
Jan 12 2016
Jan 7 2016
The Let's encrypt container is usable as is.
Jan 5 2016
Deleted jail
The 2016-01-05 series works.
Create the jail
Hostname: setstyin.nasqueron.org
IP: 2001:470:1f12:9e1::3