$ /usr/local/etc/rc.d/sshd-otp restart Performing sanity check on sshd_otp configuration. Stopping sshd_otp. Waiting for PIDS: 1331. Performing sanity check on sshd_otp configuration. Starting sshd_otp.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Feb 17 2024
Jan 28 2024
Secrets have been migrated from dot notation to slash notation.
Jan 15 2024
Alcali is still alive.
Jan 8 2024
Jan 7 2024
Jan 5 2024
FreeBSD integrates OpenSSH to the base OS.
cloudhugger:
OpenSSH_8.4p1 Debian-5+deb11u3, OpenSSL 1.1.1w 11 Sep 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
dwellers:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
docker-002:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
hervil:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
complector:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-A-001:
OpenSSH_9.3p2, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-B-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
web-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
router-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
ysul:
Minion did not return. [Not connected]
thrayce:
Minion did not return. [Not connected]
Dec 17 2023
Situation has evolved since 2017, we currently configure nginx with TLSv1.2 + TLSv1.3,
per Mozilla intermediate configuration https://ssl-config.mozilla.org/
Jun 16 2023
Jun 11 2023
Worked before (dhclient + routes), but on boot:
- we've a correct fe80 address
- no dhclient, but /usr/local/etc/rc.d/dhclient6 start does NOT complain dhclient6_enable="YES" is missing
- when dhclient is started, our correct prefix is returned
- no static IP assignment in current state (missing from /etc/netif/igb0_ipv6)
- we can add manually IP in our prefix
- routing is missing and can't be easily figured (the expectation was dhclient would take care of that)
Jun 7 2023
Jun 3 2023
Taking it as we've issues with the /128 one and I'd prefer to fix the /56 config than the /128 one.
May 29 2023
Server log
May 25 2023
May 20 2023
Documentation available at https://devcentral.nasqueron.org/w/setup_2fa/
2FA enabled
As a minimum, to have somewhere (a reports repository?) where we can write those report queries could already be useful, so we don't lose them.
May 19 2023
May 18 2023
Server is live and stable.
Subtask removed to simplify the graph. It's the task where db-B-001 has been created and so solved this one.
Resolved by db-B-001 deployment: MySQL server doesn't have a public IP anymore
In T1627#23666, @dereckson wrote:Perhaps replace references here too: https://code.nasqueron.org/?q=equatower&i=nope&literal=nope&files=&excludeFiles=&repos=
May 15 2023
Password truncation
Passwords are explicitly truncated to 25 characters in load_helpers functions:
May 13 2023
DUID published in Vault under ops/secrets/network/DUID/2001:bc8:2e84:700::
2001:bc8:2e84:700:: /56 should be used for WindRiver addresses.
Autoconfig IP isn't in our block
May 6 2023
Apr 13 2023
Apr 12 2023
Apr 2 2023
Mar 28 2023
Mar 24 2023
Not present in recent FreeBSD machines, so I guess it was solved during an OS upgrade.
Mar 7 2023
All secrets are now stored in Vault and provisioned through Salt, with policies restricting access to secrets by node.
And with the Zemke-Rhyne decom, we're done.
Mar 4 2023
Mar 3 2023
Those issues are resolved now we use Vault to provision passwords.