First step is to create a script to renew all needed certificates:
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Wed, Sep 10
May 18 2025
Apr 5 2025
Une fois que tu as retrouvé les accès SSH pour le web statique:
- WindRiver: automatiquement https://windriver.nasqueron.org/~xcombelle est disponible si tu places des fichiers dans /var/home-wwwroot/xcombelle (je ne sais plus si ça se crée automatiquement avec symlink vers $HOME/public_html, à vérifier)
- Eglide: https://www.eglide.org/~xcombelle pour $HOME/public_html
Nov 2 2024
Oct 27 2024
Oct 23 2024
Oct 13 2024
So, to get routing back:
Oct 12 2024
Not sure of the current benefit to use TC2.
This is still needed for acme.sh if we want to provision different *.nasqueron.org certificates on different servers.
Oct 9 2024
Salt SELinux module issue
SELinux context was the default for anything created under /var, which we didn't allow and aren't interested to allow for nginx.
Oct 3 2024
Yes, it's a fork from Vault 1.14 so we've all the features of token generation. back to the shorter s. tokens).
- about the UI it could be usefull managing secrets more easyly
Sep 12 2024
Can't repro
Sep 8 2024
Sep 5 2024
Aug 17 2024
Mumble isn't currently in scope.
Aug 4 2024
Both are already set in DNS:
We use a wildcard certificate, so issuewild is needed, yes.
@Ash-Crow @fauve @rama @replicatorbe @Sandlayth @xcombelle Any feedback on this?
Aug 3 2024
From router-001 network looks good:
Stopped currently not needed salt and node-exporter on router-001 to see if that helps.
Could be at hypervisor level. SSH failed until 13:22 where it worked immediately.
Jul 23 2024
It could be easier to deploy https://github.com/kpetremann/salt-exporter
Jul 10 2024
Key confirmed to work.
Jul 9 2024
Still some issue to connect, SSH2 RSA key not recognized.
Jul 5 2024
Feb 17 2024
$ /usr/local/etc/rc.d/sshd-otp restart Performing sanity check on sshd_otp configuration. Stopping sshd_otp. Waiting for PIDS: 1331. Performing sanity check on sshd_otp configuration. Starting sshd_otp.
Jan 28 2024
Secrets have been migrated from dot notation to slash notation.
Jan 15 2024
Alcali is still alive.
Jan 8 2024
Jan 7 2024
Jan 5 2024
FreeBSD integrates OpenSSH to the base OS.
cloudhugger:
OpenSSH_8.4p1 Debian-5+deb11u3, OpenSSL 1.1.1w 11 Sep 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
dwellers:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
docker-002:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
hervil:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
complector:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-A-001:
OpenSSH_9.3p2, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-B-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
web-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
router-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
ysul:
Minion did not return. [Not connected]
thrayce:
Minion did not return. [Not connected]
Dec 17 2023
Situation has evolved since 2017, we currently configure nginx with TLSv1.2 + TLSv1.3,
per Mozilla intermediate configuration https://ssl-config.mozilla.org/
Jun 16 2023
Jun 11 2023
Worked before (dhclient + routes), but on boot:
- we've a correct fe80 address
- no dhclient, but /usr/local/etc/rc.d/dhclient6 start does NOT complain dhclient6_enable="YES" is missing
- when dhclient is started, our correct prefix is returned
- no static IP assignment in current state (missing from /etc/netif/igb0_ipv6)
- we can add manually IP in our prefix
- routing is missing and can't be easily figured (the expectation was dhclient would take care of that)
Jun 7 2023
Jun 3 2023
Taking it as we've issues with the /128 one and I'd prefer to fix the /56 config than the /128 one.
May 29 2023
Server log