This tag identifies security issue.
Details
Details
Description
Wed, Sep 10
Wed, Sep 10
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTPS certificate automatically to Renew Vault web server certificate automatically.
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTP certificate automatically to Renew Vault HTTPS certificate automatically.
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault certificate to Renew Vault HTTP certificate automatically.
dereckson added a comment to T2112: Renew Vault web server certificate automatically.
First step is to create a script to renew all needed certificates:
May 18 2025
May 18 2025
Apr 5 2025
Apr 5 2025
dereckson added a comment to T2107: j'aimerais avoir une présence permanente sur internet.
Une fois que tu as retrouvé les accès SSH pour le web statique:
- WindRiver: automatiquement https://windriver.nasqueron.org/~xcombelle est disponible si tu places des fichiers dans /var/home-wwwroot/xcombelle (je ne sais plus si ça se crée automatiquement avec symlink vers $HOME/public_html, à vérifier)
- Eglide: https://www.eglide.org/~xcombelle pour $HOME/public_html
dereckson added projects to T2107: j'aimerais avoir une présence permanente sur internet: security, Eglide.
Nov 2 2024
Nov 2 2024
Oct 27 2024
Oct 27 2024
dereckson moved T2075: Generate SSH keys for backup purpose from Backlog to Backup infrastructure on the Backups board.
dereckson moved T2075: Generate SSH keys for backup purpose from Servers config to Require Salt dev on the Salt board.
dereckson moved T2075: Generate SSH keys for backup purpose from Backlog to Servers config on the Salt board.
Oct 23 2024
Oct 23 2024
Oct 13 2024
Oct 13 2024
dereckson moved T1861: Configure static IPv6 on WindRiver from Backlog to Knowledge sharing is needed on the IPv6 board.
dereckson added a comment to T1861: Configure static IPv6 on WindRiver.
So, to get routing back:
Oct 12 2024
Oct 12 2024
Not sure of the current benefit to use TC2.
dereckson moved T1486: Evaluate Archery from Backlog to Not for this sprint on the Operations sprints (Move the ambiant lights) board.
dereckson added a comment to T1602: Provision ACME DNS credentials for core domains on each servers.
This is still needed for acme.sh if we want to provision different *.nasqueron.org certificates on different servers.
Oct 9 2024
Oct 9 2024
dereckson lowered the priority of T2051: Can't renew TLS certificates verified through HTTP on docker engines from High to Normal.
dereckson updated the task description for T2051: Can't renew TLS certificates verified through HTTP on docker engines.
dereckson added a comment to T2051: Can't renew TLS certificates verified through HTTP on docker engines.
Salt SELinux module issue
dereckson updated the task description for T2051: Can't renew TLS certificates verified through HTTP on docker engines.
dereckson moved T2051: Can't renew TLS certificates verified through HTTP on docker engines from Backlog to Pending review on the Servers board.
dereckson moved T2051: Can't renew TLS certificates verified through HTTP on docker engines from Backlog to Working on on the Nasqueron Docker deployment squad board.
SELinux context was the default for anything created under /var, which we didn't allow and aren't interested to allow for nginx.
dereckson triaged T2051: Can't renew TLS certificates verified through HTTP on docker engines as High priority.
Oct 3 2024
Oct 3 2024
dereckson added a comment to T2040: Supersede Vault by OpenBao.
Yes, it's a fork from Vault 1.14 so we've all the features of token generation. back to the shorter s. tokens).
DorianWinty added a comment to T2040: Supersede Vault by OpenBao.
- about the UI it could be usefull managing secrets more easyly
dereckson moved T2040: Supersede Vault by OpenBao from Backlog to Analysis / under discussion on the Servers board.
Sep 12 2024
Sep 12 2024
dereckson shifted T1996: Servers on hyper-001 have network issues from the Restricted Space space to the S1 Nasqueron space.
Can't repro
dereckson added a revision to T930: Secrets to migrate from DevCentral to Vault: D3441: Prune Zemke-Rhyne.
Sep 8 2024
Sep 8 2024
Sandlayth closed T2013: Add new public ssh-key belonging to user sandlayth as Resolved by committing rOPS257aa8d9e00c: Add new public ssh-key belonging to user sandlayth.
Sep 5 2024
Sep 5 2024
Aug 17 2024
Aug 17 2024
Mumble isn't currently in scope.
dereckson closed T853: Deploy a Let's encrypt certificate to the Mumble server, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Wontfix.
Aug 4 2024
Aug 4 2024
Both are already set in DNS:
dereckson added a comment to T1928: Serve CAA DNS records.
We use a wildcard certificate, so issuewild is needed, yes.