Page MenuHomeDevCentral
Feed Advanced Search

Jan 23 2016

dereckson added a project to T693: Add dwellers.nasqueron.org to Ysul sshguard whitelist: security.
Jan 23 2016, 03:13 · security, Nasqueron Docker deployment squad, Servers, Restricted Project
dereckson closed T690: Ensure APP_KEY is properly defined as Resolved by committing rDNOTIF73d49d978c97: Ensure APP_KEY is defined.
Jan 23 2016, 00:24 · Notifications center, Docker images, security

Jan 22 2016

dereckson added a revision to T690: Ensure APP_KEY is properly defined: D258: Ensure APP_KEY is defined.
Jan 22 2016, 05:09 · Notifications center, Docker images, security
dereckson updated the task description for T690: Ensure APP_KEY is properly defined.
Jan 22 2016, 05:05 · Notifications center, Docker images, security
dereckson closed T691: Revert APP_KEY to a dummy non 32 character value, a subtask of T690: Ensure APP_KEY is properly defined, as Resolved.
Jan 22 2016, 05:03 · Notifications center, Docker images, security
dereckson closed T691: Revert APP_KEY to a dummy non 32 character value as Resolved.
Jan 22 2016, 05:03 · Notifications center, security
dereckson added revisions to T691: Revert APP_KEY to a dummy non 32 character value: D253: Revert "Set correct default app.key configuration setting", D254: Sync .env.example with .env for APP_KEY, D255: Allow phpunit tests to run without .env file.
Jan 22 2016, 05:01 · Notifications center, security
dereckson created T691: Revert APP_KEY to a dummy non 32 character value.
Jan 22 2016, 04:07 · Notifications center, security
dereckson added a comment to T690: Ensure APP_KEY is properly defined.

Actually, the application itself creates a security risk with a default valid key. That will be SomeRandomString.

Jan 22 2016, 04:02 · Notifications center, Docker images, security
dereckson updated the task description for T690: Ensure APP_KEY is properly defined.
Jan 22 2016, 04:00 · Notifications center, Docker images, security
dereckson added a comment to T690: Ensure APP_KEY is properly defined.

SomeRandomString actually won't work.

Jan 22 2016, 04:00 · Notifications center, Docker images, security
dereckson created T690: Ensure APP_KEY is properly defined.
Jan 22 2016, 03:49 · Notifications center, Docker images, security

Jan 20 2016

dereckson closed T680: SSL certificate for code.zed.dereckson.be as Resolved.
Jan 20 2016, 15:13 · Nasqueron Docker deployment squad, security, Zed
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 20 2016, 14:57 · security, Servers
dereckson added a comment to T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.

I've generated a SSL certificate valid for all the remaining domains hosted by Dwellers.

Jan 20 2016, 14:45 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 20 2016, 14:40 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 20 2016, 14:39 · security, Servers
dereckson added a subtask for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org: T681: Deployed SSL certificates on mail.*.
Jan 20 2016, 14:39 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 20 2016, 14:38 · security, Servers
dereckson added a comment to T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.

Added domains from Dwellers /etc/nginx.conf.

Jan 20 2016, 14:18 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 20 2016, 14:18 · security, Servers
dereckson created T680: SSL certificate for code.zed.dereckson.be.
Jan 20 2016, 14:18 · Nasqueron Docker deployment squad, security, Zed
dereckson closed T679: Generate a SSL certificate for new Dwellers nasqueron.org services, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Resolved.
Jan 20 2016, 14:10 · security, Servers

Jan 19 2016

dereckson added a subtask for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org: T679: Generate a SSL certificate for new Dwellers nasqueron.org services.
Jan 19 2016, 04:44 · security, Servers
dereckson lowered the priority of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org from Normal to Low.

I've generated and deployed a temporary mega certificate:

Jan 19 2016, 04:20 · security, Servers

Jan 18 2016

dereckson added a project to T415: Allowed ops@ and dereckson@ to sudo docker or lxc-* commands on Dwellers: Accounts.
Jan 18 2016, 18:48 · Accounts, security, Servers

Jan 17 2016

dereckson closed T673: Rebuild images using OpenSSH client as Resolved.

Done for nasqueron/nginx-php-fpm per D245 (and so Phabricator).

Jan 17 2016, 02:23 · security, Docker images
dereckson created T673: Rebuild images using OpenSSH client.
Jan 17 2016, 02:18 · security, Docker images
dereckson added a comment to T667: Mitigate CVE-2016-0777 in SSH clients configuration files.

Ysul OpenSSH_6.6.1p1, OpenSSL 1.0.1l-freebsd 15 Jan 2015
Dwellers OpenSSH_6.6.1p1, OpenSSL 1.0.1e-fips 11 Feb 2013

Jan 17 2016, 02:16 · security, Servers

Jan 14 2016

dereckson added a parent task for T665: Configure DevCentral to approve automatically the user accounts: T614: Browse and search whole Nasqueron codebase.
Jan 14 2016, 16:29 · security, DevCentral
dereckson lowered the priority of T667: Mitigate CVE-2016-0777 in SSH clients configuration files from High to Normal.

Lowered the priority as we've mitigated at places where there are ssh outgoing connections.

Jan 14 2016, 16:01 · security, Servers
dereckson added a comment to T667: Mitigate CVE-2016-0777 in SSH clients configuration files.

Done for Ysul, Dwellers, the containers for DevCentral and phabricator.wolfplex.be.

Jan 14 2016, 16:00 · security, Servers
dereckson created T667: Mitigate CVE-2016-0777 in SSH clients configuration files.
Jan 14 2016, 15:50 · security, Servers

Jan 12 2016

dereckson updated the task description for T665: Configure DevCentral to approve automatically the user accounts.
Jan 12 2016, 18:57 · security, DevCentral
dereckson created T665: Configure DevCentral to approve automatically the user accounts.
Jan 12 2016, 18:57 · security, DevCentral

Jan 7 2016

dereckson added a parent task for T261: Generate SSL certificate for devcentral.nasqueron.org: T660: Switch DevCentral in https only.
Jan 7 2016, 18:03 · DevCentral, Nasqueron Docker deployment squad, security
dereckson closed T659: Install letsencrypt on Dwellers as Resolved.

The Let's encrypt container is usable as is.

Jan 7 2016, 17:49 · security, Servers
dereckson closed T659: Install letsencrypt on Dwellers, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Resolved.
Jan 7 2016, 17:49 · security, Servers
dereckson reopened T659: Install letsencrypt on Dwellers, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Open.
Jan 7 2016, 17:40 · security, Servers
dereckson created T659: Install letsencrypt on Dwellers.
Jan 7 2016, 17:40 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 7 2016, 16:58 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 7 2016, 16:58 · security, Servers

Jan 5 2016

dereckson added a comment to T606: Create a let's encrypt certificate generator jail.

Deleted jail

Jan 5 2016, 20:24 · IPv6, Operations sprint 0, security, Servers
dereckson updated subscribers of T656: Ensure every URL is HTTPS or protocol-relative.
Jan 5 2016, 19:33 · security, bioty.co hosting
dereckson created T656: Ensure every URL is HTTPS or protocol-relative.
Jan 5 2016, 19:31 · security, bioty.co hosting
dereckson added a comment to T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.

The 2016-01-05 series works.

Jan 5 2016, 19:17 · security, Servers
dereckson closed T655: setup.nasqueron.org SSL compliance, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Resolved.
Jan 5 2016, 19:14 · security, Servers
dereckson reopened T655: setup.nasqueron.org SSL compliance, a subtask of T654: Apply Let's encrypt SSL certificates for *.nasqueron.org, as Open.
Jan 5 2016, 19:12 · security, Servers
dereckson renamed T654: Apply Let's encrypt SSL certificates for *.nasqueron.org from Generate Let's encrypt server for nasqueron.org to Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 5 2016, 19:07 · security, Servers
dereckson moved T654: Apply Let's encrypt SSL certificates for *.nasqueron.org from Backlog to Working on on the Servers board.
Jan 5 2016, 19:00 · security, Servers
dereckson updated the task description for T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 5 2016, 19:00 · security, Servers
dereckson created T654: Apply Let's encrypt SSL certificates for *.nasqueron.org.
Jan 5 2016, 18:58 · security, Servers
dereckson added projects to P150 /usr/local/etc/nginx/includes/letsencrypt.conf: Servers, security.
Jan 5 2016, 17:52 · security, Servers
dereckson closed T606: Create a let's encrypt certificate generator jail as Wontfix.

Create the jail

Jan 5 2016, 17:39 · IPv6, Operations sprint 0, security, Servers
dereckson claimed T606: Create a let's encrypt certificate generator jail.

Hostname: setstyin.nasqueron.org
IP: 2001:470:1f12:9e1::3

Jan 5 2016, 16:08 · IPv6, Operations sprint 0, security, Servers
dereckson moved T606: Create a let's encrypt certificate generator jail from Product backlog to Working on on the Operations sprint 0 board.
Jan 5 2016, 15:43 · IPv6, Operations sprint 0, security, Servers

Jan 2 2016

dereckson updated the task description for T648: Secure access to etcd.
Jan 2 2016, 02:25 · security, Nasqueron Docker deployment squad, Servers
dereckson updated the task description for T648: Secure access to etcd.
Jan 2 2016, 02:25 · security, Nasqueron Docker deployment squad, Servers
dereckson created T648: Secure access to etcd.
Jan 2 2016, 01:51 · security, Nasqueron Docker deployment squad, Servers

Dec 21 2015

dereckson added a comment to T629: Software security issues on Ysul.

Dec 21 10:41:08 ysul pkg: freetype2 upgraded: 2.6_1 -> 2.6.2
Dec 21 10:41:08 ysul pkg: giflib upgraded: 5.0.6 -> 5.1.1
Dec 21 10:41:16 ysul pkg: subversion upgraded: 1.9.2_1 -> 1.9.3_1
Dec 21 10:42:19 ysul pkg: openjdk8 upgraded: 8.60.24 -> 8.66.17
Dec 21 10:42:52 ysul pkg: openjdk8-jre upgraded: 8.60.24 -> 8.66.17
Dec 21 10:42:52 ysul pkg: webp upgraded: 0.4.4 -> 0.4.4_1
Dec 21 10:42:53 ysul pkg: imlib2 upgraded: 1.4.6_6,2 -> 1.4.6_7,2

Dec 21 2015, 11:13 · security, Servers
dereckson updated the task description for T629: Software security issues on Ysul.
Dec 21 2015, 11:13 · security, Servers
dereckson updated the title for P145 `pkg audit` on Ysul from untitled to `pkg audit` on Ysul.
Dec 21 2015, 10:45 · security, Servers

Dec 7 2015

dereckson created T619: Allow to control from TC2 the Docker engine.
Dec 7 2015, 03:10 · Operations sprints (Operations sprint 1), security, Nasqueron Docker deployment squad, Servers, Dæghrefn

Dec 6 2015

dereckson closed T618: Software security issues on Ysul as Resolved.

Dec 6 13:20:55 ysul pkg-static: py27-django-1.8.4 deinstalled
Dec 6 13:21:59 ysul pkg-static: py27-django-1.8.7 installed

Dec 6 2015, 13:31 · Servers, security
dereckson added a comment to T618: Software security issues on Ysul.

Dec 6 13:17:25 ysul pkg: png upgraded: 1.6.19 -> 1.6.20

Dec 6 2015, 13:17 · Servers, security
dereckson created T618: Software security issues on Ysul.
Dec 6 2015, 13:16 · Servers, security

Dec 1 2015

dereckson added a comment to T606: Create a let's encrypt certificate generator jail.

This task has been identified as suitable for the December product backlog for infrastructure. It's included in our product backlog and will be discussed for inclusion to sprint backlog this E3 meeting.

Dec 1 2015, 06:23 · IPv6, Operations sprint 0, security, Servers
dereckson added a parent task for T606: Create a let's encrypt certificate generator jail: T559: SSL certificate for docker.nasqueron.org.
Dec 1 2015, 06:17 · IPv6, Operations sprint 0, security, Servers

Nov 30 2015

dereckson added a parent task for T606: Create a let's encrypt certificate generator jail: T560: Install letsencrypt on Ysul.
Nov 30 2015, 19:59 · IPv6, Operations sprint 0, security, Servers
dereckson added a project to T606: Create a let's encrypt certificate generator jail: Operations sprint 0.
Nov 30 2015, 19:58 · IPv6, Operations sprint 0, security, Servers
dereckson created T606: Create a let's encrypt certificate generator jail.
Nov 30 2015, 19:32 · IPv6, Operations sprint 0, security, Servers

Nov 27 2015

dereckson renamed T599: Security software issues on Ysul from Security issues on Ysul to Security software issues on Ysul.
Nov 27 2015, 21:21 · security, Servers
dereckson triaged T599: Security software issues on Ysul as High priority.
Nov 27 2015, 21:14 · security, Servers
dereckson added projects to T599: Security software issues on Ysul: Servers, security.
Nov 27 2015, 21:10 · security, Servers

Nov 21 2015

dereckson closed T592: Ensure ffmpeg on Ysul have all our needed codecs, a subtask of T591: General upgrade round on Ysul, as Resolved.
Nov 21 2015, 03:01 · security, Servers
dereckson closed T591: General upgrade round on Ysul, a subtask of T584: Security issues on Ysul, as Resolved.
Nov 21 2015, 01:05 · Servers, security
dereckson closed T591: General upgrade round on Ysul as Resolved.
Nov 21 2015, 01:05 · security, Servers
dereckson added a comment to T591: General upgrade round on Ysul.

Nov 20 23:43:12 ysul pkg: pciids upgraded: 20151011 -> 20151108
Nov 20 23:43:12 ysul pkg: py27-asn1-0.1.8,1 deinstalled
Nov 20 23:43:14 ysul pkg: cairo upgraded: 1.14.2,2 -> 1.14.2_1,2
Nov 20 23:43:14 ysul pkg: py27-pyasn1-0.1.9 installed
Nov 20 23:43:17 ysul pkg: py27-pip upgraded: 7.0.3 -> 7.1.2
Nov 20 23:43:18 ysul pkg: py27-cryptography upgraded: 1.0.2_2 -> 1.0.2_3
Nov 20 23:43:18 ysul pkg: sqlite3 upgraded: 3.9.1 -> 3.9.2
Nov 20 23:43:20 ysul pkg: sudo upgraded: 1.8.14p3 -> 1.8.15
Nov 20 23:43:20 ysul pkg: py27-ndg_httpsclient upgraded: 0.4.0_1 -> 0.4.0_2
Nov 20 23:43:34 ysul pkg: mysql56-client upgraded: 5.6.26 -> 5.6.27
Nov 20 23:43:34 ysul pkg: libvpx upgraded: 1.4.0.488_1 -> 1.5.0
Nov 20 23:43:35 ysul pkg: youtube_dl upgraded: 2015.08.28 -> 2015.11.13
Nov 20 23:44:06 ysul pkg: vim upgraded: 7.4.900 -> 7.4.909
Nov 20 23:44:06 ysul pkg: tmux upgraded: 2.0_2 -> 2.1
Nov 20 23:44:29 ysul pkg: squid upgraded: 3.5.10 -> 3.5.11
Nov 20 23:44:45 ysul pkg: ruby21-gems upgraded: 2.4.8 -> 2.5.0
Nov 20 23:44:47 ysul pkg: py27-virtualenvwrapper upgraded: 4.3.2 -> 4.7.1
Nov 20 23:45:08 ysul pkg: py27-numpy upgraded: 1.10.0_1,1 -> 1.10.1,1
Nov 20 23:45:09 ysul pkg: py27-m2crypto upgraded: 0.22.3 -> 0.22.5
Nov 20 23:45:17 ysul pkg: py27-lxml upgraded: 3.4.1_1 -> 3.5.0
Nov 20 23:45:17 ysul pkg: py27-acme upgraded: 0.0.0.d20151104 -> 0.0.0.d20151104_1
Nov 20 23:45:36 ysul pkg: py27-Babel upgraded: 2.0 -> 2.1.1
Nov 20 23:45:37 ysul pkg: poudriere-devel upgraded: 3.1.99.20151014 -> 3.1.99.20151109
Nov 20 23:45:37 ysul pkg: porttools upgraded: 1.05_1 -> 1.06
Nov 20 23:45:39 ysul pkg: php56-gd upgraded: 5.6.14 -> 5.6.14_1
Nov 20 23:45:39 ysul pkg: p5-Params-Util upgraded: 1.07_1 -> 1.07_2
Nov 20 23:46:04 ysul pkg: p5-Image-ExifTool-devel upgraded: 10.03 -> 10.05
Nov 20 23:46:21 ysul pkg: nmap upgraded: 6.49.b5 -> 6.49.b6
Nov 20 23:46:25 ysul pkg: nano upgraded: 2.4.2 -> 2.4.3
Nov 20 23:47:09 ysul pkg: mysql56-server upgraded: 5.6.26 -> 5.6.27
Nov 20 23:47:16 ysul pkg: mercurial upgraded: 3.6 -> 3.6.1
Nov 20 23:47:17 ysul pkg: liblangtag upgraded: 0.5.7 -> 0.5.8
Nov 20 23:47:17 ysul pkg: libgd upgraded: 2.1.0_6,1 -> 2.1.0_7,1
Nov 20 23:47:20 ysul pkg: gsoap upgraded: 2.8.24 -> 2.8.24r
Nov 20 23:50:41 ysul pkg: gcc49 upgraded: 4.9.4.s20151028 -> 4.9.4.s20151111
Nov 20 23:50:42 ysul pkg: flex upgraded: 2.5.39_2 -> 2.6.0
Nov 20 23:51:02 ysul pkg: ffmpeg upgraded: 2.8.1,1 -> 2.8.2_1,1
Nov 20 23:51:03 ysul pkg: dhcp6 upgraded: 20080615_2 -> 20080615_3
Nov 20 23:51:07 ysul pkg: compat9x-amd64 upgraded: 9.2.902000.201310 -> 9.3.903000.20151116
Nov 20 23:51:07 ysul pkg: alsa-lib upgraded: 1.0.29 -> 1.1.0

Nov 21 2015, 01:05 · security, Servers
dereckson closed T584: Security issues on Ysul as Resolved.

Packages were available this night, and at the same time we upgrade all unlocked packages at T591.

Nov 21 2015, 01:04 · Servers, security
dereckson moved T591: General upgrade round on Ysul from Backlog to Pending review on the Servers board.
Nov 21 2015, 01:02 · security, Servers

Nov 20 2015

dereckson added a comment to T591: General upgrade round on Ysul.

After some deps resolution, we have:

Nov 20 2015, 23:43 · security, Servers
dereckson created T591: General upgrade round on Ysul.
Nov 20 2015, 23:35 · security, Servers

Nov 17 2015

dereckson lowered the priority of T584: Security issues on Ysul from High to Normal.
Nov 17 2015, 03:55 · Servers, security
dereckson added a comment to T584: Security issues on Ysul.

Binary update

Nov 17 2015, 03:55 · Servers, security
dereckson triaged T584: Security issues on Ysul as High priority.
Nov 17 2015, 03:51 · Servers, security

Nov 15 2015

dereckson closed T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator as Resolved by committing rDPHABd477229b3364: Set max_input_vars and upload_max_filesize PHP values.
Nov 15 2015, 00:10 · security, Nasqueron Docker deployment squad, Docker images, DevCentral

Nov 14 2015

dereckson triaged T530: Software security issues on Ysul as High priority.
Nov 14 2015, 02:57 · Servers, security
dereckson triaged T442: Install PHP 5.6.10 on Ysul as Normal priority.
Nov 14 2015, 02:56 · security, Servers

Nov 12 2015

dereckson closed T488: Upgrade PHP related images to 5.6.11 as Resolved.

There are at 5.6.15 now.

Nov 12 2015, 18:22 · security, Nasqueron Docker deployment squad
dereckson moved T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator from Working on to Pending review on the security board.
Nov 12 2015, 18:21 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson moved T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator from Working on to Pending review on the Nasqueron Docker deployment squad board.
Nov 12 2015, 18:21 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson added a revision to T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator: D48: Set max_input_vars and upload_max_filesize PHP values.
Nov 12 2015, 18:21 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson renamed T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator from Set max_input_vars and upload_max_filesize PHP value in nasqueron/phabricator to Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator.
Nov 12 2015, 18:18 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson moved T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator from Backlog to Working on on the Nasqueron Docker deployment squad board.
Nov 12 2015, 16:26 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson moved T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator from Backlog to Working on on the security board.
Nov 12 2015, 16:26 · security, Nasqueron Docker deployment squad, Docker images, DevCentral
dereckson created T558: Set max_input_vars and upload_max_filesize PHP values in nasqueron/phabricator.
Nov 12 2015, 16:25 · security, Nasqueron Docker deployment squad, Docker images, DevCentral

Oct 13 2015

dereckson closed T530: Software security issues on Ysul as Resolved.
$ pkg audit
0 problem(s) in the installed packages found.
Oct 13 2015, 20:43 · Servers, security

Sep 13 2015

dereckson added a comment to T530: Software security issues on Ysul.

Security software update is running, that will take some time as it pulls texlive 2015.

Sep 13 2015, 22:02 · Servers, security
dereckson added a comment to T530: Software security issues on Ysul.

We add P113 in the mix.

Sep 13 2015, 21:59 · Servers, security

Aug 21 2015

dereckson added a comment to T530: Software security issues on Ysul.

Aug 21 17:47:31 ysul pkg: perl5 upgraded: 5.20.2_5 -> 5.20.2_6
Aug 21 17:47:31 ysul pkg: ca_root_nss upgraded: 3.19.2 -> 3.19.3
Aug 21 17:48:01 ysul pkg: glib upgraded: 2.44.1 -> 2.44.1_1
Aug 21 17:48:10 ysul pkg: gnutls upgraded: 3.3.16 -> 3.3.17.1
Aug 21 17:48:13 ysul pkg: gdk-pixbuf2 upgraded: 2.31.5 -> 2.31.6
Aug 21 17:49:17 ysul pkg: py27-django upgraded: 1.8.3 -> 1.8.4

Aug 21 2015, 17:52 · Servers, security