This is still needed for acme.sh if we want to provision different *.nasqueron.org certificates on different servers.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Oct 12 2024
Oct 9 2024
Salt SELinux module issue
SELinux context was the default for anything created under /var, which we didn't allow and aren't interested to allow for nginx.
Oct 3 2024
Yes, it's a fork from Vault 1.14 so we've all the features of token generation. back to the shorter s. tokens).
- about the UI it could be usefull managing secrets more easyly
Sep 12 2024
Can't repro
Sep 8 2024
Sep 5 2024
Aug 17 2024
Mumble isn't currently in scope.
Aug 4 2024
Both are already set in DNS:
We use a wildcard certificate, so issuewild is needed, yes.
@Ash-Crow @fauve @rama @replicatorbe @Sandlayth @xcombelle Any feedback on this?
Aug 3 2024
From router-001 network looks good:
Stopped currently not needed salt and node-exporter on router-001 to see if that helps.
Could be at hypervisor level. SSH failed until 13:22 where it worked immediately.
Jul 23 2024
It could be easier to deploy https://github.com/kpetremann/salt-exporter
Jul 10 2024
Key confirmed to work.
Jul 9 2024
Still some issue to connect, SSH2 RSA key not recognized.
Jul 5 2024
Feb 17 2024
$ /usr/local/etc/rc.d/sshd-otp restart Performing sanity check on sshd_otp configuration. Stopping sshd_otp. Waiting for PIDS: 1331. Performing sanity check on sshd_otp configuration. Starting sshd_otp.
Jan 28 2024
Secrets have been migrated from dot notation to slash notation.
Jan 15 2024
Alcali is still alive.
Jan 8 2024
Jan 7 2024
Jan 5 2024
FreeBSD integrates OpenSSH to the base OS.
cloudhugger:
OpenSSH_8.4p1 Debian-5+deb11u3, OpenSSL 1.1.1w 11 Sep 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
dwellers:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
windriver:
OpenSSH_9.5p1, OpenSSL 3.0.12 24 Oct 2023
docker-002:
OpenSSH_8.7p1, OpenSSL 3.0.7 1 Nov 2022
hervil:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
complector:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-A-001:
OpenSSH_9.3p2, OpenSSL 1.1.1t-freebsd 7 Feb 2023
db-B-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
web-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
router-001:
OpenSSH_9.3p1, OpenSSL 1.1.1t-freebsd 7 Feb 2023
ysul:
Minion did not return. [Not connected]
thrayce:
Minion did not return. [Not connected]
Dec 17 2023
Situation has evolved since 2017, we currently configure nginx with TLSv1.2 + TLSv1.3,
per Mozilla intermediate configuration https://ssl-config.mozilla.org/
Jun 16 2023
Jun 11 2023
Worked before (dhclient + routes), but on boot:
- we've a correct fe80 address
- no dhclient, but /usr/local/etc/rc.d/dhclient6 start does NOT complain dhclient6_enable="YES" is missing
- when dhclient is started, our correct prefix is returned
- no static IP assignment in current state (missing from /etc/netif/igb0_ipv6)
- we can add manually IP in our prefix
- routing is missing and can't be easily figured (the expectation was dhclient would take care of that)
Jun 7 2023
Jun 3 2023
Taking it as we've issues with the /128 one and I'd prefer to fix the /56 config than the /128 one.
May 29 2023
Server log
May 25 2023
May 20 2023
Documentation available at https://devcentral.nasqueron.org/w/setup_2fa/
2FA enabled
As a minimum, to have somewhere (a reports repository?) where we can write those report queries could already be useful, so we don't lose them.