Our Salt state core/sshd does not set PubkeyAcceptedAlgorithms, so ssh-rsa (SHA-1) is blocked by default — this has been the case since OpenSSH 8.8 (released 2021-09-26, see https://www.openssh.com/txt/release-8.8).
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Sun, Jun 14
Sun, Jun 7
Markdown content for code review for D4022
Tested on hervil and web-001, map is parsed correctly and packages changes are no-op.
Rebased. Implemented a new map for PHP packages by version.
As of June 2026, we can login to zed51.dereckson.be and use it, so this specific task can be closed.
We aren't blocked by upstream, as it's a doc fix; our own nginx configuration is now live and problem is solved on geo.nasqueron.org with Referrer-Policy: strict-origin-when-cross-origin header now served.
Rebased per previous comment
Rebased against origin/main:
Samy commit, split from D4096 Wolfplex DNS branch.
Tested with D4102.
OK to merge, but requires D4103
Restore full exception message
Why removing block on {{ public_ipv4_interface }} from <badhosts> to any?
Tested, works fine.
Wed, Jun 3
I've also submitted upstream the same nginx configuration change in the documentation @ https://github.com/bilde2910/Hauk/issues/240