This tag identifies security issue.
Details
Details
Description
Mon, Nov 10
Mon, Nov 10
dereckson added a comment to T2183: Detect legacy SHA-1 RSA keys.
Bruteforce attack scenario possible, so we're only interested by usernames defined in users.sls, not by "root" (can't login by SSH) or generic accounts like "docker" (doesn't exist):
dereckson updated the task description for T2183: Detect legacy SHA-1 RSA keys.
dereckson updated the task description for T2183: Detect legacy SHA-1 RSA keys.
dereckson updated the task description for T2183: Detect legacy SHA-1 RSA keys.
Oct 25 2025
Oct 25 2025
dereckson moved T1145: Don't truncate passwords from Backlog to General bug & features on the C board.
Oct 24 2025
Oct 24 2025
dereckson added a comment to T2155: Review rotation for acme.sh logs.
Same issue for rhyne-wyse.log. Configuration was copied from acme.sh one.
Oct 20 2025
Oct 20 2025
dereckson added a parent task for T2155: Review rotation for acme.sh logs: T2043: Switch to acme.sh instead of certbot.
Oct 11 2025
Oct 11 2025
dereckson moved T1656: Convert daeghrefn. for Uspection use from Backlog to Need dev on the documentation board.
dereckson moved T1657: Convert docs. for Uspection use from Backlog to Need dev on the documentation board.
The full /etc/nginx directories on both docker-002 and dwellers use httpd_config_t for every file.
dereckson updated the task description for T1765: SELinux context is missing for /etc/nginx configuration files.
Oct 10 2025
Oct 10 2025
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson moved T2132: Propagate acme.sh certificate so Dovecot can read it from Backlog to Pending review on the security board.
dereckson moved T2132: Propagate acme.sh certificate so Dovecot can read it from Backlog - On hold pending T1475 to Pending review on the Mail board.
Oct 9 2025
Oct 9 2025
dereckson added a comment to T1878: Allow to run queries for reporting.
Alternatively, we made a lot of progress on this in T2124.
Oct 6 2025
Oct 6 2025
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
Sep 23 2025
Sep 23 2025
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson updated the task description for T2132: Propagate acme.sh certificate so Dovecot can read it.
dereckson moved T2132: Propagate acme.sh certificate so Dovecot can read it from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Sep 22 2025
Sep 22 2025
Sep 18 2025
Sep 18 2025
dereckson updated the task description for T2040: Supersede Vault by OpenBao.
dereckson updated the task description for T2040: Supersede Vault by OpenBao.
dereckson added a comment to T2040: Supersede Vault by OpenBao.
So, there is a new reason to do the upgrade.
Sep 14 2025
Sep 14 2025
dereckson moved T1580: Deploy ACME-specific DNS server from DNS Server / KnotDNS to AcmeDNS on the DNS board.
dereckson moved T1580: Deploy ACME-specific DNS server from Backlog to DNS Server / KnotDNS on the DNS board.
Sep 10 2025
Sep 10 2025
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTPS certificate automatically to Renew Vault web server certificate automatically.
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault HTTP certificate automatically to Renew Vault HTTPS certificate automatically.
dereckson renamed T2112: Renew Vault web server certificate automatically from Renew Vault certificate to Renew Vault HTTP certificate automatically.
dereckson added a comment to T2112: Renew Vault web server certificate automatically.
First step is to create a script to renew all needed certificates:
May 18 2025
May 18 2025
Apr 5 2025
Apr 5 2025
dereckson added a comment to T2107: j'aimerais avoir une présence permanente sur internet.
Une fois que tu as retrouvé les accès SSH pour le web statique:
- WindRiver: automatiquement https://windriver.nasqueron.org/~xcombelle est disponible si tu places des fichiers dans /var/home-wwwroot/xcombelle (je ne sais plus si ça se crée automatiquement avec symlink vers $HOME/public_html, à vérifier)
- Eglide: https://www.eglide.org/~xcombelle pour $HOME/public_html
dereckson added projects to T2107: j'aimerais avoir une présence permanente sur internet: security, Eglide.
Nov 2 2024
Nov 2 2024
Oct 27 2024
Oct 27 2024
dereckson moved T2075: Generate SSH keys for backup purpose from Backlog to Backup infrastructure on the Backups board.
