mirror/dsa-puppet.git
12 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Fri, 10 Jun 2011 19:20:56 +0000 (20:20 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

12 years agoalioth can talk to samosa
Stephen Gran [Fri, 10 Jun 2011 19:20:52 +0000 (20:20 +0100)]
alioth can talk to samosa

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agoSupport ssh options for portforwarder
Peter Palfrader [Fri, 10 Jun 2011 10:58:49 +0000 (12:58 +0200)]
Support ssh options for portforwarder

12 years agopaganini on squeeze
Peter Palfrader [Thu, 9 Jun 2011 13:08:31 +0000 (15:08 +0200)]
paganini on squeeze

12 years agoupdate logic in named.conf template
Peter Palfrader [Thu, 9 Jun 2011 12:27:07 +0000 (14:27 +0200)]
update logic in named.conf template

12 years agodraghi is another special bind authority case
Peter Palfrader [Thu, 9 Jun 2011 12:25:54 +0000 (14:25 +0200)]
draghi is another special bind authority case

12 years agodraghi on squeeze
Peter Palfrader [Thu, 9 Jun 2011 10:57:24 +0000 (12:57 +0200)]
draghi on squeeze

12 years agothis address spams us
Martin Zobel-Helas [Tue, 7 Jun 2011 13:19:26 +0000 (15:19 +0200)]
this address spams us
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
12 years agoBe secondary for sanger6 reverse
Peter Palfrader [Mon, 6 Jun 2011 16:09:56 +0000 (18:09 +0200)]
Be secondary for sanger6 reverse

12 years agobellini on squeeze
Peter Palfrader [Mon, 6 Jun 2011 12:25:36 +0000 (14:25 +0200)]
bellini on squeeze

12 years agoand allow from v6 networks
Stephen Gran [Sat, 4 Jun 2011 09:25:43 +0000 (10:25 +0100)]
and allow from v6 networks

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agopoint the nameservers at us instead
Stephen Gran [Sat, 4 Jun 2011 09:23:08 +0000 (10:23 +0100)]
point the nameservers at us instead

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agonameservers seem broken from tchaikovsky
Stephen Gran [Sat, 4 Jun 2011 09:17:18 +0000 (10:17 +0100)]
nameservers seem broken from tchaikovsky

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agothey're starting to annoy me now
Stephen Gran [Fri, 3 Jun 2011 20:41:51 +0000 (21:41 +0100)]
they're starting to annoy me now

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agopoulenc on squeeze
Peter Palfrader [Tue, 31 May 2011 06:45:50 +0000 (08:45 +0200)]
poulenc on squeeze

12 years agoporpora on squeeze
Peter Palfrader [Mon, 30 May 2011 11:24:17 +0000 (13:24 +0200)]
porpora on squeeze

12 years agolet's try this
Stephen Gran [Mon, 30 May 2011 09:18:46 +0000 (10:18 +0100)]
let's try this

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agosigh, totally broken
Stephen Gran [Mon, 30 May 2011 09:13:43 +0000 (10:13 +0100)]
sigh, totally broken

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agosigh for API compatibility, take 2
Stephen Gran [Mon, 30 May 2011 08:57:04 +0000 (09:57 +0100)]
sigh for API compatibility, take 2

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agosigh for API compatibility
Stephen Gran [Mon, 30 May 2011 08:56:11 +0000 (09:56 +0100)]
sigh for API compatibility

Signed-off-by: Stephen Gran <steve@lobefin.net>
12 years agohandel on squeeze
Peter Palfrader [Sun, 29 May 2011 14:58:19 +0000 (16:58 +0200)]
handel on squeeze

12 years agozandonai on squeeze
Peter Palfrader [Sun, 29 May 2011 13:54:55 +0000 (15:54 +0200)]
zandonai on squeeze

12 years agozelenka on squeeze
Peter Palfrader [Sun, 29 May 2011 12:52:59 +0000 (14:52 +0200)]
zelenka on squeeze

12 years agomaster to squeeze
Stephen Gran [Sun, 29 May 2011 08:41:28 +0000 (09:41 +0100)]
master to squeeze

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agopraetorius on squeeze
Peter Palfrader [Fri, 27 May 2011 14:49:00 +0000 (16:49 +0200)]
praetorius on squeeze

13 years agoquote filepaths
Peter Palfrader [Fri, 27 May 2011 10:21:59 +0000 (12:21 +0200)]
quote filepaths

13 years agoTry to restart stunnels when certs change
Peter Palfrader [Fri, 27 May 2011 10:21:34 +0000 (12:21 +0200)]
Try to restart stunnels when certs change

13 years agoDifferent name
Peter Palfrader [Fri, 27 May 2011 10:09:04 +0000 (12:09 +0200)]
Different name

13 years agoTry to restart only the affected stunnel
Peter Palfrader [Fri, 27 May 2011 10:07:15 +0000 (12:07 +0200)]
Try to restart only the affected stunnel

13 years agoExec[stunnel_restart] depends on new init script
Peter Palfrader [Fri, 27 May 2011 10:03:56 +0000 (12:03 +0200)]
Exec[stunnel_restart] depends on new init script

13 years agoYou can't be an authority and a recursor for others anymore. remove ravel from names...
Peter Palfrader [Thu, 26 May 2011 21:41:54 +0000 (23:41 +0200)]
You can't be an authority and a recursor for others anymore.  remove ravel from nameservers for UBC

13 years agoravel onto squeeze
Peter Palfrader [Thu, 26 May 2011 21:15:40 +0000 (23:15 +0200)]
ravel onto squeeze

13 years agoAnd hush
Peter Palfrader [Tue, 24 May 2011 10:13:52 +0000 (12:13 +0200)]
And hush

13 years agoInclude the shebang
Peter Palfrader [Tue, 24 May 2011 10:13:18 +0000 (12:13 +0200)]
Include the shebang

13 years agodifferent name
Peter Palfrader [Tue, 24 May 2011 10:12:15 +0000 (12:12 +0200)]
different name

13 years agosyntax
Peter Palfrader [Tue, 24 May 2011 10:11:37 +0000 (12:11 +0200)]
syntax

13 years agorestart stunnel regularly
Peter Palfrader [Tue, 24 May 2011 10:11:19 +0000 (12:11 +0200)]
restart stunnel regularly

13 years agoetc/default/stunnel kills FILES
Peter Palfrader [Tue, 24 May 2011 10:06:24 +0000 (12:06 +0200)]
etc/default/stunnel kills FILES

13 years agopatch usage
Peter Palfrader [Tue, 24 May 2011 10:00:28 +0000 (12:00 +0200)]
patch usage

13 years agofix
Peter Palfrader [Tue, 24 May 2011 09:58:57 +0000 (11:58 +0200)]
fix

13 years agoproper mode
Peter Palfrader [Tue, 24 May 2011 09:58:16 +0000 (11:58 +0200)]
proper mode

13 years agoDo it differently, II
Peter Palfrader [Tue, 24 May 2011 09:57:36 +0000 (11:57 +0200)]
Do it differently, II

13 years agoDo it differently
Peter Palfrader [Tue, 24 May 2011 09:55:25 +0000 (11:55 +0200)]
Do it differently

13 years agoAllow overriding FILES
Peter Palfrader [Tue, 24 May 2011 09:53:25 +0000 (11:53 +0200)]
Allow overriding FILES

13 years agoadd puppet header
Peter Palfrader [Tue, 24 May 2011 09:52:25 +0000 (11:52 +0200)]
add puppet header

13 years agoShip our own etc/init.d/stunnel4
Peter Palfrader [Tue, 24 May 2011 09:51:23 +0000 (11:51 +0200)]
Ship our own etc/init.d/stunnel4

13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sat, 21 May 2011 17:00:48 +0000 (18:00 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agonew ip for master
Stephen Gran [Sat, 21 May 2011 17:00:33 +0000 (18:00 +0100)]
new ip for master

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agokokkonen -> squeeze
Martin Zobel-Helas [Tue, 17 May 2011 18:41:33 +0000 (20:41 +0200)]
kokkonen -> squeeze
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agoa little more protection for the iana account
Stephen Gran [Sun, 15 May 2011 08:40:22 +0000 (09:40 +0100)]
a little more protection for the iana account

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoreally add new static file
Stephen Gran [Sat, 14 May 2011 14:59:35 +0000 (15:59 +0100)]
really add new static file

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agojust run restart directly from nrpe
Stephen Gran [Sat, 14 May 2011 14:36:27 +0000 (15:36 +0100)]
just run restart directly from nrpe

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoAdd event_handler hooks to sudo and nrpe.
Stephen Gran [Sat, 14 May 2011 14:16:39 +0000 (15:16 +0100)]
Add event_handler hooks to sudo and nrpe.

We still don't actually call it yet - we need to ship a new version of
dsa-nagios-checks and then add the event_handler stanza to the entropy
check.
Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agorore on squeeze
Stephen Gran [Sat, 14 May 2011 07:44:55 +0000 (08:44 +0100)]
rore on squeeze

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoholter to squeeze
Stephen Gran [Fri, 13 May 2011 19:39:56 +0000 (20:39 +0100)]
holter to squeeze

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoball on squeeze
Stephen Gran [Thu, 12 May 2011 19:34:33 +0000 (20:34 +0100)]
ball on squeeze

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoRevert "I'm temporarily on borrowed ADSL"
Stephen Gran [Mon, 9 May 2011 18:40:38 +0000 (19:40 +0100)]
Revert "I'm temporarily on borrowed ADSL"

About time.
This reverts commit 05f75b180353ace7dbc4f39111a1151cc959f806.

13 years agoSet keep_hostname to no
Peter Palfrader [Wed, 4 May 2011 14:53:45 +0000 (16:53 +0200)]
Set keep_hostname to no

13 years agoMerge remote branch 'symoon/master'
Peter Palfrader [Wed, 4 May 2011 11:55:19 +0000 (13:55 +0200)]
Merge remote branch 'symoon/master'

* symoon/master:
  Fix reference rewrite rule
  Canonical place for manuals is /doc/manuals/
  Handle a Redirect for the New Maintainers' Guide
  Handle a RewriteMap for Debian Reference
  Offer a link to DSA without knowing year (Closes: #474730)
  More Redirect previously handled by symlinks
  Handle links to translated 404 pages
  All Redirect are actually RedirectPermanent

Signed-off-by: Peter Palfrader <peter@palfrader.org>
13 years agochain hostnames: trust peers, but log
Peter Palfrader [Wed, 4 May 2011 10:12:40 +0000 (12:12 +0200)]
chain hostnames:  trust peers, but log

13 years agoFix reference rewrite rule
Simon Paillard [Tue, 3 May 2011 22:05:49 +0000 (00:05 +0200)]
Fix reference rewrite rule

13 years agoCanonical place for manuals is /doc/manuals/
Simon Paillard [Tue, 3 May 2011 21:13:33 +0000 (23:13 +0200)]
Canonical place for manuals is /doc/manuals/

13 years agoHandle a Redirect for the New Maintainers' Guide
David Prévot [Wed, 27 Apr 2011 21:13:51 +0000 (17:13 -0400)]
Handle a Redirect for the New Maintainers' Guide

The New Maintainers' Guide has moved from SGML to DocBook.

Signed-off-by: Simon Paillard <spaillard@debian.org>
13 years agoHandle a RewriteMap for Debian Reference
David Prévot [Fri, 29 Apr 2011 02:24:31 +0000 (22:24 -0400)]
Handle a RewriteMap for Debian Reference

The Debian Reference has been moved from SGML to DocBook.

Signed-off-by: Simon Paillard <spaillard@debian.org>
13 years agoOffer a link to DSA without knowing year (Closes: #474730)
David Prévot [Wed, 27 Apr 2011 21:08:49 +0000 (17:08 -0400)]
Offer a link to DSA without knowing year (Closes: #474730)

Signed-off-by: Simon Paillard <spaillard@debian.org>
13 years agoMore Redirect previously handled by symlinks
David Prévot [Wed, 27 Apr 2011 21:07:21 +0000 (17:07 -0400)]
More Redirect previously handled by symlinks

Mainly directories.
Thanks to Simon Paillard.
Closes: #612120

Signed-off-by: Simon Paillard <spaillard@debian.org>
Remove http://www.debian.org/ from rewrite rules

Add Chinese too

13 years agoHandle links to translated 404 pages
David Prévot [Wed, 27 Apr 2011 22:40:21 +0000 (18:40 -0400)]
Handle links to translated 404 pages

Signed-off-by: Simon Paillard <spaillard@debian.org>
13 years agoAll Redirect are actually RedirectPermanent
David Prévot [Wed, 27 Apr 2011 21:05:20 +0000 (17:05 -0400)]
All Redirect are actually RedirectPermanent

13 years agoRevert "MIT seems to be hammering morricone, making /var fill up."
Peter Palfrader [Tue, 3 May 2011 14:06:25 +0000 (16:06 +0200)]
Revert "MIT seems to be hammering morricone, making /var fill up."

This reverts commit b5db5cc3b55641a5d1b1d35be2e48adc08ed1746.

This rule really is not a good fit for systems that serve debian
archives.  If we need something like this we need to come up with better
or at least different limits.

13 years agoupdate obsolete-packages-ignore.d-hostspecific
Peter Palfrader [Tue, 3 May 2011 09:31:51 +0000 (11:31 +0200)]
update obsolete-packages-ignore.d-hostspecific

13 years agoignore linux-base on corelli
Peter Palfrader [Tue, 3 May 2011 09:23:22 +0000 (11:23 +0200)]
ignore linux-base on corelli

13 years agodo not do the www-mirror thing on www-master
Peter Palfrader [Mon, 2 May 2011 19:26:12 +0000 (21:26 +0200)]
do not do the www-mirror thing on www-master

13 years agoMIT seems to be hammering morricone, making /var fill up.
Stephen Gran [Mon, 2 May 2011 15:39:19 +0000 (16:39 +0100)]
MIT seems to be hammering morricone, making /var fill up.

morricone:/var/log/apache2# grep ^128.30 backports-master.debian.org-access.log-20110502 | wc -l
2160933

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoI'm temporarily on borrowed ADSL
Stephen Gran [Mon, 2 May 2011 15:34:14 +0000 (15:34 +0000)]
I'm temporarily on borrowed ADSL

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years ago05/02/11 [14:53:03] < carlos_c3sl> BTW, one of the dns servers changed. 200.17.202...
Martin Zobel-Helas [Mon, 2 May 2011 12:58:27 +0000 (14:58 +0200)]
05/02/11 [14:53:03] < carlos_c3sl> BTW, one of the dns servers changed. 200.17.202.1 is now 200.236.31.1
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
13 years agogrieg on squeeze
Peter Palfrader [Sat, 30 Apr 2011 18:58:58 +0000 (20:58 +0200)]
grieg on squeeze

13 years agoremove kibi, add christoph for freebsd whitelist
Peter Palfrader [Sat, 30 Apr 2011 17:17:40 +0000 (19:17 +0200)]
remove kibi, add christoph for freebsd whitelist

13 years agoremove kibi from carnet ssh whitelist
Peter Palfrader [Sat, 30 Apr 2011 17:16:53 +0000 (19:16 +0200)]
remove kibi from carnet ssh whitelist

13 years agoMake bind listen only on !localhost
Peter Palfrader [Sat, 30 Apr 2011 16:24:31 +0000 (18:24 +0200)]
Make bind listen only on !localhost

13 years agodiamond does dns
Peter Palfrader [Sat, 30 Apr 2011 15:39:33 +0000 (17:39 +0200)]
diamond does dns

13 years agoAdd diamond
Peter Palfrader [Sat, 30 Apr 2011 15:38:12 +0000 (17:38 +0200)]
Add diamond

13 years agomujeres can sudo to women
Peter Palfrader [Wed, 27 Apr 2011 16:30:12 +0000 (18:30 +0200)]
mujeres can sudo to women

13 years agofranck also has a newer python-apt
Stephen Gran [Mon, 25 Apr 2011 07:49:01 +0000 (08:49 +0100)]
franck also has a newer python-apt

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agorietz is in puppet now
Stephen Gran [Sun, 24 Apr 2011 10:02:17 +0000 (11:02 +0100)]
rietz is in puppet now

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sat, 16 Apr 2011 19:02:19 +0000 (20:02 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agooh, boy, I'm going to regret that, but it seems like a silly omission
Stephen Gran [Sat, 16 Apr 2011 19:02:07 +0000 (20:02 +0100)]
oh, boy, I'm going to regret that, but it seems like a silly omission

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoDuarte is now an nfs server
Peter Palfrader [Wed, 13 Apr 2011 18:38:02 +0000 (20:38 +0200)]
Duarte is now an nfs server

13 years agoignore /etc/dsa/cron.ignore.dsa-puppet-stuff
Peter Palfrader [Tue, 12 Apr 2011 09:38:47 +0000 (11:38 +0200)]
ignore /etc/dsa/cron.ignore.dsa-puppet-stuff

13 years agoAlso ignore puppet noise on s390
Peter Palfrader [Tue, 12 Apr 2011 09:36:45 +0000 (11:36 +0200)]
Also ignore puppet noise on s390

13 years agoAdd glinka
Peter Palfrader [Mon, 11 Apr 2011 17:50:05 +0000 (19:50 +0200)]
Add glinka

13 years agoMerge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Thu, 7 Apr 2011 18:49:05 +0000 (19:49 +0100)]
Merge branch 'master' of ssh://puppet.debian.org/srv/puppet.debian.org/git/dsa-puppet

13 years agomake is now silent for nagios repo
Stephen Gran [Thu, 7 Apr 2011 18:48:54 +0000 (19:48 +0100)]
make is now silent for nagios repo

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoAdd new 1&1 rev range to authorities
Peter Palfrader [Wed, 6 Apr 2011 16:51:09 +0000 (18:51 +0200)]
Add new 1&1 rev range to authorities

13 years agosome new sonames
Stephen Gran [Wed, 6 Apr 2011 12:00:36 +0000 (13:00 +0100)]
some new sonames

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agonew spammer
Stephen Gran [Tue, 5 Apr 2011 21:19:29 +0000 (22:19 +0100)]
new spammer

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agodoh. Needs the argument as well
Stephen Gran [Tue, 5 Apr 2011 18:43:48 +0000 (19:43 +0100)]
doh.  Needs the argument as well

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agonew sudo line for dsa-nagios
Stephen Gran [Tue, 5 Apr 2011 18:41:18 +0000 (19:41 +0100)]
new sudo line for dsa-nagios

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agowe handle unbound.conf with puppet - please to ignore
Stephen Gran [Mon, 4 Apr 2011 07:06:41 +0000 (08:06 +0100)]
we handle unbound.conf with puppet - please to ignore

Signed-off-by: Stephen Gran <steve@lobefin.net>
13 years agoedmonds recommended against using draft dns-0x20 for resolves
Peter Palfrader [Sun, 3 Apr 2011 15:35:06 +0000 (17:35 +0200)]
edmonds recommended against using draft dns-0x20 for resolves

13 years agoumn forwarders break dnssec
Peter Palfrader [Sun, 3 Apr 2011 15:32:20 +0000 (17:32 +0200)]
umn forwarders break dnssec

They don't give us NSEC records for missing DS records,
e.g:

| weasel@saens:~$ dig @128.101.101.101 debian.com  -t ds +dnssec
|
| ; <<>> DiG 9.7.3 <<>> @128.101.101.101 debian.com -t ds +dnssec
| ; (1 server found)
| ;; global options: +cmd
| ;; Got answer:
| ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 13955
| ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 2, ADDITIONAL: 1
|
| ;; OPT PSEUDOSECTION:
| ; EDNS: version: 0, flags: do; udp: 4096
| ;; QUESTION SECTION:
| ;debian.com.                    IN      DS
|
| ;; AUTHORITY SECTION:
| com.                    527     IN      SOA     a.gtld-servers.net. nstld.verisign-grs.com. 1301844372 1800 900 604800 86400
| com.                    527     IN      RRSIG   SOA 8 1 900 20110410152612 20110403141612 1793 com. JFEZa5Kb5xJyibTSX4YySdz8fY53Vftd1VswlmEMJSkMyUIqq2zYWJm6 zvpK1y4RjE9Abv7vo5X8GcMuOg4TO31Pf6rAdloqYvcqZyFtu7DBoxYF A1lpz0w5Ru9stynHe4sNTk2xnbODzbZlW5DmUpPV4b1MjbxLgXkCyuLs H6o=
|
| ;; Query time: 1 msec
| ;; SERVER: 128.101.101.101#53(128.101.101.101)
| ;; WHEN: Sun Apr  3 15:32:58 2011
| ;; MSG SIZE  rcvd: 275

(no NSEC3 records)