Julien Cristau [Wed, 7 Nov 2018 21:07:37 +0000 (22:07 +0100)]
Install srvadmin foo on dell hosts, and move our restricted archive to debian_org::apt_restricted
Peter Palfrader [Wed, 7 Nov 2018 19:22:52 +0000 (20:22 +0100)]
and symlink
Peter Palfrader [Wed, 7 Nov 2018 19:19:00 +0000 (20:19 +0100)]
change megaraid_sas test
Peter Palfrader [Wed, 7 Nov 2018 19:09:24 +0000 (20:09 +0100)]
ftp.de.debian.org appears to be unavailable -- switch man-da to ftp2
Peter Palfrader [Wed, 7 Nov 2018 18:16:04 +0000 (19:16 +0100)]
different name for aptrepo
Peter Palfrader [Wed, 7 Nov 2018 18:13:02 +0000 (19:13 +0100)]
fix class
Peter Palfrader [Wed, 7 Nov 2018 18:11:47 +0000 (19:11 +0100)]
megaraid_sas
Peter Palfrader [Wed, 7 Nov 2018 18:08:38 +0000 (19:08 +0100)]
Add megaraid_sas facter
Julien Cristau [Wed, 7 Nov 2018 09:01:25 +0000 (10:01 +0100)]
Put grub and kernel on ttyS0 on manda-node0[34]
Peter Palfrader [Tue, 6 Nov 2018 08:04:53 +0000 (09:04 +0100)]
setup-dchroot: merge from tor (genname split into function, ubuntu updates)
- split schroot base name generation into its own function
- if we build an ubuntu chroot, upgrade to the latest packages available
in -updates and -security of their suite, since it seems they don't
ever do point releases so you end up with a 4 year old openssl in your
chroot.
Julien Cristau [Mon, 5 Nov 2018 19:21:57 +0000 (20:21 +0100)]
Temporarily switch off privacy logging for security.d.o
I want to figure out what clients are still hitting it directly,
especially at specific times, so some insight into User-Agents and
timestamps would be useful.
Julien Cristau [Sun, 4 Nov 2018 12:03:42 +0000 (13:03 +0100)]
Redirect all of security.d.o to security-cdn
Instead of just /pool/updates/main/l/linux/*, redirect everything except:
- if coming from fastly or aws
- if coming from nagios or mini-nag
- if using the onion service
- if doing a health check
Eventually we might point the security.d.o name directly at the CDN, but let's
see if this helps already.
Julien Cristau [Sat, 3 Nov 2018 15:11:23 +0000 (16:11 +0100)]
Exclude dsa-check-mirrorsync nagios check from security to security-cdn redirect
Julien Cristau [Sat, 3 Nov 2018 15:09:25 +0000 (16:09 +0100)]
Exclude nagios check_http from security to security-cdn redirect
Prep for making that redirect global
Julien Cristau [Fri, 2 Nov 2018 12:19:18 +0000 (13:19 +0100)]
Disable mod_disk_cache on security-tracker
Julien Cristau [Thu, 1 Nov 2018 17:34:33 +0000 (18:34 +0100)]
Drop sibelius from postgres-make-base-backups
Julien Cristau [Thu, 1 Nov 2018 17:32:53 +0000 (18:32 +0100)]
Drop firewall rule for pg @ sibelius
Julien Cristau [Thu, 1 Nov 2018 17:31:31 +0000 (18:31 +0100)]
Remove sibelius/snapshot from dsa-check-backuppg
Peter Palfrader [Wed, 31 Oct 2018 08:41:50 +0000 (09:41 +0100)]
unique all ip addresses
Peter Palfrader [Wed, 31 Oct 2018 08:39:06 +0000 (09:39 +0100)]
Try a unique around v4addrs
Peter Palfrader [Wed, 31 Oct 2018 08:34:17 +0000 (09:34 +0100)]
Peter Palfrader [Wed, 31 Oct 2018 08:05:47 +0000 (09:05 +0100)]
sibelius nfs on public net, 2
Peter Palfrader [Wed, 31 Oct 2018 08:05:09 +0000 (09:05 +0100)]
sibelius nfs on public net
Peter Palfrader [Tue, 30 Oct 2018 10:18:15 +0000 (11:18 +0100)]
make fail2ban cleanup job shut up
Peter Palfrader [Tue, 30 Oct 2018 09:45:11 +0000 (10:45 +0100)]
move DROP blacklists to ferm prio 005, after munin
Peter Palfrader [Tue, 30 Oct 2018 09:38:18 +0000 (10:38 +0100)]
manually create the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:32:31 +0000 (10:32 +0100)]
prevent the trailing ; after the subchain
Peter Palfrader [Tue, 30 Oct 2018 09:28:01 +0000 (10:28 +0100)]
move the fail2ban rules under the dsa-f2b chain
Peter Palfrader [Tue, 30 Oct 2018 09:23:42 +0000 (10:23 +0100)]
Move logging and related/established out of ferm.conf into a dsa.d rule
Peter Palfrader [Tue, 30 Oct 2018 09:21:31 +0000 (10:21 +0100)]
move munin rules from conf.d to the rules dir, 2
Peter Palfrader [Tue, 30 Oct 2018 09:20:32 +0000 (10:20 +0100)]
move munin rules from conf.d to the rules dir
Peter Palfrader [Tue, 30 Oct 2018 09:17:50 +0000 (10:17 +0100)]
rename interfaces to 50-munin-interfaces
Peter Palfrader [Tue, 30 Oct 2018 09:15:25 +0000 (10:15 +0100)]
merge munin_ip v4 and v6 into one rule
Peter Palfrader [Tue, 30 Oct 2018 09:07:46 +0000 (10:07 +0100)]
change default ferm rule priority to 10 from 00
Peter Palfrader [Tue, 30 Oct 2018 09:00:46 +0000 (10:00 +0100)]
also govern submission port
Peter Palfrader [Tue, 30 Oct 2018 08:57:53 +0000 (09:57 +0100)]
Clean up fail2ban database
Peter Palfrader [Sun, 28 Oct 2018 12:05:41 +0000 (13:05 +0100)]
more aggressive fail2ban on exim hosts
Peter Palfrader [Tue, 23 Oct 2018 16:29:04 +0000 (18:29 +0200)]
Add a second easydns ipv4 address
Peter Palfrader [Fri, 19 Oct 2018 12:03:12 +0000 (14:03 +0200)]
mirror-isc no longer has the disk to host -debug
Peter Palfrader [Fri, 19 Oct 2018 09:27:59 +0000 (11:27 +0200)]
Make mirror-conova an onion mirror for -debug
Peter Palfrader [Fri, 19 Oct 2018 08:58:23 +0000 (10:58 +0200)]
klecker no longer has the disk to host -debug
Peter Palfrader [Thu, 18 Oct 2018 12:54:24 +0000 (14:54 +0200)]
remove debian.fi
We added it at some point because we thought it'd be given to us,
but two years later it's still not delegated to us and the whois entry
doesn't show us as registrant either.
Peter Palfrader [Wed, 17 Oct 2018 13:14:35 +0000 (15:14 +0200)]
netnod call the key netnod-debian-
20171122
Peter Palfrader [Wed, 17 Oct 2018 13:11:27 +0000 (15:11 +0200)]
try to switch dnsnodeapi-ACL over to the TSIG key
Peter Palfrader [Tue, 16 Oct 2018 13:58:20 +0000 (15:58 +0200)]
try a HEREdoc as the syntax checker seems to have issues with multi-line strings
Peter Palfrader [Tue, 16 Oct 2018 13:54:35 +0000 (15:54 +0200)]
allow respighi to access udd on ullmann
it's used to create the autoremoval hints
Peter Palfrader [Tue, 16 Oct 2018 13:54:16 +0000 (15:54 +0200)]
merge ipv4 and ipv6 rule for ullmann's dsa-postgres-udd rule
Peter Palfrader [Tue, 16 Oct 2018 09:09:51 +0000 (11:09 +0200)]
allow ssh from ftpmaster to debug_mirrors
Julien Cristau [Tue, 16 Oct 2018 08:52:15 +0000 (10:52 +0200)]
debug_mirror: remove useless and broken filter
Julien Cristau [Tue, 16 Oct 2018 08:40:13 +0000 (10:40 +0200)]
Make hiera's debug_mirror look like debian_mirror
Peter Palfrader [Tue, 16 Oct 2018 08:37:38 +0000 (10:37 +0200)]
fix a prefix len in dsa-postgres-udd6
Julien Cristau [Tue, 16 Oct 2018 08:02:40 +0000 (10:02 +0200)]
Remove old klecker IP addresses
Julien Cristau [Tue, 16 Oct 2018 04:21:39 +0000 (06:21 +0200)]
Set up grub with serial console at leaseweb
Julien Cristau [Fri, 12 Oct 2018 12:47:48 +0000 (14:47 +0200)]
Add health check on debian-debug archive backends
Peter Palfrader [Fri, 12 Oct 2018 12:33:30 +0000 (14:33 +0200)]
Using *:80 as vhost on mirror-accumu
everything else is using *:80, so if we bind more specific things we
might get precedence we don't want.
Peter Palfrader [Fri, 12 Oct 2018 12:28:31 +0000 (14:28 +0200)]
fix onion_v4_addr in debug class
Peter Palfrader [Fri, 12 Oct 2018 12:26:37 +0000 (14:26 +0200)]
fix onion role for debug
Peter Palfrader [Fri, 12 Oct 2018 12:21:04 +0000 (14:21 +0200)]
put -debug webserver and onion config onto mirror-accumu
Peter Palfrader [Fri, 12 Oct 2018 09:11:52 +0000 (11:11 +0200)]
do fail2ban on postfix AUTH attempts on lists.d.o
Peter Palfrader [Thu, 11 Oct 2018 16:04:22 +0000 (18:04 +0200)]
retire old DNS root key
Peter Palfrader [Wed, 10 Oct 2018 09:19:35 +0000 (11:19 +0200)]
drop manual blacklist of smtp abusers
Peter Palfrader [Wed, 10 Oct 2018 09:19:12 +0000 (11:19 +0200)]
use fail2ban to block some abusive smtp clients on our MXs (re: RT#7515)
Peter Palfrader [Wed, 10 Oct 2018 08:34:08 +0000 (10:34 +0200)]
Add smtp_protocol_error to log_selector
We want to learn when clients try to use AUTH LOGIN and friends so we
can block them more easily.
Peter Palfrader [Wed, 10 Oct 2018 08:24:14 +0000 (10:24 +0200)]
more
Peter Palfrader [Wed, 10 Oct 2018 08:19:14 +0000 (10:19 +0200)]
more
Peter Palfrader [Wed, 10 Oct 2018 08:15:41 +0000 (10:15 +0200)]
netfilter DROP traffic from some mail abusers
Peter Palfrader [Wed, 10 Oct 2018 08:00:40 +0000 (10:00 +0200)]
Start with removing some moszumanska entries (in particular about pg backups). re: #7513)
Peter Palfrader [Tue, 9 Oct 2018 18:21:21 +0000 (20:21 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 4
Peter Palfrader [Tue, 9 Oct 2018 18:07:04 +0000 (20:07 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 3
Peter Palfrader [Tue, 9 Oct 2018 18:02:34 +0000 (20:02 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls, 2
Peter Palfrader [Tue, 9 Oct 2018 18:00:39 +0000 (20:00 +0200)]
Do not put our 29.172.in-addr.arpa zone into unbound configs behind fascist firewalls: 1st attempt
Peter Palfrader [Tue, 9 Oct 2018 09:43:40 +0000 (11:43 +0200)]
restart unbound after putting trust anchors in place
Paul Wise [Thu, 4 Oct 2018 07:53:46 +0000 (15:53 +0800)]
Use temporary redirects for ports redirects to the wiki
The URLs could change to the website or elsewhere at some point.
Suggested-by: weasel
Paul Wise [Thu, 4 Oct 2018 07:49:27 +0000 (15:49 +0800)]
Redirect popcon.d.o ports links that are 404 to the corresponding wiki pages
Paul Wise [Tue, 25 Sep 2018 02:27:04 +0000 (10:27 +0800)]
Add workaround for new Tor configuration requirement
See-also: https://trac.torproject.org/projects/tor/ticket/27849
Peter Palfrader [Fri, 14 Sep 2018 12:23:39 +0000 (14:23 +0200)]
we send mail from nagios@. make it exist
Peter Palfrader [Thu, 23 Aug 2018 07:46:56 +0000 (09:46 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket more
Peter Palfrader [Wed, 22 Aug 2018 09:14:56 +0000 (11:14 +0200)]
and get dependency right
Peter Palfrader [Wed, 22 Aug 2018 09:14:37 +0000 (11:14 +0200)]
Add munin-async service to the catalog
Peter Palfrader [Wed, 22 Aug 2018 09:11:11 +0000 (11:11 +0200)]
Set munin-async restart time to 10sec
Sometimes munin-async fails to start, presumably because it cannot
connect to the running munind yet. The service file tells it to
restart always, but with the default sleep time before a restart of
100ms we often run into
systemd[1]: munin-async.service: Start request repeated too quickly.
after 5 fails attempts within a second or two.
Give munind more time to actually launch.
Peter Palfrader [Wed, 22 Aug 2018 08:56:51 +0000 (10:56 +0200)]
Start repro only after we are online
It fails to bind to its IP addresses otherwise.
Peter Palfrader [Wed, 22 Aug 2018 08:15:29 +0000 (10:15 +0200)]
Try to samhain ignore /var/lib/puppet/clientbucket
Peter Palfrader [Tue, 21 Aug 2018 20:48:10 +0000 (22:48 +0200)]
Also ask our nagios check if drbd is fine
Peter Palfrader [Tue, 21 Aug 2018 20:46:34 +0000 (22:46 +0200)]
ganeti-reboot-cluster: wait for drbd to have caught up
Peter Palfrader [Tue, 21 Aug 2018 14:04:04 +0000 (16:04 +0200)]
and a mirror
Peter Palfrader [Tue, 21 Aug 2018 14:02:39 +0000 (16:02 +0200)]
larger net
Peter Palfrader [Tue, 21 Aug 2018 14:00:02 +0000 (16:00 +0200)]
one more net
Peter Palfrader [Tue, 21 Aug 2018 13:57:57 +0000 (15:57 +0200)]
the amazon crawlers change IP address as soon as they are blocked
Peter Palfrader [Tue, 21 Aug 2018 13:48:53 +0000 (15:48 +0200)]
blacklist more amazon aws
Peter Palfrader [Tue, 21 Aug 2018 10:09:44 +0000 (12:09 +0200)]
blacklist 18.185.157.46 and 18.194.174.202
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: remove jessie-kfreebsd hacks
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
99builddsourceslist: temporarily add stretch-proposed-updates to stretch-security chroots
Temporarily add stretch-proposed-updates for stretch-security chroots as requested
by the security team to handle Thunderbird and Firefox ESR 60.x releases. This should
be removed with the release of the 9.5 point release.
Aurelien Jarno [Mon, 20 Aug 2018 17:43:17 +0000 (19:43 +0200)]
setup-all-dchroots: fix architecture list generation
Peter Palfrader [Sun, 19 Aug 2018 20:18:01 +0000 (22:18 +0200)]
Try one fewer threads per snapshot process
Peter Palfrader [Sun, 19 Aug 2018 09:44:29 +0000 (11:44 +0200)]
remove old cleanup items
Peter Palfrader [Sun, 19 Aug 2018 09:43:10 +0000 (11:43 +0200)]
Move default webpage from apache to webserver module
Peter Palfrader [Sun, 19 Aug 2018 09:38:57 +0000 (11:38 +0200)]
Move creation of /run/dsa/shutdown-marker to a new common webserver module
Peter Palfrader [Thu, 16 Aug 2018 08:08:52 +0000 (10:08 +0200)]
setup-all-dchroots: Support rebuilding just one arch/suite
Peter Palfrader [Thu, 16 Aug 2018 08:07:17 +0000 (10:07 +0200)]
setup-all-dchroots: move DPKGARCH to where it's used
Peter Palfrader [Thu, 16 Aug 2018 08:05:03 +0000 (10:05 +0200)]
setup-all-dchroots: remove unused $UNAMEARCH