Peter Palfrader [Mon, 8 Feb 2016 17:50:52 +0000 (18:50 +0100)]
sort entries
Peter Palfrader [Mon, 8 Feb 2016 17:50:36 +0000 (18:50 +0100)]
Revert "Try to update Exclude list"
This reverts commit
2b213a07466209440b7d628a63a28ab489728889.
Peter Palfrader [Mon, 8 Feb 2016 17:48:52 +0000 (18:48 +0100)]
Try to update Exclude list
Peter Palfrader [Mon, 8 Feb 2016 17:13:50 +0000 (18:13 +0100)]
temporarily cut retention times
Julien Cristau [Sun, 7 Feb 2016 15:56:33 +0000 (16:56 +0100)]
update for new debian-ports archive signing key
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sun, 7 Feb 2016 14:20:52 +0000 (15:20 +0100)]
Add {pet,pet-devel} cert for petrova
Peter Palfrader [Sun, 7 Feb 2016 10:07:55 +0000 (10:07 +0000)]
Add dedup.d.n cert
Peter Palfrader [Sun, 7 Feb 2016 10:03:29 +0000 (10:03 +0000)]
TLSA for rsync sites
Peter Palfrader [Sun, 7 Feb 2016 09:55:32 +0000 (09:55 +0000)]
Update .gitignore
Peter Palfrader [Sun, 7 Feb 2016 09:55:22 +0000 (09:55 +0000)]
But remove the etckeeper-* files because they seem unused
Peter Palfrader [Sun, 7 Feb 2016 09:55:05 +0000 (09:55 +0000)]
Add uncommitted etckeeper-* things
Peter Palfrader [Sun, 7 Feb 2016 09:54:03 +0000 (09:54 +0000)]
Allow arrays for tlsaport to be passed to ssl::service
Peter Palfrader [Sun, 7 Feb 2016 09:52:05 +0000 (09:52 +0000)]
Commit local changes to fileserver.conf
Peter Palfrader [Sat, 6 Feb 2016 20:26:53 +0000 (21:26 +0100)]
fix whitespace
Peter Palfrader [Sat, 6 Feb 2016 20:11:04 +0000 (21:11 +0100)]
Ship ssl certs for i18n and l10n.d.o
Peter Palfrader [Sat, 6 Feb 2016 16:46:32 +0000 (17:46 +0100)]
remove www-master rsync
Peter Palfrader [Sat, 6 Feb 2016 16:46:10 +0000 (17:46 +0100)]
Make backups of santoro
Peter Palfrader [Sat, 6 Feb 2016 15:53:12 +0000 (15:53 +0000)]
uninstall static service certs and keys from hosts that do not serve this service
Peter Palfrader [Sat, 6 Feb 2016 15:38:31 +0000 (16:38 +0100)]
static: only install apache::site instances relevant for this mirror
Peter Palfrader [Sat, 6 Feb 2016 15:32:16 +0000 (16:32 +0100)]
static: only install ssl::service instances relevant for this mirror
Peter Palfrader [Sat, 6 Feb 2016 15:09:38 +0000 (16:09 +0100)]
santoro no longer is an old-style www mirror
Peter Palfrader [Sat, 6 Feb 2016 15:01:58 +0000 (16:01 +0100)]
santoro to staticsync (for www)
Peter Palfrader [Sat, 6 Feb 2016 15:01:28 +0000 (16:01 +0100)]
sort entries in hieradata
Julien Cristau [Fri, 5 Feb 2016 17:40:08 +0000 (18:40 +0100)]
move some of www.d.o's redirects to https
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Fri, 5 Feb 2016 17:16:22 +0000 (18:16 +0100)]
switch search.d.o to letsencrypt
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Fri, 5 Feb 2016 15:52:50 +0000 (16:52 +0100)]
remove tlsa for search.debian.org
Let's try to rotate keys without breaking stuff
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Thu, 4 Feb 2016 09:16:58 +0000 (10:16 +0100)]
Try different FileSet config
Peter Palfrader [Thu, 4 Feb 2016 09:04:58 +0000 (10:04 +0100)]
bacula: try ignoring /swapfile* instead of just /swapfile. Also set Ignore FileSet Changes to avoid a full backup run everywhere. And set Accurate = yes and enable acl and xattr support
Peter Palfrader [Thu, 4 Feb 2016 08:00:39 +0000 (09:00 +0100)]
Add certs for www-master and cgi.d.o
Peter Palfrader [Tue, 2 Feb 2016 21:19:19 +0000 (22:19 +0100)]
Add planet-search key too
Peter Palfrader [Tue, 2 Feb 2016 21:13:04 +0000 (22:13 +0100)]
Add planet-search role and cert
Peter Palfrader [Tue, 2 Feb 2016 17:34:23 +0000 (18:34 +0100)]
ssl for {10years,es,fr,miniconf10}.debconf.org
Peter Palfrader [Tue, 2 Feb 2016 10:07:56 +0000 (11:07 +0100)]
clean out some buildd.debian-ports.org/portman stuff
Peter Palfrader [Tue, 2 Feb 2016 07:59:53 +0000 (08:59 +0100)]
ssl for {news,debaday,timeline}.debian.net, debconf[4567].debconf.org
Peter Palfrader [Tue, 2 Feb 2016 06:46:50 +0000 (07:46 +0100)]
Add default SSL site
Peter Palfrader [Tue, 2 Feb 2016 06:46:10 +0000 (07:46 +0100)]
There is no spohr.debian.org anymore
Peter Palfrader [Mon, 1 Feb 2016 21:34:34 +0000 (22:34 +0100)]
rsync ssl on ftp-master
Peter Palfrader [Mon, 1 Feb 2016 21:31:42 +0000 (21:31 +0000)]
Move rsync ssl setup into the rsync module
Julien Cristau [Mon, 1 Feb 2016 19:49:30 +0000 (20:49 +0100)]
Add "DST Root CA X3" to ca-debian
It signed Let's Encrypt's CA.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Mon, 1 Feb 2016 19:04:23 +0000 (20:04 +0100)]
And redirect .net to .org
Peter Palfrader [Mon, 1 Feb 2016 18:58:45 +0000 (19:58 +0100)]
Revert "Set WSGIScriptReloading On"
This reverts commit
73898a88dbf0245dc94c3f8decac8ccbb7546391.
Peter Palfrader [Mon, 1 Feb 2016 18:57:37 +0000 (19:57 +0100)]
Set WSGIScriptReloading On
Peter Palfrader [Mon, 1 Feb 2016 18:23:08 +0000 (19:23 +0100)]
Update debtags.d.o vhost
Peter Palfrader [Mon, 1 Feb 2016 18:06:02 +0000 (19:06 +0100)]
give tate access to the pg on bmdb1
Peter Palfrader [Mon, 1 Feb 2016 08:19:46 +0000 (09:19 +0100)]
dsa-rsync-ssl ferm on v6 also
Peter Palfrader [Sun, 31 Jan 2016 21:58:13 +0000 (22:58 +0100)]
dsa rsync ssl ferm
Peter Palfrader [Sun, 31 Jan 2016 21:56:49 +0000 (22:56 +0100)]
add template
Peter Palfrader [Sun, 31 Jan 2016 21:56:26 +0000 (22:56 +0100)]
rsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:54:49 +0000 (22:54 +0100)]
rsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:52:15 +0000 (22:52 +0100)]
rsync ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 21:47:15 +0000 (22:47 +0100)]
fermport for xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 21:41:22 +0000 (22:41 +0100)]
typo
Peter Palfrader [Sun, 31 Jan 2016 21:40:20 +0000 (22:40 +0100)]
one place missed
Peter Palfrader [Sun, 31 Jan 2016 21:38:53 +0000 (22:38 +0100)]
split service and port in xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 19:12:10 +0000 (20:12 +0100)]
try it as a class
Peter Palfrader [Sun, 31 Jan 2016 19:10:29 +0000 (20:10 +0100)]
Cannot re-declare ssl
Peter Palfrader [Sun, 31 Jan 2016 19:09:51 +0000 (20:09 +0100)]
enable ssl
Peter Palfrader [Sun, 31 Jan 2016 19:05:08 +0000 (20:05 +0100)]
try ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 17:58:06 +0000 (17:58 +0000)]
ssl for debconf[23]
Peter Palfrader [Sun, 31 Jan 2016 17:48:02 +0000 (18:48 +0100)]
remove useless block
Peter Palfrader [Sun, 31 Jan 2016 17:45:26 +0000 (18:45 +0100)]
ssl for debconf[01]
Peter Palfrader [Sun, 31 Jan 2016 17:22:19 +0000 (17:22 +0000)]
Add tate to sso-rp
Peter Palfrader [Sun, 31 Jan 2016 17:21:45 +0000 (17:21 +0000)]
ship debtags key
Peter Palfrader [Sun, 31 Jan 2016 17:16:02 +0000 (18:16 +0100)]
fix paths
Peter Palfrader [Sun, 31 Jan 2016 17:13:39 +0000 (18:13 +0100)]
Add debtags role
Peter Palfrader [Sun, 31 Jan 2016 17:06:50 +0000 (17:06 +0000)]
fix TLSA records with multiple cert locations
Peter Palfrader [Sun, 31 Jan 2016 17:02:36 +0000 (17:02 +0000)]
Append chain if exists
Peter Palfrader [Sun, 31 Jan 2016 17:01:53 +0000 (17:01 +0000)]
Append chain if exists
Peter Palfrader [Sun, 31 Jan 2016 16:57:55 +0000 (17:57 +0100)]
handle array of certfiles
Peter Palfrader [Sun, 31 Jan 2016 16:54:23 +0000 (17:54 +0100)]
Get certs from the LE dir also
Peter Palfrader [Sun, 31 Jan 2016 16:20:28 +0000 (17:20 +0100)]
Add tate
Peter Palfrader [Sun, 31 Jan 2016 15:56:09 +0000 (16:56 +0100)]
Add tate
Peter Palfrader [Sun, 31 Jan 2016 14:02:20 +0000 (15:02 +0100)]
letsencrypt can trigger zone file update
Peter Palfrader [Tue, 26 Jan 2016 14:38:13 +0000 (15:38 +0100)]
retire unused rsync modules on ftp-master
Iain R. Learmonth [Sun, 24 Jan 2016 16:15:34 +0000 (16:15 +0000)]
Redirects /doc/manuals/ to /doc/
The /doc/manuals/ folder contains manuals that are built as part of the
webwml process, but does not contain an index file. /doc/ is the logical
index file for this, so redirect to that to avoid just providing an
Apache index listing. (Fixes: #694927)
Signed-off-by: Peter Palfrader <peter@palfrader.org>
Julien Cristau [Sun, 24 Jan 2016 16:09:01 +0000 (17:09 +0100)]
fix ipv6 netrange for anu
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 23 Jan 2016 17:51:53 +0000 (18:51 +0100)]
local mirror for .au servers
Peter Palfrader [Fri, 22 Jan 2016 20:01:44 +0000 (21:01 +0100)]
bytemark has debian-debug
Peter Palfrader [Sun, 17 Jan 2016 20:58:58 +0000 (21:58 +0100)]
http-redir role with apache config
Peter Palfrader [Sun, 17 Jan 2016 18:54:36 +0000 (19:54 +0100)]
p-u for kfreebsd
Julien Cristau [Sun, 17 Jan 2016 15:42:23 +0000 (16:42 +0100)]
lvm.conf for clementi and czerny
Signed-off-by: Julien Cristau <jcristau@debian.org>
Aurelien Jarno [Sat, 16 Jan 2016 17:25:48 +0000 (18:25 +0100)]
buildds: force SHA512 signatures
Provide a ~/.gnupg/gpg.conf on the buildds to force SHA512 signatures.
Otherwise gpg still uses to SHA1 by default...
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Sat, 16 Jan 2016 15:43:00 +0000 (16:43 +0100)]
gnt on -14
Peter Palfrader [Fri, 15 Jan 2016 20:04:34 +0000 (21:04 +0100)]
blades update bm
Peter Palfrader [Wed, 13 Jan 2016 09:28:47 +0000 (10:28 +0100)]
Add bmdb1-lvm2 and dillon-lvm2 wwids
Peter Palfrader [Tue, 12 Jan 2016 08:23:46 +0000 (09:23 +0100)]
Fix path name (etc/rsyncd instead of /etc/rsync)
Peter Palfrader [Tue, 12 Jan 2016 08:14:23 +0000 (09:14 +0100)]
Do push -anu on static updates
Peter Palfrader [Tue, 12 Jan 2016 08:14:06 +0000 (09:14 +0100)]
-anu static address
Peter Palfrader [Tue, 12 Jan 2016 08:07:18 +0000 (09:07 +0100)]
enable -anu security addresses
Peter Palfrader [Mon, 11 Jan 2016 17:28:34 +0000 (18:28 +0100)]
samhain ignore: /etc/rsyncd/debian.secrets is handled by the mirror team
Peter Palfrader [Mon, 11 Jan 2016 11:54:31 +0000 (11:54 +0000)]
fix syncproxy manifest site name
Peter Palfrader [Mon, 11 Jan 2016 11:51:31 +0000 (12:51 +0100)]
have security rsync bind to specific address
Peter Palfrader [Mon, 11 Jan 2016 11:46:02 +0000 (12:46 +0100)]
Add IP addresses for mirror-anu in its role as syncproxy.au
Paul Wise [Sun, 10 Jan 2016 22:15:00 +0000 (06:15 +0800)]
Give d-i folks access to rebuild the d-i website
Aurelien Jarno [Sat, 9 Jan 2016 15:04:20 +0000 (16:04 +0100)]
rng-tools: yet another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:19:49 +0000 (15:19 +0100)]
rng-tools: another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:02:58 +0000 (15:02 +0100)]
Enable rng-tools module on linux
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 13:22:08 +0000 (14:22 +0100)]
Install rng-tools if there is a /dev/hwrng device
We can then provide entropy to the guests using virtio-rng.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Fri, 8 Jan 2016 21:12:57 +0000 (21:12 +0000)]
Make an apache site for syncproxies
Peter Palfrader [Fri, 8 Jan 2016 21:12:35 +0000 (21:12 +0000)]
use https in our default index page