Peter Palfrader [Wed, 8 Apr 2009 08:07:51 +0000 (10:07 +0200)]
areca-cli on powell for nagios
Peter Palfrader [Wed, 8 Apr 2009 08:04:41 +0000 (10:04 +0200)]
two comment files
Peter Palfrader [Wed, 8 Apr 2009 08:03:26 +0000 (10:03 +0200)]
ravel and d-i
Peter Palfrader [Wed, 8 Apr 2009 08:02:07 +0000 (10:02 +0200)]
chopin
Peter Palfrader [Wed, 8 Apr 2009 08:01:00 +0000 (10:01 +0200)]
raff and groups wbadm, keyring, and debadmin. And wbadm's update-buildd-sshkeys job
Peter Palfrader [Wed, 8 Apr 2009 08:00:05 +0000 (10:00 +0200)]
mahler
Peter Palfrader [Wed, 8 Apr 2009 07:58:31 +0000 (09:58 +0200)]
mahler
Peter Palfrader [Wed, 8 Apr 2009 07:58:00 +0000 (09:58 +0200)]
tartini and new group forums
Peter Palfrader [Wed, 8 Apr 2009 07:57:06 +0000 (09:57 +0200)]
unger, and Ganneff's sispm
Peter Palfrader [Wed, 8 Apr 2009 07:55:36 +0000 (09:55 +0200)]
rietz
Peter Palfrader [Wed, 8 Apr 2009 07:54:39 +0000 (09:54 +0200)]
gluck and more groups: debwww, lintian, planet, popcon, snapshot
Peter Palfrader [Wed, 8 Apr 2009 07:50:31 +0000 (09:50 +0200)]
samosa: %adm may reload bind without password
Peter Palfrader [Wed, 8 Apr 2009 07:47:52 +0000 (09:47 +0200)]
Whitespace changes, line re-ordering, and a comment
Peter Palfrader [Wed, 8 Apr 2009 07:45:36 +0000 (09:45 +0200)]
new group: pkg_maint, and on powell that needs to trigger archvsync
Peter Palfrader [Wed, 8 Apr 2009 07:43:23 +0000 (09:43 +0200)]
piatti: more groups (uddadm, debbugs, piuparts) and piupartss needs root for chroot stuff
Peter Palfrader [Wed, 8 Apr 2009 07:43:17 +0000 (09:43 +0200)]
piatti: more groups (uddadm, debbugs, piuparts) and piupartss needs root for chroot stuff
Peter Palfrader [Wed, 8 Apr 2009 07:40:57 +0000 (09:40 +0200)]
local admin on agnesi
Peter Palfrader [Wed, 8 Apr 2009 07:40:01 +0000 (09:40 +0200)]
local admin group on zelenka
Peter Palfrader [Wed, 8 Apr 2009 07:37:44 +0000 (09:37 +0200)]
wikiadm/widor
Peter Palfrader [Wed, 8 Apr 2009 07:36:13 +0000 (09:36 +0200)]
A whole set of standard hosts
Peter Palfrader [Tue, 7 Apr 2009 23:39:12 +0000 (01:39 +0200)]
3 more hosts on puppet sudo
Peter Palfrader [Tue, 7 Apr 2009 23:32:16 +0000 (01:32 +0200)]
Obligatory puppet disclaimer
Peter Palfrader [Tue, 7 Apr 2009 23:20:31 +0000 (01:20 +0200)]
Fix a typo
Peter Palfrader [Tue, 7 Apr 2009 23:13:57 +0000 (01:13 +0200)]
Add logrotate config for apache
Peter Palfrader [Tue, 7 Apr 2009 22:50:42 +0000 (00:50 +0200)]
And a few more hosts
Peter Palfrader [Tue, 7 Apr 2009 22:36:38 +0000 (00:36 +0200)]
rm sperger.debian.org/sudoers
Peter Palfrader [Tue, 7 Apr 2009 22:36:19 +0000 (00:36 +0200)]
/usr/sbin/upgrade-porter-chroots for adm
Peter Palfrader [Tue, 7 Apr 2009 22:34:12 +0000 (00:34 +0200)]
rm carver.debian.org/sudoers
Peter Palfrader [Tue, 7 Apr 2009 22:33:55 +0000 (00:33 +0200)]
Add apachectrl group
Peter Palfrader [Tue, 7 Apr 2009 22:31:08 +0000 (00:31 +0200)]
rm rore.debian.org/sudoers
Peter Palfrader [Tue, 7 Apr 2009 22:30:51 +0000 (00:30 +0200)]
Let nagios check SA controllers
Peter Palfrader [Tue, 7 Apr 2009 22:23:55 +0000 (00:23 +0200)]
On a few more hosts
Peter Palfrader [Tue, 7 Apr 2009 22:22:08 +0000 (00:22 +0200)]
rm malo.debian.org/sudoers
Peter Palfrader [Tue, 7 Apr 2009 22:21:49 +0000 (00:21 +0200)]
Add buildd
Peter Palfrader [Tue, 7 Apr 2009 22:20:57 +0000 (00:20 +0200)]
rm wieck.debian.org/sudoers
Peter Palfrader [Tue, 7 Apr 2009 22:20:40 +0000 (00:20 +0200)]
whitespace
Peter Palfrader [Tue, 7 Apr 2009 22:19:50 +0000 (00:19 +0200)]
mirroradm gets access to archvsync everywhere
Peter Palfrader [Tue, 7 Apr 2009 22:19:25 +0000 (00:19 +0200)]
comments
Peter Palfrader [Tue, 7 Apr 2009 22:17:51 +0000 (00:17 +0200)]
Removed geo*/sudoers - they were all equal and a subset of common
Peter Palfrader [Tue, 7 Apr 2009 22:16:21 +0000 (00:16 +0200)]
nagios no longer calls samhain
Peter Palfrader [Tue, 7 Apr 2009 22:15:41 +0000 (00:15 +0200)]
Tell the lazy DSA to use visudo or forever be damned
Peter Palfrader [Tue, 7 Apr 2009 22:13:17 +0000 (00:13 +0200)]
Move handel's sudoers to common - it will be the template to start from
Peter Palfrader [Tue, 7 Apr 2009 22:11:24 +0000 (00:11 +0200)]
Remove sudo from debian-org manifest
Peter Palfrader [Tue, 7 Apr 2009 22:09:34 +0000 (00:09 +0200)]
Start testing sudo on handel
Peter Palfrader [Tue, 7 Apr 2009 22:08:47 +0000 (00:08 +0200)]
Add sudoers files
Stephen Gran [Tue, 7 Apr 2009 21:44:24 +0000 (22:44 +0100)]
Ignore the new file shipped out
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 21:39:58 +0000 (22:39 +0100)]
Some more domains for spohr to relay
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Tue, 7 Apr 2009 21:29:40 +0000 (23:29 +0200)]
Mention sponsors
Peter Palfrader [Tue, 7 Apr 2009 21:23:16 +0000 (23:23 +0200)]
Sentences end with a full stop
Peter Palfrader [Tue, 7 Apr 2009 21:20:17 +0000 (23:20 +0200)]
This is my version of mkdir -p
Peter Palfrader [Tue, 7 Apr 2009 21:17:06 +0000 (23:17 +0200)]
So, if you require a package in a files block you also need to declare it
Peter Palfrader [Tue, 7 Apr 2009 21:15:44 +0000 (23:15 +0200)]
Another silly instance of picky parsers. Clearly I meant include
Peter Palfrader [Tue, 7 Apr 2009 21:13:35 +0000 (23:13 +0200)]
I wonder if quoting does change anything
Stephen Gran [Tue, 7 Apr 2009 21:11:20 +0000 (22:11 +0100)]
Fix hostlist
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 21:08:35 +0000 (22:08 +0100)]
Some fixup for submission mode
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 21:02:06 +0000 (22:02 +0100)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Tue, 7 Apr 2009 21:01:44 +0000 (22:01 +0100)]
we also need to accept mail for local domains on 587, strangely
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Tue, 7 Apr 2009 21:00:15 +0000 (23:00 +0200)]
Try to resolve syntax bug
Peter Palfrader [Tue, 7 Apr 2009 20:58:38 +0000 (22:58 +0200)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Tue, 7 Apr 2009 20:57:58 +0000 (21:57 +0100)]
do recipient verification for mailhubdomains correctly
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Tue, 7 Apr 2009 20:57:51 +0000 (22:57 +0200)]
Enable apache2 just for carver
Peter Palfrader [Tue, 7 Apr 2009 20:56:22 +0000 (22:56 +0200)]
Add apache2 module
Stephen Gran [Tue, 7 Apr 2009 20:46:24 +0000 (21:46 +0100)]
Stop ignoring my own advice about syntax for alternate ports
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:42:16 +0000 (21:42 +0100)]
really accept localhost
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:40:31 +0000 (21:40 +0100)]
Accept localhost
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:37:06 +0000 (21:37 +0100)]
Stupid macro parser not liking substrings
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:35:01 +0000 (21:35 +0100)]
Move firewall definition
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:31:54 +0000 (21:31 +0100)]
lafayette relay rules
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:25:19 +0000 (21:25 +0100)]
Syntax error
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:24:07 +0000 (21:24 +0100)]
Also serve local-settings.conf
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:20:46 +0000 (21:20 +0100)]
Send local setttings as well
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:17:01 +0000 (21:17 +0100)]
spohr should relay out for lafayette
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:12:17 +0000 (21:12 +0100)]
lafayette is behind a broken firewall
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Tue, 7 Apr 2009 20:09:31 +0000 (21:09 +0100)]
spohr should relay mail to lafayette
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 6 Apr 2009 00:25:07 +0000 (01:25 +0100)]
Ignore a file generated by an automatic upgrade
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 6 Apr 2009 00:11:45 +0000 (01:11 +0100)]
Short test - this is the wrong way to do it, but lets see if the idea
works
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 16:18:06 +0000 (17:18 +0100)]
Comment out the require options for now. This is just making noise in
the logs. I hate gnutls.
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 13:12:39 +0000 (14:12 +0100)]
Using the right name helps
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 12:50:03 +0000 (13:50 +0100)]
Allow relaying by certs
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 12:44:35 +0000 (13:44 +0100)]
Add mailhubdomains for hub/spoke setup
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 12:34:59 +0000 (13:34 +0100)]
Make client verify server cert as well
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 11:43:40 +0000 (12:43 +0100)]
Always ask for cert
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 10:32:52 +0000 (11:32 +0100)]
and samhain for same
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 10:30:20 +0000 (11:30 +0100)]
Add /etc/timezone to puppet.
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 03:02:25 +0000 (04:02 +0100)]
And fix the syntax error
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 03:00:38 +0000 (04:00 +0100)]
Gratuitous change to force exim reload
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 02:58:40 +0000 (03:58 +0100)]
We need to HUP exim after changing macro definitions
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 01:56:49 +0000 (02:56 +0100)]
It's Facter, not facter
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 01:47:05 +0000 (02:47 +0100)]
samhain ignore new exim file
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 01:33:46 +0000 (02:33 +0100)]
Add skeleton manualroute file to exim setup
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 01:09:02 +0000 (02:09 +0100)]
Make TLS usage in exim conditional on having the infrastructure to do
so. It's a little racy, so I don't want to make exim whine about it
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 00:11:20 +0000 (01:11 +0100)]
samhain ignore the ssl infrastructure for exim
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 5 Apr 2009 00:02:03 +0000 (01:02 +0100)]
Correct path for ca cert, and add crl checking (this may not work, but
let's see)
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 23:30:25 +0000 (00:30 +0100)]
Also ship the ca.crt and ca.crl to exim
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 23:17:42 +0000 (00:17 +0100)]
Add logs.buildd.debian.org on raff
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 23:06:39 +0000 (00:06 +0100)]
Make exim use tls certs distributed by puppet
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 22:58:36 +0000 (23:58 +0100)]
Again
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 22:57:35 +0000 (23:57 +0100)]
Oh, you picky picky parser
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sat, 4 Apr 2009 22:45:49 +0000 (23:45 +0100)]
Merge branch 'master' of ssh://handel.debian.org/srv/puppet.debian.org/git/dsa-puppet
Stephen Gran [Sat, 4 Apr 2009 22:45:32 +0000 (23:45 +0100)]
Ship exim ssl certs
Signed-off-by: Stephen Gran <steve@lobefin.net>