Peter Palfrader [Tue, 2 Feb 2016 10:07:56 +0000 (11:07 +0100)]
clean out some buildd.debian-ports.org/portman stuff
Peter Palfrader [Tue, 2 Feb 2016 07:59:53 +0000 (08:59 +0100)]
ssl for {news,debaday,timeline}.debian.net, debconf[4567].debconf.org
Peter Palfrader [Tue, 2 Feb 2016 06:46:50 +0000 (07:46 +0100)]
Add default SSL site
Peter Palfrader [Tue, 2 Feb 2016 06:46:10 +0000 (07:46 +0100)]
There is no spohr.debian.org anymore
Peter Palfrader [Mon, 1 Feb 2016 21:34:34 +0000 (22:34 +0100)]
rsync ssl on ftp-master
Peter Palfrader [Mon, 1 Feb 2016 21:31:42 +0000 (21:31 +0000)]
Move rsync ssl setup into the rsync module
Julien Cristau [Mon, 1 Feb 2016 19:49:30 +0000 (20:49 +0100)]
Add "DST Root CA X3" to ca-debian
It signed Let's Encrypt's CA.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Mon, 1 Feb 2016 19:04:23 +0000 (20:04 +0100)]
And redirect .net to .org
Peter Palfrader [Mon, 1 Feb 2016 18:58:45 +0000 (19:58 +0100)]
Revert "Set WSGIScriptReloading On"
This reverts commit
73898a88dbf0245dc94c3f8decac8ccbb7546391.
Peter Palfrader [Mon, 1 Feb 2016 18:57:37 +0000 (19:57 +0100)]
Set WSGIScriptReloading On
Peter Palfrader [Mon, 1 Feb 2016 18:23:08 +0000 (19:23 +0100)]
Update debtags.d.o vhost
Peter Palfrader [Mon, 1 Feb 2016 18:06:02 +0000 (19:06 +0100)]
give tate access to the pg on bmdb1
Peter Palfrader [Mon, 1 Feb 2016 08:19:46 +0000 (09:19 +0100)]
dsa-rsync-ssl ferm on v6 also
Peter Palfrader [Sun, 31 Jan 2016 21:58:13 +0000 (22:58 +0100)]
dsa rsync ssl ferm
Peter Palfrader [Sun, 31 Jan 2016 21:56:49 +0000 (22:56 +0100)]
add template
Peter Palfrader [Sun, 31 Jan 2016 21:56:26 +0000 (22:56 +0100)]
rsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:54:49 +0000 (22:54 +0100)]
rsync ssl service, more
Peter Palfrader [Sun, 31 Jan 2016 21:52:15 +0000 (22:52 +0100)]
rsync ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 21:47:15 +0000 (22:47 +0100)]
fermport for xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 21:41:22 +0000 (22:41 +0100)]
typo
Peter Palfrader [Sun, 31 Jan 2016 21:40:20 +0000 (22:40 +0100)]
one place missed
Peter Palfrader [Sun, 31 Jan 2016 21:38:53 +0000 (22:38 +0100)]
split service and port in xinetd::service
Peter Palfrader [Sun, 31 Jan 2016 19:12:10 +0000 (20:12 +0100)]
try it as a class
Peter Palfrader [Sun, 31 Jan 2016 19:10:29 +0000 (20:10 +0100)]
Cannot re-declare ssl
Peter Palfrader [Sun, 31 Jan 2016 19:09:51 +0000 (20:09 +0100)]
enable ssl
Peter Palfrader [Sun, 31 Jan 2016 19:05:08 +0000 (20:05 +0100)]
try ssl on syncproxies
Peter Palfrader [Sun, 31 Jan 2016 17:58:06 +0000 (17:58 +0000)]
ssl for debconf[23]
Peter Palfrader [Sun, 31 Jan 2016 17:48:02 +0000 (18:48 +0100)]
remove useless block
Peter Palfrader [Sun, 31 Jan 2016 17:45:26 +0000 (18:45 +0100)]
ssl for debconf[01]
Peter Palfrader [Sun, 31 Jan 2016 17:22:19 +0000 (17:22 +0000)]
Add tate to sso-rp
Peter Palfrader [Sun, 31 Jan 2016 17:21:45 +0000 (17:21 +0000)]
ship debtags key
Peter Palfrader [Sun, 31 Jan 2016 17:16:02 +0000 (18:16 +0100)]
fix paths
Peter Palfrader [Sun, 31 Jan 2016 17:13:39 +0000 (18:13 +0100)]
Add debtags role
Peter Palfrader [Sun, 31 Jan 2016 17:06:50 +0000 (17:06 +0000)]
fix TLSA records with multiple cert locations
Peter Palfrader [Sun, 31 Jan 2016 17:02:36 +0000 (17:02 +0000)]
Append chain if exists
Peter Palfrader [Sun, 31 Jan 2016 17:01:53 +0000 (17:01 +0000)]
Append chain if exists
Peter Palfrader [Sun, 31 Jan 2016 16:57:55 +0000 (17:57 +0100)]
handle array of certfiles
Peter Palfrader [Sun, 31 Jan 2016 16:54:23 +0000 (17:54 +0100)]
Get certs from the LE dir also
Peter Palfrader [Sun, 31 Jan 2016 16:20:28 +0000 (17:20 +0100)]
Add tate
Peter Palfrader [Sun, 31 Jan 2016 15:56:09 +0000 (16:56 +0100)]
Add tate
Peter Palfrader [Sun, 31 Jan 2016 14:02:20 +0000 (15:02 +0100)]
letsencrypt can trigger zone file update
Peter Palfrader [Tue, 26 Jan 2016 14:38:13 +0000 (15:38 +0100)]
retire unused rsync modules on ftp-master
Iain R. Learmonth [Sun, 24 Jan 2016 16:15:34 +0000 (16:15 +0000)]
Redirects /doc/manuals/ to /doc/
The /doc/manuals/ folder contains manuals that are built as part of the
webwml process, but does not contain an index file. /doc/ is the logical
index file for this, so redirect to that to avoid just providing an
Apache index listing. (Fixes: #694927)
Signed-off-by: Peter Palfrader <peter@palfrader.org>
Julien Cristau [Sun, 24 Jan 2016 16:09:01 +0000 (17:09 +0100)]
fix ipv6 netrange for anu
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 23 Jan 2016 17:51:53 +0000 (18:51 +0100)]
local mirror for .au servers
Peter Palfrader [Fri, 22 Jan 2016 20:01:44 +0000 (21:01 +0100)]
bytemark has debian-debug
Peter Palfrader [Sun, 17 Jan 2016 20:58:58 +0000 (21:58 +0100)]
http-redir role with apache config
Peter Palfrader [Sun, 17 Jan 2016 18:54:36 +0000 (19:54 +0100)]
p-u for kfreebsd
Julien Cristau [Sun, 17 Jan 2016 15:42:23 +0000 (16:42 +0100)]
lvm.conf for clementi and czerny
Signed-off-by: Julien Cristau <jcristau@debian.org>
Aurelien Jarno [Sat, 16 Jan 2016 17:25:48 +0000 (18:25 +0100)]
buildds: force SHA512 signatures
Provide a ~/.gnupg/gpg.conf on the buildds to force SHA512 signatures.
Otherwise gpg still uses to SHA1 by default...
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Sat, 16 Jan 2016 15:43:00 +0000 (16:43 +0100)]
gnt on -14
Peter Palfrader [Fri, 15 Jan 2016 20:04:34 +0000 (21:04 +0100)]
blades update bm
Peter Palfrader [Wed, 13 Jan 2016 09:28:47 +0000 (10:28 +0100)]
Add bmdb1-lvm2 and dillon-lvm2 wwids
Peter Palfrader [Tue, 12 Jan 2016 08:23:46 +0000 (09:23 +0100)]
Fix path name (etc/rsyncd instead of /etc/rsync)
Peter Palfrader [Tue, 12 Jan 2016 08:14:23 +0000 (09:14 +0100)]
Do push -anu on static updates
Peter Palfrader [Tue, 12 Jan 2016 08:14:06 +0000 (09:14 +0100)]
-anu static address
Peter Palfrader [Tue, 12 Jan 2016 08:07:18 +0000 (09:07 +0100)]
enable -anu security addresses
Peter Palfrader [Mon, 11 Jan 2016 17:28:34 +0000 (18:28 +0100)]
samhain ignore: /etc/rsyncd/debian.secrets is handled by the mirror team
Peter Palfrader [Mon, 11 Jan 2016 11:54:31 +0000 (11:54 +0000)]
fix syncproxy manifest site name
Peter Palfrader [Mon, 11 Jan 2016 11:51:31 +0000 (12:51 +0100)]
have security rsync bind to specific address
Peter Palfrader [Mon, 11 Jan 2016 11:46:02 +0000 (12:46 +0100)]
Add IP addresses for mirror-anu in its role as syncproxy.au
Paul Wise [Sun, 10 Jan 2016 22:15:00 +0000 (06:15 +0800)]
Give d-i folks access to rebuild the d-i website
Aurelien Jarno [Sat, 9 Jan 2016 15:04:20 +0000 (16:04 +0100)]
rng-tools: yet another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:19:49 +0000 (15:19 +0100)]
rng-tools: another try to fix it
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 14:02:58 +0000 (15:02 +0100)]
Enable rng-tools module on linux
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 9 Jan 2016 13:22:08 +0000 (14:22 +0100)]
Install rng-tools if there is a /dev/hwrng device
We can then provide entropy to the guests using virtio-rng.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Fri, 8 Jan 2016 21:12:57 +0000 (21:12 +0000)]
Make an apache site for syncproxies
Peter Palfrader [Fri, 8 Jan 2016 21:12:35 +0000 (21:12 +0000)]
use https in our default index page
Peter Palfrader [Fri, 8 Jan 2016 20:35:26 +0000 (21:35 +0100)]
vars need a $
Peter Palfrader [Fri, 8 Jan 2016 20:34:01 +0000 (21:34 +0100)]
move bind addresses to vars
Peter Palfrader [Fri, 8 Jan 2016 20:30:31 +0000 (21:30 +0100)]
klecker gets dsa-rsync from being a syncproxy
Peter Palfrader [Fri, 8 Jan 2016 20:29:17 +0000 (21:29 +0100)]
Add klecker to the syncproxy role
Peter Palfrader [Fri, 8 Jan 2016 08:35:54 +0000 (09:35 +0100)]
remove schein from security-mirror group
Aurelien Jarno [Thu, 7 Jan 2016 15:41:12 +0000 (16:41 +0100)]
debian.c3sl.ufpr.br is actually ftp.br.debian.org
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Thu, 7 Jan 2016 15:37:15 +0000 (16:37 +0100)]
update unicamp netrange
In addition, use the whole range allocated to unicamp instead of the
debian range to cope with (fortunately unlikely) future IP changes.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Wed, 6 Jan 2016 21:32:26 +0000 (22:32 +0100)]
Get rid of buildd-{lenny,squeeze,wheezy} shares on security-master rsync
Peter Palfrader [Wed, 6 Jan 2016 21:31:36 +0000 (22:31 +0100)]
log rsync for syncproxy and security to dedicated logs
Peter Palfrader [Wed, 6 Jan 2016 12:28:43 +0000 (13:28 +0100)]
No SRV support in jessie apt
Peter Palfrader [Wed, 6 Jan 2016 12:27:30 +0000 (13:27 +0100)]
Use deb.debian.org as the default mirror to test it
Peter Palfrader [Wed, 6 Jan 2016 12:26:46 +0000 (13:26 +0100)]
mirror.nl.leaseweb.nl is out of date
Peter Palfrader [Mon, 4 Jan 2016 20:40:37 +0000 (21:40 +0100)]
Add mirror-umn to syncproxy
Peter Palfrader [Mon, 4 Jan 2016 20:40:22 +0000 (21:40 +0100)]
set security IP address for mirror-umn
Julien Cristau [Sat, 2 Jan 2016 22:40:38 +0000 (23:40 +0100)]
Better if the static mirrors get the d-i.d.o cert
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:36:19 +0000 (23:36 +0100)]
HTTPS for d-i.debian.org (rt#6049)
Drop the ServerAlias, we're not using it and the ssl macro doesn't mix
with extra.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:28:21 +0000 (23:28 +0100)]
Revert "static-mirroring: add common-static-vhost-ssl-with-extra macro"
This reverts commit
8f4f534e4d36f406477077c09d113982014e49e9.
That's not going to work out.
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:22:20 +0000 (23:22 +0100)]
static-mirroring: add common-static-vhost-ssl-with-extra macro
Signed-off-by: Julien Cristau <jcristau@debian.org>
Julien Cristau [Sat, 2 Jan 2016 22:00:54 +0000 (23:00 +0100)]
add d-i.debian.org ssl cert
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 2 Jan 2016 20:21:21 +0000 (20:21 +0000)]
Attempt to configure an apache vhost for a static component only if it exists on this host, part 2
Julien Cristau [Sat, 2 Jan 2016 20:12:13 +0000 (21:12 +0100)]
switch my root ssh key to one stored on a yubikey
Signed-off-by: Julien Cristau <jcristau@debian.org>
Peter Palfrader [Sat, 2 Jan 2016 19:58:00 +0000 (19:58 +0000)]
Attempt to configure an apache vhost for a static component only if it exists on this host, part 1
Aurelien Jarno [Sat, 2 Jan 2016 16:55:19 +0000 (17:55 +0100)]
Revert "cron.d/dsa-buildd: only look for .upload files"
This reverts commit
df6c4329e9b0395d76d7170581907c70116ecebf.
Instead change buildd to avoid the condition to happen.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Aurelien Jarno [Sat, 2 Jan 2016 15:37:08 +0000 (16:37 +0100)]
cron.d/dsa-buildd: only look for .upload files
Only look for .upload files, and use their contents to determine which
files to delete. This avoid triggering reuploads when the package has
been built before midnight, but uploaded after midnight.
Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
Peter Palfrader [Wed, 30 Dec 2015 20:04:28 +0000 (21:04 +0100)]
allow gitdoadm to sudo to git
Peter Palfrader [Tue, 29 Dec 2015 22:02:46 +0000 (23:02 +0100)]
retire delfin-srv
Peter Palfrader [Tue, 29 Dec 2015 21:51:52 +0000 (22:51 +0100)]
Add delfin-lvm
Peter Palfrader [Tue, 29 Dec 2015 21:39:30 +0000 (22:39 +0100)]
retire bmdb1-srv
Peter Palfrader [Tue, 29 Dec 2015 20:31:14 +0000 (21:31 +0100)]
Add bmdb1-lvm
Martin Zobel-Helas [Sat, 26 Dec 2015 12:39:13 +0000 (12:39 +0000)]
add vittoria to ferm rules
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sat, 26 Dec 2015 12:34:41 +0000 (12:34 +0000)]
add vittoria to postgres hosts
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 25 Dec 2015 10:32:22 +0000 (10:32 +0000)]
set different path for lintian, to avoid backup of autogenerated material every day.
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>