Peter Palfrader [Wed, 23 Apr 2014 07:47:32 +0000 (09:47 +0200)]
Add security.d.o virtual domain to front ends
Luca Filipozzi [Wed, 23 Apr 2014 07:02:29 +0000 (07:02 +0000)]
removed eff.org from blacklist
Martin Zobel-Helas [Tue, 22 Apr 2014 21:23:30 +0000 (23:23 +0200)]
oyens was missing in hieradata
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Tue, 22 Apr 2014 21:18:30 +0000 (23:18 +0200)]
add role keystone
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Tue, 22 Apr 2014 20:34:52 +0000 (22:34 +0200)]
add openstack.bm.debian.org (DEBIAN-CA) certificate
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Tue, 22 Apr 2014 17:18:49 +0000 (19:18 +0200)]
Sanitize mailrelay virtualdomain paths
Peter Palfrader [Tue, 22 Apr 2014 12:44:42 +0000 (14:44 +0200)]
Try messing with signing options
Peter Palfrader [Mon, 21 Apr 2014 17:39:36 +0000 (19:39 +0200)]
move quantz
Peter Palfrader [Mon, 21 Apr 2014 17:36:15 +0000 (19:36 +0200)]
quantz gets the autofs::bytemark treatment
Peter Palfrader [Mon, 21 Apr 2014 17:21:55 +0000 (19:21 +0200)]
give wuiet and quantz access to the main cluster on bmdb1
Stephen Gran [Mon, 21 Apr 2014 16:47:21 +0000 (17:47 +0100)]
add neutron range
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Mon, 21 Apr 2014 10:46:03 +0000 (12:46 +0200)]
add an NFS mirror to delfin
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Mon, 21 Apr 2014 07:27:26 +0000 (09:27 +0200)]
quantz devices
Martin Zobel-Helas [Sat, 19 Apr 2014 07:41:53 +0000 (09:41 +0200)]
ups, Host_Alias should be defined too
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Sat, 19 Apr 2014 07:39:46 +0000 (09:39 +0200)]
add OpenStack sudo entries
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 18 Apr 2014 18:33:34 +0000 (20:33 +0200)]
open firewall ports on oyens
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 18 Apr 2014 14:34:43 +0000 (16:34 +0200)]
allow 5672
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 18 Apr 2014 07:08:57 +0000 (09:08 +0200)]
no ganeti for bm-bl9 to bm-bl14
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Thu, 17 Apr 2014 17:15:56 +0000 (19:15 +0200)]
Barriere volumes
Martin Zobel-Helas [Wed, 16 Apr 2014 22:12:23 +0000 (00:12 +0200)]
add oyens
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 16 Apr 2014 21:17:16 +0000 (23:17 +0200)]
add oyens
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Wed, 16 Apr 2014 20:07:27 +0000 (22:07 +0200)]
add oyens
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Mon, 14 Apr 2014 19:42:21 +0000 (21:42 +0200)]
add comment
Peter Palfrader [Mon, 14 Apr 2014 18:03:30 +0000 (20:03 +0200)]
Set a saner max-journal-size than unlimited
Peter Palfrader [Sun, 13 Apr 2014 15:33:07 +0000 (17:33 +0200)]
remove ftp-debian.org virtual mail domain from franck
Peter Palfrader [Sun, 13 Apr 2014 12:06:57 +0000 (14:06 +0200)]
Add ftp-debian.org virtual domain on the mail relays
Peter Palfrader [Sun, 13 Apr 2014 08:37:03 +0000 (10:37 +0200)]
more stupid rails ignores
Tollef Fog Heen [Fri, 11 Apr 2014 20:04:53 +0000 (22:04 +0200)]
Add eff.org to blacklist, they are not doing double opt-in and fail to respond to questions about spam
Peter Palfrader [Fri, 11 Apr 2014 06:23:31 +0000 (08:23 +0200)]
blacklist 216.158.85.34 for sending us training spam
Peter Palfrader [Thu, 10 Apr 2014 07:28:13 +0000 (07:28 +0000)]
activate all new certs
Peter Palfrader [Wed, 9 Apr 2014 19:57:01 +0000 (21:57 +0200)]
Add a couple -new certs
Peter Palfrader [Wed, 9 Apr 2014 18:24:22 +0000 (20:24 +0200)]
Add -new bugs-master cert
Peter Palfrader [Wed, 9 Apr 2014 16:31:23 +0000 (18:31 +0200)]
activate two certs
Peter Palfrader [Wed, 9 Apr 2014 15:40:15 +0000 (17:40 +0200)]
fix yaml entry
Peter Palfrader [Wed, 9 Apr 2014 15:30:18 +0000 (17:30 +0200)]
Deploy gobby cert to gombert
Peter Palfrader [Wed, 9 Apr 2014 15:19:18 +0000 (17:19 +0200)]
Add new certs chained off ca.d.o
Peter Palfrader [Wed, 9 Apr 2014 11:22:53 +0000 (13:22 +0200)]
Print clearer problem report if setup-dchroot fails
Peter Palfrader [Tue, 8 Apr 2014 17:16:19 +0000 (19:16 +0200)]
The dns update script is named differently
Peter Palfrader [Tue, 8 Apr 2014 17:15:49 +0000 (19:15 +0200)]
allow nagios hpacucli to check LDs
Peter Palfrader [Tue, 8 Apr 2014 13:37:49 +0000 (15:37 +0200)]
Try to remove /etc/apt/trusted-keys.d harder, II
Peter Palfrader [Tue, 8 Apr 2014 13:37:04 +0000 (15:37 +0200)]
Try to remove /etc/apt/trusted-keys.d harder
Peter Palfrader [Tue, 8 Apr 2014 13:33:24 +0000 (15:33 +0200)]
and dearmor buildd.d.o gpgkey
Peter Palfrader [Tue, 8 Apr 2014 13:33:06 +0000 (15:33 +0200)]
fix filename
Peter Palfrader [Tue, 8 Apr 2014 13:30:37 +0000 (15:30 +0200)]
Update db.d.o key
Peter Palfrader [Tue, 8 Apr 2014 13:27:55 +0000 (15:27 +0200)]
get rid of duplicate
Peter Palfrader [Tue, 8 Apr 2014 13:27:06 +0000 (15:27 +0200)]
syntax I
Peter Palfrader [Tue, 8 Apr 2014 13:26:37 +0000 (15:26 +0200)]
Switch to /etc/apt/trusted.gpg.d
Peter Palfrader [Tue, 8 Apr 2014 12:02:06 +0000 (14:02 +0200)]
stunnel: Set socket option linger for accept sockets
Peter Palfrader [Tue, 8 Apr 2014 10:06:36 +0000 (12:06 +0200)]
ekeyd: Raise retry time
Peter Palfrader [Tue, 8 Apr 2014 09:17:04 +0000 (11:17 +0200)]
Raise ulimit -n for stunnel
Héctor Orón Martínez [Thu, 3 Apr 2014 14:34:02 +0000 (16:34 +0200)]
Remove decomissioned arm* references
Signed-off-by: Héctor Orón Martínez <zumbi@debian.org>
Peter Palfrader [Mon, 31 Mar 2014 18:10:03 +0000 (20:10 +0200)]
Set up armhf porting chroots on armel hosts
Stephen Gran [Mon, 31 Mar 2014 07:10:58 +0000 (08:10 +0100)]
add client configs for mail relay
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Mon, 31 Mar 2014 07:05:18 +0000 (08:05 +0100)]
introduce pubsub config for git master
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Fri, 28 Mar 2014 17:50:22 +0000 (18:50 +0100)]
Fix: Add security-team-backend
Peter Palfrader [Fri, 28 Mar 2014 17:44:08 +0000 (18:44 +0100)]
Add security-team-backend
Peter Palfrader [Fri, 28 Mar 2014 17:37:03 +0000 (18:37 +0100)]
Fix security-team entry
Peter Palfrader [Fri, 28 Mar 2014 17:31:45 +0000 (18:31 +0100)]
%security gets to update their static component
Peter Palfrader [Fri, 28 Mar 2014 17:31:12 +0000 (18:31 +0100)]
Add security-team vhost
Peter Palfrader [Fri, 28 Mar 2014 17:30:25 +0000 (18:30 +0100)]
Add security-team static component
Peter Palfrader [Fri, 28 Mar 2014 17:30:08 +0000 (18:30 +0100)]
Whitespace changes
Peter Palfrader [Fri, 28 Mar 2014 17:28:04 +0000 (18:28 +0100)]
Sort static components
Peter Palfrader [Fri, 28 Mar 2014 17:26:08 +0000 (18:26 +0100)]
Give %security sudo to security
Peter Palfrader [Thu, 27 Mar 2014 07:12:46 +0000 (08:12 +0100)]
try this
Peter Palfrader [Thu, 27 Mar 2014 07:10:25 +0000 (08:10 +0100)]
no hp-health on DL1xx
Peter Palfrader [Thu, 27 Mar 2014 07:04:41 +0000 (08:04 +0100)]
Fix url
Peter Palfrader [Thu, 27 Mar 2014 06:58:08 +0000 (07:58 +0100)]
Add leaseweb mirror
Peter Palfrader [Thu, 27 Mar 2014 06:53:09 +0000 (07:53 +0100)]
Set leaseweb netrange
Peter Palfrader [Wed, 26 Mar 2014 20:30:09 +0000 (21:30 +0100)]
Add leaseweb nameservers
Peter Palfrader [Wed, 26 Mar 2014 12:47:33 +0000 (13:47 +0100)]
Add puppet-dashboard ssl::service to puppetmaster
Peter Palfrader [Wed, 26 Mar 2014 12:46:07 +0000 (13:46 +0100)]
Add puppet-dashboard cert
Stephen Gran [Sun, 23 Mar 2014 19:07:48 +0000 (19:07 +0000)]
drop htools
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 23 Mar 2014 19:07:35 +0000 (19:07 +0000)]
Linting
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Sun, 23 Mar 2014 18:58:55 +0000 (18:58 +0000)]
why does this make a difference
Signed-off-by: Stephen Gran <steve@lobefin.net>
Peter Palfrader [Sun, 23 Mar 2014 08:45:50 +0000 (09:45 +0100)]
Restart bacula-fd when the client cert changes
Peter Palfrader [Sun, 16 Mar 2014 12:35:47 +0000 (13:35 +0100)]
Mount a /dev in the chroot on freebsds so we can install python
Peter Palfrader [Thu, 13 Mar 2014 11:07:29 +0000 (12:07 +0100)]
Fix suites override for armhf/armel
Peter Palfrader [Sun, 9 Mar 2014 07:50:19 +0000 (08:50 +0100)]
fix
Peter Palfrader [Sun, 9 Mar 2014 07:49:55 +0000 (08:49 +0100)]
Access to dedup db
Luca Filipozzi [Sat, 8 Mar 2014 21:58:00 +0000 (21:58 +0000)]
undo all easydns changes... if we are to hard code, put in another file
Luca Filipozzi [Sat, 8 Mar 2014 21:34:44 +0000 (21:34 +0000)]
use easydns-generated tsig key since need key name to match
Luca Filipozzi [Sat, 8 Mar 2014 15:22:01 +0000 (15:22 +0000)]
log dns notify/transfers
Luca Filipozzi [Sat, 8 Mar 2014 05:46:40 +0000 (05:46 +0000)]
easydns uses hmac-md5 algorithm
Luca Filipozzi [Fri, 7 Mar 2014 05:30:44 +0000 (05:30 +0000)]
add xfr0.easydns.com to firewall rules
Luca Filipozzi [Fri, 7 Mar 2014 05:10:28 +0000 (05:10 +0000)]
but make sure the ugly is correct
Luca Filipozzi [Fri, 7 Mar 2014 05:09:45 +0000 (05:09 +0000)]
add some ugliness
Luca Filipozzi [Fri, 7 Mar 2014 04:56:12 +0000 (04:56 +0000)]
add [denis.debian.org, xfr0.easydns.com] as another tsig key
Luca Filipozzi [Mon, 3 Mar 2014 19:15:44 +0000 (19:15 +0000)]
add security-cdn{1,2} as ServerAliases for security.debian.org
Peter Palfrader [Fri, 28 Feb 2014 18:14:23 +0000 (19:14 +0100)]
db.d.o ldap cert no longer signed from SPI
Peter Palfrader [Fri, 28 Feb 2014 18:10:49 +0000 (18:10 +0000)]
Do not notify rehash on update of chains
Peter Palfrader [Fri, 28 Feb 2014 18:10:37 +0000 (18:10 +0000)]
Produce a -chained file for our certs
Peter Palfrader [Thu, 27 Feb 2014 08:57:29 +0000 (09:57 +0100)]
no backups for eberlin
Peter Palfrader [Wed, 26 Feb 2014 17:09:43 +0000 (18:09 +0100)]
Add eberlin
Stephen Gran [Wed, 19 Feb 2014 15:38:16 +0000 (15:38 +0000)]
autodoc headers
Signed-off-by: Stephen Gran <steve@lobefin.net>
Stephen Gran [Wed, 19 Feb 2014 15:36:01 +0000 (15:36 +0000)]
up apache memlimit
Signed-off-by: Stephen Gran <steve@lobefin.net>
Martin Zobel-Helas [Tue, 18 Feb 2014 20:31:45 +0000 (21:31 +0100)]
disable dacs for now, will move into roles later on
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Peter Palfrader [Mon, 17 Feb 2014 06:49:21 +0000 (07:49 +0100)]
Do not catch www.*. in the www vhost
Martin Zobel-Helas [Sat, 15 Feb 2014 15:30:02 +0000 (16:30 +0100)]
remove crap
Martin Zobel-Helas [Fri, 14 Feb 2014 20:00:33 +0000 (21:00 +0100)]
add tchaikovsky
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>
Martin Zobel-Helas [Fri, 14 Feb 2014 16:53:58 +0000 (17:53 +0100)]
add sudo for debsso
Signed-off-by: Martin Zobel-Helas <zobel@debian.org>