Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-25 Thread Wolfgang Schweer
On Wed, Jul 24, 2019 at 06:41:42PM +0200, Wolfgang Schweer wrote: > > Capturing curl issues by grepping for a 404 is IMHO incomplete. (Turn of > > Apache2 and you won't get the 404 and curl | grep ends in some untested > > realm). > > Good point; this should definitly be improved. See my

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-24 Thread Wolfgang Schweer
Hi Mike, thanks for the fast feedback. On Wed, Jul 24, 2019 at 03:11:11PM +, Mike Gabriel wrote: > I am waiting for the system to come online again fully. The admin teacher at > that school has been pinged/pong. Good. > > + if curl -k https://www.intern/debian-edu-bundle.crt >

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-24 Thread Mike Gabriel
Hi Wolfgang, On Mi 24 Jul 2019 16:05:13 CEST, Wolfgang Schweer wrote: On Mon, Jul 22, 2019 at 07:38:53PM +, Holger Levsen wrote: On Mon, Jul 22, 2019 at 06:32:47PM +, Mike Gabriel wrote: > The school I can test this on is currently powered down due to maintenance > work on the

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-24 Thread Wolfgang Schweer
On Mon, Jul 22, 2019 at 07:38:53PM +, Holger Levsen wrote: > On Mon, Jul 22, 2019 at 06:32:47PM +, Mike Gabriel wrote: > > The school I can test this on is currently powered down due to maintenance > > work on the electric wiring in the building that hosts the server chamber. > > It's on

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-22 Thread Holger Levsen
On Mon, Jul 22, 2019 at 06:32:47PM +, Mike Gabriel wrote: > The school I can test this on is currently powered down due to maintenance > work on the electric wiring in the building that hosts the server chamber. > > It's on the list... do you have an ETA for this? currently the next point

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-22 Thread Mike Gabriel
Hi Wolfgang, sorry for not having replied earlier to this. On Mo 22 Jul 2019 18:08:49 CEST, Wolfgang Schweer wrote: Moin Mike, On Thu, Jul 11, 2019 at 08:14:20PM +0200, Wolfgang Schweer wrote: On Thu, Jul 11, 2019 at 10:14:01AM +, Mike Gabriel wrote: > I don't see a reason for updating

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-22 Thread Wolfgang Schweer
Moin Mike, On Thu, Jul 11, 2019 at 08:14:20PM +0200, Wolfgang Schweer wrote: > On Thu, Jul 11, 2019 at 10:14:01AM +, Mike Gabriel wrote: > > I don't see a reason for updating the LDAP cert in the chroot on every boot > > of the ltspserver, either. > > Correct, it should only be fetched once.

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-11 Thread Wolfgang Schweer
On Thu, Jul 11, 2019 at 10:14:01AM +, Mike Gabriel wrote: > I don't see a reason for updating the LDAP cert in the chroot on every boot > of the ltspserver, either. Correct, it should only be fetched once. Thanks to Petter for explaining how the LDAP server certificate prevents potential

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-11 Thread Mike Gabriel
Hi Wolfgang, On Mi 10 Jul 2019 19:49:01 CEST, Wolfgang Schweer wrote: Imo the fetch-ldap-cert script should be changed in any case like this to get the certificate into the LTSP chroot: [...] I don't see a reason for updating the LDAP cert in the chroot on every boot of the ltspserver,

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-10 Thread Wolfgang Schweer
On Wed, Jul 10, 2019 at 06:31:32PM +0200, Wolfgang Schweer wrote: > On Wed, Jul 10, 2019 at 02:50:19PM +, Mike Gabriel wrote: > > On Mi 10 Jul 2019 15:15:53 CEST, Petter Reinholdtsen wrote: > > > [Mike Gabriel] > > > > Another error in reasoning... A diskless machine doesn't probably have > >

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-10 Thread Wolfgang Schweer
On Wed, Jul 10, 2019 at 02:50:19PM +, Mike Gabriel wrote: > On Mi 10 Jul 2019 15:15:53 CEST, Petter Reinholdtsen wrote: > > [Mike Gabriel] > > > Another error in reasoning... A diskless machine doesn't probably have > > > any values/assets to protect, so why deploy the LDAP server cert at > >

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-10 Thread Mike Gabriel
Hi Petter, On Mi 10 Jul 2019 15:15:53 CEST, Petter Reinholdtsen wrote: [Mike Gabriel] Another error in reasoning... A diskless machine doesn't probably have any values/assets to protect, so why deploy the LDAP server cert at all to the diskless chroot? It is sufficient (and fully works) to

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-10 Thread Petter Reinholdtsen
[Mike Gabriel] > Another error in reasoning... A diskless machine doesn't probably have > any values/assets to protect, so why deploy the LDAP server cert at > all to the diskless chroot? It is sufficient (and fully works) to > retrieve the LDAP cert during the diskless machine's boot

Re: Bug#931413: [debian-edu-commits] [Git][debian-edu/debian-edu-config][master] debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENER's PKI server...

2019-07-10 Thread Mike Gabriel
Hi Wolfgang, On Sa 06 Jul 2019 13:33:51 CEST, Wolfgang Schweer wrote: Hi Mike, On Fri, Jul 05, 2019 at 08:17:13PM +, Mike Gabriel wrote: Commits: f8f436e8 by Mike Gabriel at 2019-07-05T20:16:50Z debian/debian-edu-config.fetch-ldap-cert: Retrieve TJENERs PKI server certificate only once