Re: SSL to TLS

2018-06-13 Thread Roberto C . Sánchez
On Wed, Jun 13, 2018 at 10:30:52AM -, Dan Purgert wrote:
> Bringing this back to the list, in case anyone else has any
> suggestions ... 
> 
> culser wrote:
> > gee Dan
> >
> > thank you for such a fast response
> >
> > ok so i am downloading Debian 9.4.0 AMD DVD now.
> >
> > should i upgrade the existing server or build a new server with the
> > new 9.4
> 
> Personally, I'd go with at least a new VM - jumping as many versions as
> you are may prove to have a rather large number of deprecations or other
> changes in your software (e.g. Postfix, etc.), rendering current
> configuration files invalid.  Having Etch still around to do stuff until
> you've dealt with all the "new stuff" in Stretch.
> 

I would agree that a new installation would be more sensible than
attempting an upgrade.  You either skip all the versions in between and
end up in a mess, or you spend the time to upgrade one version at a
time.  Either way, it will take you much longer than a new installation.

> >
> > if i upgrade will that change my settings for Apache, Postfix, ProFTP,
> > ect ... ?
> 
> The "upgrade" itself probably wouldn't do anything -- but as I said
> above, you're talking about a pretty big jump in terms of revisions; so
> individual programs quite likely have different syntax now.

I am not sure about ProFTP and Postfix, but I am certain that your old
Apache configurations will almost certainly no longer work.  There have
been significant changes to the configuration of SSH and if you still
have clients that depend on the weak deprecated ciphers, you will need
to manually enable those.

Dan's offers an excellent recommendation to keep the Etch system around
until you have fully transitioned.  Make sure you follow that.

Regards,

-Roberto

-- 
Roberto C. Sánchez



Re: SSL to TLS

2018-06-13 Thread Dan Purgert
Bringing this back to the list, in case anyone else has any
suggestions ... 

culser wrote:
> gee Dan
>
> thank you for such a fast response
>
> ok so i am downloading Debian 9.4.0 AMD DVD now.
>
> should i upgrade the existing server or build a new server with the
> new 9.4

Personally, I'd go with at least a new VM - jumping as many versions as
you are may prove to have a rather large number of deprecations or other
changes in your software (e.g. Postfix, etc.), rendering current
configuration files invalid.  Having Etch still around to do stuff until
you've dealt with all the "new stuff" in Stretch.

>
> if i upgrade will that change my settings for Apache, Postfix, ProFTP,
> ect ... ?

The "upgrade" itself probably wouldn't do anything -- but as I said
above, you're talking about a pretty big jump in terms of revisions; so
individual programs quite likely have different syntax now.
>
> please advise
>
> Dave
>> [...]

-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281



Re: SSL to TLS

2018-06-12 Thread Dan Purgert
culser wrote:
> [...]`
> my current Debian is 4.1.2-25, Kernel 2.6.26-2 Amd, Apache 2, Postfix

Debian 4, as in Etch, which has been obsolete for 8 years now?

Yes, yes you absolutely need to upgrade.


-- 
|_|O|_| Registered Linux user #585947
|_|_|O| Github: https://github.com/dpurgert
|O|O|O| PGP: 05CA 9A50 3F2E 1335 4DC5  4AEE 8E11 DDF3 1279 A281