Re: [Fedora-sysadmin-list] Web Security

2008-11-24 Thread Paulo Santos
Hi Damian, Those look good to me, and you might want to add some extra ones just to start. # Log only relevant entries and log it SecAuditEngine RelevantOnly SecAuditLog /var/log/httpd/modsec_audit.log # Filter only Dynamic content (to minimize performance impact) should be tested to be sure

Re: [Fedora-sysadmin-list] Web Security

2008-11-24 Thread Damian Myerscough
Hello Paulo, I will add the extra fields and setup a virtual machine on my local host and use the Apache bentchmark utility to simulate high levels of traffic. 2008/11/24 Paulo Santos [EMAIL PROTECTED]: Hi Damian, Those look good to me, and you might want to add some extra ones just to

Re: Informal survey

2008-11-24 Thread Jon Ciesla
Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or an individual provider? Nope. I run my stuff out of my basement. :) If you do use a provider which one is it? For me, I do use one and I

Re: Self Introduction:Balaji

2008-11-24 Thread Mike McGrath
On Sun, 23 Nov 2008, G wrote: Hi My name is Balaji and i live in chennai which is a city in India. i am a software developer working for a private firm in chennai. I ve been contribtuting to fedora as a member of the bug-triage team, Testing packages from the bodhi repository, the Docs

Re: An introduction

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Mike McCarthy wrote: Hi all, My name is Mike and I'm a sysadmin based in the UK.  I work mainly with RHEL, TRU64 and AIX systems professionally but have a few Fedora boxes at home that I experiment with generally to save me trashing any of the corporate systems :) . 

An introduction

2008-11-24 Thread Mike McCarthy
Hi all, My name is Mike and I'm a sysadmin based in the UK. I work mainly with RHEL, TRU64 and AIX systems professionally but have a few Fedora boxes at home that I experiment with generally to save me trashing any of the corporate systems :) . I moved into administration about 5 years ago from

Re: Informal survey

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Stephen John Smoogen wrote: On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or an individual

Re: Informal survey

2008-11-24 Thread Stephen John Smoogen
On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or an individual provider? If you do use a provider which one is it?

Re: Informal survey

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Stephen John Smoogen wrote: On Mon, Nov 24, 2008 at 10:04 AM, Mike McGrath [EMAIL PROTECTED] wrote: On Mon, 24 Nov 2008, Stephen John Smoogen wrote: On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought

Re: Informal survey

2008-11-24 Thread Stephen John Smoogen
On Mon, Nov 24, 2008 at 10:04 AM, Mike McGrath [EMAIL PROTECTED] wrote: On Mon, 24 Nov 2008, Stephen John Smoogen wrote: On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how

Re: Informal survey

2008-11-24 Thread Seth Vidal
On Mon, 24 Nov 2008, Stephen John Smoogen wrote: Ahhh. I am so used to doing that from my basement.. kids these days. 1. a machine in my house would draw a lot more power than the portion of a machine I get with slicehost 2. keeping that running all the time so my email works would take a

Re: Informal survey

2008-11-24 Thread Seth Vidal
On Mon, 24 Nov 2008, Stephen John Smoogen wrote: On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or an individual

Re: Informal survey

2008-11-24 Thread Dennis Gilmore
On Monday 24 November 2008 11:01:38 am Stephen John Smoogen wrote: On Sat, Nov 22, 2008 at 11:36 AM, Mike McGrath [EMAIL PROTECTED] wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or

Fixing CSRF exploits in Infrastructure

2008-11-24 Thread Toshio Kuratomi
Greetings all, I've been researching the CSRF exploit and how it affects our web apps recently. The short story is that our code is pretty open to this at the moment. I've written up a proposal for fixing this but it will require a lot of coding so I'd love to have some more eyes on it to make

Re: Fixing CSRF exploits in Infrastructure

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Toshio Kuratomi wrote: Greetings all, I've been researching the CSRF exploit and how it affects our web apps recently. The short story is that our code is pretty open to this at the moment. I've written up a proposal for fixing this but it will require a lot of coding

Re: Fixing CSRF exploits in Infrastructure

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Mike McGrath wrote: This is well reasoned and inciteful. After F10 ships I've got a couple of things in the pipe to flush out but after that I'll work with you to get the major issues fixed as quickly as possible. Ugh, inciteful? really? You'd think I'd spell check

Re: Fixing CSRF exploits in Infrastructure

2008-11-24 Thread Mike Putnam
On Mon, Nov 24, 2008 at 03:30:03PM -0600, Mike McGrath wrote: On Mon, 24 Nov 2008, Mike McGrath wrote: This is well reasoned and inciteful. After F10 ships I've got a couple of things in the pipe to flush out but after that I'll work with you to get the major issues fixed as quickly as

Re: Congratulations to Nigel Jones

2008-11-24 Thread Xavier Lamien
On Mon, Nov 24, 2008 at 11:38 PM, Mike McGrath [EMAIL PROTECTED] wrote: I'm happy to announce I've just approved Nigel Jones in to the sysadmin-main group. He's the first new member we've had to that group since Ricky Zhou was approved in May earlier this year. Congrats Dude for both your

proper way to update /var/lib/puppet/application/mirrors/releases.txt

2008-11-24 Thread Jesse Keating
This looks like it is its own git repo, but apparently you need to be in the sysadmin-web group to edit this. I'm not in the group, so in order for me to manage this we either need to add me to the group (yuck, more groups) or move this to a different ownership set, or something else. Either way

Re: proper way to update /var/lib/puppet/application/mirrors/releases.txt

2008-11-24 Thread Mike McGrath
On Mon, 24 Nov 2008, Jesse Keating wrote: This looks like it is its own git repo, but apparently you need to be in the sysadmin-web group to edit this. I'm not in the group, so in order for me to manage this we either need to add me to the group (yuck, more groups) or move this to a

Re: Congratulations to Nigel Jones

2008-11-24 Thread Paul W. Frields
On Mon, Nov 24, 2008 at 04:38:16PM -0600, Mike McGrath wrote: I'm happy to announce I've just approved Nigel Jones in to the sysadmin-main group. He's the first new member we've had to that group since Ricky Zhou was approved in May earlier this year. For those that don't know sysadmin-main

Re: proper way to update /var/lib/puppet/application/mirrors/releases.txt

2008-11-24 Thread Jesse Keating
On Mon, 2008-11-24 at 18:18 -0600, Mike McGrath wrote: Try again. I cheated and used sudo.. -- Jesse Keating Fedora -- Freedom² is a feature! identi.ca: http://identi.ca/jkeating signature.asc Description: This is a digitally signed message part

Re: Congratulations to Nigel Jones

2008-11-24 Thread Luke Macken
On Mon, Nov 24, 2008 at 04:38:16PM -0600, Mike McGrath wrote: I'm happy to announce I've just approved Nigel Jones in to the sysadmin-main group. He's the first new member we've had to that group since Ricky Zhou was approved in May earlier this year. For those that don't know sysadmin-main

Re: Bodhi 10k bug

2008-11-24 Thread Luke Macken
On Sat, Nov 22, 2008 at 06:41:34PM -0500, Luke Macken wrote: As some of you may have noticed, the last batch of updates contained 209 updates with the ID of 'FEDORA-2008-1'. This is is due to a flaw in the way bodhi's PackageUpdate.assign_id() method finds the current update with the

Re: Informal survey

2008-11-24 Thread Imre Gergely
On 11/22/2008 08:36 PM, Mike McGrath wrote: Hey guys, completely voluntary but I thought I'd ask because I'm curious For personal use, how many of you use something like linode or slicehost or an individual provider? If you do use a provider which one is it? For me, I do use one and