diff options
| author | Nicolas Vigier <boklm@mageia.org> | 2013-04-14 13:46:12 +0000 |
|---|---|---|
| committer | Nicolas Vigier <boklm@mageia.org> | 2013-04-14 13:46:12 +0000 |
| commit | 1be510f9529cb082f802408b472a77d074b394c0 (patch) | |
| tree | b175f9d5fcb107576dabc768e7bd04d4a3e491a0 /zarb-ml/mageia-sysadm/2012-February/004189.html | |
| parent | fa5098cf210b23ab4f419913e28af7b1b07dafb2 (diff) | |
| download | archives-master.tar archives-master.tar.gz archives-master.tar.bz2 archives-master.tar.xz archives-master.zip | |
Diffstat (limited to 'zarb-ml/mageia-sysadm/2012-February/004189.html')
| -rw-r--r-- | zarb-ml/mageia-sysadm/2012-February/004189.html | 98 |
1 files changed, 98 insertions, 0 deletions
diff --git a/zarb-ml/mageia-sysadm/2012-February/004189.html b/zarb-ml/mageia-sysadm/2012-February/004189.html new file mode 100644 index 000000000..8b7c0e5fa --- /dev/null +++ b/zarb-ml/mageia-sysadm/2012-February/004189.html @@ -0,0 +1,98 @@ +<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN"> +<HTML> + <HEAD> + <TITLE> [Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW) + </TITLE> + <LINK REL="Index" HREF="index.html" > + <LINK REL="made" HREF="mailto:mageia-sysadm%40mageia.org?Subject=Re%3A%20%5BMageia-sysadm%5D%0A%20%3D%3Fiso-8859-1%3Fq%3F%3D5Bsysadmin-reports%3D5D_Hobbit_%3D5B3%3F%3D%0A%20%3D%3Fiso-8859-1%3Fq%3F8%3D5D_forums%3D2Emageia%3D2Eorg%3D3Asslcert%3D09warning_%3D28YELLOW%3F%3D%0A%20%3D%3Fiso-8859-1%3Fq%3F%3D29%3F%3D&In-Reply-To=%3C201202091112.52369.bgmilne%40zarb.org%3E"> + <META NAME="robots" CONTENT="index,nofollow"> + <META http-equiv="Content-Type" content="text/html; charset=us-ascii"> + <LINK REL="Previous" HREF="004186.html"> + <LINK REL="Next" HREF="004190.html"> + </HEAD> + <BODY BGCOLOR="#ffffff"> + <H1>[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW)</H1> + <B>Buchan Milne</B> + <A HREF="mailto:mageia-sysadm%40mageia.org?Subject=Re%3A%20%5BMageia-sysadm%5D%0A%20%3D%3Fiso-8859-1%3Fq%3F%3D5Bsysadmin-reports%3D5D_Hobbit_%3D5B3%3F%3D%0A%20%3D%3Fiso-8859-1%3Fq%3F8%3D5D_forums%3D2Emageia%3D2Eorg%3D3Asslcert%3D09warning_%3D28YELLOW%3F%3D%0A%20%3D%3Fiso-8859-1%3Fq%3F%3D29%3F%3D&In-Reply-To=%3C201202091112.52369.bgmilne%40zarb.org%3E" + TITLE="[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW)">bgmilne at zarb.org + </A><BR> + <I>Thu Feb 9 10:12:51 CET 2012</I> + <P><UL> + <LI>Previous message: <A HREF="004186.html">[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW) +</A></li> + <LI>Next message: <A HREF="004190.html">[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW) +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#4189">[ date ]</a> + <a href="thread.html#4189">[ thread ]</a> + <a href="subject.html#4189">[ subject ]</a> + <a href="author.html#4189">[ author ]</a> + </LI> + </UL> + <HR> +<!--beginarticle--> +<PRE>On Wednesday, 8 February 2012 21:29:56 nicolas vigier wrote: +><i> On Wed, 08 Feb 2012, <A HREF="https://www.mageia.org/mailman/listinfo/mageia-sysadm">root at mageia.org</A> wrote: +</I>><i> > yellow Wed Feb 8 19:58:39 2012 +</I>><i> > +</I>><i> > &yellow SSL certificate for <A HREF="https://forums.mageia.org/">https://forums.mageia.org/</A> expires in 13 days +</I>><i> > +</I>><i> > Server certificate: +</I>><i> > +</I>subject:/C=--/ST=SomeState/L=SomeCity/O=SomeOrganization/OU=SomeOrganiza +><i> > +</I>tionalUnit/CN=friteuse.mageia.org/emailAddress=<A HREF="https://www.mageia.org/mailman/listinfo/mageia-sysadm">root at friteuse.mageia.org</A> +><i> > start date: 2011-02-22 01:21:12 GMT +</I>><i> > expire date:2012-02-22 01:21:12 GMT +</I>><i> +</I>><i> We have this warning, but xymon is checking the wrong certificate as it +</I>><i> is connecting to friteuse from alamut, and checking friteuse ssl +</I>><i> certificate. +</I> +Well, there is an http/https check for friteuse for the URL +<A HREF="https://forum.mageia.org,">https://forum.mageia.org,</A> specify friteuse' IP, and there is also a check on +forums.mageia.org for the URL <A HREF="https://forums.mageia.org.">https://forums.mageia.org.</A> On Alamut, +forums.mageia.org resolves to friteuse (entry in /etc/hosts), and the URL +check <A HREF="https://forums.mageia.org">https://forums.mageia.org</A> does not currently specify to use the public +IP. + +><i> But normal users using the forum are connecting to alamut +</I>><i> which is doing reverse proxy to friteuse, and using alamut ssl +</I>><i> certificate (which is valid until febuary 2013). +</I> +But, when friteuse' certificate expires, alamut's reverse proxy may refuse to +connect to friteuse, so both should be checked. + +><i> So we should either disable this check for forums.mageia.org, or move +</I>><i> xymon to an other server. +</I> +No, the URL check for <A HREF="https://forums.mageia.org">https://forums.mageia.org</A> on host forums.mageia.org +should specify to connect to the IP of alamut instead of friteuse (or the +entry in /etc/hosts on alamut should be removed if it is not required). I have +done add the IP in the URL check for forums in r2358. + +Regards, +Buchan +</PRE> + + +<!--endarticle--> + <HR> + <P><UL> + <!--threads--> + <LI>Previous message: <A HREF="004186.html">[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW) +</A></li> + <LI>Next message: <A HREF="004190.html">[Mageia-sysadm] [sysadmin-reports] Hobbit [38] forums.mageia.org:sslcert warning (YELLOW) +</A></li> + <LI> <B>Messages sorted by:</B> + <a href="date.html#4189">[ date ]</a> + <a href="thread.html#4189">[ thread ]</a> + <a href="subject.html#4189">[ subject ]</a> + <a href="author.html#4189">[ author ]</a> + </LI> + </UL> + +<hr> +<a href="https://www.mageia.org/mailman/listinfo/mageia-sysadm">More information about the Mageia-sysadm +mailing list</a><br> +</body></html> |
