unofficial mirror of guix-devel@gnu.org 
 help / color / mirror / code / Atom feed
* guix.gnu.org sub-domain
  2018-12-13  8:05       ` Chris Marusich
@ 2018-12-14 10:26         ` Ludovic Courtès
  2018-12-15 23:20           ` Chris Marusich
  0 siblings, 1 reply; 8+ messages in thread
From: Ludovic Courtès @ 2018-12-14 10:26 UTC (permalink / raw)
  To: Chris Marusich; +Cc: Hartmut Goebel, guix-devel, 33600

Hi Chris,

Chris Marusich <cmmarusich@gmail.com> skribis:

> Ludovic Courtès <ludo@gnu.org> writes:
>
>> Regarding the GNU sub-domain, as I replied to Meiyo, I’m in favor of it,
>> all we need is someone to champion setting it up.
>
> I could help with this.  Whom should I contact?

We discussed this over the last few days in Paris and Julien (roptat on
IRC) volunteered to come up with a Knot service setup for bayfront.scm.
When that’s ready, we can contact the FSF sysadmins so they delegate to
bayfront.

I’m sure Julien wouldn’t mind getting some help or insight, so please do
get in touch!

Ludo’.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2018-12-14 10:26         ` guix.gnu.org sub-domain Ludovic Courtès
@ 2018-12-15 23:20           ` Chris Marusich
  2019-01-25  4:54             ` Amin Bandali
  0 siblings, 1 reply; 8+ messages in thread
From: Chris Marusich @ 2018-12-15 23:20 UTC (permalink / raw)
  To: Ludovic Courtès; +Cc: Hartmut Goebel, guix-devel, 33600

[-- Attachment #1: Type: text/plain, Size: 271 bytes --]

Hi Ludo,

Ludovic Courtès <ludo@gnu.org> writes:

> I’m sure Julien wouldn’t mind getting some help or insight, so please do
> get in touch!

OK, I'll speak privately with Julien about the DNS setup to avoid adding
noise to this email thread.

-- 
Chris

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 832 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2018-12-15 23:20           ` Chris Marusich
@ 2019-01-25  4:54             ` Amin Bandali
  0 siblings, 0 replies; 8+ messages in thread
From: Amin Bandali @ 2019-01-25  4:54 UTC (permalink / raw)
  To: Chris Marusich, Julien Lepiller; +Cc: guix-devel

On 2018-12-15  3:20 PM, Chris Marusich wrote:
> Hi Ludo,
>
> Ludovic Courtès <ludo@gnu.org> writes:
>
>> I’m sure Julien wouldn’t mind getting some help or insight, so please do
>> get in touch!
>
> OK, I'll speak privately with Julien about the DNS setup to avoid adding
> noise to this email thread.
>
> -- 
> Chris
>

Hi Chris, Julien,

Any update on this?  I too had asked Ludo about DNS for guix.gnu.org a
couple of weeks ago, and he’d pointed me to the bayfront.scm [1] config
file, but I was swamped with work and only recently have found a bit of
free time on my hands.  While looking for information about Knot, I also
stumbled upon Julien’s configuration [2].  I was wondering if y’all were
able to spend any time on this, and if so, if you ended up committing
your progress anywhere?

Best,
amin

Footnotes:
[1]  https://git.savannah.gnu.org/cgit/guix/maintenance.git/tree/hydra/bayfront.scm

[2]  https://lepiller.eu/ma-configuration.html

^ permalink raw reply	[flat|nested] 8+ messages in thread

* guix.gnu.org sub-domain
@ 2019-02-23 12:38 Ricardo Wurmus
  2019-04-08  8:59 ` Ludovic Courtès
  0 siblings, 1 reply; 8+ messages in thread
From: Ricardo Wurmus @ 2019-02-23 12:38 UTC (permalink / raw)
  To: Julien Lepiller; +Cc: guix-devel

Hi Julien,

I just went through the list of things that we wanted to accomplish
before releasing 1.0.  One of them is the use of a guix.gnu.org
sub-domain.

Could you please let us know what the current status is regarding the
Knot DNS server configuration?

Cheers,

--
Ricardo

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2019-02-23 12:38 guix.gnu.org sub-domain Ricardo Wurmus
@ 2019-04-08  8:59 ` Ludovic Courtès
  2019-04-08 13:22   ` Julien Lepiller
  0 siblings, 1 reply; 8+ messages in thread
From: Ludovic Courtès @ 2019-04-08  8:59 UTC (permalink / raw)
  To: Ricardo Wurmus; +Cc: guix-devel

Hello Julien,

Ricardo Wurmus <rekado@elephly.net> skribis:

> I just went through the list of things that we wanted to accomplish
> before releasing 1.0.  One of them is the use of a guix.gnu.org
> sub-domain.
>
> Could you please let us know what the current status is regarding the
> Knot DNS server configuration?

A friendly ping.  :-)

Thanks,
Ludo’.

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2019-04-08  8:59 ` Ludovic Courtès
@ 2019-04-08 13:22   ` Julien Lepiller
  2019-04-09  1:48     ` Chris Marusich
  0 siblings, 1 reply; 8+ messages in thread
From: Julien Lepiller @ 2019-04-08 13:22 UTC (permalink / raw)
  To: Ludovic Courtès, Ricardo Wurmus; +Cc: guix-devel

Le 8 avril 2019 10:59:36 GMT+02:00, "Ludovic Courtès" <ludo@gnu.org> a écrit :
>Hello Julien,
>
>Ricardo Wurmus <rekado@elephly.net> skribis:
>
>> I just went through the list of things that we wanted to accomplish
>> before releasing 1.0.  One of them is the use of a guix.gnu.org
>> sub-domain.
>>
>> Could you please let us know what the current status is regarding the
>> Knot DNS server configuration?
>
>A friendly ping.  :-)
>
>Thanks,
>Ludo’.

I'm still unsure about how to update the certificates with the dns challenge. I found a script that could help us with updating the zone served by knot when it's configured as a master.

We could use that to update the required txt record, but we also need to make sure the change is propagated to the other server, because we don't know which server will be asked to answer the challenge.

With a further delegation of the record for the dns challenge we can have two masters, but I'm still stuck at finding a way to communicate the challenge between the two servers.

Ideas?

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2019-04-08 13:22   ` Julien Lepiller
@ 2019-04-09  1:48     ` Chris Marusich
  2019-04-09  8:32       ` Julien Lepiller
  0 siblings, 1 reply; 8+ messages in thread
From: Chris Marusich @ 2019-04-09  1:48 UTC (permalink / raw)
  To: Julien Lepiller; +Cc: guix-devel

[-- Attachment #1: Type: text/plain, Size: 1190 bytes --]

Hi Julien,

Thank you for working on this!

Julien Lepiller <julien@lepiller.eu> writes:

> I'm still unsure about how to update the certificates with the dns
> challenge. I found a script that could help us with updating the zone
> served by knot when it's configured as a master.
>
> We could use that to update the required txt record, but we also need
> to make sure the change is propagated to the other server, because we
> don't know which server will be asked to answer the challenge.
>
> With a further delegation of the record for the dns challenge we can
> have two masters, but I'm still stuck at finding a way to communicate
> the challenge between the two servers.
>
> Ideas?

Can we update the DNS dynamically [1]?  Can you share the script?

I still don't know as much about Knot as I should, but I'm surprised
that a change to the primary server's database would not be propagated
to the secondary server's database automatically.  Can you elaborate on
what goes wrong, or maybe explain (even at a high level) how I can try
reproducing the problem with cert renewal locally?

Footnotes: 
[1]  https://tools.ietf.org/html/rfc2136

-- 
Chris

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 832 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: guix.gnu.org sub-domain
  2019-04-09  1:48     ` Chris Marusich
@ 2019-04-09  8:32       ` Julien Lepiller
  0 siblings, 0 replies; 8+ messages in thread
From: Julien Lepiller @ 2019-04-09  8:32 UTC (permalink / raw)
  To: Chris Marusich; +Cc: guix-devel

Le 9 avril 2019 03:48:02 GMT+02:00, Chris Marusich <cmmarusich@gmail.com> a écrit :
>Hi Julien,
>
>Thank you for working on this!
>
>Julien Lepiller <julien@lepiller.eu> writes:
>
>> I'm still unsure about how to update the certificates with the dns
>> challenge. I found a script that could help us with updating the zone
>> served by knot when it's configured as a master.
>>
>> We could use that to update the required txt record, but we also need
>> to make sure the change is propagated to the other server, because we
>> don't know which server will be asked to answer the challenge.
>>
>> With a further delegation of the record for the dns challenge we can
>> have two masters, but I'm still stuck at finding a way to communicate
>> the challenge between the two servers.
>>
>> Ideas?
>
>Can we update the DNS dynamically [1]?  Can you share the script?
>
>I still don't know as much about Knot as I should, but I'm surprised
>that a change to the primary server's database would not be propagated
>to the secondary server's database automatically.  Can you elaborate on
>what goes wrong, or maybe explain (even at a high level) how I can try
>reproducing the problem with cert renewal locally?
>
>Footnotes: 
>[1]  https://tools.ietf.org/html/rfc2136

What I found consists in using knotc to update the zone served by knot with knotc, but it only update it locally (and to slaves). So we have no issue with that method when we want to automate certs from the primary, but I don't know how to propagate the change back to the master when we ask for certs on the secondary.

I'll have a look at the rfc.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2019-04-09  8:32 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-02-23 12:38 guix.gnu.org sub-domain Ricardo Wurmus
2019-04-08  8:59 ` Ludovic Courtès
2019-04-08 13:22   ` Julien Lepiller
2019-04-09  1:48     ` Chris Marusich
2019-04-09  8:32       ` Julien Lepiller
  -- strict thread matches above, loose matches on Subject: below --
2018-12-03 15:43 [PATCH 0/3] Defaulting to ci.guix.info (aka. berlin.guixsd.org) Ludovic Courtès
2018-12-03 16:12 ` Using a CDN or some other mirror? Ludovic Courtès
2018-12-09  3:33   ` Chris Marusich
2018-12-09 15:59     ` CDN performance Ludovic Courtès
2018-12-13  8:05       ` Chris Marusich
2018-12-14 10:26         ` guix.gnu.org sub-domain Ludovic Courtès
2018-12-15 23:20           ` Chris Marusich
2019-01-25  4:54             ` Amin Bandali

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/guix.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).