Re: Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-27 Thread nodata
On 26/11/10 23:47, Philip Prindeville wrote: I recently rebuilt a failing mail server (sendmail and cyrus-imapd), replacing the hardware and building the replacement machine offline (leaving the current server in place while I did so). This would seem normal enough to do, but had some

Re: Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-27 Thread Ralf Ertzinger
Hi. On Sat, 27 Nov 2010 16:15:47 +0100, nodata wrote I don't agree. If you are replacing a production machine, you take the keys from the old machine and use them. If you don't want to do that, you buy new, probably stronger, certificates that are also valid. I think your case only covers

Re: Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-27 Thread nodata
On 27/11/10 16:44, Ralf Ertzinger wrote: Hi. On Sat, 27 Nov 2010 16:15:47 +0100, nodata wrote I don't agree. If you are replacing a production machine, you take the keys from the old machine and use them. If you don't want to do that, you buy new, probably stronger, certificates that are

Re: Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-27 Thread Philip Prindeville
On 11/27/10 8:15 AM, nodata wrote: On 26/11/10 23:47, Philip Prindeville wrote: I recently rebuilt a failing mail server (sendmail and cyrus-imapd), replacing the hardware and building the replacement machine offline (leaving the current server in place while I did so). This would seem

Re: Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-27 Thread Philip Prindeville
On 11/27/10 1:09 PM, nodata wrote: On 27/11/10 16:44, Ralf Ertzinger wrote: Hi. On Sat, 27 Nov 2010 16:15:47 +0100, nodata wrote I don't agree. If you are replacing a production machine, you take the keys from the old machine and use them. If you don't want to do that, you buy new,

Building production machines out-of-place, regenerating certs when a machine's identity changes, etc.

2010-11-26 Thread Philip Prindeville
I recently rebuilt a failing mail server (sendmail and cyrus-imapd), replacing the hardware and building the replacement machine offline (leaving the current server in place while I did so). This would seem normal enough to do, but had some unintended pitfalls that really should be more