Re: securing FAS certs

2008-08-22 Thread David Lutterkort
On Thu, 2008-08-21 at 14:18 -0500, Jeffrey Ollie wrote: > What about using a crypto card like Jesse plans on using for Sigul? I wonder if a TPM can be (ab)used for this, too; they are pretty common on newer hardware, and store a key in HW that can not be extracted. Not sure though if anybody has

Re: Server Monitoring - A replacement for Nagios?

2008-07-30 Thread David Lutterkort
On Thu, 2008-07-31 at 14:59 +1200, Nigel Jones wrote: > Okay, so while this was intended to be a primary discussion point for > tomorrows Infrastructure meeting we had a little bit of discussion first > in #fedora-admin, and then in #fedora-meeting regarding Zabbix, a tool > like Nagios that I b

Re: fedorahosted.org is ready for testing

2007-12-14 Thread David Lutterkort
On Wed, 2007-12-12 at 08:25 -0600, Mike McGrath wrote: > Mike McGrath wrote: > > > > We've had luke working on this a little, I still have yet to see a > > solid proposal on how to config manage puppet modules and deploy them > > on a larger scale. All of the selinux tools I've seen work at th

Re: Fedora Infrastructure IRC Meeting Log from 2007-07-26

2007-07-27 Thread David Lutterkort
On Thu, 2007-07-26 at 16:01 -0500, Jeffrey C. Ollie wrote: > [15:30] mmcgrath: the problem is opening up access but still keeping some of > the passwords/keys secure. > [15:30] mmcgrath: like the web guys don't need access to the buildserver keys. > [15:30] mmcgrath: and the build guys don't need